Xiaolong Lan

dblp:195/8082 · DBLP profile ↗
← Back
46ranked-venue papers
9as first author
37since 2021 · last 2026
0000-0003-3483-1710ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 5 first-author · 12 since 2021Artificial intelligence and machine learning · 10 · 10 since 2021Security and privacy · 9 · 1 first-author · 8 since 2021Databases, data management, data science and information retrieval · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 3SC-Net: A Three-Stage Progressive Framework with Clinical-Guided Cross-Modal Alignment for Hemorrhagic Transformation Prediction
Xiaolong Lan, Shaoguo Cui
ICIC (29)1
2026 CIL-FGGM: A class-incremental learning framework based on fine-grained Gaussian mixture modeling for open-set fault recognition in rotating machinery
Hekun Yang, Wengang Ma, Junjiang He, Xiaolong Lan, Tao Li 0016
Adv. Eng. Informatics5
2026 Open-set Internet of Things intrusion detection via an adaptive few-shot incremental learning framework enhanced with feature augmentation
Wengang Ma, Hekun Yang, Junjiang He, Xiaolong Lan, Jiangchuan Chen, Tao Li 0016
Eng. Appl. Artif. Intell.5
2026 Generating Black-Box Adversarial Examples for Industrial Control Systems via Immune Co-Evolution
Chenyi Huang, Junjiang He, Wenshan Li 0001, Tao Li 0016, Wengang Ma, Wenbo Fang, Xiaolong Lan
IEEE Internet Things J.7
2025 Weak Population-Empowered Large-Scale Multiobjective Immune Algorithm
abstract
The multiobjective immune optimization algorithms (MOIAs) utilize the principle of clonal selection, iteratively evolving by replicating a small number of superior solutions to optimize decision vectors. However, this method often leads to a lack of diversity and is particularly ineffective when facing large‐scale optimization problems. Moreover, an overemphasis on elite solutions may result in a large number of redundant offspring, reducing evolutionary efficiency. By delving into the causes of these issues, we find that a key factor is that existing algorithms overlook the role of weak solutions during the evolutionary process. With this in mind, we propose a weak population–empowered large‐scale multiobjective immune algorithm (WP–MOIA). The core of this algorithm is to construct, in addition to the traditional elite population, a cooperative evolutionary population based on a portion of the remaining solutions, referred to as the weak population. During the evolution, both populations work together: the elite population maximizes its advantageous status for local searches, focusing on exploitation, while the weak population seeks greater variation to escape its disadvantaged position, engaging in broader exploration. At the same time, the sizes of both populations are dynamically adjusted to collaboratively maintain the balance of evolution. Through comparisons with nine state‐of‐the‐art multiobjective evolutionary algorithms (MOEAs) and four powerful MOIAs on 30 benchmark problems, the proposed algorithm demonstrates superior performance in both small‐scale and large‐scale multiobjective optimization problems (MOPs), and exhibits better convergence efficiency. Especially in large‐scale MOPs, the new algorithm’s performance nearly surpasses all 13 advanced algorithms being compared.
Wenshan Li 0001, Junjiang He, Tao Li 0016, Wenbo Fang, Xiaolong Lan
Int. J. Intell. Syst.6
2025 NSA-AE: An inadequately represented immune spaces NSA augmented via autoencoders
Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016
Neurocomputing5
2025 Defending Against APT Attacks in Cloud Computing Environments Using Grouped Multiagent Deep Reinforcement Learning
abstract
Advanced persistent threats (APTs) pose a significant challenge to cloud computing security in the evolving landscape of cyber threats. Traditional defense models rely heavily on the attacker’s historical attack information, which greatly limits the effectiveness of actually dealing with APT attacks. To address this issues, we investigate an attack-defense game model in clouding computing environments, where multiple attackers and multiple defenders are supposed to compete for resource allocation on the cloud servers. In order to develop more effective defense strategies, we formulate the optimization problem to maximize the average rewards of defenders under constraints of the maximum available resource and acceptable cost. To solve this, we propose to use the multiagent deep reinforcement learning (RL) method to cope with the high uncertainty and dynamics of attack behavior. Then it is proposed to divide all defenders into cooperative groups and allow defenders within each group can jointly optimize the defense strategy through sharing information and experience. On this basis, we propose a novel grouped multiagent deep RL defense (GMADRLD) algorithm, which can effectively mitigate the issue of state space explosion while achieving good defense effect. Simulation results not only demonstrate the effectiveness of the proposed GMADRLD algorithm in dealing with the attacker’s ever-changing strategies, but also show that it is able to strike a balance between defense performance and computational complexity.
Xiaolong Lan, Wengang Ma, Wenbo Fang, Junjiang He
IEEE Internet Things J.2
2025 A Dual Active Domain Adaptation Approach With Loss Prediction for IIoT Intrusion Detection Under Imperfect Samples
abstract
The introduction of wireless terminals has disrupted the previously enclosed landscape of Internet of Things (IIoT), resulting in an expanded cyber-attack surface. Therefore, it is crucial to investigate intrusion detection in the IIoT. Current models rely on big data for training, but imperfect labeled data hampers robust intrusion detection. However, traditional models cannot achieve robust IIoT intrusion detection in the face of imperfect data constraints. Addressing this, we propose IIoT intrusion detection approach under imperfect samples using a hierarchical-split with knowledge distillation neural network (HS-KDNet) and dual active domain adaptation fusion loss prediction (DADA-LP). First, we construct a lightweight feature extraction model (HS-KDNet). HS-KDNet leverages soft labels from knowledge distillation to characterize the similarity between different categories. Next, we develop a single active domain adaptation algorithm through active learning evaluation, which can be used to select a sample of target domains with an active learning value evaluation. Finally, we enhance it into a DADA-LP algorithm, incorporating a loss prediction strategy in the source domain. Moreover, this model ensures outstanding IIoT intrusion detection under imperfect samples, effectively addressing the negative transfer issue. Four datasets from the IIoT are employed to validate the performance of our model. The results unequivocally demonstrate the excellent detection performance when applied to IIoT intrusion detection scenarios under imperfect samples.
