Yali Yuan

dblp:188/9655 · DBLP profile ↗
← Back
39ranked-venue papers
17as first author
35since 2021 · last 2026
0000-0002-9258-9929ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 12 first-author · 13 since 2021Security and privacy · 14 · 5 first-author · 14 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PAGPL: Privacy-Aware Graph Prompt Learning Scheme via Adaptive Perturbation-Estimated Topology Recovery
abstract
Graph prompt learning (GPL) serves as a crucial framework for mitigating the knowledge transfer by reconciling the substantial mismatch between pre-training models and downstream tasks. However, prevalent GPL paradigm fail to accommodate graph data affected by privacy-induced noise. Specifically, 1) GPL typically relies on the stability of original graph structures for the design of effective prompt templates; 2) the construction of prompts lacks explicit guidance to suppress noise introduced by privacy perturbations; 3) prompt optimization on single disturbed graphs can easily lead to overfitting to noise patterns. To address these issues, we propose a novel privacy-aware graph prompt learning (PAGPL) scheme, which alleviates spurious clues caused by privacy noise injection. Initially, an adaptive structure-wise Bayesian estimation is applied to reconstruct the privacy-perturbed graphs. Subsequently, to suppress the impact of residual perturbation, a noise-resilient prompt generation is employed to filter unreliable structural and signals. Ultimately, we incorporate a multi-view-based progressive privacy consistency to promote the robustness of prompts against the semantic misalignment while improving the task-specific consistency. The experimental results reveal that our scheme outperforms state-of-the-art (SOTA) GPL approaches with a 10%–60% improvement in accuracy under various real-world privacy-perturbed scenarios.
Ju Jia, Jiansen Song, Jingxuan Yu, Jiabao Guo, Xiaoshuang Jia, Di Wu 0050, Yali Yuan, Guang Cheng 0001
AAAI7
2026 MPAS: Breaking Sequential Constraints of Multi-Agent Communication Topologies via Individual-Epistemic Message Propagation
abstract
Large language model (LLM)-driven agents are designed to handle a wide range of tasks autonomously. As tasks become increasingly composite, the integration of multiple agents into a graph-structured system offers a promising solution. Recent advances mainly architect the communication order among agents into a specified directed acyclic graph, from which a one-by-one execution can be determined by topological sort. However, sequential architectures restrict the diversity of the information flow, hinder parallel computation, and exhibit vulnerabilities to potential backdoor threats. To overcome underlying shortcomings of sequential structures, we propose a node-wise multi-agent scheme, named message passing agent system (MPAS). Specifically, to parallelize the communication across agents, we extend the message propagation mechanism in graph representation learning to multi-agent scenarios and introduce our individual-epistemic message propagation. To further enhance expressiveness and robustness, we investigate three self-driven message aggregators. To achieve desired working flows, collaborative connections can be optimized without constraints. The experimental results reveal that compared to state-of-the-art sequential designs, MPAS could architect more advanced algorithms in 93.8% of the evaluations, reduce the average communication time from 84.6 seconds to 14.2 seconds per round on AQuA, and improve resilience against backdoor misinformation injection in 94.4% tests.
Jingxuan Yu, Ju Jia, Simeng Qin, Xiaojun Jia, Siqi Ma 0001, Yihao Huang 0001, Yali Yuan, Guang Cheng 0001
AAAI7
2026 Beyond flat identification: Exploiting site-page structure for hierarchical webpage fingerprinting
Yali Yuan, Xingjian Zeng, Guang Cheng 0001
Comput. Networks1
2026 Optimizing multi-objective strategies for enhanced Tor De-anonymization
abstract
Abstract Tor employs multi-layer encryption and three-hop circuits to provide low-latency anonymity. While indispensable for privacy, these same properties can also be misused to conceal illicit activity. This dual-use nature makes effective de‑anonymization essential under appropriate, policy-bounded oversight, so that harmful behavior can be uncovered without undermining legitimate use. Yet de‑anonymization is not free: taking nodes offline and deploying honeypots consumes significant resources, increases exposure, and risks degrading network availability. Prior work faces two limitations: (i) it decouples the choice of which node to target from which method to apply, overlooking their strong coupling; and (ii) it often evaluates effectiveness with narrow, single-effect proxies, neglecting collateral network impact and operational cost. To support better de‑anonymization, we model joint node–technique selection as a tri-objective problem balancing attack gain ( AP ), attack impact ( AI ), and attack cost( AC ). For each feasible node–method pair we compute these three metrics, extract the Pareto set, prune with $$\epsilon$$ ϵ -constraints, and select a preference-aware compromise with VIKOR. In a Docker-orchestrated testbed, this Pareto-first pipeline achieves about $$+50\%$$ + 50 % higher attack gain and roughly $$-29\%$$ - 29 % lower attack Impact and attack cost compared with random selection.
