Kaiqi Xiong

dblp:27/5547 · DBLP profile ↗
← Back
51ranked-venue papers
16as first author
15since 2021 · last 2025
0000-0003-2933-8083ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 20 · 5 first-author · 8 since 2021Security and privacy · 10 · 2 first-author · 3 since 2021Systems, architecture and hardware · 9 · 7 first-authorHuman-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 SDN-Based False Data Detection With Its Mitigation and Machine Learning Robustness for In-Vehicle Networks
abstract
As the development of autonomous and connected vehicles advances, the complexity of modern vehicles increases, with numerous Electronic Control Units (ECUs) integrated into the system. In an in-vehicle network, these ECUs communicate with one another using a standard protocol called Controller Area Network (CAN). Securing communication among ECUs plays a vital role in maintaining the safety and security of the vehicle. This paper proposes a robust SDN-based False Data Detection and Mitigation System (FDDMS) for in-vehicle networks. Leveraging the unique capabilities of Software-Defined Networking (SDN), FDDMS is designed to monitor and detect false data injection attacks in real-time. Specifically, we focus on brake-related ECUs within an SDN-enabled in-vehicle network. First, we decode raw CAN data to create an attack model that illustrates how false data can be injected into the system. Then, FDDMS, incorporating a Long Short-Term Memory (LSTM)-based detection model, is used to identify false data injection attacks. We further propose an effective variant of the DeepFool attack to evaluate the model’s robustness. To countermeasure the impacts of four adversarial attacks including Fast gradient descent method, Basic iterative method, DeepFool, and the DeepFool variant, we further enhance a re-training technique method with a threshold based selection strategy. Finally, a mitigation scheme is implemented to redirect attack traffic by dynamically updating flow rules through SDN. Our experimental results show that the proposed FDDMS is robust against adversarial attacks and effectively detects and mitigates false data injection attacks in real-time.
Long Dang, Thushari Hapuarachchi, Kaiqi Xiong
ICCCN3
2025 Securing Traffic Sign Recognition Systems in Autonomous Vehicles
abstract
Deep Neural Networks (DNNs) are widely used for traffic sign recognition because they can automatically extract high-level features from images. These DNNs are trained on large-scale datasets obtained from unknown sources. Therefore, it is important to ensure that the models remain secure and are not compromised or poisoned during training. In this paper, we investigate the robustness of DNNs trained for traffic sign recognition. First, we perform the error-minimizing attacks on DNNs used for traffic sign recognition by adding imperceptible perturbations on training data. Then, we propose a data augmentation-based training method to mitigate the error-minimizing attacks. The proposed training method utilizes nonlinear transformations to disrupt the perturbations and improve the model robustness. We experiment with two well-known traffic sign datasets to demonstrate the severity of the attack and the effectiveness of our mitigation scheme. The error-minimizing attacks reduce the prediction accuracy of the DNNs from 99.90% to 10.6%. However, our mitigation scheme successfully restores the prediction accuracy to 96.05%. Moreover, our approach outperforms adversarial training in mitigating the error-minimizing attacks. Furthermore, we propose a detection model capable of identifying poisoned data even when the perturbations are imperceptible to human inspection. Our detection model achieves a success rate of over 99% in identifying the attack. This research highlights the need to employ advanced training methods for DNNs in traffic sign recognition systems to mitigate the effects of data poisoning attacks.
Thushari Hapuarachchi, Long Dang, Kaiqi Xiong
ICCCN3
2025 Advancing ensemble learning against unlearnable data
Thushari Hapuarachchi, Kaiqi Xiong
Neurocomputing2
2024 Redefining DDoS Attack Detection Using A Dual-Space Prototypical Network-Based Approach
abstract
Distributed Denial of Service (DDoS) attacks pose an increasingly substantial cybersecurity threat to organizations across the globe. In this paper, we introduce a new deep learning-based technique for detecting DDoS attacks, a paramount cyber-security challenge with evolving complexity and scale. Specifically, we propose a new dual-space prototypical network that leverages a unique dual-space loss function to enhance detection accuracy for various attack patterns through geometric and angular similarity measures. This approach capitalizes on the strengths of representation learning within the latent space (a lower-dimensional representation of data that captures complex patterns for machine learning analysis), improving the model’s adaptability and sensitivity towards varying DDoS attack vectors. Our comprehensive evaluation spans multiple training environments, including offline training, simulated online training, and prototypical network scenarios, to validate the model’s robustness under diverse data abundance and scarcity conditions. The Multilayer Perceptron (MLP) with Attention, trained with our dual-space prototypical design over a reduced training set, achieves an average accuracy of 94.85% and an F1-Score of 94.71% across our tests, showcasing its effectiveness in dynamic and constrained real-world scenarios.
