Weiting Zhang

dblp:247/9527 · DBLP profile ↗
← Back
57ranked-venue papers
7as first author
55since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 48 · 6 first-author · 47 since 2021Systems, architecture and hardware · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Enabling QoS-Aware Multi-Stage Task Allocation in FANETs: A Hierarchical Learning Approach
Jiangyu Lan, Xiaoting Ma, Weiting Zhang, Xindi Hou
ICC4
2026 CIFDM: A Fault Diagnosis Mechanism for Access Networks Based on Cause Inference in Heterogeneous Emergency Networks
abstract
In heterogeneous wireless emergency networks, network fault diagnosis plays a critical role in ensuring reliable and secure communication. To improve network transmission quality, the complexity of network equipment—both in hardware and software design—has increased, which inevitably gives rise to equipment failures with complex root causes, significantly elevating the difficulty of fault diagnosis. Current fault diagnosis algorithms are inadequate for addressing the challenges in fault diagnosis of complex emergency access networks, primarily due to their high diagnostic costs and low accuracy. In this study, we first propose a diagnosis framework and a Deterministic Fault Propagation (DFP) model, and a Hierarchical Fault Diagnosis Framework. Second, we develop three algorithms to construct a Fault Cause Relationship Graph, which supports identifying the logical relationships among various fault causes associated with a specific fault. Third, we propose a Fault Diagnosis algorithm based on Relational Graph Inference (FDRGI). Finally, we conduct extensive experiments in real-world wireless access networks. The experimental results demonstrate that our algorithm satisfies the requirements for root cause diagnosis of access failures in emergency networks, and outperforms other comparative algorithms in terms of diagnostic cost and accuracy: it reduces the average diagnostic cost by 13.71%-69.88% and improves the average diagnostic accuracy by 39.06%-1.98-fold.
Wenxiao Wang 0008, Wenxuan Qiao, Weiting Zhang, Chengxiao Yu, Hongke Zhang
IEEE Internet Things J.5
2026 PBox: Cross-Switch Pipeline Orchestration for Accelerated Service Function Chaining in High-Performance Cloud Networks
abstract
The rise of latency-sensitive and bandwidth-intensive services has driven hardware accelerator adoption in cloud networks. Programmable data plane (PDP) switches achieve significant performance gains in high-performance cloud computing but face fixed pipeline constraints that limit flexibility in multi-tenant service function chaining (SFC) with dynamic function compositions. Existing approaches either exhaust resources through redundant embeddings or degrade performance via packet recirculation. This paper presents PBox, a framework enabling flexible SFC orchestration across multiple PDP switches by optimizing network function (NF) execution orders to minimize pipeline traversals-the dominant end-to-end processing delay source. This requires co-designing NF embedding with routing strategies. PBox contributes: (i) an optimized Network Service Header design supporting one-pass matching of multiple NFs through per-bit activation, reducing packet matching overhead by 45-60%; (ii) a nested optimization formulation capturing interdependence between long-term pipeline orchestration and short-term flow routing decisions; and (iii) a sampling-based genetic algorithm with statistical robustness guarantees, achieving fast switch configuration while adapting to dynamic service patterns. Evaluations on BMv2 and Intel Tofino demonstrate 33-79% completion time reduction, 46% capacity increase, and 78% line-rate efficiency, validating cloud-scale deployment potential.
Deyun Gao, Weiting Zhang, Ruichen Zhang 0001, Dusit Niyato, Hongke Zhang
IEEE Trans. Cloud Comput.3
2026 SeFUL: A Selective Federated Unlearning Framework for Client Data Heterogeneity in Intelligent Wireless Networks
abstract
As sixth-generation (6 G) networks evolve towards AI-native architectures, Federated Learning (FL) is becoming a cornerstone for enabling intelligent services by leveraging distributed data from diverse sources such as Integrated Sensing and Communication (ISAC) devices and edge clients. However, a critical challenge lies in efficiently handling data removal requests, mandated by regulations like the “right to be forgotten”. This problem is significantly exacerbated by the extreme data heterogeneity ( non-IID) inherent across diverse 6 G devices and the communication constraints of wireless networks. To address these challenges, this paper proposes SeFUL, a novel two-stage federated unlearning framework tailored for the security and privacy demands of 6 G systems. SeFUL first proactively mitigates data heterogeneity by partitioning clients into clusters based on their data distribution similarity. Subsequently, a lightweight, information-theoretic unlearning strategy is deployed. This method surgically erases information by optimizing a composite loss function which, in the latent space, pushes the feature representations of forgotten data away from their original class cluster and towards samples from other classes, while reinforcing knowledge from the retain set. Comprehensive experiments on benchmark datasets demonstrate that SeFUL achieves unlearning performance on par with the gold standard of complete model retraining. It successfully reduces forget-set accuracy to nearly random guess levels while preserving high retain-set accuracy, significantly outperforming existing state-of-the-art methods. Furthermore, Membership Inference Attacks (MIAs) confirm that SeFUL effectively reduces privacy risks to a level statistically indistinguishable from a fully retrained model, validating its efficacy as a robust privacy-preserving mechanism.
Yujun Cheng, Weiting Zhang, Tao Zheng 0003, Enfang Cui, Haijun Zhang 0001
IEEE Trans. Mob. Comput.2
2026 HierTFL: Hierarchical Scheduling for Industrial TSN-Enhanced Federated Learning System
abstract
The adoption of federated learning (FL) in industrial IoT (IIoT) facilitates the deployment of field-level industrial intelligence by multi-node collaborative and distributed learning. Numerous studies on FL primarily concentrate on enhancing model accuracy under non-independent and identically distributed data. Nevertheless, this focus is inadequate for time-critical industrial systems, as these systems necessitate real-time processing during the FL model training phase and any strategy that prioritizes incremental accuracy gains at the expense of latency risks violating real-time deadlines. However, the system heterogeneity of computing and communication capabilities will impose a formidable bottleneck to the overall time consumed for FL model training. In this paper, we present a FL-enabled Time-Sensitive IIoT (FETI) framework that integrates FL with Time-Sensitive Networking (TSN) to support the deterministic forwarding of FL flows in industry. Aiming to speed up FL convergence within a targeted accuracy gap, we formulate a heterogeneity-aware FL-TSN joint optimization problem, which is theoretically transformed into a stochastic mixed- integer programming problem solved at each FL round. To address this problem, we propose a hierarchical reinforcement learning-based scheduling scheme, called HierTFL, with two interacting layers of policies. With the assistance of a proposed spatial-temporal state encoder, the high-level policy dynamically selects client participants based on data quality and resource availability in each FL round, while the low-level policy optimizes TSN flow scheduling of each selected client using non-cumulative Bellman updates. Experimental results under industrial monitoring datasets have shown the effectivity of HierTFL in achieving a balanced trade-off between model precision and convergence time compared to existing benchmarks.
Songtao Guo, Fuqiang Gu, Pengzhan Zhou, Weiting Zhang
IEEE Trans. Mob. Comput.6
2026 Joint Optimization of Communication-Aware Group Microservice Deployment and Multi-Chain Request Routing
Hongchao Wang 0001, Weiting Zhang, Dong Yang 0001, Laurence T. Yang
IEEE Trans. Serv. Comput.5
2025 X-CFL: Enabling Cross-Layer Clustered Federated Learning in UAV Swarms
abstract
Federated learning (FL) in Unmanned Aerial Vehicle (UAV) swarms faces the challenges of data heterogeneity and resource constraints, limiting its large-scale deployment. Existing solutions attempt to leverage Clustered Federated Learning (CFL) to mitigate data heterogeneity by grouping clients based on data similarity. However, these data-driven approaches concentrate on application-layer features without comprehensive consideration of status in other layers, leading to unstable clustering and suboptimal routing. In this paper, we propose X-CFL, a novel cross-layer framework that co-optimizes clustering and routing by integrating application-layer data features with cross-layer node status. Specifically, X-CFL introduces a joint clustering mechanism that groups UAVs based on data similarity to minimize model discrepancy, while concurrently leveraging real-time physical conditions (e.g., location and energy) to enhance cluster robustness. Subsequently, a two-stage routing protocol is employed to establish reliable intra-cluster communication and enable efficient global aggregation among cluster heads. Extensive simulation results demonstrate that X-CFL significantly improves training throughput, network lifetime, and model training performance compared to state-of-the-art baselines.
Jiangyu Lan, Xiaoting Ma, Weiting Zhang, Xindi Hou
GLOBECOM4
2025 DetRM: Deterministic Resource Management for Delay-Sensitive Flows in Open RAN
Hongchao Wang 0001, Weiting Zhang, Dong Yang 0001
GLOBECOM4
2025 AI-Native and Data-Driven Resource Scheduling for Inference Services in Computing-Aware Networks
abstract
Computing-aware networks (CAN) can provide ubiquitous AI inference services for intelligent applications. However, due to the huge differences in the demand for inference services of intelligent applications and the continuous innovation of computing devices, traditional protocol-based scheduling methods make it difficult to schedule complex heterogeneous computing resources. In this paper, we propose a CAN resource scheduling method, named SMAD, which can adapt to external environmental changes without human modification of the protocol mechanism. Aiming at the scheduling problem of complex heterogeneous computing resources and concurrent random diverse inference tasks, a constrained multi-objective optimization problem of scheduling service quantity, accuracy, and delay is formulated. Through the general Markov Decision Process (MDP) transformation from the model, the Deep Reinforcement Learning (DRL)-based AI-native scheduling algorithm framework can further solve the optimization problem. Meanwhile, the AI-native framework aggregates diverse device states into a data tensor, integrates the DRL algorithm in a data-driven manner to generate a dynamic action tensor, and reversely drives full-stack resource scheduling for global closed-loop optimization in CAN, aligning with inference service demands. Extensive simulation results show that the proposed SMAD has good convergence performance. Compared with the traditional DRL algorithm, it significantly increases the number of concurrent schedulable tasks and reduces the inference service delay.