Yali Yuan, Ruolin Ma, Liangyi Gong, Guang Cheng 0001
Cybersecur.1
2026 Network intrusion detection with edge-directed graph Multi-Head Attention Networks
Xiang Li 0167, Haiyang Diao, Yali Yuan, Jing Zhang 0015
Eng. Appl. Artif. Intell.3
2026 AHE: Adaptive hybrid-sampling ensemble for large-scale highly imbalanced data classification
Xingjian Zeng, Yali Yuan, Hantao Mei, Guang Cheng 0001
Knowl. Based Syst.2
2026 Heterogeneous graph contrastive learning with spectral augmentation and dual aggregation
Jing Zhang 0015, Xiaoqian Jiang, Yingjie Xie, Yali Yuan, Shunmei Meng, Cangqi Zhou
Pattern Recognit.5
2026 Robust and Invisible Flow Watermarking With Invertible Neural Network for Traffic Tracking
abstract
This paper introduces an innovative blind flow watermarking framework on the basis of Invertible Neural Network (INN) called IFW, which aims to solve the problem of suboptimal encoder-decoder coupling in existing end-to-end watermarking architectures. The framework tightly couples the encoder and decoder to achieve highly consistent feature mapping using the same parameters, thus effectively avoiding redundant feature embedding. In addition, this paper adopts the INN to implement watermarking, which supports forward encoding and backward decoding, and the watermark extraction is completely dependent on the embedding algorithm without the need for the original network flow. This feature enables both the embedding and the blind extraction of watermarks simultaneously. Extensive experiments demonstrate that the proposed IFW method achieves a watermark extraction accuracy exceeding 96.6% and maintains a stable K-S test p-value above 0.85 in both simulated and real-world Tor traffic environments. These results indicate a clear advantage over mainstream baselines, highlighting the methods ability to jointly ensure robustness and invisibility, as well as its strong potential for real-world deployment.
Yali Yuan, Ruolin Ma, Jian Ge 0004, Guang Cheng 0001
IEEE Trans. Netw. Serv. Manag.1
2026 Early-MFC: Enhanced Flow Correlation Attacks on Tor via Multi-View Triplet Networks With Early Network Traffic
abstract
Flow correlation attacks is an efficient network attacks, aiming to expose those who use anonymous network services, such as Tor. Conducting such attacks during the early stages of network communication is particularly critical for scenarios demanding rapid decision-making, such as cybercrime detection or financial fraud prevention. Although recent studies have made progress in flow correlation attacks techniques, research specifically addressing flow correlation with early network traffic flow remains limited. Moreover, due to factors such as model complexity, training costs, and real-time requirements, existing technologies cannot be directly applied to flow correlation with early network traffic flow. In this paper, we propose flow correlation attack with early network traffic, named Early-MFC, based on multi-view triplet networks. The proposed approach extracts multi-view traffic features from the payload at the transport layer and the Inter-Packet Delay. It then integrates multi-view flow information, converting the extracted features into shared embeddings. By leveraging techniques such as metric learning and contrastive learning, the method optimizes the embeddings space by ensuring that similar flows are mapped closer together while dissimilar flows are positioned farther apart. Finally, Bayesian decision theory is applied to determine flow correlation, enabling high-accuracy flow correlation with early network traffic flow. Furthermore, we investigate flow correlation attacks under extra-early network traffic flow conditions. To address this challenge, we propose Early-MFC+, which utilizes payload data to construct embedded feature representations, ensuring robust performance even with minimal packet availability.
Yali Yuan, Qianqi Niu, Yachao Yuan
IEEE Trans. Netw. Serv. Manag.1
2025 CoDA: Cross-Domain Few-Shot Website Fingerprinting via Contrastive Prototype Alignment
abstract
Tor is widely used to facilitate anonymous web communication, but it remains vulnerable to Website Fingerprinting (WF) attacks. Although deep learning-based WF attacks have shown promising results, they typically rely on large-scale labeled data and assume consistent conditions between training and deployment. These assumptions limit their practical applicability in real-world scenarios, where data scarcity and domain shifts are common. To address these challenges, recent research has focused on Cross-Domain Few-Shot Website Fingerprinting (CDFSWF), a more realistic yet challenging setting. Existing efforts mainly leverage data augmentation or feature alignment techniques. While data augmentation can mitigate sample scarcity, it often fails to capture true distributional variability. In contrast, many feature alignment WF methods overlook the semantic structure of class relationships, reducing their effectiveness in the target domain. In this paper, we propose CoDA, a novel method designed to improve cross-domain robustness in CDFSWF. CoDA integrates supervised contrastive pre-training, hierarchical flow attention, and prototype-based classification to effectively model semantic traffic structures under domain shifts. Furthermore, a Dual Confidence Alignment (DCA) strategy is introduced during fine-tuning to adaptively align semantic structures. Extensive experiments across various cross-domain scenarios show that CoDA consistently outperforms state-of-the-art baselines in both closed-world and open-world settings.