Fernando Martínez-López, Mariyam Mapkar, Ali Alfatemi, Mohamed Rahouti, Yufeng Xin, Kaiqi Xiong, Nasir Ghani
ICCCN6
2024 Exploring Feature Importance and Explainability Towards Enhanced ML-Based DoS Detection in AI Systems
abstract
Denial of Service (DoS) attacks pose a significant threat to AI systems security, causing substantial financial losses and downtime. However, AI systems’ high computational demands, dynamic behavior, and data variability make monitoring and detecting DoS attacks challenging. Nowadays, statistical and machine learning (ML)-based DoS classification and detection approaches utilize a broad range of feature selection mechanisms to select a feature subset from networking traffic datasets. Feature selection is critical in enhancing the overall model performance and attack detection accuracy while reducing the training time. In this paper, we investigate the importance of feature selection in improving ML-based detection of DoS attacks. Specifically, we explore feature contribution to the overall components in DoS traffic datasets by utilizing statistical analysis and feature engineering approaches. Our experimental findings demonstrate the usefulness of the thorough statistical analysis of DoS traffic and feature engineering in understanding the behavior of the attack and identifying the best feature selection for ML-based DoS classification and detection.
Lesther Santana, Paul Badu Yakubu, Evans Owusu, Mohamed Rahouti, Abdellah Chehri, Kaiqi Xiong, Yufeng Xin
VTC Fall6
2023 Improving Machine Learning Robustness via Adversarial Training
abstract
As Machine Learning (ML) is increasingly used in solving various tasks in real-world applications, it is crucial to ensure that ML algorithms are robust to any potential worst-case noises, adversarial attacks, and highly unusual situations when they are designed. Studying ML robustness will significantly help in the design of ML algorithms. In this paper, we investigate ML robustness using adversarial training in centralized and decentralized environments, where ML training and testing are conducted in one or multiple computers. In the centralized environment, we achieve a test accuracy of 65.41% and 83.0% when classifying adversarial examples generated by Fast Gradient Sign Method and DeepFool, respectively. Comparing to existing studies, these results demonstrate an improvement of 18.41% for FGSM and 47% for DeepFool. In the decentralized environment, we study Federated learning (FL) robustness by using adversarial training with independent and identically distributed (IID) and non-IID data, respectively, where CIFAR-10 is used in this research. In the IID data case, our experimental results demonstrate that we can achieve such a robust accuracy that it is comparable to the one obtained in the centralized environment. Moreover, in the non-IID data case, the natural accuracy drops from 66.23% to 57.82%, and the robust accuracy decreases by 25% and 23.4% in C&W and Projected Gradient Descent (PGD) attacks, compared to the IID data case, respectively. We further propose an IID data-sharing approach, which allows for increasing the natural accuracy to 85.04% and the robust accuracy from 57% to 72% in C&W attacks and from 59% to 67% in PGD attacks.
Long Dang, Thushari Hapuarachchi, Kaiqi Xiong
ICCCN3
2022 From adversarial examples to data poisoning instances: utilizing an adversarial attack method to poison a transfer learning model
abstract
Despite the wide-ranging applicability of machine learning methods, they are vulnerable to security attacks, such as evasion attacks and triggerless data poisoning attacks. An evasion attack occurs at the inference time when an attacker feeds in an adversarial example, a malicious perturbed input that appears the same as its untampered copy to a human oracle. In contrast, a triggerless data poisoning attack occurs at training time. An attacker tries to subvert learning with injected poisoned instances. In this research, we focus on a special sub-category of data poisoning attacks, namely triggerless clean-label targeted data poisoning attacks. This type of attacks is more realistic in the sense that it does not require an attacker to have the ability to change the label of any training instance. That is, attackers can successfully attack the training process with a poison instance that is correctly labeled by a human oracle. We propose a simple but effective way to alter an adversarial attack method into a triggerless clean-label targeted data poisoning attack method with a remarkable attack success rate. Furthermore, our proposed method only requires the injection of a single poison instance to manipulate a transfer learning model to misclassify an untampered targeted instance. We compare our method with a popular one-shot attack and show that our method is easier to be used as we do not need to tune for a hyperparameter such as a similarity coefficient.
