VLDB 2026 Research / reviewers in the wild / expert
Yuepeng E
dblp:20/10444 · also Yuepeng E.
· DBLP profile ↗
17ranked-venue papers
0as first author
11since 2021 · last 2025
0000-0001-7434-3995ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 4 since 2021Systems, architecture and hardware · 3 · 2 since 2021Security and privacy · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Cancelable Biometrics Based on Cosine Locality Sensitive Hashing and Grouped Inner Product Transformation for Real-Valued Features
Ruoqi Zhang, Yulin Ni, Peisong Shen, Xue Tian, Yuepeng E |
ACNS (3) | 5 |
| 2025 | QShield: Universal Defense Framework Against QUIC Client-Side Attacks with eBPFabstractQUIC adapts well to complex network situations due to mechanisms such as 0/1-RTT handshake and fast retransmission. It has now become a new star in the era of IoT. However, a phenomenon reveals the security risks of QUIC. Studies indicate that the internet is exposed to an average of four QUIC flood attacks per hour. The efficiency-oriented features of QUIC introduce vulnerabilities, making it particularly susceptible to attacks. In IoT scenarios, protocol security often depends on the design of the protocol itself and the middlewares. However, QUIC's design does not prioritize security as its highest concern and due to the ossification of middleboxes, the server-side defense is the only option. Therefore, we propose the QShield framework to seek breakthroughs from an engineering perspective. Based on the SDN principles, QShield consists of three parts. At the application layer, QUIC applications can utilize this library to implement strategy development and enable data sharing. A user-space library operates as the control layer, facilitating real-time bidirectional data transfers between the kernel and user space via a suite of APIs. In the data layer, QShield core blocks attack packets at the lowest layer of the Linux network protocol stack using eBPF technology. QShield effectively resists client-side attacks, and experimental results show that QShield can reduce the server's CPU usage for processing attack packets by nearly 50%, thereby essentially restoring normal Queries Per Second and bandwidth, reducing the bandwidth amplification by about 68% on the specific QUIC implementation. Yulin Ni, Yuepeng E, Jingguo Ge, Bingzhen Wu |
CSCWD | 2 |
| 2025 | System States Forecasting of Microservices Based on Spatio-Temporal RelationshipsabstractIn the AIOps realm, precise system state forecasting is essential, particularly within microservices architectures, where may have dynamic deployments, varied call paths, and cascading effects complicate spatio-temporal relationships. Existing time series forecasting methods, which emphasize temporal patterns, fall short in capturing the critical spatial dimensions. Spatio-temporal graph methods, while useful, often overlook temporal trends and the length of forecast horizons. Furthermore, existing research about microservices tends to undervalue the role of network metrics and topological structures in reflecting system dynamics. This paper presents STMformer, a novel model designed for microservices state forecasting, adept at managing multi-node and multivariate time series based on diverse spatio-temporal relationships. It harnesses dynamic network connections and topological insights to model complex spatio-temporal interactions and incorporates a PatchCrossAttention module for global cascading effect analysis. Based on a microservices-based dataset we collect with our developed tool, we demonstrated that STMformer outperformed existing methods, reducing MAE by 8.6% and MSE by 2.2% in forecasting tasks. The source code is available at https://github.com/xuyifeiiie/STMformer. Yuhao Gao, Jingguo Ge, Yuepeng E, Tong Li 0012 |
CSCWD | 5 |
| 2024 | Trace Anomaly Detection for Microservice Systems via Graph-based Semi-supervised LearningabstractMicroservice architectures have become mainstream for cloud-native applications, and distributed tracing is widely used to ensure system observability. Trace is essentially an aggregated data with multimodal attributes (e.g., performance metric, invocation log, and topology relationships). Existing methods typically do not adequately consider the complex correlations and interactions between the different modalities of trace, whereas fusing multimodal data into a unified analysis provide the possibility to improve performance. On the other hand, most of the existing methods are trained in an unsupervised manner and cannot utilize historical data. Therefore, this article proposes a trace anomaly detection method using graph-based semi-supervised learning, TraceGSAD. It extracts features of trace from multiple modalities and train an improved message-passing neural network to fuse features for unified modeling and generate a graph-level representation. The end-to-end deep anomaly detection model trained in an semi-supervised manner, using only a small amount of labeled data to achieve superior performance. The evaluation on the microservice benchmarks show that TraceGSAD achieves a high precision, outperforming state-of-the-art trace anomaly detection approaches. It also demonstrates the effectiveness of multimodal fusion analysis as well as the use of empirical data in semi-supervised learning that can significantly improve anomaly detection performance. Yuepeng E, Liangxiong Li, Lei Zhang 0116, Jingguo Ge |