Wengang Ma, Xiaolong Lan
IEEE Internet Things J.2
2025 Age-of-Task-Aware AAV-Based Mobile Edge Computing Techniques in Emergency Rescue Applications
abstract
In the case of extreme natural disasters like typhoons, earthquakes, and forest fires, the terrestrial communication infrastructure often suffers from severe damage, which seriously undermines the effectiveness of emergency response efforts, leading to critical challenges, such as the timely assessment of disasters, the quick emergency response strategy development, and the rapid implementation of reconnaissance and search-and-rescue operations. To address these challenge issues, autonomous aerial vehicles (AAVs)-based mobile edge computing (MEC) techniques had attracted research attention to effectively support emergency communication, disaster assessment, and rescue strategy decisions. In order to characterize the time-critical requirements of many emergency rescue applications, the concept of “Age of Task” (AoT) was introduced in this article as a metric for assessing the timeliness of task, and the minimization of the weighted AoT across all the terrestrial user equipments (UEs) was formulated. By leveraging the Lyapunov optimization analysis framework, the problem of minimizing the time-averaged weighted AoT was transformed into a series of real-time subproblems that involve task offloading scheduling decision, computational resource allocation, UE transmit power control, and AAV flight trajectory planning, all of which enable an AoT-aware AAV-based MEC network for emergency rescue applications. To highlight the effectiveness, four benchmark schemes were included for comparison to show the advantages of the AoT-aware adaptive AAV-based MEC algorithm (AAAUMA) in terms of the realized task freshness performance, lower energy consumption by the AAV, and smaller data buffer backlog sizes at all ground source nodes.
Xiangyang Peng, Xiaolong Lan, Qingchun Chen
IEEE Internet Things J.2
2025 An Immune Memory-Empowered SCADA-Based Industrial Virus Dynamic Repropagation Model
abstract
SCADA (Supervisory Control and Data Acquisition) systems, as the core of industrial control systems and widely deployed in the nation’s critical industrial infrastructure, are attractive targets for malicious hackers due to their strategic importance. According to Check Point Research, 96% of daily cyberattacks targeting industrial control systems worldwide are known to be repeat attacks. Although current research on virus propagation assists operators in mitigating the damage caused by industrial viruses to SCADA systems, these modeling methods often fail to distinguish between initial and secondary virus invasions, making them unsuitable for modeling the repeated infection spread of industrial viruses. In order to solve this problem, we propose an immune memory-empowered SCADA-based industrial virus dynamic re-propagation model MLBRM (Memory- Latent- Broken- Robust- Memory). First, by introducing an M node, the model is used to realize the function of memorizing viral strains and to quickly immunize against and eliminate them. Besides, we perform dynamic analysis of the model and conduct the second invasion analysis to demonstrate the effect of the M nodes on suppressing the spread of the virus. Additionally, we conduct a model comparison experiment and perform simulations on the US power grid real dataset to demonstrate the effectiveness of the proposed model. Finally, we draw a conclusion and provide some advice for SCADA network operators to better protect the SCADA systems.
Jiahang Tang, Junjiang He, Pin Yang, Xiaolong Lan, Jiangchuan Chen, Tao Li 0016
IEEE Internet Things J.5
2025 Malicious encrypted traffic detection method based on multi-granularity representation under data imbalance conditions
Tao Li 0016, Wenshan Li 0001, Linfeng Du, Xiaolong Lan, Junjiang He
Knowl. Based Syst.5
2025 Adaptive secure wireless information and power transfer in delay-constrained multiuser multi-input single-output networks
Xiaolong Lan, Junjiang He, Qingchun Chen, Tao Li 0016
Signal Process.1
2025 Unknown Cyber Threat Discovery Empowered by Genetic Evolution Without Prior Knowledge
abstract
With the continuous development of cyber-attack technologies, attackers increasingly exploit zero-day vulnerabilities or leverage emerging techniques to launch sophisticated attacks, resulting in the persistent emergence of unknown cyber-attacks. However, traditional DL-based cyber-attack detection methods heavily rely on large-scale labeled training data. In practice, obtaining sufficient samples of unknown attacks is challenging, which makes it difficult for these methods to effectively defend against unknown cyber-attacks. In this paper, we propose a method for discovering unknown cyber threats empowered by genetic evolution without prior knowledge. Specifically, We, first mapped the network feature space into a gene framework, and divided the attack genes into a static gene region (SGZ) and a dynamic gene region (DGZ) according to the importance of the cyber-attack genes. Subsequently, leveraging the known attack genes, we utilized different gene evolution strategies and a Convolutional Autoencoder (CAE) to generate attack variants and potential unknown attack genes. Finally, we constructed a cyber-attack detection model incorporating both the global attention mechanism (GAM) and the local attention mechanism (LAM). The generated attack variants and unknown attack genes are the used to enhance the detection ability of the detection model for variants and unknown cyber-attacks. We conducted a large number of experiments on six real and authoritative network datasets. The experimental results show that in different scenario settings, the F1 scores of our proposed method for detecting unknown attacks are 84.64% and 95.77% respectively. The F1 score for detecting unknown attacks on the UNSW-NB15 dataset exceeds that of the baseline classifier. The F1 score for detecting unknown attacks on the CSE-CIC-IDS2018 dataset is 98.85%. In comparison with SOTA methods, the average F1 score is improved by 3.14%. In the evaluation of variant detection performance, the generation method we proposed improves the detection of variants by approximately 11.2%, surpassing generation methods such as the Conditional Generative Adversarial Network (CGAN) and the Variational Autoencoder (VAE). Meanwhile, we also comprehensively evaluated the generalization ability of our proposed method and the evolution ability of different evolution strategies on different datasets and through ablation experiments.
