VLDB 2026 Research / reviewers in the wild / expert
Liyuan Chang
dblp:258/1941
· DBLP profile ↗
8ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0002-6729-1450ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Moving target defense strategies against lateral movement in cloud-native environments
Shangrong Ma, Liyuan Chang, Lixiang Li 0001 |
Future Gener. Comput. Syst. | 4 |
| 2026 | LCE-PPDA: Lightweight Certificateless and Escrow-Free Privacy-Preserving Data Aggregation for UAV-Assisted IoT-Enabled Smart GridsabstractThe convergence of unmanned aerial vehicles (UAVs) and the Internet of Things (IoT) is expected to enhance sensing coverage, connectivity, and resilience in distributed smart grids, especially in remote or infrastructure-sparse regions. In this UAV-assisted, IoT-enabled paradigm, UAVs act as aerial relays that collect, aggregate, and forward sensing data between ground devices and control centers. However, privacy-preserving data aggregation (PPDA) in such settings still faces key-escrow vulnerabilities, certificate management overhead, incomplete privacy protection, and high computational and energy costs, particularly for signature verification at UAV relays and decryption at control centers. To address these challenges, we propose LCE-PPDA, a lightweight, certificateless, and escrow-free PPDA scheme tailored for UAV-assisted, IoT-enabled smart grids. LCE-PPDA eliminates key escrow through joint key generation, adopts a hierarchical timing structure with macro-interval rekeying and micro-interval reporting, and supports ciphertext-level in-network aggregation with both individual and batch authentication at UAV relays. To ensure privacy with accountability, it integrates certificateless signatures, dynamic pseudonyms, and session-bound key masking, achieving end-to-end confidentiality, conditional anonymity, unlinkability, and accountable traceability. Formal analysis shows that LCE-PPDA achieves correctness and EUF-CMA security in the random-oracle model under the ECDLP assumption against both Type-I and Type-II adversaries. Performance evaluation further demonstrates that LCE-PPDA reduces computational, communication, and energy overheads compared with representative schemes, providing a scalable and lightweight foundation for secure, privacy-preserving data aggregation in UAV-assisted, IoT-enabled smart grids. Liyuan Chang, Junyan Guo, Shuang Yao, Haizhen Qi, Le Zhang 0017, Bin Cao 0002 |
IEEE Internet Things J. | 1 |
| 2026 | EF-CPPA: Escrow-Free Conditional Privacy-Preserving Authentication Scheme for Real-Time Emergency Messages in Smart GridsabstractTimely and secure emergency message delivery is critical to resilient smart-grid operation and rapid disturbance response. However, existing schemes remain inadequate, leaving smart grids vulnerable to security and privacy threats and causing verification bottlenecks, particularly when nonlinear emergency measurements cannot be homomorphically aggregated, which prevents bandwidth-efficient in-network aggregation and scalable batch verification. We propose EF-CPPA, an escrow-free, conditional privacy-preserving authentication scheme for real-time emergency messaging in smart grids. EF-CPPA enables smart meters to deliver authenticated emergency messages to the CC via power gateways verifiable as legitimate relays, while ensuring the confidentiality, integrity, and unlinkability of embedded nonlinear measurements. EF-CPPA further provides conditional anonymity with accountable tracing, as well as origin authentication, intra-domain verification, and scalable batch verification under bursty multi-meter messaging. An ECDLP-based escrow-free key-generation mechanism reduces reliance on the CC and enables efficient node joining and revocation. Security analysis shows that EF-CPPA achieves existential unforgeability under chosen-message attacks (EUF-CMA) and satisfies the stated security and privacy requirements. Performance evaluation demonstrates low computational, communication, energy, and node-management overhead, making EF-CPPA suitable for security-critical, time-sensitive smart-grid emergency messaging. Junyan Guo, Shuang Yao, Le Zhang 0017, Liyuan Chang |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2025 | Toward Efficient Network Traffic Classifications via Multimodal LearningabstractWith revolutionized various real-time and cyber-physical applications, today’s networked systems face more threats of cyberattacks due to their expansive networking attack surface. One promising trend is to deploy deep learning network (DNN) models to classify and identify cyberattacks at the network layer to identify either malicious traffic or anomaly traffic as alerts. However, deploying DNN models to classify network traffic will compromise the efficiency requirements of networked systems since high-performance DNN models are usually complex at inference. With more attack surfaces in today’s networked system, more complex DNN models are required to fulfill the feature extraction. In this paper, we propose a multi-model learning approach for both accurate and efficient traffic classification to address the above challenge. Our key insight is that network traffic is multi-model data including structured data (e.g., protocol text) and non-structured data (e.g., packets). By designing different lightweight feature extractors, we extract features of multi-modal data via language models and linear models respectively, and fuse features from heterogeneous network traffic data to classify and identify typical cyberattacks. Experimenting with showcases of adopting classic learning methods indicates that our approach can achieve an accurate and efficient network traffic classification to ensure the security of networked systems. Liyuan Chang, Bin Cao 0002 |
IEEE Internet Things J. | 1 |
