VLDB 2026 Research / reviewers in the wild / expert
Chunyang Zheng
dblp:231/0779
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A tolerance analysis framework for microservice-based systems against cascading failuresabstractAbstract Microservice has become a dominant approach for building large-scale Internet applications. The microservice-based system (MS) consists of thousands of services, and its complex interactions make it highly susceptible to unforeseen cascading failures. Cascading failure models are commonly used to analyze the system’s tolerance, while the existing models overlook MS’s features and fail to incorporate real-world events, leading to bias in simulation results. To address these, we proposed a comprehensive tolerance analysis framework of MS named the MSTAF. Specifically, we extracted the real-world failure-triggering scenarios and constructed the Workload-based Cascading Failure Model (WL-CFM) to model the load initialization and redistribution. Then, we implemented the Business Loss Assessment Method (BLAM) to quantify the impact by calculating the workload loss. To validate our MSTAF, we conducted experiments on the WL-CFM and BMAL and performed an analysis on the TrainTicket (TT). The results confirm the MSTAF’s superiority. Specifically, the WL-CFM outperforms baselines, reducing simulation error by 10– 48%. The BMAL demonstrates greater accuracy, with deviations from the ground truth ranging from $$-45$$ - 45 % to + 7%. Overall, the MSTAF offers valuable insights for enhancing tolerance and provides an effective solution for developers and researchers. Chunyang Zheng, Shuaizong Si, Xiaoxi Wang, Jinfa Wang, Shichao Lv, Limin Sun 0001 |
Cybersecur. | 1 |
| 2025 | Microservice Dependency Discovery Based on Spatio-Temporal Network Flow Behavior ModelingabstractThe microservice architectural style offers significant application scalability and development advantages. Composing monolithic systems into loosely coupled, containerized services reduces deployment and development costs while enhancing the flexibility and resilience of the overall system. However, in large-scale internet applications involving multi-party collaboration and global deployment, the formation of complex microservice dependencies increases the risk of cascading failures. It complicates the process of identifying the source of a fault. Identifying such dependencies in uncontrolled conditions with limited observational data represents a significant challenge. This paper proposes Microservice Dependency Discovery based on Spatio-Temporal Network Flow Behaviour Modelling (Cross-MSDD). This method infers microservice dependencies by modeling spatiotemporal interactions of network traffic. The method employs network flow characteristics to mine frequent behavioral patterns, thereby inferring dependency chains without the necessity for additional tracing tools. The method utilizes network flow characteristics to mine frequent behavior patterns, inferring dependency chains without additional tracing tools, minimizing system interruptions, and protecting request content privacy. To verify the effectiveness of the proposed method, a semi-simulated experimental environment was set up using traffic data from typical microservice applications. The results demonstrate that the method attains an accuracy rate exceeding 96.3% in cross-domain dependency identification, markedly surpassing the performance of existing techniques. This facilitates the practical detection of faults and the mitigation of cascading failure risks, thereby ensuring system stability. Jinfa Wang, Chunyang Zheng, Hui Wen 0001, Hong Li 0004, Hongsong Zhu |
CSCWD | 3 |
| 2025 | BSN-OCF: Businesses Sink Node-Oriented Cascading Failure Model in Microservice ApplicationsabstractThousands of service units interact through dependency chains in the Microservice Application (MA) to handle various business functions. As a result, microservice applications feature complex interaction structures. Furthermore, these service units are distributed across multiple devices in the network, making them highly susceptible to cascading failures from single points of failure. Considerable efforts have been made to address and mitigate the significant risks posed by cascading failures. However, as an emerging network architecture, microservices have not yet been fully studied in terms of cascading failure modeling specific to microservice applications. This paper leverages the characteristics of the MA and proposes the Business