Ke Xu 0002

dblp:181/2626-2 · DBLP profile ↗
← Back
328ranked-venue papers
23as first author
172since 2021 · last 2026
0000-0003-2587-8517ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 191 · 10 first-author · 76 since 2021Security and privacy · 61 · 58 since 2021Systems, architecture and hardware · 24 · 6 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 23 · 4 first-author · 10 since 2021Artificial intelligence and machine learning · 18 · 1 first-author · 15 since 2021Databases, data management, data science and information retrieval · 7 · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Multi-CDN as a Collective Service: Towards Hot Start in Congestion Control at Scale
Tong Li 0014, Jiuxiang Zhu, Bo Wu 0002, Haoyi Fang, Ke Xu 0002
APNet7
2026 LCMP: Distributed Long-Haul Cost-Aware Multi-Path Routing for Inter-Datacenter RDMA Networks
abstract
RDMA-empowered cloud services are gradually deployed across datacenters (DCs) with multiple paths, which exhibit new properties of path asymmetry, delayed congestion signals, and simultaneous flow routing collisions, and further fail existing routing methods.
Dong-Yang Yu 0001, Yuchao Zhang 0004, Jun Wang 0178, Wenfei Wu, Haipeng Yao, Wendong Wang 0003, Ke Xu 0002
EuroSys8
2026 Invisible Adversaries: A Systematic Study of Session Manipulation Attacks on VPNs
Xuewei Feng, Qi Li 0002, Ke Xu 0002
INFOCOM5
2026 Desi: Revisiting Signature Verification in Blockchain-based Storage System
Songsong Xu, Xiaoliang Wang 0004, Yangfei Guo, Shenglin Jiang, Ke Xu 0002
IWQoS8
2026 Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature Filtering
abstract
Model Inversion Attacks (MIAs) pose a significant threat to data privacy by reconstructing sensitive training samples from the knowledge embedded in trained machine learning models. Despite recent progress in enhancing the effectiveness of MIAs across diverse settings, defense strategies have lagged behind—struggling to balance model utility with robustness against increasingly sophisticated attacks. In this work, we propose the ideal inversion error to measure the privacy leakage, and our theoretical and empirical investigations reveals that higher-rank features are inherently more prone to privacy leakage. Motivated by this insight, we propose a lightweight and effective defense strategy based on low-rank feature filtering, which explicitly reduces the attack surface by constraining the dimension of intermediate representations. Extensive experiments across various model architectures and datasets demonstrate that our method consistently outperforms existing defenses, achieving state-of-the-art performance against a wide range of MIAs. Notably, our approach remains effective even in challenging regimes involving high-resolution data and high-capacity models, where prior defenses fail to provide adequate protection. The code is available at https://github.com/Chrisqcwx/LoFt.
Hongyao Yu, Yixiang Qiu, Hao Fang 0011, Tianqu Zhuang, Bin Chen 0011, Sijin Yu, Bin Wang 0034, Shutao Xia, Ke Xu 0002
KDD (1)9
2026 Understanding the Stealthy BGP Hijacking Risk in the ROV Era
Qi Li 0002, Ke Xu 0002, Zhuotao Liu
NDSS3
2026 Enhancing Website Fingerprinting Attacks against Traffic Drift
Xinhao Deng 0001, Qi Li 0002, Zhuotao Liu, Ke Xu 0002
NDSS6
2026 Achieving Interpretable DL-based Web Attack Detection through Malicious Payload Localization
Fukun Mei, Ye Wang 0002, Zhuotao Liu, Ke Xu 0002, Chao Shen 0001, Qian Wang 0002, Qi Li 0002
NDSS5
2026 A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection Systems
Yi Zhao 0011, Zhuotao Liu, Qi Li 0002, Chuanpu Fu, Guangmeng Zhou, Ke Xu 0002
NDSS7
2026 Robust Fraud Transaction Detection: A Two-Player Game Approach
Qi Tan 0003, Yi Zhao 0011, Laizhong Cui, Qi Li 0002, Weiqiang Wang 0002, Ke Xu 0002
NDSS9
2026 FENIX: Enabling In-Network DNN Inference with FPGA-Enhanced Programmable Switches
Tong Li 0014, Yinchao Zhang, Xiangsheng Zeng, Su Yao, Ke Xu 0002
NSDI7
2026 Forewarned is Forearmed: A Responsive Congestion Control with Non-intrusive Uplink Dynamics Capture
Yiying Lin, Shenghui Wei, Enhuan Dong, Kang Chen 0001, Tong Li 0014, Yinchao Zhang, Renjie Xie, Su Yao, Ke Xu 0002, Changqiao Xu
SIGCOMM10
2026 Robust LLM-Based Website Fingerprinting under Dynamic Real-World Conditions
abstract
Website Fingerprinting (WF) attacks aim to infer the websites visited by Tor users by analyzing patterns in encrypted network traffic. However, most existing WF attacks are evaluated on traffic collected in controlled environments with fixed configurations, failing to reflect the complexity and variability of real-world conditions. In practice, traffic is far more dynamic and diverse due to heterogeneous network conditions, the large number of subpages within individual websites, and continuous evolution of website content. These factors increase intra-class variability and induce temporal feature drift, which ultimately degrades the long-term effectiveness of existing attacks. In this paper, we propose TraVerse, an LLM-based representation learning framework designed to achieve robust WF attacks under real-world conditions. TraVerse applies architectural adaptation and large-scale fine-tuning on diverse unlabeled traffic to learn generalizable and resilient representations that remain effective in dynamic and evolving environments. Furthermore, TraVerse integrates a lightweight classifier atop the LLM-derived representations, enabling accurate website identification and efficient few-shot adaptation with minimal model updates. We prototype TraVerse and conduct comprehensive evaluations using real-user traffic. Experimental results show that TraVerse improves Accuracy@3 by an average of 176.3% and weighted F1 by 343.3% over state-of-the-art baselines, while maintaining strong performance throughout a three-month longitudinal evaluation.
Xinhao Deng 0001, Tianyu Cui, Ke Xu 0002, Qi Li 0002
WWW5
2026 Mico: efficient query scheduling for multi-cloud deployed LLM inference service
Peizhuang Cong, Tong Yang 0003, Yuchao Zhang 0004, Wendong Wang 0003, Ke Xu 0002
Sci. China Inf. Sci.5
2026 Towards Efficient and Reliable Training Assurance of Untrusted Federated Learning Participants Under Hardware Non-Determinism
abstract
Federated learning (FL) is a popular privacy-preserving machine learning paradigm, enabling collaborative training across participants without exposing local data. Since FL loses direct control over participants' training executions, a fundamental requirement is to verify that participants faithfully perform the assigned training tasks. In this paper, we present TrustFL+, an efficient, scalable, and reliable verification scheme that ensures the training correctness of federated learning participants by leveraging both Trusted Execution Environments (TEEs) and GPUs. Essentially, it pushes all local training on high-performance but untrusted GPUs, while the TEE replicates the random parts for tunable levels of assurance. A key challenge is that hardware non-determinism can cause the same floating-point operations to yield different results between GPUs and TEEs, leading to false positives when participants behave honestly. TrustFL+ builds on deterministic training by recording rounding directions of intermediate operations during GPU-side model training and reusing them in TEE-based verification. It especially introduces adaptive rounding precisions to practically control non-determinism while maintaining global model performance in federated learning systems with lots of heterogeneous GPUs and iterative training. We prototype TrustFL+ using a range of NVIDIA GPUs covering multiple hardware architectures, along with Intel SGX, and evaluate its performance across convolutional neural networks and transformer-based networks. The experimental results demonstrate that TrustFL+ delivers up to an order of magnitude speedup compared to naive SGX-based training. Furthermore, all models trained with TrustFL+ on different GPU architectures successfully pass verification within SGX, resulting in 0 false positives.
Xiaoli Zhang 0003, Jiaqing Cheng, Wenmao Liu, Xiaohu Ye, Ke Xu 0002, Qi Li 0002, Xu-Cheng Yin
IEEE Trans. Dependable Secur. Comput.6
2026 PriGraph: Defending Against Inference Attacks on Graph Neural Networks via Policy-Based Adversarial Perturbations
abstract
Graph Neural Networks (GNNs) have been widely used in various domains, such as social networks and transportation networks. Previous research has shown that GNNs are vulnerable to inference attacks. Node Membership Inference Attacks (NMIA) on GNNs infer whether a set of graph data records belongs to the training graph data of a target model. Link Status Inference Attacks (LSIA) against GNNs aim to infer whether there exists a link between a pair of nodes in the graph used to train the target GNN model. Specifically, given black-box access to a GNN model, NMIAs and LSIAs are conducted by analyzing the outputs (e.g., confidence score vectors) from GNN models. The defense methods against these two score-based inference attacks face the challenges of achieving effective defense performance and maintaining the utility of GNN models. In this paper, we propose PriGraph, a defense mechanism to protect the node privacy and link privacy of training graph data, while maintaining the high accuracy of the target GNN models. PriGraph adds crafted adversarial perturbations to outputs of the target GNN model by deploying two key components, i.e., defense auxiliary classifier and adversarial perturbation generator, which are used to find the minimal adversarial perturbations that can reduce the attack accuracy while maintaining task performance of node classification. We evaluate PriGraph with different GNN models and multiple benchmark datasets. The results show that PriGraph can dramatically reduce the attack accuracy of NMIA and LSIA on GNNs, providing a superior trade-off between the model utility and privacy.
Meng Shen 0001, Aijing Gu, Qi Li 0002, Ke Xu 0002, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.5
2026 OCEAN: Optional Capability-Based En Route Acknowledgement in Network Layer
abstract
High security and low latency are important in mission-critical data transmission, such as the end-to-end transmission in Industrial IoT (IIoT). However, existing schemes often struggle to simultaneously meet these demanding requirements due to hardware limitations and the lack of a packet lossless forwarding protocol in the network layer data plane. To address this challenge, we propose OCEAN (Optional Capability-based En route Acknowledgement in Network layer). OCEAN includes (1) an in-network caching hardware, which is a programmable Application Specific Integrated Circuit (ASIC) integrated with a Field Programmable Gate Array (FPGA), and (2) a packet lossless forwarding protocol in the network layer data plane. In OCEAN, each packet was generated by an authorized end device, while each en route node verifies the packet, and caches it until receiving the acknowledgment from the next en route node. It incurs negligible latency to packet forwarding when there is no packet loss while retransmitting the packet at the en route node after a short timeout, which reduces the packet forwarding latency. Besides that, the per-packet verification guarantees that the adversary could not subvert the forwarding protocol. Our simulation in the BMv2 environment confirms its functionality, and the hardware implementation demonstrates that it can process packets at line rate with a total processing latency ranging from 2519 ns to 6160 ns, which is negligible in end-to-end transmission.
Su Yao, Songtao Fu, Qi Li 0002, Zhuotao Liu, Yinchao Zhang, Ke Xu 0002
IEEE Trans. Dependable Secur. Comput.7
2026 Covert Knowledge Poisoning Attacks in Retrieval-Augmented Code Generation
abstract
Retrieval-Augmented Code Generation (RACG) systems enhance code generation by dynamically integrating examples retrieved from open knowledge bases, but their reliance on external sources exposes them to knowledge poisoning. While prior attacks inject explicit vulnerable code, such payloads are easily detected, limiting their real-world impact and failing to probe the full attack surface. To overcome this limitation, we propose Arachne, a covert knowledge poisoning attack that, for the first time, achieves fine-grained control over vulnerability types while evading detection. Arachne relies on two mechanisms: (1) Benign-Appearing Fragment Construction, where vulnerable code is decomposed into benign-appearing fragments that pre serve compilability and contextual cues, rendering them effectively undetectable by vulnerability analyzers; and (2) Retrieval Driven Knowledge Completion, in which retrieved fragments activate the large language model's (LLM) contextual reasoning to autonomously generate complete vulnerable code. We evaluate Arachne on eight mainstream LLMs and four retrievers across four common vulnerability types. On GPT-4, Qwen2.5, Gemini 3-flash, Claude-4-sonnet and DeepSeekCoder, Arachne achieves attack success rates exceeding 70% in most settings for each vulnerability type across CWE-78, CWE-295, CWE-367, and CWE-614, peaking at 100% for CWE-367. Arachne demonstrates up to a 37% improvement in attack success rate over existing poisoning attacks. In two real-world applications, the attack achieves 87% success rate with 70% benign utility, indicating that the generated code often satisfies user requirements while introducing vulnerable code. Critically, our poisoned samples, which are designed without explicit malicious patterns, fully bypass rule-based analyzers and challenge state-of-the-art LLM based detectors, exemplifying their stealth among multiple failed defense paradigms. Our findings expose critical limitations in existing defense frameworks, highlighting the urgent need for novel defense mechanisms specifically designed for RACG systems.
Xinlei He 0001, Tianshuo Cong, Ke Xu 0002, Qi Li 0002
IEEE Trans. Dependable Secur. Comput.5
2026 Learning Flow Semantics for Encrypted Traffic Analysis: A Contrastive Pre-Training Approach
abstract
Encrypted traffic analysis is crucial for cyberspace security. Self-supervised learning shows great promise to enhance traffic analysis with the pre-trained traffic encoder, which is constructed using large-scale, readily available unlabeled traffic data. However, existing approaches struggle to handle the increasingly prevalent encrypted traffic, as their generative reconstruction tasks cannot process encrypted content. To this end, we propose TACO, a robust and flexible encrypted traffic analysis system based on flow semantics learning. Specifically, we first design several feasible traffic data augmentation strategies to prepare flow semantics knowledge from the unlabeled traffic. Then, our traffic encoder with a traffic partition module learns the semantics knowledge based on the contrastive pre-training paradigm. It serves as a traffic foundation encoder that can comprehend flow semantics and extract effective semantic representations. Finally, we fine-tune the traffic encoder to leverage flow semantics for various downstream encrypted traffic analysis tasks. The experimental results illustrate that TACO outperforms the optimal baseline by 7.5% in average F1 score on four traffic classification datasets and achieves an improvement of at least 11.62% in average F1 score on the three transfer tasks, while indicating superior efficiency. We will release the source code as well as the experiment data upon publication to foster future research.
Ruijie Zhao 0001, Mingwei Zhan, Qi Li 0002, Zhuotao Liu, Xianwen Deng, Guang Cheng 0001, Zhi Xue, Ke Xu 0002
IEEE Trans. Dependable Secur. Comput.9
2026 I2BGP: A Privacy-Preserving Intra-AS State-Assisted Inter-AS Routing Scheme
abstract
BGP is the most widely employed inter-AS routing protocol, connecting millions of ASes worldwide. While it is possible to select the egress for outgoing flows based on administrators’ configurations, such schemes are localized due to the privacy of the intra-AS network state. TheAS_Pathfield of BGP records all crossed ASes, which can be used to prevent routing loops and select paths,i.e., selecting the minimum AS-hop path among available paths. Although this scheme is simple, effective, and offers a certain degree of global perspective, selecting paths at AS granularity ignores the transmission performance within each intra-AS, which may result in selecting non-optimal routing paths. To enable the use of private intra-AS data for inter-AS routing, we proposed a privacy-preserving intra-AS state-assisted inter-AS routing scheme, which can select optimal inter-AS paths without disclosing specific intra-AS state data. Specifically, we added an additional BGP header field to carry path performance features and designed a three-step data masking mechanism to protect intra-AS state data, enabling the selection of inter-AS paths with intra-AS state awareness. I2BGP has been deployed in the Greater Bay Area Future Network and a large-scale network simulator based on real network topologies. The results show that I2BGP outperforms BGP in terms of specified forwarding hops, delay, and bandwidth metrics.
Peizhuang Cong, Yuchao Zhang 0004, Jun Wang 0178, Wendong Wang 0003, Tong Yang 0003, Dan Li 0001, Ke Xu 0002
IEEE Trans. Netw.7
2026 Toward Robust Multi-Tab Website Fingerprinting
abstract
Website fingerprinting enables an eavesdropper to determine which websites a user is visiting over an encrypted connection. State-of-the-art website fingerprinting (WF) attacks have demonstrated effectiveness even against Tor-protected network traffic. However, existing WF attacks have critical limitations on accurately identifying websites in multi-tab browsing sessions, where the holistic pattern of individual websites is no longer preserved, and the number of tabs opened by a client is unknown a priori. In this paper, we propose ARES, a novel WF framework natively designed for multi-tab WF attacks. ARES formulates the multi-tab attack as a multi-label classification problem and solves it using the novel Transformer-based models. Specifically, ARES extracts local patterns based on multi-level traffic aggregation features and utilizes the improved self-attention mechanism to analyze the correlations between these local patterns, effectively identifying websites. We implement a prototype of ARES and extensively evaluate its effectiveness using our large-scale datasets collected over multiple months. The experimental results illustrate that ARES achieves optimal performance in several realistic scenarios. Further, ARES remains robust even against various WF defenses.
Xinhao Deng 0001, Qilei Yin, Zhuotao Liu, Qi Li 0002, Mingwei Xu 0001, Ke Xu 0002
IEEE Trans. Netw.7
2026 AutoRec: Accelerating Loss Recovery for Live Streaming in a Multi-Supplier Market
abstract
Due to the limited permissions for upgrading dual-side (i.e., server-side and client-side) loss tolerance schemes from the perspective of CDN vendors in a multi-supplier market, modern large-scale live streaming services are still using the automatic-repeat-request (ARQ) based paradigm for loss recovery, which only requires server-side modifications. In this paper, we first conduct a large-scale measurement study with up to 50 million live streams. We find that loss showsdynamicsand live streaming contains frequenton-off mode switchingin the wild. We further find that the recovery latency, enlarged by the ubiquitous retransmission loss, is a critical factor affecting live streaming’s client-side QoE (e.g., video freezing). We then propose an enhanced recovery mechanism called AutoRec, which can transform the disadvantages of on-off mode switching into an advantage for reducing loss recovery latency without any modifications on the client side. AutoRec allows users to customize overhead tolerance and recovery latency tolerance and adaptively adjusts strategies as the network environment changes to ensure that recovery latency meets user demands whenever possible while keeping overhead under control. We implement AutoRec upon QUIC and evaluate it via testbed and real-world commercial services deployments. The experimental results demonstrate the practicability and profitability of AutoRec.
Tong Li 0014, Bo Wu 0002, Fuyu Wang 0006, Jiuxiang Zhu, Haoyi Fang, Xinle Du, Ke Xu 0002
IEEE Trans. Netw.9
2026 Toward Robust Detection of Malicious Encrypted Traffic Using Only Low-Quality Training Data
abstract
Machine learning (ML) is promising in accurately detecting malicious flows in encrypted network traffic; however, it is challenging to collect a training dataset that contains a sufficient amount of encrypted malicious data with correct labels. When ML models are trained with low-quality training data, they suffer degraded performance. In this paper, we aim to address a real-world low-quality training dataset problem, namely, detecting encrypted malicious traffic generated by continuously evolving malware. We develop RAPIER+ that fully utilizes different distributions of normal and malicious traffic data in the feature space, where normal data is tightly distributed in a certain area, and the malicious data is scattered over the entire feature space to augment training data for model training. RAPIER+ includes two pre-processing modules to convert traffic into feature vectors and correct label noises. We evaluate our system on two public datasets and one combined dataset. With 1000 samples and 45% noise from each dataset, our system achieves the F1 scores of 0.78, 0.84, and 0.87, respectively, achieving average improvements of 358.5%, 314.0%, and 221.1% over the existing methods, respectively. Furthermore, we evaluate RAPIER+ with a real-world dataset obtained from a security enterprise. RAPIER+ effectively achieves encrypted malicious traffic detection with the best F1 score of 0.81 and improves the F1 score of existing methods by an average of 288.7%.
Yuqi Qing, Qilei Yin, Xinhao Deng 0001, Zhuotao Liu, Kun Sun 0001, Ke Xu 0002, Jia Zhang 0004, Qi Li 0002
IEEE Trans. Netw.7
2025 Benchmarking Open-ended Audio Dialogue Understanding for Large Audio-Language Models
abstract
Large Audio-Language Models (LALMs), such as GPT-4o, have recently unlocked audio dialogue capabilities, enabling direct spoken exchanges with humans.The potential of LALMs broadens their applicability across a wide range of practical scenarios supported by audio dialogues.However, given these advancements, a comprehensive benchmark to evaluate the performance of LALMs in the open-ended audio dialogue understanding remains absent currently.To address this gap, we propose an Audio Dialogue Understanding Benchmark (ADU-Bench), which consists of 4 benchmark datasets.They assess the open-ended audio dialogue ability for LALMs in 3 general scenarios, 12 skills, 9 multilingual languages, and 4 categories of ambiguity handling.Notably, we firstly propose the evaluation of ambiguity handling in audio dialogues that expresses different intentions beyond the same literal meaning of sentences, e.g., "Really!?" with different intonations.In summary, ADU-Bench includes over 20,000 open-ended audio dialogues for the assessment of LALMs.Through extensive experiments on 16 LALMs, our analysis reveals that existing LALMs struggle with mathematical symbols and formulas, understanding human behavior such as roleplay, comprehending multiple languages, and handling audio dialogue ambiguities from different phonetic elements, such as intonations, pause positions, and homophones.The benchmark is available at https://adu-bench.github.io/.
Kuofeng Gao, Shutao Xia, Ke Xu 0002, Philip Torr 0001, Jindong Gu
ACL (1)3
2025 Understanding the Dark Side of LLMs' Intrinsic Self-Correction
abstract
Qingjie Zhang, Di Wang, Haoting Qian, Yiming Li, Tianwei Zhang, Minlie Huang, Ke Xu, Hewu Li, Liu Yan, Han Qiu. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Haoting Qian, Yiming Li 0004, Tianwei Zhang 0004, Minlie Huang, Ke Xu 0002, Hewu Li, Liu Yan, Han Qiu 0001
ACL (1)7
2025 Swallow: A Transfer-Robust Website Fingerprinting Attack via Consistent Feature Learning
abstract
Website fingerprinting (WF) attacks on Tor networks can analyze traffic patterns to identify the websites Tor users are visiting, and thus pose a significant threat to user privacy. In a real-world environment, Tor users face diverse network conditions and can also employ WF defenses, raising new challenges to launch WF attacks. The state-of-the-art (SOTA) WF attacks either rely on a strong assumption that WF classifiers are trained and deployed under the same network condition, or suffer from significant performance degradation against WF defenses. In this paper, we propose Swallow, a transfer-robust WF attack that can quickly transfer to new network conditions while maintaining robustness against various WF defenses. Specifically, we propose a novel trace representation named Consistent Interaction Feature (CIF), which aligns traffic distributions across different network conditions to capture consistent features. Then we design three data augmentation algorithms to simulate potential variations under various network conditions. We extensively evaluate Swallow using ten datasets, including both self-collected and public datasets. The closed- and open-world evaluation results demonstrate that Swallow significantly outperforms the SOTA attacks. In particular, with only 5 labeled instances per website for model fine-tuning, Swallow achieves an average improvement in accuracy of 17.50% over the SOTA WF attacks.
Meng Shen 0001, Jinhe Wu, Junyu Ai, Qi Li 0002, Chenchen Ren, Ke Xu 0002, Liehuang Zhu
CCS6
2025 Off-Path TCP Exploits: PMTUD Breaks TCP Connection Isolation in IP Address Sharing Scenarios
abstract
Path MTU Discovery (PMTUD) and IP address sharing are integral aspects of modern Internet infrastructure. In this paper, we investigate the security vulnerabilities associated with PMTUD within the context of prevalent IP address sharing practices. We reveal that PMTUD is inadequately designed to handle IP address sharing, creating vulnerabilities that attackers can exploit to perform off-path TCP hijacking attacks. We demonstrate that by observing the path MTU value determined by a server for a public IP address (shared among multiple devices), an off-path attacker on the Internet, in collaboration with a malicious device, can infer the sequence numbers of TCP connections established by other legitimate devices sharing the same IP address. This vulnerability enables the attacker to perform off-path TCP hijacking attacks, significantly compromising the security of the affected TCP connections. Our attack involves first identifying a target TCP connection originating from the shared IP address, followed by inferring the sequence numbers of the identified connection. We thoroughly assess the impacts of our attack under various network configurations. Experimental results reveal that the attack can be executed within an average time of 220 seconds, achieving a success rate of 70%. Case studies, including SSH DoS, FTP traffic poisoning, and HTTP injection, highlight the threat it poses to various applications. Additionally, we evaluate our attack across 50 real-world networks with IP address sharing---including public Wi-Fi, VPNs, and 5G---and find 38 vulnerable. Finally, we responsibly disclose the vulnerabilities, receive recognition from organizations such as IETF, Linux, and Cisco, and propose our countermeasures.
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002
CCS6
2025 Training with Only 1.0 ‰ Samples: Malicious Traffic Detection via Cross-Modality Feature Fusion
abstract
Machine Learning (ML) based malicious traffic detection systems can accurately recognize unseen network attacks by learning from large-scale traffic datasets. However, deploying such systems across multiple networks involves substantial efforts to construct large training datasets for each network. This paper addresses the issue of training with minimal datasets, that is, achieving accurate malicious traffic detection by learning a small portion of traffic in entirely new network environments, thereby eliminating prohibitive labor costs associated with traffic dataset construction. We develop tFusion to effectively extract information from limited datasets by treating network traffic data as multimodal data, comprising features from multiple sensory modalities of packets, flows, and hosts. In particular, we design a dedicated crossmodal attention model that fuses fine-grained per-packet sequential features with coarse-grained per-flow and per-host statistical features, to synthesize correlations among the different granularities of traffic features. Moreover, we design a topology-driven contrastive learning approach that pre- trains the models while reducing topology-related biases, which allows tFusion to achieve generic detection across various networks. We deploy tFusion in an institutional network and measure its performance over five days. tFusion requires human experts to label only 1.0 ‰ traffic, yet it achieves 99.82% accuracy when detecting various attacks. Meanwhile, it outperforms 14 existing methods by improving over 12.76% accuracy on 11 existing datasets.
Chuanpu Fu, Qi Li 0002, Elisa Bertino, Ke Xu 0002
CCS4
2025 Training Robust Classifiers for Classifying Encrypted Traffic under Dynamic Network Conditions
abstract
Most existing DL-based encrypted traffic classification methods suffer performance degradation in real-world deployments due to dynamic network conditions, e.g., network environment changes and traffic obfuscation. Dynamic network conditions cause encrypted traffic to exhibit distinct feature patterns during training and testing phases. To address this issue, we propose MetaTraffic, a novel and general DL training framework built upon meta-learning that enhances the performance of supervised DL models designed for encrypted traffic classification against dynamic network conditions. Our key observation is that the traffic of the same network behaviors share the same semantic features even under different network conditions, which can be considered as stable feature representations. Therefore, MetaTraffic helps DL models learn stable feature representations by minimizing the discrepancies in how the models represent traffic features under different network conditions, thereby achieving robust classification under dynamic network conditions. We implement MetaTraffic based on meta-learning with three innovative facilitate modules to enhance its performance. We evaluate MetaTraffic using three public datasets and three new large-scale encrypted traffic datasets that cover multiple types of network conditions. Experimental results show that, under dynamic multiple types of network conditions, our framework improves the accuracy of DL models by 8.94% and the F1-Macro score by 12.55%, while existing robust training methods decrease the accuracy by 28.85% and the F1-Macro score by 33.52%.
Yuqi Qing, Qilei Yin, Xinhao Deng 0001, Xiaoli Zhang 0003, Zhuotao Liu, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
CCS8
2025 RingSG: Optimal Secure Vertex-Centric Computation for Collaborative Graph Processing
abstract
Collaborative graph processing refers to the joint analysis of inter-connected graphs held by multiple graph owners. To honor data privacy and support various graph processing algorithms, existing approaches employ secure multi-party computation (MPC) protocols to express the vertex-centric abstraction. Yet, due to certain computation-intensive cryptography constructions, state-of-the-art (SOTA) approaches are asymptotically suboptimal, imposing significant overheads in terms of computation and communication. In this paper, we present RingSG, the first system to attain optimal communication/computation complexity within the MPC-based vertex-centric abstraction for collaborative graph processing. This optimal complexity is attributed to Ring-ScatterGather, a novel computation paradigm that can avoid exceedingly expensive cryptography operations (e.g., oblivious sort), and simultaneously ensure the overall workload can be optimally decomposed into parallelizable and mutually exclusive MPC tasks. Within Ring-ScatterGather, RingSG improves the concrete runtime efficiency by incorporating 3-party secure computation via share conversion, and optimizing the most cost-heavy part using a novel oblivious group aggregation protocol. Finally, unlike prior approaches, we instantiate RingSG into two end-to-end applications to effectively obtain application-specific results from the protocol outputs in a privacy-preserving manner. We developed a prototype of RingSG and extensively evaluated it across various graph collaboration settings, including different graph sizes, numbers of parties, and average vertex degrees. The results show RingSG reduces the system running time of SOTA approaches by up to 15.34× and per-party communication by up to 10.36×. Notably, RingSG excels in processing sparse global graphs collectively held by more parties, consistent with our theoretical cost analysis.
Zhenhua Zou, Zhuotao Liu, Jinyong Shan, Qi Li 0002, Ke Xu 0002, Mingwei Xu 0001
CCS5
2025 "I've Decided to Leak": Probing Internals Behind Prompt Leakage Intents
abstract
Large language models (LLMs) exhibit prompt leakage vulnerabilities, where they may be coaxed into revealing system prompts embedded in LLM services, raising intellectual property and confidentiality concerns.An intriguing question arises: Do LLMs genuinely internalize prompt leakage intents in their hidden states before generating tokens?In this work, we use probing techniques to capture LLMs' intent-related internal representations and confirm that the answer is yes.We start by comprehensively inducing prompt leakage behaviors across diverse system prompts, attack queries, and decoding methods.We develop a hybrid labeling pipeline, enabling the identification of broader prompt leakage behaviors beyond mere verbatim leaks.Our results show that a simple linear probe can predict prompt leakage risks from pre-generation hidden states without generating any tokens.Across all tested models, linear probes consistently achieve 90%+ AUROC, even when applied to new system prompts and attacks.Understanding the model internals behind prompt leakage drives practical applications, including intention-based detection of prompt leakage risks.
Jianshuo Dong, Liu Yan, Zhenyu Zhong, Tao Wei 0002, Ke Xu 0002, Minlie Huang, Chao Zhang 0008, Han Qiu 0001
EMNLP6
2025 FacLens: Transferable Probe for Foreseeing Non-Factuality in Fact-Seeking Question Answering of Large Language Models
abstract
Despite advancements in large language models (LLMs), non-factual responses still persist in fact-seeking question answering.Unlike extensive studies on post-hoc detection of these responses, this work studies non-factuality prediction (NFP), predicting whether an LLM will generate a non-factual response prior to the response generation.Previous NFP methods have shown LLMs' awareness of their knowledge, but they face challenges in terms of efficiency and transferability.In this work, we propose a lightweight model named Factuality Lens (FacLens), which effectively probes hidden representations of fact-seeking questions for the NFP task.Moreover, we discover that hidden question representations sourced from different LLMs exhibit similar NFP patterns, enabling the transferability of FacLens across different LLMs to reduce development costs.Extensive experiments highlight FacLens's superiority in both effectiveness and efficiency. 1
Haoyang Li 0015, Jing Zhang 0001, Xinlei He 0001, Qi Li 0002, Ke Xu 0002
EMNLP7
2025 Speculating LLMs' Chinese Training Data Pollution from Their Tokens
abstract
Qingjie Zhang, Di Wang, Haoting Qian, Liu Yan, Tianwei Zhang, Ke Xu, Qi Li, Minlie Huang, Hewu Li, Han Qiu. Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing. 2025.
Haoting Qian, Liu Yan, Tianwei Zhang 0004, Ke Xu 0002, Qi Li 0002, Minlie Huang, Hewu Li, Han Qiu 0001
EMNLP6
2025 One Perturbation is Enough: On Generating Universal Adversarial Perturbations Against Vision-Language Pre-Training Models
abstract
Vision-Language Pre-training (VLP) models have exhibited unprecedented capability in many applications by taking full advantage of the multimodal alignment. However, previous studies have shown they are vulnerable to maliciously crafted adversarial samples. Despite recent success, these methods are generally instance-specific and require generating perturbations for each input sample. In this paper, we reveal that VLP models are also vulnerable to the instance-agnostic universal adversarial perturbation (UAP). Specifically, we design a novel Contrastive-training Perturbation Generator with Cross-modal conditions (C-PGC) to achieve the attack. In light that the pivotal multimodal alignment is achieved through the advanced contrastive learning technique, we devise to turn this powerful weapon against themselves, i.e., employ a malicious version of contrastive learning to train the C-PGC based on our carefully crafted positive and negative image-text pairs for essentially destroying the alignment relationship learned by VLP models. Besides, C-PGC fully utilizes the characteristics of Vision-and-Language (V+L) scenarios by incorporating both unimodal and cross-modal information as effective guidance. Extensive experiments show that C-PGC successfully forces adversarial samples to move away from their original area in the VLP model's feature space, thus essentially enhancing attacks across various victim models and V+L tasks. The GitHub repository is available at https://github.com/ffhibnese/CPGC_VLP_Universal_Attacks.
Hao Fang 0011, Jiawei Kong 0001, Bin Chen 0011, Jiawei Li 0006, Shutao Xia, Ke Xu 0002
ICCV8
2025 An Engorgio Prompt Makes Large Language Model Babble on
abstract
Auto-regressive large language models (LLMs) have yielded impressive performance in many real-world tasks. However, the new paradigm of these LLMs also exposes novel threats. In this paper, we explore their vulnerability to inference cost attacks, where a malicious user crafts Engorgio prompts to intentionally increase the computation cost and latency of the inference process. We design Engorgio, a novel methodology, to efficiently generate adversarial Engorgio prompts to affect the target LLM's service availability. Engorgio has the following two technical contributions. (1) We employ a parameterized distribution to track LLMs' prediction trajectory. (2) Targeting the auto-regressive nature of LLMs' inference process, we propose novel loss functions to stably suppress the appearance of the <EOS> token, whose occurrence will interrupt the LLM's generation process. We conduct extensive experiments on 13 open-sourced LLMs with parameters ranging from 125M to 30B. The results show that Engorgio prompts can successfully induce LLMs to generate abnormally long outputs (i.e., roughly 2-13$\times$ longer to reach 90\%+ of the output length limit) in a white-box scenario and our real-world experiment demonstrates Engergio's threat to LLM service with limited computing resources. The code is released at https://github.com/jianshuod/Engorgio-prompt.
Jianshuo Dong, Tianwei Zhang 0004, Hao Wang 0003, Hewu Li, Qi Li 0002, Chao Zhang 0008, Ke Xu 0002, Han Qiu 0001
ICLR9
2025 PIPE: Identity-Aware Privacy-Enhanced Source and Path Verification for Strengthened Network Accountability
abstract
Network-layer security threats have become increasingly sophisticated, exposing significant vulnerabilities in the current Internet architecture. Despite various proposed solutions, the field faces fundamental challenges in balancing user privacy with network security and achieving practical deployment. This paper presents a novel approach called PIPE (Privacy-preserving Identity and Path Enhancement), which leverages a distributed infrastructure of Key Distribution Servers (KDS) to integrate Decentralized Identity (DID) with source and path verification. Our solution binds user identity, address, path, and data while maintaining privacy through encryption and per-hop address transformation. By embedding DID information in address and implementing encrypted path verification, we achieve enhanced network accountability without compromising privacy. Experimental results demonstrate PIPE’s practicality and advantages over existing approaches in terms of deployment flexibility and security guarantees. Our work contributes to the evolution of secure network architectures by balancing accountability requirements with privacy protection while ensuring practical deployability.
Jianfeng Guan, Kexian Liu, Su Yao, Ye Qin, Songtao Fu, Ke Xu 0002
ICNP9
2025 Wedjat: Detecting Sophisticated Evasion Attacks via Real-time Causal Analysis
abstract
Traffic encryption has been widely adopted to protect the confidentiality and integrity of Internet traffic. However, attackers can also abuse such mechanism to deliver malicious traffic. Particularly, existing methods detecting encrypted malicious traffic are not robust against evasion attacks that manipulate traffic to obfuscate traffic features. Robust detection against evasion attacks remains an open problem. To the end, we develop Wedjat, which utilizes a causal network to model benign packet interactions among relevant flows, such that it recognizes abnormal causality that represents malicious traffic and disrupted causality incurred by evasion attacks. We extensively evaluate Wedjat with millions of flows collected from a real-world enterprise. The experimental results demonstrate that Wedjat achieves an accuracy of 0.957 F1-score when detecting various advanced attacks. Notably, five sophisticated evasion attacks, which have successfully evaded all existing methods, are accurately detected by Wedjat with over 0.915 F1. It demonstrates that Wedjat achieves exceptional robustness against evasions. Meanwhile, Wed- jat maintains an outstanding detection latency, i.e., it can predict each packet in less than 0.125 seconds.
Chuanpu Fu, Xinhao Deng 0001, Ke Xu 0002, Qi Li 0002
KDD (1)4
2025 ReDAN: An Empirical Study on Remote DoS Attacks against NAT Networks
Xuewei Feng, Qi Li 0002, Xingxiang Zhan, Kun Sun 0001, Ganqiu Du, Ke Xu 0002
NDSS9
2025 Off-Path TCP Hijacking in Wi-Fi Networks: A Packet-Size Side Channel Attack
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ganqiu Du, Ke Xu 0002
NDSS8
2025 FlowRefiner: A Robust Traffic Classification Framework against Label Noise
abstract
Network traffic classification is essential for network management and security. In recent years, deep learning (DL) algorithms have emerged as essential tools for classifying complex traffic. However, they rely heavily on high-quality labeled training data. In practice, traffic data is often noisy due to human error or inaccurate automated labeling, which could render classification unreliable and lead to severe consequences. Although some studies have alleviated the label noise issue in specific scenarios, they are difficult to generalize to general traffic classification tasks due to the inherent semantic complexity of traffic data. In this paper, we propose FlowRefiner, a robust and general traffic classification framework against label noise. FlowRefiner consists of three core components: a traffic semantics-driven noise detector, a confidence-guided label correction mechanism, and a cross-granularity robust classifier. First, the noise detector utilizes traffic semantics extracted from a pre-trained encoder to identify mislabeled flows. Next, the confidence-guided label correction module fine-tunes a label predictor to correct noisy labels and construct refined flows. Finally, the cross-granularity robust classifier learns generalized patterns of both flow-level and packet-level, improving classification robustness against noisy labels. We evaluate our method on four traffic datasets with various classification scenarios across varying noise ratios. Experimental results demonstrate that FlowRefiner mitigates the impact of label noise and consistently outperforms state-of-the-art baselines by a large margin. The code is available at https://github.com/NSSL-SJTU/FlowRefiner.