Weikang Tian, Hongchao Wang 0001, Weiting Zhang, Dong Yang 0001
GLOBECOM5
2025 Srvcast: Facilitating Host-Transparent and Stateful Anycast for Computing-Aware Networks
abstract
6G-driven compute-intensive applications require the collaboration of communication and computing to achieve optimal performance. Such collaboration drives integrated sensing, communication, and computing to support service requirement sensing and on-demand computing task steering within the network. To this end, the Computing-Aware Network proposes to incorporate computing information into the network layer address called service identifier (SID), to implement serviceoriented SID anycast. This integration aims to naturally support dynamic task steering using the anycast mechanism. However, SID represents an abstract service rather than a specific host, making SID anycast incompatible with the TCP communication patterns used by existing socket-based applications. To address this challenge, this paper introduces Srvcast, a host-transparent and stateful anycast solution. Srvcast consists of two stages: WAN routing and edge network forwarding. In WAN routing, it employs a novel service-oriented routing mechanism to ensure connection affinity for anycast. In the edge network forwarding, Srvcast presents ServiceNAT, a P4-based address translation mechanism that enhances SID compatibility with socket-based applications. To implement Srecast, a prototype system is built in a practical WAN environment. The results demonstrate that Srvcast outperforms existing solutions in terms of system complexity and socket connection establishment time. Srvcast can maintain the flexibility of SID anycast while ensuring compatibility with TCP communication patterns at a lower cost.
Heyao Zhang, Bo Lei 0002, Weiting Zhang, Hongke Zhang
ICC4
2025 Enhancing Energy Efficiency in Multipath Routing for Industrial Internet of Things
abstract
Industrial Internet of Things (IIoT) applications, such as industrial process control, demand ultra-high reliability and bounded delay. The Reliable and Available Wireless (RAW) initiative within the IETF DetNet working group addresses these needs by applying IEEE 802.15.4 time-slotted channel hopping (TSCH) technology and leveraging techniques like Packet Replication, Elimination, and Ordering Functions (PREOF) to ensure deterministic performance for IIoT. However, while PREOF improves reliability, its redundant transmission mechanism inevitably increases energy consumption, conflicting with the energy constraints of TSCH nodes. The existing multipath routing approaches struggle to address this challenge, failing to jointly consider both energy efficiency and deterministic performance. Additionally, these approaches often overlook the delay variation caused by multipath transmissions of different lengths—a key factor that can undermine deterministic performance by increasing buffering requirements and affecting the predictability of data flows. In this paper, we investigate a multipath optimization problem aiming at improving energy efficiency and minimizing delay variation while meeting the requirements of bounded reliability and delay for deterministic flows. Considering the above multipath routing optimization problem, which aims to satisfy multiple objectives under multiple constraints, is typically NP-hard, solving these challenges with traditional methods is highly complex. Thus, we further propose a Energy-Efficient Multi-path Routing (EEMR) algorithm that utilizes deep reinforcement learning (DRL) to optimize the multipath selection, effectively enhancing energy efficiency for deterministism. EEMR can be extended to solve optimization problems in holistic-deterministic multi-domain scenarios, such as smart factories integrating 5G and DetNet. We compare the performance of our proposed method with several baseline methods. Empirical evaluations show that EEMR significantly reduces energy comsumption and delay variation compared to baseline methods under various environment settings.
Weiting Zhang, Hongchao Wang 0001, Dong Yang 0001, Hongke Zhang
IEEE Internet Things J.2
2025 OpenL3: Embedding Diverse Network Services into MANETs Using Multidimensional Identifier
abstract
Practical applications in mobile ad-hoc networks (MANETs) require the support of diverse network services, e.g., host-centric, content-centric, and location-centric routing and forwarding services. However, existing solutions are typically designed over a single network service rather than integrated ones. To embed diverse network services into MANETs, the major challenge is enabling interoperability among various network-layer (L3) protocols without suffering complexity and scalability issues. In this article, we propose OpenL3, a programmable L3 approach to support the coexistence of diverse network services in MANETs. Specifically, OpenL3 first abstracts key attributes from network entities, such as content, locations, or groups of devices. These attributes are embedded into a network address, named multidimensional identifier (MID), to control the routing and forwarding processes. Then, a distributed MID mapping system is established to facilitate efficient MID registration and query. Based on the MID, a programmable routing and forwarding scheme is proposed, which incorporates a lightweight packet processing design using a P4 programmable data plane to enable interoperability among various L3 protocols. A cluster of SDN-based control plane devices collaboratively distribute flow rules to manage data plane behavior. Furthermore, a prototype system is built to implement and evaluate the proposed solutions. Experimental results show that OpenL3 outperforms the existing solutions in terms of end-to-end latency and network throughput while being deployable in MANETs without modifications to network protocols or sockets.
Jiangyu Lan, Weiting Zhang, Xindi Hou, Minghui Xi, Bo Lei 0002, Hongke Zhang, Xuemin Shen
IEEE Internet Things J.3
2025 A Collaborative Programmable LFA Defense Using Temporal Graph Learning in AIoT
abstract
In the current era of rapid advancements in Artificial Intelligence of Things (AIoT), with the increase in cloud data center operations and the limited security computing capabilities of AIoT terminal devices, link flooding attack (LFA) has emerged as a complex and stealthy new threat. However, the existing defense methods based on programmable networks usually have issues of slow offline inference and delayed defense activation. To address these issues, we propose a collaborative programmable defense framework (CPDTG) to predict, detect, and mitigate LFA. First, an early attack intention prediction model based on temporal graph learning (TGL) is proposed to accurately locate attacks and promptly activate defenses to save resource consumption during idle time. Second, a switch-native clustering algorithm independent of the global perspective is introduced for line-speed detection of LFA. The unsupervised algorithm does not rely on labeled datasets for training, which enhances its robustness against differentiated attack scenarios. Third, we propose a distributed defense mechanism that achieves the pushback deployment of adaptive rate-limiting strategies. Compressing the potential attack vector space effectively increases the difficulty of launching rolling attacks. Extensive experimental validation demonstrates the effectiveness of the proposed CPDTG in predicting and defending against LFA.
Ying Liu 0018, Yu Xia 0031, Weiting Zhang, Wei Quan 0001, Jiawen Kang 0001, Hongke Zhang
IEEE Internet Things J.4
2025 All-in-One: Unified Computing and Networking Resource Scheduling for Next-Generation Converging Networks
abstract
The emerging intelligent services, spurred by the rise of the intelligent Internet, are placing multidimensional requirements on the network to collaboratively guarantee computing and networking resources. In this article, we propose a unified end-to-end intelligent resource scheduling method for converging networks [e.g., Internet of Things (IoT)], which can always globally abstract the available resources from different networks with a unified model description, and jointly planning the resources from end-to-end by deep reinforcement learning (DRL) algorithms supporting both discrete and continuous variable decisions. The method proposes a three-layer architecture, including service layer, network layer, and adaption layer, which aims at optimizing the flow transmission performance. Through the general Markov decision process (MDP) transformation from the model, the DRL-assisted algorithm can further solve the optimization problem. We categorize heterogeneous network resource scheduling into horizontal and vertical scenarios, applying the proposed architecture to both. Compared with the existing diverse learning (DiLearn) and naive (DiNaive) approaches, the proposed approach is not only time-saving but also can schedule 28.4% and$8\times $more flows in horizontal scheduling scenarios, and improve 54.2% and$3.5\times $flows in vertical scheduling scenarios, respectively.
Weikang Tian, Zongrong Cheng, Hongchao Wang 0001, Weiting Zhang, Jiawen Kang 0001, Dong Yang 0001
IEEE Internet Things J.6
2025 Intelligent and Reliable Routing for Audio/Video Mixed Traffic in Overlay Networks
abstract
Traditional route forwarding generates obvious performance problems and it cannot fulfill the increasing diversity in the number of user accesses and Quality of Service (QoS). It is necessary to investigating an intelligent and reliable routing for online audio/video mixed traffic with high-real time to meet different QoS requirements. In this article, we design a routing scheme based on deep reinforcement learning (DRL) and graph neural networks (GNNs), which could be easily implemented as an application on a controller, named RtDG. Specifically, a network topology is first extracted using GNN to generate high-dimensional feature representations. To obtain QoS utility values comprehensively, we set four parameters, namely, bandwidth, delay, packet loss rate, and delay jitter, and construct weighted formulas using the parameters determined by Bayesian optimization. We use proximal policy optimization (PPO) to make output decisions while adding a KL scatter penalty to the loss function. And then, the controller assigns it to switches via traffic table based on the calculated QoS values. Furthermore, we deploy an overlay network using Mininet and ONOS, enabling optimal pathfinding without changing the existing network architecture. Meanwhile, tests are conducted under background traffic of online audio/video. Extensive simulation results demonstrate that the RtDG can significantly reduce average delay and packet loss rate by 52.21% and 57.83%, compared to traditional routing strategies. Especially under high traffic conditions, it is able to consider the uncertainty during path selection and achieve excellent routing performance.