Yuwei Xu 0001, Xinhe Fan, Yujie Hou, Yali Yuan, Qiao Xiang, Guang Cheng 0001
TrustCom5
2025 DeMarking: A defense for network flow watermarking in real-time
Yali Yuan, Jian Ge 0004, Guang Cheng 0001
Comput. Secur.1
2025 Attack smarter: Attention-driven fine-grained webpage fingerprinting attacks
Yali Yuan, Weiyi Zou, Guang Cheng 0001
Comput. Secur.1
2025 A network flow fingerprinting method with adaptive embedding strength
abstract
Abstract Network flow fingerprinting technology extends the number of embedded bits based on watermarking, thereby conveying additional information about the marked traffic, such as the traffic origin or the identity of the marking entity. However, existing fingerprinting/watermarking techniques follow the same embedding pattern under various levels of network noise, which hinders adaptation to high-noise environments and increases the risk of information loss. Therefore, this paper introduces the concept of embedding strength and proposes a network flow fingerprinting method with adaptive embedding strength. The embedding strength is adaptive for different network flows and can be freely adjusted. To achieve this, we design a two-stage training framework to generate fingerprint delays. In the first stage, we use an autoencoder architecture to obtain the optimal embedding for the fingerprint. In the second stage, we introduce a new component-the Adaptor-to produce a minimized embedding strength that eliminates redundant embeddings from the previous stage, thus balancing robustness and invisibility. Experimental results show that, after two stages of training, our scheme achieves an extraction rate of 98.33% and a bit error rate of 0.83%. Furthermore, in high-noise environments, our scheme can adjust the embedding strength to improve the extraction rate from 60.83 to over 90%.
Yali Yuan, Jian Ge 0004, Guang Cheng 0001
Cybersecur.1
2025 FDGAT-WTA: A dynamic detection model for web tracking and advertising based on improved graph attention networks
Yali Yuan, Runke Li, Guang Cheng 0001
J. Netw. Comput. Appl.1
2025 MW3F: Improved multi-tab website fingerprinting attacks with Transformer-based feature fusion
Yali Yuan, Weiyi Zou, Guang Cheng 0001
J. Netw. Comput. Appl.1
2025 Class Incremental Website Fingerprinting Attack Based on Dynamic Expansion Architecture
abstract
Encrypted traffic on anonymizing networks is still at risk of being exposed to the Website Fingerprinting (WF) attack. This attack can seriously threaten the online privacy of users of anonymity networks such as Tor. While deep-learning-based WF attacks achieve high accuracy in controlled experimental settings, they cannot continuously learn after deployment. In real-world environments, new websites are constantly emerging, requiring attackers to expand their monitoring scope continuously. This necessitates attack models capable of continuous learning and expanding classification capabilities. In this paper, we explore how attackers can leverage incremental class learning techniques to continuously learn new classes while retaining the ability to distinguish old ones. This approach mitigates the catastrophic forgetting problem in dynamic, open-world scenarios. We introduce a new WF attack, Class Incremental Fingerprinting (CIF), which employs a scalable architecture enabling Class Incremental Learning (CIL) with limited resources. We evaluate this attack in various scenarios, such as learning 100, 200, and 500 monitored website classes across 5 and 10 incremental tasks, achieving an average accuracy of 97.8% and above. Additionally, we assess the CIF attack’s effectiveness in open-world multi-classification scenarios and test it in few-shot settings using the proposed data augmentation method, Mixtam, achieving an average task accuracy of 87.6% and above with only 30 samples per class.
Yali Yuan, Yangyang Du, Guang Cheng 0001
IEEE Trans. Netw. Serv. Manag.1
2025 High Precision and Efficient Anonymous Traffic Classification in the Real-World
abstract
Various Traffic Classification (TC) technologies have been developed to de-anonymize anonymous tools, such as Tor, the most popular communication anonymous system. Although current TC methods boast high performance in closed-world scenarios, they frequently encounter challenges when dealing with the low base rate of anonymous traffic in the real open world, a phenomenon referred to as the base rate fallacy. In this paper, we introduce HPETC, an anonymous traffic classification system tailored for real-world scenarios, with a focus on achieving high precision, even in the presence of extremely low rates of anonymous traffic within expansive network environments. HPETC comprises an online classifier that efficiently filters anonymous traffic with minimal resource requirements, alongside an offline classifier responsible for extracting detailed information to support fine-grained classification. In response to the base rate fallacy, we introduce three Enhanced Techniques to enhance the performance of the classifiers within HPETC. Experimental findings illustrate that HPETC markedly diminishes resource consumption and greatly enhances the actual precision in comparison to state-of-the-art methods. Remarkably, in scenarios characterized by an extremely low rate of anonymous traffic (non-Tor/Tor$=$1000), our HPETC demonstrates an actual precision improvement that exceeds eightfold when benchmarked against commonly utilized models, specifically the Random Forest (RF) and Convolutional Neural Network (CNN) models.