Ryan Luley, Kaiqi Xiong
ICC3
2022 Route recommendation for evacuation networks using MMPP/M/1/N queueing models
Ting Sun 0006, Kaiqi Xiong, Chuangbai Xiao
Comput. Commun.3
2022 Secure machine learning against adversarial samples at test time
abstract
Abstract Deep neural networks (DNNs) are widely used to handle many difficult tasks, such as image classification and malware detection, and achieve outstanding performance. However, recent studies on adversarial examples, which have maliciously undetectable perturbations added to their original samples that are indistinguishable by human eyes but mislead the machine learning approaches, show that machine learning models are vulnerable to security attacks. Though various adversarial retraining techniques have been developed in the past few years, none of them is scalable. In this paper, we propose a new iterative adversarial retraining approach to robustify the model and to reduce the effectiveness of adversarial inputs on DNN models. The proposed method retrains the model with both Gaussian noise augmentation and adversarial generation techniques for better generalization. Furthermore, the ensemble model is utilized during the testing phase in order to increase the robust test accuracy. The results from our extensive experiments demonstrate that the proposed approach increases the robustness of the DNN model against various adversarial attacks, specifically, fast gradient sign attack, Carlini and Wagner (C&W) attack, Projected Gradient Descent (PGD) attack, and DeepFool attack. To be precise, the robust classifier obtained by our proposed approach can maintain a performance accuracy of 99% on average on the standard test set. Moreover, we empirically evaluate the runtime of two of the most effective adversarial attacks, i.e., C&W attack and BIM attack, to find that the C&W attack can utilize GPU for faster adversarial example generation than the BIM attack can. For this reason, we further develop a parallel implementation of the proposed approach. This parallel implementation makes the proposed approach scalable for large datasets and complex models.
Laurent Njilla, Kaiqi Xiong
EURASIP J. Inf. Secur.3
2021 An Adversarial Attack Defending System for Securing In-Vehicle Networks
abstract
In a modern vehicle, there are over seventy Electronics Control Units (ECUs). For an in-vehicle network, ECUs communicate with each other by following a standard communication protocol, such as Controller Area Network (CAN). However, an attacker can easily access the in-vehicle network to compromise ECUs through a WLAN or Bluetooth. Though there are various deep learning (DL) methods suggested for securing in-vehicle networks, recent studies on adversarial examples have shown that attackers can easily fool DL models. In this research, we further explore adversarial examples in an in-vehicle network. We first discover and implement two adversarial attack models that are harmful to a Long Short Term Memory (LSTM)-based detection model used in the in-vehicle network. As shown in our experiments, adversaries can attack the LSTM-based detection model with a success rate of over 98%. Then, we propose an Adversarial Attack Defending System (AADS) for securing an in-vehicle network. Specifically, we focus on brake-related ECUs in an in-vehicle network. Our extensive experimental results demonstrate that the proposed AADS achieves over 99 % accuracy for detecting adversarial attacks.
Yi Li 0023, Kaiqi Xiong
CCNC3
2021 A Priority-Based Queueing Mechanism in Software-Defined Networking Environments
abstract
To support latency-sensitive applications (e.g., emergency response) in Software-Defined Networking (SDN) environments, reliable Quality of Service (QoS) mechanisms are needed to ensure the minimization of end-to-end (E2E) latency and control response time. In this research, we design a double-queue system with feedback, named QoSP, to improve data-control communication performance and impose efficient queueing control in SDN. We further study a priority-based queueing scheme to achieve differentiated QoS provisioning via maintaining multiple OpenFlow queues with different priorities at the switch ports of a data plane. The prototype of QoSP is implemented and evaluated on the NSF-sponsored GENI testbed.
Mohamed Rahouti, Kaiqi Xiong, Yufeng Xin, Nasir Ghani
CCNC2
2021 Active Learning Under Malicious Mislabeling and Poisoning Attacks
abstract
Deep neural networks usually require large labeled datasets for training to achieve state-of-the-art performance in many tasks, such as image classification and natural language processing. Although a lot of data is created each day by active Internet users, most of these data are unlabeled and are vulnerable to data poisoning attacks. In this paper, we develop an efficient active learning method that requires fewer labeled instances and incorporates the technique of adversarial retraining in which additional labeled artificial data are generated without increasing the budget of the labeling. The generated adversarial examples also provide a way to measure the vulnerability of the model. To check the performance of the proposed method under an adversarial setting, i.e., malicious mislabeling and data poisoning attacks, we perform an extensive evaluation on the reduced CIFAR-10 dataset, which contains only two classes: airplane and frog. Our experimental results demonstrate that the proposed active learning method is efficient for defending against malicious mislabeling and data poisoning attacks. Specifically, whereas the baseline active learning method based on the random sampling strategy performs poorly (about 50%) under a malicious misla-beling attack, the proposed active learning method can achieve the desired accuracy of 89% using only one-third of the dataset on average.
