VLDB 2026 Research / reviewers in the wild / expert
Ke Ruan
dblp:230/0591
· DBLP profile ↗
12ranked-venue papers
0as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 7 · 7 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards High-Performance Intrusion Detection with Robustness Guarantees on Programmable Switches at ISP ScaleabstractIn order to provide security connections to the enterprise campus sites, internet service providers are offering comprehensive intrusion detection services at the network layer. However, existing network intrusion detection systems (NIDS) are either ineffective or inefficient for high-speed network protection, especially for encrypted traffic analysis. In this paper, we design and implement SiteGuard, an inline network intrusion detection system with programmable switches specifically developed to protect enterprise campus sites connecting to ISP. SiteGuard proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed. SiteGuard also proposes a lightweight one-class classification model that trains the best parameters exclusively on benign traffic to identify malicious traffic. In addition, SiteGuard introduces an online update mechanism that aims to dynamically adjust the detection model in response to environmental changes. SiteGuard has been in production for more than three years. Our production and testbed evaluations demonstrate SiteGuard can detect malicious traffic with approximately 90% accuracy in minutes. Han Zhang 0009, Linqiang Qian, Guyue Liu, Kaiyang Zhao 0004, Yantu Tong, Zeji Xiao, Dongbiao He, Ke Ruan, Jilong Wang 0001, Xia Yin 0001 |
SIGCOMM | 11 |
| 2026 | PoD-BNG for Mega-Metropolitan Networks: Reliable and Scalable Broadband Network Gateway EvolutionabstractGiven the wide range of growing online commerce, reliable broadband access has become essential to connecting households and business. In the past twenty years, several solutions have been developed for this purpose, from BNG to vBNG and to BNG-CUPS most recently. However, existing solutions suffer from constrained scalability, inefficient hardware utilization, and an absence of robust fault tolerance. Consequently, these deficiencies have significantly hindered the deployment of carrier-grade access networks in densely populated areas. In response to this, we proposed Pooled Disaggregated Broad-band Gateway (PoD-BNG), an architecture featuring a shared user plane resource pool and an integrated warm standby topology for seamless failover. We validate its performance using a probabilistic model parameterized with real-world operational data. Our analysis shows that a “3+1” standby topology offers the optimal balance of cost and resilience, increasing hardware utilization by 45% and reducing operational and energy costs by 70% compared to legacy BNGs. Furthermore, the architecture is fundamentally fault-resistant, with the probability of a catastrophic outage being less than one in a billion. The success of PoD-BNG is validated by its large-scale deployment since 2020, serving over 46 million households by the end of 2024, establishing it as a superior solution for next-generation access networks. Zaifeng Lin, Xia Gong, Ke Ruan |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Probabilistic Analysis of Overload-Free Property for Critical TrafficabstractNetwork structures are sophisticated and hence vulnerable to errors. Link failures and traffic load fluctuations lead to complexity in network states. Different failure scenarios can result in varying network traffic distribution patterns. Meanwhile, the load on links within the same failure scenario dynamically changes with fluctuations in traffic. Network administrators are particularly concerned about whether links along the paths traversed by critical traffic are overload-free guaranteed when link failures occur. Yet, no attention was ever paid to overload-free property analysis for critical traffic. We propose Offaela, an efficient and accurate probabilistic analysis framework that verifies an overload-free property for critical traffic. We prudently formulate the problem and prove its computational hardness, then storm this fortification by proffering a failure scenario merging algorithm and adopting a randomized approximation method. Evaluations on real networks show that Offaela outperforms the state-of-the-art solution by 4.83 x and can provide availability analysis assistance such as identifying vulnerable failure scenarios. Zhiyun Tang, Ke Ruan, Yingjun Ye, Jilong Wang 0001, Xia Yin 0001, Xingang Shi, Han Zhang 0009 |
IWQoS | 3 |