Sink Node-Oriented Cascading Failure (BSN-OCF) model. The model extracts the network and application layers to describe the MA and models the load and capacity of service units and physical devices. The concept of a business sink node is introduced to address the challenge of directly calculating load. Furthermore, the Assessment Method of Structural Loss (AMSL) is proposed to quantify the vulnerability of the MA. This method overcomes the limitations of previous approaches, which focused solely on the loss of topology. Experiments and results validate the effectiveness of the proposed model. This work provides a self-assessment method for the MA and offers valuable support for optimizing its deployment structure in the future. Chunyang Zheng, Jinfa Wang, Shuaizong Si, Zhiwen Pan, Limin Sun 0001 |
CSCWD | 1 |
| 2025 | Implicit Device Tracking Under the Multimedia Technology WaveabstractThe proliferation of Android multimedia applications highlights the critical role of mobile sensors. Inherent manufacturing defects enable implicit device identification without consent, facilitating covert tracking. This bolsters security through reliable malicious actor tracking, unlike spoof-vulnerable explicit methods. However, prior sensor-based identification suffers from signal noise and device degradation, compromising robustness.In this paper, we propose AMSensorFP, a novel Android implicit device tracking framework. We develop an application to collect device information and multi-sensor data to construct device fingerprints. Subsequently, we build a dataset by performing pairwise difference calculations on the collected fingerprints. And then enhance the dataset with Gaussian noise to improve data diversity and robustness. An autoencoder reduces feature dimensionality, and the processed features are fed into a BiLSTM model with a multi-head attention mechanism, enabling effective fingerprint recognition. Experimental results show that AMSensorFP achieves 99.88% accuracy and 97.34% true positive rate(TPR), significantly outperforming existing methods. Ablation analysis further highlights the contributions of each module and feature in the framework. AMSensorFP delivers a reliable solution for device tracking and security enhancement. Xiaoxi Wang, Kerui Huang, Chunyang Zheng, Jinhe Ren, Qixu Liu |
SMC | 4 |
| 2025 | XFP-recognizer: detecting cross-file browser fingerprintingabstractAbstract In recent years, the evolving browser fingerprinting technology has posed significant challenges and constant demands on detection methods. Research related to malicious code shows that cross-file techniques, which disperse code into multiple files, can resist current detection methods. To address this challenge, we introduce cross-file tracking technology into browser fingerprinting, constructing cross-file browser fingerprinting (XFP). The dispersion of files and features in XFP effectively circumvents detection methods that primarily focus on single-file tracking. In this paper, we propose XFP-Recognizer, a Random Forest-based detection method for identifying XFP behaviors. XFP-Recognizer aggregates code files and dynamic APIs by constructing function call relationship graphs (FCRgraphs). It extracts dynamic and static features to train random forest models for detecting and classifying the aggregated files, and then backtracks based on FCRgraphs to mark original scripts. To validate our method, we implement a code-splitting algorithm and constructed a cross-file tracking dataset to address the lack of XFP in real-world scenarios. We combine this dataset with the dataset of Alexa Top-10K websites in different proportions to verify the effectiveness of XFP-Recognizer. The results show that XFP-Recognizer achieved an Accuracy of 92.25%, a Precision of 97.01% and an AUC of 0.9152 in recognizing browser fingerprinting, demonstrating superior performance in both single-file and cross-file tracking. XFP-Recognizer complements existing detection methods, and the constructed split dataset also serves as a foundational resource for future research. Xiaoxi Wang, Zhenxu Liu, Chunyang Zheng, Xinyu Liu 0019, Wei Liu 0243, Qixu Liu |
Cybersecur. | 3 |
| 2024 | SDM-GAT: StylisticFP Detection Method Based on Graph Attention Network
Xiaoxi Wang, Chunyang Zheng, Yaqin Cao, Qixu Liu |
ADMA (3) | 3 |