CSCWD | 2 |
| 2024 | A time-sensitive cloud-native network based on eBPFabstractThe evolution of cloud computing and microservices is gradually supplanting traditional network deployment schemes within data centers. As applications deploy substantial computing resources in data centers, a fierce competition for network services ensues, marked by stringent quality requirements. Simultaneously, safeguarding the time sensitivity of the main flow becomes imperative. However, prevailing container network solutions primarily ensure service quality through scheduling and orchestration, neglecting the influence of computing resources on network service quality under intense resource competition. Consequently, our focus revolves around exploring the preservation of time-sensitive attributes of primary service network links, aiming to enhance the service quality of container networks in highly competitive computing resource environments. This paper introduces a novel container network solution designed to meet the quality of service requirements for time-sensitive data in container networks. Implemented on the Kubernetes platform, this solution establishes an underlay network structure based on Cilium for transmitting network packets requiring performance guarantees and exhibiting time sensitivity. Utilizing eBPF programs with adjusted CPU affinity for packet forwarding, the solution records packets necessitating quality of service guarantees. Network service quality is ensured through algorithms such as Multiqueue Priority, Earliest TxTime First, Enhancements for Scheduled Traffic, etc. The network packets requiring performance guarantees and time sensitivity refer to the TSN (Time-Sensitive Networking) standard. To assess the solution’s effectiveness, we deployed Kubernetes on two directly connected physical servers. Measurements were conducted in scenarios of both idle and highly competitive computing resources, evaluating bandwidth, latency, and jitter of container access packets across different hosts. The results confirm a noteworthy enhancement in container network service quality under highly competitive computing resource environments. Jifei Wen, Jingguo Ge, Hui Li 0098, Yuepeng E, Bingzhen Wu |
CSCWD | 5 |
| 2024 | On Improved Efficiency of Zero-Trust Tunnel for Inter-Microservices CommunicationabstractAfter trading the hardware cost and deployment complexity of inter-microservice communication architecture, the data plane of service mesh has gradually changed from sidecar mode to sidecarless mode. In sidecarless mode, the traffic of microservices need to be processed by zero-trust tunnel, so that the confidentiality, integrity and authentication of application data can be achieved. Thus, the efficiency of zero trust tunnel has a great impact on the performance of inter-microservices communication. However, current zero trust tunnel schemes require additional data transmission and processing, resulting in serious performance degradation. Thus, in this paper, we propose an efficient zero-trust tunnel which is called EZTunnel. Based on a programmable kernel, EZTunnel can execute L4 traffic management and security policies during system calls, thereby improving the communication performance between microservices. Through experiments under different traffic characteristic, we show that EZTunnel can achieve better inter-microservice request response delay, flow completion time and communication bandwidth than current zero-trust tunnel. Lei Zhang 0116, Jingguo Ge, Yulei Wu, Jifei Wen, Yuepeng E |
HPCC | 5 |
| 2024 | On Improved Efficiency and Forward Security of 0-RTT Key Exchange for SDPabstractThe Transport Layer Security (TLS) protocol has been widely used in software-defined perimeter (SDP) to establish secure, encrypted connections between distributed SDP components. To improve communication efficiency of its handshake protocol, the latest TLS standard (i.e., TLS 1.3) introduces a zero round-trip-time (0-RTT) handshake. However, traditional 0-RTT handshake protocols lack a forward secure key exchange scheme, so encrypted data that have already been transmitted could be potentially leaked to attackers after the pre-shared key (PSK) is compromised. To achieve secure TLS handshake with minimal communication cost, several forward secure 0-RTT key exchange schemes based on puncturable encryption were proposed. However, they are not applicable to real world SDP environments, because they either need to pre-store a large number of secret keys in the host onboard phase, or require a large number of complex cryptography operations (e.g., bilinear-pairing) in the access phase. Therefore, to avoid high computational overhead while still maintaining communication efficiency and forward security, a novel 0-RTT key exchange scheme based on efficient puncturable key encapsulation mechanism is proposed in this paper. Experimental results show that, with reasonable (and configurable) memory consumption, the latency performance of the proposed scheme is about 30% better than FFDHE3072, which is a practical 1-RTT key exchange scheme in TLS 1.3. Lei Zhang 0116, Jingguo Ge, Yulei Wu, Tong Li 0012, Hui Li 0098, Yuepeng E |