Wenbo Fang, Junjiang He, Wenshan Li 0001, Wengang Ma, Linlin Zhang 0005, Xiaolong Lan, Geying Yang, Jiangchuan Chen, Tao Li 0016
IEEE Trans. Inf. Forensics Secur.6
2025 Automatic penetration testing model based on reinforcement learning for complex network environments
Junjiang He, Wenbo Fang, Shenwen Yang, Jiangchuan Chen, Tao Li 0016, Xiaolong Lan
J. Supercomput.7
2024 SPAW-SMOTE: Space Partitioning Adaptive Weighted Synthetic Minority Oversampling Technique For Imbalanced Data Set Learning
abstract
Abstract The problem of data imbalance is common in reality, which greatly affects the performance of classifiers. Most of the solutions are to balance the data set by generating new minority class samples, which are faced with the problems of selecting the appropriate area for generating samples, fuzzy classification boundary and uneven distribution of samples. To solve these problems, we propose a novel oversampling algorithm named space partitioning adaptive weighted synthetic minority oversampling technique (SPAW-SMOTE). We first divide the data space into boundary space and non-boundary space based on spatial partitioning techniques. The number of samples to be generated is assigned to different spaces by the designed adaptive weighting algorithm, which is used to solve the problems of uneven distribution of samples and easy to blur the classification boundary. Finally, we also endeavor to develop a new generation algorithm to reduce the probability of overlapping samples generated when synthesizing new samples and to ensure the diversity of new samples. Experimental results on 18 real-world data sets show that the average performance (G-mean, F1-measure and Area Under Curve) of SPAW-SMOTE is significantly better than other existing oversampling techniques.
Junjiang He, Tao Li 0016, Xiaolong Lan, Wenbo Fang
Comput. J.4
2024 Automating the Deployment of Cyber Range with OpenStack
abstract
Abstract Cyber Range is an experimental platform based on virtualization technology to construct a controlled simulation environment, providing a real-world simulation environment for cybersecurity personnel to conduct various practical exercises. The problem is that generating a virtual environment satisfying the requirements is labor-intensive and time-consuming. To resolve the above problem, this paper proposes a system to automate the deployment of a cyber range. In our method, the first step is to collect virtual machines (VMs) related to cybersecurity and extract relevant features. Then, machine learning is used to classify VMs to reduce the cost of manual VMs selection. Lastly, leveraging the popular OpenStack cloud platform as the deployment platform enhances the applicability of the cyber range. When it comes time to deploy a virtual environment, the instructor only needs to provide some brief description information of a virtual environment. Then, the system will automatically parse the description file to complete the automated deployment of the virtual environment. This system has been successfully applied to the cyber range of Sichuan University for daily teaching tasks.
Shaohong Zhou, Junjiang He, Tao Li 0016, Xiaolong Lan, Hui Zhao 0007
Comput. J.4
2024 Efficient Based on Improved Random Forest Defense System Against Application-Layer DDoS Attacks
abstract
Application‐layer distributed denial of service (DDoS) attacks have become the main threat to Web server security. Because application‐layer DDoS attacks have strong concealability and high authenticity, intrusion detection technologies that rely solely on judging client authenticity cannot accurately detect such attacks. In addition, application‐layer DDoS attacks are periodic and repetitive, and attack targets suddenly in a short period. In this study, we propose an efficient application‐layer DDoS detection system based on improved random forest. Firstly, the Web logs are preprocessed to extract the user session characteristics. Subsequently, we propose a Session Identification based on Separation and Aggregation (SISA) method to accurately capture user sessions. Lastly, we propose an improved random forest classification algorithm based on feature weighting to address the issue of an increasing number of features leading to prolonged calculation times in the random forest algorithm, and as the feature dimension increases, there might be instances where no subfeature is related to the category to be classified. More importantly, we compare the request source IP with the malicious IP in the threat intelligence library to deal with the periodicity and repetition of application‐layer DDoS attacks. We conducted a comprehensive experiment on the publicly available Web log dataset and the threat intelligence database of the laboratory as well as the simulated generated attack log dataset in the laboratory environment. The experimental results show that the proposed detection system can control the false alarm rate and false alarm rate within a reasonable range, improving the detection efficiency further, the detection rate is 99.85%. In secondary attack detection experiments, our proposed detection method achieves a higher detection rate in a shorter time.
Junjiang He, Wenbo Fang, Xiaolong Lan, Geying Yang, Tao Li 0016, Jiangchuan Chen
Int. J. Intell. Syst.3
2024 A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution
abstract
Unmanned aerial vehicles (UAVs) have experienced rapid development, permeating diverse domains. However, addressing security challenges in UAV networks remains daunting due to resource limitations and the high autonomy of UAV terminals. The current research on the UAV network intrusion detection lacks an efficient process covering each UAV terminal and a lightweight collaborative response mechanism between the UAVs and ground stations, which affects the performance of the UAV network intrusion detection. In this article, inspired by the vaccine distribution mechanism in artificial immune systems, we propose a hierarchical UAV network intrusion detection and response approach based on the vaccine distribution. Specifically, we first implement an immune game-based negative selection algorithm at the ground station, to effectively generate vaccines covering the immune space. Then, we distribute vaccines to the UAV terminals, empowering them with intrusion detection capabilities. Finally, we introduce a collaborative response mechanism to enable the intrusion detection at the UAV terminals and perform terminal state assessments. We evaluate the performance of our proposed approach on a large number of the real UAV network data sets. The experimental results indicate that our proposed intrusion detection approach for the UAV networks at the ground stations surpasses all the baseline models. In scenarios involving air-ground coordination, our suggested collaborative response approach proves to be effective in enabling intrusion detection at the UAV terminal, facilitating timely and efficient UAV intrusion detection. Moreover, we demonstrate on the ALFA and NSL-KDD data sets that our approach excels in detecting UAV network intrusions. Particularly, on real UAV network data (ALFA), the detection rate reaches 99.05% and the accuracy is 96.13% surpassing the other models by approximately 6%.
Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016
IEEE Internet Things J.5
2024 Corrections to "A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution"
abstract
Presents corrections to the paper, (Corrections to “A Hierarchical Unmanned Aerial Vehicle Network Intrusion Detection and Response Approach Based on Immune Vaccine Distribution”).
Jiangchuan Chen, Junjiang He, Wenshan Li 0001, Wenbo Fang, Xiaolong Lan, Wengang Ma, Tao Li 0016
IEEE Internet Things J.5
2024 An Immune-Knowledge-Driven SCADA-Based Industrial Virus Propagation Model
abstract
Supervisory Control and Data Acquisition (SCADA) systems are the core of industrial control systems and an important part of critical infrastructure. With the deployment of 5G networks around the world, SCADA systems are no longer a relatively secure and physically isolated system like in the past, but are facing huge network virus threats. In order to solve the problem that existing models ignore the communication between nodes in the system, we propose an industrial virus transmission model SELBR based on immune knowledge by simulating the function of T cells in the immune system. By introducing E node, the model is used to realize the function of information transfer between nodes. What’s more, we fit the numerical simulation results with the actual data set to verify the existence of the model, and verify the effectiveness of the model for controlling the spread of industrial viruses through model comparison experiments. Numerical results show that the model can effectively control the spread of the virus. Finally, on the basis of parameter sensitivity analysis, preventive suggestions are put forward to further strengthen the security of SCADA system.
Junjiang He, Jiahang Tang, Hongxia Wang 0001, Geying Yang, Tao Li 0016, Xiaolong Lan
IEEE Internet Things J.7
2024 Information-Freshness-Aware Wireless Multiuser Uplink Physical-Layer Security Communication
abstract
In this article, we focus on a wireless multiuser uplink network consisting of a single antenna access point (AP) and multiple single antenna users, in which each user transmits time-sensitive confidential message to the AP in a time-division multiple access (TDMA) manner. When a user is scheduled to transmit, the other users will be regarded as potential eavesdroppers. In practical Internet of Things (IoT) applications, different users may have different requirements for throughput, and the timeliness of information needs to be guaranteed. In order to effectively adapt to these heterogeneous application requirements, the average weighted sum Age of Information (AoI) minimization problem is formulated under the premise of satisfying the minimum sampling rate requirement, power allocation constraint, and user scheduling constraint. In order to solve this problem, we first propose two stationary randomized scheduling policies, which are modeled as D/Geom/1 and Geom/Geom/1 queueing systems, respectively, and design two algorithms to find the optimal sampling period of D/Geom/1 system, the sampling probability of Geom/Geom/1 system, the power ratio allocated to confidential information, and the user scheduling probability. Second, an AoI-aware adaptive secure transmission scheme (AASTS) is proposed under Lyapunov optimization framework by transforming the original time-average weighted sum AoI minimization problem into a real-time optimization problem related to data queue state and AoI evolution of every time slot. Numerical results show that the proposed AASTS scheme can achieve better average AoI performance, and the D/Geom/1 system is superior to the Geom/Geom/1 one.
Xiaolong Lan, Junjiang He, Liang Liu 0009, Qingchun Chen, Tao Li 0016
IEEE Internet Things J.1
2024 On the AoI-Aware Status Update in Buffer-Aided Wireless-Powered Internet of Things Network
abstract
In this paper, we focus on buffer-aided wireless powered Internet of Things (IoTs) comprising of one wireless access point (AP) and multiple devices, where the AP provides energy to all devices via downlink radio frequency (RF) energy beams. All devices utilize the harvested energy to transmit their data to the AP in a time-division multiple access (TDMA) manner. Every device is assumed to be provisioned with energy storage and data buffer to store the collected energy from the AP and its data, respectively. The problem of minimizing the long-term average age of information (AoI) of the system is formulated in this paper. By solving the problem under the Lyapunov optimization framework, the AoI-aware adaptive transmission scheme is obtained, in which downlink RF energy beamforming, downlink energy transfer and uplink access, as well as transmit power and transmission rate by every device, will be jointly adjusted in order to minimize average weightede AoI according to the underlying channel state information (CSI), the buffer state information (BSI), the energy-consumption status information (ESI) of all terminals, as well as the AoI status information (ASI). Our analysis unveils that, the status update rate at devices has a significant impact on the achievable AoI performance, and the minimum average weighted AoI can only be realized at a reasonable status update rate, which is neither too high nor too low. Moreover, flexible AoI-aware scheme can be realized by adjusting either the AoI priority level or the AoI weighting coefficient.
Tianheng Wang, Xiaolong Lan, Yong Liu 0005, Qingchun Chen, Pei Xiao 0001
IEEE Internet Things J.3
2024 Optimal Age of Information and Throughput Scheduling in Heterogeneous Traffic Wireless Physical-Layer Security Communications
abstract
A wireless multi-user uplink heterogeneous network is investigated in this paper, which comprises an access point and two distinct user groups including throughput-oriented users and age of information (AoI)-oriented users, in which throughput-oriented users prioritize achieving as high throughput as possible, while AoI-oriented users emphasize timely transmission of information. It is assumed that the transmitted information needs to be kept strictly confidential to unintended users, and the time-division multiple access (TDMA) approach is adopted to transmit confidential information of each user. For such a network, all users who are not scheduled for transmission will be treated as potential eavesdroppers. The objective of our work is to maximize the average achievable secrecy rate of throughput-oriented users while minimizing the average AoI of AoI-oriented users subject to the data queue causality and stability constraints, the sampling rate requirements of AoI-oriented users, the time-averaged and peak transmission power constraints, and the user scheduling constraint. We propose using Lyapunov optimization to convert the original time-averaged optimization problem into a sequence of real-time ones associated with both queue sizes and AoI involved in the current time slot. On this basis, an adaptive heterogeneous traffic security transmission (AHTST) strategy is proposed to determine the optimal strategies for the flow control of throughput-oriented users, the sampling rate control of AoI-oriented users, the power allocation, as well as the user scheduling. Numerical results demonstrate that the AHTST strategy surpasses the considered benchmark schemes in both achievable average secrecy rate and average AoI.