Ryan Luley, Kaiqi Xiong
GLOBECOM3
2021 QoSP: A Priority-Based Queueing Mechanism in Software-Defined Networking Environments
abstract
Software-defined networking (SDN) is an emerging networking technology and allows for a separation of data and control planes traffic in order to enhance the Quality of Service (QoS) for traffic and services delivery. Latency metric is regarded as a critical parameter by service providers and end users alike, where inter-link delays can be measured using end-to-end (E2E) probing packets. Moreover, to support latency-sensitive applications in SDN such as emergency response, we need a comprehensive QoS mechanism to ensure the minimization of E2E latency, the efficacious calculation of forwarding paths, and the minimization of control response time. We first distinguish between a flow’s admission latency and a flow’s packet forwarding latency. The former is decided by its controller’s response time, and the latter by its data plane queue delay. We then design a two-queue system with feedback, named QoSP, that aims to control overall latency performance in SDN through improving data-control communication performance and imposing efficient queueing control. We specifically introduce a priority-based queueing discipline in the data plane to achieve differentiated QoS provisioning via maintaining multiple OpenFlow queues with different priorities at each switch port. We implement the proposed QoSP using a Floodlight SDN controller and conduct emulation studies on the Global Environment for Networking Innovations. Our evaluation shows that QoSP can optimize the E2E delay and significantly reduce the control response time for priority traffic.
Mohamed Rahouti, Kaiqi Xiong, Yufeng Xin, Nasir Ghani
IPCCC2
2021 Mahalanobis distance-based robust approaches against false data injection attacks on dynamic power state estimation
Kaiqi Xiong
Comput. Secur.2
2021 A survey on security attacks and defense techniques for connected and autonomous vehicles
Kaiqi Xiong
Comput. Secur.2
2020 Robust Machine Learning against Adversarial Samples at Test Time
abstract
Though the performance of deep learning is remarkable, recent works have shown that deep learning models are vulnerable to adversarial samples that are close to their original samples to human eyes but misclassified by Deep Neural Network (DNN). This is a serious problem as many deep learning models are used in physical infrastructures and critical application domains such as medical diagnosis, self-driving cars, malware detection, as well as digital assistants like Google Assistant, Alexa, and Siri. Many researchers have attempted to secure neural networks through techniques such as defensive distillation and adversarial retraining. Nevertheless, many of these techniques are ineffective to new or slightly strong adversarial attacks such as the Carlini and Wagner (C&W)'s attack. In this paper, we propose a robust adversarial retraining method to iteratively retrain a given model so that it can not only detect the adversarial examples but also maintain the prediction accuracy for the normal dataset. Our experimental results show that the prediction accuracy on the MNIST test set is maintained while the accuracies under FGSM, C&W, and DeepFool attacks increase from 29% to 91%, 7% to 70%, and 29% to 91%, respectively.
Laurent Njilla, Kaiqi Xiong
ICC3
2019 A Customized Educational Booster for Online Students in Cybersecurity Education
Mohamed Rahouti, Kaiqi Xiong
CSEDU (2)2
2019 Understanding User Behaviors When Phishing Attacks Occur
abstract
To study user security-related behaviors, we conduct an experimental study where participants take part in our experiments in a lab contained environment. We used a set of emails including phishing emails from the real world. We collect data including participants' basic information and time measurement. We check whether or not factors such as intervention, phishing types, and incentive mechanisms play a major role in user behaviors when phishing attacks occur.
Yi Li 0023, Kaiqi Xiong
ISI2
2019 LatencySmasher: A Software-Defined Networking-Based Framework for End-to-End Latency Optimization
abstract
The centralized control capability of Software Defined Networking (SDN) presents a unique opportunity for enabling Quality of Service (QoS) routing. For delay sensitive traffic flows, a QoS mechanism requires efficiently computing path latency and minimizing controller's response time. At the core of the challenges is how to handle short term network state fluctuations in terms of congestion and latency while guaranteeing the end-to-end latency performance of networking services. In this paper, we present LatencySmasher, a systematic framework that considers active link latency measurements, efficient statistic estimate of network states, and fast adaptive path computation. We first implement LatencySmasher as an SDN controller application and then conduct extensive experimental studies on the Global Environment for Network Innovations (GENI), a real-world distributed network testbed. Our performance evaluation shows that the proposed framework can find optimal end-to-end paths with minimum latency and significantly reduce the control overhead.
