VLDB 2026 Research / reviewers in the wild / expert
Youjun Huang
dblp:182/9192
· DBLP profile ↗
5ranked-venue papers
1as first author
4since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A real-time FPGA-based radiation noise suppression and detection method with comparative analysis against deep learning techniques
Shoulong Xu, Zhixiong Hou, Cuiyue Wei, Youjun Huang, Shuliang Zou, Qingyang Wei |
Expert Syst. Appl. | 4 |
| 2025 | Detection and Mitigation of Unknown Threats in IPv6 Networks via Layered Data AdaptationabstractWith the rapid proliferation of IPv6 deployment, traditional threat detection approaches are increasingly challenged by the scale, diversity, and concealment of emerging attack behaviors. This paper tackles three key limitations in IPv6 threat detection: poor adaptability across diverse network environments, insufficient result validation mechanisms, and the absence of globally applicable detection toolsets. To address these challenges, we propose a data-driven, layer-adaptive detection framework that forms a closed-loop pipeline of detection, validation, and mitigation. Our framework constructs a hierarchical dataset covering multiple detection scenarios, including open sensitive ports, entropy-based traffic anomalies, and TensorFlow-enhanced machine learning inputs. We introduce a novel validation technique, the Daily Active Mutual Access Index Matrix, which captures inter-prefix interaction patterns to identify coordinated malicious behavior. Additionally, we deploy a global-scale threat intelligence resolution and measurement system to validate detection outcomes and uncover cross-border threats missed by conventional models. Extensive analysis of abuse reports and complaint email interactions reveals that 65.53% of observed abuse involves sensitive service ports, and 38.64% of detected addresses exhibit verifiable abuse behavior. Notably, detection methods based on information entropy and AI models demonstrate higher abuse report delivery rates compared to commercial threat intelligence sources. Experimental results confirm that our multi-modal, adaptive approach significantly enhances the accuracy of unknown threat detection and the effectiveness of coordinated response, offering scalable and robust technical support for IPv6 security operations. Youjun Huang, Xiang Li 0108, Jia Zhang 0004, Hai-Xin Duan |
TrustCom | 1 |
| 2022 | Research on Quantitative Optimization Method Based on Incremental Optimization
Youjun Huang, Lichao Gao |
ICIC (3) | 2 |
| 2021 | Fast IPv6 Network Periphery Discovery and Security ImplicationsabstractNumerous measurement researches have been performed to discover the IPv4 network security issues by leveraging the fast Internet-wide scanning techniques. However, IPv6 brings the 128-bit address space and renders brute-force network scanning impractical. Although significant efforts have been dedicated to enumerating active IPv6 hosts, limited by technique efficiency and probing accuracy, large-scale empirical measurement studies under the increasing IPv6 networks are infeasible now. To fill this research gap, by leveraging the extensively adopted IPv6 address allocation strategy, we propose a novel IPv6 network periphery discovery approach. Specifically, XMap, a fast network scanner, is developed to find the periphery, such as a home router. We evaluate it on twelve prominent Internet service providers and harvest 52M active peripheries. Grounded on these found devices, we explore IPv6 network risks of the unintended exposed security services and the flawed traffic routing strategies. First, we demonstrate the unintended exposed security services in IPv6 networks, such as DNS, and HTTP, have become emerging security risks by analyzing 4.7M peripheries. Second, by inspecting the periphery's packet routing strategies, we present the flawed implementations of IPv6 routing protocol affecting 5.8M router devices. Attackers can exploit this common vulnerability to conduct effective routing loop attacks, inducing DoS to the ISP's and home routers with an amplification factor of \gt 200. We responsibly disclose those issues to all involved vendors and ASes and discuss mitigation solutions. Our research results indicate that the security community should revisit IPv6 network strategies immediately. Xiang Li 0108, Baojun Liu 0002, Hai-Xin Duan, Qi Li 0002, Youjun Huang |
DSN | 6 |
| 2020 | DNS Cache Poisoning Attack Reloaded: Revolutions with Side ChannelsabstractIn this paper, we report a series of flaws in the software stack that leads to a strong revival of DNS cache poisoning --- a classic attack which is mitigated in practice with simple and effective randomization-based defenses such as randomized source port. To successfully poison a DNS cache on a typical server, an off-path adversary would need to send an impractical number of $2^32 $ spoofed responses simultaneously guessing the correct source port (16-bit) and transaction ID (16-bit). Surprisingly, we discover weaknesses that allow an adversary to "divide and conquer'' the space by guessing the source port first and then the transaction ID (leading to only $2^16 +2^16 $ spoofed responses). Even worse, we demonstrate a number of ways an adversary can extend the attack window which drastically improves the odds of success. The attack affects all layers of caches in the DNS infrastructure, such as DNS forwarder and resolver caches, and a wide range of DNS software stacks, including the most popular BIND, Unbound, and dnsmasq, running on top of Linux and potentially other operating systems. The major condition for a victim being vulnerable is that an OS and its network is configured to allow ICMP error replies. From our measurement, we find over 34% of the open resolver population on the Internet are vulnerable (and in particular 85% of the popular DNS services including Google's 8.8.8.8). Furthermore, we comprehensively validate the proposed attack with positive results against a variety of server configurations and network conditions that can affect the success of the attack, in both controlled experiments and a production DNS resolver (with authorization). Keyu Man, Zhiyun Qian, Zhongjie Wang 0002, Youjun Huang, Hai-Xin Duan |
CCS | 5 |