Haoying Wang, Hongchao Wang 0001, Weiting Zhang, Dong Yang 0001
IEEE Internet Things J.4
2025 Learning-Based Proactive and Adaptive Link Flooding Attack Mitigation in AIoT
abstract
Artificial intelligence of things (AIoT) is a new networking paradigm incorporating AI and IoT, empowering multiple industries. Due to the high value of AI infrastructure in AIoT, its security issues are becoming increasingly prominent. A new type of covert DDoS attack, link flooding attack (LFA), is emerging as a vital threat. It congests critical links to AI infrastructure by manipulating multiple heterogeneous terminals to send legitimate low-speed traffic to cut off the connection of AI infrastructure while hiding itself. To quickly mitigate the LFA-induced congestion, this paper presents a learning-based proactive and adaptive LFA mitigation mechanism in AIoT. Specifically, a link suspicious level evaluation scheme based on graph autoencoder is first proposed. The potential risk links are identified by mining the link traffic features in the attack preparation and synthesizing two types of reconstruction errors, which is helpful for early to support rapid response to subsequent attacks. Second, a local traffic engineering model is presented based on maximizing the benefit of defenders. To solve the model to obtain the mitigation strategy, a solution based on deep reinforcement learning is designed to make real-time optimal local traffic path assignment decisions. Simulation results demonstrate that the proposed scheme can quickly perceive LFA and effectively resist the link congestion caused by LFA.
Yu Xia 0031, Weiting Zhang, Ying Liu 0018, Jiawen Kang 0001, Hongke Zhang
IEEE Internet Things J.2
2025 Computing and Network Load Balancing for Decentralized Deep Federated Learning in Industrial Cyber-Physical Systems: A Multi-Task Approach
abstract
Given the delay-critical nature of AI-driven industrial automation applications, industrial cyber-physical systems are evolving from centralized cloud automation to decentralized cloud-fog automation to reduce model inference delay. However, traditional centralized deep federated learning is not wellsuited for this evolution, primarily due to scalability and delay issues caused by centralized parameter synchronization. Thus, we introduce a decentralized deep federated learning (DDFL) architecture. While DDFL resolves scalability and delay concerns, decentralized parameter synchronization amplifies the delay imbalance impact caused by uneven computing and network loads. Additionally, traditional single-task load balancing approaches with fixed load balancing weights face challenges posed by diverse delay requirements across different model training tasks. To overcome these challenges, we formulate a hybrid multi-task Markov decision process with the objective of minimizing flexibly weighted computing and network load. We further propose a hybrid multi-task deep reinforcement learning (MTDRL) scheme based on the importance-weighted actor-learner architecture, which trains a hybrid-MTDRL decision model to select fog servers and paths with balanced loads suited to diverse delay requirements. Realistic trace-based simulation and testbed evaluation results demonstrate that hybrid-MTDRL outperforms benchmarks in load balancing and reducing training delay.
Xuening Shang, Deyun Gao, Dong Yang 0001, Weiting Zhang, Chuan Heng Foh, Hongke Zhang
IEEE J. Sel. Areas Commun.5
2025 Practical Iterative Quantum Consensus Protocol With Sharding Construction
abstract
With the development of quantum blockchain, the quantum consensus protocols have garnered increasing attention, which play a crucial role in driving the implementation of quantum blockchains. However, existing protocols, derived from the classical consensus algorithms, face practical application challenges due to current quantum technology limitations. The first challenge is the bottleneck in generating large-scale entangled quantum states. The second challenge arises from the generation of malicious quantum states. The final challenge involves privacy concerns. To address these challenges, we propose a practical iterative QUantum consensus protocol with sharding construction, namely, Q-Union. In fact, Q-Union employs an iterative consensus algorithm where participating nodes are divided into multiple smaller shards, with the consensus process occurring within the current shard, and new shards are involved only if consensus is not achieved. Leveraging Greenberger-Horne- Zeilinge states and Aharonov states, Q-Union harnesses the advantages of quantum mechanics to achieve anonymous consensus, protecting the private information of participating nodes. Additionally, by integrating state verification, Q-Union ensures the correctness of the consensus procedure in the presence of malicious nodes generating adversarial quantum states. Finally, it is proven that Q-Union can also defend against Byzantine attacks from adversarial nodes, maintaining the same security level as traditional non-sharded consensus protocols. Specifically, it consistently outputs the correct consensus when the fraction of adversaries among participating nodes is less than 1/2 with synchronous communication. Both the theoretical analysis and performance illustration demonstrate the superior performance of the proposed Q-Union compared to state-of-the-art protocols.
Chenhao Ying 0001, Weiting Zhang, Xikun Jiang, Gang Wang 0012, Haiming Jin, Jie Li 0002, Yuan Luo 0003, Dacheng Tao
IEEE J. Sel. Areas Commun.3
2025 Intelligent End-to-End Deterministic Scheduling Across Converged Networks
abstract
Deterministic network services play a vital role for supporting emerging real-time applications with bounded low latency, jitter, and high reliability. The deterministic guarantee is penetrated into various types of networks, such as 5G, WiFi, satellite, and edge computing networks. From the user’s perspective, the real-time applications require end-to-end deterministic guarantee across the converged network. In this paper, we investigate the end-to-end deterministic guarantee problem across the whole converged network, aiming to provide a scalable method for different kinds of converged networks to meet the bounded end-to-end latency, jitter, and high reliability demands of each flow, while improving the network scheduling QoS. Particularly, we set up the global end-to-end control plane to abstract the deterministic-related resources from converged network, and model the deterministic flow transmission by using the abstracted resources. With the resource abstraction, our model can work well for different underlying technologies. Given large amounts of abstracted resources in our model, it is difficult for traditional algorithms to fully utilize the resources. Thus, we propose a deep reinforcement learning based end-to-end deterministic-related resource scheduling (E2eDRS) algorithm to schedule the network resources from end to end. By setting the action groups, the E2eDRS can support varying network dimensions both in horizontal and vertical end-to-end deterministic-related network architectures. Experimental results show that E2eDRS can averagely increase 1.33x and 6.01x schedulable flow number for horizontal scheduling compared with MultiDRS and MultiNaive algorithms, respectively. The E2eDRS can also optimize 2.65x and 3.87x server load balance than MultiDRS and MultiNaive algorithms, respectively. For vertical scheduling, the E2eDRS can still perform better on schedulable flow number and server load balance.
Zongrong Cheng, Weiting Zhang, Dong Yang 0001, Chuan Huang 0001, Hongke Zhang, Xuemin Shen
IEEE Trans. Mob. Comput.2
2025 SnapCFL: A Pre-Clustering-Based Clustered Federated Learning Framework for Data and System Heterogeneities
abstract
Federated Learning (FL) has emerged as a promising framework to address data privacy concerns associated with mobile devices, in contrast to conventional Machine Learning (ML). However, traditional FL encounters significant challenges due to the heterogeneities among different clients. Clustered Federated Learning (CFL) has demonstrated effectiveness in mitigating the data heterogeneity challenge, which significantly limits a broader application of FL. Nevertheless, existing CFL approaches often tightly couple the clustering process with the main FL process, affecting the flexibility and performance of CFL. In this paper, we propose a pre-clustering-based CFL approach, named SnapCFL, which decouples the CFL process into pre-clustering and main FL stages, considering both the impact of heterogeneity on CFL accuracy and the framework's flexibility. The pre-clustering stage models the measurement of data similarity as a two-sample hypothesis testing problem to more accurately group clients and alleviate data heterogeneity. In the main FL stage, a constraint-based client selection method is employed to address the system heterogeneity problem. We conduct extensive experiments using popular datasets with various heterogeneity settings. The results demonstrate that SnapCFL achieves excellent performance in terms of accuracy and efficiency. Compared to five other state-of-the-art approaches, SnapCFL can improve model accuracy by 0.7%$\sim$36.4%, and achieve the same level of accuracy with at least 0.08× the convergence time.
Yujun Cheng, Weiting Zhang, Jiawen Kang 0001, Shengjin Wang, Dusit Niyato
IEEE Trans. Mob. Comput.2
2025 Feature-Based Machine Unlearning for Vertical Federated Learning in IoT Networks
abstract
In the era of the Internet of Things (IoT), managing the deluge of data generated by distributed devices presents unique challenges, particularly concerning privacy and the efficient use of computational resources. Vertical Federated Learning (VFL) offers a promising avenue for collaborative machine learning without centralizing data, thereby addressing privacy concerns inherent in traditional approaches. However, as data privacy laws and personal data deletion requests become more prevalent, the necessity for effective machine unlearning strategies within VFL frameworks grows increasingly important. To this end, this paper introduces a novel approach to feature-based machine unlearning tailored specifically for VFL systems in IoT networks. Our methodology enables the selective removal of data influence from trained models without the need for full retraining, thus preserving model utility while ensuring compliance with privacy requirements. By integrating a combination of feature relevance measuring techniques and efficient communication protocols, our solution minimizes the data footprint on network nodes, reduces bandwidth consumption, and maintains the integrity and performance of the learning models. To the best of our knowledge, our proposed framework represents the first practical approach to enable machine unlearning within vertical federated learning environments. We demonstrate the effectiveness of our approach through rigorous evaluation using several IoT datasets, highlighting significant improvements in unlearning efficiency and model robustness compared to existing techniques. Our work not only furthers the development of sustainable and compliant machine learning models in IoT but also sets a foundational framework for future research in secure and efficient data management within federated environments.