Mohamed Rahouti, Kaiqi Xiong, Yufeng Xin, Nasir Ghani
LCN2
2018 A Machine Learning Framework for Studying Domain Generation Algorithm (DGA)-Based Malware
Tommy Chin, Kaiqi Xiong, Chengbin Hu, Yi Li 0023
SecureComm (1)2
2018 KrackCover: A Wireless Security Framework for Covering KRACK Attacks
Tommy Chin, Kaiqi Xiong
WASA2
2017 An SDN Based Framework for Guaranteeing Security and Performance in Information-Centric Cloud Networks
abstract
Cloud data centers are critical infrastructures to deliver cloud services. Although security and performance of cloud data centers have been well studied in the past, their networking aspects are overlooked. Current network infrastructures in cloud data centers limit the ability of cloud provider to offer guaranteed cloud network resources to users. In order to ensure security and performance requirements as defined in the service level agreement (SLA) between cloud user and provider, cloud providers need the ability to provision network resources dynamically and on the fly. The main challenge for cloud provider in utilizing network resource can be addressed by provisioning virtual networks that support information centric services by separating the control plane from the cloud infrastructure. In this paper, we propose an sdn based information centric cloud framework to provision network resources in order to support elastic demands of cloud applications depending on SLA requirements. The framework decouples the control plane and data plane wherein the conceptually centralized control plane controls and manages the fully distributed data plane. It computes the path to ensure security and performance of the network. We report initial experiment on average round-trip delay between consumers and producers.
Uttam Ghosh, Pushpita Chatterjee, Deepak K. Tosh, Sachin Shetty, Kaiqi Xiong, Charles A. Kamhoua
CLOUD5
2017 A payment scheme in crowdsourcing
abstract
Crowdsourcing coordinates a large group of workers online to do self-contained small tasks that are published by job requesters on a crowdsourcing platform. Many papers propose incentive strategies to motivate workers to participate in crowdsourcing. In this paper, we shift the focus from the workers to the job requesters by addressing two of their issues: how to design a good payment scheme to maximize profit and how to select qualified workers to do the job. We use a widely-adopted payment formula consisting of a base salary and extra bonus. We first formulate the problem as an optimization problem and then provide a general solution in which we show that the pay rate can be the same to all the workers. Next we instantiate the solution with a concrete example to derive more concrete results and propose a worker selection algorithm WS. In WS, we not only consider workers' workload demands but also their past working performance to guarantee crowdsourcing quality. Simulation results show that a job requester can pay much less to get the job done in a crowdsourcing environment and our worker selection algorithm is efficient in that it only searches a tiny space to find the solution to the optimization problem. Our effort here provides an evidence to support the benefits of using crowdsourcing in our daily lives.
Xiao Chen 0001, Kaiqi Xiong
ICC2
2017 A Forensic Methodology for Software-Defined Network Switches
Tommy Chin, Kaiqi Xiong
IFIP Int. Conf. Digital Forensics2
2017 SDN-Based Kernel Modular Countermeasure for Intrusion Detection
Tommy Chin, Kaiqi Xiong, Mohamed Rahouti
SecureComm2
2016 MPBSD: A Moving Target Defense Approach for Base Station Security in Wireless Sensor Networks
Tommy Chin, Kaiqi Xiong
WASA2
2015 Nonlinear target tracking for threat detection using RSSI and optical fusion
Tommy Chin, Kaiqi Xiong, Erik Blasch
FUSION2
2015 Detecting Driver Drowsiness Using Wireless Wearables
abstract
The National Highway Traffic Safety Administration data show that drowsy driving causes more than 100,000 crashes a year. In order to prevent these devastating accidents, it is necessary to build a reliable driver drowsiness detection system which could alert the driver before a mishap happens. In the literature, the drowsiness of a driver can be measured by vehicle-based, behavior-based, and physiology-based approaches. Comparing with the vehicle-based and behavior-based measurements, the physiological measurement of drowsiness is more accurate. With the latest release of wireless wearable devices such as biosensors that can measure people's physiological data, we aim to explore the possibility of designing a user-friendly and accurate driver drowsiness detection system using wireless wearables. In this paper, we use a wearable biosensor called Bio Harness 3 produced by Zephyr Technology to measure a driver's physiological data. We present our overall design idea of the driver drowsiness detection system and the preliminary experimental results using the biosensor. The detection system will be designed in two phases: The main task of the first phase is to collect a driver's physiological data by the biosensor and analyze the measured data to find the key parameters related to the drowsiness. In the second phase, we will design a drowsiness detection algorithm and develop a mobile app to alert drowsy drivers. The results from this project can lead to the development of real products which can save many lives and avoid many accidents on the road. Furthermore, our results can be widely applied to any situation where people should not fall asleep: from the applications in mission-critical fields to the applications in everyday life.