Xiaolong Lan, Junjiang He, Wengang Ma, Qingchun Chen
IEEE Internet Things J.3
2024 A fast dual-module hybrid high-dimensional feature selection algorithm
Geying Yang, Junjiang He, Xiaolong Lan, Tao Li 0016, Wenbo Fang
Inf. Sci.3
2024 An Automatic XSS Attack Vector Generation Method Based on the Improved Dueling DDQN Algorithm
abstract
As one of the most common web attack types, the XSS (Cross Site Scripting) attack is an important research topic in web attack and defense technology. However, the attack vectors in security evaluation methods are often based on expert experience or manual testing methods, which are not only costly and time-consuming but also have a large number of false positives. In this paper, we build an automatic XSS attack vector generation method based on the improved Dueling DDQN algorithm. First, we model the XSS attack vector generation process as a Markov decision process, mapping the initial attack vector mutation points and mutation strategies to the state space and action space of the model, respectively. Second, we propose an improved Dueling DDQN algorithm by introducing a priority experience replay mechanism to improve algorithm performance and the speed of attack vector generation. Third, we establish a feedback mechanism based on the edit distance algorithm to define the role of the reward function, preventing the model from getting stuck in local optima and achieving better mutation effects. Finally, we propose an automatic XSS attack verification method based on static semantic analysis to validate the effectiveness of our generated attack vectors. Based on the aforementioned methods, we have developed a prototype tool for automatic XSS scanning, which avoids generating a high proportion of invalid samples like traditional XSS scanners. The experimental results demonstrate that the improved Dueling DDQN algorithm outperforms other value-based reinforcement learning algorithms in terms of convergence speed, learning efficiency, and stability. The adaptive attack vector generation model can generate attack vectors that adapt to program context semantics and bypass defense mechanisms. Our method performs well when directly scanning the target system and exhibits a higher bypass rate of 85.71% in target systems deployed with WAFs. Furthermore, the model can learn the shortest path for selecting strategies to bypass WAF detection
Junjiang He, Tao Li 0016, Xiaolong Lan
IEEE Trans. Dependable Secur. Comput.5
2024 BR-HIDF: An Anti-Sparsity and Effective Host Intrusion Detection Framework Based on Multi-Granularity Feature Extraction
abstract
Host-based intrusion detection systems (HIDS) have been widely acknowledged as an effective approach for detecting and mitigating malicious activities. Among various data sources utilized in HIDS, system call traces have gained significant popularity due to their inherent advantage of providing fine-grained information. Nevertheless, conventional feature extraction techniques relying on system calls tend to overlook the issue of high-dimensional sparse feature space. In this paper, we conduct a theoretical analysis to investigate the underlying causes of the sparsity problem. Subsequently, we propose an anti-sparse theory (anti-ST) as a solution to address this issue. Then, we design a multi-granularity feature extraction method (MGFE), which also meets the prerequisite mathematical conditions of the anti-ST. By applying this method, we effectively reduce the size of the feature space and minimize the number of generated features, thus mitigating sparsity. Furthermore, leveraging this approach, we propose a robust and anti-sparsity host intrusion detection framework, known as the MGFE-based Host Intrusion Detection Framework (BR-HIDF). A series of experiments were conducted to evaluate the proposed framework and compare it with the state-of-the-art method. The results demonstrate that our framework achieves impressive accuracy (97.26%), precision (97.62%), recall (96.85%), and F1 score (97.23%) in the intrusion detection task, surpassing existing frameworks. Moreover, the proposed framework significantly reduces the time overhead by 38.80%, exhibiting the highest AUC value of 0.992. Furthermore, we enhance the robustness of the detection system by integrating host-based and network-based detection, which provides greater flexibility in identifying various types of attacks.
Junjiang He, Cong Tang, Wenshan Li 0001, Tao Li 0016, Xiaolong Lan
IEEE Trans. Inf. Forensics Secur.6
2023 MPF-FS: A multi-population framework based on multi-objective optimization algorithms for feature selection
Junjiang He, Wenshan Li 0001, Tao Li 0016, Xiaolong Lan
Appl. Intell.5
2023 Feature selection optimized by the artificial immune algorithm based on genome shuffling and conditional lethal mutation
Yongbin Zhu, Tao Li 0016, Xiaolong Lan
Appl. Intell.3
2023 DBWE-Corbat: Background network traffic generation using dynamic word embedding and contrastive learning for cyber range
Linfeng Du, Junjiang He, Tao Li 0016, Xiaolong Lan, Yunhua Huang
Comput. Secur.5
2023 Uniformity-Comprehensive Multiobjective Optimization Evolutionary Algorithm Based on Machine Learning
abstract
When solving real‐world optimization problems, the uniformity of Pareto fronts is an essential strategy in multiobjective optimization problems (MOPs). However, it is a common challenge for many existing multiobjective optimization algorithms due to the skewed distribution of solutions and biases towards specific objective functions. This paper proposes a uniformity‐comprehensive multiobjective optimization evolutionary algorithm based on machine learning to address this limitation. Our algorithm utilizes uniform initialization and self‐organizing map (SOM) to enhance population diversity and uniformity. We track the IGD value and use K‐means and CNN refinement with crossover and mutation techniques during evolutionary stages. Our algorithm’s uniformity and objective function balance superiority were verified through comparative analysis with 13 other algorithms, including eight traditional multiobjective optimization algorithms, three machine learning‐based enhanced multiobjective optimization algorithms, and two algorithms with objective initialization improvements. Based on these comprehensive experiments, it has been proven that our algorithm outperforms other existing algorithms in these areas.
