Qi Li 0057

dblp:181/2688-57 · DBLP profile ↗
← Back
26ranked-venue papers
6as first author
22since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 2 first-author · 10 since 2021Security and privacy · 5 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Satellite Communications-Enabled Three-Tier Computing Task Offloading Optimization for Iot Via Multi-Agent Reinforcement Learning
Meihui Li, Meng Li 0007, Qi Li 0057, Ruizhe Yang, Pengbo Si, F. Richard Yu
WCNC3
2026 GIANT: Structure-Agnostic Practical Adversarial Attacks for Graph-based Network Intrusion Detection Systems
Jianjin Zhao, Qi Li 0057, Hua Zhang 0001, Mingshu He, Jiong Dong, Yuyin Ma, Meng Shen 0001
WWW4
2026 KGAgent4CTI: unlocking the power of LLM in threat intelligence
abstract
Abstract Cyber threat intelligence (CTI) serves as the cognitive hub for cybersecurity defense, deeply integrating the domain knowledge of security experts with the characteristics of attack behaviors. Constructing attack knowledge graphs from CTI provides critical support for attack chain reconstruction and defensive decision-making. However, traditional knowledge graph construction methods exhibit significant limitations when facing the domain-specific challenges of CTI: ambiguous entity boundaries leading to named entity recognition (NER) drift, the long-tail phenomenon causing the omission of low-frequency threat elements, and difficulties in modeling multi-hop contextual dependencies. Furthermore, the dynamic evolution of adversarial technique frameworks such as MITRE ATT&CK poses a severe version drift risk for traditional models that rely on parameterized knowledge storage. To address these challenges, this paper introduces KGAgent4CTI—a threat intelligence analysis framework based on large language models (LLMs). Its core breakthroughs are twofold: (1) It establishes a multi-agent collaborative architecture that, through a task decoupling mechanism, decomposes knowledge graph construction into five specialized modules, enabling a progressive cognitive enhancement for attack chain analysis. (2) It designs a dynamic knowledge adaptation engine that combines a hybrid retrieval-augmented generation strategy with version-aware indexing technology, overcoming the limitations of an LLM’s parameterized knowledge storage to achieve precise, zero-shot identification of attack techniques. Our experimental results indicate that, compared with state-of-the-art methods, KGAgent4CTI demonstrates significant improvements, achieving an attack technique identification precision of 92.3% while also reducing the need for manual intervention and computational resources. Furthermore, the knowledge graphs we construct directly enable downstream security tasks, such as attack scenario reconstruction and organizational attribution.
Lirong Yang, Jin Mu, Qi Li 0057
Cybersecur.4
2026 A publishing scheme for high-dimensional graph data under personalized local differential privacy
Kaixuan Li 0007, Hua Zhang 0001, Xiangliang Ma, Qi Li 0057, Yanxin Xu
Neurocomputing5
2026 Pinching-Antenna System (PASS)-Enabled UAV Delivery
abstract
o address the critical need for stable communication and energy efficiency in dynamic unmanned aerial vehicle (UAV) scenarios,o address the critical need for stable communication and energy efficiency in dynamic unmanned aerial vehicle (UAV) scenarios,T a pinching-antenna system (PASS)-enabled UAV delivery framework is proposed, which exploits the capability of PASS to establish a strong line-of-sight link and reduce the free-space pathloss. Aiming at achieving a balance between communication performance and energy efficiency, we define an effective utility function, construct a utility maximization problem, and develop an iterative joint optimization algorithm for pinching antenna (PA) activation vector and UAV delivery sequencing (IJO-PADS). More specifically, to solve the highly coupled mixed-integer nonlinear programming problem of PA activation vector optimization, we propose a pair of algorithms: 1) Branch-and-Bound (BnB) algorithm for finding global optimum; 2) incremental search and local refinement (ISLR) algorithm for reducing computational complexity. With the optimized PA activation vector, we define the path weight between a pair of nodes, which accounts for communication rate reward and energy consumption penalty. To maximize sum pate weight, we propose a genetic algorithm and dynamic programming (GA-DP) hybrid optimization method to tackle the NP-hard problem of delivery sequence planning, where a GA performs global exploration to generate candidate solutions, while a DP performs local refinement to obtain elite solutions. Simulation results indicate that: i) the proposed IJO-PADS framework converges within a moderate number of iterations; ii) the proposed algorithms (BnB, ISLR, GA-DP) outperform several benchmarks, demonstrating the effectiveness of our designs for PA activation and delivery sequence planning; iii) PASS is superior to conventional MIMO systems, due to PASS’s flexible PA activation and low-attenuation waveguide transmission.