Mingwei Zhan, Ruijie Zhao 0001, Xianwen Deng, Zhi Xue, Qi Li 0002, Zhuotao Liu, Guang Cheng 0001, Ke Xu 0002
NeurIPS8
2025 PRED: Performance-oriented Random Early Detection for Consistently Stable Performance in Datacenters
Xinle Du, Tong Li 0014, Guangmeng Zhou, Zhuotao Liu, Hanlin Huang, Mowei Wang, Kun Tan 0002, Ke Xu 0002
NSDI9
2025 Detecting and Adapting to Stealthy Label-Inversion Drifts via Conditional Distribution Inference
abstract
Deep learning (DL) based malicious traffic detectors have been widely developed to detect diverse network attacks, yet they are suffering from significant performance degradation due to concept drift. Existing anti-concept drift arts focus on combating the drifting traffic whose features significantly diverge from training traffic. However, they neglect a stealthy yet common situation where the testing traffic has similar features to the training traffic but with opposite ground truth labels. As a result, the DL-based detectors would always make incorrect predictions for the stealthy drifting traffic, insufficient to perform long-term real-world intrusion detection. In this paper, we propose Chameleon, a novel active learning framework that combats stealthy drifting traffic by inferring the conditional distribution of the testing traffic with small manual labeling overhead. Specifically, Chameleon measures the fine-grained correlations between the high-dimensional and heterogeneous testing traffic and selects a small number of highly representative testing traffic samples for manual labeling, to accurately infer other testing samples’ labels. With the inferred labels, Chameleon checks the conditional distribution shift from the training to testing traffic to detect concept drift and incrementally trains the DL-based detectors to make them effectively adapt to the shifted distribution. Extensive experiments with six supervised and unsupervised DL-based detectors on three public and four synthetic datasets show that, under stealthy drifting traffic, Chameleon improves the AUT of the DL-based detectors by a range of $18.53 \%$ to $23.89 \%$, while the improvement of SOTA baselines is only between $0.06 \%$ and $1.86 \%$.
Xiaoli Zhang 0003, Qilei Yin, Jianrong Zhang, Ke Xu 0002, Qi Li 0002, Xu-Cheng Yin
RAID7
2025 Pegasus: A Universal Framework for Scalable Deep Learning Inference on the Dataplane
abstract
The paradigm of Intelligent DataPlane (IDP) embeds deep learning (DL) models on the network dataplane to enable intelligent traffic analysis at line-speed. However, the current use of the match-action table (MAT) abstraction on the dataplane is misaligned with DL inference, leading to several key limitations, including accuracy degradation, limited scale, and lack of generality. This paper proposes Pegasus to address these limitations. Pegasus translates DL operations into three dataplane-oriented primitives to achieve generality: Partition, Map, and SumReduce. Specifically, Partition "divides" high-dimensional features into multiple low-dimensional vectors, making them more suitable for the dataplane; Map "conquers" computations on the low-dimensional vectors in parallel with the technique of Fuzzy Matching, while SumReduce "combines" the computation results. Additionally, Pegasus employs Primitive Fusion to merge computations, improving scalability. Finally, Pegasus adopts full-precision weights with fixed-point activations to improve accuracy. Our implementation on a P4 switch demonstrates that Pegasus can effectively support various types of DL models, including Multi-Layer Perceptron (MLP), Recurrent Neural Network (RNN), Convolutional Neural Network (CNN), and AutoEncoder models on the dataplane. Meanwhile, Pegasus outperforms state-of-the-art approaches with an average accuracy improvement of up to 22.8%, along with up to 248× larger model size and 212× larger input scale.
Yinchao Zhang, Su Yao, Kang Chen 0001, Tong Li 0014, Zhuotao Liu, Yi Zhao 0011, Lexuan Zhang, Qi Li 0002, Ke Xu 0002
SIGCOMM12
2025 A PINN-Centric Approach to Battery SOH: Harmonizing LSTM Dynamics with Kalman Filter Precision
abstract
This paper presents a new Physics-Informed Neural Network (PINN) framework to estimate the State of Health (SOH) of lithium-ion batteries. The proposed architecture, PINN-LSTM-KF, integrates long- and short-term memory (LSTM) networks with extended Kalman filtering under physics-based constraints. Conventional data-driven approaches often fail to generalize across different operating conditions due to non-linear degradation patterns. Our method addresses these challenges by enforcing electrochemical constraints within a multiscale architecture. It simultaneously captures microscopic physical processes, mesoscopic temporal dynamics, and macroscopic uncertainty quantification. Experiments on lithium-ion, lithium iron phosphate, and lithium-sulfur batteries demonstrate that the proposed framework achieves mean absolute percentage errors below 0. 01% under physics-informed configurations. Model compression techniques further reduce memory overhead, enabling real-time deployment in embedded systems. The framework also supports feature-level interpretability by quantifying contributions of physical variables to degradation, offering practical insights for battery design and management. These results highlight the potential of combining physics-based modeling with learning-based estimation to improve reliability and safety in energy storage systems, particularly in critical domains such as electric vehicles and smart grids.
Ke Xu 0002, Fusen Guo, Rui Zhang 0017, Huadong Mo
SMC1
2025 TrafficFormer: An Efficient Pre-trained Model for Traffic Data
abstract
Traffic data contains deep domain-specific knowledge, making labeling challenging, and the lack of labeled data adversely impacts the accuracy of learning-based traffic analysis. The pre-training technology is widely adopted in the fields of vision and natural language to address the problem of limited labeled data. However, the exploration in the domain of traffic analysis remains insufficient. This paper proposes an efficient pre-training model, TrafficFormer, for traffic data. In the pre-training stage, TrafficFormer introduces a fine-grained multi-classification task to enhance the representation capabilities of traffic data; in the fine-tuning stage, TrafficFormer proposes a traffic data augmentation method utilizing the random initialization feature of fields, which helps the traffic model focus on key information. We evaluate TrafficFormer using both traffic classification tasks and protocol understanding tasks. The experimental results show that TrafficFormer achieves superior performance on six traffic classification datasets, with improvements of up to 10% in the F1 score and demonstrates significantly superior protocol understanding capabilities compared to existing traffic pre-training models.
Guangmeng Zhou, Xiongwen Guo, Zhuotao Liu, Tong Li 0014, Qi Li 0002, Ke Xu 0002
SP6
2025 CertTA: Certified Robustness Made Practical for Learning-Based Traffic Analysis
Jinzhu Yan, Zhuotao Liu, Shiyu Liang, Lin Liu 0018, Ke Xu 0002
USENIX Security Symposium6
2025 SPWS-Transformer: A Study of 3D Target Detection Method Based on Lightweight Depth Prediction With Multi-Scale Fusion
abstract
ABSTRACT Advanced driver assistance systems (ADAS) mainly consist of three components: environmental perception, decision planning, and motion control. As a fundamental component of the ADAS environmental perception system, 3D object detection enables vehicles to avoid obstacles and ensure driving safety only through accurate and real‐time prediction and localization of three‐dimensional targets such as vehicles and pedestrians in road scenes. Therefore, to improve both the real‐time performance and accuracy of 3D object detection, we propose a lightweight depth prediction‐based 3D object detection model with multi‐scale fusion—SPWS‐Transformer. First, to enhance the model's accuracy, we propose a feature extraction network incorporating multi‐scale feature fusion and depth prediction. By designing a multi‐scale feature fusion module, we effectively combine multi‐scale semantic and fine‐grained information from feature maps of different scales to enhance the network's feature extraction capability. To capture spatial information from the feature maps, we apply convolution, group normalization, and nonlinear activation operations on the fused feature maps to generate depth feature maps. Both the fused feature maps and depth feature maps serve as inputs for subsequent network stages. To further improve accuracy, we leverage the long‐range modelling advantages of Transformers by designing a feature enhancement encoder to strengthen the representation capability of depth feature maps. We incorporate a dilated encoder to perform positional encoding on depth feature maps and utilize multi‐head self‐attention mechanisms to capture contextual relationships within the input scene, thereby enhancing the detection capability of the 3D object detection network. Then, to improve real‐time performance, we design a decoder structure with scale‐aware attention. By predefining masks of different scales, we adaptively learn a scale‐aware filter using depth and visual features to enhance object queries. Finally, on the KITTI dataset, the improved algorithm achieves an AP of 24.66% for the car category, with more significant improvements in detection accuracy under the ‘hard’ difficulty level. The model achieves an inference time of 24 ms.
Chang'an Zhang, Ke Xu 0002, Chunhong Yuan, Fusen Guo
IET Image Process.3
2025 MGCP: A Multi-Grained Correlation based Prediction Network for multivariate time series
Xi Xiao 0001, Ke Xu 0002, Zhong Zhang 0014, Yu Rong 0001, Qing Li 0006, Guojun Gan, Zhiqiang Xu 0003, Peilin Zhao
Neurocomputing3
2025 LEOEdge: A Satellite-Ground Cooperation Platform for the AI Inference in Large LEO Constellation
abstract
With the rapid growth of low earth orbit (LEO) satellites, enabling LEO AI inference becomes a fast-increasing trend. However, due to resource heterogeneity, scheduling complexity, and fast movement, how to decide the place of executing each AI inference task is nontrivial in LEO systems. In this paper, we propose LEOEdge, an edge-assisted AI inference system for LEO satellites. We first introduce the adaptive modeling technologies that automatically generate the model for each satellite according to its computation resources. We then propose a layered scheduling optimization scheme to schedule the AI inference task in a distributed manner. LEOEdge also designs a seamless data transmission scheme to avoid transmission failure due to the LEO satellite movement. We conduct a series of simulation tests to validate the performance of the proposed LEOEdge, in terms of the neural network searching efficiency, average time execution latency, and delivery latency.
Su Yao, Yiying Lin, Ke Xu 0002, Mingwei Xu 0001, Changqiao Xu, Hongke Zhang
IEEE J. Sel. Areas Commun.4
2025 MemDefense: Defending Against Membership Inference Attacks in IoT-Based Federated Learning via Pruning Perturbations
abstract
Depending on large-scale devices, the Internet of Things (IoT) provides massive data support for resource sharing and intelligent decision, but privacy risks also increase. As a popular distributed learning framework, Federated Learning (FL) is widely used because it does not need to share raw data while only parameters to collaboratively train models. However, Federated Learning is not spared by some emerging attacks, e.g., membership inference attack. Therefore, for IoT devices with limited resources, it is challenging to design a defense scheme against the membership inference attack ensuring high model utility, strong membership privacy and acceptable time efficiency. In this paper, we propose MemDefense, a lightweight defense mechanism to prevent membership inference attack from local models and global models in IoT-based FL, while maintaining high model utility. MemDefense adds crafted pruning perturbations to local models at each round of FL by deploying two key components, i.e., parameter filter and noise generator. Specifically, the parameter filter selects the apposite model parameters which have little impact on the model test accuracy and contribute more to member inference attacks. Then, the noise generator is used to find the pruning noise that can reduce the attack accuracy while keeping high model accuracy, protecting each participant's membership privacy. We comprehensively evaluate MemDefense with different deep learning models and multiple benchmark datasets. The experimental results show that lowcost MemDefense drastically reduces the attack accuracy within limited drop of classification accuracy, meeting the requirements for model utility, membership privacy and time efficiency.
Meng Shen 0001, Ke Xu 0002, Shui Yu 0001, Liehuang Zhu
IEEE Trans. Big Data3
2025 Accelerating Loss Recovery for Content Delivery Network
abstract
Packet losses significantly impact the user experience of content delivery network (CDN) services such as live streaming and data backup-and-archiving. However, our production network measurement studies show that the legacy loss recovery is far from satisfactory due to the wide-area loss characteristics (i.e., dynamics and burstiness) in the wild. In this paper, we propose a sender-side Adaptive ReTransmission scheme, ART, which minimizes the recovery time of lost packets with minimal redundancy cost. Distinguishing itself from forward-error-correction (FEC), which preemptively sends redundant data packets to prevent loss, ART functions as an automatic-repeat-request (ARQ) scheme. It applies redundancy specifically to lost packets instead of unlost packets, thereby addressing the characteristic patterns of wide-area losses in real-world scenarios. We implement ART upon QUIC protocol and evaluate it via both trace-driven emulation and real-world deployment. The results show that ART reduces up to 34% of flow completion time (FCT) for delay-sensitive transmissions, improves up to 26% of goodput for throughput-intensive transmissions, reduces 11.6% video playback rebuffering, and saves up to 90% of redundancy cost.
Tong Li 0014, Wei Liu 0230, Shuaipeng Zhu, Jingkun Cao, Duling Xu, Zhaoqi Yang, Senzhen Liu, Taotao Zhang, Yinfeng Zhu 0002, Bo Wu 0002, Kezhi Wang, Ke Xu 0002
IEEE Trans. Computers13
2025 Secure Fault Localization in Path Aware Networking
abstract
Secure data forwarding is critical for users to meet their requirements. In this paper, we propose D3 (Demon Detector in Data Plane), a source-driven, secure fault localization mechanism, which empowers the source to localize faulty link in Path Aware Networking, thus circumventing faulty link to guarantee secure data forwarding. D3 utilizes the source to instruct the on-path routers, thus empowering it to detect whether the on-path routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the heavy storage, computation, and communication overhead, D3 offloads most of the on-path router's storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, thus having a low communication overhead. Besides that, the destination in D3 could keep stateless processing, thus having backward compatibility and eliminating the opportunity for DoS attacks toward a stateful destination. The BMv2 and Barefoot Tofino hardware evaluations show that D3 could achieve high fault localization accuracy and process the packet at line rate.
Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002
IEEE Trans. Dependable Secur. Comput.9
2025 Pisces: In-Path Distributed Denial-of-Service Defense via Efficient Authentication Code Embedded in IP Address
abstract
High-volume brute-force distributed denial-of-service (DDoS) attack is among the top threats on the Internet. Existing widely deployed methods (e.g., BGP blackhole and scrubbing center) have difficulty achieving legitimate traffic friendliness, low cost, low latency, and high accuracy. We present an in-path DDoS defense mechanism, namelyPisces. Without requiring modifications to existing IP protocols,Piscesembeds authentication information into the IP address. Simultaneously, we design a QUIC-based extension to distribute authentication information.Piscesincorporates a translator module and a filter module, which accurately identifies malicious and legitimate traffic. These multi-dimensional compatibility advantages make it easy to deploy in the real world. We implementPisceson a high-end commercial router with service processing units. Even without hardware acceleration, a single CPU can achieve$ 20\,\text{Gbps}$throughput and the performance can scale linearly with the number of CPUs. The additional latency for the victim-related traffic and other traffic is around$27\,\text{us}$and$0.5\,\text{us}$, respectively, whose cost is far less than the scrubbing center. Remarkably,Pisceswithout false positives can provide high-quality datasets for intelligent approaches and form a prominent complementary effect.
Yi Zhao 0011, Bingyang Liu, Weiyu Jiang, Ke Xu 0002, Qi Li 0002, Chuang Wang 0012, Zongxin Dou
IEEE Trans. Dependable Secur. Comput.4
2025 Pricing Utility vs. Location Privacy: A Differentially Private Data Sharing Framework for Ride-on-Demand Services
abstract
Noise perturbation introduced by differential privacy (DP) could degrade the quality of essential services like dynamic pricing and ride-matching in ride-on-demand (RoD) services. In this paper, we focus on RoD services under an honest-but-curious server, and propose a Pricing-Aware Differentially Private framework (PADP-RoD) to protect users’ location privacy while providing them with high-quality location-based services. Specifically, given that a price multiplier is subject to abrupt changes in response to shifts in supply and demand, especially near hotspots, we propose an adaptive supply and demand aware grid to capture the changes. Powered by the grid, we put forward two utility metrics for quantifying the quality loss of dynamic pricing and ride-matching services caused by perturbation, respectively. With those metrics, PADP-RoD is formulated as a minimization problem, aiming to minimize the quality loss of services given DP constraint. In this way, we can achieve an optimal balance between privacy and service quality. Due to the problem being a multi-objective optimization, we decompose it into a dynamic-pricing utility sub-problem and a ride-matching utility sub-problem, and solve them separately. To solve the dynamic pricing utility sub-problem, we propose a heuristic algorithm named the dynamic pricing mapping algorithm. Since the semi-infinite and non-differentiable nature of the ride-matching utility sub-problem, we transform this sub-problem into an unconstrained problem by the exact penalty function method, and solve it employing the particle swarm optimization algorithm. Our theoretical analysis demonstrates that PADP-RoD satisfies both$\varepsilon _{d}$-DP and$\varepsilon _{d}$-identifiability, and extensive experiments on a real-world dataset show that it can provide high-quality dynamic pricing and ride-matching services.
Zhirun Zheng, Zhetao Li, Saiqin Long, Suiming Guo, Chao Chen 0004, Ke Xu 0002
IEEE Trans. Dependable Secur. Comput.6
2025 Robust Detection of Malicious Encrypted Traffic via Contrastive Learning
abstract
Traffic encryption is widely used to protect communication privacy but is increasingly exploited by attackers to conceal malicious activities. Existing malicious encrypted traffic detection methods rely on large amounts of labeled samples for training, limiting their ability to quickly respond to new attacks. These methods also are vulnerable to traffic obfuscation strategies, such as injecting dummy packets. In this paper, we proposeSmartDetector, a robust malicious encrypted traffic detection method via contrastive learning. We first propose a novel traffic representation named Semantic Attribute Matrix (SAM), which can effectively distinguish between malicious and benign traffic. We also design a data augmentation method to generate diverse traffic samples, which makes the detection model more robust against different traffic obfuscation strategies. We propose a malicious encrypted traffic classifier that first pre-trains a model via contrastive learning to learn deep representations from unlabeled data, then fine-tunes the model with a supervised classifier to achieve accurate detection even with only a few labeled samples. We conduct extensive experiments with five public datasets to evaluate the performance of SmartDetector. The results demonstrate that it outperforms the state-of-the-art (SOTA) methods in three typical scenarios. Specifically, in the evasion attack detection scenario, SmartDetector achieves an F1 score and AUC above 93%, with average improvements of 19.84% and 18.17% over the SOTA method, respectively.
Meng Shen 0001, Jinhe Wu, Ke Ye, Ke Xu 0002, Gang Xiong 0001, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2025 Enhancing Federated Learning Robustness Using Locally Benignity-Assessable Bayesian Dropout
abstract
Federated Learning (FL) has emerged as a privacy-preserving training paradigm, which enables distributed devices to jointly learn a shared model without raw data sharing. However, the inaccessible client-side data and unverifiable local training leave FL vulnerable to Byzantine attacks. Most defense strategies focus on penalizing malicious clients in server-side aggregations and ignore clients-side weight units poisoning assessment, failing to maintain robustness and convergence in non-IID settings. In this paper, we propose Federated learning with Benignity-assessable Bayesian Dropout and variational Attention (FedBDA) to achieve local robust training based on fine-grained benignity indicators and guarantee global robustness over non-IID data. Specifically, FedBDA integrates variational inference explanation of dropout into local training, where each client individually quantifies the benign degree of weight units to determine a resilient dropping pattern for the local Bayesian model, enabling client-side robust training with Bayesian interpretability. To accommodate variational distributions of local Bayesian models and globally assess their benign potentials, we design a joint attention mechanism based on Jensen-Shannon divergence among local, global, and median distributions for robust weighted aggregation. Theoretical analysis proves the robustness and convergence of FedBDA. We conduct extensive experiments on four benchmark datasets with five typical attacks, and the results demonstrate that FedBDA outperforms status quo approaches in model performance and running efficiency.
Min Liu 0001, Qi Li 0002, Ke Xu 0002
IEEE Trans. Inf. Forensics Secur.5
2025 GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture Search
abstract
Gradient Inversion Attacks invert the transmitted gradients in Federated Learning (FL) systems to reconstruct the sensitive data of local clients and have raised considerable privacy concerns. A majority of gradient inversion methods rely heavily on explicit prior knowledge (e.g., a well pre-trained generative model), which is often unavailable in realistic scenarios. This is because real-world client data distributions are often highly heterogeneous, domain-specific, and unavailable to attackers, making it impractical for attackers to obtain perfectly matched pre-trained models, which inevitably suffer from fundamental distribution shifts relative to target private data. To alleviate this issue, researchers have proposed to leverage the implicit prior knowledge of an over-parameterized network. However, they only utilize a fixed neural architecture for all the attack settings. This would hinder the adaptive use of implicit architectural priors and consequently limit the generalizability. In this paper, we further exploit such implicit prior knowledge by proposing Gradient Inversion via Neural Architecture Search (GI-NAS), which adaptively searches the network and captures the implicit priors behind neural architectures. Extensive experiments verify that our proposed GI-NAS can achieve superior attack performance compared to state-of-the-art gradient inversion methods, even under more practical settings with high-resolution images, large-sized batches, and advanced defense strategies. To the best of our knowledge, we are the first to successfully introduce NAS to the gradient inversion community. We believe that this work exposes critical vulnerabilities in real-world federated learning by demonstrating high-fidelity reconstruction of sensitive data without requiring domain-specific priors, forcing urgent reassessment of FL privacy safeguards.
Hao Fang 0011, Bin Chen 0011, Xiaohang Sui, Chuan Chen 0001, Shutao Xia, Ke Xu 0002
IEEE Trans. Inf. Forensics Secur.8
2025 DeCross: Toward Accountable and Efficient Cross-Chain Collaboration in IIoT
abstract
Blockchain-based industrial Internet-of-Things (IIoT) systems have seen rapid adoption and development in recent years. The increasing diversity of IIoT application scenarios is driving the growth of multichain ecosystem, making cross-chain communication a key issue in multichain collaboration. However, existing centralized cross-chain architectures risk derailing the blockchain's trust-free decentralization and suffer from single point failure. The design of decentralized cross-chain collaboration mainly faces two key challenges. First, implicit cross-chain accountability, which is caused by collusion among malicious distributed participants and, thus, compromises cross-chain security. Second, low cross-chain efficiency, which is induced by the highly dynamic environment in practical cross-chain networks, i.e., changing memberships, and adaptive attacks to corrupt honest nodes. In this article, we propose a cross-chain consensus protocolDeCrossto solve the abovementioned problems.DeCrossachieves decentralized cross-chain collaboration with explicit accountability and high efficiency. Specifically, we audit participants with a succinct auditable data object constructed from the protocol to hold nodes accountable for misbehaving. Furthermore, we propose a parallel processing workflow that leverages both CPUs and GPUs to guarantee efficient and stable cross-chain communication. Finally, we implement a prototype based on the hyperledger fabric with both local and geo-distributed clusters. Our extensive experiments show thatDeCrossachieves 44% better throughput over the existing cross-chain approaches.
Yuchao Zhang 0004, Ke Xu 0002
IEEE Trans. Ind. Informatics5
2025 Toward Optimal Broadcast Mode in Offline Finding Network
abstract
This paper proposes ElastiCast, a novel Bluetooth Low Energy (BLE) broadcast mode that reduces the neighbor discovery latency in offline finding networks (OFNs). ElastiCast adapts the broadcast mode of the lost devices to the scan modes of the finder devices, considering their diversity. We start with an overview of OFNs, followed by a detailed analysis of the issues and challenges of existing solutions, which motivates the design of ElastiCast. Then we provide Blender, a simulator that models the neighbor discovery behavior of different broadcasters and scanners. By adopting Blender, ElastiCast can be implemented with three components: Local Optima Estimation, Common Interest Extraction, and Interval Multiplexing, in which we capture the key features of BLE neighbor discovery and globally optimize the broadcast mode interacting with diverse scan modes. Experimental evaluation results and commercial product deployment experience demonstrate that ElastiCast is effective in achieving stable and bounded neighbor discovery latency within the power budget.
Tong Li 0014, Yukuan Ding, Kai Zheng 0003, Xu Zhang 0006, Tian Pan 0001, Dan Wang 0002, Ke Xu 0002
IEEE Trans. Mob. Comput.8
2025 Burst-Sensitive Traffic Forecast via Multi-Property Personalized Fusion in Federated Learning
abstract
For distributed network traffic prediction with data localization and privacy protection, Federated Learning (FL) enables collaborative training without raw data exchange across Base Stations (BSs). Nevertheless, traffic across BSs exhibit inherently heterogeneous trend burst and smooth fluctuation properties, but existing FL methods model single-scale series from only one view, which cannot simultaneously capture diverse trend and fluctuation properties, especially distinct burst distributions. In this paper, we proposePersonalized Federated Forecasting with Multi-property Self-fusion (P2FMS), which can represent multi-scale traffic properties from different views. With precise multi-property representations, a fusion-level prediction decision is learned for each client in a personalized manner to promptly sense traffic bursts and improve forecasting performance in non-IID settings. Specifically, P2FMS decomposes the traffic series into distinct time scales, based on which, we effectively extract closeness, period, and trend properties from different views. The closeness and period are embedded through global-view representations with spatial correlations, while non-stationary trends are individually fitted from the client-side view. Furthermore, a personalized combiner is designed to accurately quantify the proportion of general fluctuation raws (i.e., closeness and period) and specific trend property in predictions, which enables multi-property self-fusion for each client to accommodate heterogeneous traffic patterns and enhance prediction accuracy. Besides, an alternant training mechanism is introduced to optimize property representation and fusion modules with the convergence guarantee. Extensive experiments on real-world datasets show that P2FMS outperforms status quo methods in both prediction performance and convergence time.
Min Liu 0001, Yuwei Wang 0003, Xuying Meng, Jingyuan Wang 0001, Junbo Zhang 0004, Ke Xu 0002
IEEE Trans. Mob. Comput.8
2025 Multi-Agent Reinforcement Learning for Task Offloading in Crowd-Edge Computing
abstract
The Crowd-edge (CE) computing paradigm facilitates the utilization of the computational resources through simultaneously relying the edge computing and the collaboration among various mobile devices (MDs). Most existing works, focusing on offloading tasks from device to edge servers by centralized solutions, are unable to distribute tasks to massive MDs in CE. Meanwhile, designing a decentralized task offloading solution enabling task subscribers to individually make offloading decisions can be challenging given the randomness of crowd resource provisioning and limited knowledge of global status variations. In this paper, we propose a decentralized crowd-edge task offloading solution that enables users to optimally offload tasks to the CE in a distributed manner. Specifically, we formulate the corresponding problem as a stochastic optimization with partially observable status. By observing network and process delays at the crowd side, we further reform the optimization forms and provide a novel approximation policy, enabling users to optimize their offloading strategy based on local observations without interaction with each other. We then solve this task offloading problem by developing a Mixed Multi-Agent Proxy Policy Optimization algorithm (mixed MAPPO). Extensive testing, including numerical and system-level simulations, was conducted to validate the performance of the proposed algorithm in terms of task delay (including the processing delay and transmission delay), load rate, and resource utilization.
Su Yao, Ju Ren 0001, Weiqiang Wang 0002, Ke Xu 0002, Mingwei Xu 0001, Hongke Zhang
IEEE Trans. Mob. Comput.6
2025 DiffECN: Differential ECN Marking for Datacenter Networks
abstract
ECN marking has been integrated into datacenter switches to enable high-throughput and low-latency transport. We observe that current marking schemes are coarse-grained: they blindly mark all flows when congestion occurs, causing large flows to occupy undeserved bandwidth and preventing newly arriving small flows from finishing quickly. In this paper, we propose DiffECN, a differential marking strategy that marks only the flows that are the culprits of congestion and protects the remaining flows from being limited. We have implemented it in the Barefoot Tofino switch and performed extensive evaluations via both physical testbed and large-scale simulations. The results show that DiffECN can restrain flows responsible for congestion successfully while providing desirable network performance. For instance, compared to the legacy way of ECN marking, DiffECN achieves up to 32.5% (40.1%) lower average (99th percentile) flow completion time (FCT) for small flows while delivering similar FCT for large flows under production workloads.
Hanlin Huang, Ke Xu 0002, Tong Li 0014, Zhuotao Liu, Xinle Du
IEEE Trans. Netw.2
2025 Constructing SDN Covert Timing Channels Between Hosts With Unprivileged Attackers
abstract
Software-defined networking (SDN) has been widely deployed due to its centralization and programmable features. However, these new features bring new threats at the same time. Previous studies have shown that SDN covert channels can be built with a privileged adversary that controls SDN key components, such as controller applications or SDN switches. In this paper, we propose new SDN covert timing channels between hosts without controlling applications, controllers, or having access to switches. Experiments in a real SDN testbed demonstrate the feasibility and effectiveness of our covert channels. To defend against the covert timing channels, we design a defense system named CovertGuard, which utilizes the timing characteristics of the covert channels’ delays to detect and eliminate covert channels effectively.
Yixiong Ji, Jiahao Cao 0001, Qi Li 0002, Yan Liu 0069, Tao Wei 0002, Ke Xu 0002
IEEE Trans. Netw.6
2025 StateShield: Real-Time Defenses Against Information Leakage Over Connectionless Protocols
abstract
Connectionless protocols such as ICMP and UDP are manipulated to construct novel information leakage channels by which attackers can disrupt TCP connections or leak secret information. Existing solutions have mainly focused on repairing vulnerable protocols through OS patches, which are OS-specific and slow to deploy. Other traditional defenses either cannot cover these attacks or are prone to incur unintended dropping of legitimate packets due to the heavily manipulated IP spoofing technique in these attacks. In this paper, we present StateShield, an in-network, real-time defense against state-of-the-art information leakage attacks over connectionless protocols. StateShield can detect and defend against various information leakage attacks without incurring unintended dropping of legitimate traffic, even when attackers heavily spoof the IP addresses of legitimate clients. To achieve that, we propose three indicators that can cover major attack vectors of connectionless information leakage channels and are effective for detecting more than ten attack variants. We design the architecture of StateShield based on programmable switches, with efficient data structures for monitoring and on-demand defense components in the data plane. We develop two novel defense components to mitigate UDP and ICMP-based information leakage channels automatically while achieving minimal unintended dropping of legitimate packets. Our extensive experiments show that StateShield can effectively mitigate more than ten attack variants in real time without hurting the services over legitimate connectionless packets, and the defense provided by StateShield is robust under high-intensive background traffic over connectionless protocols.
Qi Li 0002, Xuewei Feng, Chuanpu Fu, Ke Xu 0002
IEEE Trans. Netw.6
2025 Revisiting Random Early Detection Tuning for High-Performance Datacenter Networks
abstract
Random Early Detection (RED) has been integrated into datacenter switches as a fundamental Active Queue Management (AQM) for decades. The accurate configuration of RED parameters is crucial to achieving high throughput and low latency. However, due to the highly dynamic nature of workloads in datacenter networks, maintaining consistently high performance with statically configured RED thresholds poses a challenge. Prior work applies reinforcement learning to predict proper thresholds, but their real-world deployment has been hindered by poor tail performance caused by instability. In this paper, we propose$\textsf {PRED}$, a novel system that enables automatic and stable RED parameter adjustment in response to traffic dynamics. Specifically, the system employs a Multiplicative-Increase Multiplicative-Decrease (MIMD) strategy to dynamically adapt to flow concurrency while utilizing an Additive-Increase Additive-Decrease (AIAD) mechanism to adapt to flow distribution. We perform extensive evaluations on our physical testbed and large-scale simulations. The results demonstrate that$\textsf {PRED}$can keep up with the real-time network dynamics generated by realistic workloads. For instance, compared with the static-threshold-based methods,$\textsf {PRED}$keeps 66% shorter switch queue length and obtains up to 80% lower Flow Completion Time (FCT). Compared with the state-of-the-art learning-based method,$\textsf {PRED}$reduces the tail FCT by 34%.
Tong Li 0014, Xinle Du, Guangmeng Zhou, Hanlin Huang, Zhuotao Liu, Mowei Wang, Kun Tan 0002, Ke Xu 0002
IEEE Trans. Netw.9
2025 Expediting Federated Learning on Non-IID Data by Maximizing Communication Channel Utilization
abstract
Federated learning (FL) is at the core of intelligent Internet architecture. It allows clients to jointly train a model without direct data sharing. In such a process, clients and the central server share information through communication channels formed by parameters. However, the non-iid training data in clients significantly impacts global model convergence and brings difficulties for the evaluation of local contributions. Most of existing studies try to expand the communication channel by improving consistency with variance reduction or regularization, but such methods neglect an important factor, i.e., channel utilization, hence their capability for sharing information is under-utilized. Moreover, the issue of contribution evaluation is still unsolved. In this paper, we simultaneously solve the former two challenges (i.e., model convergence and contribution evaluation) by modeling the indirect data sharing of FL as a problem of information communication. We prove that FL with non-iid data forms noisy communication channels, which have limited capability for information transmission, i.e., limited channel capacity. The main factor in deciding the channel capacity is the Gradient Signal to Noise Ratio (GSNR). Through analyzing GSNR, we further prove that channel capacity can be reached by optimal local updates and propose a method FedGSNR to calculate it, which allows us to maximize channel utilization in FL, leading to faster model convergence. Moreover, as the contribution of the local dataset depends on the amount of provided information, the derived GSNR allows the server to accurately evaluate the contributions of different clients (i.e., the quality of local datasets).
Qi Tan 0003, Yi Zhao 0011, Qi Li 0002, Ke Xu 0002
IEEE Trans. Netw.4
2025 "One Model Fits All Nodes": Neuron Activation Pattern Analysis-Based Attack Traffic Detection Framework for P2P Networks
abstract
Machine learning (ML) based network attack traffic detection is an emerging security paradigm, which is capable of capturing various advanced network attacks according to the features of traffic. When leveraging such promising security application to protect P2P services, particularly distributed cryptocurrency systems, one detection model should be deployed on many nodes to handle various unseen traffic patterns generated by nodes around the world. However, unseen yet benign traffic patterns are commonly classified as attack traffic, and thus trigger massive false-positive (FP) alarms. Unfortunately, the common practice of retraining models to reduce FPs is not salable for large-scale P2P networks, which incurs prohibitive labor efforts of collecting traffic on each node individually. To effectively deploy ML based attack traffic detection systems to protect distributed networks, we present tNeuron that automatically identifies FPs triggered by unseen traffic via neuron activation pattern analysis, such that it significantly improves the performance on various nodes. Specifically, we construct a shadow model with Transformer encoders to extract the knowledge of traffic patterns. Afterward, we train a model that learns how to classify FPs among alarms raised by ML models according to neuron activation patterns of the shadow model. Our experiments on real Ethereum nodes show that tNeuron can reduce 83.40% FP for seven state-of-the-art ML based attack detection systems, when detecting 15 kinds of P2P network attacks, thereby significantly improving detection accuracy in nine different metrics. In addition, tNeuron is robust against various adversarial examples constructed by existing evasion attacks. Besides, it achieves real-time detection and is capable of handling massive FPs generated by many nodes in large-scale distributed networks.
Songsong Xu, Chuanpu Fu, Qi Li 0002, Ke Xu 0002
IEEE Trans. Netw.4
2025 Off-Path TCP Hijacking Attack to NAT-Enabled Wi-Fi Networks
abstract
In this paper, we uncover a novel side-channel vulnerability arising from the shared NAT tables of Wi-Fi routers, enabling malicious insiders to hijack TCP connections between other clients and remote servers. First, by creating different NAT mappings within the shared NAT table, an off-path attacker can infer whether a victim client within the same Wi-Fi network is communicating with an external host over TCP, leveraging the widely adopted NAT port preservation strategy and insufficient reverse path validation in Wi-Fi routers. Once an active connection is detected, the attacker can manipulate the victim’s NAT mapping in the shared NAT table with spoofed TCP packets, exploiting the lack of TCP window tracking in most routers. In this way, the attacker can intercept TCP packets from the server and obtain the current sequence and acknowledgment numbers, which in turn allows the attacker to forcibly close the connection, poison the traffic in plain text, or reroute the server’s incoming packets to the attacker. We test 67 widely used routers from 30 vendors and discover that 52 of them are vulnerable. Also, we conduct an extensive measurement study on 93 real-world Wi-Fi networks and find that 75 of them (81%) are fully affected to our attack. Our case study shows that it takes about 17.5, 19.4, and 54.5 seconds on average to terminate SSH connections, download private files from FTP servers, and inject fake HTTP response packets with success rates of 87.4%, 82.6%, and 76.1%. Moreover, We evaluate the feasibility of the proposed attack in NAT-enabled IPv6 Wi-Fi networks. We responsibly disclose the vulnerability and suggest mitigation strategies to all affected vendors and have received positive feedback, including acknowledgments, CVEs, rewards, and adoption of our suggestions.
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002
IEEE Trans. Netw.7
2025 SmartUpdater: Enabling Transparent, Automated, and Secure Maintenance of Stateful Smart Contracts
abstract
Smart contracts in the Ethereum system are stored tamper-resistant, complicating necessary maintenance for offering new functionalities or fixing security vulnerabilities. Previous contract maintenance approaches mainly focus on logic modification using delegatecall-based patterns. While popular, they fail to handle data state updates (like storage layout changes), leading to impracticality and security risks in real-world applications. To address these challenges, this paper introduces SmartUpdater, a novel toolchain designed for transparent, automated, and secure maintenance of stateful smart contracts. SmartUpdater employs a hyperproxy-based contract maintenance pattern, where the hyperproxy serves as a constant entry and ensures that any state/logic modifications remain transparent to end users. SmartUpdater automates the maintenance process in terms of development streamlining, gas cost efficiency, and state migration verifiability. In extensive evaluations, we show that SmartUpdater can reduce gas consumption in contract maintenance compared with actual maintenance approaches. The evaluations point out the potential of SmartUpdater to significantly simplify the maintenance process for developers.
Xiaoli Zhang 0003, Yiqiao Song, Yuefeng Du 0001, Chengjun Cai, Hongbing Cheng, Ke Xu 0002, Qi Li 0002
IEEE Trans. Software Eng.6
2024 Adversarial Robust Safeguard for Evading Deep Facial Manipulation
abstract
The non-consensual exploitation of facial manipulation has emerged as a pressing societal concern. In tandem with the identification of such fake content, recent research endeavors have advocated countering manipulation techniques through proactive interventions, specifically the incorporation of adversarial noise to impede the manipulation in advance. Nevertheless, with insufficient consideration of robustness, we show that current methods falter in providing protection after simple perturbations, e.g., blur. In addition, traditional optimization-based methods face limitations in scalability as they struggle to accommodate the substantial expansion of data volume, a consequence of the time-intensive iterative pipeline. To solve these challenges, we propose a learning-based model, Adversarial Robust Safeguard (ARS), to generate desirable protection noise in a single forward process, concurrently exhibiting a heightened resistance against prevalent perturbations. Specifically, our method involves a two-way protection design, characterized by a basic protection component responsible for generating efficacious noise features, coupled with robust protection for further enhancement. In robust protection, we first fuse image features with spatially duplicated noise embedding, thereby accounting for inherent information redundancy. Subsequently, a combination comprising a differentiable perturbation module and an adversarial network is devised to simulate potential information degradation during the training process. To evaluate it, we conduct experiments on four manipulation methods and compare recent works comprehensively. The results of our method exhibit good visual effects with pronounced robustness against varied perturbations at different levels.
Jiazhi Guan, Yi Zhao 0011, Zhuoer Xu, Changhua Meng, Ke Xu 0002, Youjian Zhao
AAAI5
2024 BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low Energy
abstract
Bluetooth Low Energy (BLE) is a short-range wireless communication technology for resource-constrained IoT devices. Unfortunately, BLE is vulnerable to session-based attacks, where previous packets construct exploitable conditions for subsequent packets to compromise connections. Defending against session-based attacks is challenging because each step in the attack sequence is legitimate when inspected individually. In this paper, we present BlueSWAT, a lightweight state-aware security framework for protecting BLE devices. To perform inspection on the session level rather than individual packets, BlueSWAT leverages a finite state machine (FSM) to monitor sequential actions of connections at runtime. Patterns of session-based attacks are modeled as malicious transition paths in the FSM. To overcome the heterogeneous IoT environment, we develop a lightweight eBPF framework to facilitate universal patch distribution across different BLE architectures and stacks, without requiring device reboot. We implement BlueSWAT on 5 real-world devices with different chips and stacks to demonstrate its cross-device adaptability. On our dataset with 101 real-world BLE vulnerabilities, BlueSWAT can mitigate 76.1% of session-based attacks, outperforming other defense frameworks. In our end-to-end application evaluation, BlueSWAT introduces an average of 0.073% memory overhead and negligible latency.