Yuxuan Luan, Junjiang He, Jingmin Yang, Xiaolong Lan, Geying Yang
Int. J. Intell. Syst.4
2023 DGA-PSO: An improved detector generation algorithm based on particle swarm optimization in negative selection
abstract
The negative selection algorithm (NSA) is an essential algorithm in the artificial immune system used to achieve anomaly detection by generating detectors. The traditional NSA algorithm generates candidate detectors randomly, which leads to a partially dense and redundant distribution of detectors in the nonself areas, resulting in the presence of holes that are not covered by detectors. A detector generation algorithm based on particle swarm optimization (DGA-PSO) is proposed to overcome these defects. DGA-PSO converts the self-tolerance process into an adaptation function to guide particles to move in a specific direction by artificial settings and variants, generates efficient detectors covering the nonself space, reduces the redundancy among detectors and fills holes not covered. Thus, we successfully reduce the number of detectors while improving the detection rate of the algorithm. Through experimental validation analysis, DGA-PSO ranks first in detector training time and the detection rate on four UCI datasets compared to the classical algorithms RNSA and V-Detector and the improved algorithms BIORV-NSA, ADC-NSA and IFB-NSA.
Junjiang He, Wenshan Li 0001, Tao Li 0016, Xiaolong Lan
Knowl. Based Syst.5
2023 Comprehensive Android Malware Detection Based on Federated Learning Architecture
abstract
Android malware and its variants are a major challenge for mobile platforms. However, there are two main problems in the existing detection methods:a) The detection method lacks the evolution ability for Android malware, which leads to the low detection rate of the detection model for malware and its variants.b) Traditional detection methods require centralized data for model training, however, the aggregation of training samples is limited due to the infectivity of malware and growing data privacy concerns, centralized detection methods are difficult to be applied in actual detection scenarios. In this paper, we propose FEDriod, a comprehensive Android malware detection method based on federated learning architecture that protects against growing Android malware or emerging Android malware variants. Specifically, we employ genetic evolution strategy to simulate the evolution of Android malware and develop potential malware variants from typical Android malware. Then, we customize the Android malware detection model based on residual neural network to achieve high detection accuracy. Finally, to achieve the protection sensitive data, we develope a federated learning framework to allows multiple Android malware detection agencies to jointly build a comprehensive Android malware detection model. We comprehensively evaluate the performance of FEDriod on the CIC, Drebin, and Contagio authoritative datasets. Experimental results show that our local model outperforms all baseline classifiers. In the federal scenario, our proposed method is superior to the state-of-the-art detection methods, especially in the cross-dataset evaluation, the F1 of FEDriod is 98.53%. More important, we performed genetic evolution experiments on the Drebin dataset, and the results showed that our proposed method has the ability to detect Android malware variants.
Wenbo Fang, Junjiang He, Wenshan Li 0001, Xiaolong Lan, Tao Li 0016, Jiwu Huang, Linlin Zhang 0005
IEEE Trans. Inf. Forensics Secur.4
2022 XSS adversarial example attacks based on deep reinforcement learning
Cong Tang, Junjiang He, Hui Zhao 0007, Xiaolong Lan, Tao Li 0016
Comput. Secur.5
2021 On the Adaptive AoI-aware Buffer-aided Transmission Scheme for NOMA Networks
abstract
In this paper, non-orthogonal multiple access (NOMA) technology was exploited in a downlink wireless network to improve the averaged age of information (AoI) performance, where a source deployed with data buffers is supposed to send independent information to two users. A long-term average AoI minimization problem is formulated by taking into account of data and energy causality, peak and long-term average power constraints. Then, to fully explore the potential of data buffers, we used Lyapunov optimization framework and proposed a novel adaptive AoI-aware butter-aided transmission scheme (ABTS) to adjust the transmission rate and transmit power according to dynamic channel state information (CSI) and butter state information (BSI). Simulation results were presented to validate that the proposed ABTS scheme performs much better than those schemes with OMA transmission in terms of reducing AoI.
Yong Liu 0005, Qingchun Chen, Xiaolong Lan, Yongwei Fu
WCNC4
2021 An immune-based risk assessment method for digital virtual assets
Junjiang He, Tao Li 0016, Beibei Li 0002, Xiaolong Lan
Comput. Secur.4
2021 SP-SMOTE: A novel space partitioning based synthetic minority oversampling technique
Tao Li 0016, Beibei Li 0002, Xiaolong Lan
Knowl. Based Syst.5
2021 Achievable Rate Region of Energy-Harvesting Based Secure Two-Way Buffer-Aided Relay Networks
abstract
This paper considered an energy-harvesting based secure two-way relay (EH-STWR) network, where two users exchanged information with the assistance of one buffer-aided relay that harvested energy from two users. To realize the confidential message exchange between two users in the presence of a potential eavesdropper, a secure bidirectional relaying scheme based on time division broadcast (TDBC) was proposed, where one user sent artificial noise to suppress the eavesdropper and another user transmitted data to the relay. A secure sum-rate maximization problem was formulated subject to average and peak transmit power constraints, data buffer and energy storage causality, and transmission mode constraints. By employing the Lyapunov optimization framework, a security-aware adaptive transmission scheme was proposed to jointly adapt transmission mode selection, power allocation, and security rate allocation according to channel/buffer/energy state information (CSI/BSI/ESI). Analysis results showed that the average achievable secrecy rate region can be significantly improved and there exists an inherent trade-off among transmission delay, requirement of transmit power consumption, and achievable secure sum-rate. Moreover, the channel condition between the energy-constrained relay and the potential eavesdropper is a critical factor on the achievable long-term average secrecy rate performance.