Suyu Lv, Meng Li 0007, Qi Li 0057, Yuanwei Liu
IEEE Trans. Commun.3
2026 RePriChain: A Privacy-Enhanced Blockchain With Dynamic Reputation Management for Industry 4.0 Supply Chains
abstract
In the context of Industry 4.0, increasing data interconnectivity in supply chains introduces critical challenges, notably in dynamically detecting evolving malicious behaviors and safeguarding sensitive information. While existing reputation-based blockchain systems enhance transparency and efficiency, they remain vulnerable to slow adaptive attacks and privacy breaches due to limited adaptability in their evaluation mechanisms. To address these limitations, we propose RePriChain, a blockchain-based supply chain model that integrates dynamic reputation management with robust privacy protection. Specifically, we design a logistic regression-based mechanism to dynamically evaluate node reputations and apply adaptive caps based on historical behavior, enabling the timely identification and penalization of malicious actors. To preserve confidentiality during reputation updates, we incorporate confidential smart contracts and fully homomorphic encryption for secure on-chain computation. In addition, an enhanced Access Control List framework is employed for precise permission management, complemented by an input packing mechanism to improve cryptographic computational efficiency effectively. Simulation results demonstrate that the model effectively balances privacy protection and consensus efficiency, confirming its feasibility and effectiveness in supply chain management applications.
Qi Li 0057, Zetian Zhang, Hanqing Yang 0008
IEEE Trans. Ind. Informatics3
2025 Performance Optimization and Improvement of ISAC-Enabled Industrial IoT Based on Intelligent Sharding Blockchain
Meng Li 0007, Ruizhe Yang, Qi Li 0057, Pengbo Si, F. Richard Yu
ICC4
2025 Graph Learning on Instruction Stream-Augmented CFG for Malware Variant Detection
abstract
As malware as a service (MaaS) and organized attacks develop and drive a shift in malware variant generation mechanism, current variant detection, designed to counter conventional obfuscation and anti-detection strategies, falls short in facing new challenges, particularly in identifying variants that maintain core functionalities while altering local behaviors, or those sharing similar code logic but diverge in actual functionalities. To tackle the problems, we present ISCMVD, an Instruction Stream-augmented CFG-based Malware Variant Detection scheme, melding control flow structures with machine semantic information from instruction streams within blocks to build a comprehensive functional representation for variants’ basic and detailed behaviors. Leveraging a global-enhanced attentive graph neural network to integrate local and global functional features, we significantly boost the capture of representative stable primary behaviors’ similarity from variants within the same family identifying variants generated under attackers’ code rewriting, module modification, and other transformation means. Additionally, through cross-family associative analysis, we eliminate classification interference of variants’ logic similarities stemming from the same organization generating. Evaluation results on public and real-world datasets demonstrate the superiority and robustness of ISCMVD with an average of 99.29% in AC and 99.25% in F1 and perform well even in few-shot cases. What’s more important, we achieve a breakthrough in two special sample sets including variants related to MaaS and APT group, and outperform state-of-the-art methods under the current variant generation mechanism, proving its suitability for future trends.