Xijia Che, Yi He 0020, Xuewei Feng, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
CCS5
2024 Robust and Reliable Early-Stage Website Fingerprinting Attacks via Spatial-Temporal Distribution Analysis
abstract
Website Fingerprinting (WF) attacks identify the websites visited by users by performing traffic analysis, compromising user privacy. Particularly, DL-based WF attacks demonstrate impressive attack performance. However, the effectiveness of DL-based WF attacks relies on the collected complete and pure traffic during the page loading, which impacts the practicality of these attacks. The WF performance is rather low under dynamic network conditions and various WF defenses, particularly when the analyzed traffic is only a small part of the complete traffic. In this paper, we propose Holmes, a robust and reliable early-stage WF attack. Holmes utilizes temporal and spatial distribution analysis of website traffic to effectively identify websites in the early stages of page loading. Specifically, Holmes develops adaptive data augmentation based on the temporal distribution of website traffic and utilizes a supervised contrastive learning method to extract the correlations between the early-stage traffic and the pre-collected complete traffic. Holmes accurately identifies traffic in the early stages of page loading by computing the correlation of the traffic with the spatial distribution information, which ensures robust and reliable detection according to early-stage traffic. We extensively evaluate Holmes using six datasets. Compared to nine existing DL-based WF attacks, Holmes improves the F1-score of identifying early-stage traffic by an average of 169.18%. Furthermore, we replay the traffic of visiting real-world dark web websites. Holmes successfully identifies dark web websites when the ratio of page loading on average is only 21.71%, with an average precision improvement of 169.36% over the existing WF attacks.
Xinhao Deng 0001, Qi Li 0002, Ke Xu 0002
CCS3
2024 Detecting Tunneled Flooding Traffic via Deep Semantic Analysis of Packet Length Patterns
abstract
Distributed denial-of-service (DDoS) protection services capture various flooding attacks by analyzing traffic features. However, existing services are unable to accurately detect tunneled attack traffic because the tunneling protocols encrypt both packet headers and payloads, which hide the traffic features used for detection, and can thus evade these detection services. In this paper, we develop Exosphere, which detects tunneled attack traffic by analyzing packet length patterns, without investigating any information in packets. Specifically, it utilizes a deep learning based method to analyze the semantics of packet patterns, i.e., the features represent the strong correlations between flooding packets with similar length patterns, and classify attack traffic according to these semantic features. We prove that the strong correlations of packet length patterns ensure the theoretical guarantee of applying semantic analysis to recognize correlated attack packets. We prototype Exosphere with FPGAs and deploy it in a real-world institutional network. The experimental results demonstrate that Exosphere achieves 0.967 F1 accuracy, while detecting flooding traffic generated by unseen attacks and misconfigurations. Moreover, it achieves 0.996 AUC accuracy on existing datasets including various stealthy attacks, and thus significantly outperforms the existing deep learning models. It achieves accuracy comparable to the best performances achieved by 12 state-of-the-art methods that cannot detect tunneled flooding traffic, while improving their efficiency by 6.19 times.
Chuanpu Fu, Qi Li 0002, Meng Shen 0001, Ke Xu 0002
CCS4
2024 Towards Fine-Grained Webpage Fingerprinting at Scale
abstract
Website Fingerprinting (WF) attacks can effectively identify the websites visited by Tor clients via analyzing encrypted traffic patterns. Existing attacks focus on identifying different websites, but their accuracy dramatically decreases when applied to identify fine-grained webpages, especially when distinguishing among different subpages of the same website. WebPage Fingerprinting (WPF) attacks face the challenges of highly similar traffic patterns and a much larger scale of webpages. Furthermore, clients often visit multiple webpages concurrently, increasing the difficulty of extracting the traffic patterns of each webpage from the obfuscated traffic. In this paper, we propose Oscar, a WPF attack based on multi-label metric learning that identifies different webpages from obfuscated traffic by transforming the feature space. Oscar can extract the subtle differences among various webpages, even those with similar traffic patterns. In particular, Oscar combines proxy-based and sample-based metric learning losses to extract webpage features from obfuscated traffic and identify multiple webpages. We prototype Oscar and evaluate its performance using traffic collected from 1,000 monitored webpages and over 9,000 unmonitored webpages in the real world. Oscar demonstrates an 88.6% improvement in the multi-label metric Recall@5 compared to the state-of-the-art attacks.
Xinhao Deng 0001, Qi Li 0002, Zhuotao Liu, Kun Sun 0001, Ke Xu 0002
CCS7
2024 CoGNN: Towards Secure and Efficient Collaborative Graph Learning
abstract
Collaborative graph learning represents a learning paradigm where multiple parties jointly train a graph neural network (GNN) using their own proprietary graph data. To honor the data privacy of all parties, existing solutions for collaborative graph learning are either based on federated learning (FL) or secure machine learning (SML). Although promising in terms of efficiency and scalability due to their distributed training scheme, FL-based approaches fall short in providing provable security guarantees and achieving good model performance. Conversely, SML-based solutions, while offering provable privacy guarantees, are hindered by their high computational and communication overhead, as well as poor scalability as more parties participate.
Zhenhua Zou, Zhuotao Liu, Jinyong Shan, Qi Li 0002, Ke Xu 0002, Mingwei Xu 0001
CCS5
2024 Walking in Others' Shoes: How Perspective-Taking Guides Large Language Models in Reducing Toxicity and Bias
abstract
The common toxicity and societal bias in contents generated by large language models (LLMs) necessitate strategies to reduce harm.Present solutions often demand whitebox access to the model or substantial training, which is impractical for cutting-edge commercial LLMs.Moreover, prevailing prompting methods depend on external tool feedback and fail to simultaneously lessen toxicity and bias.Motivated by social psychology principles, we propose a novel strategy named perspective-taking prompting (PET) that inspires LLMs to integrate diverse human perspectives and self-regulate their responses.This self-correction mechanism can significantly diminish toxicity (up to 89%) and bias (up to 73%) in LLMs' responses.Rigorous evaluations and ablation studies are conducted on two commercial LLMs (ChatGPT and GLM) and three open-source LLMs, revealing PET's superiority in producing less harmful responses, outperforming five strong baselines."Words kill, words give life; they're either poison or fruit-you choose."~Proverbs 18:21 (MSG)
Rongwu Xu, Zi'an Zhou, Tianwei Zhang 0004, Zehan Qi, Su Yao, Ke Xu 0002, Wei Xu 0039, Han Qiu 0001
EMNLP6
2024 Reducing First-Frame Delay of Live Streaming by Simultaneously Initializing Window and Rate
abstract
The first-frame delay is an essential indicator for evaluating the performance of cloud CDN vendors and affects the client-side QoE of live streaming. Instead of the traditional way of tuning the initial congestion window (cwnd) for all connections to a fixed value based on expert experience, this paper explores the using of transport signals unique to each connection (e.g., application-layer framing, historical QoS metrics) to initialize the sending parameters for each connection. Thus we propose Wira, a first-frame optimization mechanism that adjusts both initial cwnd and initial rate, which are two key parameters for decreasing the first-frame completion time (FFCT). Particularly, Wira provides cross-layer Frame Perception that parses frames and adapts the initial cwnd to the first-frame size. Meanwhile, Wira introduces the Transport Cookie to enable cloud-client collaborations, in which the historical QoS metrics from the clients can be reported and reused by rate initialization in the stateless cloud. This assures the initial rate matches the actual network conditions while avoiding non-trivial storage overhead in the cloud. We implement Wira upon QUIC and evaluate it via real-world deployments of commercial services. Results demonstrate the profitability of Wira, in which the average and 90th-percentile FFCT are reduced by 10.6% and 16.7%, respectively.
Bo Wu 0002, Tong Li 0014, Fuyu Wang 0006, Changkui Ouyang, Linfeng Guo, Ke Xu 0002
ICDCS9
2024 Performant TCP over Wi-Fi Direct
abstract
Wi-Fi Direct has been serving a progressively wide range of applications such as device-to-device file sharing, face-to-face interactive gaming, and wireless projection. However, when TCP meets Wi-Fi Direct, we find that two independent control loops exist, i.e., the transport-layer control loop and the link-layer control loop. First, these functionally redundant loops result in spectrum inefficiency. Second, the lack of effective information interaction between layers results in local optimal. To tackle these issues, this paper proposes Wi-Fi Direct TCP (WDTCP), a performant TCP that provides a full protocol design of the acknowledgment de-redundancy and explicit-capacity-based congestion control. WDTCP tightly couples the two control loops by capturing the WiFi Direct’s key feature of one-hop communication. Evaluation results demonstrate that WDTCP can maximize bandwidth utilization while keeping low latency. For instance, compared to legacy TCP, WDTCP improves throughput by up to 49.2% and reduces average and 95th latency by up to 32.4% and 50.7%, respectively.
Hanlin Huang, Ke Xu 0002, Xinle Du, Yiyang Shao, Tong Li 0014
IWQoS2
2024 ReND: Toward Reasoning-based BLE Neighbor Discovery by Integrating with Wi-Fi Fingerprints
abstract
This paper proposes the novel concept of reasoning-based Bluetooth Low-Energy (BLE) neighbor discovery, an indirect paradigm of device-to-device sensing to address challenges (e.g., interference and power limitations) where direct sensing falls short. Inspired by the classical Rule of Syllogism, reasoning-based BLE neighbor discovery abstracts the device-to-device sensing as the presence detection of a BLE signal in a certain space. It deduces the presence of the BLE signal according to the presence of the Wi-Fi signal through the historical correlation between BLE and Wi-Fi. To demonstrate the feasibility of this new neighbor discovery paradigm, we report the design and evaluation of a prototype called ReND. By leveraging the complementary strengths of Wi-Fi and BLE, ReND reduces up to 91.3% and 65.9% of the 50thand 95thpercentile BLE neighbor discovery latency, respectively. We further discuss the feasibility and incentive of ReND in the Polygon’s Mumbai Testnet public blockchain.
Zhaoqi Yang, Tong Li 0014, Bo Wu 0002, Yukuan Ding, Dulin Xu, Ke Xu 0002
IWQoS8
2024 A Horizontal Study on the Mixed IPID Assignment Vulnerability in the Linux Ecosystem
abstract
The off-path TCP hijacking attack poses a significant threat to Internet security, allowing attackers to manipulate various upper-layer applications and causing severe real-world damage. In this paper, we undertake a horizontal study on a critical TCP hijacking attack affecting Linux servers, which was reported in November 2020 (CVE-2020-36516). This attack has the potential to compromise over 20% of popular websites on the Internet. Our study particularly focuses on determining the extent to which the developed stack patches, designed to address this vulnerability, have been effectively deployed in the real world and whether they have successfully mitigated the identified attack. In our horizontal study, we thoroughly examine the current status of the vulnerability, covering upstream and downstream components of the Linux ecosystem. This study encompasses 12 mainstream Linux distributions, 296 images from 7 leading cloud vendors, 2.92 million IPs from 301 network segments belonging to 6 major CDN vendors, as well as the top 1 million websites from 3 datasets. Our study unveils a notable disparity in the patching of the vulnerability in the Linux ecosystem, spanning various ISPs and vendors, which leaves the vulnerability open to potential exploitation and poses a serious threat to the Internet.
Xuewei Feng, Qi Li 0002, Ke Xu 0002
IWQoS5
2024 Enhancing Fraud Transaction Detection via Unlabeled Suspicious Records
abstract
Deep learning-based classifiers have been widely used in the field of financial fraud transaction detection. However, training a high-performance classifier for fraud detection is challenging due to the lack of sufficient labeled fraud data. Particularly, it is difficult to detect stealthy fraud transactions that closely mimic benign user behaviors. We observe that the suspicious transactions identified by the online detection system can augment the feature space to improve the detection performance of machine learning-based models. In this paper, we propose a new framework GIANTESS to leverage suspicious transactions to augment the feature space and thus enhance the detection of stealthy fraud transactions. Our semi-supervised approach combines both labeled transactions and unlabeled suspicious transactions to train a detection model. Specifically, it first estimates pseudo labels of suspicious transactions and then combines the pseudo labels with ground truth labels to train the detection model. We conduct experiments on two real-world datasets to demonstrate the effectiveness of our proposed method on detecting stealthy fraud transactions. The experimental results show that GIANTESS successfully improves the recall by up to 6.3% at the fixed low false positive rate of 1%. We also perform a 9-week deployment test of our system in a real-world online payment platform to demonstrate the performance of GIANTESS.
Ye Wang 0002, Ningtao Wang, Weiqiang Wang 0002, Kun Sun 0001, Qi Li 0002, Ke Xu 0002
IWQoS10
2024 Rethinking and Optimizing Workload Redistribution in Large-scale Internet Data Centers
abstract
Heuristic-based workload redistribution is the most commonly adopted solution to provide enhanced service performance in large-scale Internet Data Centers (IDCs). However, statistics show that they cannot perform as well as expected in real-world IDCs. In this paper, we rethink existing solutions based on real-world trace data and pinpoint two major pitfalls: (i) Sensitive to hand-tuning parameters; (ii) Reassigning only a few workloads locally at a time. The two of them jointly limit the universal applicability of existing solutions in optimizing multiple objectives fairly. To address such issues, we propose the matching-theory-based solution for workload redistribution, namely Themis. It is an efficient and universal solution for large-scale IDCs, which can avoid empirical parameters in optimization and reassign several workloads globally each time. Moreover, the newly proposed Themis can optimize multiple objectives (e.g., resource utilization balancing and communication efficiency improving) simultaneously and fairly. In addition to its own performance advantages, our proposed Themis is also compatible with existing methods, thus adapting to a wider range of deployment scenarios. Extensive evaluations based on the trace data from two real-world IDCs demonstrate that our proposed Themis outperforms multiple comparison solutions, as well as the compatibility of parameter changes (i.e., stability properties in terms of parameter configuration).
Yi Zhao 0011, Yusen Li, Meng Shen 0001, Liehuang Zhu, Ke Xu 0002
IWQoS6
2024 Toward Timeliness-Enhanced Loss Recovery for Large-Scale Live Streaming
abstract
Due to the limited permissions for upgrading dual-side (i.e., server-side and client-side) loss tolerance schemes from the perspective of CDN vendors in a multi-supplier market, modern large-scale live streaming services are still using the automatic-repeat-request (ARQ) based paradigm for loss recovery, which only requires server-side modifications. In this paper, we first conduct a large-scale measurement study with up to 50 million live streams. We find that loss shows dynamics and live streaming contains frequent on-off mode switching in the wild. We further find that the recovery latency, enlarged by the ubiquitous retransmission loss, is a critical factor affecting live streaming's client side QoE (e.g., video freezing). We then propose an enhanced recovery mechanism called AutoRec, which can transform the disadvantages of on-off mode switching into an advantage for reducing loss recovery latency without any modifications on the client side. AutoRec also adopts an online learning-based policy to fit the dynamics of loss, balancing the tradeoff between the recovery latency and the incurred overhead. We implement AutoRec upon QUIC and evaluate it via both testbed and real-world commercial services deployments. The experimental results demonstrate the practicability and profitability of AutoRec, in which the average times and duration of client-side video freezing can be lowered by 11.4% and 5.2%, respectively.
Bo Wu 0002, Tong Li 0014, Fuyu Wang 0006, Xinle Du, Ke Xu 0002
ACM Multimedia7
2024 Pencil: Private and Extensible Collaborative Learning without the Non-Colluding Assumption
Xuanqi Liu, Zhuotao Liu, Qi Li 0002, Ke Xu 0002, Mingwei Xu 0001
NDSS4
2024 Low-Quality Training Data Only? A Robust Framework for Detecting Encrypted Malicious Network Traffic
Yuqi Qing, Qilei Yin, Xinhao Deng 0001, Zhuotao Liu, Kun Sun 0001, Ke Xu 0002, Jia Zhang 0004, Qi Li 0002
NDSS7
2024 From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT Devices
Yi He 0020, Xiaoli Zhang 0003, Qian Wang 0002, Renjie Xie, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
NDSS7
2024 Exploiting Sequence Number Leakage: TCP Hijacking in NAT-Enabled Wi-Fi Networks
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002
NDSS6
2024 Brain-on-Switch: Towards Advanced Intelligent Network Data Plane via NN-Driven Traffic Analysis at Line-Speed
Jinzhu Yan, Zhuotao Liu, Qi Li 0002, Ke Xu 0002, Mingwei Xu 0001
NSDI5
2024 Real-Time Website Fingerprinting Defense via Traffic Cluster Anonymization
abstract
Website Fingerprinting (WF) attacks significantly threaten user privacy in anonymity networks such as Tor. While numerous defenses have been proposed, they are unable to efficiently defend against recent deep learning based WF attacks. In this paper, we propose Palette, a novel and practical WF defense that utilizes traffic cluster anonymization to protect live Tor traffic. By clustering websites with high similarity in traffic patterns and regulating them into a well-designed uniform pattern for a cluster (i.e., a group of similar websites), Palette prevents attackers from distinguishing between these similar websites within the cluster and further provides a strong anonymity guarantee. Comprehensive evaluations with public real-world datasets show that Palette is superior to the existing defenses, greatly reducing the accuracy of the state-of-the-art (SOTA) WF attacks with acceptable overheads. Furthermore, we implement Palette as a Pluggable Transport in the Tor network. The experiment results demonstrate that, on average, Palette effectively reduces the accuracy of the SOTA WF attacks by 73.60%, which improves the existing defenses by 33.50%-43.47%.
Meng Shen 0001, Kexin Ji, Jinhe Wu, Qi Li 0002, Ke Xu 0002, Liehuang Zhu
SP6
2024 Transferability of White-box Perturbations: Query-Efficient Adversarial Attacks against Commercial DNN Services
Meng Shen 0001, Changyue Li, Qi Li 0002, Liehuang Zhu, Ke Xu 0002
USENIX Security Symposium6
2024 Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection System
Qilei Yin, Qi Li 0002, Zhuotao Liu, Ke Xu 0002, Mingwei Xu 0001
USENIX Security Symposium5
2024 Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory Approach
Qi Tan 0003, Qi Li 0002, Yi Zhao 0011, Zhuotao Liu, Xiaobing Guo, Ke Xu 0002
USENIX Security Symposium6
2024 Seeking in Ride-on-Demand Service: A Reinforcement Learning Model With Dynamic Price Prediction
abstract
Recent years witness the increasing popularity of ride-on-demand (RoD) services such as Uber and Didi. Compared with traditional taxi, RoD service is more “data-driven” and adopts dynamic pricing to manipulate the supply and demand in real time. Dynamic price could be viewed as an accurate and quantitative indicator of the supply and demand, and could provide clues to drivers, passengers, and the service providers, possibly reshaping the ways in which some problems are solved. In this paper, we focus on the seeking route recommendation problem that aims at increasing driver revenue by recommending highly profitable seeking routes to drivers of vacant cars with the help of dynamic prices. We first justify our motivation by showing the importance of route recommendation and answering why it is necessary to consider dynamic prices, based on the analysis of real service data. We then design a dynamic price prediction model to generate the dynamic prices at any given time and location based on multi-source urban data. After that, a reinforcement learning model is adopted to perform seeking route recommendation based on predicted dynamic prices. We conduct extensive experiments in different spatio-temporal combinations and make comparisons with multiple baselines. Results first show that our dynamic price prediction model achieves an accuracy ranging from 83.82% to 90.67% under different settings. It also proves that considering the real-time predicted dynamic prices significantly increases driver revenue by, for example, 12% and 47.5% during weekday evening rush hours, than merely using the average prices or completely ignoring dynamic prices.
Suiming Guo, Baoying Deng, Chao Chen 0004, Jintao Ke, Jingyuan Wang 0001, Saiqin Long, Ke Xu 0002
IEEE Internet Things J.7
2024 Robust NOMA-Assisted OTFS-ISAC Network Design With 3-D Motion Prediction Topology
abstract
This paper proposes a novel non-orthogonal multiple access (NOMA)-assisted orthogonal time-frequency space (OTFS)-integrated sensing and communication (ISAC) network, which uses unmanned aerial vehicles (UAVs) as air base stations to support multiple users. By employing ISAC, the UAV extracts position and velocity information from the user’s echo signals, and non-orthogonal power allocation is conducted to achieve a superior achievable rate. A 3D motion prediction topology is used to guide the NOMA transmission for multiple users, and a robust power allocation solution is proposed under perfect and imperfect channel estimation for max-min fairness (MMF) and maximum sum-rate (SR) problems. Simulation results demonstrate the superiority of the proposed NOMA-assisted OTFS-ISAC system over other systems in terms of achievable rate under both perfect and imperfect channel conditions with the aid of 3D motion prediction topology.
Luping Xiang, Ke Xu 0002, Jie Hu 0001, Christos Masouros, Kun Yang 0001
IEEE Internet Things J.2
2024 Galaxy: A Scalable BFT and Privacy-Preserving Pub/Sub IoT Data Sharing Framework Based on Blockchain
abstract
The emergence of the Internet of Things (IoT) technology in recent years has led to a considerable amount of data to be shared across different organizations. The publish and subscribe (Pub/Sub) paradigm, with its asynchronous, one-to-many, and decoupling characteristics, is considered to be a promising communication model in IoT. However, designing a Pub/Sub framework for IoT data sharing confronts two challenges: 1) Byzantine faults and 2) privacy concerns. Byzantine nodes that are subjectively malicious or hacked by attackers may discard or forge data in the broker network composed of untrusted IoT organizations. Unauthorized brokers or clients may try to obtain the content of publications or subscriptions, thus violating the IoT data privacy. Existing works have limitations in terms of relatively low scalability and high overhead in tackling these two challenges. In this article, we propose Galaxy, a blockchain-based Pub/Sub IoT data sharing framework. To achieve Byzantine fault-tolerant (BFT) Pub/Sub, Galaxy adopts sharding to improve scalability and achieve efficient BFT Pub/Sub workflow within each shard with a novel leader rotation scheme. In attaining privacy-preserving Pub/Sub, a secret key sharing and encrypted Pub/Sub scheme is designed in Galaxy to achieve low overhead without breaking the decoupling of the system. We implemented a prototype of Galaxy and deployed it on Alibaba Cloud for experimental evaluation. The experiment results show the feasibility and efficiency of Galaxy.
Yuchao Zhang 0004, Ning Zhang 0007, Zibin Zheng, Ke Xu 0002
IEEE Internet Things J.6
2024 FLAIR: A Fast and Low-Redundancy Failure Recovery Framework for Inter Data Center Network
abstract
Due to the fast developments of 5G and IoT technologies, Inter-Datacenter (Inter-DC) networks are facing unprecedented pressure to duplicate large volumes of geographically distributed user data in a real-time manner. Meanwhile, with the expansion of Inter-DC networks scale, link/node failures also become increasingly frequent, negatively affecting the data transmission efficiency. Therefore, link failure recovery methods become of utmost importance. Many works investigated fast failure recovery, yet none of them consider the deployment overhead of such recovery schemes. While in this paper, we found that the side-effect of deploying recovery strategies and the future availability of the recovered transmissions are also crucial for fast recovery. So we propose a fast and low-redundancy failure recovery framework, FLAIR, which consists of a fast recovery strategy FRAVaR and a redundancy removal algorithm ROSE. FRAVaR takes full consideration of deployment overhead by minimizing shuffle traffic. On its base, ROSE regularly eliminates the cumulative rerouting redundancy by removing unnecessary routing updates. The experiment results on 4 realistic network topologies show that FLAIR successfully reduces up to 48.2% deployment overhead compared with the state-of-the-art solutions, and thus reduces up to 70.2% recovery speed and improves up to 36% network utilization.
Yuchao Zhang 0004, Haoqiang Huang, Ahmed M. Abdelmoniem, Gaoxiong Zeng, Chenyue Zheng, Xirong Que, Wendong Wang 0003, Ke Xu 0002
IEEE Trans. Cloud Comput.8
2024 Decision-Based Query Efficient Adversarial Attack via Adaptive Boundary Learning
abstract
Decision-based adversarial attacks pose a severe threat to real-world applications of Deep Neural Networks (DNNs), as attackers are assumed to have no prior knowledge about target model except hard labels of model outputs. Existing decision-based attacks require a large number of queries on the target model for a successful attack. In this paper, we propose DEAL, a decision-based query efficient adversarial attack based on adaptive boundary learning. DEAL relies on a local model named boundary learner, which is initialized through meta-learning mechanism to obtain the ability to adapt the decision boundaries to a new model. We conduct extensive experiments to evaluate the effectiveness of DEAL, which demonstrates that it outperforms 8 state-of-the-art attacks. Specifically for the evaluation on CIFAR-10 dataset, DEAL can achieve similar attack success rates with a maximum reduction in average number of queries of 51% in untargeted attacks and 14% in targeted attacks, respectively.
Meng Shen 0001, Changyue Li, Hao Yu 0017, Qi Li 0002, Liehuang Zhu, Ke Xu 0002
IEEE Trans. Dependable Secur. Comput.6
2024 Multi-Scale Attention Flow for Probabilistic Time Series Forecasting
abstract
The probability prediction of multivariate time series is a notoriously challenging but practical task. On the one hand, the challenge is how to effectively capture the cross-series correlations between interacting time series, to achieve accurate distribution modeling. On the other hand, we should consider how to capture the contextual information within time series more accurately to model multivariate temporal dynamics of time series. In this work, we proposed a novel non-autoregressive deep learning model, called Multi-scale Attention Normalizing Flow(MANF), where we combine multi-scale attention with relative position information and the multivariate data distribution is represented by the conditioned normalizing flow. Additionally, compared with autoregressive modeling methods, our model avoids the influence of cumulative error and does not increase the time complexity. Extensive experiments demonstrate that our model achieves state-of-the-art performance on many popular multivariate datasets.
Shibo Feng, Chunyan Miao, Ke Xu 0002, Jiaxiang Wu 0001, Yang Zhang 0075, Peilin Zhao
IEEE Trans. Knowl. Data Eng.3
2024 Privacy Leakage From Dynamic Prices: Trip Purpose Mining as an Example
abstract
Dynamic prices are used in many scenarios, e.g., flight ticketing, hotel room booking and ride-on-demand (RoD) service such as Uber and DiDi, and while they are beneficial for service providers, practitioners or users, they lead to the concern of privacy leakage – the possibility of learning user information from dynamic prices. In this paper, we aim to study this possibility and choose trip purpose mining in RoD service as an attack example, based on real-world large datasets. We discuss the criteria of choosing datasets – ubiquitous, collective and easily accessible – from the perspective of an attacker, and extract features describing trip information, spatio-temporal and dynamic prices context. The trip purpose mining problem is then solved as a multi-class classification problem and multiple binary-class problems. In the multi-class problem, we verify that dynamic prices information results in a 17.1% improvement in classification accuracy; in the binary-class problems, we quantify feature contributions and explain the different extents of privacy leakage in identifying different trip purposes. Our hope is that the study not only serves as a case study demonstrating the privacy leakage problem in RoD service, but also sheds light on such privacy problem in other services using dynamic prices and triggers more research efforts.
Suiming Guo, Chao Chen 0004, Zhetao Li, Chengwu Liao, Yaxiao Liu, Ke Xu 0002, Daqing Zhang 0001
IEEE Trans. Mob. Comput.6
2024 FedCache: A Knowledge Cache-Driven Federated Learning Architecture for Personalized Edge Intelligence
abstract
Edge Intelligence (EI) allows Artificial Intelligence (AI) applications to run at the edge, where data analysis and decision-making can be performed in real-time and close to data sources. To protect data privacy and unify data silos distributed among end devices in EI, Federated Learning (FL) is proposed for collaborative training of shared AI models across multiple devices without compromising data privacy. However, the prevailing FL approaches cannot guarantee model generalization and adaptation on heterogeneous clients. Recently, Personalized Federated Learning (PFL) has drawn growing awareness in EI, as it enables a productive balance between local-specific training requirements inherent in devices and global-generalized optimization objectives for satisfactory performance. However, most existing PFL methods are based on the Parameters Interaction-based Architecture (PIA) represented by FedAvg, which suffers from unaffordable communication burdens due to large-scale parameters transmission between devices and the edge server. In contrast, Logits Interaction-based Architecture (LIA) allows to update model parameters with logits transfer and gains the advantages of communication lightweight and heterogeneous on-device model allowance compared to PIA. Nevertheless, previous LIA methods attempt to achieve satisfactory performance either relying on unrealistic public datasets or increasing communication overhead for additional information transmission other than logits. To tackle this dilemma, we propose a knowledge cache-driven PFL architecture, named FedCache, which reserves a knowledge cache on the server for fetching personalized knowledge from the samples with similar hashes to each given on-device sample. During the training phase, ensemble distillation is applied to on-device models for constructive optimization with personalized knowledge transferred from the server-side knowledge cache. Empirical experiments on four datasets demonstrate that FedCache achieves comparable performance with state-of-art PFL approaches, with more than two orders of magnitude improvements in communication efficiency. Our code and DEMO are available athttps://github.com/wuzhiyuan2000/FedCache.
Yuwei Wang 0003, Min Liu 0001, Ke Xu 0002, Xuefeng Jiang 0001, Bo Gao 0006, Jinda Lu
IEEE Trans. Mob. Comput.5
2024 Flow Interaction Graph Analysis: Unknown Encrypted Malicious Traffic Detection
abstract
Nowadays traffic on the Internet has been widely encrypted to protect its confidentiality and privacy. However, traffic encryption is always abused by attackers to conceal their malicious behaviors. Since encrypted malicious traffic is similar to benign flows, it can easily evade traditional detection. In particular, the existing encrypted traffic detection methods are supervised which rely on the prior knowledge of known attacks (e.g., labeled datasets). Detecting unknown encrypted malicious traffic, which does not require prior knowledge, is still an open problem. In this paper, we propose, an unsupervised machine learning (ML) based malicious traffic detection system. Particularly, is able to detect unknown patterns of encrypted malicious traffic by utilizing a graph built upon flow interaction patterns, instead of learning the features of specific known attacks. We develop an unsupervised graph learning method to detect abnormal interaction patterns by analyzing the graph features, which allows to detect unknown attacks without requiring any labeled datasets. Moreover, we establish an information theory model to prove the effectiveness of . We show the performance of by real-world experiments with 140 attacks. The experimental results illustrate that outperforms the state-of-the-art methods by 13.9% accuracy improvement. Moreover, achieves 15.82 Mpps detection throughput with the average detection latency of 0.29s.
Chuanpu Fu, Qi Li 0002, Ke Xu 0002
IEEE/ACM Trans. Netw.3
2024 Re-Architecting Buffer Management in Lossless Ethernet
abstract
Converged Ethernet employs Priority-based Flow Control (PFC) to provide a lossless network. However, issues caused by PFC, including victim flow, congestion spreading, and deadlock, impede its large-scale deployment in production systems. The fine-grained experimental observations on switch buffer occupancy find that the root cause of these performance problems is a mismatch of sending rates between end-to-end congestion control and hop-by-hop flow control. Resolving this mismatch requires the switch to provide an additional buffer, which is not supported by the classic dynamic threshold (DT) policy in current shared-buffer commercial switches. In this paper, we propose Selective-PFC (SPFC), a practical buffer management scheme that handles such mismatch. Specifically, SPFC incrementally modifies DT by proactively detecting port traffic and adjusting buffer allocation accordingly to trigger PFC PAUSE frames selectively. Extensive case studies demonstrate that SPFC can reduce the number of PFC PAUSEs on non-bursty ports by up to 69.0%, and reduce the average flow completion time by up to 83.5% for large victim flows.
Hanlin Huang, Xinle Du, Tong Li 0014, Ke Xu 0002, Mowei Wang, Huichen Dai
IEEE/ACM Trans. Netw.5
2024 Stable Byzantine Fault Tolerance in Wide Area Networks With Unreliable Links
abstract
With the increasing demand for blockchain technology in various industry sectors, there has been a growing interest in the Byzantine Fault Tolerance (BFT) consensus that is the backbone of most of these blockchains. However, many state-of-the-art algorithms that require reliable connections can only offer limited throughput in wide-area networks (WANs), where participants are connected over long distances and may experience unpredictable network failures. The partially-connected BFTs are designed for unreliable and highly dynamic networks yet impose exponential communication complexity. This paper proposes Stable Byzantine Fault Tolerance (SBFT), a BFT communication abstraction that can sustain high throughput and low latency in WAN. SBFT separates the leader from consensus in pipelined BFT consensus and uses an adaptive consensus mechanism to resist dynamic faulty links, maintaining consensus efficiency when network connectivity is high while adapting to dynamic networks with low connectivity. We implemented a prototype of SBFT and tested it on the WAN. The results demonstrate that SBFT has a throughput similar to HotStuff in a fault-free environment but can reduce about 80% of consensus latency. Besides, SBFT retains 40% of the original throughput when the link failure probability is 0.4, while the baseline HotStuff retains less than 40% when the link failure probability is only 0.1.
Sitong Ling, Zhuotao Liu, Qi Li 0002, Xinle Du, Ke Xu 0002
IEEE/ACM Trans. Netw.6
2024 Toward Practical Inter-Domain Source Address Validation
abstract
The Internet Protocol (IP) is the most fundamental building block of the Internet. However, it provides no explicit notion of packet-level authenticity. Such a weakness allows malicious actors to spoof IP packet headers and launch a wide variety of attacks. Meanwhile, the highly decentralized management of Internet infrastructure makes large-scale source address validation challenging in terms of overhead, validity, and flexibility. This paper presents a practical anti-spoofing approach, Source Address Validation Architecture eXternal (SAVA-X). SAVA-X introduces the concept of Address Domain to enable address validation in finer, prefix-level granularity. The address domains are organized in nested hierarchies to provide higher scalability and lower maintenance costs for partial deployment. We implement SAVA-X on commercial backbone routers and the P4 platform. The experiments indicate that the hardware implementation of SAVA-X can achieve 98% throughput on 100 Gbps links and close to the native IP forwarding in per-packet overhead, with less than 10 microseconds additional processing latency.
Xiaoliang Wang 0004, Ke Xu 0002, Yangfei Guo, Songtao Fu, Qi Li 0002
IEEE/ACM Trans. Netw.2
2024 Privacy-Preserving and Lightweight Verification of Deep Packet Inspection in Clouds
abstract
In the trend of network middleboxes as a service, enterprise customers adopt in-the-cloud deep packet inspection (DPI) services to protect networks. As network misconfigurations and hardware failures notoriously exist, recent efforts envision to ensure the execution integrity of DPI services in untrusted clouds. However, they either require enterprise customers to know proprietary DPI rulesets of cloud providers or introduce forbidden overhead in the network context. In the paper, we propose a privacy-preserving and lightweight verification scheme that efficiently checks whether in-the-cloud DPI services run correctly without leaking private DPI rulesets. Particularly, our design introduces one trusted third party to perform privacy-preserving and trustworthy ruleset evaluation and DPI execution verification. Meanwhile, it devises a novel DPI ruleset authentication method that enables tamper-proof DPI operations and facilitates fast proof generation. The proofs can be verified without requiring the verifier to always maintain all rulesets. To further reduce the verification costs while resisting cloud cheating behaviors like bias treatments of packets, it employs a commitment-based delayed sampling mechanism which requires the DPI services to first demonstrate that all packets have been processed before receiving sampling decisions. Moreover, extensive experiments are conducted based on Click modules. The results show that the proposed scheme is practical and only incurs the real-time overhead of 10–20 microseconds.
Xiaoli Zhang 0003, Yiqiao Song, Hongbing Cheng, Ke Xu 0002, Qi Li 0002
IEEE/ACM Trans. Netw.5
2024 FedPAGE: Pruning Adaptively Toward Global Efficiency of Heterogeneous Federated Learning
abstract
When workers are heterogeneous in computing and transmission capabilities, the global efficiency of federated learning suffers from the straggler issue, i.e., the slowest worker drags down the overall training process. We propose a novel and efficient federated learning framework named FedPAGE, where workers perform distributed pruning adaptively towards global efficiency, i.e., fast training and high accuracy. For fast training, we develop a pruning rate learning approach generating an adaptive pruning rate for each worker, making the overall update time approximate to the fastest worker’s update time, i.e., no stragglers. For high accuracy, we find that structural similarity between sub-models is essential to global model accuracy in the distributed pruning, and thus propose the CIG_X pruning scheme to ensure maximum similarity. Meanwhile, we adopt the sparse training and design model aggregating of different size sub-models to cope with distributed pruning. We prove the convergence of FedPAGE and demonstrate the effectiveness of FedPAGE on image classification and natural language inference tasks. Compared with the state-of-the-art, FedPAGE achieves higher accuracy with the same speedup ratio.
Guangmeng Zhou, Qi Li 0002, Yang Liu 0038, Yi Zhao 0011, Qi Tan 0003, Su Yao, Ke Xu 0002
IEEE/ACM Trans. Netw.7
2023 Differentially Private Learning with Per-Sample Adaptive Clipping
abstract
Privacy in AI remains a topic that draws attention from researchers and the general public in recent years. As one way to implement privacy-preserving AI, differentially private learning is a framework that enables AI models to use differential privacy (DP). To achieve DP in the learning process, existing algorithms typically limit the magnitude of gradients with a constant clipping, which requires carefully tuned due to its significant impact on model performance. As a solution to this issue, latest works NSGD and Auto-S innovatively propose to use normalization instead of clipping to avoid hyperparameter tuning. However, normalization-based approaches like NSGD and Auto-S rely on a monotonic weight function, which imposes excessive weight on small gradient samples and introduces extra deviation to the update. In this paper, we propose a Differentially Private Per-Sample Adaptive Clipping (DP-PSAC) algorithm based on a non-monotonic adaptive weight function, which guarantees privacy without the typical hyperparameter tuning process of using a constant clipping while significantly reducing the deviation between the update and true batch-averaged gradient. We provide a rigorous theoretical convergence analysis and show that with convergence rate at the same order, the proposed algorithm achieves a lower non-vanishing bound, which is maintained over training iterations, compared with NSGD/Auto-S. In addition, through extensive experimental evaluation, we show that DP-PSAC outperforms or matches the state-of-the-art methods on multiple main-stream vision and language tasks.
Shuheng Shen, Su Yao, Ke Xu 0002
AAAI5
2023 Point Cloud Analysis for ML-Based Malicious Traffic Detection: Reducing Majorities of False Positive Alarms
abstract
As an emerging security paradigm, machine learning (ML) based malicious traffic detection is an essential part of automatic defense against network attacks. Powered by dedicated traffic features, the ML based methods can detect various sophisticated attacks, in particular capturing zero-day attacks, which cannot be achieved by the traditional non-ML methods. However, false positive alarms raised by these advanced ML methods become the major obstacle to real-world deployment. These methods require experts to manually analyze false positives, which incurs significant labor costs. Thus, it is vital that we can reduce such false positives without heavyweight manual investigations.
Chuanpu Fu, Qi Li 0002, Ke Xu 0002
CCS3
2023 martFL: Enabling Utility-Driven Data Marketplace with a Robust and Verifiable Federated Learning Architecture
abstract
The development of machine learning models requires a large amount of training data. Data marketplace is a critical platform to trade high-quality and private-domain data that is not publicly available on the Internet. However, as data privacy becomes increasingly important, directly exchanging raw data becomes inappropriate. Federated Learning (FL) is a distributed machine learning paradigm that exchanges data utilities (in form of local models or gradients) among multiple parties without directly sharing the original data. However, we recognize several key challenges in applying existing FL architectures to construct a data marketplace. (i) In existing FL architectures, the Data Acquirer (DA) cannot privately assess the quality of local models submitted by different Data Providers (DPs) prior to trading; (ii)The model aggregation protocols in existing FL designs cannot effectively exclude malicious DPs without "overfitting'' to the DA's (possibly biased) root dataset; (iii) Prior FL designs lack a proper billing mechanism to enforce the DA to fairly allocate the reward according to contributions made by different DPs. To address above challenges, we propose martFL, the first federated learning architecture that is specifically designed to enable a secure utility-driven data marketplace. At a high level, martFL is empowered by two innovative designs: (i) a quality-aware model aggregation protocol that allows the DA to properly exclude local-quality or even poisonous local models from the aggregation, even if the DA's root dataset is biased; (ii) a verifiable data transaction protocol that enables the DA to prove, both succinctly and in zero-knowledge, that it has faithfully aggregated these local models according to the weights that the DA has committed to. This enables the DPs to unambiguously claim the rewards proportional to their weights/contributions. We implement a prototype of martFL and evaluate it extensively over various tasks. The results show that martFL can improve the model accuracy by up to 25% while saving up to 64% data acquisition cost.