Zijie Pan, Zuobin Ying, Chuan Zhang 0003, Weiting Zhang, Wanlei Zhou 0001, Liehuang Zhu
IEEE Trans. Mob. Comput.5
2025 Deep Reinforcement Learning-Based Joint Caching and Routing in AI-Driven Networks
abstract
To reduce redundant traffic transmission in both wired and wireless networks, optimal content placement problem naturally occurring in many applications is studied. In this paper, considering the limited cache capacity, unknown popularity distribution and non-stationary user demands, we address this problem by jointly optimizing content caching and routing with the objective of minimizing transmission cost. By optimizing the routing with theroute-to-least cost-cachepolicy, the content caching process is modeled as a Markov decision process (MDP), aiming to maximize caching reward. However, the optimization problem consists of multiple nodes selecting caching contents, which leads to the combinatorial increase of the number of action dimensions with the number of possible actions. To handle this curse of dimensionality, we propose an intelligent caching algorithm by embedding action branching architecture into a dueling double deep Q-network (D3QN) to optimize caching decisions, and thus the agent at the controller can adaptively learn and track the underlying dynamics. Considering the independence of each branch, a marginal gain-based replacement rule is proposed to satisfy cache capacity constraint. Our simulation results show that compared with the prior art, the caching reward and hit rate of the proposed algorithm are increased by 35.3% and 33.6% respectively on average.
Deyun Gao, Weiting Zhang, Dong Yang 0001, Dusit Niyato, Hongke Zhang, Victor C. M. Leung
IEEE Trans. Mob. Comput.3
2025 BIT-FL: Blockchain-Enabled Incentivized and Secure Federated Learning Framework
abstract
Harnessing the benefits of blockchain, such as decentralization, immutability, and transparency, to bolster the credibility and security attributes of federated learning (FL) has garnered increasing attention. However, blockchain-enabled FL (BFL) still faces several challenges. The primary and most significant issue arises from its essential but slow validation procedure, which selects high-quality local models by recruiting distributed validators. The second issue stems from its incentive mechanism under the transparent nature of blockchain, increasing the risk of privacy breaches regarding workers’ cost information. The final challenge involves data eavesdropping from shared local models. To address these significant obstacles, this paper proposes a Blockchain-enabled Incentivized and Secure Federated Learning (BIT-FL) framework. BIT-FL leverages a novel loop-based sharded consensus algorithm to accelerate the validation procedure, ensuring the same security as non-sharded consensus protocols. It consistently outputs the correct local model selection when the fraction of adversaries among validators is less than$1/2$with synchronous communication. Furthermore, BIT-FL integrates a randomized incentive procedure, attracting more participants while guaranteeing the privacy of their cost information through meticulous worker selection probability design. Finally, by adding artificial Gaussian noise to local models, it ensures the privacy of trainers’ local models. With the careful design of Gaussian noise, the excess empirical risk of BIT-FL is upper-bounded by$\mathcal {O}(\frac{\ln n_{\min}}{ n_{\min}^{3/2}}+\frac{\ln n}{n})$, where$n$represents the size of the union dataset, and$n_{{\min}}$represents the size of the smallest dataset. Our extensive experiments demonstrate that BIT-FL exhibits efficiency, robustness, and high accuracy for both classification and regression tasks.
Chenhao Ying 0001, Fuyuan Xia, David S. L. Wei, Xinchun Yu, Yibin Xu, Weiting Zhang, Xikun Jiang, Haiming Jin, Yuan Luo 0003, Tao Zhang 0005, Dacheng Tao
IEEE Trans. Mob. Comput.6
2025 Toward Deterministic Satellite-Terrestrial Integrated Networks via Resource Adaptation and Differentiated Scheduling
abstract
Satellite-terrestrial integrated network (STIN) is a full-scale communication paradigm, which can support joint information processing and seamless service provision by leveraging satellites' wide coverage and terrestrial networks' high capacity. The existing STIN operates with insufficient synergy in transmission scheduling, impacting resource allocation efficiency and transmission delay optimization, particularly in complex transmission scenarios. In this paper, we designDeterministic STIN (DetSTIN), a novel architecture for STIN, along with two algorithms tailored for transmission scheduling to collaboratively optimize resource adaptation and service flow scheduling. Specifically, the DetSTIN enables the smooth interconnection and integration of heterogeneous networks by providing layered deterministic services. Besides, a genetic-based resource adaptation algorithm is designed for fixed-mobile-satellite heterogeneous networks to reduce resource allocation overhead while maintaining the network performance. Furthermore, we propose a deep reinforcement learning-based differentiated scheduling algorithm to solve the routing-queue two-dimensional decision problem to differentially optimize transmission delay of service flows, thus obtaining higher transmission scheduling benefit. By addressing resource adaptation and differentiated scheduling synergistically, the proposed solution achieves reduced resource allocation overhead and increased transmission scheduling benefit, ultimately leading to increased network operation revenue of the DetSTIN. Simulation results demonstrate that the proposed solution delivers effective performance across various flow proportions, and as the number of flows increases, the network operation revenue exhibits a noticeable improvement, compared with benchmark algorithms.
Weiting Zhang, Peixi Liao, Dong Yang 0001, Qiang Ye 0002, Shiwen Mao, Hongke Zhang
IEEE Trans. Mob. Comput.1
2025 Toward Deterministic Wide-Area Networks via Deadline-Aware Routing and Scheduling
abstract
The widespread adoption of real-time services on the Internet has aroused interest in the study of low-latency and deterministic communications. Deterministic guarantee over wide-area networks (WANs), the primary infrastructure for communications, is essential to achieving end-to-end deterministic transmission. However, applying off-the-shelf deterministic schemes to WANs is challenging due to the statistical multiplexing nature of WANs and the non-periodic nature of WAN traffic. In this paper, we propose a novel deterministic framework for WANs, named DetWAN, which guarantees the timely delivery of WAN traffic via deadline-aware routing and scheduling. We design a coordinated earliest deadline first (CEDF) scheduling scheme in the data plane of the DetWAN, which provides determinism for non-periodic deadline-constrained traffic while following statistical multiplexing. To precisely estimate the capacity of deadline-constrained traffic that the DetWAN can satisfy, we derive an end-to-end deadline satisfiability criterion in the DetWAN by introducing the deadline curve into traffic modeling. Based on the criterion, we formulate the deadline-aware routing and scheduling problem as a stochastic optimization problem to maximize the timely delivery ratio. Furthermore, we propose a distributed admission control algorithm based on multi-agent deep reinforcement learning in the control plane to solve the problem in a highly autonomous manner. The algorithm can jointly determine optimal routes and per-hop deadline budgets for traffic flows in a decentralized mode. Extensive evaluation results validate the deterministic guarantee as well as the high throughput of the DetWAN and show that the proposed admission control algorithm can significantly improve the timely delivery ratio compared with benchmarks in WAN scenarios.
Weiting Zhang, Hongchao Wang 0001, Dong Yang 0001, Hongke Zhang, Shuguang Cui
IEEE Trans. Netw.2
2024 High-quality Trajectory Generation for Autonomous Driving: A Lightweight Federated Learning-based Diffusion Model
abstract
Vehicle trajectory data plays a pivotal role in simulation testing for autonomous driving. Hence, there exist well-established trajectory generation methods employing deep generative models to generate trajectories mapping the distribution of the original dataset, thereby augmenting existing trajectory datasets. However, these methods typically rely on large datasets gathered by governmental or organizational entities for central training, which may pose data privacy, security, and accessibility issues. Therefore, it is challenging to generate high-quality traffic trajectory data while preserving privacy which involves a delicate balance between these two objectives. To deal with this challenge, we introduce Federated Learning into the diffusion model and propose a Federated Learning-based diffusion model (FedDifftraj) to generate traffic trajectory data. Unlike existing central training methods, FedDifftraj aggregates model parameters uploaded by different vehicles and then updates a global model. Additionally, there is a substantial communication overhead incurred during the training of the federated diffusion model. Therefore, we quantize the local diffusion model before uploading it to the parameter server. Through extensive simulations on real-world datasets, FedDifftraj can generate high-quality traffic trajectory data that is consistent with the results of the central training while preserving privacy and reducing communication overhead by 93.74% when utilizing 8-bit quantization.
Runquan Gao, Jiawen Kang 0001, Bingkun Lai, Minrui Xu, Geng Sun 0001, Tao Zhang 0063, Weiting Zhang, Dong Yang 0001
GLOBECOM7
2024 Flow-MPNN: A Flow-Based Message-Passing Neural Network for Traffic Engineering
abstract
The emergence of the new network paradigm of software-defined networking (SDN) provides a unified control interface for centralized machine learning and greater flexibility for solving traffic engineering (TE) problems. However, most existing machine learning solutions to SDN TE problems rely on traffic requirements and fixed link capacity, ignoring the structural information of network topology and the correlation between flows and topology. This oversight can cause rapid network performance degradation during link failures and result in poor performance when traffic demand fluctuates significantly. To overcome these challenges, this study designs a flow-based message passing neural network (Flow-MPNN) and deep reinforcement learning (DRL) to facilitate information exchange between flows. Among them, Flow-MPNN is a method we designed based on graph neural network (GNN).By gaining a better understanding of flow-to-flow interplay and structural information about the network topology. Experimental results show that compared with existing algorithms, our proposed algorithm can accommodate 5% to 8% more traffic when the network link status remains unchanged. It also reduces maximum link utilization by 25% to 35%. Importantly, our algorithm exhibits better robustness when link status changes.