Brandy Warwick, Nicholas Symons, Xiao Chen 0001, Kaiqi Xiong
MASS4
2015 An improved IEEE 802.11 CSMA/CA medium access mechanism through the introduction of random short delays
abstract
The work in this paper studies the performance of Carrier Sense Multiple Access/Collision Avoidance (CSMA/CA) medium access control (MAC) mechanism in IEEE 802.11 DCF. From studying the propagation delay and clock synchronization differences between terminals, it is concluded that the slight timing differences, effectively a relative jitter, contributes to reducing the probability of collisions after a MAC backoff. This lesson is leveraged in a presented new CSMA/CA MAC technique that deliberately introduces a random short delay, akin to jitter, in the backoff slots time structure. The new medium access technique is evaluated through both an analytical model and simulations that consider the realistic timing constraints set in the IEEE 802.11 standard. Simulation results show improvements in normalized saturated throughput with the new technique from at least 14% for 10 nodes up to 26% for 50 nodes.
Nirmala Shenoy, John F. Hamilton, Andres Kwasinski, Kaiqi Xiong
WiOpt4
2014 Quality of Service (QoS)-Guaranteed Network Resource Allocation via Software Defined Networking (SDN)
abstract
Quality of Service (QoS) -- based bandwidth allocation plays a key role in real-time computing systems and applications such as voice IP, teleconferencing, and gaming. Likewise, customer services often need to be distinguished according to their service priorities and requirements. In this paper, we consider bandwidth allocation in the networks of a cloud carrier in which cloud users' requests are processed and transferred by a cloud provider subject to QoS requirements. We present a QoS-guaranteed approach for bandwidth allocation that satisfies QoS requirements for all priority cloud users by using Open vSwitch, based on software defined networking (SDN). We implement and test the proposed approach on the Global Environment for Networking Innovations (GENI). Experimental results show the effectiveness of the proposed approach.
Anand V. Akella, Kaiqi Xiong
DASC2
2014 Practical Routing Protocol for Impromptu Mobile Social Networks
abstract
With the popularity of mobile devices, mobile social networks (MSNs) formed by people carrying mobile devices moving around and contacting each other have become a hot research topic these days. In this paper, we study a specific kind of MSNs that is formed impromptu (e.g. when people carrying mobile devices gather at some social events). We refer to them as Impromptu Mobile Social Networks (IMSNs). Due to the dynamic nature of such networks, routing poses special challenges. The existing social-based MSN routing algorithms that take advantage of stable social relationships or social features of people in the network may not be suitable for IMSNs. Thus, new routing algorithms that can catch node contact behavior need to be designed for IMSNs. We first propose two statistical-based theoretical routing algorithms named BerRout and PoiRout inspired by the node contact models in several papers and then put forward a practical routing algorithm UpDown which makes routing decisions based on a simple Counter capturing the ups and downs of people's relationships formed in an IMSN. We compare our algorithms with the existing social-based MSN routing algorithms by simulations. The results show that the practical algorithm performs close to the two theoretical ones and all of our proposed algorithms outperform the existing ones in terms of performance versus cost in an IMSN environment.
Xiao Chen 0001, Kaiqi Xiong, Jian Shen 0005
EUC3
2013 Security Risk Assessment of Cloud Carrier
abstract
Cloud computing based delivery model has been adopted by end-users and enterprises to reduce IT costs and complexities. The ability to offload user software and data to cloud data centers has raised many security and privacy concerns over the cloud computing model. Significant research efforts have focused on hyper visor security and low-layer operating system implementations in cloud data centers. Unfortunately, the role of cloud carrier in the security and privacy of user software and data has not been well studied. Cloud carrier represents the wide area network that provides the connectivity and transport of cloud services between cloud consumers and cloud providers. In this paper, we present a risk assessment framework to study the security risk of the cloud carrier between cloud consumers and cloud providers. The risk assessment framework leverages the National Vulnerability Database (NVD) to examine the security vulnerabilities of operating systems of routers within the cloud carrier. This framework provides quantifiable security metrics for cloud carrier, which enables cloud consumers to establish the quality of security services among cloud providers. Such security metric information is very useful in the Service Level Agreement (SLA) negotiation between a cloud consumer and a cloud provider. It can be also be used to build a tool to verify SLA compliance. Furthermore, we implement this framework for the cloud carriers of Amazon Web Services and Windows Azure Platform. Our experiments show that the security risks of cloud carriers on these two commercial clouds are significantly different. This finding provides guidance for a network provider to improve the security of cloud carriers.