Jiaxin Mi, Qi Li 0057, Zewei Han, Weilue Liao, Junsong Fu 0001
IEEE Trans. Inf. Forensics Secur.2
2025 F2Attack: Two-Factors Scoring Method for Query-Efficient Hard-Label Black-Box Textual Adversarial Attacks
Hua Zhang 0001, Qi Li 0057, Huiyu Zhou 0001
IEEE Trans. Inf. Forensics Secur.5
2025 ReTrial: Robust Encrypted Malicious Traffic Detection via Discriminative Relation Incorporation and Misleading Relation Correction
abstract
Encryption techniques greatly ensure the confidentiality and integrity of network communications. However, they also allow attackers to conceal malicious activities within encrypted traffic, posing severe cybersecurity challenges. Current detection methods primarily rely on statistics and correlation analysis. However, both statistical features and inter-entity relations can be easily obfuscated. Moreover, issues with low-quality data and fixed feature sets limit the generalizability and adaptability to defend against various evasion techniques. Robustifying encrypted malicious traffic detection in adverse conditions is still an open problem. In this paper, we propose ReTrial, a robust encrypted malicious traffic detection system via discriminative relation incorporation and misleading relation correction. The key motivations behind ReTrialare to accurately leverage the rich relations among flows for contextual analysis, and correct misleading ones for robust threat detection. Specifically, we construct a relational multigraph and develop a tailored Graph Attention Network (GAT) to selectively incorporate contextual information. Then we retrieve multi-order neighborhood similarity graphs as observations for adaptive relation correction. Following an iterative scheme, both detector performance and graph topology mutually optimize. To validate the robustness of ReTrial, we simulate various adverse conditions by randomly dropping packets and greedily injecting perturbation edges. The experimental results show that ReTrialis competitive in ideal condition. Under adverse conditions, though the performances of other state-of-the-art methods degrade significantly, ReTrialconsistently exhibits superior performance with a maximum reduction of only 5.88% in F1, highlighting its robustness in threat detection.
Jianjin Zhao, Qi Li 0057, Zewei Han, Junsong Fu 0001, Guoshun Nan, Meng Shen 0001, Bharat K. Bhargava
IEEE Trans. Inf. Forensics Secur.2
2025 Machine Learning-Based Reliable Transmission for UAV Networks With Hybrid Multiple Access
abstract
Emerging applications are placing increasing demands on wireless networks, particularly in terms of ensuring reliable communication for control-related information. However, the complexity of network architectures and the growing number of user devices present significant challenges in achieving reliable multiple access. In this paper, we present a framework that utilizes machine learning (ML) to meet the need for reliable access in unmanned aerial vehicle (UAV) networks. The K-means algorithm is employed to cluster users according to their communication reliability requirements, grouping together users with similar demands within each cluster. Each cluster adopts a different access strategy: clusters with lower reliability requirements utilize non-orthogonal multiple access to enhance spectrum efficiency, while clusters with higher reliability requirements employ orthogonal multiple access to ensure reliability. Taking into account the impact of UAV altitude and power allocation schemes on reliability, we propose an iterative algorithm to optimize the UAV altitude and power allocation factors, aiming to maximize UAV coverage while meeting the users’ reliability requirements. The simulation results validate the effectiveness of the proposed ML-based reliable access scheme, highlighting its potential to enhance the design and deployment of reliable communication in future UAV networks.
Yibo Zhang 0005, Xiangwang Hou, Guoyu Du, Qi Li 0057, Mian Ahmad Jan, Alireza Jolfaei, Muhammad Usman 0015
IEEE Trans. Netw. Serv. Manag.4
2024 Dynamic Resource Allocation for ISAC enabled Internet of Vehicles
abstract
The development of wireless communication technology is reshaping the landscape of intelligent transportation systems, particularly in the realm of internet of vehicles (IoV). Among these, integrated sensing and communications (ISAC) has garnered widespread attention by leveraging shared hardware resources or even spectrum between sensing and communication to achieve integrated benefits. For IoV, parameters such as target position and speed estimated by ISAC can be used as prior information for resource allocation and beamforming to improve communication performance. In this paper, we focus on ISAC-enabled IoV, where radar sensing signals and communication signals are transmitted within different slots of a subframe to avoid interference. We propose a resource allocation scheme to maximize system throughput while meeting the differentiated needs of all users, where spatial division multiple access is dynamically employed based on network load. Simulation outcomes verify the efficiency of the suggested algorithm.