ICCCN | 6 |
| 2024 | A Latency-Predictable Cloud-Native Network Architecture based on XDPabstractCloud computing and microservices are increasingly supplanting traditional network deployment strategies within data centers due to their inherent flexibility in infrastructure management and rapid scalability. Nevertheless, current approaches often fall short in addressing quality of service (QoS) for virtual networks, especially under conditions of intense resource competition. This shortfall prevents the fulfillment of critical services’ requirements for low latency and predictability. To mitigate this challenge, we propose a cloud-native network service architecture designed to deliver consistently low latency and predictable packet arrival times. This architecture dynamically coordinates and reserves computational resources even during high contention periods, thereby maintaining container network QoS and ensuring the stable availability of microservice applications under extreme conditions. We validated the effectiveness of our proposed solution by deploying multiple container nodes across two directly connected servers and establishing a Kubernetes cluster. By launching a large volume of tasks within a constrained time frame, we assessed the container network’s load, latency, and jitter during peak usage periods. Our results indicate that, although our solution exhibits marginally reduced performance compared to the open-source Kubernetes network plugin under low-load conditions, it significantly outperforms the plugin under high-load scenarios. Specifically, when host CPU usage surpasses 90% and memory usage exceeds 80%, the open-source plugin experiences notable packet loss and long-tail latency distributions. In contrast, our solution demonstrates an 84% reduction in jitter compared to the open-source CNI. Jifei Wen, Jingguo Ge, Yuepeng E, Bingzhen Wu |
ISPA | 4 |
| 2021 | Network Automation for Path Selection: A New Knowledge Transfer ApproachabstractDue to the ever-increasing complexity of modern communication networks, network operators are making tremendous efforts on achieving objectives for the network to meet the diversified requirements of many real-world applications. However, network operators are repeatedly taking a lot of time on some common tasks shared by different networks. In order to reduce repetitive human efforts on network management, advanced machine learning paradigms, such as deep reinforcement learning, has received numerous attention in the networking community. Nevertheless, it encounters great difficulty in transferring learned policies to new environments, resulting in new model training and testing for each changed environment setting. To tackle this important issue, in this paper we propose a new framework that is the first of its kind to enable an agent to have transferable knowledge for network management, specifically, for network path selection tasks. Through this framework, an agent can efficiently learn and express the transferable network knowledge for achieving task objectives. Extensive experimental results show that the learned knowledge through the proposed framework can realize some common objectives of path selection tasks across different network environments. In addition, the knowledge learned from one network task can significantly improve the learning performance of another similar but different task. Guozhi Lin, Jingguo Ge, Yulei Wu, Hui Li 0098, Tong Li 0012, Wei Mi, Yuepeng E |
Networking | 7 |
| 2021 | MATEC: A lightweight neural network for online encrypted traffic classification
Jin Cheng 0008, Yulei Wu, Yuepeng E, Junling You, Tong Li 0012, Hui Li 0098, Jingguo Ge |
Comput. Networks | 3 |
| 2021 | VNE-HRL: A Proactive Virtual Network Embedding Algorithm Based on Hierarchical Reinforcement LearningabstractVirtual network embedding (VNE) that instantiates virtualized networks on a substrate infrastructure, is one of the key research problems for network virtualization. Most existing VNE approaches, however, focus on the current virtual network request (VNR) and treat all VNRs equally, which disregard the long-term impact and waste many resources on the process of embedding infeasible VNRs (i.e., VNRs that cannot be embedded completely). To address these problems, a proactive virtual network embedding algorithm based on hierarchical reinforcement learning, VNE-HRL, is proposed in this paper. Within our framework, the VNE task is performed by a two-level agent that considers both the long-term impact of a VNR and the short-term effect of an embedding action. For each processing, a high-level agent aims to select a currently feasible VNR with the maximum long-term reward from a window-based batch, and a low-level agent is assigned to embed the selected VNR on a substrate infrastructure by performing a series of embedding actions. Extensive simulation results indicate that our algorithm best performance on most metrics compared with existing state-of-the-art solutions, with up to 9.92% and 33.03% improvement on acceptance ratio and average revenue. Jin Cheng 0008, Yulei Wu, Yeming Lin, Yuepeng E, Fan Tang, Jingguo Ge |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | Real-Time Encrypted Traffic Classification via Lightweight Neural NetworksabstractThe fast growth of encrypted traffic puts forward burning requirements on the efficiency of traffic classification. Although deep learning models perform well in the classification, they sacrifice the efficiency to obtain high-precision results. To reduce the resource and time consumption, a novel and lightweight model is proposed in this paper. Our design principle is to “maximize the reuse of thin modules A thin module adopts the multi-head attention and the 1D convolutional network. Attributed to the one-step interaction of all packets and the parallelized computation of the multi-head attention mechanism, a key advantage of our model is that the number of parameters and running time are significantly reduced. In addition, the effectiveness and efficiency of 1D convolutional networks are proved in traffic classification. Besides, the proposed model can work well in a real time manner, since only three consecutive packets of a flow are needed. To improve the stability of the model, the designed network is trained with the aid of ResNet, layer normalization and learning rate warm up. The proposed model outperforms the state-of-the-art works based on deep learning on two public datasets. The results show that our model has higher accuracy and running efficiency, while the number of parameters used is 1.8% of the 1D convolutional network and the training time halves. Jin Cheng 0008, Runkang He, Yuepeng E, Yulei Wu, Junling You, Tong Li 0012 |
GLOBECOM | 3 |
| 2020 | Exploitation of Information Centric Networking in federated satellite: 5G network
Jiadi Chen, Wei Mi, Zongzhen Liu, Yuepeng E, Jingguo Ge |
Wirel. Networks | 4 |
| 2016 | Performance improvement for source mobility in named data networking based on global-local FIB updates
Jingguo Ge, Yulei Wu, Haina Tang, Yuepeng E |
Peer-to-Peer Netw. Appl. | 5 |
| 2015 | H-SOFT: a heuristic storage space optimisation algorithm for flow table of OpenFlowabstractSummary OpenFlow has become the key standard and technology for software defined networking, which has been widely adopted in various environments. However, the global deployment of OpenFlow encountered several issues, such as the increasing number of fields and complex structure of flow entries, making the size of flow table in OpenFlow switches explosively grows, which results in hardware implementation difficulty. To this end, this paper presents the modelling on the minimisation for storage space of flow table and proposes a Heuristic Storage space Optimisation algorithm for Flow Table (H‐SOFT) to solve this optimisation problem. The H‐SOFT algorithm degrades the complex and high‐dimensional fields of a flow table into multiple flow tables with simple and low‐dimensional fields based on the coexistence and conflict relationships among fields to release the unused storage space due to blank fields. Extensive simulation experiments demonstrate that the H‐SOFT algorithm can effectively reduce the storage space of flow table. In particular, with frequent updates on flow entries, the storage space compression rate of flow table is stable and can achieve at ~70%. Moreover, in comparison with the optimal solution, the H‐SOFT algorithm can achieve the similar compression rate with much lower execution time. Copyright © 2014 John Wiley & Sons, Ltd. Jingguo Ge, Yulei Wu, Yuepeng E |
Concurr. Comput. Pract. Exp. | 4 |
| 2012 | Design and Evaluation of an Operational Mobility Model over IPv6 (OMIPv6) Based on ID/Locator Split ArchitectureabstractMobile IPv6 suffers various limitations, e.g., lack of business model and management of enormous and discrete home agents, preventing it from being deployed in large-scale commercial environments. Recently, the identification/locator (ID/Locator) split architecture has demonstrated its significant predominance in next generation mobile networks. With the aim of pushing the global deployment of mobility support over IPv6, this study makes an effort to design and evaluate an operational mobility model over IPv6 (OMIPv6) based on ID/Locator split architecture. Instead of the home agents adopted in the standard MIPv6, a cloud mobility management center is employed to be responsible for maintaining the identification and locations of mobile hosts, as well as providing the name resolution services to the mobile hosts. Moreover, this paper develops an analytical model considering all possible costs required for the operation of OMIPv6. Yulei Wu, Jingguo Ge, Junling You, Yuepeng E |
TrustCom | 4 |
| 2011 | IPv4+6abstractThe routing scalability and IP address exhaustion are two significant issues the current Internet faces. The "locator/identifier (Loc/ID) split" has become a well recognized design principle for future Internet architectures that make Internet routing more scalable. In this paper, a novel Loc/ID split routing and addressing architecture called IPv4+6 is proposed. It not only solves the routing scalability problem but also expands the IP address space. It is easy to deploy, which only needs to make simple changes on DNS and gateway router. Yongmao Ren, Hualin Qian, Yuepeng E, Jun Li 0002, Jingguo Ge |
NCA | 3 |