Swetha Reddy Lenkala, Sachin Shetty, Kaiqi Xiong
CCGRID3
2013 Power-effiicent resource allocation in MapReduce clusters
Kaiqi Xiong, Yuxiong He
IM1
2012 Assessing network path vulnerabilities for secure cloud computing
abstract
In recent times, cloud computing based delivery model has been proven to reduce enterprise IT costs and complexities. In contrast to traditional enterprise IT solution, the cloud computing model moves the application software and data to remote servers in large datacenters, which raise many security challenges. One of the critical challenges is the inability to characterize the cloud network's impact on the cloud security and performance guarantees. In this paper, we analyze the degree of security provided by the network to data sharing applications deployed in cloud environments that span administrative and network domains. Our analysis is based on examining the security level of network applications on routers which lie between cloud subscriber and cloud provider. Our preliminary results confirm that the majority of the routers are plagued by insecure network protocols, leading to vulnerable routers. These results confirm our hypothesis that the security of the network infrastructure needs to be upgraded to assure the protection of information exchange between the cloud subscriber and cloud provider.
Sachin Shetty, Nicholas Luna, Kaiqi Xiong
ICC3
2012 Locating jamming attackers in malicious wireless sensor networks
abstract
Recent years have witnessed a rapid growth of wireless sensor network applications in civil and military environments. Radio interference tends to be a serious threat in such applications. Jamming attacks are a direct consequence of radio interference that an adversary may intentionally launch. While it is necessary to defend against jamming attacks in order for sensor communication channels to be available and reliable, it is also difficult. In this paper, we develop a systematic approach to tackling jamming attacks. We propose robust fault-tolerant algorithms for the location discovery of jamming attackers that permit us to remove jamming attackers from wireless sensor networks. Then, we investigate the proposed approach through theoretical analysis and experiments. Our analytical and numerical results demonstrate the efficiency and effectiveness of the proposed approach.
Kaiqi Xiong, David J. Thuente
IPCCC1
2012 Energy-efficient Resource Management for QoS-guaranteed Computing Clusters
abstract
A cluster computing system in data centers not only improves service availability and performance but also increase power consumption. It is a challenge to increase the performance of a cluster computing system and reduce its power consumption simultaneously. MapReduce has recently evolved in data-intensive parallel computing. It is a programming model for processing large data sets. The implementation of MapReduce typically runs on a large scale of cluster computing systems consisting of thousands of commodity machines simply called MapReduce clusters that results in high power consumption, which is a major concern by service providers such as Amazon and Yahoo. In this research, we consider a collection of cluster computing resources owned by a service provider to host an enterprise application for business customers. We investigate the problem of resource allocation for power management in MapReduce clusters. Specifically, we propose resource allocation approaches to minimizing the mean end-to-end delay of customer jobs or services under the constraints of the energy consumption and the availability of MapReduce clusters and to minimizing the energy consumption of MapReduce clusters under the availability of MapReduce clusters and the mean end-to-end delay of customer jobs or services that play an essential role in the delivery of quality of services (QoS) for customer services.. Numerical experiments demonstrate that the proposed approaches are applicable and efficient to solve these resource allocation problems for power management in MapReduce clusters.
Kaiqi Xiong
MASCOTS1
2012 The Performance of Public Key-Based Authentication Protocols
Kaiqi Xiong
NSS1
2012 Improving the localization accuracy of targets by using their spatial-temporal relationships in wireless sensor networks
Xiao Chen 0001, Neil C. Rowe, Jie Wu 0001, Kaiqi Xiong
J. Parallel Distributed Comput.4
2012 Containing bogus packet insertion attacks for broadcast authentication in sensor networks
abstract
Broadcast is a critical communication primitive in wireless sensor networks. The multihop nature of sensor networks makes it necessary for sensor nodes to forward broadcast messages so that the messages can reach an entire network. Authentication of broadcast messages is an important but challenging problem in sensor networks. Public key cryptography (PKC) has been used recently to address this problem. However, PKC-based authentication techniques are susceptible to bogus packet insertion attacks in which attackers keep broadcasting bogus messages and force resource-constrained sensor nodes to forward such messages. Moreover, because it takes time to do signature verifications, it is impractical for each node to authenticate every received message before forwarding it. In this article, we propose a dynamic window scheme to thwart the aforementioned bogus packet insertion attacks which permits sensor nodes to efficiently broadcast messages. Within this scheme, a sensor node has the ability to determine whether or not to verify an incoming message before forwarding the message. We further study the property of this dynamic window scheme and investigate the best strategy for thwarting bogus packet insertion attacks. We propose three strategies for finding the optimal parameters by an improved additive increase multiplicative decrease (AIMD) window updating function so that the proposed dynamic window scheme can achieve the best overall performance with respect to the authentication and forwarding times of messages. Numerical validations show that our proposed scheme performs very well in terms of energy saving and broadcast delays based on three different metrics, including average authentication delays, the percentage of nodes receiving fake messages, and the percentage of nodes forwarding fake messages.