| 2024 | MOMR: A Threat in Web Application Due to the Malicious Orchestration of Microservice RequestsabstractMicroservice is an increasingly favored architecture for constructing modern web applications and the fast-paced business requirements facilitate the transmission of microservice traffic among distributed servers. In contrast to traditional architectures, microservice architecture has tight inherent dependencies between microservice units when supporting web application business. Attackers can excavate these dependencies to maliciously orchestrate microservice requests, scheduling microservice traffic to converge on the target link. This attack disrupts link and application quality of service, bringing new potential threats to web applications and cyberspace security. This work analyzes and evaluates the threat due to the malicious orchestration of microservice requests (MOMR) with the initial intention of promoting microservice application security and other information system security based on the microservice architecture. A Cross-Layer Coupling (CLC) model is proposed that aims to describe microservice traffic transmission, which efficiently supports the threat evaluation. A Path-aware Microservice Traffic Scheduling (PMTS) attack method is imposed on the CLC model so that it can construct the MOMR threat accurately. To demonstrate the effectiveness of the proposed method in evaluating the MOMR threat, a comprehensive analysis is performed on a typical microservice application and a semi- physical simulation platform. The result shows the threat causes performance degradation and impacts the network, such as a packet loss rate of up to 79% and an RTT increase of 600% of the target link. Chunyang Zheng, Jinfa Wang, Shuaizong Si, Zhi Li 0018, Limin Sun 0001 |
ICC | 1 |
| 2023 | ChainDet: A Traffic-Based Detection Method of Microservice ChainsabstractWith the increasing prevalence of contemporary web applications built upon microservice architecture, intricate dependencies emerge among numerous microservices within specific network areas. These microservice dependencies contain critical information that can significantly aid network managers in optimizing network performance and enhancing application security. This paper introduces ChainDet, a traffic-based method specifically designed for detecting microservice dependencies. Notably, ChainDet is non-intrusive, and capable of handling mixed and encrypted traffic, making it suitable for network managers’ requirements. By leveraging the TSLC and TPD algorithms, ChainDet effectively detects both Inter-microservice Dependencies and Microservice Chains. Experimental results confirm the high accuracy and completeness rate of ChainDet in identifying microservice dependencies in both open-world and isolated environments. This method offers valuable insights for network managers seeking to accurately detect and model microservice dependencies. Chunyang Zheng, Jinfa Wang, Shuaizong Si |
IPCCC | 1 |
| 2022 | PLIN: A Persistent Learned Index for Non-Volatile Memory with High Performance and Instant RecoveryabstractNon-Volatile Memory (NVM) has emerged as an alternative to next-generation main memories. Although many tree indices have been proposed for NVM, they generally use B+-tree-like structures. To further improve the performance of NVM-aware indices, we consider integrating learned indexes into NVM. The challenges of such an integration are two fold: (1) existing NVM indices rely on small nodes to accelerate insertions with crash consistency, but learned indices use huge nodes to obtain a flat structure. (2) the node structure of learned indices is not NVM friendly, meaning that accessing a learned node will cause multiple NVM block misses. Thus, in this paper, we propose a new persistent learned index called PLIN. The novelty of PLIN lies in four aspects: an NVM-aware data placement strategy, locally unordered and globally ordered leaf nodes, a model copy mechanism, and a hierarchical insertion strategy. In addition, PLIN is proposed for the NVM-only architecture, which can support instant recovery. We also present optimistic concurrency control and fine-grained locking mechanisms to make PLIN scalable to concurrent requests. We conduct experiments on real persistent memory with various workloads and compare PLIN with APEX, PACtree, ROART, TLBtree, and Fast&Fair. The results show that PLIN achieves 2.08x higher insertion performance and 4.42x higher query performance than its competitors on average. Meanwhile, PLIN only needs ~30 μs to recover from a system crash. Zhou Zhang 0006, Zhaole Chu, Peiquan Jin, Yongping Luo, Xike Xie, Shouhong Wan, Xufei Wu, Chunyang Zheng, Guoan Wu, Andy Rudoff |
Proc. VLDB Endow. | 10 |