Deyun Gao, Weiting Zhang
GLOBECOM3
2024 End-to-end Flow Scheduling Optimization for Industrial 5G and TSN Integrated Networks
abstract
The integrated of the fifth generation (5G) and time-sensitive networking (TSN) is a promising approach to meet the requirements of deterministic forwarding with extremely low latency and high flexibility for the Industrial Internet of Things (IIoT). However, due to the large dissimilarity of protocol stacks, the 5G system normally serves as a logical bridge for TSN, performing hold-and-forward operations in Base Stations (BSs) under the current 5G-TSN frameworks. To provide ubiquitous and seamless connectivity for IIoT devices, this paper focuses on the integrated enhancement of 5G and TSN by optimizing the scheduling of time-sensitive flows with end-to-end latency of 5G-TSN transmission taken into consideration. Specifically, we propose a novel architecture named GF-CQF, which combines 5G Grant-free (GF) access with TSN Cyclic Queuing and Forwarding (CQF). Subsequently, the distributed flow scheduling problem based on GF-CQF architecture is established due to the high timeliness demands. To alleviate the impact of the uncertainty inherent in 5G channels on end-to-end deterministic transmission, a feature-aware decentralized real-time scheduling (FDRS) policy based on Multi-agent Reinforcement Learning is proposed. FDRS allows each agent at BS to adaptively allocate TSN injection slots for flows mainly based on dynamic 5G transmission performance and TSN network resource state so that TSN queue overflow can be avoided and flow delay constraints can be guaranteed. Simulations show that FDRS offers superior scheduling capabilities under the limited TSN queue resources.
Houling Liu, Fuqiang Gu, Qihao Li, Weiting Zhang, Songtao Guo
GLOBECOM5
2024 Diffusion-based Reinforcement Learning for Dynamic UAV-assisted Vehicle Twins Migration in Vehicular Metaverses
abstract
Air-ground integrated networks can relieve communication pressure on ground transportation networks and provide 6G-enabled vehicular Metaverses services offloading in remote areas with sparse RoadSide Units (RSUs) coverage and downtown areas where users have a high demand for vehicular services. Vehicle Twins (VTs) are the digital twins of physical vehicles to enable more immersive and realistic vehicular services, which can be offloaded and updated on RSU, to manage and provide vehicular Metaverses services to passengers and drivers. The high mobility of vehicles and the limited coverage of RSU signals necessitate VT migration to ensure service continuity when vehicles leave the signal coverage of RSUs. However, uneven VT task migration might overload some RSUs, which might result in increased service latency, and thus impactive immersive experiences for users. In this paper, we propose a dynamic Unmanned Aerial Vehicle (UAV)-assisted VT migration framework in air-ground integrated networks, where UAVs act as aerial edge servers to assist ground RSUs during VT task offloading. In this framework, we propose a diffusion-based Reinforcement Learning (RL) algorithm, which can efficiently make immersive VT migration decisions in UAV-assisted vehicular networks. To balance the workload of RSUs and improve VT migration quality, we design a novel dynamic path planning algorithm based on a heuristic search strategy for UAVs. Simulation results show that the diffusion-based RL algorithm with UAV-assisted performs better than other baseline schemes.
Yongju Tong, Jiawen Kang 0001, Minrui Xu, Gaolei Li, Weiting Zhang, Xincheng Yan
GLOBECOM6
2024 Two-Stage Resource Scheduling for Deterministic Communication and Computation Integration
abstract
In this paper, we investigate a resource orchestration and transmission scheduling problem for data-intensive services with diversified service requirements. A three-layer collaborative architecture is presented to support dynamic networking and computing resource allocation. To obtain optimal orchestration and scheduling policies, we formulate a constrained resource scheduling problem with the objective to maximizing resource utilization and scheduling success ratio. Since the complicated coupled constraints among decisions, we decouple the problem into a two-stage sub-problems of resource orchestration and transmission scheduling. To realize cross-domain resource orchestration and deterministic transmission of large-scale computing tasks, a two-stage resource scheduling scheme is proposed. Specifically, the first stage makes the resource orchestration decision by a greedy algorithm, and the second stage makes the transmission scheduling decision based on a deep reinforcement learning algorithm. Simulation results show that the proposed solution can effectively improve resource utilization and scheduling success ratio while satisfying diversified service requirements, as compared with benchmarks.
Weiting Zhang, Nian Tang, Chuan Zhang 0003, Ruibin Guo, Chenhao Ying 0001
GLOBECOM1
2024 Learning-Based Deterministic Scheduling for TSN and 5G Integrated Networks
abstract
Integration of the fifth-generation mobile communication technology (5G) into time-sensitive networking (TSN) was first proposed in the 3GPP Release 16. However, this conceptual proposal lacks of detailed designs to guarantee bounded latency and high reliability of this integration. In this paper, we study a deterministic scheduling problem for TSN-5G integrated networks in industrial Internet of things (IIoT) scenarios, in which a unified control plane jointly allocates the time-frequency resources for TSN and 5G to support deterministic end-to-end transmission. Specifically, we design a novel control architecture, i.e., centralized network and distributed user, for the integrated networks to reduce the signaling overhead. Moreover, we formulate a stochastic optimization problem for IIoT scenarios to maximize the number of successfully scheduled flows as well as realize throughput fairness for wired and wireless equipment. Since the resource allocation of TSN and 5G are coupled, this problem is NP-hard. We propose a dueling double deep Q network (D3QN) based Joint Resource Allocation (DJRA) algorithm. By leveraging two convolution-enhanced neural networks, with their parameters periodically synchronized, the accuracy of the estimated Q-value can be increased and the convergence speed of DJRA can be accelerated. Simulation results show that the proposed algorithm can facilitate efficient cooperation between TSN and 5G as compared to the other heuristic and learning-based algorithms.
Ruibin Guo, Dong Yang 0001, Weiting Zhang, Qingyu Cai, Hongke Zhang, Xuemin Shen
ICC3
2024 ChronusFed: Reinforcement-Based Adaptive Partial Training for Heterogeneous Federated Learning
abstract
Due to the progress in computer hardware and network technologies, federated learning (FL), a decentralized training method in machine learning, has garnered widespread attention. In this approach, individuals share local model parameters rather than raw training data to protect their privacy. However, the inherent heterogeneity of practical computing devices poses challenges to the efficiency and performance of FL. In this paper, we explore the landscape of heterogeneous FL frameworks and introduce ChronusFed, a reinforCement-based adaptive partial training method for heterogeneous Federated learning. ChronusFed employs a dynamic epoch adjustment mechanism (DEA) and a customizable partial training framework (CPT) to optimize model training efficiency. By integrating DEA and CPT, ChronusFed effectively tackles the straggler issues that arise from limited hardware resources, while simultaneously enhancing the model performance. More specifically, DEA leverages deep reinforcement learning (DRL) to model the current state of the global model and determine optimal local training epochs, while CPT utilizes our proposed maximum coverage algorithm to handle device heterogeneity and accelerate model convergence. Theoretical analysis of training convergence validates the effectiveness of ChronusFed, and comprehensive experimental evaluations demonstrate that ChronusFed outperforms state-of-the-art methods across various learning tasks, showcasing its robustness and superiority in heterogeneous FL scenarios.
Fuyuan Xia, Chenhao Ying 0001, David S. L. Wei, Wei Chen 0180, Weiting Zhang, Haiming Jin, Yuan Luo 0003
ICPP5
2024 Optimizing Information Propagation for Blockchain-empowered Mobile AIGC: A Graph Attention Network Approach
abstract
Artificial Intelligence-Generated Content (AIGC) is a rapidly evolving field that utilizes advanced AI algorithms to generate content. Through integration with mobile edge networks, mobile AIGC networks have gained significant attention, which can provide real-time customized and personalized AIGC services and products. Since blockchains can facilitate decentralized and transparent data management, AIGC products can be securely managed by blockchain to avoid tampering and plagiarization. However, the evolution of blockchain-empowered mobile AIGC is still in its nascent phase, grappling with challenges such as improving information propagation efficiency to enable blockchain-empowered mobile AIGC. In this paper, we design a Graph Attention Network (GAT)-based information propagation optimization framework for blockchain-empowered mobile AIGC. We first innovatively apply age of information as a data-freshness metric to measure information propagation efficiency in public blockchains. Considering that GATs possess the excellent ability to process graph-structured data, we utilize the GAT to obtain the optimal information propagation trajectory. Numerical results demonstrate that the proposed scheme exhibits the most outstanding information propagation efficiency compared with traditional routing mechanisms.
Jiana Liao, Jinbo Wen, Jiawen Kang 0001, Yang Zhang 0025, Jianbo Du, Qihao Li, Weiting Zhang, Dong Yang 0001
IWCMC7
2024 Multi-domain collaborative two-level DDoS detection via hybrid deep learning
Huifen Feng, Weiting Zhang, Ying Liu 0018, Chuan Zhang 0003, Chenhao Ying 0001, Zhenzhen Jiao
Comput. Networks2
2024 Securing Federated Diffusion Model With Dynamic Quantization for Generative AI Services in Multiple-Access Artificial Intelligence of Things
abstract
Generative diffusion models (GDMs) have emerged as potent tools for generating high-quality, creative content across various media, including audio, images, videos, and 3-D models. Their application in artificial intelligence-generated content (AIGC) marks a pivotal advancement in the evolution from the Internet of Things (IoT) to the Artificial Intelligence of Things (AIoT). Considering the inherent multiple-access nature of AIoT, training GDMs via federated learning and deploying them collaboratively is paramount. However, such approaches introduce considerable security risks and energy consumption challenges. To address these issues, we propose a comprehensive architecture for GDMs, encompassing both training and sampling stages. This architecture, termed secure and sustainable diffusion (SS-Diff), aims to thwart trigger-based security threats, such as backdoor attacks and trojan attacks, while simultaneously reducing energy consumption in multiple-access AIoT. The SS-Diff architecture incorporates a dynamic quantization mechanism within the training phase, significantly reducing communication overhead and thereby improving both spectrum and energy efficiency. During the sampling stage, a detection-based defense strategy is employed to identify and negate trigger inputs associated with malicious attacks. Through extensive simulations, we evaluate the performance of the SS-Diff architecture. The results demonstrate that the SS-Diff can effectively train GDMs and eliminate the impact of the attacks, compared with existing schemes.
