Jingnan Dong

dblp:260/8034 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0001-7718-7334ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 2 first-author · 8 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Interpretable intrusion detection for IoT security: A SHAP-enhanced NGBoost model
Jingnan Dong, Haolei Chen, Shigen Shen, Huibin Xu, Zhiquan Liu 0001
Comput. Networks1
2026 Privacy-Aware DRL for Differential Games-Assisted Malware Defense in Edge Intelligence-Enabled Social IoT
abstract
The edge intelligence-enabled Social Internet of Things (SIoT) faces severe security threats from stealthy malware propagation, while existing defenses struggle to model complex behaviors or provide real-time and privacy-aware responses. Herein, we propose a comprehensive malware defense framework integrating a five-state propagation model, continuous-time differential games, and a privacy-aware reinforcement learning algorithm named PP-D3QN (Privacy-Preserving Dueling Double Deep Q Network). The malware propagation model includes susceptible, infectious, patched, quarantined, and removed states, accurately representing centralized and cooperative patching as well as quarantine detection mechanisms. Leveraging differential games, optimal defense strategies are theoretically derived by solving the Hamilton–Jacobi– Bellman equation, dynamically balancing infection risk, patching benefits, and quarantine costs. The PP-D3QN algorithm employs prioritized experience replay with strict control over private data sampling and Gaussian noise perturbation to ensure differential privacy, while learning effective defense strategies through practical interaction with dynamic edge intelligence-enabled SIoT systems. Extensive simulations demonstrate that the proposed method significantly improves malware suppression speed and SIoT nodes recovery rates, showcasing strong theoretical and practical value. This work offers a rigorous and applicable solution for dynamic malware defense under privacypreserving constraints in edge intelligence-enabled SIoT systems.
Shigen Shen, Yizhou Shen, Jingnan Dong, Tian Wang 0001, Ruidong Li 0001
IEEE Trans. Netw. Serv. Manag.5
2025 Deep-Reinforcement-Learning-Based Botnet Propagation Control in the Social Internet of Things
abstract
The rapid development of the social Internet of Things (IoT) enhances interconnectivity but also raises significant network security challenges, particularly from botnet attacks that disrupt system stability. Addressing this issue requires effective strategies to control botnet propagation in social IoT environments. This study develops a social IoT botnet propagation model incorporating social factors to analyze their influences on its propagation dynamics. Based on this, a social IoT botnet propagation control framework is constructed, formulating an optimization problem using Markov games. To solve the optimization problem, we propose SD-DRQN (Social-Dynamics Deep Recurrent Q-Network), a novel deep reinforcement learning algorithm that integrates Long Short-Term Memory (LSTM) layers to improve learning in dynamic social IoT environments. Experimental results validate the performance of the proposed SD-DRQN across various social IoT scenarios, including complex real-world topologies. The algorithm demonstrates faster convergence, superior generalization, and practical applicability, making it an effective solution for botnet propagation control in real-world social IoT deployments.
Shigen Shen, Xuanbin Hao, Yizhou Shen, Huibin Xu, Jingnan Dong, Zhaoxi Fang, Zongda Wu
IEEE Internet Things J.5
2025 An efficient vehicular network anomaly detection framework based on encoder and dynamic threshold adjustment
Huibin Xu, Long Fang, Jingnan Dong, Jishui Shi
Peer Peer Netw. Appl.3
2025 RMAAC: Joint Markov Games and Robust Multiagent Actor-Critic for Explainable Malware Defense in Social IoT
abstract
The end-edge-cloud-based Social Internet of Things (SIoT) faces increasing threats from malware. To address these challenges, we propose an explainable novel malware defense framework that integrates Markov games with multi-agent deep reinforcement learning under an end-edge-cloud-based SIoT collaborative architecture. The framework models the interactions between malicious SIoT nodes and edge devices as a multi-agent game problem, incorporating multi-layer defense mechanisms to achieve precise descriptions of attack-defense behaviors. By combining Markov games with the Multi-Agent Deep Deterministic Policy Gradient (MADDPG) algorithm, we develop the Robust Multiagent Actor-Critic (RMAAC) algorithm, which enables adaptive strategy optimization. To enhance system interpretability, we introduce SHapley Additive exPlanations (SHAP) value analysis into the defense decision-making process, providing transparent insights into feature contributions and decision rationales. Extensive experimental results demonstrate that the proposed RMAAC algorithm significantly outperforms existing methods, including MADDPG and Minimax Multi-Agent Deep Deterministic Policy Gradient (M3DDPG), in multiple performance metrics such as episode reward, hacking success rate, and cumulative defense number. Through systematic parameter optimization, including batch size and agent interaction speed, the framework provides an effective and sustainable solution for explainable malware defense in SIoT environments.
