Kehong Liu

dblp:179/9348 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 PH-EMO: Decoding Emotions from the Brain Inward - EEG-Grounded Multimodal Reasoning with LLMs
Kehong Liu, Yang Liu 0007, Jiming Liu 0001
WWW1
2026 PELR-GS: perception-enhanced large-scale 3D reconstruction for view-adaptive rendering
Hong-an Li, Jiale Yang, Kehong Liu
J. Supercomput.3
2025 Leading Attackers Astray: Mitigating Link Flooding Attacks through Stub Node Relocation and Insertion
abstract
Link Flooding Attacks (LFA) exploit network topology knowledge to disrupt connectivity by targeting critical links and nodes. Existing defenses often presuppose an attacker with complete topological awareness and overlook the concentration of attack traffic on specific routers. Furthermore, many countermeasures rely on SDN, which can suffer from performance degradation due to the limited packet processing capabilities of switches. To address these issues, we introduce the GateLFA attacker model, which assumes that attackers lack complete topology knowledge and guide their attacks based on traffic density analysis. We propose the EqualFlow algorithm, which utilizes stub node relocation and insertion to minimize adversarial impact, balance attack traffic, and reduce defense costs. Additionally, we present the Network Topology Obfuscation System, leveraging XDP for high-speed packet processing at the network boundary to overcome the performance challenges of SDN-based solutions. Our experimental results demonstrate that EqualFlow computes high-quality virtual topologies, outperforming existing algorithms across small, medium, and large-scale networks. Moreover, the Network Topology Obfuscation System effectively disrupts prominent topology probing tools through explicit information interference at a 10 Gbps line rate. For implicit interference, the system increases the packet rate of typical traceroute probes by approximately 17% compared to traffic control methods. This research provides an efficient and practical solution for defending against LFA.
Bin Wang 0098, Kehong Liu, Yu Zhang 0036, Guopu Zhu, Binxing Fang
SMC2
2025 μGAN: A mutation-based cost optimal adversarial malware generation approach against evolving Android malware variants
Xiaojian Liu 0003, Zilin Qin, Kehong Liu
Comput. Secur.3
2025 Enhanced rotating ship detection in SAR images via noise suppression and feature amplification
Kehong Liu, Ming Zhang 0025, Xiaoli Gao
Vis. Comput.1
2024 MTS-IoT: A Robust Encrypted IoT Traffic Classification via Multi-dimensional Time Series
abstract
The rapid proliferation of IoT devices presents a two-fold challenge: a pronounced deficiency in security measures and a diverse array of Quality of Service (QoS) requirements. For network providers to address these challenges effectively, it is paramount first accurately to identify IoT devices. Current methodologies fall short in their robustness, owing to encrypted traffic and the intricate network environments. This paper applies multi-feature time series to the problem of encrypted IoT device traffic classification, proposing a multi-dimensional time series-based IoT traffic classification method, MTS-IoT. MTS-IoT constructs multi-dimensional time series samples from raw traffic using sliding windows of fixed packet numbers, preserving abundant information. It then utilizes a "Global-Local-Spacial" framework to deeply extract sequence features and introduces sparse self-attention to reduce the training overhead caused by multi-dimensional temporal features. Comprehensive experiments were conducted on a renowned dataset, in which we retained the traffic of non-IoT devices to simulate the real world. Experiments indicate that MTS-IoT outperforms existing methods in classification performance, pushing the F1 to 98.63%(4.46%↑). Moreover, it can achieve accurate detection throughout the entire traffic cycle, resist network congestion, and resist traffic shaping, underscoring its robustness in diverse scenarios.
Tianye Gao, Kehong Liu, ShengBao Li, Ruihai Ge, Tianning Zang
CSCWD3
2024 A Machine Learning-based Method for Clustering the Traffic of Linux NATed Network Entities with TCP/IP Feature
abstract
It is crucial to distinguish the network entities (NEs) behind NAT devices for tasks such as information gathering, asset management, and legal interception. The current mainstream approach has the problem of erroneously clustering traffic from a sparsely communicating NE as traffic from multiple NE. This leads to current algorithms not being able to be applied effectively in real environment. To address this issue, we propose a Linux NEs traffic clustering method based on TCP/IP features in this paper. We integrate multiple hidden level features such as operating system and timestamp and freely cluster the data set based on the density of spatial distribution. We use the datasets from the real campus network and public dataset to evaluate the performance of our method, and the results show that our method overcomes the problem erroneously clustering traffic from a sparsely communicating NE as traffic from multiple NEs. For the current mainstream Linux types, the purity of each version exceeds 0.91, RI exceeds 0.98, ARI exceeds 0.88, and FMI exceeds 0.89. Our method can accurately calculate the number of hosts behind NAT and cluster traffic accordingly.
Kehong Liu, Tianye Gao, Tianxing Ma, Tianning Zang
CSCWD1
2024 Revisiting Open DNS Resolver Vulnerabilities to Reflection-Based DDoS Threats
abstract
DNS, as a vital component of the Internet, is frequently exploited for malicious activities. Millions of open DNS resolvers are exposed with public access, posing significant risks. Amplification vulnerability in UDP-based DNS protocol has been abused by miscreants to launch reflection amplification Distributed Denial of Service (DDoS) attacks. In reflection amplification attacks, forged DNS request packets are continuously sent to open resolvers, triggering amplified attack traffic against the targeted victim. To defend against such attacks, resolvers can take measures to reject anomalous requests and limit the size of responses. Measures such as source address verification and response rate limiting prove effective in mitigating the risk of resolver exploitation. However, implementing these measures requires software and hardware updates or configuration changes, potentially incurring additional costs. Currently, it remains unclear how many open resolvers are adequately protected and how many still pose the potential for exploitation. In this paper, we conducted a thorough measurement on open resolvers about the actual potential of abuse. Our measurement results indicated that 14.9% of open resolvers are susceptible to exploitation for reflection-based DDoS attacks and thousands of resolvers are still exposed to reflection amplification attacks with no mitigation measure.
Kehong Liu, Junnan Yin, Letian Du, Tianning Zang
CSCWD1
2024 Candidate Evaluation with Multimodal Data-Driven for Recruitment
Xing Wu 0001, Kehong Liu, Jianjia Wang, Junfeng Yao, Rongqi Lv
ICPR (8)2
2023 A permission-carrying security policy and static enforcement for information flows in Android programs
Xiaojian Liu 0003, Kehong Liu
Comput. Secur.2