Bingkun Lai, Jiawen Kang 0001, Hongyang Du 0001, Jiangtian Nie, Tao Zhang 0063, Yanli Yuan, Weiting Zhang, Dusit Niyato, Abbas Jamalipour
IEEE Internet Things J.8
2024 FedSAP: Secure Federated Learning in SDN-IoT via DRL-Enabled Social Attribute Perception
abstract
Federated learning (FL) is an innovative distributed privacy-preserving machine learning paradigm, which enables participants to collaboratively train artificial intelligence (AI) models without disclosing private data. Nevertheless, malicious participants have the potential to introduce vicious models via poisoning attacks, which jeopardizes the convergence and accuracy of the global model in FL. In this article, we propose a secure FL distributed architecture based on deep deterministic policy gradient (DDPG), which advances the accuracy of the global model and enhances system robustness. Specifically, we model the accuracy optimization problem with the goal of minimizing the overall loss function of participating devices during each FL iteration. Furthermore, we design the device nodes selection mechanism, named FedSAP, which leverages social attribute perception. Particularly, we first construct the device node selection problem as a Markov decision process (MDP), and then apply social attribute perception and attribute information to the state space ensuring the reliability of the device. Moreover, the long short term memory (LSTM) algorithm is introduced into the actor-critic network structure to learn part of the hidden state through memory inference. The extensive experimental results show that FedSAP can effectively select reliable nodes and significantly improve the accuracy of the global model.
Jiushuang Wang, Ying Liu 0018, Weiting Zhang, Chenhao Ying 0001, Jiawen Kang 0001
IEEE Internet Things J.3
2024 VSpatial: Enabling Private and Verifiable Spatial Keyword-Based Positioning in 6G-Oriented IoT
abstract
For increasing Internet of Things (IoT) devices, 6G wireless technology aims for ubiquitous communications in which positioning services are necessary. Private spatial keyword-based positioning service is promising in 6G-oriented IoT since it positions users based on spatial locations and textual keywords while protecting user privacy. However, due to economic benefits or malicious attacks, positioning service providers may return erroneous or incomplete results, which cause tremendous economic damage and security threats, e.g., always assigning a selective driver for the specific car-hailing user. A technical challenge for extending existing private schemes to enable users to verify the correctness and completeness of positioning results is the distinctive positioning paradigm between compared spatial locations and matched textual keywords. This paper proposes a private and verifiable spatial keyword positioning scheme named VSpatial in 6G-oriented IoT. VSpatial enables users to verify the correctness and completeness of spatial keyword-based positioning results while preserving user privacy. The main inspiration for addressing the technical challenge is converting both spatial locations and textual keywords into an internal status, i.e., adapting comparison and matching to existence judging by multiple cryptographic tools, such as hierarchical cube and pseudorandom function. Based on this inspiration, we design a novel private authenticated data structure (named PVTree), and then propose two constructions of VSpatial, i.e., VSpatial-S and VSpatial-D, to suit static and dynamic environments, respectively. The core idea for adapting VSpatial-S to VSpatial-D is transferring one whole PVTree into multiple exponential-size partitions. Security analysis proves the security and verifiability of VSpatial. Theoretical and experimental evaluations show that VSpatial achieves faster-than-linear positioning efficiency and linear verification overhead.
Weiting Zhang, Mingyang Zhao 0002, Zhuoyu Sun, Chuan Zhang 0003, Jinwen Liang, Liehuang Zhu, Song Guo 0001
IEEE J. Sel. Areas Commun.1
2024 Privacy-Preserving Identity-Based Data Rights Governance for Blockchain-Empowered Human-Centric Metaverse Communications
abstract
Metaverse provides human-centric immersive communication experiences where humans can teleport across different virtual landscapes and build real-time communications via digital identities with others in the same landscape. Despite great benefits, a natural question in human-centric metaverse communications is how to secure digital content among humans. In this regard, blockchain has been widely applied due to its distinct features (e.g., decentralization, transparency, and immutability). Unfortunately, the inherent properties of the blockchain also hinder humans from further deploying preferences to flexibly govern the digital content (i.e., who can read and who can edit), limiting human-centric communication abilities. Some redactable blockchain-based solutions have been proposed, but most of them suffer from the issues of data and preference leakage. To address the issues, we propose a privacy-preserving identity-based data governance (IDRG) scheme for blockchain-empowered human-centric metaverse communications. Combining digital identities, IDRG cryptographically allows humans to govern readability and editability with the right downward compatibility (i.e., humans with editability are endowed with readability) while protecting policy privacy. Specifically, IDRG leverages the polynomial function technique to break through the bottleneck of the traditional identity-based encryption technique (i.e., a policy only contains a user) to achieve a policy for multiple users. Subsequently, the optimized policies are utilized to enrich chameleon hash-based redactable blockchains for comprehensive rights governance. Further, IDRG supports user accountability and revocation by combining the proxy re-encryption technique. Security analysis proves the security of IDRG under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that IDRG requires approximately 0.1 s to process an encryption request, 0.01 s for a reading request, and 1 s for an editing request. Overall, IDRG achieves a$3\times $reduction in computational costs compared with state-of-the-art solutions.
Chuan Zhang 0003, Mingyang Zhao 0002, Weiting Zhang, Jianbing Ni, Liehuang Zhu
IEEE J. Sel. Areas Commun.3
2024 DetFed: Dynamic Resource Scheduling for Deterministic Federated Learning Over Time-Sensitive Networks
abstract
In this paper, we present a three-layer (i.e., device, field, and factory layers) deterministic federated learning (FL) framework, named DetFed, which accelerates collaborative learning process for ultra-reliable and low-latency industrial Internet of Things (IoT) via integrating 6G-oriented Time-sensitive Networks (TSN). Utilizing dispersive local data, industrial IoT devices distributively train a deep neural network (DNN) model, and the updated model parameters are aggregated at their associated field servers every round or at a centralized factory server every a few rounds. Aiming at optimizing the learning accuracy of FL without affecting the co-transmission of burst traffic (e.g., safety-critical traffic), an integrated TSN is considered to establish connections among the three layers, where a cyclic queuing and forwarding mechanism is deployed in each switch to support deterministic model parameter transmission with microsecond-level delay and near-zero packet loss requirements. To improve the FL performance, we formulate a multi-objective stochastic optimization problem to simultaneously maximize the scheduling success ratio and learning accuracy while satisfying the deterministic requirements of delay, jitter, and packet loss. Since the objective function is implicit and the available time slots of the considered TSN in each FL round are temporally correlated, the problem is difficult to solve in real time. Therefore, we transform the problem into a Markov decision process formulation and propose a dynamic resource scheduling algorithm, based on deep reinforcement learning, to make optimal resource scheduling decisions while adapting to device heterogeneity and network dynamics. Experimental results based on real-world dataset demonstrate that the proposed DetFed significantly accelerates FL convergence and improves learning accuracy as compared to state-of-the-art benchmarks.
Dong Yang 0001, Weiting Zhang, Qiang Ye 0002, Chuan Zhang 0003, Ning Zhang 0007, Chuan Huang 0001, Hongke Zhang, Xuemin Shen
IEEE Trans. Mob. Comput.2
2023 In-Network Collaborative Link Flooding Attack Defense with Adaptive Anomaly Analysis
abstract
The rapid growth of cloud data centers has reduced the organizational cost of botnets while significantly increasing the risk of Link Flooding Attack (LFA) to network service providers. The attacker utilizes legitimate low-rate flows with non-spoofing addresses to congest the bottleneck link, which aims to disconnect the target area. To overcome certain hitches of traditional defenses, we propose an in-network collaborative link flooding attack defense scheme (ICDLFA) to implement detection and mitigation. First, an adaptive anomaly detection algorithm, namely constrained clustering inference, is proposed to detect malicious flows at line rate without pre-trained models, which improves the adaptability of the detection algorithm to different scenarios. In particular, the anomaly detection algorithm is executed independently on a programmable switch, which significantly improves the detection efficiency by escaping the global view of the controller. Second, the collaborative mitigation mechanism propagates the traffic limitation policy to the vicinity of the attack source, which alleviates the impact on legitimate flows. In addition, the distributed defense can effectively limit the flexible transformation of attack vectors and reduce the possibility of launching subsequent attacks. Simulation results demonstrate that our in-network LFA defense scheme could accurately and effectively detect and mitigate LFA, quickly adapt to attack changes, and reduce network resource overhead.
Ying Liu 0018, Weiting Zhang, Wei Quan 0001
GLOBECOM3
2023 Deep Reinforcement Learning for On-Demand Intelligent Routing in Deterministic Networks
abstract
Deterministic networks have an obligation to guarantee deterministic transmission requirements of various applications in terms of delay, packet loss, throughput, and reliability. Traditional routing mechanisms, however, do not take sufficient advantage of the abundant network resources and can only provide limited quality of service (QoS) guarantees. Therefore, we propose an on-demand intelligent routing (OdIR) framework for deterministic networks. First, built on in-band network telemetry (INT) implemented by programming protocol-independent packet processors (P4), we design a fine-grained and high-precision awareness strategy to obtain network state information in real-time. Second, we present an intelligent routing decision approach based on the improved deep deterministic policy gradient (DDPG) algorithm. Finally, we adopt the segment routing MPLS (SR-MPLS) paradigm in the data plane to forward deterministic flows according to decision paths. Simulation results show that the OdIR framework can effectively reduce link overhead, end-to-end delay, packet loss rate, and southbound communication overhead under guaranteed deterministic QoS compared with traditional routing mechanisms.