Shigen Shen, Yizhou Shen, Jingnan Dong, Jie Wu 0001
IEEE Trans. Dependable Secur. Comput.5
2024 DID-HVC-based Web3 healthcare data security and privacy protection scheme
Xiaoling Song, Guangxia Xu, Yongfei Huang, Jingnan Dong
Future Gener. Comput. Syst.4
2024 Blockchain-Based Certificate-Free Cross-Domain Authentication Mechanism for Industrial Internet
abstract
In Industrial Internet, mutual authentication between enterprises is a prerequisite for establishing reliable upstream and downstream relationships. Existing authentication methods suffer from complicated certificate management and key escrow problems. Moreover, many authentication mechanisms cannot resist common security attacks and have high computational overhead and communication costs. Therefore, this paper proposes a blockchain-based certificate-free cross-domain authentication mechanism for Industrial Internet. By establishing an Ethereum consortium blockchain as the trusted cornerstone among different regions, industrial enterprises in each region generate the user’s private key with the key generation center in the region, thus avoiding the key escrow problem. This consortium blockchain adopts the proof of authority consensus mechanism for scalability and throughput. Industrial enterprises in different regions invoke smart contracts and query other industrial enterprises for mutual authentication and key negotiation. SVO logic proves the proposed scheme achieves the intended authentication goal, and the automated formal verification tool Scyther proves the scheme’s security. In addition, compared with seven related schemes in the last three years, the experimental results show that the proposed scheme has low communication overhead and computational cost in the authentication key negotiation phase. The experiments on the Ethereum consortium blockchain built by Raspberry Pi prove the effectiveness of the proposed scheme. Finally, the comparative analysis of common security properties proves the reliability of the scheme.
Jingnan Dong, Guangxia Xu, Jun Liu 0044, Uchani Gutierrez Omar Cliff
IEEE Internet Things J.1
2023 A Certificateless Signcryption Mechanism Based on Blockchain for Edge Computing
abstract
The emergence of edge computing makes it possible to realize new technologies, such as virtual reality and augmented reality. However, a large number of devices and more messages at the edge bring more security problems. Therefore, it is an important research topic to provide users with faster network services while ensuring confidentiality and authentication of data transmission. Because signcryption can encrypt and sign messages at the same time, it has become a new cryptographic primitive. In the meantime, certificateless signcryption guarantees data confidentiality and authentication and addresses traditional single point failure problems based on the trust center and the problem of relying on a trusted third party. Therefore, certificateless signcryption has attracted great attention from academia and industry. But certificateless signcryption also faces two types of attacks. In order to more effectively resist these two types of attacks, we propose a certificateless signcryption mechanism based on blockchain. This mechanism can make good use of the nontamperable feature of blockchain, prevent illegal users from substituting the public key of the user, and guarantee signature nonrepudiation. And our scheme is investigated in a comparative study with eight schemes. Comparative analysis outcomes demonstrate our scheme has achieved better results in efficiency and security. The process of signcryption and unsigncryption consumes the least amount of computation, which is very suitable for the edge computing environment.
Guangxia Xu, Jingnan Dong, Jun Liu 0044, Uchani Gutierrez Omar Cliff
IEEE Internet Things J.2
2023 A Blockchain-Based Federated Learning Scheme for Data Sharing in Industrial Internet of Things
abstract
As the Industrial Internet of Things (IIoT) continues to grow in scale, edge devices will generate massive amounts of data every single day. However, most of the IIoT data exists in the form of data silos, which makes it difficult to share data across domains securely. Therefore, a secured data-sharing scheme for IIoT based on blockchain and federated learning (FL) is proposed in this article. Leveraging blockchain in FL systems to enhance the tamper-proof and decentralized capabilities of IIoT devices. Model parameter validation and incentives are also added to the consensus algorithm to encourage more IIoT data owners to contribute local privacy data and arithmetic power. To address potential security issues, such as parameter leakage and inference attacks in data sharing, this article designs an adaptive differential privacy mechanism and a node contribution consensus mechanism. Without affecting the global model’s accuracy, some of the noise is also reduced. The reputation mechanism is used to resist poisoning attacks by malicious nodes. It is demonstrated on different data sets that our scheme has high global model accuracy and can effectively resist 30% model poisoning attacks.
Guangxia Xu, Zhaojian Zhou, Jingnan Dong, Lejun Zhang, Xiaoling Song
IEEE Internet Things J.3
2021 A certificateless encryption scheme based on blockchain
Guangxia Xu, Jingnan Dong
Peer-to-Peer Netw. Appl.2