Qi Li 0040, Zhuotao Liu, Qi Li 0002, Ke Xu 0002
CCS4
2023 Learning from Limited Heterogeneous Training Data: Meta-Learning for Unsupervised Zero-Day Web Attack Detection across Web Domains
abstract
Recently unsupervised machine learning based systems have been developed to detect zero-day Web attacks, which can effectively enhance existing Web Application Firewalls (WAFs). However, prior arts only consider detecting attacks on specific domains by training particular detection models for the domains. These systems require a large amount of training data, which causes a long period of time for model training and deployment. In this paper, we propose RETSINA, a novel meta-learning based framework that enables zero-day Web attack detection across different domains in an organization with limited training data. Specifically, it utilizes meta-learning to share knowledge across these domains, e.g., the relationship between HTTP requests in heterogeneous domains, to efficiently train detection models. Moreover, we develop an adaptive preprocessing module to facilitate semantic analysis of Web requests across different domains and design a multi-domain representation method to capture semantic correlations between different domains for cross-domain model training. We conduct experiments using four real-world datasets on different domains with a total of 293M Web requests. The experimental results demonstrate that RETSINA outperforms the existing unsupervised Web attack detection methods with limited training data, e.g., RETSINA needs only 5-minute training data to achieve comparable detection performance to the existing methods that train separate models for different domains using 1-day training data. We also conduct real-world deployment in an Internet company. RETSINA captures on average 126 and 218 zero-day attack requests per day in two domains, respectively, in one month.
Ye Wang 0002, Qi Li 0002, Zhuotao Liu, Ke Xu 0002, Ju Ren 0001, Ruilin Lin
CCS5
2023 Secure Collaborative Learning in Mining Pool via Robust and Efficient Verification
abstract
Recently, collaborative learning is proposed to amortize massive computation costs of highly sophisticated artificial intelligence (AI) tasks. To attract lots of participants, researchers investigate blockchains ‘ economic incentives with proof of useful work (PoUW) consensus protocols to motivate substantial numbers of miners in a mining pool to complete AI tasks. However, participants might be untrusted and defraud rewards with as less as possible efforts. In the paper, we propose a robust and efficient proof of learning scheme called RPoL that enables pool managers to verify the training integrity of pool workers for secure pooled mining. Specifically, we devise an address-encoded model and employ a commitment-based secure sampling method to prevent malicious participants from abusing well-trained models or evading the sampling-based verification. Besides, we optimize RPoL via locality-sensitive hashing (LSH) to achieve communication-efficient verification while tolerating inherent reproduction errors of AI tasks. Furthermore, we conduct theoretical analysis and extensive evaluations. The results demonstrate that RPoL preserves high model performance against adversaries with acceptable costs and thus helps the pool win the mining competition among consensus nodes.
Xiaoli Zhang 0003, Hongbing Cheng, Tong Che, Ke Xu 0002, Weiqiang Wang 0002, Wenbiao Zhao, Qi Li 0002
ICDCS5
2023 ART: Adaptive Retransmission for Wide-Area Loss Recovery in the Wild
abstract
Packet losses significantly impact the user experience of wide-area applications such as content distribution and remote procedure call (RPC) based services. However, our production network measurement studies show that the legacy loss recovery is far from satisfactory due to the wide-area loss characteristics (i.e., dynamics and burstiness) in the wild. In this paper, we propose a sender-side Adaptive ReTransmission scheme, ART, which minimizes the recovery time of lost packets with minimal redundancy cost. Distinguishing itself from forward-error-correction (FEC), which preemptively sends redundant data packets to prevent loss, ART functions as an automatic-repeat-request (ARQ) scheme. It applies redundancy specifically to lost packets instead of unlost packets, thereby addressing the characteristic patterns of wide-area losses in real-world scenarios. We implement ART upon QUIC protocol and evaluate it via both trace-driven emulation and real-world deployment. The results show that ART reduces up to 34% of flow completion time (FCT) for delay-sensitive transmissions, improves up to 28 % of goodput for throughput-intensive transmissions, and saves up to 90% of redundancy cost.
Tong Li 0014, Wei Liu 0230, Shuaipeng Zhu, Jingkun Cao, Senzhen Liu, Taotao Zhang, Yinfeng Zhu 0002, Bo Wu 0002, Ke Xu 0002
ICNP10
2023 On Design and Performance of Offline Finding Network
abstract
Recently, such industrial pioneers as Apple and Samsung have offered a new generation of offline finding network (OFN) that enables crowd search for missing devices without leaking private data. Specifically, OFN leverages nearby online finder devices to conduct neighbor discovery via Bluetooth Low Energy (BLE), so as to detect the presence of offline missing devices and report an encrypted location back to the owner via the Internet. The user experience in OFN is closely related to the success ratio (possibility) of finding the lost device, where the latency of the prerequisite stage, i.e., neighbor discovery, matters. However, the crowd-sourced finder devices show diversity in scan modes due to different power modes or different manufacturers, resulting in local optima of neighbor discovery performance. In this paper, we present a brand-new broadcast mode called ElastiCast to deal with the scan mode diversity issues. ElastiCast captures the key features of BLE neighbor discovery and globally optimizes the broadcast mode interacting with diverse scan modes. Experimental evaluation results and commercial product deployment experience demonstrate that ElastiCast is effective in achieving stable and bounded neighbor discovery latency within the power budget.
Tong Li 0014, Yukuan Ding, Kai Zheng 0003, Xu Zhang 0006, Ke Xu 0002
INFOCOM6
2023 Grandet: Cost-aware Traffic Scheduling without Prior Knowledge in SD-WAN
abstract
The rapid growth of traffic demands on wide-area networks (WANs) has resulted in escalated transmission costs for cross-national enterprises. Many researchers have proposed traffic scheduling methods that can effectively reduce transmission costs and improve network performance. However, the majority of research in this field assumes that traffic demands and network link quality are known in advance, disregarding the impact of information agnostic. While some works try to obtain this knowledge through prediction, they lack awareness of prediction errors, which makes it difficult for their scheduling strategies to achieve theoretical results. In this paper, we propose a novel scheduler Grandet that aims to reduce transmission costs without any prior knowledge. First, instead of requiring prior knowledge or accurate prediction, Grandet determines the intervals of flow sizes and link quality parameters through confidence-based Bootstrap method combined with neural network model, thus quantifying the uncertainty of these information. Then, we design a cost-aware online traffic scheduling framework using the uncertainty intervals from interval determination to optimize the cost minimization problem. Through rigorous theoretical analysis, we prove the approximate optimality of Grandet in minimizing transmission costs. Trace-driven and large-scale simulations show that Grandet successfully reduces transmission costs by over 23%, reduces deadline miss rate by over 31%, and reduces Service Level Agreement (SLA) dissatisfaction rate by over 37%.
Yuchao Zhang 0004, Huahai Zhang, Peizhuang Cong, Wendong Wang 0003, Ke Xu 0002
IWQoS5
2023 Detecting Unknown Encrypted Malicious Traffic in Real Time via Flow Interaction Graph Analysis
Chuanpu Fu, Qi Li 0002, Ke Xu 0002
NDSS3
2023 Poster: TOO: Accelerating Loss Recovery by Taming On-Off Traffic Patterns
abstract
As the ubiquitous phenomenon occurs in applications such as live streaming and video conferencing, the on-off traffic pattern is regarded as a disadvantage for congestion control. However, we argue that it can be transformed as an advantage for accelerating loss recovery. In this paper, we report the design of TOO, a loss recovery acceleration mechanism that tames on-off patterns for loss duplicate reinjection without incurring non-trivial traffic overhead.
Tong Li 0014, Bo Wu 0002, Fuyu Wang 0006, Ke Xu 0002
SIGCOMM7
2023 Poster: PolyCC: Poly-Algorithmic Congestion Control
abstract
This paper demonstrates PolyCC, a general framework for simultaneous operation of poly-algorithmic congestion control. PolyCC gains benefits from taking advantage of the complementary among already existing congestion controllers.
Shuaipeng Zhu, Tong Li 0014, Yinfeng Zhu 0002, Taotao Zhang, Senzhen Liu, Ke Xu 0002
SIGCOMM8
2023 Robust Multi-tab Website Fingerprinting Attacks in the Wild
abstract
Website fingerprinting enables an eavesdropper to determine which websites a user is visiting over an encrypted connection. State-of-the-art website fingerprinting (WF) attacks have demonstrated effectiveness even against Tor-protected network traffic. However, existing WF attacks have critical limitations on accurately identifying websites in multi-tab browsing sessions, where the holistic pattern of individual websites is no longer preserved, and the number of tabs opened by a client is unknown a priori. In this paper, we propose ARES, a novel WF framework natively designed for multi-tab WF attacks. ARES formulates the multi-tab attack as a multi-label classification problem and solves it using a multi-classifier framework. Each classifier, designed based on a novel transformer model, identifies a specific website using its local patterns extracted from multiple traffic segments. We implement a prototype of ARES and extensively evaluate its effectiveness using our large-scale dataset collected over multiple months (by far the largest multi-tab WF dataset studied in academic papers.) The experimental results illustrate that ARES effectively achieves the multi-tab WF attack with the best F1-score of 0.907. Further, ARES remains robust even against various WF defenses.
Xinhao Deng 0001, Qilei Yin, Zhuotao Liu, Qi Li 0002, Mingwei Xu 0001, Ke Xu 0002
SP7
2023 Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects
abstract
Modern Wi-Fi networks are commonly protected by the security mechanisms, e.g., WPA, WPA2 or WPA3, and thus it is difficult for an attacker (a malicious supplicant) to hijack the traffic of other supplicants as a man-in-the-middle (MITM). In traditional Evil Twins attacks, attackers may deploy a bogus wireless access point (AP) to hijack the victim supplicants’ traffic (e.g., stealing credentials). In this paper, we uncover a new MITM attack that can evade the security mechanisms in Wi-Fi networks by spoofing the legitimate AP to send a forged ICMP redirect message to a victim supplicant and thus allow attackers to stealthily hijack the traffic from the victim supplicant without deploying any bogus AP. The core idea is to misuse the vulnerability of cross-layer interactions between WPAs and ICMP protocols, totally evading the link layer security mechanisms enforced by WPAs. We resolve two requirements to successfully launch our attack. First, when the attacker spoofs the legitimate AP to craft an ICMP redirect message, the legitimate AP cannot recognize and filter out those forged ICMP redirect messages. We uncover a new vulnerability (CVE-2022-25667) of the Network Processing Units (NPUs) in AP routers that restrict the AP routers from blocking fake ICMP error messages passing through the router. We test 55 popular wireless routers from 10 well-known AP vendors, and none of these routers can block the forged ICMP redirect messages due to this vulnerability. Second, we develop a new method to ensure the forged ICMP redirect message can evade the legitimacy check of the victim supplicant and then poison its routing table. We conduct an extensive measurement study on 122 real-world Wi-Fi networks, covering all prevalent Wi-Fi security modes. The experimental results show that 109 out of the 122 (89%) evaluated Wi-Fi networks are vulnerable to our attack. Besides notifying the vulnerability to the NPU manufacturers and the AP vendors, we develop two countermeasures to throttle the identified attack.
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002
SP5
2023 Subverting Website Fingerprinting Defenses with Robust Traffic Representation
Meng Shen 0001, Kexin Ji, Zhenbo Gao, Qi Li 0002, Liehuang Zhu, Ke Xu 0002
USENIX Security Symposium6
2023 Cross Container Attacks: The Bewildered eBPF on Clouds
Yi He 0020, Roland Guo, Yunlong Xing, Xijia Che, Kun Sun 0001, Zhuotao Liu, Ke Xu 0002, Qi Li 0002
USENIX Security Symposium7
2023 An Efficient Design of Intelligent Network Data Plane
Guangmeng Zhou, Zhuotao Liu, Chuanpu Fu, Qi Li 0002, Ke Xu 0002
USENIX Security Symposium5
2023 FRAVaR: A Fast Failure Recovery Framework for Inter-DC Network
abstract
Along with the development of 5G and IoT technologies in recent years, Inter Data Center (Inter-DC) network is facing an explosive growth of geographically distributed user data, which needs to be duplicated among DCs in a real-time manner. Transmission-based applications require high availability that is going beyond 99.99%. However, with the expansion of Inter-DC network scale, link failures are also growing, which seriously affects data transmission efficiency, so fast link failure recovery is then urgently needed. Many previous works have been done to achieve fast failure recovery, but most of them ignore two key points, 1) the cost of deploying recovery strategies, and 2) the side-effect of re-transmission to network availability. These two factors make the existing failure recovery process too slow to be practical in real-time online industrial environments. To achieve realistic fast recovery from Inter-DC network failures, we propose a failure recovery framework FRAVaR, which achieves high network availability with very little deployment overhead. Particularly, FRAVaR reduces the deployment overhead by a novel incremental routing strategy to isolate link failures. In other words, it only needs to shuffle a tiny amount of traffic within a small failure isolation domain. On this base, FRAVaR further adopts a risk assessment theory named Value-at-Risk (VaR) to control flow re-transmission. We implement a prototype of FRAVaR and conduct a series of experiments on 4 real InterDC network topologies (ATT North America, IBM, GlobalCenter, AGIS). Experiment results show that FRAVaR outperforms state-of-the-art solutions on the recovery speed by 70.2%.1
Haoqiang Huang, Yuchao Zhang 0004, Qiao Xiang, Wendong Wang 0003, Xirong Que, Ke Xu 0002
WCNC7
2023 Provenance of Training without Training Data: Towards Privacy-Preserving DNN Model Ownership Verification
abstract
In the era of deep learning, it is critical to protect the intellectual property of high-performance deep neural network (DNN) models. Existing proposals, however, are subject to adversarial ownership forgery (e.g., methods based on watermarks or fingerprints) or require full access to the original training dataset for ownership verification (e.g., methods requiring the replay of the learning process). In this paper, we propose a novel Provenance of Training (PoT) scheme, the first empirical study towards verifying DNN model ownership without accessing any original dataset while being robust against existing attacks. At its core, PoT relies on a coherent model chain built from the intermediate checkpoints saved during model training to serve as the ownership certificate. Through an in-depth analysis of model training, we propose six key properties that a legitimate model chain shall naturally hold. In contrast, it is difficult for the adversary to forge a model chain that satisfies these properties simultaneously without performing actual training. We systematically analyze PoT’s robustness against various possible attacks, including the adaptive attacks that are designed given the full knowledge of PoT’s design, and further perform extensive empirical experiments to demonstrate our security analysis.
Zhuotao Liu, Bihan Wen, Ke Xu 0002, Weiqiang Wang 0002, Wenbiao Zhao, Qi Li 0002
WWW5
2023 Exploration of Reflective ASMs for Security
Linjie Tong, Ke Xu 0002, Jiarun Hu, Flavio Ferrarotti, Klaus-Dieter Schewe
ABZ2
2023 Towards real-time ML-based DDoS detection via cost-efficient window-based feature extraction
Yi Zhao 0011, Wenbing Yao, Ke Xu 0002, Qi Li 0002
Sci. China Inf. Sci.4
2023 A delayed eviction caching replacement strategy with unified standard for edge servers
Pengmiao Li, Yuchao Zhang 0004, Huahai Zhang, Wendong Wang 0003, Ke Xu 0002
Comput. Networks5
2023 DIT and Beyond: Interdomain Routing With Intradomain Awareness for IIoT
abstract
Along with the ever-increasing amount of data generated from industrial devices, the cross domain [also known as autonomous systems (ASs)] data transmission problem has attracted more and more attention in the Industrial Internet of Things (IIoT). As mature and widely used interdomain routing protocols, border gateway protocol-based solutions often take the number of domains (i.e., AS hops) of each path as a criterion to make routing decisions, which is simple and effective. However, such protocols can only meet the reachability requirements while ignoring the performance requirements. That is, the path with the minimum AS hops will be selected to carry flows, even if the actual performance of this path does not meet the transmission requirements due to the unawareness of intradomain information on that path. But it is not impractical to directly access intradomain information for making better routing decisions given data privacy concerns. In this article, we propose M-DIT, which can make interdomain routing decisions with the assistance of desensitized intradomain information for multiple-requirement transmissions. To do so, we design a homomorphic encrypted-based private number comparison scheme to export intradomain information securely and, thus, assist in routing decisions. The results of some experiments based on five real topologies (ATMnet,Claranet,Compuserve,NSFnet, andPeer1) with thousands of interdomain flows demonstrate that M-DIT reduced flow completion time by about 60% or selected high bandwidth paths flexibly for interdomain routing for IIoT scenarios.
Peizhuang Cong, Yuchao Zhang 0004, Wendong Wang 0003, Xiangyang Gong, Tong Yang 0003, Dan Li 0001, Ke Xu 0002
IEEE Internet Things J.8
2023 AI-Bazaar: A Cloud-Edge Computing Power Trading Framework for Ubiquitous AI Services
abstract
Driven by the burgeoning growth of the Internet of Everything and the substantial breakthroughs in deep learning (DL) algorithms, a booming of artificial intelligence (AI) applications keep emerging. Meanwhile, the advance in existing computing paradigms, i.e., cloud computing and edge computing, provide assorted computing solutions to satisfy the increasingly high requirements for ubiquitous AI services. Nevertheless, there are some non-trivial issues in the computing frameworks, including the underutilization of computing power, the self-interest of computing-power trading mechanism, and the inefficiency of AI services management. To tackle the above issues, we propose a computing-power trading framework based on blockchain, also named AI-Bazaar. In AI-Bazaar, the AI consumers play multiple roles and feel free to contribute the computing power rented from the computing-power provider (CPP) for blockchain mining and AI services. Accordingly, we formulate the computing trading problem as a Stackelberg game. Based on the win or learn fast principle (WoLF), we design a profit-balanced multi-agent reinforcement learning (PB-MARL) algorithm to search the AI-Bazaar equilibrium, while finding the balanced profits for AI consumers and CPP. Numerical simulations are carried out to demonstrate the satisfactory performance and effectiveness of the proposed framework.
Xiaoxu Ren, Chao Qiu, Xiaofei Wang 0001, Zhu Han 0001, Ke Xu 0002, Haipeng Yao, Song Guo 0001
IEEE Trans. Cloud Comput.5
2023 FedDef: Defense Against Gradient Leakage in Federated Learning-Based Network Intrusion Detection Systems
abstract
Deep learning (DL) methods have been widely applied to anomaly-based network intrusion detection system (NIDS) to detect malicious traffic. To expand the usage scenarios of DL-based methods, federated learning (FL) allows multiple users to train a global model on the basis of respecting individual data privacy. However, it has not yet been systematically evaluated how robust FL-based NIDSs are against existing privacy attacks under existing defenses. To address this issue, we propose two privacy evaluation metrics designed for FL-based NIDSs, including (1) privacy score that evaluates the similarity between the original and recovered traffic features using reconstruction attacks, and (2) evasion rate against NIDSs using adversarial attack with the recovered traffic. We conduct experiments to illustrate that existing defenses provide little protection and the corresponding adversarial traffic can even evade the SOTA NIDS Kitsune. To defend against such attacks and build a more robust FL-based NIDS, we further propose FedDef, a novel optimization-based input perturbation defense strategy with theoretical guarantee. It achieves both high utility by minimizing the gradient distance and strong privacy protection by maximizing the input distance. We experimentally evaluate four existing defenses on four datasets and show that our defense outperforms all the baselines in terms of privacy protection with up to 7 times higher privacy score, while maintaining model accuracy loss within 3% under optimal parameter combination.
Jiahui Chen 0009, Yi Zhao 0011, Qi Li 0002, Xuewei Feng, Ke Xu 0002
IEEE Trans. Inf. Forensics Secur.5
2023 Seeking Based on Dynamic Prices: Higher Earnings and Better Strategies in Ride-on-Demand Services
abstract
In recent years, ride-on-demand (RoD) services such as Uber and DiDi are becoming increasingly popular. Different from traditional taxi services, RoD services adopt dynamic pricing mechanisms to manipulate the supply and demand on the road, and such mechanisms improve service capacity and quality. Seeking route recommendation has been widely studied in taxi service. In RoD service, the dynamic price is a new and accurate indicator describing the supply and demand, but it is yet rarely studied in providing clues for drivers to seek for passengers. In this paper, we propose to incorporate the impacts of dynamic prices as a key factor in recommending seeking routes to drivers. We first justfiy why it is necessary to recommend seeking routes and consider dynamic prices, by analyzing real service data from a typical RoD service. We then design a reinforcement learning model based on order and GPS trajectories datasets, and take into account dynamic prices in the design. Results prove that our model improves both driver earnings and seeking strategies. On driver earnings, the reinforcement learning model increases revenue efficiency by up to 34.52%, and considering dynamic prices leads to another increase of 6.19%. On seeking strategies, drivers are encouraged to serve local demand first, and they are redistributed more evenly and effectively.
Suiming Guo, Qianrong Shen, Zhiquan Liu 0001, Chao Chen 0004, Chaoxiong Chen, Jingyuan Wang 0001, Zhetao Li, Ke Xu 0002
IEEE Trans. Intell. Transp. Syst.8
2023 Enriching Large-Scale Trips With Fine-Grained Travel Purposes: A Semi-Supervised Deep Graph Embedding Framework
abstract
Knowing why people travel is meaningful for human mobility understanding and smart services development. Unfortunately, in real-world scenarios, trip purpose cannot be automatically collected on a large scale, thus calling for effective prediction models. Nevertheless, since passengers’ trip purposes in the city are diverse and complicated, the prediction is very difficult especially at a fine-grained level. Worse still, the informative data sources and real purpose-labels about trips are commonly limited for model learning. To resolve the dilemma, we propose a semi-supervised deep embedding framework for predicting fine-grained trip purposes on a large scale. Specifically, we first derive augmented trip contexts from the vehicle’s GPS trajectory and public POI check-in data, then convert POI contexts into the graph structure. We further establish aDual-AttentionGraphEmbedding Network withAutoencoder architecture (DAGE-A) to accomplish prediction and reconstruction simultaneously, in which category-aware graph attention networks are devised to model the POI semantics at trip’s origin/destination and extract complementary knowledge from unlabeled trips; and soft-attention is employed to aggregate different trip semantics appropriately for the final prediction. We conduct extensive experiments in Beijing and Shanghai, and results show our framework outperforms state-of-the-arts and could reduce labelling efforts by up to 20%. We also find that our model is generalized at different times and locations, and the performance varies for different trip purposes.
Chengwu Liao, Chao Chen 0004, Suiming Guo, Leye Wang, Fuqiang Gu, Ke Xu 0002
IEEE Trans. Intell. Transp. Syst.7
2023 R-AQM: Reverse ACK Active Queue Management in Multitenant Data Centers
abstract
TCP incast has become a practical problem for high-bandwidth, low-latency transmissions, resulting in throughput degradation of up to 90% and delays of hundreds of milliseconds, severely impacting application performance. However, in virtualized multi-tenant data centers, host-based advancements in the TCP stack are hard to deploy from the operators’ perspective. Operators only provide infrastructure in the form of virtual machines, in which only tenants can directly modify the end-host TCP stack. In this paper, we present R-AQM, a switch-powered reverse ACK active queue management (R-AQM) mechanism for enhancing ACK-clocking effects through assisting legacy TCP. Specifically, R-AQM proactively intercepts ACKs and paces the ACK-clocked in-flight data packets, preventing TCP from suffering incast collapse. We implement and evaluate R-AQM in NS-3 simulation and NetFPGA-based hardware switch. Both simulation and testbed results show that R-AQM greatly improves TCP performance under heavy incast workloads by significantly lowering packet loss rate, reducing retransmission timeouts, and supporting 16 times (i.e., 60 to 1000) more senders. Meanwhile, the forward queuing delays are also reduced by 4.6 times.
Xinle Du, Ke Xu 0002, Lei Xu 0019, Kai Zheng 0003, Meng Shen 0001, Bo Wu 0002, Tong Li 0014
IEEE/ACM Trans. Netw.2
2023 Frequency Domain Feature Based Robust Malicious Traffic Detection
abstract
Machine learning (ML) based malicious traffic detection is an emerging security paradigm, particularly for zero-day attack detection, which is complementary to existing rule based detection. However, the existing ML based detection achieves low detection accuracy and low throughput incurred by inefficient traffic features extraction. Thus, they cannot detect attacks in realtime, especially in high throughput networks. Particularly, these detection systems similar to the existing rule based detection can be easily evaded by sophisticated attacks. To this end, we propose Whisper, a realtime ML based malicious traffic detection system that achieves both high accuracy and high throughput by utilizing frequency domain features. It utilizes sequential information represented by the frequency domain features to achieve bounded information loss, which ensures high detection accuracy, and meanwhile constrains the scale of features to achieve high detection throughput. In particular, attackers cannot easily interfere with the frequency domain features and thus Whisper is robust against various evasion attacks. Our experiments with 74 types of attacks demonstrate that, compared with the state-of-the-art systems, Whisper can accurately detect various sophisticated and stealthy attacks, achieving at most 18.36% improvement of AUC, while achieving two orders of magnitude throughput. Even under various evasion attacks, Whisper is still able to maintain around 90% detection accuracy.
Chuanpu Fu, Qi Li 0002, Meng Shen 0001, Ke Xu 0002
IEEE/ACM Trans. Netw.4
2023 MASK: Practical Source and Path Verification Based on Multi-AS-Key
abstract
The source and path verification in Path-Aware Networking considers the two critical issues: (1) end hosts could verify that the network follows their forwarding decisions, and (2) both on-path routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the state-of-the-art mechanisms require heavy communication overhead in the network and computation overhead in the router; moreover, it is difficult to meet the dynamic requirements of the end host. We propose a user-driven mechanism, source and path verification based on Multi-AS-Key (MASK). MASK decreases the communication overhead by a short additional packet header and reduces the computation overhead by separating the control and data plane in terms of the cryptographic operation. Furthermore, it utilizes the stateful user to instruct the stateless routers to process the packet with a user-driven policy, thus satisfying the user’s requirements such as detecting the packet drop and replay attack. With the plausible design, the communication overhead for realistic path lengths is 1/2 to 1/10 compared with the state-of-the-art mechanisms. We implement MASK in the BMv2 environment and commodity Barefoot Tofino programmable switch, testify that MASK introduces significantly less overhead than the state-of-the-art mechanisms, and demonstrate that MASK could achieve the verification in the programmable switch at line rate.
Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du, Ke Xu 0002
IEEE/ACM Trans. Netw.8
2023 Friendship Inference in Mobile Social Networks: Exploiting Multi-Source Information With Two-Stage Deep Learning Framework
abstract
With the tremendous growth of mobile social networks (MSNs), people are highly relying on it to connect with friends and further expand their social circles. However, the conventional friendship inference techniques have issues handling such a large yet sparse multi-source data. The related friend recommendation systems are therefore suffering from reduced accuracy and limited scalability. To address this issue, we propose a Two-stage Deep learning framework for Friendship Inference, namely TDFI. This approach enables MSNs to exploit multi-source information simultaneously, rather than hierarchically. Therefore, there is no need to manually set which information is more important and the order in which the various information is applied. In details, we apply an Extended Adjacency Matrix (EAM) to represent the multi-source information. We then adopt an improved Deep Auto-Encoder Network (iDAEN) to extract the fused feature vector for each user. Our framework also provides an improved Deep Siamese Network (iDSN) to measure user similarity. To provide a substantial description and evaluation of the proposed methodology, we evaluate the effectiveness and robustness on three large-scale real-world datasets. Trace-driven evaluation results demonstrate that TDFI can effectively handle the sparse multi-source data while providing better accuracy for friendship inference. Through the comparison with numerous state-of-the-art methods, we find that TDFI can achieve superior performance via real-world multi-source information. Meanwhile, it demonstrates that the proposed pipeline can not only integrate structural information and attribute information, but also be compatible with different attribute information, which further enhances the overall applicability of friend-recommendation systems under information-rich MSNs.
Yi Zhao 0011, Meina Qiao, Rui Zhang 0017, Dan Wang 0002, Ke Xu 0002
IEEE/ACM Trans. Netw.6
2022 Verifying the Quality of Outsourced Training on Clouds
Ye Wang 0002, Zhuotao Liu, Ke Xu 0002, Qian Wang 0002, Chao Shen 0001, Qi Li 0002
ESORICS (2)4
2022 DIP: unifying network layer innovations using shared L3 core functions
abstract
The IP protocol has made a great contribution to the development of the Internet and has become the narrow waist of the Internet. However, the fixed packet processing of IP hinders the functional expansion and evolution of the Internet. In order to solve the rigidity of the Internet, our community has proposed various new L3 protocols to better support various network functions at the network layer. In this paper, we propose DIP (Dynamic Internet Protocol), a novel primitive to unify these protocols. DIP builds a common network function core shared by these L3 protocols based on a new L3 function core primitive, named Field Operation (FN). With FNs, each standalone L3 protocol can be decomposed into a combination of multiple FNs, and meanwhile it is feasible to compose various FNs to realize new (derived) L3 protocols. We demonstrate the feasibility of DIP by realizing five radically different network layer protocols1: the canonical IP forwarding, NDN [41], XIA [12], OPT [16], and NDN+OPT (a derived L3 protocol combining the merits of both NDN and OPT). We implement a prototype of DIP and evaluate its forwarding performance.
Zhuotao Liu, Xiaoliang Wang 0004, Songtao Fu, Ke Xu 0002
HotNets5
2022 D3: Lightweight Secure Fault Localization in Edge Cloud
abstract
In pursuit of high-performance applications, the cloud is moving out of the data center and towards the edge. Secure data forwarding is critical for the users between the edge and the remote cloud. In this paper, we propose D3 (Demon Detector in Data Plane), a lightweight, secure fault localization mechanism, which can enable the users in the edge cloud to localize faulty links and thus avoid the faulty links to guarantee secure data forwarding along the path to the remote cloud. D3 utilizes the user to instruct the transit routers, thus empowering the user to detect whether the transit routers forward the packet as expected. Compared with existing schemes that are difficult to be deployed in practice due to the incurred heavy storage, computation, and communication overhead, D3 offloads most of the transit router’s storage and computation overhead, thus dramatically improving the deployment efficiency. Particularly, the length of the additional packet header in D3 is 2-5 times less than the state-of-the-art mechanisms, and the extra control packet overhead is ten times less while keeping a little constant storage overhead in the data plane. The evaluations in BMv2 and Barefoot Tofino hardware show that D3 could achieve high fault localization accuracy and efficiency.
Songtao Fu, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Xuewei Feng, Xinle Du, Kao Wan, Ke Xu 0002
ICDCS9
2022 Break the Blackbox! Desensitize Intra-domain Information for Inter-domain Routing
abstract
Along with the ever-increasing amount of data generated from edge networks, cross domain (also known as Autonomous Systems, AS) transmission problem has attracted more and more attention. As mature and widely used inter-domain routing protocols, BGP-based solutions often use the number of domains (i.e. AS hops) of each path to make inter-domain routing decisions, which is simple and effective, but usually can not get the optimal routing results due to the lack of real state/information within ASes. These protocols choose the path with less AS hops as the forwarding path, even if the total latency or cost of the domains on this path is higher. While to solve this problem, directly access to intra-domain information as the assistance to make routing decisions is impractical due to data privacy.In this paper, we propose DIT, which makes near-optimal inter-domain routing decisions with desensitized intra-domain information. To do so, we design a homomorphic encrypted-based private number comparison scheme to export intra-domain information securely and thus assist in routing decisions. We conduct a series of experiments according to five real network topologies with nearly 900 simulated flows, and the results show that DIT reduces the number of forwarding hops by about 45% in average and reduces flow completion time by about 60%.
Peizhuang Cong, Yuchao Zhang 0004, Wendong Wang 0003, Xiangyang Gong, Tong Yang 0003, Dan Li 0001, Ke Xu 0002
IWQoS9
2022 Congestion-Aware Modeling and Analysis of Sponsored Data Plan from End User Perspective
abstract
The past decade has witnessed the rapid expansion of demands for mobile traffic, while the traditional mobile traffic pricing schemes cannot accommodate such demands. Sponsored data plan (SDP), which can increase the revenue of all stakeholders in the market through transferring some of the revenue from content providers (CPs) to end users (EUs), is more suitable. However, existing studies have focused more on Internet service providers (ISPs) and CPs, ignoring the influence of EUs (e.g., the inherent attribute differences of EUs and the interaction among EUs) on the market under SDP. Regarding the difficulty of modeling the abstract property about interaction among EUs, we utilize network congestion as the medium and construct the congestion-aware SDP model based on Stackelberg game. The newly proposed model can not only analyze how network congestion affects SDP mechanism, but also elucidate the impact of interactions among EUs. More specifically, through theoretical analysis, we prove that there is a unique dynamic equilibrium in the interaction among EUs (i.e., the traffic consumption of different EUs). By taking into account network congestion, the newly proposed model also more accurately and realistically describes the optimal strategies and computation methods of all stakeholders in the market. Moreover, simulation experiments demonstrate that the positive effect brought by SDP is not as obvious as before, and EUs influence each other instead of being independent of each other. Overall, this paper emphasizes the non-negligible influence of EUs and promotes a deeper understanding of SDP mechanism, which can guide the relevant stakeholders to optimize their own decision-making details.
Yi Zhao 0011, Qi Tan 0003, Xiaohua Xu 0002, Hui Su, Dan Wang 0002, Ke Xu 0002
IWQoS6
2022 PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002, Baojun Liu 0002, Qiushi Yang, Hai-Xin Duan, Zhiyun Qian
NDSS4
2022 Value Penalized Q-Learning for Recommender Systems
abstract
Scaling reinforcement learning (RL) to recommender systems (RS) is promising since maximizing the expected cumulative rewards for RL agents meets the objective of RS, i.e., improving customers' long-term satisfaction. A key approach to this goal is offline RL, which aims to learn policies from logged data rather than expensive online interactions. In this paper, we propose Value Penalized Q-learning (VPQ), a novel uncertainty-based offline RL algorithm that penalizes the unstable Q-values in the regression target using uncertainty-aware weights, achieving the conservative Q-function without the need of estimating the behavior policy, suitable for RS with a large number of items. Experiments on two real-world datasets show the proposed method serves as a gain plug-in for existing RS models.
Chengqian Gao, Ke Xu 0002, Kuangqi Zhou, Lanqing Li, Xueqian Wang 0001, Bo Yuan 0008, Peilin Zhao
SIGIR2
2022 Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect Attacks
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Zhiyun Qian, Xiaohui Kuang, Chuanpu Fu, Ke Xu 0002
USENIX Security Symposium8
2022 RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices
Yi He 0020, Zhenhua Zou, Kun Sun 0001, Zhuotao Liu, Ke Xu 0002, Qian Wang 0002, Chao Shen 0001, Zhi Wang 0004, Qi Li 0002
USENIX Security Symposium5
2022 WIP: When RDMA Meets Wireless
abstract
The emerging applications including AR/VR inter-active gaming, ultra-high-definition live streaming, 4K wireless projection, Metaverse, etc. imply the demand for ultra-low latency and ultra-high bandwidth wireless transmission. The legacy kernel TCP stack is not fully satisfactory because it induces the CPU bottleneck on hosts. In this paper, we propose Wireless-RDMA (W-RDMA) that enables RDMA in wireless networks to tackle the CPU bottleneck issue on wireless hosts. The feasibility of W-RDMA is demonstrated through testbed experiments. Technical challenges and future opportunities are further discussed. We believe it is a small but crucial step for enabling RDMA for wireless transmission.
Tong Li 0014, Ke Xu 0002, Hanlin Huang, Xinle Du, Kai Zheng 0003
WoWMoM2
2022 Intelligent networking in adversarial environment: challenges and opportunities
Yi Zhao 0011, Ke Xu 0002, Qi Li 0002, Dan Wang 0002
Sci. China Inf. Sci.2
2022 Chameleon: A Self-adaptive cache strategy under the ever-changing access frequency in edge network
Pengmiao Li, Yuchao Zhang 0004, Wendong Wang 0003, Weiliang Meng, Ke Xu 0002
Comput. Commun.6
2022 A&B: AI and Block-Based TCAM Entries Replacement Scheme for Routers
abstract
With the ever-increasing deployment of 5G and IoT, the number of end-hosts/terminals is increasing rapidly, so that routers have to cache more and more forwarding entries to guarantee communication reachability of these terminals, which makes Ternary Content Addressable Memory (TCAM)-based routers keep expanding resource requirements. However, the design and implementation of large-capacity TCAM-based routers are faced with such challenges: difficult circuit design, high production cost and energy consumption, thereby posing an urgent requirement on a lightweight TCAM that can still maintain those massive communication connections. In this paper, we aim to design a lightweight router with small storage requirement while still retaining the original communication connection performance, which is not straightforward due to the following two challenges: First, under the condition of massive sequential flow data, it’s difficult to accurately and timely select the entries to cache for a small capacity TCAM. Second, given the strict prefix matching principle, how to efficiently insert the selected entries into TCAM is also challenging. To address these problems, we propose A&B: an AI-based Routing entry prediction strategy (AIR) and a Block-based entry Insertion Tactic (BIT). AIR can precisely select entries by conducting accurate entry predictions, which converts dynamic flow-based prediction into stable and parallelizable entry-based prediction by decoupling spatio-temporal characteristics. BIT optimizes entry insertion by isolating TCAM into several blocks, thus eliminating the time-consuming entry movements. The experiment results based on real backbone traffic show that our lightweight A&B achieves comparable performance compared to the traditional schemes by using only 1/8 TCAM storage.
Peizhuang Cong, Yuchao Zhang 0004, Bin Liu 0001, Wendong Wang 0003, Zehui Xiong, Ke Xu 0002
IEEE J. Sel. Areas Commun.6
2022 Blockchain-Empowered Collaborative Task Offloading for Cloud-Edge-Device Computing
abstract
How to enable high-performance task offloading and preserve the trust between participants is imperative yet nontrivial to the Cloud-Edge-Device (CED) computing, mainly because the resources are geo-distributed and operated by different parties. Also, the CED participants are highly dynamic and heterogeneous in resource provision and may conflict in interest. This paper proposes BlockChain-empowered CED (BC-CED), a blockchain-empowered collaborative task offloading for CED computing. In BC-CED, blockchain plays a central role in the main functionality of CED, including task offloading, brokerage of resource usage, and incentives. We distinguish the BC-CED from the existing solutions by modifying the blockchain consensus process, enabling the participants to reach an agreement via solving the task offloading problem. For this purpose, we formulate the offloading problem by considering the computation capabilities of candidate nodes and the network performance. BC-CED allows each participant to apply reinforcement learning-based methods to solve this problem and compete for the right of block output by comparing the offloading policy performance and accepting the best policy as the offloading scheme within the next period. We also propose a truthful incentive mechanism to encourage resource contributions in BC-CED and force them to be honest. Extensive tests by implementing our solutions in a commercialized blockchain platform have shown how BC-CED achieves a superior performance in task offloading and blockchain maintenance.