Ying Liu 0018, Jianhui Yin, Weiting Zhang, Shanghan Xie
GLOBECOM3
2023 An efficient scheduling approach for multi-level industrial chain flows in time-sensitive networking
Dong Yang 0001, Weiting Zhang
Comput. Networks3
2023 Survey on the scheme evaluation, opportunities and challenges of software defined-information centric network
abstract
Abstract As a promising architecture of next‐generation network, software defined‐information centric network (SD‐ICN) inherits the advantages of software defined network (SDN) and information‐centric network (ICN) to enable flexible and fast content retrieval, especially in the current era of artificial intelligence. However, the existing researches mainly focus on a single respective in this field, which motivates in comprehensively providing a forward‐looking guidance and development direction for scholars and engineers. To this end, the latest developments of SD‐ICN is presented. First, the widely‐accepted concepts and impacts on traditional networks are introduced. Second, the shortcomings of SDN and ICN over conventional networks are respectively analyzed to illustrate the necessity of SD‐ICN. Third, based on extensive analysis and deep deliberation, a methodical taxonomy for existing combination studies is proposed. They are divided into SDN over ICN, ICN over SDN, and mutual immersive pattern. Fourth, the performances of three integration categories are compared and the limitations of related works are highlighted. Fifth, the maturity index from six development indicators are evaluated. Further, the maturity and practicality of these schemes are generalized. Based on the above studies and comparisons, the lessons learned by SDN and ICN developments are concluded. Finally, future research directions and opportunities are discussed for the readers.
Zhengyang Ai, Weiting Zhang, Jiawen Kang 0001, Lingling Tong, Yunqiang Duan
IET Commun.3
2023 Blockchain-Based Anonymous Data Sharing With Accountability for Internet of Things
abstract
Blockchain has been a promising infrastructure for enabling secure data sharing for the Internet of Things (IoT). With the widespread of IoT applications, security issues, such as data privacy, anonymity, and accountability become critical concerns for the users, which are essential principles for secure communication in those applications. However, the existing blockchain-based data-sharing schemes mainly consider data privacy. Only a few works can support anonymity with strong, trusted assumptions. Thus, there is a research gap on the anonymity of blockchain-based data sharing for IoT, which does not rely on any trusted party. In this article, we propose a blockchain-based anonymous data-sharing scheme (BA-DS) by adopting a novel public key encryption derived from a ring signature. In BA-DS, we remove the trusted party and ensure anonymity by using an unconditional linkable ring signature and Signature of Knowledge (SoK). During the revocation, we apply blockchain infrastructure to record the valid revocation list and generate a tag for data stored on the cloud, providing solid accountability. The formal security analysis shows that BA-DS is selective indistinguishable secure in the random oracle model. Additionally, we also prove that BA-DS holds anonymity, data privacy, accountability, and authenticity. The extensive experiments indicate that our proposed BA-DS achieves reasonable efficiency in terms of computational complexity, communication overhead, and consumption on the blockchain.
Tong Wu 0011, Weijie Wang 0010, Chuan Zhang 0003, Weiting Zhang, Liehuang Zhu, Keke Gai
IEEE Internet Things J.4
2023 A smart collaborative framework for dynamic multi-task offloading in IIoT-MEC networks
Zhengyang Ai, Weiting Zhang, Pengxiao Li
Peer Peer Netw. Appl.2
2023 Burst-Aware Time-Triggered Flow Scheduling With Enhanced Multi-CQF in Time-Sensitive Networks
abstract
Deterministic transmission guarantee in time-sensitive networks (TSN) relies on queue models (such as CQF, TAS, ATS) and resource scheduling algorithms. Thanks to its ease of use, the CQF queue model has been widely adopted. However, the existing resource scheduling algorithms of CQF model only focus on periodic time-triggered (TT) flows without consideration of bursting flows. Considering that the bursting flows often carry high-priority data in real systems, in this paper we investigate the mixed-flow (i.e., TT and bursting flows) scheduling problem in CQF-based TSN aiming to maximize the number of schedulable flows and system load balance while satisfying the deterministic demands of delay, jitter, and reliability for both TT and bursting flows. Unfortunately, it is challenging to schedule the mixed flows with the original CQF model because of the huge difference between TT and bursting flows. To resolve this problem, we firstly design an enhanced Multi-CQF model to satisfy the basic demands of bursting flows sent at any time without affecting the deterministic transmission of TT flows. Given the complexity of mixed-flow scheduling and the proposed queue model, it is difficult for traditional algorithms to fully utilize network resources. Thus, we further propose a uline time-correlated uline DRL uline resource uline scheduling (TimeDRS) algorithm to optimize the resource allocation. TimeDRS can be extended to other time-related resource scheduling scenarios, such as TDMA-based scheduling. Experimental results demonstrate that our proposed approaches can greatly reduce frame loss and end-to-end latency for bursting flows, and well balance runtime and schedulability compared with state-of-the-art benchmarks.
Dong Yang 0001, Zongrong Cheng, Weiting Zhang, Hongke Zhang, Xuemin Shen
IEEE/ACM Trans. Netw.3
2022 Achieving a Blockchain-based Privacy-preserving Quality-aware Knowledge Marketplace in Crowdsensing
abstract
It is increasingly popular to utilize the wisdom of the crowd for knowledge discovery and monetization. Most of the existing knowledge marketplaces in crowdsensing are implemented by a third-party platform, which may compromise users' rights and be vulnerable to incurring attacks in practice. To eliminate the untrustworthy behaviors of the third party and improve tolerance for the attacks, some blockchain-based knowledge marketplaces in crowdsensing have been proposed. However, the existing blockchain-based knowledge marketplaces fail to simultaneously guarantee privacy (i.e., data privacy and task privacy) and quality awareness. In this paper, we design a blockchain-based privacy-preserving quality-aware knowledge marketplace (PQKM) based on truth discovery, secure K-nearest neighbor computation, matrix decomposition, and data perturbation. PQKM privately calculates users' data quality and automatically rewards users based on their data quality. Detailed security analysis demonstrates that PQKM can preserve data privacy and task privacy during knowledge discovery and monetization. Extensive experiments are conducted on the open real-world dataset to show that PQKM has acceptable efficiency and affordable performance.
Mingyang Zhao 0002, Weiting Zhang, Jinyang Dong, Tong Wu 0011, Chuan Zhang 0003, Liehuang Zhu
EUC4
2022 Stealing Secrecy from Outside: A Novel Gradient Inversion Attack in Federated Learning
abstract
Knowing model parameters has been regarded as a vital factor for recovering sensitive information from the gradients in federated learning. But is it safe to use federated learning when the model parameters are unavailable for adversaries, i.e., external adversaries’ In this paper, we answer this question by proposing a novel gradient inversion attack. Speciffically, we observe a widely ignored fact in federated learning that the participants’ gradient data are usually transmitted via the intermediary node. Based on this fact, we show that an external adversary is able to recover the private input from the gradients, even if it does not have the model parameters. Through extensive experiments based on several real-world datasets, we demonstrate that our proposed new attack can recover the input with pixelwise accuracy and feasible efficiency.
Chuan Zhang 0003, Haotian Liang, Youqi Li, Tong Wu 0011, Liehuang Zhu, Weiting Zhang
ICPADS6
2022 Learning-Based Computation Offloading for IoRT Through Ka/Q-Band Satellite-Terrestrial Integrated Networks
abstract
In this article, we propose a multilayer Ka/Q-band satellite–terrestrial integrated network for the Internet of Remote Things (IoRT) to achieve a high transmission rate with communication robustness in dynamic network environments. Under this architecture, we investigate how to jointly manage the offloading path selection and resource allocation to offload computation-intensive and delay-sensitive tasks in the IoRT. Considering continuous low earth orbit (LEO) satellite movements and Markovian rainfall changes, the computation offloading problem is described as a Markov decision process (MDP) formulation with the objective of maximizing the number of offloaded tasks with satisfied delay requirements and minimizing the power consumption of the LEO satellites. A deep reinforcement learning (DRL) approach is leveraged to make optimal decisions by taking account of dynamic queues of IoRT devices, channel conditions that vary with rainfall intensities and satellite positions, and computing capabilities of ground stations. Extensive simulations are conducted to validate the effectiveness and superiority of our proposed scheme.
Tianjiao Chen, Jiang Liu 0010, Qiang Ye 0002, Weihua Zhuang, Weiting Zhang, Tao Huang 0005, Yunjie Liu 0001
IEEE Internet Things J.5
2022 A Secure Revocable Fine-Grained Access Control and Data Sharing Scheme for SCADA in IIoT Systems
abstract
The supervisory control and data acquisition (SCADA) system is widely used in industrial control and the contemporary Industrial Internet of Things (IIoT). Unfortunately, due to its relatively weak design in terms of data security and access control, SCADA systems are becoming a favorite target for attackers. End-to-end encryption, such as SSL/TLS protocol, is used to protect the data transmission, but it cannot guarantee security in third-party cloud platforms. In this article, we propose a secure revocable fine-grained access control and data sharing scheme. This scheme not only ensures the confidentiality of the data but also enhances the access control of the SCADA system. Our scheme is based on three key observations. The common communication architecture of SCADA systems cannot protect data security itself. The security supports provided by industrial control protocols are limited. Moreover, the third-party cloud platforms are semitrusted. In addition, we have introduced digital signature technology to assure the integrity of the data in the SCADA system. We prove that our scheme is secure. This scheme has been experimentally evaluated to introduce negligible performance losses while improving data security in the SCADA system.