Yibo Zhang 0005, Jingjing Wang 0001, Lanjie Zhang, Qi Li 0057
MobiCom5
2024 Energy-Efficient Communication and Computing Scheduling in UAV-Aided Industrial IoT
abstract
Efficient data processing is crucial for industrial Internet of Things (IIoT) applications, but the limited energy and computing resources in IIoT devices (IIoT-Ds) pose constraints. This article utilizes a unmanned aerial vehicle (UAV) as a computing server for enhanced IIoT mission execution. Specifically, the energy consumption of IIoT-Ds and the UAV, as well as the weighted cost of the communication and computing scheduling strategy in the UAV-aided IIoT, are jointly taken into account. An optimization problem based on the system energy consumption is built under the constraints of UAV motion, computing offloading, and transmitting power allocation. A problem decoupling-based alternating optimization method is proposed to solve the minimization problem by decomposing it into three subproblems: 1) UAV motion optimization; 2) computing offloading configuration; and 3) transmitting power allocation. Through comparing the proposed communication and computing scheduling strategy with existing methods, simulation results illustrate its attainment of quasi-optimal performance, thereby validating the effectiveness of the alternating optimization method.
Qi Li 0057, Jingjing Wang 0001, Pengbo Si, Yibo Zhang 0005, Jianrui Chen 0001, Chunxiao Jiang
IEEE Internet Things J.1
2024 Efficient IoT Device Identification via Network Behavior Analysis Based on Time Series Dictionary
abstract
Due to hardware limitations, Internet of Things (IoT) devices without integrated security become easy targets for network attacks. IoT device identification is significant for network security management. Despite many efforts, previous studies either require excessive features raising concerns about efficiency and privacy, or underutilize the data resources to fulfill the potential of simple features. Moreover, the severe data imbalance problem is unaddressed. In this article, we present IoTProfile, an efficient IoT device identification framework via time series dictionary. It only considers simple packet-level attributes and maps them into different time windows. On this basis, it further follows a shuffle&split organization scheme to structure the imbalanced data as multichannel time series. By performing random convolutional kernel transformations in two ways and aggregations, IoTProfile captures discriminative patterns and forms the frequency count of recurring patterns to profile the network behaviors of IoT devices over a period of time. The experimental results show that IoTProfile is superior to the other state-of-the-art methods in terms of both identification effectiveness and time overhead, achieving 99.81% and 97.65% Macro-F1 scores on the University of New South Wales and University of New Brunswick data sets in under 4 min.
Jianjin Zhao, Qi Li 0057, Mianxiong Dong, Kaoru Ota, Meng Shen 0001
IEEE Internet Things J.2
2024 Graph Mining for Cybersecurity: A Survey
abstract
The explosive growth of cyber attacks today, such as malware, spam, and intrusions, has caused severe consequences on society. Securing cyberspace has become a great concern for organizations and governments. Traditional machine learning based methods are extensively used in detecting cyber threats, but they hardly model the correlations between real-world cyber entities. In recent years, with the proliferation of graph mining techniques, many researchers have investigated these techniques for capturing correlations between cyber entities and achieving high performance. It is imperative to summarize existing graph-based cybersecurity solutions to provide a guide for future studies. Therefore, as a key contribution of this work, we provide a comprehensive review of graph mining for cybersecurity, including an overview of cybersecurity tasks, the typical graph mining techniques, and the general process of applying them to cybersecurity, as well as various solutions for different cybersecurity tasks. For each task, we probe into relevant methods and highlight the graph types, graph approaches, and task levels in their modeling. Furthermore, we collect open datasets and toolkits for graph-based cybersecurity. Finally, we present an outlook on the potential directions of this field for future research.