Hantao Mei, Guang Cheng 0001, Yali Yuan
IEEE Trans. Netw.3
2024 ProfistMAC: A Protocol Finite State Machine Classifier via Graph Representation
Yali Yuan, Guang Cheng 0001
ACISP (2)1
2024 Improve Deep Forest with Learnable Layerwise Augmentation Policy Schedules
abstract
As a modern ensemble technique, Deep Forest (DF) employs a cascading structure to construct deep models, providing stronger representational power compared to traditional decision forests. However, its greedy multi-layer learning procedure is prone to overfitting, limiting model effectiveness and generalizability. This paper presents AugDF, an optimized Deep Forest featuring learnable, layerwise data augmentation policy schedules. Specifically, We introduce the Cut Mix for Tabular data (CMT) augmentation technique to mitigate overfitting and develop a population-based search algorithm to tailor augmentation intensity for each layer. Additionally, we propose to incorporate outputs from intermediate layers into a checkpoint ensemble for more stable performance. Experimental results show that AugDF sets new state-of-the-art (SOTA) benchmarks in various tabular classification tasks, outperforming shallow tree ensembles, deep forests, deep neural network, and AutoML competitors. The learned policies also transfer effectively to Deep Forest variants, underscoring its potential for enhancing non-differentiable deep learning modules in tabular signal processing.
Hongyu Zhu 0004, Sichu Liang, Fangqi Li 0001, Yali Yuan, Shi-Lin Wang, Guang Cheng 0001
ICASSP5
2024 TorHunter: A Lightweight Method for Efficient Identification of Obfuscated Tor Traffic Through Unsupervised Pre-training
Yuwei Xu 0001, Zhengxin Xu, Jie Cao 0009, Yali Yuan, Guang Cheng 0001
ICICS (2)5
2024 M-ETC: Improving Multi-Task Encrypted Traffic Classification by Reducing Inter-Task Interference
abstract
With the rapid evolution of deep learning (DL), its integration in encrypted traffic classification (ETC) can automatically extract key features from raw traffic data, enhancing classification performance. So far, researchers have proposed many DL-based models for ETC. However, the complexity and dynamism of network applications lead to the diversification of ETC tasks. Current models, mostly tailored for single tasks, overlook real-world multi-tasking needs of network devices. Deploying task-specific complex models concurrently on resource-limited devices is impractical. In response to the increasing number of tasks, researchers have introduced multi-task learning frameworks for ETC, demonstrating its potential as a promising technical approach. However, current research overlooks the interference between tasks, resulting in flawed models when it comes to sharing parameters, setting learning rates, and determining loss values. Aiming at these deficiencies, we propose $\mathcal{M}$-ETC, a multi-task ETC method reducing inter-task interference. The innovation of $\mathcal{M}$-ETC lies in two aspects. Firstly, we design a hierarchical multi-task learning model (HMLM) to provide effective features for each task and prevent the impact of invalid features. Secondly, we propose a learning rate balancing strategy (LRB) for modules and a dynamic weight average strategy (DWA) for tasks’ loss values. During model training, LRB prevents overfitting and underfitting of tasks, while DWA prevents bias towards tasks with large loss values. To validate $\mathcal{M}$-ETC, we carry out comparative experiments using four encrypted traffic datasets. The experimental results show that the classification performance of $\mathcal{M}$-ETC on multiple tasks exceeds those of five state-of-the-art methods.
Yuwei Xu 0001, Xiaotian Fang, Zhengxin Xu, Kehui Song, Yali Yuan, Guang Cheng 0001
TrustCom5
2024 TriViewNet: Achieve Accurate Tor Hidden Service Classification by Multi-View Feature Extraction and Fusion
abstract
Tor has provided hidden services (HS) and protected the anonymity of the Web server with hidden service directory servers. Some criminals use hidden services to engage in illegal activities, such as anonymous transactions, pirated distribution, hacking, etc. In order to protect the security of cyberspace, hidden service traffic needs to be deanonymized. Artificial intelligence-based methods have become the most promising, but there are still two shortcomings in current research work. First, some of them mainly uses the size and direction sequence of the data packet as the input to complete the recognition, without mining the features of network traffic from many views. Second, they extract information from different view, but just concatenate them together instead of fuse them densely. Therefore, in this paper we propose a Tor hidden service traffic identification method with multi views named TriViewNet. TriViewNet extracts information from three different views, local flow, TLS layer, and TCP layer for identification ad fuses them with Tri-attention module. By comparing with state-of-the-art models, the results show that our TriViewNet outperforms in the recognition of Tor HS traffic.