Weiting Zhang, Hanyi Zhang, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001
IEEE Internet Things J.1
2022 Deep-Reinforcement-Learning-Based Latency Minimization in Edge Intelligence Over Vehicular Networks
abstract
A novel paradigm that combines federated learning with blockchain to empower edge intelligence over vehicular networks (FBVN) can enable latency-sensitive deep neural network-based applications to be executed in a distributed pattern. However, the complex environments in FBVN make the system latency much harder to minimize by traditional methods. In this article, we model the training and transmission latency of each autonomous vehicle (AV) and consensus latency of the blockchain in-edge side in FBVN. Considering the dynamic and time-varying wireless channel conditions, unpredictable packet error rate, and unstable data sets quality, we adopt duel deep$Q$-learning (DDQL) as the solving approach. We propose a federated DDQL algorithm, in which the learning agent is deployed on each AV side, and the sensing states on each AV do not need to be shared so that it increases scalability and flexibility for practical implementation. Simulation results show that the proposed algorithm has better performance in reducing system latency compared with the other schemes.
Hao Wu 0005, F. Richard Yu, Weiting Zhang, Victor C. M. Leung
IEEE Internet Things J.5
2022 FRUIT: A Blockchain-Based Efficient and Privacy-Preserving Quality-Aware Incentive Scheme
abstract
Incentive plays an important role in knowledge discovery, as it impels users to provide high-quality knowledge. To promise incentive schemes with transparency, blockchain technology has been widely used in incentive schemes. Currently, privacy, reliability, streamlined processing, and quality awareness are major challenges in designing blockchain-based incentive schemes. In this paper, we design a blockchain-based eFficient and pRivacy-preserving qUality-aware IncenTive scheme called FRUIT. With well-designed smart contracts, FRUIT achieves privacy, reliability, streamlined processing, and quality awareness during the whole procedure. Specifically, we design a novel lightweight encryption method by combining matrix decomposition with proxy re-encryption and a privacy-preserving task allocation based on the polynomial fitting function and hash function. Then, we leverage our proposed lightweight encryption and task allocation to build an efficient and privacy-preserving knowledge discovery protocol in order to securely calculate the data quality and truthful knowledge. To promise user reliability in the incentive scheme, we utilize the Dirichlet distribution to realize the automatic reputation prediction based on the data quality by deploying the reputation management on the blockchain. Moreover, we also deploy the payment management on the blockchain, endowing the incentive scheme to reward participants based on the data quality automatically. Through a detailed security analysis, we demonstrate that data privacy and task privacy are well preserved during the whole process. Theoretical analysis and extensive experiments on real-world datasets demonstrate that FRUIT has acceptable efficiency and affordable performance in terms of computation cost, communication overhead, and gas consumption.
Chuan Zhang 0003, Mingyang Zhao 0002, Liehuang Zhu, Weiting Zhang, Tong Wu 0011, Jianbing Ni
IEEE J. Sel. Areas Commun.4
2021 Optimizing Federated Learning in Distributed Industrial IoT: A Multi-Agent Approach
abstract
In this paper, we aim to make the best joint decision of device selection and computing and spectrum resource allocation for optimizing federated learning (FL) performance in distributed industrial Internet of Things (IIoT) networks. To implement efficient FL over geographically dispersed data, we introduce a three-layer collaborative FL architecture to support deep neural network (DNN) training. Specifically, using the data dispersed in IIoT devices, the industrial gateways locally train the DNN model and the local models can be aggregated by their associated edge servers every FL epoch or by a cloud server every a few FL epochs for obtaining the global model. To optimally select participating devices and allocate computing and spectrum resources for training and transmitting the model parameters, we formulate a stochastic optimization problem with the objective of minimizing FL evaluating loss while satisfying delay and long-term energy consumption requirements. Since the objective function of the FL evaluating loss is implicit and the energy consumption is temporally correlated, it is difficult to solve the problem via traditional optimization methods. Thus, we propose a “Reinforcement on Federated” (RoF) scheme, based on deep multi-agent reinforcement learning, to solve the problem. Specifically, the RoF scheme is executed decentralizedly at edge servers, which can cooperatively make the optimal device selection and resource allocation decisions. Moreover, a device refinement subroutine is embedded into the RoF scheme to accelerate convergence while effectively saving the on-device energy. Simulation results demonstrate that the RoF scheme can facilitate efficient FL and achieve better performance compared with state-of-the-art benchmarks.
Weiting Zhang, Dong Yang 0001, Wen Wu 0003, Haixia Peng, Ning Zhang 0007, Hongke Zhang, Xuemin Shen
IEEE J. Sel. Areas Commun.1
2021 Accuracy-Guaranteed Collaborative DNN Inference in Industrial IoT via Deep Reinforcement Learning
abstract
Collaboration among industrial Internet of Things (IoT) devices and edge networks is essential to support computation-intensive deep neural network (DNN) inference services, which require low delay and high accuracy. Sampling rate adaption, which dynamically configures the sampling rates of industrial IoT devices according to network conditions, is the key in minimizing the service delay. In this article, we investigate the collaborative DNN inference problem in industrial IoT networks. To capture the channel variation and task arrival randomness, we formulate the problem as a constrained Markov decision process (CMDP). Specifically, sampling rate adaption, inference task offloading, and edge computing resource allocation are jointly considered to minimize the average service delay while guaranteeing the long-term accuracy requirements of different inference services. Since CMDP cannot be directly solved by general reinforcement learning (RL) algorithms due to the intractable long-term constraints, we first transform the CMDP into an MDP by leveraging the Lyapunov optimization technique. Then, a deep RL-based algorithm is proposed to solve the MDP. To expedite the training process, an optimization subroutine is embedded in the proposed algorithm to directly obtain the optimal edge computing resource allocation. Extensive simulation results are provided to demonstrate that the proposed RL-based algorithm can significantly reduce the average service delay while preserving long-term inference accuracy with a high probability.
Wen Wu 0003, Peng Yang 0004, Weiting Zhang, Conghao Zhou, Xuemin Shen
IEEE Trans. Ind. Informatics3
2021 DeepHealth: A Self-Attention Based Method for Instant Intelligent Predictive Maintenance in Industrial Internet of Things
abstract
With the rapid development of artificial intelligence and industrial Internet of Things (IIoT) technologies, intelligent predictive maintenance (IPdM) has received considerable attention from researchers and practitioners. To efficiently predict impending failures and mitigate unexpected downtime, while satisfying the instant maintenance demands of industrial facilities is very important for improving the production efficiency. In this article, a self-attention based “Perception and Prediction” framework, called DeepHealth, is proposed for the instant IPdM. Specifically, the framework is composed of two submodels (i.e., DH-1 and DH-2), which are respectively utilized to perform the health perception and sequence prediction. By operating the framework, the proposed models can predict the health conditions via predicting the future signal samples, thereby completing the instant IPdM. Considering the potential temporal correlation in time series, we deploy an enhanced attention mechanism to capture global dependencies from the vibration signals, and leverage the long- and short-term sequence prediction of sensor signals to support instant maintenance decision-making. On this basis, we conduct a destructive experiment based on the IIoT-enabled rotating machinery and construct a balanced industrial dataset for model evaluations. Extensive experiment results show that the proposed solution achieves good prediction accuracy for instant IPdM on the automatic washing equipment and Case Western Reserve University datasets.
Weiting Zhang, Dong Yang 0001, Youzhi Xu, Xuefeng Huang, Mikael Gidlund
IEEE Trans. Ind. Informatics1
2020 Deep Reinforcement Learning Based Resource Management for DNN Inference in IIoT
abstract
In this paper, we investigate the joint task assignment and resource allocation for deep neural network (DNN) inference in the device-edge-cloud based industrial Internet of things (IIoT) networks. To efficiently orchestrate the limited spectrum and computing resources in IIoT networks for massive DNN inference tasks, a resource management problem is formulated with the objective of maximizing the average inference accuracy while satisfying the quality-of-service of DNN inference tasks. Considering the strict delay requirements of inference tasks, we transform the formulated problem into a Markov decision process, and propose a deep deterministic policy gradient based learning algorithm to obtain the solution rapidly. Simulation results show that the proposed algorithm can achieve high average inference accuracy.
Weiting Zhang, Dong Yang 0001, Haixia Peng, Wen Wu 0003, Wei Quan 0001, Hongke Zhang, Xuemin Shen
GLOBECOM1
2020 Secure Door on Cloud: A Secure Data Transmission Scheme to Protect Kafka's Data
abstract
Apache Kafka, which is a high-throughput distributed message processing system, has been leveraged by the majority of enterprise for its outstanding performance. Unlike common cloud-based access control architectures, Kafka service providers often need to build their systems on other enterprises' high-performance cloud platforms. However, since the cloud platform belongs to a third party, it is not necessarily reliable. Paradoxically, it has been demonstrated that Kafka's data is stored in the cloud in the plaintext form, and thus poses a serious risk of user privacy leakage. In this paper, we propose a secure fine-grained data transmission scheme called Secure Door on Cloud (SDoC) to protect the data from being leaked in Kafka. SDoC is not only more secure than Kafka's built-in security mechanism, but also can effectively prevent third-party cloud from stealing plaintext data. To evaluate the performance of the SDoC, we simulate normal inter-entity communication and show that Kafka with SDoC integration has a lower data transfer time overhead than that of Kafka with built-in security mechanism opened.
Hanyi Zhang, Liming Fang 0001, Keyu Jiang, Weiting Zhang, Lu Zhou 0002
ICPADS4