Su Yao, Qiang Qu 0001, Ke Xu 0002, Mingwei Xu 0001
IEEE J. Sel. Areas Commun.6
2022 A Force-Directed Approach to Seeking Route Recommendation in Ride-on-Demand Service Using Multi-Source Urban Data
abstract
The rapidly-growing business of ride-on-demand (RoD) service such as Uber, Lyft and Didi proves the effectiveness of their new service model – using mobile apps and dynamic pricing to coordinate between drivers, passengers and the service provider, to manipulate the supply and demand, and to improve service responsiveness as well as quality. Despite its success, dynamic pricing creates a new problem for drivers: how to seek for passengers to maximize revenue under dynamic prices. Seeking route recommendation has already been studied extensively in traditional taxi service, but most studies do not consider the effects of taxis and passengers on the seeking taxi simultaneously. Further, in RoD service it is necessary to consider more factors such as dynamic prices, the status of other transportation services, etc. In this paper, we employ a force-directed approach to model, by analogy, the relationship between vacant cars and passengers as that between positive and negative charges in electrostatic field. We extract features from multi-source urban data to describe dynamic prices, the status of RoD, taxi and public transportation services, and incorporate them into our model. The model is then used in route recommendation in every intersection so that a driver in a vacant RoD car knows which road segment to take next. We conduct extensive experiments based on our multi-source urban data, including RoD service operational data, taxi GPS trajectory data and public transportation distribution data, and results not only show that our approach outperforms existing baselines, but also justify the need to incorporate multi-source urban data and dynamic prices.
Suiming Guo, Chao Chen 0004, Jingyuan Wang 0001, Yan Ding 0002, Yaxiao Liu, Ke Xu 0002, Zhiwen Yu 0001, Daqing Zhang 0001
IEEE Trans. Mob. Comput.6
2022 Off-Path TCP Hijacking Attacks via the Side Channel of Downgraded IPID
abstract
In this paper, we uncover a new off-path TCP hijacking attack that can be used to terminate victim TCP connections or inject forged data into victim TCP connections by manipulating the new mixed IPID assignment method, which is widely used in Linux kernel version 4.18 and beyond. Our attack has three steps. First, an off-path attacker can downgrade the IPID assignment for TCP packets from the more secure per-socket-based policy to the less secure hash-based policy, thus building a shared IPID counter that forms a side channel in the victim. Second, the attacker detects the presence of TCP connections by observing the side channel of the shared IPID counter. Third, the attacker infers sequence and acknowledgment numbers of the detected connection by observing the side channel. Consequently, the attacker can completely hijack the connection, e.g., resetting the connection or poisoning the data stream. We evaluate the impacts of our attack in the real world, and we uncover that more than 20% of Alexa top 100k websites are vulnerable to our attack. Our case studies of SSH DoS, manipulating web traffic, and poisoning BGP routing tables show its threat on a wide range of applications. Moreover, we demonstrate that our attack can be further extended to exploit IPv4/IPv6 dual-stack networks on increasing the hash collisions and enlarging vulnerable populations. Finally, we analyze the root cause and develop a new IPID assignment method to defeat this attack. We prototype our defense in Linux 4.18 and confirm its effectiveness in the real world.
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Chuanpu Fu, Ke Xu 0002
IEEE/ACM Trans. Netw.5
2022 Introduction to the Special Section on Energy-efficient and Secure Computing for Artificial Intelligence and Beyond
abstract
introduction Share on Introduction to the Special Section on Energy-efficient and Secure Computing for Artificial Intelligence and Beyond Authors: Meikang Qiu Dakota State University, USA Dakota State University, USASearch about this author , Ke Xu Tsinghua University, China Tsinghua University, ChinaSearch about this author , Cheng Zhang Ibaraki University, Japan Ibaraki University, JapanSearch about this author , Tianwei Zhang Nanyang Technological University, Singapore Nanyang Technological University, SingaporeSearch about this author Authors Info & Claims ACM Transactions on Sensor NetworksVolume 18Issue 4November 2022 Article No.: 51epp 1–3https://doi.org/10.1145/3558553Published:09 March 2023Publication History 0citation0DownloadsMetricsTotal Citations0Total Downloads0Last 12 Months0Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Meikang Qiu, Ke Xu 0002, Cheng Zhang 0007, Tianwei Zhang 0004
ACM Trans. Sens. Networks2
2021 Try before You Buy: Privacy-preserving Data Evaluation on Cloud-based Machine Learning Data Marketplace
abstract
A cloud-based data marketplace provides a service to match data shoppers with appropriate data sellers, so that data shoppers can augment their internal data sets with external data to improve their machine learning (ML) models. Since data may contain diverse values, it is critical for a shopper to evaluate the most valuable data before making the final trade. However, evaluating ML data typically requires the cloud to access a shopper’s ML model and sellers’ data, which are both sensitive. None of the existing cloud-based data marketplaces enable ML data evaluation while preserving both model privacy and data privacy. In this paper, we develop a privacy-preserving ML data evaluation framework on a cloud-based data marketplace to protect shoppers’ ML models and sellers’ data. First, we provide a privacy-preserving framework that allows shoppers and sellers to encrypt their models and data, respectively, while preserving data functionality and model functionality in the cloud. We then develop a privacy-preserving data selection protocol that enables the cloud to help shoppers select the most valuable ML data. Also, we develop a privacy-preserving data validation protocol that allows shoppers to further check the quality of the selected data. Compared to random data selection, the experimental results show that our solution can reduce 60% prediction errors.
Qiyang Song, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002, Ke Xu 0002
ACSAC5
2021 Realtime Robust Malicious Traffic Detection via Frequency Domain Analysis
abstract
Machine learning (ML) based malicious traffic detection is an emerging security paradigm, particularly for zero-day attack detection, which is complementary to existing rule based detection. However, the existing ML based detection achieves low detection accuracy and low throughput incurred by inefficient traffic features extraction. Thus, they cannot detect attacks in realtime, especially in high throughput networks. Particularly, these detection systems similar to the existing rule based detection can be easily evaded by sophisticated attacks. To this end, we propose Whisper, a realtime ML based malicious traffic detection system that achieves both high accuracy and high throughput by utilizing frequency domain features. It utilizes sequential information represented by the frequency domain features to achieve bounded information loss, which ensures high detection accuracy, and meanwhile constrains the scale of features to achieve high detection throughput. In particular, attackers cannot easily interfere with the frequency domain features and thus Whisper is robust against various evasion attacks. Our experiments with 42 types of attacks demonstrate that, compared with the state-of-the-art systems, Whisper can accurately detect various sophisticated and stealthy attacks, achieving at most 18.36% improvement of AUC, while achieving two orders of magnitude throughput. Even under various evasion attacks, Whisper is still able to maintain around 90% detection accuracy.
Chuanpu Fu, Qi Li 0002, Meng Shen 0001, Ke Xu 0002
CCS4
2021 A Deep Reinforcement Learning-based Routing Scheme with Two Modes for Dynamic Networks
abstract
With the development of communication and transmission technologies, more and more applications, like Internet of vehicles and tele-medicine, become more sensitive to network latency and accuracy, which requires routing schemes to be more efficient. In order to meet such urgent need, learning-based routing strategies emerges, with the advantages of high flexibility and accuracy. These strategies can be divided into two categories, centralized and distributed, enjoying the advantages of high precision and high efficiency, respectively. However, routing become more complex in dynamic network, where the link connections and access states are time-varying, so these learning-based routing mechanisms are required to be able to adapt to network changes in real time. In this paper, we designed and implemented both two of centralized and distributed reinforcement learning-based routing schemes (RLR-T). By conducting a series of experiments, we deeply analyzed the results and gave the conclusion that the centralized is better to cope with dynamic networks due to its faster reconvergence, while the distributed is better to handle with large-scale networks by its high scalability.
Peizhuang Cong, Yuchao Zhang 0004, Wendong Wang 0003, Ke Xu 0002, Ruidong Li 0001, Fuliang Li
ICC4
2021 R-AQM: Reverse ACK Active Queue Management in Multi-tenant Data Centers
abstract
TCP incast has become a practical problem for high-bandwidth, low-latency transmissions, resulting in throughput degradation of up to 90% and delays of hundreds of milliseconds, severely impacting application performance. However, in virtualized multi-tenant data centers, host-based advancements in the TCP stack are hard to deploy from the operators perspective. Operators only provide infrastructure in the form of virtual machines, in which only tenants can directly modify the end-host TCP stack. In this paper, we present R-AQM, a switch-powered reverse ACK active queue management (R-AQM) mechanism for enhancing ACK-clocking effects through assisting legacy TCP. Specifically, R-AQM proactively intercepts ACKs and paces the ACK-clocked in-flight data packets, preventing TCP from suffering incast collapse. We implement and evaluate R-AQM in NS-3 simulation and NetFPGA-based hardware switch. Both simulation and testbed results show that R-AQM greatly improves TCP performance under heavy incast workloads by significantly lowering packet loss rate, reducing retransmission timeouts, and supporting 16 times (i.e., 60 → 1000) more senders. Meanwhile, the forward queuing delays are also reduced by 4.6 times.
Xinle Du, Tong Li 0014, Lei Xu 0019, Kai Zheng 0003, Meng Shen 0001, Bo Wu 0002, Ke Xu 0002
ICNP7
2021 FedPrune: Personalized and Communication-Efficient Federated Learning on Non-IID Data
Yang Liu 0038, Yi Zhao 0011, Guangmeng Zhou, Ke Xu 0002
ICONIP (5)4
2021 MASK: Practical Source and Path Verification based on Multi-AS-Key
abstract
The source and path verification in path-aware Internet consider the two critical issues: (1) end hosts could verify that their forwarding decisions followed by the network, (2) both intermediate routers and destination host could authenticate the source of packets and filter the malicious traffic. Unfortunately, the current verification mechanism requires validation operations in each router on the path in an inter-domain environment, thus requiring high communication and computation overhead, reducing its usefulness; besides, it is also difficult to meet the dynamic requirements of the end host. Ideally, the verification should be secure and provide the customized capability to meet the end host’s requirements. We propose a new mechanism called source and path verification based on Multi-AS-Key (MASK). Instead of each packet verified and marked at each router on the path, MASK improves the verification by empowering the end hosts to instruct the routers to achieve the verification, thus decreasing the router’s overhead while ensuring security performance to meet the end host’s requirements. With the plausible design, the communication overhead for realistic path lengths is 3–8 times smaller than the state-of-the-art mechanisms. The computation overhead in the routers is 2-5 times smaller. We implement our design in the BMv2 environment and commodity Barefoot Tofino programmable switch, demonstrating that MASK introduces significantly less overhead than the existing mechanisms.
Songtao Fu, Ke Xu 0002, Qi Li 0002, Xiaoliang Wang 0004, Su Yao, Yangfei Guo, Xinle Du
IWQoS2
2021 Efficient Fine-Grained Website Fingerprinting via Encrypted Traffic Analysis with Deep Learning
abstract
Fine-grained website fingerprinting (WF) enables potential attackers to infer individual webpages on a monitored website that victims are visiting, by analyzing the resulting traffic protected by security protocols such as TLS. Most existing studies focus on WF at the granularity of website, which takes website homepages as their representatives for fingerprinting. Fine-grained WF can reveal more user privacy, such as online purchasing habits and video-viewing interests, and can also be employed for web censorship. Due to striking similarly of webpages on a same website, it is still an open problem to conduct fine-grained WF in an accurate and time-efficient way.In this paper, we propose BurNet, a fine-grained WF method using Convolutional Neural Networks (CNNs). To extract differences of similar webpages, we propose a new concept named unidirectional burst, which is a sequence of packets corresponding to a piece of HTTP message. BurNet takes as input unidirectional burst sequences, instead of bidirectional packet sequences, which makes it applicable to local and remote attack scenarios. BurNet employs CNNs to build a powerful classifier, where sophisticated architecture is designed to improve classification accuracy while reducing time complexity in training. We collect real-world datasets from two well-known websites and conduct extensive experiments to evaluate the performance of BurNet. The closed-world evaluation results show that BurNet outperforms the state-of-the-art methods in both attack scenarios. In the more realistic open-world setting, BurNet can achieve 0.99 precision and 0.99 recall. BurNet is also superior to its CNN-based counterparts in terms of training efficiency.
Meng Shen 0001, Zhenbo Gao, Liehuang Zhu, Ke Xu 0002
IWQoS4
2021 Privacy-Preserving Approximate Top-k Nearest Keyword Queries over Encrypted Graphs
abstract
With the prosperity of graph-based applications, it is increasingly popular for graph nodes to have labels in terms of a set of keywords. The top-k nearest keyword (k-NK) query can find a set of k nearest nodes containing a designated keyword to a given source node. In cloud computing era, graph owners prefer to outsource their graphs to cloud servers, leading to severe privacy risk for conducting k-NK queries. The current studies fail to support efficient and accurate k-NK query under the premise of privacy protection.In this paper, we propose a new graph encryption scheme Aton, which enables efficient and privacy-preserving k-NK querying. Based on the symmetric-key encryption and particular pseudo-random functions, we construct a secure k-NK query index. Aton is built on a ciphertext sum comparison scheme which can achieve approximate distance comparison with high accuracy. Rigorous security analysis proves that it is CQA-2 secure. Experiments with real-world datasets demonstrate that it can efficiently answer k-NK queries with more accurate results compared with the state-of-the-art.
Meng Shen 0001, Ke Xu 0002, Liehuang Zhu
IWQoS3
2021 Demystifying the Relationship Between Network Latency and Mobility on High-Speed Rails: Measurement and Prediction
abstract
Recent years have seen increasing attention on building High-Speed Railways (HSR) in many countries. Trains running on the railways have a top velocity of up to over 300 km/hour. This makes it become a scenario with unstable connection qualities. In this paper, we propose a novel model that can accurately estimate the mobility status on HSR based on the changing patterns of network latency. Though various impact factors make the prediction complex, we however argue that the recent advance of deep learning applies well in our context, and further we design a neural network model that can estimate the moving velocity based on monitoring network latency’s changing patterns in a short period. In this model, we use a new variable called Round Difference Time (RDT) to describe latency’s changing patterns. We also use the Fourier Transform to extract the hidden time-frequency and use the generated spectrum for estimation. Our data-driven evaluations show that with suitable parameters, this model can get an accuracy of up to 94% on all three lines.
Jiangchuan Liu, Fangxin Wang 0001, Ke Xu 0002
IWQoS4
2021 AIR: An AI-based TCAM Entry Replacement Scheme for Routers
abstract
Ternary Content Addressable Memory (TCAM) is an important hardware used to store route entries in routers, which is used to assist routers to make fast decision on forwarding packets. In order to cope with the explosion of route entries due to massive IP terminals brought by 5G and the Internet of Things (IoT), today’s commercial TCAM has to keep the corresponding growth in capacity. But large TCAM capacity is causing many problems such as circuit design difficulties, production costs, and high energy consumption, so it is urgent to design a lightweight TCAM with small capacity while still maintains the original query performance.Designing such a TCAM faces two fundamental challenges. Firstly, it is essential to accurately predict the incoming flows in order to cache correct entries in limited TCAM capacity, but prediction on aggregated time-sequential data is challenging in the massive IoT scenarios. Secondly, the prediction algorithm needs to be real-time as the lookup process is in line-rate. In order to address the above two challenges, in this paper, we proposed a lightweight AI-based solution, called AIR, where we successfully decoupled the route entries and designed a parallel-LSTM prediction method. The experiment results under real backbone traffic showed that we successfully achieved comparable query performance by using just 1/8 TCAM size.
Yuchao Zhang 0004, Peizhuang Cong, Bin Liu 0001, Wendong Wang 0003, Ke Xu 0002
IWQoS5
2021 CRATES: A Cache Replacement Algorithm for Low Access Frequency Period in Edge Server
abstract
In recent years, with the maturity of 5G and Internet of Things technologies, the traffic in mobile network is growing explosively. To reduce the burden of cloud data centers and CDN network, edge servers that are closer to users are widely deployed, caching hot contents and providing higher Quality of Service (QoS) by shortening access latency. Storage resources on edge servers are much limited compared with CDN servers, so the research on cache replacement strategy of edge servers is critical to edge computing and storage area. Many efforts have been made to improve caching performance on edge servers. Existing caching strategies only focus on the high access frequency period to solve the caching problem, they ignore low access frequency period with two characteristics, including that hot contents are difficult to predict and hot topics usually change unstably, which makes it inefficient to improve the hit rate on edge servers.In this paper, we deeply analyzed the real traces from Chuang-Cache and found some specific user groups are playing more important roles than general users during low access frequency period, and the contents accessed by these specific user groups have a much higher possibility to become hot contents. Therefore, we firstly classify such users to core users, and treat others as common users. Then we adopt the principal component analysis algorithm to analyze the relationship between hot contents and core users. On this basis, we finally propose a hot contents pre-cache protection mechanism, which is a significant part of our cache replacement algorithm CRATES. To improve CRATES’s efficiency, we extract key part of historical data by designing a sliding window method. Through a series of experiments using real application data, we demonstrate that CRATES reaches about 98% in caching hit rate and outperforms the state-of-the-art algorithm LRB by 1.4X.
Pengmiao Li, Yuchao Zhang 0004, Huahai Zhang, Wendong Wang 0003, Ke Xu 0002
MSN5
2021 TAP: A Traffic-Aware Probabilistic Packet Marking for Collaborative DDoS Mitigation
abstract
In recent years, Distributed Denial-of-Service (DDoS) attacks have become more rampant and continue to be one of the most serious security threats facing network infrastructure. In a classic DDoS attack, the attacker controls numerous bots from many sources to send a significant volume of traffic to flood the victim end or the bottleneck link. In practical networks, it is inefficient and costly to request all partner routers to collaboratively mitigate DDoS attacks. The common feature of DDoS attacks is the abnormal distribution of traffic to the victim. In this paper, we propose TAP, a collaborative DDoS mitigation framework, based on traffic-aware probabilistic packet marking (PPM). TAP enables the victim to select a few hit routers as collaborators to mitigate attack traffic efficiently depending on the traffic distribution. Our evaluation results show that TAP greatly reduces attack traffic within seconds and mitigate the damage caused by DDoS with less overhead, which demonstrates that TAP is an effective, efficient, and rapid-response scheme for collaborative DDoS mitigation.
Mingxing Liu, Ying Liu 0024, Ke Xu 0002, Lin He 0004, Xiaoliang Wang 0004, Yangfei Guo, Weiyu Jiang
MSN3
2021 A deep reinforcement learning-based multi-optimality routing scheme for dynamic IoT networks
Peizhuang Cong, Yuchao Zhang 0004, Zheli Liu, Thar Baker, Hissam Tawfik, Wendong Wang 0003, Ke Xu 0002, Ruidong Li 0001, Fuliang Li
Comput. Networks7
2021 Exploiting Unintended Property Leakage in Blockchain-Assisted Federated Learning for Intelligent Edge Computing
abstract
Federated learning (FL) serves as an enabling technology for intelligent edge computing, where high-quality machine learning (ML) models are collaboratively trained over large amounts of data generated by various Internet of Things devices while preserving data privacy. To further provide data confidentiality, computation auditability, and participant incentives, the blockchain framework has been incorporated into FL. However, it is an open question whether the model updates from participants in blockchain-assisted FL can disclose properties of the private data the participants are unintended to share. In this article, we propose a novel property inference attack that exploits the unintended property leakage in blockchain-assisted FL for intelligent edge computing. More specifically, we present an active attack to learn the property leakage from model updates of participants and to identify a set of participants with a certain property. We also design a dynamic participant selection strategy tailored to the setting of large-scale FL, which accelerates the selection process of target participants and improves attack accuracy. We evaluate the proposed attack through extensive experiments with publicly available data sets. The experimental results demonstrate that the proposed attack is effective and efficient in inferring various properties of training data, while maintaining the high quality of the main tasks in FL.
Meng Shen 0001, Bin Zhang 0016, Liehuang Zhu, Ke Xu 0002, Qi Li 0002, Xiaojiang Du
IEEE Internet Things J.5
2021 MEC-Enabled Hierarchical Emotion Recognition and Perturbation-Aware Defense in Smart Cities
abstract
With the explosive growth of Internet of Things (IoT) devices and various emerging network technologies, IoT-enabled smart cities are further refined into health smart cities. For example, IoT devices can automatically recognize emotional states through collected facial expressions, which can further serve mental health assessment, human–computer interaction, etc. On the other hand, existing facial expression recognition algorithms emphasize the application of deep neural networks (DNNs), and it is difficult for resource-constrained IoT devices to provide sufficient computing resources to optimize parameters for DNN-based structures. To solve the challenge of resource constraints, we propose the hierarchical emotion recognition system enabled by mobile edge computing (MEC). Specifically, MEC nodes provide IoT devices with short-delay and high-performance computing services, satisfying the requirements of training DNN-based algorithms. Moreover, our proposed emotion recognition system leverages a pretrained feature extraction module on the remote cloud to accelerate optimization and provides a localization module for specific tasks of IoT devices. In addition to evaluating the accuracy and efficiency, we also clarify that the DNN-based emotion recognition system exposes obvious vulnerability to perturbation. Due to the uncertainty of the environment, it is common for facial expressions collected by IoT devices to be accompanied by perturbation. To address this issue, we propose the proactive perturbation-aware defense mechanism. It has been demonstrated that the newly proposed defense mechanism can maintain state-of-the-art performance on the publicly available LIRIS-CSE dataset while defending against known and unknown perturbation. This can promote the deployment of our proposed MEC-enabled hierarchical emotion recognition system and defense mechanism in real-world scenarios.
Yi Zhao 0011, Ke Xu 0002, Bo Li 0026, Meina Qiao, Haobin Shi
IEEE Internet Things J.2
2021 Effective and Robust Physical-World Attacks on Deep Learning Face Recognition Systems
abstract
Deep neural networks (DNNs) have been increasingly used in face recognition (FR) systems. Recent studies, however, show that DNNs are vulnerable to adversarial examples, which potentially mislead DNN-based FR systems in the physical world. Existing attacks either generate perturbations working merely in the digital world, or rely on customized equipment to generate perturbations that are not robust in the ever-changing physical environment. In this paper, we propose FaceAdv, a physical-world attack that crafts adversarial stickers to deceive FR systems. It mainly consists of a sticker generator and a convertor, where the former can craft several stickers with different shapes while the latter aims to digitally attach stickers to human faces and provide feedback to the generator to improve the effectiveness. We conduct extensive experiments to evaluate the effectiveness of FaceAdv on attacking three typical FR systems (i.e., ArcFace, CosFace and FaceNet). The results show that compared with a state-of-the-art attack, FaceAdv can significantly improve the success rates of both dodging and impersonating attacks. We also conduct comprehensive evaluations to demonstrate the robustness of FaceAdv.
Meng Shen 0001, Hao Yu 0017, Liehuang Zhu, Ke Xu 0002, Qi Li 0002, Jiankun Hu
IEEE Trans. Inf. Forensics Secur.4
2021 Accurate Decentralized Application Identification via Encrypted Traffic Analysis Using Graph Neural Networks
abstract
Decentralized Applications (DApps) are increasingly developed and deployed on blockchain platforms such as Ethereum. DApp fingerprinting can identify users' visits to specific DApps by analyzing the resulting network traffic, revealing much sensitive information about the users, such as their real identities, financial conditions and religious or political preferences. DApps deployed on the same platform usually adopt the same communication interface and similar traffic encryption settings, making the resulting traffic less discriminative. Existing encrypted traffic classification methods either require hand-crafted and fine-tuning features or suffer from low accuracy. It remains a challenging task to conduct DApp fingerprinting in an accurate and efficient way. In this paper, we present GraphDApp, a novel DApp fingerprinting method using Graph Neural Networks (GNNs). We propose a graph structure named Traffic Interaction Graph (TIG) as an information-rich representation of encrypted DApp flows, which implicitly reserves multiple dimensional features in bidirectional client-server interactions. Using TIG, we turn DApp fingerprinting into a graph classification problem and design a powerful GNN-based classifier. We collect real-world traffic datasets from 1,300 DApps with more than 169,000 flows. The experimental results show that GraphDApp is superior to the other state-of-the-art methods in terms of classification accuracy in both closed- and open-world scenarios. In addition, GraphDApp maintains its high accuracy when being applied to the traditional mobile application classification.
Meng Shen 0001, Liehuang Zhu, Ke Xu 0002, Xiaojiang Du
IEEE Trans. Inf. Forensics Secur.4
2021 Revisiting Acknowledgment Mechanism for Transport Control: Modeling, Analysis, and Implementation
abstract
The shared nature of the wireless medium induces contention between data transport and backward signaling, such as acknowledgment. The current way of TCP acknowledgment induces control overhead which is counter-productive for TCP performance especially in wireless local area network (WLAN) scenarios. In this paper, we present a new acknowledgment called TACK (“Tame ACK”), as well as its TCP implementation TCP-TACK. TACK seeks to minimize ACK frequency, which is exactly what is required by transport. TCP-TACK works on top of commodity WLAN, delivering high wireless transport goodput with minimal control overhead in the form of ACKs, without any hardware modification. Evaluation results show that TCP-TACK achieves significant advantages over legacy TCP in WLAN scenarios due to less contention between data packets and ACKs. Specifically, TCP-TACK reduces over 90% of ACKs and also obtains an improvement of up to 28% on goodput. A TACK-based protocol is a good replacement of the legacy TCP to compensate for scenarios where the acknowledgment overhead is non-negligible.
Tong Li 0014, Kai Zheng 0003, Ke Xu 0002, Rahul Arvind Jadhav, Keith Winstein, Kun Tan 0002
IEEE/ACM Trans. Netw.3
2021 BDS+: An Inter-Datacenter Data Replication System With Dynamic Bandwidth Separation
abstract
Many important cloud services require replicating massive data from one datacenter (DC) to multiple DCs. While the performance of pair-wise inter-DC data transfers has been much improved, prior solutions are insufficient to optimize bulk-data multicast, as they fail to explore the rich inter-DC overlay paths that exist in geo-distributed DCs, as well as the remaining bandwidth reserved for online traffic under fixed bandwidth separation scheme. To take advantage of these opportunities, we present BDS+, a near-optimal network system for large-scale inter-DC data replication. BDS+ is an application-level multicast overlay network with a fully centralized architecture, allowing a central controller to maintain an up-to-date global view of data delivery status of intermediate servers, in order to fully utilize the available overlay paths. Furthermore, in each overlay path, it leverages dynamic bandwidth separation to make use of the remaining available bandwidth reserved for online traffic. By constantly estimating online traffic demand and rescheduling bulk-data transfers accordingly, BDS+ can further speed up the massive data multicast. Through a pilot deployment in one of the largest online service providers and large-scale real-trace simulations, we show that BDS+ can achieve 3- 5× speedup over the provider's existing system and several well-known overlay routing baselines of static bandwidth separation. Moreover, dynamic bandwidth separation can further reduce the completion time of bulk data transfers by 1.2 to 1.3 times.
Yuchao Zhang 0004, Xiaohui Nie, Junchen Jiang, Wendong Wang 0003, Ke Xu 0002, Youjian Zhao, Martin J. Reed, Kai Chen 0005, Guang Yao
IEEE/ACM Trans. Netw.5
2020 Off-Path TCP Exploits of the Mixed IPID Assignment
abstract
In this paper, we uncover a new off-path TCP hijacking attack that can be used to terminate victim TCP connections or inject forged data into victim TCP connections by manipulating the new mixed IPID assignment method, which is widely used in Linux kernel version 4.18 and beyond to help defend against TCP hijacking attacks. The attack has three steps. First, an off-path attacker can downgrade the IPID assignment for TCP packets from the more secure per-socket-based policy to the less secure hash-based policy, building a shared IPID counter that forms a side channel on the victim. Second, the attacker detects the presence of TCP connections by observing the shared IPID counter on the victim. Third, the attacker infers the sequence number and the acknowledgment number of the detected connection by observing the side channel of the shared IPID counter. Consequently, the attacker can completely hijack the connection, i.e., resetting the connection or poisoning the data stream. We evaluate the impacts of this off-path TCP attack in the real world. Our case studies of SSH DoS, manipulating web traffic, and poisoning BGP routing tables show its threat on a wide range of applications. Our experimental results show that our off-path TCP attack can be constructed within 215 seconds and the success rate is over 88%. Finally, we analyze the root cause of the exploit and develop a new IPID assignment method to defeat this attack. We prototype our defense in Linux 4.18 and confirm its effectiveness through extensive evaluation over real applications on the Internet.
Xuewei Feng, Chuanpu Fu, Qi Li 0002, Kun Sun 0001, Ke Xu 0002
CCS5
2020 Auction-based High Timeliness Data Pricing under Mobile and Wireless Networks
abstract
Data is the cornerstone of intelligent algorithms such as deep learning, and the explosive development of mobile and wireless networks has prompted more devices to share data in time via the Internet. Meanwhile, data is highly time sensitive. It has been found that the value of data is becoming more and more critical to any application areas, significantly highlighting the importance of data pricing mechanisms in data transactions. Although traditional auction mechanisms for ordinary commodities are gradually becoming matures, they fail in the high timeliness data pricing market due to the following key challenges: Firstly, the value and price of the high timeliness data is ever changing with time, making existing mechanisms with fixed prices expired. Secondly, the price changing of such data is uncertain and dynamic, requiring the auction mechanisms to work stably under different price variations of the high timeliness data. To address these challenges, we for the first time innovatively propose an efficient auction mechanism for High Timeliness Data Pricing, namely HTDP. The newly proposed HTDP can maximize the profit of auctioneer in the high timeliness data transactions. And the key factor for HTDP's success is the consideration of the price changing in the high timeliness data, which fills the blank of traditional auction mechanisms in this area. We further evaluate the newly proposed HTDP on the overall auction profit, and compare the results with the benchmark. Experimental results demonstrate that HTDP not only achieves high profit under proper settings, but also is stable and efficient.
Yi Zhao 0011, Ke Xu 0002, Yuchao Zhang 0004
ICC2
2020 Relation-Aware Transformer for Portfolio Policy Learning
abstract
Portfolio selection is an important yet challenging task in AI for FinTech. One of the key issues is how to represent the non-stationary price series of assets in a portfolio, which is important for portfolio decisions. The existing methods, however, fall short of capturing: 1) the complicated sequential patterns for asset price series and 2) the price correlations among multiple assets. In this paper, under a deep reinforcement learning paradigm for portfolio selection, we propose a novel Relation-aware Transformer (RAT) to handle these aspects. Specifically, being equipped with our newly developed attention modules, RAT is structurally innovated to capture both sequential patterns and asset correlations for portfolio selection. Based on the extracted sequential features, RAT is able to make profitable portfolio decisions regarding each asset via a newly devised leverage operation. Extensive experiments on real-world crypto-currency and stock datasets verify the state-of-the-art performance of RAT.
Ke Xu 0002, Yifan Zhang 0004, Deheng Ye, Peilin Zhao, Mingkui Tan
IJCAI1
2020 Analysis, Modeling, and Implementation of Publisher-side Ad Request Filtering
abstract
Online advertising has been a great driving force for the Internet industry. To maintain a steady growth of advertising revenue, advertisement (ad) publishers have made great efforts to increase the impressions as well as the conversion rate. However, we notice that the results of these efforts are not as good as expected. In detail, to show more ads to the consumers, publishers have to waste a significant amount of server resources to process the ad requests that do not result in consumers' clicks. On the other hand, the increasing ads are also impacting the browsing experience of the consumers. In this paper, we explore the opportunity to improve publishers' overall utility by handling a selective number of requests on ad servers. Particularly, we propose a publisher-side proactive ad request filtration solution Win2. Upon receiving an ad request, Win2 estimates the probability that the consumer will click if serving it. The ad request will be served if the clicking probability is above a dynamic threshold. Otherwise, it will be filtered to reduce the publisher's resource cost and improve consumer experience. We implement Win2 in a large-scale ad serving system and the evaluation results confirm its effectiveness.
Ke Xu 0002, Meng Shen 0001, Yi Zhao 0011, Guanhui Geng
INFOCOM2
2020 DeepQoE: Real-time Measurement of Video QoE from Encrypted Traffic with Deep Learning
abstract
With the dramatic increase of video traffic on the Internet, video quality of experience (QoE) measurement becomes even more important, which provides network operators with an insight into the quality of their video delivery services. The widespread adoption of end-to-end encryption protocols such as SSL/TLS, however, sets a barrier to QoE monitoring as the most valuable indicators in cleartext traffic are no longer available after encryption. Existing studies on video QoE measurement in encrypted traffic support only coarse-grained QoE metrics or suffer from low accuracy. In this paper, we propose DeepQoE, a new approach that enables real-time video QoE measurement from encrypted traffic. We summarize critical fine-grained QoE metrics, including startup delay, rebuffering, and video resolutions. In order to achieve accurate and real-time inference of these metrics, we build DeepQoE by employing Convolutional Neural Networks (CNNs) with a sophisticated input and architecture design. More specifically, DeepQoE only leverages packet Round-Trip Time (RTT) in upstream traffic as its input. Evaluation results with real-world datasets collected from two popular content providers (i.e., YouTube and Bilibili) show that DeepQoE can improve QoE measurement accuracy by up to 22% over the state-of-the-art methods.
Meng Shen 0001, Ke Xu 0002, Liehuang Zhu, Jiangchuan Liu, Xiaojiang Du
IWQoS3
2020 I Know If the Journey Changes: Flexible Source and Path Validation
abstract
No matter from the perspective of detection or defense, source and path validations are fundamentally primitive in constructing security mechanisms to greatly enhance network immunity in the face of malicious attacks, such as injection, traffic hijacking and hidden threats. However, existing works for source and path verification still impose a non-trivial operational overhead and lack adjustment capability for path dynamic changes. In this paper, we propose a flexible and convenient source and path validation protocol called PSVM, which uses an authentication structure PIC composed of ordered pieces to carry out packet verification. Specifically, in the basic PSVM protocol, PIC (related to cryptographic computation) in the packet header does not require any update during packet verification, which thus enables a lower processing overhead in routers. To cope with the challenge of path policy changes in the running protocol, the dynamic PSVM protocol supports controllable adjustment and migration, especially in the case of avoiding a malicious node or region. Our evaluation of a prototype experiment on Click demonstrates that the verification efficiency of PSVM is barely influenced by payload size or path length. Compared to the baseline of normal IP routing, the throughput reduction ratio of the basic PSVM is about 13%, which is much better than 28% of existing best solution Origin and Path Trace (OPT). In addition, for a 35-hop path with 30 pieces of PIC needed to be adjusted in dynamic PSVM, the throughput reduction ratio of routing cross node performing the adjustment operation after normal verification is only 2.4 %.
Ke Xu 0002, Qi Li 0002, Rongxing Lu, Bo Wu 0002, Yi Zhao 0011, Meng Shen 0001
IWQoS2
2020 NoPTPeer: Protecting Android Devices from Stealthy Spoofing and Stealing in WLANs without Privilege
abstract
Android devices are prone to spoofing attacks in Wireless Local Area Networks (WLANs), and many of them access numerous unknown networks in daily use. Moreover, because of the weak authentication between Android smartphones, attackers can steal data in a stealthier way based on Address Resolution Protocol (ARP) spoofing. These facts bring a gap in the study of device-side spoofing defense for Android devices. So in this paper a framework is proposed which requires No Privilege but can guarantee the True identity of Peers (NoPTPeer), to protect Android's device-to-device communication in WLANs. Its main features include realizing strong authentication between Android devices, controlling dangerous outgoing connections, and monitoring suspicious incoming connections. These features are realized by an Identity-Based-Signature (IBS) scheme, an Android base class VpnService, and information read from Android system files, which all require no root privilege and are independent of network infrastructures. We implement this framework as an Android smartphone application. The experiments show its effectiveness in detecting spoofing and monitoring stealing, as well as acceptable overhead in memory, Central Processing Unit (CPU) usage and communication latency.
Shuying Wei, Xiaoliang Wang 0004, Ke Xu 0002
MSN3
2020 TACK: Improving Wireless Transport Performance by Taming Acknowledgments
abstract
The shared nature of the wireless medium induces contention between data transport and backward signaling, such as acknowledgement. The current way of TCP acknowledgment induces control overhead which is counter-productive for TCP performance especially in wireless local area network (WLAN) scenarios.
Tong Li 0014, Kai Zheng 0003, Ke Xu 0002, Rahul Arvind Jadhav, Keith Winstein, Kun Tan 0002
SIGCOMM3
2020 Incentive mechanisms for mobile data offloading through operator-owned WiFi access points
Yi Zhao 0011, Ke Xu 0002, Yifeng Zhong, Xiang-Yang Li 0001, Ning Wang 0001, Hui Su, Meng Shen 0001
Comput. Networks2
2020 Congestion avoidance transmission mechanism based on two-dimensional forwarding
Heyang Chen, Chengan Zhao, Mingwei Xu 0001, Ke Xu 0002, Yingya Guo
Future Gener. Comput. Syst.6
2020 Guest Editorial Special Issue on Trust-Oriented Designs of Internet of Things for Smart Cities
abstract
The Internet of Things (IoT) offers new opportunities for cities to make citizens live and work in more sustainable, healthy, and safe places. Since IoT applications in smart cities are characterized by different devices, networking standards, and data management strategies, trust becomes a fundamental issue in the IoT ecosystem. The explosion of IoT devices, along with their decentralized deployment, constraint resources, limited computational and cryptographic capabilities, brings challenges to trust management in IoT. The coexistence of multiple IoT domains also raises challenges, for example, how to evaluate and maintain trust across domain boundaries. This special issue aims at bringing the researchers from both academia and industry together to disseminate their recent advances related to the challenges and solutions in building trustful IoT for smart cities.
Meng Shen 0001, Ke Xu 0002, Xiaojiang Du, Martin J. Reed, Md. Zakirul Alam Bhuiyan, Rashid Mijumbi
IEEE Internet Things J.2
2020 Blockchain-Assisted Secure Device Authentication for Cross-Domain Industrial IoT
abstract
Industrial Internet of Things (IIoT) is considered as one of the most promising revolutionary technologies to prompt smart manufacturing and increase productivity. With manufacturing being more complicated and sophisticated, an entire manufacturing process usually involves several different administrative IoT domains (e.g., factories). Devices from different domains collaborate on the same task, which raises great security and privacy concerns about device-to-device communications. Existing authentication approaches may result in heavy key management overhead or rely on a trusted third party. Thus, security and privacy issues during communication remain unsolved but imperative. In this paper, we present an efficient block-chain-assisted secure device authentication mechanism BASA for cross-domain IIoT. Specifically, consortium blockchain is introduced to construct trust among different domains. Identity-based signature (IBS) is exploited during the authentication process. To preserve the privacy of devices, we design an identity management mechanism, which can realize that devices being authenticated remain anonymous. Besides, session keys between two parties are negotiated, which can secure the subsequent communications. Extensive experiments have been conducted to show the effectiveness and efficiency of the proposed mechanism.
Meng Shen 0001, Huisen Liu, Liehuang Zhu, Ke Xu 0002, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.4
2020 Understand Love of Variety in Wireless Data Market Under Sponsored Data Plans
abstract
Sponsored Data Plan (SDP) is an emerging pricing model for the wireless data market where the Content Provider (CP) can sponsor the data usage for specific content on behalf of the users. This strategy sheds new light on the data pricing model and receives significant attention from the Internet Service Provider (ISP). However, the existing SDP studies consider traffic price (e.g., sponsorship) as the only factor that affects user decision. The impact of other classic market features, such as the demand for a variety of contents (i.e., love of variety), remains largely unclear. In this paper, we develop a new model to understand the love of variety in the wireless data market under SDPs. Our model has demonstrated that, such variety is important to understand the complex gaming between ISPs, CPs, and users in both short-run and long-run markets. For example, the analysis indicates that the advantage of CPs with higher revenue will be significantly reduced when users have a greater love of variety. Moreover, to help the ISP better adopt the proposed model in the real market, we also develop a practical method to calibrate the related parameters, which can also be applied to quantity the love of variety.