Yuwei Xu 0001, Yujie Hou, Xinxu Huang, Yali Yuan, Guang Cheng 0001
TrustCom5
2024 Joint Optimization of QoE and Fairness for Adaptive Video Streaming in Heterogeneous Mobile Environments
abstract
The rapid growth of mobile video traffic and user demand poses a more stringent requirement for efficient bandwidth allocation in mobile networks where multiple users may share a bottleneck link. This provides content providers an opportunity to jointly optimize multiple users’ experiences but users often suffer short connection durations and frequent handoffs because of their high mobility. In this paper, we propose an end-to-end scheme, VSiM, for supporting mobile video streaming applications in heterogeneous wireless networks. The key idea is allocating bottleneck bandwidth among multiple users based on their mobility profiles and Quality of Experience (QoE)-related knowledge to achieve max-min QoE fairness. Besides, the QoE of buffer-sensitive clients is further improved by the novel server push strategy based on HTTP/3 protocol without affecting the existing bandwidth allocation approach or sacrificing other clients’ view quality. VSiM is lightweight and easy to deploy in the real world without touching the underlying network infrastructure. We evaluated VSiM experimentally in both simulations and a lab testbed on top of the HTTP/3 protocol. We find that the clients’ QoE fairness of VSiM achieves more than 40% improvement compared with state-of-the-art solutions, i.e., the viewing quality of clients in VSiM can be improved from 720p to 1080p in resolution. Meanwhile, VSiM provides about 20% improvement of average QoE.
Yali Yuan, Weijun Wang 0001, Sripriya Srikant Adhatarao, Bangbang Ren, Kai Zheng 0003, Xiaoming Fu 0001
IEEE/ACM Trans. Netw.1
2023 Zoomer: A Website Fingerprinting Attack Against Tor Hidden Services
Yuwei Xu 0001, Kehui Song, Yali Yuan
ICICS5
2023 PrSLoc: Sybil attack detection for localization with private observers using differential privacy
Yachao Yuan, Yali Yuan
Comput. Secur.3
2023 ReplaceDGA: BiLSTM-Based Adversarial DGA With High Anti-Detection Ability
abstract
Botnets extensively leverage Domain Generation Algorithms (DGAs) to establish reliable communication channels between bots and Command and Control (C&C) servers. Numerous character-level DGA classifiers have been extensively studied to detect and classify domain names generated by DGAs. Meanwhile, a series of adversarial domain generation algorithms have been proposed to evade DGA classifiers. Although the existing domain name generation algorithms have progressed against DGA classifier, their anti-detection abilities are still weak. This paper proposes a Bidirectional Long Short-Term Memory (BiLSTM) network-based adversarial DGA with high anti-detection ability, referred to as ReplaceDGA. ReplaceDGA requires no knowledge of the targeted DGA classifiers. It first builds a prediction model for benign domain names using the BiLSTM network to model the semantic relationship hidden within benign domain names and then replaces two characters of each input benign domain name based on the prediction model to maximize the similarity between the benign and generated domain names. Our experimental results validate that ReplaceDGA successfully evades various character-level DGA classifiers even after they are retrained by domain names generated by ReplaceDGA and outperforms the state-of-the-art adversarial DGAs in anti-detection ability, repetition rate, and collision rate. Our study of ReplaceDGA promotes the urgent need for developing more comprehensive and robust DGA classifiers that consider other factors besides character-level information of domain names.
Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004, Yali Yuan
IEEE Trans. Inf. Forensics Secur.7
2022 VSiM: Improving QoE Fairness for Video Streaming in Mobile Environments
abstract
The rapid growth of mobile video traffic and user demand poses a more stringent requirement for efficient bandwidth allocation in mobile networks where multiple users may share a bottleneck link. This provides content providers an opportunity to optimize multiple users’ experiences jointly, but users often suffer short connection durations and frequent handoffs because of their high mobility. This paper proposes an end-to-end scheme, VSiM, to support mobile video streaming applications in heterogeneous wireless networks. The key idea is allocating bottleneck bandwidth among multiple users based on their mobility profiles and Quality of Experience (QoE)-related knowledge to achieve max-min QoE fairness. Besides, the QoE of buffer-sensitive clients is further improved by the novel server push strategy based on HTTP/3 protocol without affecting the existing bandwidth allocation approach or sacrificing other clients’ view quality. We evaluated VSiM experimentally in both simulations and a lab testbed on top of the HTTP/3 protocol. We find that the clients’ QoE fairness of VSiM achieves more than 40% improvement compared with state-of-the-art solutions, i.e., the viewing quality of clients in VSiM can be improved from 720p to 1080p in resolution. Meanwhile, VSiM provides about 20% improvement on average of the averaged QoE.