Bo Yan 0005, Cheng Yang 0002, Chuan Shi 0001, Yong Fang 0002, Qi Li 0057, Yanfang Ye 0001, Junping Du 0001
ACM Trans. Knowl. Discov. Data5
2024 MetaRockETC: Adaptive Encrypted Traffic Classification in Complex Network Environments via Time Series Analysis and Meta-Learning
abstract
Encrypted Traffic Classification (ETC) is crucial for network security management and Quality of Service (QoS) improvement. There have been many attempts to tackle various ETC tasks, however, which generally suffer from task dependency and limited adaptability, falling short of meeting practical requirements. Under the realistic assumptions of complex network environments, diverse encryption techniques and ever-changing application landscapes coexist. It is highly desirable to learn the generic encrypted traffic representations to investigate the common knowledge across different ETC tasks and rapidly adapt to the dynamic shifts. To fill the gap, we propose MetaRockETC, a generic encrypted traffic classification framework, which extracts protocol-agnostic features to learn the common knowledge and rapidly adapt to novel ETC tasks and evolving network environments. In MetaRockETC, we first model packet length sequences of encrypted sessions as multivariate time series and perform random convolution kernel transformations to summarize discriminatory behavioral patterns across channels. By integrating MetaRockETC into an advanced Model-Agnostic Meta-Learning (MAML) framework, we learn a task-adaptive loss function to facilitate better generalization and transferability across diverse ETC tasks. Extensive experimental results demonstrate the superiority of MetaRockETC in both across-task and few-shot scenarios, highlighting its potential to provide a practical solution for encrypted traffic classification in real-world scenarios.
Jianjin Zhao, Qi Li 0057, Yueping Hong, Meng Shen 0001
IEEE Trans. Netw. Serv. Manag.2
2023 Spear-Phishing Detection Method Based on Few-Shot Learning
Qi Li 0057, Mingyu Cheng
APPT1
2023 Graph based encrypted malicious traffic detection with hybrid analysis of multi-view features
Yueping Hong, Qi Li 0057, Yanqing Yang, Meng Shen 0001
Inf. Sci.2
2023 Reliable Transmission for NOMA Systems With Randomly Deployed Receivers
abstract
Non-orthogonal multiple access (NOMA) is regarded as a promising technology in achieving high capacity and massive connectivity. In this paper, the reliable transmission scheme of downlink NOMA systems is investigated. In particular, we divide the disc covered by the base station into several annular areas, where the receivers are randomly located following a uniform distribution. In this way, NOMA pairing is performed by randomly selecting receivers from two different areas. Firstly, we derive the closed-form expressions of bit error rate (BER) with quadrature phase-shift keying (QPSK) modulation, where the channel is modeled as small-scale Rayleigh fading and large-scale path loss. To achieve reliable communications, then, the BER performance of the receiver with the worst channel gain in each area is studied. Finally, an optimal power allocation algorithm is proposed, which obtains the minimum transmission power and optimal power allocation factor with a given BER constraint of all receivers. Extensive simulations demonstrate the accuracy of obtained BER expressions and the effectiveness of the proposed algorithm. These results provide valuable insight into realizing on reliable transmission of NOMA with randomly deployed receivers.
Yibo Zhang 0005, Jingjing Wang 0001, Lanjie Zhang, Qi Li 0057, Kwang-Cheng Chen
IEEE Trans. Commun.5
2022 LSTM Based Phishing Detection for Big Email Data
abstract
In recent years, cyber criminals have successfully invaded many important information systems by using phishing mail, causing huge losses. The detection of phishing mail from big email data has been paid public attention. However, the camouflage technology of phishing mail is becoming more and more complex, and the existing detection methods are unable to confront with the increasingly complex deception methods and the growing number of emails. In this article, we proposed an LSTM based phishing detection method for big email data. The new method includes two important stages, sample expansion stage and testing stage under sufficient samples. In the sample expansion stage, we combined KNN with K-Means to expand the training data set, so that the size of training samples can meet the needs of in-depth learning. In the testing stage, we first preprocess these samples, including generalization, word segmentation and word vector generation. Then, the preprocessed data is used to train a LSTM model. Finally, on the basis of the trained model, we classify the phishing emails. By experiment, we evaluate the performance of the proposed method, and experimental results show that the accuracy of our phishing detection method can reach 95 percent.