Yi Zhao 0011, Hui Su, Liang Zhang 0042, Rui Zhang 0017, Dan Wang 0002, Ke Xu 0002
IEEE J. Sel. Areas Commun.7
2020 Fine-grained Dynamic Price Prediction in Ride-on-demand Services: Models and Evaluations
Suiming Guo, Chao Chen 0004, Jingyuan Wang 0001, Yaxiao Liu, Ke Xu 0002, Dah-Ming Chiu
Mob. Networks Appl.5
2020 An Efficient and Compacted DAG-Based Blockchain Protocol for Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) has been widely used in many fields. Meanwhile, blockchain is considered promising to address the issues of the IIoT. However, the current blockchains have a limited throughput. In this article, we devise an efficient and secure blockchain protocol compacted directed acyclic graph (CoDAG) based on a compacted directed acyclic graph, where blocks are organized in levels and width. New-generated blocks in the CoDAG will be placed appropriately and point to those in the previous level, making it a well-connected channel. Transactions in the network will be confirmed in a deterministic period, and the CoDAG keeps a simple data structure at the same time. We also illustrate the attack strategies by adversary, and it is proved that our protocols are resistant to these attacks. Furthermore, we design a CoDAG-based IIoT architecture to improve the efficiency of the IIoT system. Experimental results show that the CoDAG achieves 164× Bitcoin's throughput and 77× Ethererum's throughput.
Laizhong Cui, Shu Yang 0002, Ziteng Chen, Yi Pan 0001, Mingwei Xu 0001, Ke Xu 0002
IEEE Trans. Ind. Informatics6
2020 ROD-Revenue: Seeking Strategies Analysis and Revenue Prediction in Ride-on-Demand Service Using Multi-Source Urban Data
abstract
Recent years have witnessed the rapidly-growing business of ride-on-demand (RoD) services such as Uber, Lyft and Didi. Unlike taxi services, these emerging transportation services use dynamic pricing to manipulate the supply and demand, and to improve service responsiveness and quality. Despite this, on the drivers' side, dynamic pricing creates a new problem: how to seek for passengers in order to earn more under the new pricing scheme. Seeking strategies have been studied extensively in traditional taxi service, but in RoD service such studies are still rare and require the consideration of more factors such as dynamic prices, the status of other transportation services, etc. In this paper, we develop ROD-Revenue, aiming to mine the relationship between driver revenue and factors relevant to seeking strategies, and to predict driver revenue given features extracted from multi-source urban data. We extract basic features from multiple datasets, including RoD service, taxi service, POI information, and the availability of public transportation services, and then construct composite features from basic features in a product-form. The desired relationship is learned from a linear regression model with basic features and high-dimensional composite features. The linear model is chosen for its interpretability-to quantitatively explain the desired relationship. Finally, we evaluate our model by predicting drivers' revenue. We hope that ROD-Revenue not only serves as an initial analysis of seeking strategies in RoD service, but also helps increasing drivers' revenue by offering useful guidance.
Suiming Guo, Chao Chen 0004, Jingyuan Wang 0001, Yaxiao Liu, Ke Xu 0002, Zhiwen Yu 0001, Daqing Zhang 0001, Dah-Ming Chiu
IEEE Trans. Mob. Comput.5
2020 Minimizing Tardiness for Data-Intensive Applications in Heterogeneous Systems: A Matching Theory Perspective
abstract
The increasing data requirements of Internet applications have driven a dramatic surge in developing new programming paradigms and complex scheduling algorithms to handle data-intensive workloads. Due to the expanding volume and the variety of such flows, their raw data are often processed on Intermediate Processing Nodes (IPNs) before being sent to servers. However, the intermediate processing constraint is rarely considered in existing flow computing models. This paper aims to minimize the tardiness of data-intensive applications in the presence of intermediate processing constraint. Motivating cases show that the tardiness is affected by both IPN locations and flow dispatching strategies. Based on the observation that dispatching flows to IPNs is essentially building a matching between flows and IPNs, a novel solution is proposed based on matching theory. In the deployment phase, a tardiness-aware deferred acceptance algorithm is developed to optimize IPN locations. In the operation phase, the Power-of-D paradigm and matching theory are combined together to dispatch flows efficiently. Evaluation results show that our solution effectively minimizes the total tardiness of data-intensive applications in heterogeneous systems.
Ke Xu 0002, Tong Li 0014, Meng Shen 0001, Kun Yang 0001
IEEE Trans. Parallel Distributed Syst.1
2019 Privacy-Preserving Graph Encryption for Approximate Constrained Shortest Distance Queries
abstract
Constrained shortest distance (CSD) queries are a valuable extension of the traditional pairwise shortest distance computation over graph-structured data, where the answers to the queries should fulfill a cost constraint (e.g., the toll payment in road networks). With the popularity of cloud computing, data owners have a strong desire to migrate their privacy-sensitive graphs to remote servers without losing the ability to query them. Existing graph encryption schemes cannot provide security guarantees for CSD queries. In this paper, we present Acro, a graph encryption scheme, which executes approximate CSD queries securely. The homomorphic encryption and the symmetric-key primitives are applied to our scheme. Through a security analysis, we prove that Acro meets the security definition of CQA2-security. The prototype of Acro is implemented and evaluated using real datasets. The results show that our proposal outperforms a state-of-the-art baseline in terms of query accuracy at the cost of enlarging query completion time.
Meng Shen 0001, Liehuang Zhu, Renyi Xiao, Ke Xu 0002, Xiaojiang Du
GLOBECOM5
2019 SmartCrowd: Decentralized and Automated Incentives for Distributed IoT System Detection
abstract
Internet of Things (IoT) devices achieve the rapid development and have been widely deployed recently. Meanwhile, inherent vulnerabilities of IoT systems (including firmware and software) have been continually uncovered and thus the systems are always exposed to various attacks. The root cause of the issue is that IoT systems always have design flaws and implementation bugs. In particular, the released systems (e.g., by third-party marketplaces and IoT vendors) may be maliciously repackaged with malware. Unfortunately, IoT consumers are not able to effectively capture such vulnerabilities because of the limited detection capabilities. In this paper, we propose SmartCrowd, a blockchain-based platform that aims to outsource security detection of IoT systems to distributed detectors with strong detection incentives. SmartCrowd enables built-in accountability for IoT providers and authoritative references of detection results for IoT consumers. By building smart contracts, we can incentivize the efficient and high-coverage security detection of IoT systems, while providing decentralized and automated incentives for both IoT providers releasing secure IoT systems and detectors uncovering vulnerabilities. We present the security and theoretical analysis that demonstrates the security of SmartCrowd and the incentives for participators. We prototype SmartCrowd by using Ethereum and the experimental results show that SmartCrowd has both technical feasibility and financial benefits, which can be applied to build a secure IoT ecosystem.
Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Zhuotao Liu, Yih-Chun Hu, Xinle Du, Bingyang Liu, Shoushou Ren
ICDCS2
2019 TDFI: Two-stage Deep Learning Framework for Friendship Inference via Multi-source Information
abstract
Due to the explosive growth of social network services, friendship inference has been widely adopted by Online Social Service Providers (OSSPs) for friend recommendation. The conventional techniques, however, have limitations in accuracy or scalability to handle such a large yet sparse multi-source data. For example, the OSSPs will be required to manually give the order in which the various information is applied. This unavoidably reduces the applicability of existing friend recommendation systems. To address this issue, we propose a Two-stage Deep learning framework for Friendship Inference (TDFI). This approach can utilize multi-source information simultaneously with low complexity. In particular, we apply an Extended Adjacency Matrix (EAM) to represent the multi-source information. We then adopt an improved Deep AutoEncoder Network (iDAEN) to extract the fused feature vector for each user. The TDFI framework also provides an improved Deep Siamese Network (iDSN) to measure user similarity from iDAEN. Finally, we evaluate the effectiveness and robustness of TDFI on three large-scale real-world datasets. It shows that TDFI can effectively handle the sparse multi-source data while providing better accuracy for friend recommendation.
Yi Zhao 0011, Meina Qiao, Rui Zhang 0017, Dan Wang 0002, Ke Xu 0002, Qi Tan 0003
INFOCOM6
2019 Exploring the Influence of News Articles on Bitcoin Price with Machine Learning
abstract
In recent years, cryptocurrencies have become more and more popular around the world, and they are being accepted and used by more countries. Cryptocurrencies are decentralized, and they form an emerging market that is different from stocks. At present, there is already much work around the stock price prediction using news articles, but there are few papers on the cryptocurrency market. In this paper, we aim to research the effects of news articles on bitcoin prices. We extract features from news articles with both commonly used text feature extraction algorithms (e.g., N-Gram and TF-IDF) and SentiGraph, which is a novel text representation method we propose. SentiGraph takes advantages of sentiment analysis and transforms a news article into a graph. Compared with previous feature extraction methods, our experiment results show that this new approach is superior on the prediction accuracy, which also demonstrates the impacts of news articles on the bitcoin price.
Wenbing Yao, Ke Xu 0002, Qi Li 0002
ISCC2
2019 Encrypted traffic classification of decentralized applications on ethereum using feature fusion
abstract
With the prevalence of blockchain, more and more Decentralized Applications (DApps) are deployed on Ethereum to achieve the goal of communicating without supervision. Users habits may be leaked while these applications adopt SSL/TLS to encrypt their transmission data. Encrypted protocol and the same blockchain platform bring challenges to the traffic classification of DApps. Existing encrypted traffic classification methods suffer from low accuracy in the situation of DApps.
Meng Shen 0001, Liehuang Zhu, Ke Xu 0002, Xiaojiang Du
IWQoS4
2019 Variety matters: a new model for the wireless data market under sponsored data plans
abstract
In this paper, we develop a new model to study the competition among Content Providers (CPs) under Sponsored Data Plans (SDPs). SDP is an emerging pricing model for the wireless data market where Internet Service Providers (ISPs) allow a CP to compensate the traffic volume of users when users access the contents of this CP. Studies have shown that SDPs create a triple-win situation, where users consume more contents and the revenue of both CPs and ISPs increases. Currently, a main concern of SDPs is on whether SDPs may bring about unfair competition among CPs. Studies have shown that big CPs have an advantage over small CPs. We observe that such conclusions are derived because in all previous models, traffic price is the only factor that affects user decisions. We argue that it is not precise. Nowadays, people conduct a large variety of activities online, and users have an intrinsic demand for a variety of contents. To reflect this, we for the first time characterize the variety demand as an intrinsic parameter of users, and integrate such variety into a new model to help us drive some novel insights into SDPs, especially the competition among CPs. Our model shows that variety matters for understanding SDPs more thoroughly and comprehensively. For example, under SDPs, the advantage of CPs with higher revenue will be significantly reduced if users have a greater love for variety. Overall, our new model leads to a set of completely new results and rectifies some past conclusions.
Yi Zhao 0011, Hui Su, Liang Zhang 0042, Dan Wang 0002, Ke Xu 0002
IWQoS5
2019 RFL: Robust fault localization on unreliable communication channels
Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Bingyang Liu, Shoushou Ren, Meng Shen 0001, Kui Ren 0001
Comput. Networks2
2019 Secure Phrase Search for Intelligent Processing of Encrypted Data in Cloud-Based IoT
abstract
Phrase search allows retrieval of documents containing an exact phrase, which plays an important role in many machine learning applications for cloud-based Internet of Things (IoT), such as intelligent medical data analytics. In order to protect sensitive information from being leaked by service providers, documents (e.g., clinic records) are usually encrypted by data owners before being outsourced to the cloud. This, however, makes the search operation an extremely challenging task. Existing searchable encryption schemes for multikeyword search operations fail to perform phrase search, as they are unable to determine the location relationship of multiple keywords in a queried phrase over encrypted data on the cloud server side. In this paper, we propose P3, an efficient privacy-preserving phrase search scheme for intelligent encrypted data processing in cloud-based IoT. Our scheme exploits the homomorphic encryption and bilinear map to determine the location relationship of multiple queried keywords over encrypted data. It also utilizes a probabilistic trapdoor generation algorithm to protect users' search patterns. Thorough security analysis demonstrates the security guarantees achieved by P3. We implement a prototype and conduct extensive experiments on real-world datasets. The evaluation results show that compared with existing multikeyword search schemes, P3 can greatly improve the search accuracy with moderate overheads.
Meng Shen 0001, Bao-Li Ma 0002, Liehuang Zhu, Xiaojiang Du, Ke Xu 0002
IEEE Internet Things J.5
2019 Communication-Aware Container Placement and Reassignment in Large-Scale Internet Data Centers
abstract
Containerization has been used in many applications for isolation purposes due to its lightweight, scalable, and highly portable properties. However, to apply containerization in large-scale Internet data centers faces a big challenge. Services in data centers are always instantiated as a group of containers, which often generate heavy communication workloads and therefore resulting in inefficient communications and downgraded service performance. Although assigning the containers of the same service to the same server can reduce the communication overhead, this may cause heavily imbalanced resource utilization since containers of the same service are usually intensive to the same resource. To reduce communication cost as well as balance the resource utilization in large-scale data centers, we further explore the container distribution issues in a real industrial environment and find that such conflict lies in two phases-container placement and container reassignment. The objective of this paper is to address the container distribution problem in these two phases. For the container placement problem, we propose an efficient communication aware worst fit decreasing algorithm to place a set of new containers into data centers. For the container reassignment problem, we propose a two-stage algorithm called Sweep&Search to optimize a given initial distribution of containers by migrating containers among servers. We implement the proposed algorithms in Baidu's data centers and conduct extensive evaluations. Compared with the state-of-the-art strategies, the evaluation results show that our algorithms perform better up to 70% and increase the overall service throughput up to 90% simultaneously.
Yuchao Zhang 0004, Yusen Li, Ke Xu 0002, Dan Wang 0002, Wendong Wang 0003, Xuan Cao, Qingqing Liang
IEEE J. Sel. Areas Commun.4
2019 Guest Editorial: Smart Grid Inspired Data Sensing, Processing and Networking Technologies
Jia Hu 0001, Kun Yang 0001, Victor C. M. Leung, Ke Xu 0002
Mob. Networks Appl.4
2018 BDS: a centralized near-optimal overlay network for inter-datacenter data replication
abstract
Many important cloud services require replicating massive data from one datacenter (DC) to multiple DCs. While the performance of pair-wise inter-DC data transfers has been much improved, prior solutions are insufficient to optimize bulk-data multicast, as they fail to explore the capability of servers to store-and-forward data, as well as the rich inter-DC overlay paths that exist in geo-distributed DCs. To take advantage of these opportunities, we present BDS, an application-level multicast overlay network for large-scale inter-DC data replication. At the core of BDS is a fully centralized architecture, allowing a central controller to maintain an up-to-date global view of data delivery status of intermediate servers, in order to fully utilize the available overlay paths. To quickly react to network dynamics and workload churns, BDS speeds up the control algorithm by decoupling it into selection of overlay paths and scheduling of data transfers, each can be optimized efficiently. This enables BDS to update overlay routing decisions in near realtime (e.g., every other second) at the scale of multicasting hundreds of TB data over tens of thousands of overlay paths. A pilot deployment in one of the largest online service providers shows that BDS can achieve 3-5 x speedup over the provider's existing system and several well-known overlay routing baselines.
Yuchao Zhang 0004, Junchen Jiang, Ke Xu 0002, Xiaohui Nie, Martin J. Reed, Guang Yao, Kai Chen 0005
EuroSys3
2018 Enabling Efficient Source and Path Verification via Probabilistic Packet Marking
abstract
The Internet lacks verification of source authenticity and path compliance between the planned packet delivery paths and the real delivery paths, which allows attackers to construct attacks like source spoofing and traffic hijacking attacks. Thus, it is essential to enable source and path verification in networks to detect forwarding anomalies and ensure correct packet delivery. However, most of the existing security mechanisms can only capture anomalies but are unable to locate the detected anomalies. Besides, they incur significant computation and communication overhead, which exacerbates the packet delivery performance. In this paper, we propose a high-efficient packet forwarding verification mechanism called PPV for networks, which verifies packet source and their forwarding paths in real time. PPV enables probabilistic packet marking in routers instead of verifying all packets. Thus, it can efficiently identify forwarding anomalies by verifying markings. Moreover, it localizes packet forwarding anomalies, e.g., malicious routers, by reconstructing packet forwarding paths based on the packet markings. We implement PPV prototype in Click routers and commodity servers, and conducts real experiments in a real testbed built upon the prototype. The experimental results demonstrate the efficiency and performance of PPV. In particular, PPV significantly improves the throughput and the goodput of forwarding verification, and achieves around 2 times and 3 times improvement compared with the-state-of-art OPT scheme, respectively.
Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Zhuotao Liu, Yih-Chun Hu, Martin J. Reed, Meng Shen 0001
IWQoS2
2018 SmartRetro: Blockchain-Based Incentives for Distributed IoT Retrospective Detection
abstract
Internet of Things (IoT) has already been in the period of rapid development and widespread deployment, while it is still vulnerable to various malicious attacks. Security detection before system installation is not enough to ensure that IoT devices are always secure, because newly emerging vulnerabilities can still be exploited to launch attacks. To address this issue, retrospective detection is often required to trace the security status of IoT systems. Unfortunately, existing centralized detection mechanisms cannot easily provide a comprehensive security analysis. In particular, consumers cannot automatically receive security notification whenever a new vulnerability is uncovered. In this paper, we propose a novel blockchain-powered incentive platform, called SmartRetro, that can incentivize and attract more distributed detectors to participate in retrospective vulnerability detection and contribute their detection results. Leveraging smart contracts, consumers in SmartRetro receive automatic security feedback about their installed IoT systems. We perform the security and theoretical analysis to demonstrate that SmartRetro achieves our desirable security goals.We further implement SmartRetro prototype on Ethereum to evaluate its performance. Our experimental results show SmartRetro is technically feasible and economically beneficial.
Bo Wu 0002, Qi Li 0002, Ke Xu 0002, Ruoyu Li 0003, Zhuotao Liu
MASS3
2018 Dynamic Price Prediction in Ride-on-demand Service with Multi-source Urban Data
abstract
Ride-on-demand (RoD) services such as Uber and Didi (in China) are becoming increasingly popular, and in these services dynamic price plays an important role in balancing the supply (i.e., the number of cars) and demand (i.e., the number of passenger requests) to benefit both drivers and passengers. However, the dynamic price also creates concerns for passengers: the "unpredictable" prices sometimes prevent them from making quick decisions at ease. One may wonder if it is possible to get a lower price if s/he chooses to wait a while. Giving passengers more information helps to tackle this concern, and predicting the prices is a possible solution.
Suiming Guo, Chao Chen 0004, Jingyuan Wang 0001, Yaxiao Liu, Ke Xu 0002, Dah-Ming Chiu
MobiQuitous5
2018 A measurement study on multi-path TCP with multiple cellular carriers on high speed rails
abstract
Recent advances in high speed rails (HSRs) are propelling the need for acceptable network service in high speed mobility environments. However, previous studies show that the performance of traditional single-path transmission degrades significantly during high speed mobility due to frequent handoff. Multi-path transmission with multiple carriers is a promising way to enhance the performance, because at any time, there is possibly at least one path not suffering a handoff. In this paper, for the first time, we measure multi-path TCP (MPTCP) with two cellular carriers on HSRs with a peak speed of 310km/h. We find a significant difference in handoff time between the two carriers. Moreover, we observe that MPTCP can provide much better performance than TCP in the poorer of the two paths. This indicates that MPTCP's robustness to handoff is much higher than TCP's. However, the efficiency of MPTCP is far from satisfactory. MPTCP performs worse than TCP in the better path most of the time. We find that the low efficiency can be attributed to poor adaptability to frequent handoff by MPTCP's key operations in sub-flow establishment, congestion control and scheduling. Finally, we discuss possible directions for improving MPTCP for such scenarios.
Li Li 0034, Ke Xu 0002, Tong Li 0014, Kai Zheng 0003, Chunyi Peng 0001, Dan Wang 0002, Meng Shen 0001, Rashid Mijumbi
SIGCOMM2
2018 Migrating big video data to cloud: a peer-assisted approach for VoD
Fei Chen 0010, Haitao Li 0005, Jiangchuan Liu, Bo Li 0001, Ke Xu 0002, Yuemin Hu
Peer-to-Peer Netw. Appl.5
2018 Toward Cloud-Based Distributed Interactive Applications: Measurement, Modeling, and Analysis
abstract
With the prevalence of broadband network and wireless mobile network accesses, distributed interactive applications (DIAs) such as online gaming have attracted a vast number of users over the Internet. The deployment of these systems, however, comes with peculiar hardware/software requirements on the user consoles. Recently, such industrial pioneers as Gaikai, Onlive, and Ciinow have offered a new generation of cloud-based DIAs (CDIAs), which shifts the necessary computing loads to cloud platforms and largely relieves the pressure on individual user's consoles. In this paper, we aim to understand the existing CDIA framework and highlight its design challenges. Our measurement reveals the inside structures as well as the operations of real CDIA systems and identifies the critical role of cloud proxies. While its design makes effective use of cloud resources to mitigate client's workloads, it may also significantly increase the interaction latency among clients if not carefully handled. Besides the extra network latency caused by the cloud proxy involvement, we find that computation-intensive tasks (e.g., game video encoding) and bandwidth-intensive tasks (e.g., streaming the game screens to clients) together create a severe bottleneck in CDIA. Our experiment indicates that when the cloud proxies are virtual machines (VMs) in the cloud, the computation-intensive and bandwidth-intensive tasks may seriously interfere with each other. We accordingly capture this feature in our model and present an interference-aware solution. This solution not only smartly allocates workloads but also dynamically assigns capacities across VMs based on their arrival/departure patterns.
Tong Li 0014, Ryan Shea, Xiaoqiang Ma, Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002
IEEE/ACM Trans. Netw.7
2018 Errata to "Modeling, Analysis, and Implementation of Universal Acceleration Platform Across Online Video Sharing Sites"
abstract
Presents corrections to the paper, “Modeling, analysis, and implementation of universal acceleration platform across online video sharing sites,” (Xu, K. et al), IEEE Trans. Serv. Comput., vol. 11, no. 3, pp. 534–548, May/Jun. 2018.
Ke Xu 0002, Tong Li 0014, Haitao Li 0005, Jiangchuan Liu
IEEE Trans. Serv. Comput.1
2018 Modeling, Analysis, and Implementation of Universal Acceleration Platform Across Online Video Sharing Sites
abstract
User-generated video sharing service has attracted a vast number of users over the Internet. The most successful sites, such as YouTube and Youku, now enjoy millions of videos being watched every day. Yet, given limited network and server resources, the user experience of existing video sharing sites (VSSes) is still far from being satisfactory. To mitigate such a problem, peer-to-peer (P2P) based video accelerators have been widely suggested to enhance the video delivery on VSSes. In this paper, we find that the interference of multiple accelerators will lead to a severe bottleneck across the VSSes. Our model analysis shows that a universal video accelerator can naturally achieve better performance with lower deployment cost. Based on this observation, we further present the detailed design of Peer-to-Peer Video Accelerator (PPVA), a real-world system for universal and transparent P2P accelerating. Such a system has already attracted over 180 million users, with 48 million video transactions every day. We carefully examine the PPVA performance from extensive measurements. Our trace analysis indicates that it can significantly reduce server bandwidth cost and accelerate the video download speed by 80 percent.
Ke Xu 0002, Tong Li 0014, Haitao Li 0005, Jiangchuan Liu
IEEE Trans. Serv. Comput.1
2018 GreenLink: An Energy Efficient Scatternet Formation for BLE Devices
abstract
Formation technology of Bluetooth scatternet has been researched for over a decade and promoted by rapid development of wearable computing. Limited by technical features, the traditional scatternet formation technology has not been widely used in real commercial chipsets. As new features are introduced into the Bluetooth core field, the ability to use Bluetooth Low Energy (BLE) technology to construct a network becomes the reality and puts forward new challenges. The scatternet formation technology facing to BLE and wearable devices requires significant improvement in energy efficiency. According to our experiments, 92% of the system energy consumption can be attributed to central nodes. In this paper, we presented a Bluetooth scatternet formation technology focused on energy efficiency, GreenLink, which minimizes the amount of central nodes by enhancing system aggregation degree to ensure excellent energy‐saving performance. Meanwhile, we implemented a prototype of GreenLink on Nordic nRF51822 chipsets, conducted experiments, and verified in practice. According to the experiments, GreenLink used only 30% central nodes and reduced 50% system energy consumption compared with traditional technology.
Xiaoliang Wang 0004, Ke Xu 0002, Bo Mao 0002
Wirel. Commun. Mob. Comput.2
2017 On Efficient Offloading Control in Cloud Radio Access Network with Mobile Edge Computing
abstract
Cloud radio access network (C-RAN) and mobile edge computing (MEC) have emerged as promising candidates for the next generation access network techniques. Unfortunately, although MEC tries to utilize the highly distributed computing resources in close proximity to user equipments equipments (UE), C-RAN suggests to centralize the baseband processing units (BBU) deployed in radio access networks. To better understand and address such a conflict, this paper closely investigates the MEC task offloading control in C-RAN environments. In particular, we focus on perspective of matching problem. Our model smartly captures the unique features in both MEC and C-RAN with respect to communication and computation efficiency constraints. We divide the cross-layer optimization into the following three stages: (1) matching between remote radio heads (RRH) and UEs, (2) matching between BBUs and UEs, and (3) matching between mobile clones (MC) and UEs. By applying the Gale-Shapley Matching Theory in the duplex matching framework, we propose a multi-stage heuristic to minimize the refusal rate for user's task offloading requests. Trace-based simulation confirms that our solution can successfully achieve near-optimal performance in such a hybrid deployment.
Tong Li 0014, Chathura M. Sarathchandra Magurawalage, Kezhi Wang, Ke Xu 0002, Kun Yang 0001
ICDCS4
2017 A Communication-Aware Container Re-Distribution Approach for High Performance VNFs
abstract
Containers have been used in many applications for isolation purposes due to the lightweight, scalable and highly portable properties. However, to apply containers in virtual network functions (VNFs) faces a big challenge because high-performance VNFs often generate frequent communication workloads among containers while the container communications are generally not efficient. Compared with hardware modification solutions, properly distributing containers among hosts is an efficient and low-cost way to reduce communication overhead. However, we observe that this approach yields a trade-off between the communication overhead and the overall throughput of the cluster. In this paper, we focus on the communication-aware container redistribution problem to optimize the communication overhead and the overall throughput jointly for VNF clusters. We propose a solution called FreeContainer which utilizes a novel two-stage algorithm to re-distribute containers among hosts. We implement FreeContainer in Baidu clusters with 6000 servers and 35 services deployed. Extensive experiments on real networks are conducted to evaluate the performance of the proposed approach. The results show that FreeContainer can increase the overall throughput up to 90% with significant reduction on communication overhead.
Yuchao Zhang 0004, Yusen Li, Ke Xu 0002, Dan Wang 0002, Xuan Cao, Qingqing Liang
ICDCS3
2017 Robust and lightweight fault localization
abstract
The current network is vulnerable to various attacks, e.g., source spoofing and flow hijacking attacks, which can be constructed by misconfigurations or compromising routers. Unfortunately, both users and network operators are unable to localize these faults. Existing fault localization mechanisms detect such attacks under an assumption that localization is performed upon reliable communication channels. In this paper, we will relax the assumption and propose a robust and lightweight dataplane fault localization (RFL) protocol that aims to achieve source authenticity and path compliance in unreliable communication channels. RFL uses symmetric keys to build secure detection channels and samples packets for localization on the channels such that it can detect and localize faults. In particular, the localization performed is not impacted by the reliability of the communication channels, e.g., the packets that used to localize faults are dropped. We prototype of RFL on Click routers and the experiment results with the prototype demonstrate that RFL achieves more than 99.5% localization accuracy, while only incurring around 10% throughput degradation.
Bo Wu 0002, Ke Xu 0002, Qi Li 0002
IPCCC2
2017 A measurement study on Skype voice and video calls in LTE networks on high speed rails
abstract
Recent advances in high speed rails (HSRs), coupled with user demands for communication on the move, are propelling the need for acceptable quality of communication services in high speed mobility scenarios. This calls for an evaluation of how well popular voice/video call applications, such as Skype, can perform in such scenarios. This paper presents the first comprehensive measurement study on Skype voice/video calls in LTE networks on HSRs with a peak speed of 310 km/h in China. We collected 50 GB of performance data, covering a total HSR distance of 39,900 km. We study various objective performance metrics (such as RTT, sending rate, call drop rate, etc.), as well as subjective metrics such as quality of experience of the calls. We also evaluate the efficiency of Skype's algorithms regarding the level of utilization of network resources. We observed that the quality of Skype calls degrades significantly on HSRs. Moreover, it was discovered that Skype significantly under-utilizes the network resources, such as available bandwidth. We discovered that the root of these inefficiencies is the poor adaptability of Skype in many aspects, including overlay routing, rate control, state update and call termination. These findings highlight the need to develop more adaptive voice/video call services for high speed mobility scenarios.
Li Li 0034, Ke Xu 0002, Dan Wang 0002, Chunyi Peng 0001, Kai Zheng 0003, Rashid Mijumbi
IWQoS2
2017 It Can be Cheaper: Using Price Prediction to Obtain Better Prices from Dynamic Pricing in Ride-on-demand Services
abstract
In emerging ride-on-demand (RoD) services such as Uber or Didi (in China), dynamic pricing plays an important role in regulating supply and demand, trying to make such service, to some extent, more convenient for passengers. Despite the convenience, dynamic pricing also exerts mental burden on passengers: they wonder whether the current price is low enough to accept, or if it is not, what they could do to get a lower price. Without extra information, passengers sometimes feel anxious and lose satisfaction. It is thus necessary to provide more information to relieve the anxiety, and price prediction is one of the solutions.
Suiming Guo, Chao Chen 0004, Yaxiao Liu, Ke Xu 0002, Dah-Ming Chiu
MobiQuitous4
2017 Throughput optimization of TCP incast congestion control in large-scale datacenter networks
Lei Xu 0019, Ke Xu 0002, Yong Jiang 0001, Fengyuan Ren
Comput. Networks2
2017 Interest-suppression-based NDN live video broadcasting over wireless LAN
Dan Pei, Xiaoping Zhang 0004, Beichuan Zhang 0001, Ke Xu 0002
Frontiers Comput. Sci.5
2017 TrueID: A practical solution to enhance Internet accountability by assigning packets with creditable user identity code
Guangwu Hu, Qi Li 0002, Yong Jiang 0001, Ke Xu 0002
Future Gener. Comput. Syst.5
2017 Equilibrium Price and Dynamic Virtual Resource Allocation for Wireless Network Virtualization
Guopeng Zhang, Kun Yang 0001, Ke Xu 0002, Lianming Zhang
Mob. Networks Appl.5
2017 A Longitudinal Measurement Study of TCP Performance and Behavior in 3G/4G Networks Over High Speed Rails
abstract
While TCP has been extensively studied in static and low speed mobility situations, it has not yet been well explored in high speed mobility scenarios. Given the increasing deployment of high speed transport systems (such as high speed rails), there is an urgent need to understand the performance and behavior of TCP in such high speed mobility environments. In this paper, we conduct a comprehensive study to investigate the performance and behavior of TCP in a high speed environment with a peak speed of 310 km/h. Over a 16-month period spanning four years, we collect 500 GB of performance data on 3/4G networks in high speed trains in China, covering a distance of 108,490 km. We start by analyzing performance metrics, such as RTT, packet loss rate, and throughput. We then evaluate the challenges posed on the main TCP operations (establishment, transmission, congestion control, flow control, and termination) by such high speed mobility. This paper shows that RTT and packet loss rate increase significantly and throughput drops considerably in high speed situations. Moreover, TCP fails to adapt well to such extremely high speed leading to abnormal behavior, such as high spurious retransmission time out rate, aggressive congestion window reduction, long delays during connection establishment and closure, and transmission interruption. As we prepare to move into the era of 5G, and as the need for high speed travel continues to increase, our findings indicate a critical need for efforts to develop more adaptive transport protocols for such high speed environments.
Li Li 0034, Ke Xu 0002, Dan Wang 0002, Chunyi Peng 0001, Kai Zheng 0003, Rashid Mijumbi, Qingyang Xiao
IEEE/ACM Trans. Netw.2
2017 SmartFix: Indoor Locating Optimization Algorithm for Energy-Constrained Wearable Devices
abstract
Indoor localization technology based on Wi-Fi has long been a hot research topic in the past decade. Despite numerous solutions, new challenges have arisen along with the trend of smart home and wearable computing. For example, power efficiency needs to be significantly improved for resource-constrained wearable devices, such as smart watch and wristband. For a Wi-Fi-based locating system, most of the energy consumption can be attributed to real-time radio scan; however, simply reducing radio data collection will cause a serious loss of locating accuracy because of unstable Wi-Fi signals. In this paper, we present SmartFix, an optimization algorithm for indoor locating based on Wi-Fi RSS. SmartFix utilizes user motion features, extracts characteristic value from history trajectory, and corrects deviation caused by unstable Wi-Fi signals. We implemented a prototype of SmartFix both on Moto 360 2nd-generation Smartwatch and on HTC One Smartphone. We conducted experiments both in a large open area and in an office hall. Experiment results demonstrate that average locating error is less than 2 meters for more than 80% cases, and energy consumption is only 30% of Wi-Fi fingerprinting method under the same experiment circumstances.
Xiaoliang Wang 0004, Ke Xu 0002
Wirel. Commun. Mob. Comput.2
2016 Towards Minimal Tardiness of Data-Intensive Applications in Heterogeneous Networks
abstract
The increasing data requirement of Internet applications has driven a dramatic surge in developing new programming paradigms and complex scheduling algorithms to handle data-intensive workloads. Due to the expanding volume and the variety of such flows, their raw data are often processed on intermediate processing nodes before being sent to servers. The intermediate processing constraints are however not yet considered in existing task and flow computing models. In this paper, we aim to minimize the total tardiness of all flows in the presence of intermediate processing constraints. We build a model to consider Tardiness-aware Flow Scheduling with Processing constraints (TFS-P), which is unfortunately NP-Hard. Hence, we propose a heuristic Routing and Scheduling duplex MATching (RSMAT) framework based on the classic Gale-Shapley Matching Theory. We find that the problem can be well-addressed by classic Deferred Acceptance (DA) algorithm, in which the match is stable but inefficient for the model. We therefore propose the Tardiness-aware Deferred Acceptance algorithm with Dynamical Quota (TDA-DQ). This algorithm is enhanced by overcoming the inefficient stability and smartly considering the dynamical quota in the system. The evaluation compares TDA-DQ to the lower bound obtained by a modified subgradient optimization algorithm. The result indicates that TDA-DQ can achieve near-optimal performance for data-intensive applications.
Tong Li 0014, Ke Xu 0002, Meng Sheng, Kun Yang 0001, Yuchao Zhang 0004
ICCCN2
2016 Power-Aware Wireless Transmission for Computation Offloading in Mobile Cloud
abstract
In today's mobile devices, the battery reservoir remains severely limited in capacity, making power consumption a key concern in the design and implementation of mobile applications. In this paper, we closely examine one widely adopted approach to improve the energy efficiency of mobile applications-adaptively offloading the computation to the remote cloud. In particular, we measure the power consumption of computation offloading for two representative real-world mobile cloud applications under various wireless network conditions and identify the unique features of data transmission for computation offloading. We then formulate the power-aware scheduling problem for computation offloading and present a scheduling algorithm that makes adaptive offloading decisions according to the dynamic network conditions. Simulation results show that our proposed method can achieve better battery performance, which also reveal that computation-intensive and delay-tolerant tasks are more likely to benefit from offloading.
Lei Zhang 0066, Cong Zhang 0002, Jiangchuan Liu, Xiaowen Chu 0001, Ke Xu 0002, Yong Jiang 0001
ICCCN5
2016 Measurement, Modeling, and Analysis of TCP in High-Speed Mobility Scenarios
abstract
The rapid growth of high-speed transit systems, such as High Speed Rail (HSR), is putting considerable pressure on TCP-based data transmission. It is well known that TCP is suffering from severe throughput degradation in high-speed mobility scenarios. The root cause at the transport layer however remains unclear and largely undetermined to date. In this paper, we aim to pinpoint the throughput bottlenecks and develop a throughput model to understand TCP in high-speed mobility environments. Based on the analysis of real-world HSR traces, we find that high-speed mobility will introduce significant challenges to the packet retransmission process after timeouts. And ACKs are more likely to trigger spurious retransmission timeouts in TCP flows in high-speed mobile environments. Such problems are not yet considered in the existing TCP models because classic timeouts can easily be recovered by retransmission in stationary scenarios. We therefore propose an enhanced TCP throughput model to integrate the above features. Our model analysis indicates that the optimization of TCP ACK latency is critical to obtain better throughput. Moreover, reliable retransmission mechanisms, e.g., multi-path TCP (MPTCP), can also bring notable benefits in high-speed mobility environments.
Qingfang Liu, Ke Xu 0002, Meng Shen 0001, Li Li 0034, Qingyang Xiao
ICDCS2
2016 PieBridge: A Cross-DR scale Large Data Transmission Scheduling System
abstract
Cross-DR WAN (Datacenter Region Wide Area Network) with various services are deployed to provide timely data information and analytics for users in a wide range of geographical locations. For its reliability and performance, data duplication synchronization is essential among different IDCs (Internet datacenters). However, this problem poses a challenge. First, data duplication requires huge amount of bandwidth whereas the bandwidth of cross-DR links and the upload/download rates of server interfaces are limited. Second, data transmissions are time sensitive, but the current network cannot complete such tasks in a timely manner. In this work, we present PieBridge, a cross-RD data duplicate transmission platform that accommodates hundreds of TBs of data generated from user applications online data analytics. We deployed PieBridge on the IDCs of Baidu and obtained promising performance results in comparison with the prevalent approaches.
Yuchao Zhang 0004, Ke Xu 0002, Guang Yao, Xiaohui Nie
SIGCOMM2
2016 Continuous double auction for cloud market: Pricing and bidding analysis
abstract
Cloud computing has recently attracted a substantial amount of attention from both industry and academia. Its growing demand gives normal users an opportunity to sell their local resources to the cloud market, which introduces new challenges for the existing coarse-grained pricing models. In this paper, we examine the potential of applying continuous double auction framework to handle these heterogeneous cloud resources. First, we establish an e-auction platform, on which cloud service providers and users can trade computing and storage resources online. Then we formulate a continuous double auction model for cloud market and further develop a novel belief-based hybrid bidding strategy (BH-strategy) for cloud players to ensure their profit maximization. At last, we conduct three simulation scenarios to compare the performance between BH-strategy and other dominating bidding strategies, and plenty of simulation results show that our BH-strategy outperforms others in all the scenarios on user surpluses by 20% or above. Besides, the BH-strategy can obtain a 16% higher efficiency in 1/3 the amount of time of other strategies.
Yuchao Zhang 0004, Ke Xu 0002, Xuelin Shi, Jiangchuan Liu
WCNC2
2016 Achieving Optimal Traffic Engineering Using a Generalized Routing Framework
abstract
The open shortest path first (OSPF) protocol has been widely applied to intra-domain routing in today's Internet. Since a router running OSPF distributes traffic uniformly over equal-cost multi-path (ECMP), the OSPF-based optimal traffic engineering (TE) problem (i.e., deriving optimal link weights for a given traffic demand) is computationally intractable for large-scale networks. Therefore, many studies resort to multi-protocol label switching (MPLS) based approaches to solve the optimal TE problem. In this paper we present a generalized routing framework to realize the optimal TE, which can be potentially implemented via OSPFor MPLS-based approaches. We start with viewing the conventional optimal TE problem in a fresh way, i.e., optimally allocating the residual capacity to every link. Then we make a generalization of network utility maximization (NUM) to close this problem, where the network operator is associated with a utility function of the residual capacity to be maximized. We demonstrate that under this framework, the optimal routes resulting from the optimal TE are also the shortest paths in terms of a set of non-negative link weights that are explicitly determined by the optimal residual capacity and the objective function. The network entropy maximization theory is employed to enable routers to exponentially, instead of uniformly, split traffic over ECMP. The shortest-path penalizing exponential flow-splitting (SPEF) is designed as a link-state protocol with hop-by-hop forwarding to implement our theoretical findings. An alternative MPLS-based implementation is also discussed here. Numerical simulation results have demonstrated the effectiveness of the proposed framework as well as SPEF.