Yali Yuan, Weijun Wang 0001, Sripriya Srikant Adhatarao, Bangbang Ren, Kai Zheng 0003, Xiaoming Fu 0001
INFOCOM1
2022 LbSP: Load-Balanced Secure and Private Autonomous Electric Vehicle Charging Framework With Online Price Optimization
abstract
Nowadays, autonomous electric vehicles (AEVs) are increasingly popular due to low resource consumption, low pollutant emission, and high efficiency. In practice, Vehicle-to-Grid (V2G) networks supply energy power to EVs to ensure the usage of EVs. However, there are still certain security and privacy concerns in V2G connections, such as identity impersonation and message manipulation. Additionally, the widespread usage of EVs brings significant pressure on the power grid, leading to undesirable effects like voltage deviations if EVs’ charging is not well coordinated. In this article, to tackle these issues, we design a novel load-balanced secure and private EV charging framework named load-balanced secure and private framework (LbSP) for secure, private, and efficient EV charging with a minimal negative effect on the existing power grid. It assures reliable and efficient charging services by a lightweighted encryption technique. Also, it balances the energy consumption of power grids via an online pricing strategy that minimizes load variance by optimizing energy prices in real time. Moreover, it preserves users’ privacy while not affecting online pricing using an advanced differential privacy technique. Furthermore, LbSP deploys on an edge-cloud structure for fast response and more precise pricing, where clouds balance overall load consumption by online price optimization while edges gather data for clouds and respond to charging requests from EVs. The evaluation results show that the proposed framework ensures secure and private EV charging, balances energy load consumption, and preserves users’ privacy.
Yachao Yuan, Yali Yuan, Parisa Memarmoshrefi, Thar Baker, Dieter Hogrefe
IEEE Internet Things J.2
2022 Eurus: Towards an Efficient Searchable Symmetric Encryption With Size Pattern Protection
abstract
To achieve efficiently search and update on outsourced encrypted data, dynamic searchable symmetric encryption (DSSE) was proposed by just leaking some well-defined leakages. Though small, many recent works show that an attacker can exploit these leakages to undermine the security of existing DSSE schemes. In particular, an attacker can exploit even seemingly harmless size pattern to perform severe attacks. Many exiting schemes resort to oblivious RAM (ORAM) to hide search/access pattern; however, even such powerful cryptographic primitive cannot protect size pattern leakage. In this article, we first show that size pattern can lead to more information leakages, which is not well studied or protected by existing schemes. We then extend the existing privacy notion for DSSE to capture the size pattern leakage, achieving a strong forward and backward privacy definition. Following the definition, we propose a new DSSE scheme Eurus. Eurus can eliminate search/access pattern by relying on a multi-server ORAM scheme, meanwhile reducing size pattern with reasonable efficiency. We show that Eurus can reduce leakage significantly with better efficiency, compared with state-of-the-art leakage reduction schemes.
Zheli Liu, Yanyu Huang, Xiangfu Song, Bo Li 0062, Jin Li 0002, Yali Yuan, Changyu Dong
IEEE Trans. Dependable Secur. Comput.6
2022 EncodeORE: Reducing Leakage and Preserving Practicality in Order-Revealing Encryption
abstract
Order-preserving encryption (OPE) is a cryptographic primitive that preserves the order of plaintexts. In the past few years, many OPE schemes were proposed to solve the problem of executing range queries in encrypted databases. However, OPE leaks some certain information (for example, the order of ciphertext), so it is vulnerable to many attacks. Subsequently, order-revealing encryption (ORE) was proposed by Bonehet al.(Eurocrypt 2015) as a generalization of order-preserving encryption. It breaks through the limitation of the numeric order of OPE plaintext. It implements ciphertext comparison for any specific form of plaintext through a publicly computable comparison function. In this article, we aim to design a new ORE scheme which reduces the leakages and preserves the practicality in terms of ciphertext length and encryption time. We first propose the hybrid model namedHybridORE. Then, we propose an improved scheme namedEncodeOREwhich achieves acceptable security and appropriate ciphertext length. They both explore the encode strategy of encoding plaintext into different parts and apply suitable ORE algorithms to each part according to its security characteristics to reduce leakages. Compared with the typical CLWW scheme (FSE 2016) and Lewi-Wu (CCS 2016) in large domain, they have fewer leakages. The experiment shows that the proposedEncodeOREis very practical.