| 2025 | N3PA-STIN: A Novel Three-Party Authentication Protocol for Multiuser Access in Satellite Terrestrial Integrated NetworksabstractSatellite-Terrestrial Integrated Network (STIN) serves as essential infrastructure for providing seamless global coverage and wireless remote subscription services. However, the inherent heterogeneity, satellite exposure, and the openness of satellite-terrestrial links pose significant security challenges for authentication, such as privacy breaches, eavesdropping, replay attacks, and identity impersonation, as well as scalability issues like dynamic node joining and revocation. Existing authentication protocols suffer from deficiencies in unlinkability, scalability, and resistance to multiple attacks, and often rely on overly optimistic assumptions regarding satellite trustworthiness. Moreover, performance bottlenecks in handling numerous user access authentication requests within short timeframes remain unresolved. To address these challenges, we propose the N3PA-STIN protocol, a novel three-party authentication protocol for multi-user access that ensures mutual trust among users, satellites, and ground stations. The protocol minimizes computational overhead through an efficient batch verification mechanism, and enhances privacy and unlinkability by employing temporary identifiers derived from one-time pseudonyms. Furthermore, the protocol ensures conditional anonymity, enabling accountability while preserving user privacy, and achieves conditional verifiability by restricting the verification of authentication messages exclusively to registered nodes. A domain key update mechanism based on the Chinese Remainder Theorem (CRT) supports dynamic node management, effectively addressing the scalability challenges in heterogeneous networks. Security and performance analyses demonstrate that the N3PA-STIN protocol meets the security requirements and minimizes both computational and communication overhead, making it a practical and effective solution for STIN. Junyan Guo, Shuang Yao, Liyuan Chang |
IEEE Internet Things J. | 6 |
| 2024 | DoS-Dam: a Hierarchical Method for Identifying and Mitigating DDoS Attacks in High-Speed Network TrafficabstractAs the prevalence of high-speed networks with augmented transmission capacities expands, the security technologies devised to shield these networks lag behind the rapid advancements. This disparity leads to many issues, with Distributed Denial of Service (DDoS) attacks representing the most harmful. In such attacks, hackers exploit numerous bots to flood the target with a torrent of vicious traffic or spurious requests, leading to the paralysis of the communication framework and the interruption of essential services. Existing defense mechanisms against DDoS attacks struggle to reconcile detection speed, lead time, and accuracy, revealing several deficiencies. Our method begins by employing a sketch-based algorithm characterized by minimal computational demands paired with considerable swiftness. This strategy significantly mitigates the intensity of DDoS attacks and reduces the imbalance rate of benign traffic and attacks. Subsequently, the deployment of the CatBoost classifier augments the detection's F1-score to$9 9. 6 4 \%$. The experimental findings corroborate the efficacy of DDoS-Dam in the expeditious detection and mitigation of DDoS attacks in high-speed networks. Yihang Hao, Liyuan Chang, Haizhen Qi, Jin'ao Cuil |
ICNP | 2 |
| 2024 | Network anomaly detection via similarity-aware ensemble learning with ADSimabstractThe last decade has seen the increasing application of machine learning to various tasks, including network anomaly detection . But anomaly detection methods based on a single machine learning algorithm usually fail to achieve good results, since network traffic have complex and changeable patterns. Therefore, many solutions based on ensemble learning have been proposed to address this problem. However, most previous studies have the main drawback that they overlook the similarity between the weak classifiers , which may degrade the detection performance. What is more, most existing works use offline and supervised algorithms, which means a large number of computing resources and reliable labels are necessary during the training period. In this paper, we propose ADSim , an online, unsupervised, and similarity-aware network anomaly detection algorithm based on ensemble learning. For a similarity-aware scheme, the target of ADSim can be intuitively described as recognizing the similar weak classifiers during the training phase and treat them as a whole. To achieve this, ADSim first incrementally maintains a distance matrix to record the similarity between the classifiers in the training phase and uses Hierarchy Clustering to group the similar classifiers. In the detecting phase, each cluster will be assigned a weight depending on the consistency of the detection results of the classifiers within it. Moreover, the working procedure of ADSim is online and unsupervised, which significantly improves its practicality. We test ADSim on two datasets, MAWILab and CIC-IDS-2017. The results show that ADSim outperforms the state-of-the-art ensemble learning methods and has ideal runtime performance. Liyuan Chang, Ying Zhong 0008, Chenxin Duan, Xia Yin 0001, Jiahai Yang 0001, Xingang Shi |
Comput. Networks | 3 |
| 2024 | Investigating Deployment Issues of DNS Root Server Instances From a China-Wide ViewabstractDNS root servers are the starting point of most DNS queries. To ensure their security and stability, multiple anycast instances are operated worldwide, and new root instances have been rapidly deployed in recent years. Apart from authorized instances managed by Root Server System, some networks equip unauthorized instances to hijack queries from clients. Despite various root instances handling queries within their residing networks, few studies have focused on the deployment issues of these instances. In this paper, we provide the first study to reveal the deployment issues of root instances from a nationwide view. With the support of 7,860 vantage points, we utilized a suite of methodologies to identify the deployment of unauthorized instances. 54 vantage points witnessed the evidence of unauthorized instances, and 70.4% of them further observed security issues of unauthorized instances, including DoS, unavailability of DNSSEC validation, and vulnerable DNS software. Additionally, we utilized the side-channel information of censorship mechanisms to measure the catchment area of authorized instances. We found that most authorized instances in the Chinese mainland serve with limited catchment areas due to restricted BGP policies. Through discussions with ISPs and network operators, we make recommendations to improve the deployment status of different root instances. Fenglu Zhang, Baojun Liu 0002, Chaoyi Lu, Yunpeng Xing, Hai-Xin Duan, Ying Liu 0024, Liyuan Chang |
IEEE Trans. Dependable Secur. Comput. | 7 |