Yulong Nie, Xiaolong Lan, Yong Liu 0005, Qingchun Chen, Gaojie Chen 0001, Lisheng Fan
IEEE Trans. Inf. Forensics Secur.2
2020 Adaptive Transmission Design for Rechargeable Wireless Sensor Network With a Mobile Sink
abstract
In this article, we aim at maximizing the data gathering performance of the rechargeable wireless sensor network, where a mobile sink moves along the predefined path to charge sensor nodes through a wireless energy transfer technique and gather data from them. First, we show how to transform the original time-average optimization problem into a queue stability one by using the Lyapunov optimization framework, then we show how to decompose it into multiple subproblems by using the optimization decomposition. A distributed speed control and routing algorithm was proposed to reduce the computing load of the mobile sink and to obtain the near-optimal solution for data collection. Our analysis shows that there is an inherent tradeoff between the network utility and the average data queuing size, and the proposed adaptive transmission scheme can achieve the near-optimal network utility when a certain queueing delay can be tolerated.
Xiaolong Lan, Yongmin Zhang, Lin Cai 0001, Qingchun Chen
IEEE Internet Things J.1
2020 Energy Efficient Buffer-Aided Transmission Scheme in Wireless Powered Cooperative NOMA Relay Network
abstract
In this paper, we consider a wireless powered cooperative non-orthogonal multiple access (NOMA) relay network, in which one source is supposed to send independent messages to two users with the assistance of one energy-constrained relay that harvests energy from the source. Firstly, we study the minimum power consumption at the source node to fulfill the least required transmission rates by two users in both time switching relaying (TSR) strategy and power splitting relaying (PSR) one. Secondly, when the relay is provisioned with data buffer and energy storage, the long-term average power consumption minimization problem is formulated to take into account of the data and energy queue causality, peak transmit power constraint, and transmission mode selection. By using Lyapunov optimization framework, a novel buffer-aided transmission scheme (BATS) is proposed to asymptotically approach the optimal solution. Our analysis shows that, the PSR outperforms the TSR in terms of the realized energy efficiency, and BATS can be utilized to further improve the energy efficiency. It is disclosed that, there is an inherent trade-off between the long-term power consumption and the average queuing delay. In addition, larger user rates or less power consumption can be realized if a larger delay can be tolerated.
Xiaolong Lan, Yongmin Zhang, Qingchun Chen, Lin Cai 0001
IEEE Trans. Commun.1
2020 Achievable Secrecy Rate Region for Buffer-Aided Multiuser MISO Systems
abstract
In this paper, we consider a buffer-aided multiuser multiple-input single-output (MISO) network consisting of one multi-antenna access point (AP) and multiple single-antenna users, in which the AP is provisioned with data buffers for temporarily storing the data for each user either from the upper layer applications or the message by the AP. The data for one specific user must be kept confidential from all other unintended users. For such a system, we aim at maximizing the long-term average achievable secrecy rate region by carefully designing the flow control, the information signal and artificial noise beamforming, as well as the user selection. To address this issue, we first transform the time average optimization problem into a real-time one by using the Lyapunov optimization framework. Then it is proposed to decompose the optimization problem into several sub-problems by using the optimization decomposition technique. Although the information signal and artificial noise beamforming sub-problem is non-convex, we show that it can be decomposed into a two-stage optimization problem to effectively solve it by using the exact line search and DC (difference of two convex functions) algorithms. Moreover, we extend the average secrecy rate region maximization problem to the worst-case scenario, in which all unintended users are colluding in eavesdropping. Our analysis discloses that, there exists an inherent tradeoff between the average achievable secrecy rate region and the average queueing length. It is shown that a better average secrecy rate region can be realized by fully taking advantage of the buffer-aided transmission potentials in the MISO network, if a certain queueing delay is tolerable.
Xiaolong Lan, Juanjuan Ren, Qingchun Chen, Lin Cai 0001
IEEE Trans. Inf. Forensics Secur.1
2020 Efficient Computing Resource Sharing for Mobile Edge-Cloud Computing Networks
abstract
Both the edge and the cloud can provide computing services for mobile devices to enhance their performance. The edge can reduce the conveying delay by providing local computing services while the cloud can support enormous computing requirements. Their cooperation can improve the utilization of computing resources and ensure the QoS, and thus is critical to edge-cloud computing business models. This paper proposes an efficient framework for mobile edge-cloud computing networks, which enables the edge and the cloud to share their computing resources in the form of wholesale and buyback. To optimize the computing resource sharing process, we formulate the computing resource management problems for the edge servers to manage their wholesale and buyback scheme and the cloud to determine the wholesale price and its local computing resources. Then, we solve these problems from two perspectives: i) social welfare maximization and ii) profit maximization for the edge and the cloud. For i), we have proved the concavity of the social welfare and proposed an optimal cloud computing resource management to maximize the social welfare. For ii), since it is difficult to directly prove the convexity of the primal problem, we first proved the concavity of the wholesaled computing resources with respect to the wholesale price and designed an optimal pricing and cloud computing resource management to maximize their profits. Numerical evaluations show that the total profit can be maximized by social welfare maximization while the respective profits can be maximized by the optimal pricing and cloud computing resource management.