Zheli Liu, Siyi Lv, Jin Li 0002, Yanyu Huang, Liang Guo 0013, Yali Yuan, Changyu Dong
IEEE Trans. Dependable Secur. Comput.6
2022 Adaptive Fuzzy Game-Based Energy-Efficient Localization in 3D Underwater Sensor Networks
abstract
Numerous applications in 3D underwater sensor networks (UWSNs), such as pollution detection, disaster prevention, animal monitoring, navigation assistance, and submarines tracking, heavily rely on accurate localization techniques. However, due to the limited batteries of sensor nodes and the difficulty for energy harvesting in UWSNs, it is challenging to localize sensor nodes successfully within a short sensor node lifetime in an unspecified underwater environment. Therefore, we propose the Adaptive Energy-Efficient Localization Algorithm (Adaptive EELA) to enable energy-efficient node localization while adapting to the dynamic environment changes. Adaptive EELA takes a fuzzy game-theoretic approach, whereby the Stackelberg game is used to model the interactions among sensor and anchor nodes in UWSNs and employs the adaptive neuro-fuzzy method to set the appropriate utility functions. We prove that a socially optimal Stackelberg–Nash equilibrium is achieved in Adaptive EELA. Through extensive numerical simulations under various environmental scenarios, the evaluation results show that our proposed algorithm accomplishes a significant energy reduction, e.g., 66% lower compared to baselines, while achieving a desired performance level in terms of localization coverage, error, and delay.
Yali Yuan, Chencheng Liang, Xu Chen 0004, Thar Baker, Xiaoming Fu 0001
ACM Trans. Internet Techn.1
2022 Optimal Deployment of SRv6 to Enable Network Interconnection Service
abstract
Many organizations nowadays have multiple sites at different geographic locations. Typically, transmitting massive data among these sites relies on the interconnection service offered by ISPs. Segment Routing over IPv6 (SRv6) is a new simple and flexible source routing solution which could be leveraged to enhance interconnection services. Compared to traditional technologies, e.g., physical leased lines and MPLS-VPN, SRv6 can easily enable quick-launched interconnection services and significantly benefit from traffic engineering with SRv6-TE. To parse the SRv6 packet headers, however, hardware support and upgrade are needed for the conventional routers of ISP. In this paper, we study the problem of SRv6 incremental deployment to provide a more balanced interconnection service from a traffic engineering view. We formally formulate the problem as an SRID problem with integer programming. After transforming the SRID problem into a graph model, we propose two greedy methods considering short-term and long-term impacts with reinforcement learning, namely GSI and GLI. The experiment results using a public dataset demonstrate that both GSI and GLI can significantly reduce the maximum link utilization, where GLI achieves a saving of 59.1% against the default method.
Bangbang Ren, Deke Guo, Yali Yuan, Guoming Tang, Weijun Wang 0001, Xiaoming Fu 0001
IEEE/ACM Trans. Netw.3
2021 Cetus: an efficient symmetric searchable encryption against file-injection attack with SGX
Yanyu Huang, Siyi Lv, Zheli Liu, Xiangfu Song, Jin Li 0002, Yali Yuan, Changyu Dong
Sci. China Inf. Sci.6
2021 FedRD: Privacy-preserving adaptive Federated learning framework for intelligent hazardous Road Damage detection and warning
Yachao Yuan, Yali Yuan, Thar Baker, Lutz M. Kolbe, Dieter Hogrefe
Future Gener. Comput. Syst.2
2021 EcRD: Edge-Cloud Computing Framework for Smart Road Damage Detection and Warning
abstract
Road damages have caused numerous fatalities, thus the study of road damage detection, especially hazardous road damage detection and warning is critical for traffic safety. Existing road damage detection systems mainly process data at cloud, which suffers from a high latency caused by long-distance. Meanwhile, supervised machine learning algorithms are usually used in these systems requiring large precisely labeled data sets to achieve a good performance. In this article, we propose EcRD: an edge-cloud-based road damage detection and warning framework, that leverages the fast-responding advantage of edge and the large storage and computation resources advantages of cloud. There are three main contributions in this article: we first propose a simple yet efficient road segmentation algorithm to enable fast and accurate road area detection. Then, a light-weighted road damage detector is developed based on gray level co-occurrence matrix features at edge for rapid hazardous road damage detection and warning. Furthermore, a multitypes road damage detection model is introduced for long-term road management at cloud, embedded with a novel image generator based on cycle-consistent adversarial networks which automatically generates images with labels to further improve road damage detection accuracy. By comparing with the state-of-the-art, we demonstrate that the proposed EcRD can accurately detect both hazardous road damages at edge and multitypes road damages at cloud. Besides, it is around 579 times faster than cloud-based approaches without affecting users' experience and requiring very low storage and labeling cost.