Ke Xu 0002, Meng Shen 0001, Jiangchuan Liu, Fan Li 0001, Tong Li 0014
IEEE Trans. Parallel Distributed Syst.1
2015 SNACS: Social Network-Aware Cloud Assistance for Online Propagated Video Sharing
abstract
The deep penetration of Online Social Networks (OSNs) has made them as major portals for video information sharing. Propagated through chains of friends, the coverage of OSN-shared videos can be much broader with stronger micro- and macro-dynamics. Given that the contents are still hosted by external Video Sharing Sites (VSSes), such distinct access patterns from OSN users have created significant new challenges to VSSes. In this paper, we present SNACS, a cost-effective social network-aware cloud assistance for video sharing. The SNACS module sits between VSSes and an OSN, and is managed by the OSN to improve its users' video access experience using both centralized cloud resources and edge servers. Given the strong dynamics of the access patterns, we are particularly interested in the content management and update strategies in the SNACS' implementation. Motivated by real world data traces, we show that conventional cache replacement can be quite inefficient in this context. We then develop optimal offline algorithms with minimized cache misses and replacements, which also motivate an online solution that makes effective use of the video sharing patterns in the OSN. Our design has been extensively evaluated and its superiority has been validated under diverse network and user configurations.
Haitao Li 0005, Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002
CLOUD4
2015 ESTRA: Incentivizing Storage Trading for Edge Caching in Mobile Content Delivery
abstract
The explosion of mobile content and usage imposes enormous pressures on mobile communication networks. To reduce content delivery latency and to ease the burden on network bottlenecks (e.g., backhaul networks), besides upgrading the infrastructures, it is promising to cache popular contents at the edge-storage on BSs (Base Stations), APs (Access Points) or other third-party devices associated with BSs and APs, which have been widely deployed in mobile networks. Then it is a challenge here to effectively match such demands of CPs (Content Providers) and the supplies of edge-storage owners because of the complexity caused by the two-fold matching requirements on both coverage and quantity combined with the multi-buyer multi-seller scenario and the divisibility of heterogeneous edge-storages. In this paper, we propose ESTRA (Edge Storage TRading Auction) mechanism to tackle such a challenge. By proposing a region-based model for edge-storage trading, we design a demand cover mechanism to transfer subscriber coverage demands into edge-storage bundle demands and design a truthful, weakly budget balanced and individually rational auction mechanism under the constraints of enabling multi-unit asks and bundle bids. Our theoretical analysis proves the economic robustness, and the simulation result shows that ESTRA achieves 74%-91% of the maximum social welfare and maintains the sustainability of the trading platform through a proper distribution of social welfare.
Yifeng Zhong, Ke Xu 0002, Xiang-Yang Li 0001, Hui Su, Qingyang Xiao
GLOBECOM2
2015 NDN Live Video Broadcasting over Wireless LAN
abstract
Named Data Networking (NDN) is a new Internet architecture that replaces today's focus on where - addresses and hosts - with what - the content that users and applications care about. One of NDN's prominent advantages is scalable and efficient content distribution due to its native support of caching and multicast in the network. However, at the last hop to wireless users, often the WiFi link, current NDN implementation still treats the communication as multiple unicast sessions, which will cause duplicate packets and waste of bandwidth when multiple users request for the same popular content. WiFi's built-in broadcast mechanism can alleviate this problem, but it suffers from packet loss since there is no MAC-layer acknowledgement as in unicast. In this paper, we develop a new NDN-based cross-layer approach called NLB for efficient and scalable live video streaming over wireless LAN. The idea is to use WiFi's broadcast channel to deliver content from the access point to the users, a leader-based mechanism to suppress duplicate requests from users, and receiver-driven rate control and loss recovery. The design is implemented and evaluated in a physical testbed comprised of a commodity residential access point and 20 WiFi clients. While NDN with multiple unicast sessions or plain broadcast can support no more than 7 concurrent viewers of a 1Mbps streaming video, NDN plus NLB supports all 20 viewers, and can likely support many more when present.
Dan Pei, Xiaoping Zhang 0004, Beichuan Zhang 0001, Ke Xu 0002
ICCCN5
2015 Elastic and Efficient Virtual Network Provisioning for Cloud-Based Multi-tier Applications
abstract
The multi-tier architecture is prevalently adopted by cloud applications, such as the three-tier web application. It is highly desirable for both tenants and providers to provide virtual networks in an efficient and elastic way, where tenant applications can automatically scale in or out with varying workloads and providers can accommodate as many requests as possible in the underlying network. However, due to potential conflicts between efficiency and elasticity, it is challenging to achieve these two goals simultaneously in abstracting tenant requirements and designing corresponding provisioning algorithms. In this paper, we propose an efficient and elastic virtual network provisioning solution called Easy Alloc, which is comprised of an elasticity-aware abstraction model and a virtual network provisioning algorithm. To accurately capture the tenant requirement and maintain the provisioning simplicity for providers, the elasticity-aware model enables two types of decoupling, i.e., Always-on VMs for normal load and on-demand VMs for dynamic scaling, and the bandwidth requirement of each VM for intra- and inter-tier communications. Then we formulate the virtual network provisioning as an overhead minimization problem, where the objective simultaneously considers the bandwidth and elasticity overhead. Due to the NP-completeness of this problem, we leverage two heuristics, slot reservation and tier iteration, to obtain an efficient algorithm. Extensive simulation results show that compared with a typical elasticity-agnostic method under a heavy load, Easy Alloc enables a 9% increase of request acceptance rate and a 16.8% improvement of the successful extension rate. To the best of our knowledge, this is the first work targeting at the elastic virtual network provisioning.
Meng Shen 0001, Ke Xu 0002, Fan Li 0001, Kun Yang 0001, Liehuang Zhu
ICPP2
2015 An intelligent two-agent self-configuration approach for radio resource management
abstract
In this paper we propose the use of a two-agent learning scheme for the management of radio resources on cellular access networks. The management is materialized by the implementation of a self-configuration system governing the setup of several parameters on each base station. The two agents have independent goals; one is trying to maximize the quality of service and the other the economic benefit. Thanks to the combined use of the fuzzy logic technique and reinforcement learning, both agents will work in a complementary mode, achieving both goals simultaneously.
Kevin Collados, Juan-Luis Gorricho, Joan Serrat 0001, Zheng Hu 0001, Ke Xu 0002
IM5
2015 A measurement study on TCP behaviors in HSPA+ networks on high-speed rails
abstract
TCP has been the dominant transport protocol for mobile internet since its origin. Its behaviors play an essential role in determining quality of service/experience (QoS and QoE) for mobile apps. While TCP has been extensively studied in a static, walking, or driving mobility, it has not been well explored in highspeed (> 200 km/h) mobility cases. With increasing investment and deployment of high speed rails (HSRs), a critical demand of understanding TCP performance under extremely high-speed mobility arises. In this paper, we conduct an in-depth study to investigate TCP behaviors on HSR. We collect 90 GB of measurement data on HSPA+ networks in Chinese high-speed trains with a peak speed of 310 km/h, along various routes (covering 5,000 km) during an 8-month period. We analyze the impacts of high-speed mobility and handoff on performance metrics including RTT, packet loss and network disconnection. Then we demystify the grand challenges posed on TCP operations (TCP establishment, transmission, congestion control and termination). Our study shows that performance greatly declines in HSR, where RTT spikes, packet drops and network disconnections are more significant and occur more frequently, compared with static, slowly moving or driving mobility cases. Moreover, TCP fails to adapt well to such extremely high-speed and yields severely abnormal behaviors, such as high spurious RTO rate, aggressive congestion window reduction, long delay of connection establishment and closure, and transmission interruption. All these findings indicate that extremely high-speed indeed poses a big threat to today's TCP and it calls for urgent efforts to develop HSR-friendly protocols and wireless networks to address even more complicated challenges raised by faster trains/aircrafts in the foreseeable future.
Li Li 0034, Ke Xu 0002, Dan Wang 0002, Chunyi Peng 0001, Qingyang Xiao, Rashid Mijumbi
INFOCOM2
2015 Lifetime maximization in rechargeable wireless sensor networks with charging interference
abstract
Radio Frequency based Wireless Power Transfer (RF-WPT) technology is recognized as a promising way to charge low-power wireless devices. But the application of RF-WPT in wireless sensor networks also introduces charging interference to wireless communications. The network lifetime maximization by jointly considering wireless charging and data transmission under interference concerns, however, has seldom been examined. In this paper, we take initial steps to consider communication and charger scheduling together in wireless sensor networks. We propose a smart interference-aware scheduling to maximize the network lifetime and avoid potential data loss caused by charging interference. The evaluation result indicates that the proposed design can guarantee 99% optimality and significantly improve network lifetime.
Ke Xu 0002, Dan Wang 0002, Bo Wu 0002
IPCCC2
2015 Towards shorter task completion time in datacenter networks
abstract
Datacenters are now used as the underlying infrastructure of many modern commercial operations, powering both large Internet services and a growing number of data-intensive scientific applications. The tasks in these applications always consist of rich and complex flows which require different resources at different time slots. The existing data center scheduling frameworks are however base on either task or flow level metrics. This simplifies the design and deployment, but hardly unleashes the potentials of obtaining low task completion time for delay sensitive applications. In this paper, we show that the performance (e.g., tail and average task completion time) of existing flow-aware and task-aware network scheduling is far from being optimal. To address such a problem, we carefully examine the possibility to consider both task and flow level metrics together and present the design of TAFA (Task-Aware and Flow-Aware) in data center networks. This approach seamlessly combines the existing flow and task metrics together while successfully avoids their problems as flow-isolation and flow indiscrimination. The evaluation result shows that TAFA can obtain a near-optimal performance and reduce over 35% task completion time for the existing data center systems.
Yuchao Zhang 0004, Ke Xu 0002, Meng Shen 0001
IPCCC2
2015 TSP: A traffic sharing platform for mobile networks
abstract
In mobile Internet era, wireless traffic has become a rare resource and there is no effective ways for users to share their unused traffic with each other. This paper introduces a system solution requiring no sophisticated hardware. An incentive mechanism is designed and implemented in a novel system named Traffic Sharing Platform (TSP) for mobile users, which can optimize network resource configuration and achieve Pareto optimality of the society. Simulation results show the TSP is available and the incentive mechanism is effective.
Hui Su, Tong Li 0014, Ke Xu 0002, Shenglin Zhang, Xiaoliang Wang 0004
IWQoS3
2015 Enhancing TCP Incast congestion control over large-scale datacenter networks
abstract
Many-to-one traffic pattern in datacenter networks introduces the problem of Incast congestion for Transmission Control Protocol (TCP) and puts unprecedented pressure to the cloud service providers. To address heavy Incast, we present an Receiver-oriented Datacenter TCP (RDTCP). The proposal is motivated by oscillatory queue size when handling heavy Incast traffic and substantial potential of receiver in congestion control. Finally, RDTCP adopts both open- and closed-loop congestion controls. We provide a systematic discussion on its design issues and implement a prototype to examine its performance. The evaluation results indicate that RDTCP has an average decrease of 47.5% in the mean queue size, 51.2% in the 99th-percentile latency in the increasingly heavy Incast over TCP, and 43.6% and 11.7% over Incast congestion Control for TCP (ICTCP).
Lei Xu 0019, Ke Xu 0002, Yong Jiang 0001, Fengyuan Ren
IWQoS2
2015 Performance and incentive of teamwork-based channel allocation in spectrum access networks
abstract
Recent years have witnessed the great popularity of dynamic spectrum access networks. Such an approach is adopted between three players: government, Internet Service Providers (ISPs) and end-users. ISPs need to purchase spectrum from the government before subletting it to end-users, but currently most researches focus on the subletting process and ignore the purchasing process. In this paper, we try to investigate the game between government and ISPs in spectrum access networks. In this framework, the former aims to optimize user experience yet the later want to maximize their own profits. Such a conflict of interests introduces significant challenges to ensure end-user's performance and thus leads to a severe bottleneck to the spectrum access networks. Inspired by cooperative trends among users, we proposed a novel Channel Allocation model based on Teamwork (CAT). This approach considers both ISP's respective bands and end-user's experience and enables a smart profit sharing algorithm to address the problem. The evaluation results indicate that CAT improves the overall social welfare by about 30% than the Vickrey Clarke Groves (VCG) mechanism and obtains higher stability.
Yuchao Zhang 0004, Ke Xu 0002, Jiangchuan Liu, Yifeng Zhong
IWQoS2
2015 Modeling Multi-path TCP Throughput with Coupled Congestion Control and Flow Control
abstract
Multi-Path Transmission Control Protocol (MPTCP) is emerging as a dominant paradigm that enables users to utilize multiple Network Interface Controllers (NICs) simultaneously. Due to the complexity of its protocol design, the steady-state performance of MPTCP still remains largely unclear through model analysis. This introduces severe challenges to quantitatively study the efficiency, fairness and stability of existing MPTCP implementations. In this paper, we for the first time investigate the modeling of coupled congestion control and flow control algorithms in MPTCP. By proposing a closed-form throughput model, we reveal the relationship between MPTCP throughput and subflow characters, such as Round Trip Time (RTT), packet loss rate and receive buffer size. The extensive NS2-based evaluation indicates that the proposed model can be applied to understand the throughput of MPTCP in various situations. In particular, when MPTCP subflows have similar RTTs, the average Error Rate (ER) of the proposed model is less than 8%. Even in the situation where huge RTT difference exists between subflows, the model can still behave well with average ER less than 10%.
Qingfang Liu, Ke Xu 0002, Lei Xu 0019
MSWiM2
2015 Special issue on big data inspired data sensing, processing and networking technologies
Jia Hu 0001, Kun Yang 0001, Chirag Warty, Ke Xu 0002
Ad Hoc Networks4
2015 A bargaining game theoretic method for virtual resource allocation in LTE-based cellular networks
Guopeng Zhang, Kun Yang 0001, Ke Xu 0002, Yongquan Dong
Sci. China Inf. Sci.3
2015 A neuro-fuzzy approach to self-management of virtual network resources
Rashid Mijumbi, Juan-Luis Gorricho, Joan Serrat 0001, Meng Shen 0001, Ke Xu 0002, Kun Yang 0001
Expert Syst. Appl.5
2015 Toward a Practical Energy Conservation Mechanism With Assistance of Resourceful Mules
abstract
As wireless sensor networks (WSNs) gradually move from specialized fields such as military and industry toward domains with general purposes, more and more sensors locate around our living areas. The reality that various wireless devices coexist in new circumstances encourages us to come up with new ideas to solve the extremely energy-constrained problem in WSNs. In this paper, we propose energy conservation with assistance of resourceful mules (ECARM), a mechanism that opportunistically utilizes resourceful mules (RMs) such as specifically designed powerful sensors or ubiquitously used laptops, tablet PCs, and smart phones to act as assistants and save energy for WSNs. We verify ECARM through extensive simulations written on the OMNET$\boldsymbol{++}$ platform. Single RM simulation shows that 43% sensors in an RM's communication range enjoy power reduction by decreasing their wake-up time to 16% at most. Multiple RM simulations illustrate that 86% sensors in the simulated network benefit from 14 RMs, and wake-up time of 56% sensors decrease to 50% below. We emphasize that ECARM can also be applied in duty-cycled WSNs that adopt schemes such as ContikiMAC and X-MAC. Simulation results demonstrate that the duty-cycling ratio of ContikiMAC is further decreased by at least 20.9% after the ECARM application.
Ke Xu 0002, Jiangchuan Liu
IEEE Internet Things J.2
2015 A Family of Stable Multipath Dual Congestion Control Algorithms
Ying Liu 0024, Ke Xu 0002, Meng Shen 0001
J. Comput. Sci. Technol.3
2015 Exploring the policy selection of the P2P VoD system: A simulation-based research
Ke Xu 0002, Yifeng Zhong
Peer-to-Peer Netw. Appl.1
2014 On incentive of customer-provided resource sharing in cloud
abstract
The state-of-the-art cloud computing service has attracted significant interests from the Internet users. However, in the existing cloud platforms, the cloud users are pure consumers; their local resources, though abundant, have been largely ignored. In this paper, we for the first time explore the resource pricing as well as the incentive issues in SpotCloud, a real-world system that enables customer-provided cloud computing service on the Internet. In this system, the resource providers are largely heterogeneous and are not forced to contribute their resources. A working business model is therefore important to offer them enough sharing incentive. Instead of setting a standardized pricing rule for unit resource, we suggest a distributed market that allows the sellers to decide the quality, quantity, and pricing of their own resources. We demonstrate the efficiency of this business model through a repeated seller competition game. The trace-analysis further indicates that the proposed business model can successfully motivate the resource sharing in our Spotcloud system.
Jiangchuan Liu, Ke Xu 0002
ICC3
2014 TCP Performance over Mobile Networks in High-Speed Mobility Scenarios
abstract
Recently, the performance of mobile data networks has been evaluated from many aspects, e.g., TCP/IP protocols, comparison with WiFi or even satellite communication, under different movements within a metropolis area. Nevertheless, the result is still unknown in high-speed mobility scenarios and in a scale that crosses different metropolis and geographic areas. To fill in this blank, we carry out a comprehensive measurement study on the performance of mobile data networks under high-speed mobility, i.e., 300 km/h or above. Such speed is the current de facto standard of the China Railway High speed (CRH) network, the largest commercial high-speed railway network in the world so far. We first present an overview on the TCP performance over LTE networks. We observe that decent throughput may exist under high-speed mobility. However, comparing to the stationary and driving (100 km/h) scenarios, the throughput and RTT not only are worse, but also have a large variance. We then take an in-depth investigation into two key factors affecting the performance, i.e., The wireless channel and handoff. We believe our study on these factors is useful not only for TCP, but also for other upper-layer protocols.
Qingyang Xiao, Ke Xu 0002, Dan Wang 0002, Li Li 0034, Yifeng Zhong
ICNP2
2014 Achieving bandwidth guarantees in multi-tenant cloud networks using a dual-hose model
abstract
In public cloud networks, applications of different tenants compete for the shared network bandwidth and thus might suffer from unpredictable performance. It is desirable for cloud providers to offer tenants with bandwidth guarantees. However, it is challenging to precisely abstract tenant bandwidth requirements for their intra- and inter-tenant communications and to achieve work conservation simultaneously. In this paper, we first propose a dual-hose model, a novel tenant requirement abstraction that decouples bandwidth guarantees for a tenant's inter-tenant communications from those for its intra-tenant communications. We then develop a new VM placement algorithm to optimize operational goals of cloud providers, while providing tenants with minimum bandwidth guarantees captured by the dual-hose model. Finally, we design a dynamic bandwidth allocation strategy to achieve work conservation. Through extensive simulation results, we show that our solution provides bandwidth guarantees for tenant requests while improving the overall request throughput by 5.3%.
Meng Shen 0001, Lixin Gao 0001, Ke Xu 0002, Liehuang Zhu
IPCCC3
2014 Online combinatorial double auction for mobile cloud computing markets
abstract
The emergence of cloud computing as an efficient means of providing computing as a form of utility can already be felt with the burgeoning of cloud service companies. Notable examples including Amazon EC2, Rackspace, Google App and Microsoft Azure have already attracted an increasing number of users over the Internet. However, due to the dynamic behaviors of some users, the traditional cloud pricing models cannot well support such popular applications as Mobile Cloud Computing (MCC). To mitigate this problem, we take our first steps towards the design of an efficient double-sided combinatorial auction model in the context of mobile cloud computing. In particular, we carefully develop the framework of online combinatorial double auctions and apply a Winner Determination Problem (WDP) model for the proposed auction mechanism. The experiment results indicate that the allocation efficiency of our proposed online auction mechanism is comparable to the social optimal solution.
Ke Xu 0002, Yuchao Zhang 0004, Xuelin Shi, Meng Shen 0001
IPCCC1
2014 Towards efficient virtual network embedding across multiple network domains
abstract
Network virtualization provides a promising way to run multiple virtual networks (VNs) simultaneously on a shared infrastructure. It is critical to efficiently map VNs onto substrate resources, which is known as the VN embedding problem. Most existing studies restrict this problem in a single substrate domain, whereas the VN embedding process across multiple domains (i.e., inter-domain embedding) is more practical, because a single domain rarely controls an entire end-to-end path. Since infrastructure providers (InPs) are usually reluctant to expose their substrate information, the inter-domain embedding is more sophisticated than the intra-domain case. In this paper, we develop an efficient solution to facilitate the inter-domain embedding problem. We start with extending the current business roles by employing a broker-like role, virtual network provider (VNP), to make centralized embedding decisions. Accordingly, a reasonable information sharing scheme is proposed to provide VNP with partial substrate information meanwhile keeping InPs' confidential information. Then we formulate the embedding problem as an integer programming problem. By relaxing integer constraints, we devise an inter-domain embedding algorithm to handle online VN requests in polynomial time. Simulation results show that our solution outperforms other counterparts and achieves 80%-90% of the benchmarks in an ideal scenario where VNP has complete knowledge of all substrate information.
Meng Shen 0001, Ke Xu 0002, Kun Yang 0001, Hsiao-Hwa Chen
IWQoS2
2014 Towards evolvable Internet architecture-design constraints and models analysis
Ke Xu 0002, Guangwu Hu, Yifeng Zhong, Ying Liu 0024, Ning Wang 0001
Sci. China Inf. Sci.1
2014 On IGP link weight optimization for joint energy efficiency and load balancing improvement
Frédéric François, Ning Wang 0001, Klaus Moessner, Stylianos Georgoulas, Ke Xu 0002
Comput. Commun.5
2014 An Anti-Tracking Source-Location Privacy Protection Protocol in WSNs Based on Path Extension
abstract
In the application field using sensor networks to monitor valuable asset, source-location anonymity is a serious concern. As a series of event packets are reported to the base station, adversaries eavesdropping on the network can backtrack to the source through traffic analysis and the RF localization techniques. This leakage of contextual information will expose sensitive or precious objects and bring down the effectiveness of sensor networks. Existing techniques such as phantom routing or source simulation are proposed to discourage the adversaries, both of which trade energy for security. In this paper, we propose a new scheme, called path extension method (PEM), providing strong protection for source-location privacy. It performs quite well even though an object occurs near the base station, while other methods cannot protect the source well in this case. In PEM, fake sources are generated dynamically after the source sends event messages to the base station, which makes it much more flexible. Fake sources form several fake paths in the network and an adversary will be induced farther away from the source if it is entrapped by any of them. The theoretical and simulation results show that PEM is efficient in protecting source-location privacy with minimal message delivery delay and acceptable overhead.
Ke Xu 0002, Dan Wang 0002
IEEE Internet Things J.2
2014 Peer-to-peer as an infrastructure service
Jiangchuan Liu, Ke Xu 0002, Yongqiang Xiong, Dongchao Ma, Kai Shuang
Peer-to-Peer Netw. Appl.2
2014 Energy Management in Cross-Domain Content Delivery Networks: A Theoretical Perspective
abstract
In a content delivery network (CDN), the energy cost is dominated by its geographically distributed data centers (DCs). Generally within a DC, the energy consumption is dominated by its server infrastructure and cooling system, with each contributing approximately half. However, existing research work has been addressing energy efficiency on these two sides separately. In this paper, we jointly optimize the energy consumption of both server infrastructures and cooling systems in a holistic manner. Such an objective is achieved through both strategies of: 1) putting idle servers to sleep within individual DCs; and 2) shutting down idle DCs entirely during off-peak hours. Based on these strategies, we develop a heuristic algorithm, which concentrates user request resolution to fewer DCs, so that some DCs may become completely idle and hence have the opportunity to be shut down to reduce their cooling energy consumption. Meanwhile, QoS constraints are respected in the algorithm to assure service availability and end-to-end delay. Through simulations under realistic scenarios, our algorithm is able to achieve an energy-saving gain of up to 62.1% over an existing CDN energy-saving scheme. This result is bound to be near-optimal by our theoretically-derived lower bound on energy-saving performance.
Chang Ge 0001, Zhili Sun, Ning Wang 0001, Ke Xu 0002, Jinsong Wu 0001
IEEE Trans. Netw. Serv. Manag.4
2014 Pushing Server Bandwidth Consumption to the Limit: Modeling and Analysis of Peer-Assisted VoD
abstract
Recent years have witnessed video-on-demand (VoD) as an efficient means for providing reliable streaming service for Internet users. It is known that peer-assisted VoD systems, such as NetFlix and PPlive, generally incur a lower deployment cost in terms of server bandwidth consumption. However, some fundamental issues still need to be further clarified, particularly for VoD service providers. In particular, how far can we push peer-assisted VoD forward, and at the scale of VoD systems, the maximum reduction of server bandwidth consumption that can be achieved with peer-assisted approaches. In this paper, we provide extensive model analysis to understand the minimum server bandwidth consumption for peer-assisted VoD systems. We first propose a basic model that can optimally schedule user demands at given snapshots. Our model analysis reveals the optimal performance bound and shows that the existing peer-assisted protocols are still far from being optimal. How to push the server bandwidth consumption to the limit remains a big challenge in VoD system design. To approach the optimal bandwidth consumption in real deployment, we further extend our model to a realistic case to capture the peer dynamic across continuous time-slots. The simulation result indicates that the optimal load scheduling problem is still achievable through a dynamic programming algorithm. Its design principle further motivates a fast priority-based algorithm that achieves near-optimal performance. These proposed algorithms can significantly reduce the bandwidth consumption of dedicated VoD servers.
Ke Xu 0002, Jiangchuan Liu, Lei Xu 0019
IEEE Trans. Netw. Serv. Manag.1
2014 A Model Approach to the Estimation of Peer-to-Peer Traffic Matrices
abstract
Peer-to-Peer (P2P) applications have witnessed an increasing popularity in recent years, which brings new challenges to network management and traffic engineering (TE). As basic input information, P2P traffic matrices are of significant importance for TE. Because of the excessively high cost of direct measurement, many studies aim to model and estimate general traffic matrices, but few focus on P2P traffic matrices. In this paper, we propose a model to estimate P2P traffic matrices in operational networks. Important factors are considered, including the number of peers, the localization ratio of P2P traffic, and the network distance. Here, the distance can be measured with AS hop counts or geographic distance. To validate our model, we evaluate its performance using traffic traces collected from both the real P2P video-on-demand (VoD) and file-sharing applications. Evaluation results show that the proposed model outperforms the other two typical models for the estimation of the general traffic matrices in several metrics, including spatial and temporal estimation errors, stability in the cases of oscillating and dynamic flows, and estimation bias. To the best of our knowledge, this is the first research on P2P traffic matrices estimation. P2P traffic matrices, derived from the model, can be applied to P2P traffic optimization and other TE fields.
Ke Xu 0002, Meng Shen 0001, Yong Cui 0001, Mingjiang Ye, Yifeng Zhong
IEEE Trans. Parallel Distributed Syst.1
2014 Can P2P Technology Benefit Eyeball ISPs? A Cooperative Profit Distribution Answer
abstract
Peer-to-Peer (P2P) technology has been promoting the development of Internet applications, like Video on Demand (VoD) and file sharing. However, under the traditional pricing mechanism, the fact that most P2P traffic flows among peers can dramatically decrease the profit of ISPs, who may take actions against P2P and impede the adoption of P2P-assisted applications. So far, there is no proper profit distribution mechanism to solve this problem. In this paper, we develop a mathematical framework to analyze such economic issues. Inspired by the idea from cooperative game theory, we propose a cooperative profit-distribution model based on Nash Bargaining Solution (NBS), in which both eyeball ISPs and Peer-assisted Content Providers (PCPs) form coalitions and compute a fair Pareto point to determine profit distribution. Moreover, we design a fair and feasible mechanism for profit distribution within each coalition and give a model to discuss the potential competition among ISPs. We show that such a cooperative method not only guarantees the fair profit distribution among network participants, but also improves the economic efficiency of the network system; and the potential competition among ISPs will make the network more efficient. This paper systematically studies solutions to unbalanced profit distribution caused by P2P and presents a feasible cooperative method to increase and fairly distribute the profit.
Ke Xu 0002, Yifeng Zhong
IEEE Trans. Parallel Distributed Syst.1
2013 On popularity prediction of videos shared in online social networks
abstract
Popularity prediction, with both technological and economic importance, has been extensively studied for conventional video sharing sites (VSSes), where the videos are mainly found via searching, browsing, or related links. Recent statistics however suggest that online social network (OSN) users regularly share video contents from VSSes, which has contributed to a significant portion of the accesses; yet the popularity prediction in this new context remains largely unexplored. In this paper, we present an initial study on the popularity prediction of videos propagated in OSNs along friendship links.
Haitao Li 0005, Xiaoqiang Ma, Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002
CIKM5
2013 Resource provisioning on customer-provided clouds: Optimization of service availability
abstract
Cloud computing has recently garnered significant interests from both industries and academia. The industrial pioneers such as Enomaly therefore offered commercial platforms which enable customer-provided resources for cloud computing. Such systems provide very flexible service especially to the customers who seek to run short-term and customized tasks at minimum costs. In this paper, we investigate the service availability challenges on the customer-provided clouds. We find that their cloud resources are highly heterogeneous and dynamic, the service availability remains a critical problem in such systems. This introduces a severe bottleneck to provide reliable cloud service to support long-term tasks. To mitigate such a problem, we present an optimal resource provisioning algorithm that ensures service availability with minimized lease costs. The trace-based simulation further demonstrates its reliability as a promising complement to the datacenter-based cloud services.
Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002, Di Wu 0007
ICC4
2013 Video requests from Online Social Networks: Characterization, analysis and generation
abstract
The deep penetration of Online Social Networks (OSNs) have made them major portals for video content sharing. It is known that a significant portion of the accesses to video sharing sites are now coming from OSN users. Yet the unique features of video sharing over OSNs and their impact remain largely unknown. In this paper, we present a measurement study towards understanding the video requests from OSNs. We closely collaborated with a large-scale Facebook-like OSN to analyze its user access logs spanning over four months. Our measurement reveals a number of distinctive features on the popularity distribution of videos shared over the OSN. In particular, we observe that the OSN amplifies the skewness of video popularity so largely that about 2% most popular videos account for 90% of total views; the video requests distribution also exhibits perfect powerlaw feature; video popularity evolution shows more dynamics. All these noticeably differ from that of conventional videos, such as YouTube videos. To further understand the characteristics, we model the video viewing and sharing behaviors in OSNs, leading to the development of a practical emulator. It reveals the gap between the sharing rate and the viewing rate, and generates user requests that well capture the video popularity distribution and dynamics as observed in our empirical data.
Haitao Li 0005, Jiangchuan Liu, Ke Xu 0002
INFOCOM4
2013 The 2ACT model-based evaluation for in-network caching mechanism
abstract
With the popularity of information and content items that can be cached within ISP networks, developing high-quality and efficient content distribution approaches has become an important task in future internet architecture design. As one of the main techniques of content distribution, in-network caching mechanism has attracted attention from both academia and industry. However, the general evaluation model of in-network caching is seldom discussed. The trade-off between economic cost and the deployment of in-network caching still remains largely unclear, especially for heterogeneous applications. We take a first yet important step towards the design of a better evaluation model based on the Application Adaptation CapaciTy (2ACT) of the architecture to quantify the trade-off in this paper. Based on our evaluation model, we further clarify the deployment requirements for the in-network caching mechanism. Based on our findings, ISPs and users can make their own choice according to their application scenarios. © 2013 IEEE.
Ke Xu 0002, Ning Wang 0001, Tong Li 0014
ISCC1
2013 Green IGP link weights for energy-efficiency and load-balancing in IP backbone networks
Frédéric François, Ning Wang 0001, Klaus Moessner, Stylianos Georgoulas, Ke Xu 0002
Networking5
2013 Research achievements on the new generation Internet architecture and protocols
Ying Liu 0024, Zhou Zhang 0008, Ke Xu 0002
Sci. China Inf. Sci.4
2013 Resource management in radio access and IP-based core networks for IMT Advanced and Beyond
Gang Su, Markus Hidell, Henrik Abrahamsson, Bengt Ahlgren, Dan Li 0001, Peter Sjödin, Voravit Tanyingyong, Ke Xu 0002
Sci. China Inf. Sci.8
2013 Accelerating Peer-to-Peer File Sharing with Social Relations
abstract
Peer-to-peer file sharing systems, most notably BitTorrent (BT), have achieved tremendous success among Internet users. Recent studies suggest that long-term relationships among BT peers could be explored for peer cooperation, so as to achieve better sharing efficiency. However, whether such long-term relationships exist remain unknown. From an 80-day trace of 100,000 real world swarms, we find that less than 5% peers can meet each other again throughout the whole period, which largely invalidates the fundamental assumption of these peer cooperation protocols. Yet the recent emergence of online social network applications sheds new light on this problem. In particular, a number of BT swarms are now triggered by Twitter, reflecting a new trend for initializing sharing among communities. In this paper, we for the first time examine the challenges and potentials of accelerating peer-to-peer file sharing with Twitter social networks. We show that the peers in such swarms have stronger temporal locality, thus offering great opportunity for improving their degree of sharing. Based on the Hadamard Transform of peers' online behaviors, we develop a social index to quickly locate peers of common patterns. We further demonstrate a practical cooperation protocol that identifies and utilizes the social relations with the index. Our PlanetLab experiments indicate that the incorporation of social relations remarkably accelerates the downloading time. The improvement remains noticeable even in a hybrid system with a small set of socially active peers only.
Feng Wang 0001, Jiangchuan Liu, Chuang Lin 0002, Ke Xu 0002, Chonggang Wang
IEEE J. Sel. Areas Commun.5
2013 Torrents on Twitter: Explore Long-Term Social Relationships in Peer-to-Peer Systems
abstract
Peer-to-peer file sharing systems, most notably BitTorrent (BT), have achieved tremendous success among Internet users. Recent studies suggest that the long-term relationships among BT peers can be explored to enhance the downloading performance; for example, for re-sharing previously downloaded contents or for effectively collaborating among the peers. However, whether such relationships do exist in real world remains unclear. In this paper, we take a first step towards the real-world applicability of peers' long-term relationship through a measurement based study. We find that 95% peers cannot even meet each other again in the BT networks; therefore, most peers can hardly be organized for further cooperation. This result contradicts to the conventional understanding based on the observed daily arrival pattern in peer-to-peer networks. To better understand this, we revisit the arrival of BT peers as well as their long-range dependence. We find that the peers' arrival patterns are highly diverse; only a limited number of stable peers have clear self-similar and periodic daily arrivals patterns. The arrivals of most peers are, however, quite random with little evidence of long-range dependence. To better utilize these stable peers, we start to explore peers' long-term relationships in specific swarms instead of conventional BT networks. Fortunately, we find that the peers in Twitter-initialized torrents have stronger temporal locality, thus offering great opportunity for improving their degree of sharing. Our PlanetLab experiments further indicate that the incorporation of social relations remarkably accelerates the download completion time. The improvement remains noticeable even in a hybrid system with a small set of social friends only.
Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002, Di Wu 0007
IEEE Trans. Netw. Serv. Manag.4
2012 Understanding video propagation in online social networks
abstract
Recent statistics suggest that online social network (OSN) users regularly share video contents from video sharing sites (VSSes), and a significant amount of views of VSSes are indeed from OSN users nowadays. By crawling and comparing the statistics of same videos shared in both RenRen (the largest Facebook-like OSN in China) and Youku (the largest Youtube-like VSS in China), we find that the huge and distinguished video requests from OSNs have substantially changed the workload of VSSes. In particular, OSNs amplify the skewness of video popularity so largely that about 0.31% most popular videos account for 80% of total views. Another interesting phenomenon is that many popular videos in VSSes may not receive many requests in OSNs. To further understand these findings, we track the propagation process of videos shared in RenRen since their introduction to this OSN, and analyze the effect of potential parameters to such process, including the number of initiators (users who bring the video to the OSN directly from a VSS), branching factor (the number of users who watch the friend's shared video), and share rate (the probability that the viewers of a video will further share this video). Beyond our expectation, none of these factors determine a video's popularity in an OSN. Instead, it shows great randomness for the number of a video's potential requests when it is shared to an OSN. By modifying the basic Galton-Watson stochastic branching process, we develop a simple yet effective model to simulate the video propagation process in an OSN. Simulation results show that it can well capture the randomness of a video's popularity and the skewed video popularity distribution.
Haitao Li 0005, Jiangchuan Liu, Ke Xu 0002, Song Wen 0004
IWQoS3
2012 Exploring the policy selection of P2P VoD system - A simulation based research
abstract
The P2P-assisted video-on-demand (P2P VoD) service has achieved tremendous success among the Internet users. There are three core strategies in the P2P VoD system: the piece selection policy, the peer selection policy as well as the replica management policy. Different from the existing research works that only consider single policy optimization, we for the first time study the existing P2P VoD policies by using a simulation framework to understand the performance of different policy compositions. The simulation results indicate that when the bandwidth and storage resources are limited in the P2P VoD system, the composition of the sequential piece selection policy, the cascading peer selection policy and the proportional replica management policy has the best performance among all different policy compositions. However, when the bandwidth and storage resources are sufficient in the P2P VoD system, there will be little difference between different choices.
Ke Xu 0002, Yifeng Zhong
IWQoS2
2012 Routing On Demand: Toward the Energy-Aware Traffic Engineering with OSPF
Meng Shen 0001, Ke Xu 0002, Ning Wang 0001, Yifeng Zhong
Networking (1)3
2012 Enhancing Traffic Locality in BitTorrent via Shared Trackers
Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002
Networking (2)4
2012 Video sharing in online social networks: measurement and analysis
abstract
Online social networks (OSNs) have become popular destinations for connecting friends and sharing information. Recent statistics suggest that OSN users regularly share contents from video sites, and a significant amount of requests of the video sites are indeed from them nowadays. These behaviors have substantially changed the workload of online video services. To better understand this paradigm shift, we conduct a long-term and extensive measurement of video sharing in RenRen, the largest Facebook-like OSN in China. In this paper, we focus on the video popularity distribution and evolution. In particular, we find that the video popularity distribution exhibits perfect power-law feature (while videos in YouTube exhibit a power-law waist with a long truncated tail). Moreover, we observe that the requests for the new published videos generally experience two or three days latency to reach the peak value, and then change dynamically with a series of unpredictable bursts (while in YouTube, videos reach the global peak immediately after introduction to the system, and then the accesses generally decrease overtime, except possibly on some special days). These differences can raise new challenges to content providers. For example, the video popularity is now hard to predict based on their historical requests. We further develop a simple yet effective model to simulate user requests process across videos in OSNs. Trace-based simulation shows that it can well capture the observed features.