Yongmin Zhang, Xiaolong Lan, Ju Ren 0001, Lin Cai 0001
IEEE/ACM Trans. Netw.2
2020 Throughput-Optimal H-QMW Scheduling for Hybrid Wireless Networks With Persistent and Dynamic Flows
abstract
The well-known Queue-length-based MaxWeight scheduling algorithm (QMW) has been proved to be throughput-optimal for persistent flows only, which are long-lived with infinite traffic arrival. If the flows are dynamic ones, i.e., short-lived with finite data to transmit, QMW cannot guarantee queue stability. Given future wireless networks may support both persistent machine-to-machine flows and dynamic human-to-human flows, a Flow (File) Delay based MaxWeight scheduling algorithm (F-D-MW) has been shown to be throughput-optimal. However, new flows have to suffer a long start-up latency after arriving in the system. In this work, we present the definition of the capacity region for hybrid systems with the coexistence of persistent and dynamic flows. First, when a new arrival dynamic flow classification is known, we propose an online Hybrid Queue-length-based MaxWeight (H-QMW) scheduling algorithm, and then propose a more realistic adaptive H-QMW (A-H-QMW) scheduling algorithm for the system without the knowledge of the classification of flows. We prove that H-QMW can achieve throughput-optimality for hybrid systems. Performance evaluation not only validates the throughput-optimality of H-QMW and A-H-QMW in various types of networks but also reveals that H-QMW and A-H-QMW can achieve lower start-up and total latency for dynamic flows than F-D-MW.
Xiaolong Lan, Yi Chen 0006, Lin Cai 0001
IEEE Trans. Wirel. Commun.1
2019 Adaptive Content Placement in Edge Networks Based on Hybrid User Preference Learning
abstract
Edge caching is promising to alleviate the backhaul pressure and provide low latency delivery for delay sensitive applications. However, it encounters great challenges to make adaptive content placement decisions according to the scattered explicit feedback with spatial and temporal dynamics. We propose a hybrid learning framework to obtain a more accurate prediction of users' preference by combining historical data from the central cloud and real-time data in edge networks. Two hybrid-learning algorithms, i.e., Hybrid Learning based on Alternating Least Squares (HLALS) and Hybrid Learning based on Conjugate Gradient Descent (HLCGD) are designed to achieve efficient caching decisions, where HLCGD is more efficient than HLALS at the expense of complexity. Simulation results show that, compared to the popular stochastic gradient descent strategy, the proposed algorithms can achieve superior performance thanks to more accurate prediction of users preference.
Lei Zhao 0007, Xiaolong Lan, Lin Cai 0001, Jianping Pan 0001
GLOBECOM2
2019 Efficient Computation Resource Management in Mobile Edge-Cloud Computing
abstract
We study the computation resource management problem in mobile edge-cloud computing networks. Mobile edge servers shall first satisfy the computation requirements of mobile users and Internet of Things (IoT) devices, and then wholesale redundant computation resources to the cloud networks to maximize their profit. Due to the coarse time granularity of wholesales, computation resource buyback may happen occasionally to deal with traffic bursts. Thus, the mobile edge servers need to make a tradeoff between the wholesale profit and the buyback cost. In this paper, the computation resource management problem is modeled as profit maximization. To solve this problem, we first analyze the relationship among the reserved computation resources, the computation tasks of mobile users and IoT devices, and the buyback cost. Then, we design an efficient wholesale scheme to determine the amount of the wholesaled computation resources, by which the total expected profit of the mobile edge server can be maximized. Given the reserved computation resources, we also propose a fast-convergent realtime buyback scheme for mobile edge servers to minimize the buyback cost. Finally, the simulation results show that our proposed efficient wholesale and buyback scheme can increase the total profit while guaranteeing the computation delay of all the computation tasks, especially when the computation workloads are time-varying.
Yongmin Zhang, Xiaolong Lan, Yue Li 0007, Lin Cai 0001, Jianping Pan 0001
IEEE Internet Things J.2
2019 Buffer-Aided Adaptive Wireless Powered Communication Network With Finite Energy Storage and Data Buffer
abstract
In this paper, the access point (AP) in a wireless network is assumed to provide energy supply via wireless energy transfer to multiple terminals in the downlink, and all the terminals use the harvested energy to transmit their collected data to the AP in the uplink in a time division multiple access (TDMA) manner. Each terminal is provisioned with a finite energy storage and a finite data buffer to store the harvested energy and to buffer the arrived data traffic, respectively. Due to the limited data buffer and energy storage size, there might be data loss due to either data buffer overflow or energy storage depletion. Firstly, we aim at maximizing the long-term weighted sum-rate through energy beamforming vector design, power allocations, rate control, time allocations, and transmission mode selection subject to average transmit power, peak transmit power, data loss ratio requirements, practical data buffer as well as energy storage constraints. Secondly, the weighted max-min scheduling scheme is proposed to guarantee the fair access requirement by multiple terminals. Numerical analyses are presented to show that, the proposed adaptive design can substantially improve the average achievable rate region, while the proposed weighted max-min fair scheduling can effectively ensure the fair access requirements.
Xiaolong Lan, Qingchun Chen, Lin Cai 0001, Lisheng Fan
IEEE Trans. Wirel. Commun.1
2018 Wireless Powered Buffer-Aided Communication Over $K$-User Interference Channel
abstract
In this paper, we consider the wireless powered communication network, in which K terminals are supplied by one common power station (PS) via the radio frequency (RF) energy harvesting technology to transmit their independent data to the corresponding K receivers. In addition, each terminal is assumed to be equipped with an energy storage to store the collected energy and one data buffer to cache the message to be delivered. We formulate an optimization problem to minimize the average power consumption of the PS subject to the given data arrival rates, the energy sustainability and the data buffer stability constraints at all K terminals. By using Lyapunov framework, an adaptive transmission scheme is proposed to determine the energy beamforming, the transmit power allocation and transmit mode selection based on the energy storage and data buffer status. Our analysis unveils that, there exists an inherent tradeoff between the average power consumption and the average queuing delay, and the requested information rates by multiple energy-constrained wireless powered terminals can be effectively supported with less power consumption if a certain transmission delay is tolerable.
Xiaolong Lan, Qingchun Chen, Lin Cai 0001
VTC Fall1