Qi Li 0057, Mingyu Cheng, Junfeng Wang 0003
IEEE Trans. Big Data1
2021 An IRL-based malware adversarial generation method to evade anti-malware engines
Qi Li 0057
Comput. Secur.2
2021 CNN-Based Malware Variants Detection Method for Internet of Things
abstract
Malware has become one of the most serious security threats to the Internet of Things (IoT). Detection of malware variants can inhibit the spread of malicious code from the traditional network to the IoT, and can also inhibit the spread of malicious code within the IoT, which is of great significance to the security detection and defense of the IoT. Since the terminals and the operating systems of IoT are very different from the traditional network, when malicious code is transferred from the traditional network to the IoT platform, the characteristics of the variants may change significantly. As a result, malicious code variant detection methods for traditional platforms cannot be directly applied to the IoT. In this article, a malware variant detection method for the IoT is proposed. First, we propose a feature representation method based on RGB image for IoT to solve the problem of representation difficulty caused by platform difference, which pays more attention to the assembly code and developer information of the malware. The generated image has richer texture information, which can dig out the deep association between the IoT variants and the original malicious code. Moreover, this article improves the convolutional neural network model by combining the self-attention mechanism and spatial pyramid pooling to solve the problem of large differences in the size of IoT malware. Experimental results show that our method can be used in cross-platform to detect malware variants in the IoT effectively.
Qi Li 0057, Jiaxin Mi, Junfeng Wang 0003, Mingyu Cheng
IEEE Internet Things J.1
2019 Detection malicious Android application based on simple-Dalvik intermediate language
Qi Li 0057, Meiqi Chen 0003
Neural Comput. Appl.1
2017 Research on machine learning algorithms and feature extraction for time series
abstract
This paper aims to use various machine learning algorithms and explore the influence between different algorithms and multi-feature in the time series. The real consumption records constitute the time series as the research object. We extract consumption mark, frequency and other features. Moreover, we utilize support vector machine (SVM), long short-term memory (LSTM) and other algorithms to predict the user's consumption behavior. Besides, we have also implemented multi-feature fusion and multi-algorithm fusion with LSTM and SVM. Eventually, the experimental results show that LSTM algorithms is advantageous in prediction when the data is sparse. In the other hand, the SVM is beneficial when the data is more abundant. What's more, LSTM-SVM fusion model has advantages on the extracting features of LSTM and on the classification of SVM. In most cases, LSTM-SVM is most outstanding in prediction.
Lei Li 0009, Yabin Wu, Yihang Ou, Qi Li 0057, Yanquan Zhou, Daoxin Chen
PIMRC4
2014 Green heterogeneous network with load balancing in LTE-A systems
abstract
Heterogeneous networks (HetNets) have been considered as a promising technique for improving spectral efficiency, but the energy efficiency influenced by the fluctuation of user numbers should not be neglected to achieve green communications. We introduce the energy-efficient switch-off mode algorithm for pico cells to reduce power consumption in the self-organizing network (SON). Once the switch-off mode is initiated in some picked pico cells, the users connecting to these cells would face the problem of redistribution. In this paper, we introduce the energy saving (ES) strategy based on the prediction of load capability to select pico cells to enter switchoff mode. Furthermore, network flow based load balancing (LB) is proposed to provide solution of uneven load status caused by ES. System level simulations are conducted to exhibit the performance enhancement that the proposed algorithm can reduce energy consumption as well as improve the balanced degree of resource allocation significantly.
Qi Li 0057, Liyang Lu, Lin Zhang 0013
PIMRC1
2013 Joint Power Reduction and Time-Domain Scheduling for Interference Mitigation in Macro-Pico Heterogeneous Networks with Differential Evolution
abstract
Heterogeneous Network (HetNet) in 3GPP is a promising way to increase network coverage and capacity compared to macro cellular-only network. In order to further increase network capacity and balance cell load, Cell Range Expansion (CRE) and time-domain Inter-Cell Interference Coordination (ICIC) have been introduced into LTE-Advanced. The goal of our research is to mitigate the interference towards the User Equipments (UEs) served by the picocells and maintain the throughput of macrocells at the same time. We solve the problem by reducing the transmission power of macro Base Stations (BSs) in some subframes based on the proposed utility function, and accordingly scheduling picocell CRE UEs in these subframes. The existence of optimal solutions to the problem is discussed, and the Differential Evolution (DE) is applied to find the optimal transmission power which maximizes the utility function. System level simulation results show that the proposed algorithm can not only increase the total network's capacity but also improve the load balance between macrocell and picocell.
Chunyan Feng, Hailun Xia, Qi Li 0057
VTC Spring4