Haitao Li 0005, Jiangchuan Liu, Ke Xu 0002
NOSSDAV4
2012 Measurement, modeling and enhancement of BitTorrent-based VoD system
Ke Xu 0002, Jiangchuan Liu
Comput. Networks2
2012 Understand traffic locality of peer-to-peer video file swarming
Jiangchuan Liu, Ke Xu 0002
Comput. Commun.3
2012 Enhancing the Trust of Internet Routing With Lightweight Route Attestation
abstract
The weak trust model in Border Gateway Protocol (BGP) introduces severe vulnerabilities for Internet routing including active malicious attacks and unintended misconfigurations. Although various secure BGP solutions have been proposed, the complexity of security enforcement and data-plane attacks still remain open problems. We propose TBGP, a trusted BGP scheme aiming to achieve high authenticity of Internet routing with a simple and lightweight attestation mechanism. TBGP introduces a set of route update and withdrawal rules that, if correctly enforced by each router, can guarantee the authenticity and integrity of route information that is announced to other routers in the Internet. To verify this enforcement, an attestation service running on each router provides interfaces for a neighboring router to challenge the integrity of its routing stack, enforced rules, and the attestation service itself. If this attestation succeeds, the neighboring router updates its routing table or announces the route to its neighbors, following the same rules. Thus, a router on a routing path only needs to verify one neighbor's routing status to ensure that the route information is valid. Through this, TBGP builds a transitive trust relationship among all routers on a routing path. We implement a prototype of TBGP to investigate its practicality. In our implementation, we use identity-based signature and trusted computing techniques to further reduce the complexity of security operations. Our security analysis and performance study shows that TBGP can achieve the security goals of BGP with significantly better convergence performance and lower computation overhead than existing secure BGP solutions.
Qi Li 0002, Mingwei Xu 0001, Xinwen Zhang, Patrick P. C. Lee, Ke Xu 0002
IEEE Trans. Inf. Forensics Secur.6
2011 Cost-Effective Partial Migration of VoD Services to Content Clouds
abstract
Since user demand for a Video-on-demand (VoD) service varies with time in one-day period, provisioning self-owned servers for the peak load it must sustain a few hours per day leads to bandwidth underutilization at other times. Content clouds, e.g. Amazon Cloud Front and Azure CDN, let VoD providers pay by bytes for bandwidth resources, potentially leading to cost savings even if the unit rate to rent a machine from a cloud provider is higher than the rate to own one. In this paper, based on long-term traces from two large-scale VoD systems and temporal development model of content clouds, we tackle challenges, design and potential benefits in migrating VoD services into the hybrid cloud-assisted deployment, where the user requests are partly served by the self-owned servers and partly served by the cloud. Our measurements show that the popularity of the most popular videos decays so quickly, for example, by 11% after one hour that it poses large challenges on updating videos in the cloud. However, the trace-driven evaluations show that our proposed migration strategies (active, reactive and smart strategies), although simply based on the current information, can make the hybrid cloud-assisted VoD deployment save up to 30% bandwidth expense compared with the Clients/Server mode. They can also handle unpredicted the flash crowd traffic with little cost. It also shows that the cloud price and server bandwidth chosen play the most important roles in saving cost, while the cloud storage size and cloud content update strategy play the key roles in the user experience improvement.
Haitao Li 0005, Lili Zhong, Jiangchuan Liu, Bo Li 0001, Ke Xu 0002
IEEE CLOUD5
2011 Enhancing the trust of internet routing with lightweight route attestation
abstract
The weak trust model in Border Gateway Protocol (BGP) introduces severe vulnerabilities for Internet routing including active malicious attacks and unintended misconfigurations. Although various secure BGP solutions have been proposed, they share similar weaknesses such as high complexity of security enforcement and incapability of data-plane attack prevention. We propose TBGP, a trusted BGP scheme aiming to achieve high authenticity of Internet routing with a simple and lightweight attestation mechanism. TBGP introduces a set of route update and withdrawal rules that, if correctly enforced by each router, can guarantee the authenticity and integrity of route information that is announced to other routers in the Internet. Through this, TBGP builds a transitive trust relationship among all routers on a routing path. We implement a prototype of TBGP to investigate its practicality. In our implementation, we use identity-based signature (IBS) and trusted computing (TC) techniques to further reduce the complexity of security operations. The performance study show that TBGP can achieve significantly better convergence performance and lower computation overhead than existing secure BGP solutions.
Qi Li 0002, Mingwei Xu 0001, Xinwen Zhang, Patrick P. C. Lee, Ke Xu 0002
AsiaCCS6
2011 SafeZone: A Hierarchical Inter-Domain Authenticated Source Address Validation Solution
abstract
Next generation Internet is highly concerned with the issue of trustworthy. An important foundation of trustworthy is authentication of the source IP address. With existing signature-and-verification based defense mechanisms, there is a lack of hierarchical architecture, which makes the structure of the trust alliance excessively flat and single. Moreover, with the increasing scale of trust alliances, costs of validation grow so quickly that they do not adapt to incremental deployment. Via comparison with traditional solutions, this article proposes a hierarchical, inter-domain authenticated source address validation solution named SafeZone. SafeZone employs two intelligent designs: lightweight tag replacement and a hierarchical partitioning scheme, each of which helps to ensure that SafeZone can construct trustworthy and hierarchical trust alliances without the negative influences and complex operations on de facto networks. Extensive experiments also indicate that SafeZone can effectively obtain the design goals of a hierarchical architecture, along with lightweight, loose coupling and "multi-fence support" as well as supporting incremental deployment.
Ke Xu 0002
GLOBECOM3
2011 SAVT: A Practical Scheme for Source Address Validation and Traceback in Campus Network
abstract
In current network, as we all know, packets delivered by routers only rely on destination-address-directed forwarding, but their source addresses are not checked. Consequently, this incurs many serious network security breach events which are hard to trackback. Under this situation, a switch (we call it SAVI switch) followed SAVI (Source Address Validation Improvement) framework proposed by IETF was invented which dedicates to resolving this problem in user local subnet. SAVI switch is a direct and very effective anti-spoofing device, but because it just steps into a phase of industrialization and for economical and incremental deployment reasons, these switches are not fully covered in domain. This results in two issues at the same time: 1)how to filter out and abandon those packets whose source IP addresses belong to SAVI switches coverage, but actually not, otherwise, this will severely compromise the SAVI switch access users' motivation and SAVI's promotion. 2) how to traceback those packets' source router-the first hop routers of spoofed packets. In this paper, we present SAVT, a practical and smart scheme for source address validation and traceback in campus network for all outbound packets, it just need less 25% routers as filter router can resolve those two questions in most condition. Experiments illustrate our proposal keeps the promise of practicality, stability and efficiency.
Guangwu Hu, Ke Xu 0002
ICCCN3
2011 An Algebraic Approach to Computing the Reliability of Internet Routing
abstract
Evaluating the reliability of Internet routing is important for an ISP to assess existing peer relationships or establish new peer relationships. Existing algorithms for network reliability computations take all routing paths as inputs. However, these paths may not be actually available for routing because of the constraints of routing policies in the Internet. In this paper, we propose an algebraic approach that effectively reduces the number of candidate routing paths according to the given routing policy. We further improve the accuracy of the routing reliability result by subtracting the miscounted value of routing paths due to overlooking routing policy constraints.
Qi Li 0002, Mingwei Xu 0001, Patrick P. C. Lee, Ke Xu 0002
ICCCN5
2011 One More Weight is Enough: Toward the Optimal Traffic Engineering with OSPF
abstract
Traffic Engineering (TE) leverages information of network traffic to generate a routing scheme optimizing the traffic distribution so as to advance network performance. However, optimizing the link weights for OSPF to the offered traffic is an known NP-hard problem. In this paper, we model the optimal TE as the utility maximization of multi-commodity flows and theoretically prove that any given set of optimal routes corresponding to a particular objective function can be converted to shortest paths with respect to a set of positive link weights, which can be explicitly formulated using the optimal distribution of traffic and objective function. This can be directly configured on OSPF-based protocols. On these bases, we employ the Network Entropy Maximization (NEM) framework and develop a new OSPF-based routing protocol, SPEF, to realize a flexible way to split traffic over shortest paths in a distributed fashion. Actually, comparing to OSPF, SPEF only needs one more weight for each link and provably achieves optimal TE. Numerical experiments have been done to compare SPEF with the current version of OSPF, showing the effectiveness of SPEF in terms of link utilization and network load distribution.
Ke Xu 0002, Jiangchuan Liu, Meng Shen 0001
ICDCS1
2011 A model approach to estimate Peer-to-Peer traffic matrices
abstract
Peer-to-Peer (P2P) applications have become increasingly popular in recent few years, which bring new challenges to network management and traffic engineering (TE). As basic input information, P2P traffic matrices are of significant importance for TE. Due to excessively high cost of direct measurement, a lot of studies aim at modeling and estimating general traffic matrices, but few focus on P2P traffic matrices. In this paper, we proposed a model to estimate P2P traffic matrices in networks. Important factors are considered, including the number of peers, the localization ratio of P2P traffic, and the distances among different networks. Here distance can be hop counts or geographic distance accordingly. To validate our model, we have evaluated the performance using both real P2P live steaming traces and file sharing application traces. Evaluation results show that the proposed model outperforms the other two typical models for general traffic matrices estimation, in terms of estimate errors. To the best of our knowledge, this is the first research on P2P traffic matrices estimation. P2P traffic matrices, derived from the model, can be applied to P2P traffic optimization and other TE fields.
Ke Xu 0002, Meng Shen 0001, Mingjiang Ye
INFOCOM1
2011 Access Path Based Source Address Validation in Mobile IPv6
Ke Xu 0002, Qi Li 0002
NPC2
2011 Pitfalls of re-sharing BitTorrent contents: The failure of daily pattern
abstract
Peer-to-peer file sharing systems, most notably Bit-Torrent (BT), have achieved tremendous success among Internet users. Recent studies suggest that the long-term relationships among BT peers can be explored to enhance the downloading performance; for example, the cooperation of peers to re-share old contents. However, whether such relationships can be built still remain unknown. In this paper, we take a first step towards the real-world applicability of the content re-sharing through a measurement based study. We find that 95% peers cannot even meet each other again in the BT networks; therefore, most peers can hardly be organized for further cooperation. This result is contradict to the conventional understanding based on the observed daily arrival pattern in peer-to-peer networks. To better understand this, we revisit the arrival of BT peers as well as their long-range dependence. We find that the peers' arrival patterns are highly diverse; only a limited number of peers have very clear self-similar and periodic daily arrival features (which we call them "stable peers"). The arrivals of other peers are, however, quite random with the clear absence of long-range dependence.
Xu Cheng 0004, Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002
Peer-to-Peer Computing5
2011 PPVA: A universal and transparent P2SP accelerator for online video sharing
abstract
To alleviate the server bandwidth cost of online video sharing services, p2p delivering has been suggested as an effective tool with success already seen in accelerating individual sites. The numerous video sharing sites existed however call for a universal solution that provides transparent p2p acceleration beyond ad hoc solutions. More importantly, only a universal platform can fully explore the aggregated video and client resources across sites, particular for identical videos replicated in diverse sites. To this end, we develop PPVA, a working platform for universal and transparent P2SP (peer to server and peer) accelerating. As of May 2011, it has attracted over 190 million distinct clients, with 78 million daily transactions. We will demonstrate the novel features, implementation, and also effectiveness of PPVA.
Haitao Li 0005, Jiangchuan Liu, Ke Xu 0002
Peer-to-Peer Computing4
2011 Large-scale P2PVOD system: Focusing on clients
Ke Xu 0002, Haitao Li 0005, Xin Yao 0003
Sci. China Inf. Sci.2
2011 Impact of user selfishness in construction action on the streaming quality of overlay multicast
Dan Li 0001, Yong Cui 0001, Jiangchuan Liu, Ke Xu 0002
Comput. Networks5
2011 Defending Against Distance Cheating in Link-Weighted Application-Layer Multicast
abstract
Application-layer multicast (ALM) has recently emerged as a promising solution for diverse group-oriented applications. Unlike dedicated routers in IP multicast, the autonomous end-hosts are generally unreliable and even selfish. A strategic host might cheat about its private information to affect protocol execution and, in turn, to improve its individual benefit. Specifically, in a link-weighted ALM protocol where the hosts measure the distances from their neighbors and accordingly construct the ALM topology, a selfish end-host can easily intercept the measurement message and exaggerate the distances to other nodes, so as to reduce the probability of being a relay. Such distance cheating, rarely happening in IP multicast, can significantly impact the efficiency and stability of the ALM topology. To defend against this kind of cheating, we present a Vickrey–Clarke–Groves (VCG)-based cheat-proof mechanism in this paper. We demonstrate a practical mapping from the utility, payment, and welfare of a VCG mechanism to the link-weighted ALM context. Based on this, we further discuss practical issues for implementing the cheat-proof mechanism—specifically, a trustworthy distributed algorithm for payment computation. Performance analyses show that the overheads of the computation, storage, and communication of our implementation are controlled at low levels, and extensive simulations further testify the implementation's effectiveness. Although there are other similar studies in this area, the contribution of our cheat-proof mechanism and its implementation primarily lies in two aspects. On one hand, we first explicitly solve the distance cheating problem in link-weighted ALM since its proposal by mapping the VCG mechanism to link-weighted ALM context. On the other hand, our distributed implementation can not only effectively defend against distance cheating, but can also avoid the potential cheating behaviors when selfish ALM nodes fulfill the cheat-proof mechanism itself.
Dan Li 0001, Jiangchuan Liu, Yong Cui 0001, Ke Xu 0002
IEEE/ACM Trans. Netw.5
2011 LBMP: A Logarithm-Barrier-Based Multipath Protocol for Internet Traffic Management
abstract
Traffic management is the adaptation of source rates and routing to efficiently utilize network resources. Recently, the complicated interactions between different Internet traffic management modules have been elegantly modeled by distributed primal-dual utility maximization, which sheds new light for developing effective management protocols. For single-path routing with given routes, the dual is a strictly concave network optimization problem. Unfortunately, the general form of multipath utility optimization is not strictly concave, making its solution quite unstable. Decomposition-based techniques like TRaffic-management Using Multipath Protocol (TRUMP) alleviates the instability, but their convergence is not guaranteed, nor is their optimality. They are also inflexible in differentiating the control at different links. In this paper, we address the above issues through a novel logarithm-barrier-based approach. Our approach jointly considers user utility and routing/congestion control. It translates the multipath utility maximization into a sequence of unconstrained optimization problems, with infinite logarithm barriers being deployed at the constraint boundary. We demonstrate that setting up barriers is much simpler than choosing traditional cost functions and, more importantly, it makes optimal solution achievable. We further demonstrate a distributed implementation, together with the design of a practical Logarithm Barrier-based-Multipath Protocol (LBMP). We evaluate the performance of LBMP through both numerical analysis and packet-level simulations. The results show that LBMP achieves high throughput and fast convergence over diverse representative network topologies. Such performance is comparable to TRUMP, and is often better. Moreover, LBMP is flexible in differentiating the control at different links, and its optimality and convergence are theoretically guaranteed.
Ke Xu 0002, Jiangchuan Liu, Jixiu Zhang
IEEE Trans. Parallel Distributed Syst.1
2010 The Minimum Server Bandwidth in Peer-Assisted VoD Systems
abstract
Recent years, the wide spread peer-assisted video-on-demand (VoD) systems have generated a great attention on how to optimize these applications. In particular, how to improve the system performance has become a popular issue. In this paper, we propose how to minimize server bandwidth to satisfy user demand in peer-assisted VoD systems. Furthermore, a linear programming method is presented to calculate the optimal value. We carry out extensive simulation to show how the system performance varies with the change of system parameters. Via comparison, we find conventional peer-selection algorithms, the random algorithm and the greedy algorithm do not perform well. Further work is needed in designing better peer selection algorithms.
Ke Xu 0002
ICCCN3
2010 Exploring BitTorrent peer distribution via hybrid PlanetLab-Internet measurement
abstract
Understanding the peer distribution over the global Internet is the key issue toward building new generation of ISP-friendly peer-to-peer systems. However, there are unfortunately significant scalability and representability challenges in measuring and understanding real-world peer distribution. In this paper, we demonstrate a novel hybrid measurement methodology that uses the PlanetLab as a distributed probing platform to interact with BitTorrent trackers and peers in the global Internet.
Jiangchuan Liu, Ke Xu 0002
IWQoS3
2010 PPVA: A universal and transparent peer-to-peer accelerator for interactive online video sharing
abstract
Recent years have witnessed an explosion of online video sharing as a new killer Internet application. Yet, given limited network and server resources, user experience with existing video sharing sites are far from being satisfactory. To alleviate the bottleneck, peer-to-peer delivering has been suggested as an effective tool with success already seen in accelerating individual sites. The numerous video sharing sites existed however call for a universal solution that provides transparent peer-to-peer acceleration beyond ad hoc solutions. More importantly, only a universal platform can fully explore the aggregated video and client resources across sites, particular for identical videos replicated in diverse sites. To this end, we develop PPVA, a working platform for universal and transparent peer-to-peer accelerating. PPVA was first released in May 2008 and has since been constantly updated. As of January 2010, it has attracted over 50 million distinct clients, with 48 million daily transactions. In this paper, we highlight the unique challenges in implementing such a platform, and discuss the PPVA solutions. We have also constantly monitored the service of PPVA since its deployment. The mass amount of traces collected enables us to thoroughly investigate its effectiveness and potential drawbacks, and provide valuable guidelines to its future development.
Ke Xu 0002, Haitao Li 0005, Jiangchuan Liu
IWQoS1
2010 Collaborative delay-aware scheduling in peer-to-peer UGC video sharing
abstract
We have recently witnessed an explosion of user-generated content (UGC) sharing, particularly video clips, as the new killer Internet application. Given the sheer amount of resource demands, the peer-to-peer (or peer-assisted) model has been suggested for this new service scenario. There are however a series of unique challenges from the UGC videos to be addressed, in particular, their significantly shorter lengths. As such, any delay, even being minor as compared to those for conventional movie-like videos, will be perceptually amplified.
Xu Cheng 0004, Feng Wang 0001, Jiangchuan Liu, Ke Xu 0002
NOSSDAV4
2010 On Tracker Selection for Peer-to-Peer Traffic Locality
abstract
BitTorrent (BT) is an extremely successful peer-to-peer (P2P) application providing efficient file sharing over the Internet. The ever-increasing traffic among the peers has also put unprecedented pressure to Internet Service Providers (ISPs). P2P locality has therefore been widely suggested, which explores finding local resources to optimize the cross-ISP/AS traffic. However, the ISPs would fail to reduce the cross-AS traffic if they could not control the neighbor selection of their P2P subscribers. In this paper, we examine the applicability of P2P locality through real-world measurement. We find that the widely deployed load balance trackers will greatly reduce the efficiency of traffic locality. Due to peers' random tracker selection, there is no grantee that the peers will always choose the modified trackers as we expected. To make the matter worse, some Internet trackers involve serious copyright violation and may hardly cooperate with the ISPs. Fortunately, our investigation of the AS-Tracker relationship indicates that if we carefully select the trackers during the locality deployment, most peers can still be controlled by the ISPs with relatively high probability. A machine learning based model is then proposed to quantify the similarity of trackers' peer distribution. Our trace-based simulation shows that, the similarity value can provide useful hints to enhance P2P locality. In particular, the peers are more likely to be optimized with higher probability. Moreover, the learning of tracker similarity does not require the global knowledge of Internet trackers, which can hardly be obtained by the individual ISPs.
Jiangchuan Liu, Bo Chen 0019, Ke Xu 0002
Peer-to-Peer Computing4
2010 Proxy caching for peer-to-peer live streaming
Ke Xu 0002, Jiangchuan Liu, Zhijing Qin, Mingjiang Ye
Comput. Networks1
2010 Identify P2P traffic by inspecting data transfer behavior
Ke Xu 0002, Mingjiang Ye, Dah-Ming Chiu
Comput. Commun.1
2010 Measurement and enhancement of BitTorrent-based video file swarming
Jiangchuan Liu, Ke Xu 0002
Peer-to-Peer Netw. Appl.3
2009 Identify P2P Traffic by Inspecting Data Transfer Behaviour
Mingjiang Ye, Ke Xu 0002, Dah-Ming Chiu
Networking3
2009 Web 2.0 traffic measurement: analysis on online map applications
abstract
In recent years, web based online map applications have been getting more and more popular, such as Google Maps, Yahoo Maps. Many new Web 2.0 techniques such as mash-up and AJAX were adopted in these map applications to improve user experiences. But few researches have been done on traffic analysis of the Web 2.0 based online map applications. In this paper, we introduced our research on features of online map applications that previous studies hadn't cover. In our research, we captured map application related HTTP traffic in a campus network while not violating user privacy. We introduced the traffic overview, mash-up and web caching characteristics of four map web sites (Google Maps, Yahoo Maps, Sogou Maps and Baidu Maps). For the first time, the mash-up characteristics of Google map traffic were analyzed using a new method proposed in this paper. The same method could be applied to other mash-up analysis works. These results can help us optimize the future web application designs and CDN based accelerating solution designs.
Zhiguo Gao, Ke Xu 0002
NOSSDAV3
2008 Hierarchical Packet Scheduling for Satellite Multimedia Broadcasting: An Adaptive QoS-Aware Design
abstract
With the unique broadcast nature and ubiquitous coverage of satellite network, the synergy between satellite and terrestrial networks provides new opportunities for delivering wideband services to a wide range of audiences over extensive geographical areas. This paper concerns the optimization techniques pertinent to the packet scheduling to facilitate multimedia content delivery over the satellite with a return channel via terrestrial network. We propose a novel hierarchical packet scheduling (HPS) scheme, which allocates the resources at different parts of the network in an adaptive and QoS-aware manner, in response to traffic dynamics in the networks as well as link variations of each user. Simulations prove that the proposed HPS scheme can effectively improve the end-to-end performance and resource utilization.
Ke Xu 0002
GLOBECOM3
2008 Tod-Cache: Peer-to-Peer Traffic Management and Optimization Using Combined Caching and Redirection
abstract
Peer-to-peer (P2P) computing has emerged as a popular model aiming at further utilizing Internet information and resources, complementing the available client-server services. Such applications have achieved a tremendous success in the past few years and the traffic generated by P2P applications is now a major portion of the Internet. This has also put unprecedented pressure on the network operators and service providers. To address this challenge, a number of P2P traffic management schemes have been proposed in recent years, among which caching and redirection are two representatives. Both of them have shown their success in theory and in practice. Yet, their implementations are largely independent, making the overall effectiveness sub-optimal. In this paper, we for the first time examine the joint implementation of these two promising solutions under a coherent framework, Tod-Cache (Traffic Orientated Distributed Caching). We show that the combination of caching and redirection can dramatically reduce the P2P traffic traversing across ISPs. Under this framework, we formulate the optimal caching and redirection problem, and show its complexity. We then present a highly adaptive and scalable heuristic algorithm which achieves close-to- optimal performance with much lower computational complexity. We extensively evaluate our framework under diverse network and end-system configurations. Our simulation results show that, under the same configuration, it can achieve at least 85% of performance of the traditional cache with at most 1/10 of the device number.
Ke Xu 0002, Jiangchuan Liu
GLOBECOM1
2008 Quadratic Residue Based Address Allocation for Mobile Ad Hoc Networks
abstract
Address allocation in Mobile Ad Hoc Network (MANET) receives significant importance recently, as a mobile device cannot participate in unicast communications until it is assigned with a conflict free IP address. All routing protocols assume nodes to be configured a priori with a unique IP address. Unlike infrastructure based networks, MANET supports autonomous and spontaneous networking and therefore, should be capable of self organization and configuration. We present a new address allocation protocol in MANET based on the concept of quadratic residue. Each node in the network is capable of assigning a unique IP address with low latency. Addresses are reclaimed automatically, as the quadratic residues lie in cycles. This saves lot of extra communication overhead and bandwidth. Our approach also has support for network merging and partitioning. The proposed scheme can be applied to large scale MANETs with low communication overhead, even distribution, and low latency.
Xiaowen Chu 0001, Ke Xu 0002, Z. Sakander, Jiangchuan Liu
ICC3
2008 A Hash Tree Based Authentication Scheme in SIP Applications
abstract
Being one of the leading signaling protocols of VoIP applications, SIP protocol becomes popular in IP-based multimedia services, and securing SIP has become a priority. In this paper, we develop a novel authentication scheme which relies only on one way hash functions. In contrast to the computationally expensive asymmetric RSA signature scheme, our scheme is efficient in signing and verifying procedures. And hash tree is exploited to store and verify key information. Our scheme can be used in SIP entities which have less computation power and limited memory.
Ke Xu 0002, Chunyu Liu 0002
ICC1
2008 Caching the P2P Traffic in ISP Network
abstract
The rise in peer-to-peer(P2P) networking has been tremendous in last several years. P2P traffic has significant impact on ISPs as it accounts for more than half of all traffic. Although many methods have been proposed to manage P2P traffic, little effort was spent on the deployment issues. In this paper, we have studied how to deploy P2P traffic cache devices in the backbone network to maximize the benefit of the ISP. A novel model is proposed to evaluate the benefits of deploying cache devices on different links. Guided by our model, two algorithms were developed to instruct the deployment of cache devices in the network. The experiment shows that deploying cached devices on less than 10% links can efficiently reduce the heavy load of the backbone network.
Mingjiang Ye, Ke Xu 0002
ICC3
2008 Analysis and case study on multi-dimensional scalability of the Internet architecture
Ke Xu 0002, Mingwei Xu 0001, Qi Li 0002
Sci. China Ser. F Inf. Sci.1
2007 A Strategyproof Protocol in Mesh-Based Overlay Streaming System
Ke Xu 0002
MMM (1)2
2007 Modified flap damping mechanism to improve inter-domain routing convergence
Ke Xu 0002
Comput. Commun.3
2006 Heterogeneous QoS Multicast and Its Improvement on Edge-Based Overlay Networks
Suogang Li, Ke Xu 0002, Ying Liu 0024
HPCC3
2006 A Tree-Based Distributed Model for BGP Route Processing
Ke Xu 0002
HPCC3
2006 Segment-sending Schedule in Data-driven Overlay Network
abstract
Data-driven overlay network is suitable for live-event streaming, because it can provide relatively-continuous streaming even in dynamic environment. In terms of improving streaming quality, prior work covered membership management, buffer map exchange, segment requesting schedule, etc. In this paper, we address the problem of segment-sending schedule on the segment-providing node, which may also affect the streaming quality. The schedule methods we discuss include FIFO schedule, lower-sequence favored schedule, and higher-sequence favored schedule. Simulation results show that if users care playing continuity much more than playing delay, the higher-sequence favored schedule brings the best streaming quality; however, if users care playing delay much more than playing continuity, lower-sequence favored schedule is the preferred choice. Through this work, we find another way to improve streaming quality in data-driven overlay network.
Dan Li 0001, Yong Cui 0001, Ke Xu 0002
ICC3
2006 Building Trees to Support Comparable Multi-class Services in Edge Overlay Multicast
abstract
Traditional IP multicast in a network domain is likely to imply a huge burden of storage and forwarding for routers and it's hard to support quality of service. The recent proposed application layer multicast is more scalable but increases traffic load and end-to-end delay. In the paper, we make multicast supporting comparable multi-class services on the overlay network comprising only edge routers. Considering resource limitation on the router and multi-class services by the member, the problem to build minimum cost trees is NP-hard, so we design three feasible heuristic algorithms to solve it. Extensive simulations are conducted to evaluate the performance of the proposed heuristics and validate the effectiveness of reducing the total tree cost and iteration times under considered constraints. The proposal is expected to combine with DiffServ or MPLS VPN networks to fulfill multi-class QoS multicast.
Suogang Li, Ke Xu 0002, Ying Liu 0024
ICCCN3
2006 A modularized QoS multicasting approach on common homogeneous trees for heterogeneous members in DiffServ
abstract
Traditional IP multicast suffers from forwarding state scalability problems as the number of concurrent active multicast groups increases. The problem is exacerbated when provisioning QoS since additional information of resource requirement from members must be kept at routers. In this paper, we firstly consider the comparability between various QoS levels and propose a modularized QoS multicasting approach in the DiffServ model. To achieve the multicast state scalability, the trees, called common trees, are decoupled from groups. The groups including the members requiring heterogeneous QoS are divided into subgroups and delivered through the common homogeneous QoS trees. We put forward a tree-choosing algorithm to find out appropriate trees for a group. Extensive simulations demonstrate that the approach is able to improve multicast forwarding state scalability as well as supporting different QoS requirement. The modularized approach can be considered a building block for QoS multicasting in the DiffServ architecture for its ease of deployment and compatibility with DiffServ
Suogang Li, Ke Xu 0002, Ying Liu 0024
IPCCC3
2006 An improved Wu-Manber multiple patterns matching algorithm
abstract
NIDS is a powerful tool to defense the malicious attacks over the Internet. For the purpose of detecting the attack online, NIDS must inspect the payload of the packets very fast to expose the malicious code. String matching is a very important module in NIDS. To raise the performance of the string matching algorithm, we introduce an improved Wu-Manber algorithm QWM in this article. It combined the method of QS algorithm and used the mismatch information during the patterns matching, reached the top shift distance, improved the performance. We compared QWM with Aho-Corasick, Commentz-Walter and Wu-Manber algorithms. The experiment results shows on large alphabet such as English text and Chinese text, QWM algorithm has better performance, is faster than the other three algorithms. It can be used in various fields, such as network content analysis, intrusion detection, and text retrieval.
Donghong Yang, Ke Xu 0002, Yong Cui 0001
IPCCC2
2006 A Variation of Route Flap Damping to Improve BGP Routing Convergence
abstract
Inter-domain routing stability and convergence delay have significant effect on QoS in Internet RFD is a mechanism to limit route oscillation from spreading wildly and is deemed as a key contributor for Internet routing stability. Recent research discovers that RFD may exacerbate relatively stable routes influenced by path exploration procedure and the interaction between RFD reuse timers. In this paper, a variation of RFD is proposed to deal with the side effect of RFD on routing convergence. Flapping routes are confined by neighboring nodes and invalid routes generated in path exploration are reduced by a RFD-like mechanism more suitable for their characteristics. Simulation results indicate that the modified flap damping mechanism limits persistent flapping routes while causing relatively stable routes converge more quickly
Ke Xu 0002
IWQoS2
2006 Research on Next-Generation Internet Architecture
Ke Xu 0002
J. Comput. Sci. Technol.2
2005 Impact of receiver cheating on the stability of ALM tree
abstract
Application layer multicast (ALM) is an effective supplement to IP multicast, but it has the potential trouble of trust on end systems. For instance, multicast receivers may cheat in order to obtain a better position in the multicast tree. Receiver cheating may transform the multicast tree, and lead to its instability. We establish the cheating model of ALM receivers and analyze the stability of ALM tree when receiver cheating occurs. Simulation results show that receiver cheating has considerably negative effects on the stability of ALM tree. This discovery brings forward an issue in ALM study, that is, we should take receiver cheating into consideration to maintain a stable ALM tree when designing ALM protocols.
Dan Li 0001, Yong Cui 0001, Ke Xu 0002
GLOBECOM3
2005 On peer-to-peer client web cache sharing
abstract
Conventional web caching systems based on client-server model often suffer from the limited cache space and the single point of failure. In this paper, we present a novel peer-to-peer client web caching system, in which end-hosts collectively share their web cache contents. Aggregating these individual web caches, a huge virtual cache space is formed, and the burden on web servers can be greatly lightened. We design an efficient algorithm for managing and searching in the aggregated cache. We also implement consistency control to prevent sharing stale web objects in peers' caches. Finally and most importantly, considering that end-hosts are generally not trustworthy as servers or proxies, we employ an opinion-based sampling technique to minimize the chance of distributing forged copies from malicious nodes. We have built a prototype of the proposed system, and our experimental results demonstrate that it has fast response time with low overhead, and can effectively identify and block malicious peers.
Jiangchuan Liu, Xiamen Chu, Ke Xu 0002
ICC3
2005 Precomputation for intra-domain QoS routing
Yong Cui 0001, Ke Xu 0002
Comput. Networks3
2004 Simple quality-of-service path first protocol and modeling analysis
abstract
QoS (quality-of-service) control is one of the most important mechanisms in the next-generation Internet, where QoS routing (QoSR) is a promising solution. We propose a multi-constrained intradomain QoS routing protocol SQOSPF. The advantages of this protocol include easy implementation, multi-constrained QoS support, high-speed convergence and multiple QoSR algorithms support. Stochastic Petri net is employed to model SQOSPF and analyze impacts of update threshold and routing holding time upon the load of networks and routers. Extensive simulations show that choosing appropriate update threshold and routing holding time can excessively reduce the extra load and keep routing performance at the same time.
Shen Lin 0004, Mingwei Xu 0001, Ke Xu 0002, Yong Cui 0001, Youjian Zhao
ICC3
2004 Using fuzzy-PI controller in active queue management
abstract
In this paper we propose using fuzzy logic to improve the performance of PI controller in the design of AQM (active queue management). With the introduction of integral factor in PI controller, the steady state error in proportional controller (such as RED) is eliminated. However, the response speed is slowed down. We design a fuzzy-PI (FPl) controller to solve this problem. FPI controller combines the advantages of fuzzy control while maintaining the simplicity and robustness of a conventional PI controller. The performance of FPI is verified and compared with Pl controller using ns-2 simulations. It is suggested that FPI is superior to Pl in response speed. Thus FPI is more robust in the presence of disturbance caused by the non-responsive UDP flows and the changing number of active flows.
Fengyuan Ren, Ke Xu 0002
ISCC4
2003 Precomputation for finding paths with two additive weights
abstract
As the most challenging problems of the upcoming next-generation networks, 2-constrained quality of service routing (QoSR) is NP-complete problem, for which we propose a novel precomputation algorithm, LEFPA. This algorithm converts two additive weights to a single metric with linear energy functions (LEFs) and pre-computes QoS routing table with multiple (B) LEFs to further enhance its scalability. We first analyze the performance of LEFs and give a method to determine the feasible and unfeasible areas in the metric space for a QoS request. We then introduce the proposed LEFPA, whose computation complexity is O(B(m+nlogn+n)). Furthermore, we use three methods to evaluate the routing performance. Extensive simulations show that our LEFPA has both absolutely and competitively high performance.
Yong Cui 0001, Ke Xu 0002, Mingwei Xu 0001
ICC2
2003 Multi-constrained routing based on simulated annealing
abstract
Multi-constrained quality-of-service routing (QoSR) is to find a feasible path that satisfies multiple constraints simultaneously, as an NPC problem, which is also a big challenge for the upcoming next-generation networks. In this paper, we propose SA/spl I.bar/MCP, a novel heuristic algorithm, by applying simulated annealing to Dijkstra's algorithm. This algorithm first uses a nonlinear energy function to translate multiple QoS weights into a single metric and then seeks to find a feasible path by simulated annealing. The paper outlines simulated annealing algorithm and analyzes the problems met when we apply it to QoSR. Extensive simulations demonstrate that SA/spl I.bar/MCP has good scalability regarding both network size and the number of QoS constraints with high performance. Furthermore, when most QoS requests are feasible, the running time of SA/spl I.bar/MCP is about O(k(m+nlogn)), which is only k times that of the traditional Dijkstra's algorithm, where k is the number of QoS constraints.
Yong Cui 0001, Ke Xu 0002, Zhongchao Yu, Youjian Zhao
ICC2
2003 Precomputation for Multi-constrained QoS Routing in High-speed Networks
abstract
As one of the most challenging problems of the next-generation high-speed networks, quality-of- service routing (QoSR) with multiple (k) constraints is an NP-complete problem. In this paper, we propose a multiconstrained energy function-based precomputation algorithm, MEFPA. It cares each QoS weight to b degrees, and computes a number (B= C/sub b+k-2//sup k-1/) of coefficient vectors uniformly distributed in the k-dimensional QoS metric space to construct B linear energy functions. Using each LEF, it then converts k QoS constraints to a single energy value. At last, it uses Dijkstra's algorithm to create B least energy trees, based on which the QoS routing table is created. We first analyze the performance of energy functions with k constraints, and give the method to determine the feasible and unfeasible areas for QoS requests in the k-dimensional QoS metric space. We then introduce our MEFPA for k-constrained routing with the computation complexity of O(B(m+n+nlogn)). Extensive simulations show that, with few coefficient vectors, this algorithm performs well in both absolute performance and competitive performance. In conclusion, for its high scalability, high performance and simplicity, MEFPA is a promising QoSR algorithm in the next-generation high-speed networks.
Yong Cui 0001, Ke Xu 0002
INFOCOM2
2003 Adjustable multi-constrained routing with a novel evaluation method
abstract
Quality-of-service routing (QoSR) with multiple constraints, which seeks to find a feasible path satisfying multiple constraints simultaneously, is a challenging problem of the next-generation networks. For its NP-complete complexity, we propose an adjustable heuristic based on converting multiple QoS weights to a single metric with energy functions. By applying the breadth-first search (BFS) to Dijkstra's algorithm with adjustable depth, BFS _MCP (BFS for multi-constrained paths) can adjust its time complexity according to the CPU load on a router in real time. Thus, it has an extensive adaptability. Additionally, we propose a novel approach to performance evaluation by generating QoS constraints, named weight-proportion simulation. Generating QoS constraints similar to QoS applications, this method extends the original success ratio, only used in relative performance comparison, to the evaluation of absolute performance. By this method, extensive simulations show that BFS improves the performance greatly. The main contribution of the paper includes a heuristic for multi-constrained routing and a novel approach to performance evaluation.
Yong Cui 0001, Ke Xu 0002
IPCCC2
2003 Stability of a multicast tree in cumulative layered multicast congestion control
abstract
This paper examines the stability of a multicast tree in the context of a cumulative layered multicast system. In particular it addresses the question, "How does the number of links change us the number of users in a group changes when congestion occurs?" A stability index is defined to evaluate and quantify the stability of such a tree. For obtaining the general expression of the stability index, we develop a simple statistical model and extend it to a more general tree-type: the k-ary balanced tree. We show that the k-values of the k-ary balanced tree have trivial impact on the stability of the tree; however, other parameters in the model, e.g., the dependency-degree factor, the link-marking probability and the tree height, can seriously affect it.
Ke Xu 0002
IPCCC3
2002 Proportional fairness scheduling on tandem network
abstract
We study packet scheduling algorithms that satisfy multiple performance objectives simultaneously. We have realized the proportional fairness principle based QoS model, which defines both delay and loss rate requirements of a class, to include fairness. The resulting proportional fairness scheduling algorithms on a tandem network formalize the goals of the network performance, user's QoS requirements and system fairness, and expose the fundamental tradeoffs between these goals. In particular, it is difficult to provide these objects simultaneously. By performing simulation and measurement experiments, we evaluate the proportional fairness of the algorithm.
Yong Jiang 0001, Ke Xu 0002
ICC3
2002 Rethink the tradeoff between proportional controller and PI controller
abstract
In this paper we rethink the tradeoff between proportional controller and PI controller in AQM (active queue management) algorithm design. With the introduction of integral factor, the steady state error in a proportional controller such as RED is eliminated. However the integral factor also slows down the response speed. We present a simple algorithm P/sup 2/I to solve this problem. P/sup 2/I combines the advantage of the proportional controller and the PI controller. The performance of P/sup 2/I is verified and compared with the PI controller using ns-2 simulations. P/sup 2/I is shown to respond much faster than the PI controller while retaining the merits of the PI controller. We also analyze the impact of the traffic pattern on the design and success of AQM.
Chuang Lin 0002, Ke Xu 0002
ISCC4
2002 A Non-Collision Hash Trie-Tree Based Fast IP Classification Algorithm
Ke Xu 0002, Zhongchao Yu, Mingwei Xu 0001
J. Comput. Sci. Technol.1
2001 A fast IP classification algorithm applying to multiple fields
abstract
With the network applications development, routers must support those functions such as firewalls, provision of QoS and traffic billing etc. All these functions need classification of IP packets, according to which it is determined how different packets are processed subsequently. A novel IP classification algorithm is proposed based on the grid of tries algorithm. The new algorithm not only eliminates original limitations in the case of multiple fields but also shows better performance in regard to both time and space. It has better overall performance than many other algorithms.
Zhongchao Yu, Ke Xu 0002, Mingwei Xu 0001
ICC3