Yachao Yuan, Md. Saiful Islam 0011, Yali Yuan, Shengjin Wang, Thar Baker, Lutz M. Kolbe
IEEE Internet Things J.3
2020 ADA: Adaptive Deep Log Anomaly Detector
abstract
Large private and government networks are often subjected to attacks like data extrusion and service disruption. Existing anomaly detection systems use offline supervised learning and employ experts for labeling. Hence they cannot detect anomalies in real-time. Even though unsupervised algorithms are increasingly used nowadays, they cannot readily adapt to newer threats. Moreover, many such systems also suffer from high cost of storage and require extensive computational resources. In this paper, we propose ADA: Adaptive Deep Log Anomaly Detector, an unsupervised online deep neural network framework that leverages LSTM networks and regularly adapts to newer log patterns to ensure accurate anomaly detection. In ADA, an adaptive model selection strategy is designed to choose pareto-optimal configurations and thereby utilize resources efficiently. Further, a dynamic threshold algorithm is proposed to dictate the optimal threshold based on recently detected events to improve the detection accuracy. We also use the predictions to guide storage of abnormal data and effectively reduce the overall storage cost. We compare ADA with state-of-the-art approaches through leveraging the Los Alamos National Laboratory cyber security dataset and show that ADA accurately detects anomalies with high F1-score ~95% and it is 97 times faster than existing approaches and incurs very low storage cost.
Yali Yuan, Sripriya Srikant Adhatarao, Mingkai Lin, Yachao Yuan, Zheli Liu, Xiaoming Fu 0001
INFOCOM1
2017 Two Layers Multi-class Detection method for network Intrusion Detection System
abstract
Intrusion Detection Systems (IDSs) are powerful systems which monitor and analyze events in order to detect signs of security problems and take action to stop intrusions. In this paper, the Two Layers Multi-class Detection (TLMD) method used together with the C5.0 method and the Naive Bayes algorithm is proposed for adaptive network intrusion detection, which improves the detection rate as well as the false alarm rate. The proposed TLMD algorithm also addresses some difficulties in data mining situations such as handling imbalance datasets, dealing with continuous attributes, and reducing noise in training dataset. We compared the performance of the proposed TLMD method with that of existing algorithms, using the detection rate, accuracy as well as false alarm rate on the KDDcup99 benchmark intrusion detection dataset. The experimental results prove that the proposed TLMD method has a reduced false alarm rate and a good detection rate based on the imbalanced dataset.
Yali Yuan, Liuwei Huo, Dieter Hogrefe
ISCC1
2016 Tri-MCL: Synergistic Localization for Mobile Ad-Hoc and Wireless Sensor Networks
abstract
Localization is a highly important topic in wireless sensor networks as well as in many Internet of Things applications. Many current localization algorithms are based on the Sequential Monte Carlo Localization method (MCL), the accuracy of which is bounded by the radio range. High computational complexity in the sampling step is another issue of these approaches. We present Tri-MCL which significantly improves on the accuracy of the Monte Carlo Localization algorithm. To do this, we leverage three different distance measurement algorithms based on range-free approaches. Using these, we estimate the distances between unknown nodes and anchor nodes to perform more fine-grained filtering of the particles as well as for weighting the particles in the final estimation step of the algorithm. Simulation results illustrate that the proposed algorithm achieves better accuracy than the MCL and SA-MCL algorithms. Furthermore, it also exhibits high efficiency in the sampling step.
Arne Bochem, Yali Yuan, Dieter Hogrefe
LCN2
2016 A Novel Semi-Supervised Adaboost Technique for Network Anomaly Detection
abstract
With the developing of Internet, network intrusion has become more and more common. Quickly identifying and preventing network attacks is getting increasingly more important and difficult. Machine learning techniques have already proven to be robust methods in detecting malicious activities and network threats. Ensemble-based and semi-supervised learning methods are some of the areas that receive most attention in machine learning today. However relatively little attention has been given in combining these methods. To overcome such limitations, this paper proposes a novel network anomaly detection method by using a combination of a tri-training approach with Adaboost algorithms. The bootstrap samples of tri-training are replaced by three different Adaboost algorithms to create the diversity. We run 30 iteration for every simulation to obtain the average results. Simulations indicate that our proposed semi-supervised Adaboost algorithm is reproducible and consistent over a different number of runs. It outperforms other state-of-the-art learning algorithms, even with a small part of labeled data in the training phase. Specifically, it has a very short execution time and a good balance between the detection rate as well as the false-alarm rate.
Yali Yuan, Georgios Kaklamanos, Dieter Hogrefe
MSWiM1