| 2025 | Achieving High-Speed and Robust Encrypted Traffic Anomaly Detection with Programmable SwitchesabstractAttacks against data centers are becoming more common as a result of the fast expansion of applications. In order to keep pace with the growing amount of data centers connected to their networks, internet service providers must offer comprehensive security services. However, existing network intrusion detection systems (NIDS) are either ineffective or inefficient for the high-speed encrypted network traffic. In this paper, we design and implement Mazu, an inline network intrusion detection system with programmable switches specifically developed to protect data centers connecting to the internet service provider. Mazu proposes a dual-plane feature extraction model to extract extensive traffic features at near line-speed. Mazu also proposes a lightweight one-class classification model that trains the best parameters exclusively on benign traffic to identify the malicious traffic. In addition, Mazu introduces an online update mechanism aimed at dynamically adjusting the detection model in response to environmental changes. Mazu has been in production for two years, during which time it has identified over 10 critical attack events and protect more than 10 million servers for two ISPs. Our production and testbed evaluations demonstrate that Mazu can detect malicious traffic entering the data center sites with approximately 90% accuracy within minutes. Han Zhang 0009, Guyue Liu, Xingang Shi, Dongbiao He, Jilong Wang 0001, Ke Ruan, Xia Yin 0001 |
SIGCOMM | 9 |
| 2025 | MSTFCAN: Multiscale sparse temporal-frequency cross attention network for traffic prediction
Haopeng Ma, Ke Ruan, Zehua Hu |
Comput. Networks | 3 |
| 2025 | Evaluation and Optimization of Backbone Network Reliability Problems Using Decision Diagram MethodsabstractThe structure of the backbone network is complex, and the characteristics of multi-layer architecture and non-independent IP layer links lead to a lack of suitable reliability assessment models and methods to evaluate the reliability of the backbone network. To this end, this paper uses decision diagram methods to model the dependency relationship between IP layer links and optical layer components, relaxing the assumption of independent network link failures. The decision diagram can logically combine features, and while retaining the original connectivity reliability and capacity reliability solution methods, it supplements the dependency relationship and inter-layer relationship of the network with subgraph merging operations. In addition, the issue of capacity reliability or business reliability for multi-terminals and all-terminals has not yet yielded a suitable solution. This paper uses the directed acyclic graph feature of the decision diagram to design a state expansion algorithm, which can be used to solve the multi-terminal capacity availability of multi-state networks. Finally, based on the easy-to-parallel characteristics of the decision diagram, parallel methods are designed to parallelize the entire process of network reliability evaluation, which can alleviate the problem of state space explosion. Yingjun Ye, Ke Ruan, Weihao Yu 0002 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | TSA-Net: a temporal knowledge graph completion method with temporal-structural adaptation
Ruzhong Xie, Ke Ruan, Bosong Huang, Weihao Yu 0002, Jing Xiao 0005, Jin Huang 0007 |
Appl. Intell. | 2 |
| 2023 | Enhanced edge convolution-based spatial-temporal network for network traffic prediction
Zehua Hu, Ke Ruan, Weihao Yu 0002, Siyuan Chen 0005 |
Appl. Intell. | 2 |
| 2023 | Routing hypergraph convolutional recurrent network for network traffic prediction
Weihao Yu 0002, Ke Ruan, Jin Huang 0007 |
Appl. Intell. | 2 |
| 2023 | ODformer: Spatial-temporal transformers for long sequence Origin-Destination matrix forecasting against cross application scenario
Bosong Huang, Ke Ruan, Weihao Yu 0002, Jing Xiao 0005, Ruzhong Xie, Jin Huang 0007 |
Expert Syst. Appl. | 2 |
| 2023 | Achieving High Availability in Inter-DC WAN Traffic EngineeringabstractInter-DataCenter Wide Area Network (Inter-DC WAN) that connects geographically distributed data centers is becoming one of the most critical network infrastructures. Due to limited bandwidth and inevitable link failures, it is highly challenging to guarantee network availability for services, especially those with stringent bandwidth demands, over inter-DC WAN. We present$\mathsf {TEDAT}$, a novel Traffic Engineering (TE) framework for Diverse Availability Targets (DAT), where a Service Level Agreement (SLA) is defined to ensure that each bandwidth demand must be satisfied with a stipulated probability, when subjected to the network capacity and possible failures of the inter-DC WAN.$\mathsf {TEDAT}$has two core components, i.e., traffic scheduling and failure recovery, which are crystalized through different mathematical models and theoretically analyzed. They are also extensively compared against state-of-the-art TE schemes, using a testbed as well as real trace driven simulations across different topologies, traffic matrices and failure scenarios. Our evaluations show that, compared with the optimal admission strategy,$\mathsf {TEDAT}$can speed up the online admission control by$30\times $at the expense of less than 4% false rejections. On the other hand, compared with the latest TE schemes like FFC and TEAVAR,$\mathsf {TEDAT}$can meet the bandwidth availability SLAs for 23%~60% more demands under normal loads, and when network failure causes SLA violations, it can retain 10%~20% more profit under a pricing and refunding model. Han Zhang 0009, Xia Yin 0001, Xingang Shi, Jilong Wang 0001, Yingya Guo, Tian Lan 0001, Ke Ruan, Haijun Geng |
IEEE/ACM Trans. Netw. | 10 |
| 2021 | k-dominant Skyline query algorithm for dynamic datasets
Ke Ruan, Mengyao Yu, Xingjin Zhang, Dun Li |
Frontiers Comput. Sci. | 2 |