Kaiqi Xiong, Ronghua Wang, Wenliang Du 0001, Peng Ning
ACM Trans. Sens. Networks1
2011 A Priority-Type Resource Allocation Approach in Cluster Computing
abstract
In cluster computing, a service provider must allocate necessary computing resources for large-scale scientific computations to process a customer's service request according to a service level agreement (SLA) that is a set of quality of services (QoS) and a fee agreed between a customer and a service provider. Thus, Resource allocation is a challenging but very necessary problem in cluster computing. In an effort to maximize a service provider's profit, it is commonplace and important to prioritize customer services in favor of those who are willing to pay higher fees. In this paper, we consider a set of computing resources owned by a service provider who serves differentiated customer services subject to an SLA for scientific applications that often require parallel computation. The QoS defined in the paper includes percentile response time and cluster utilization. We present an approach for optimal resource allocation in cluster computing systems in that we minimize the total cost of computing resources owned by a service provider while satisfying multiple priority customer service requirements. Our simulation experiments show that the proposed approach is applicable to the resource allocation in a cluster computing system with multiple customer services.
Kaiqi Xiong, Kyoung-Don Kang, Xiao Chen 0001
HPCC1
2011 Power and Performance Management in Priority-Type Cluster Computing Systems
abstract
Cluster computing not only improves performance but also increase power consumption. It is a challenge to increase the performance of a cluster computing system and reduce its power consumption simultaneously. In this paper, we consider a collection of cluster computing resources owned by a service provider to host an enterprise application for multiple class business customers where customer requests are distinguished, with different request characteristics and service requirements. We start with a development of computing an average end-to-end delay and an average energy consumption for multiple class customers in such an application. Then, we present approaches for optimizing the average end-to-end delay subject to the constraint of an average energy consumption and optimizing the average end-to-end energy consumption subject to the constraints of an average end-to-end delay for all class and each class customer requests respectively. Moreover, a service provider processes the service requests of customers according to a service level agreement (SLA), which is a contract agreed between a customer and a service provider. It becomes important and commonplace to prioritize multiple customer services in favor of customers who are willing to pay higher fees. We propose an approach for minimizing the total cost of cluster computing resources allocated to ensure multiple priority customer service guarantees by the service provider. It is demonstrated through our simulation that the proposed approaches are efficient and accurate for power management and performance guarantees in priority-type cluster computing systems.
Kaiqi Xiong
IPDPS1
2010 Power-aware resource provisioning in cluster computing
abstract
The high power consumption of cluster computing infrastructures has become a major concern. It leads to the increased heat dissipation and decreased reliability of cluster servers. Power management becomes a critical issue in cluster computing. In this paper, we start with an analysis of the relationship between cluster performance and power consumption. We study both the problem of minimizing the average end-to-end delay with the constraint of average energy consumption and the problem of minimizing the average energy consumption of cluster service requests with the constraint of an average end-to-end delay for customer services. We propose novel approaches to solving these two problems. In an effort to maximize profits, a service provider only provides sufficient resources to ensure quality of services (QoS) but often avoid over provisioning to meet QoS defined in a service level agreement (SLA) which is a contract agreed between a customer and a service provider. We present an approach for optimizing SLA-based resource provisioning in cluster computing in that we minimize the total cost of cluster servers owned by a service provider while satisfying the requirements of both a percentile of the end-to-end delay and average energy consumption. Numerical experiments show that the proposed approach is efficient and accurate for the SLA-based resource provisioning problem in cluster computing.
Kaiqi Xiong
IPDPS1
2010 Resource Provisioning in SLA-Based Cluster Computing
Kaiqi Xiong, Sang C. Suh
JSSPP1
2009 Multiple priority customer service guarantees in cluster computing
abstract
Cluster computing is an efficient computing paradigm for solving large-scale computational problems. Resource management is an essential part in such a computing system. A service provider uses computational resources to process a customer's service request. In an effort to maximize a service provider's profit, it becomes commonplace and important to prioritize services in favor of customers who pay higher fees. In this paper, we present an approach for optimal resource management in cluster computing that minimizes the total cost of computer resources owned by a service provider while satisfying multiple priority customer service requirements. Simulation examples show that the proposed approach is efficient and accurate for resource management in a cluster computing system with multiple customer services.
Kaiqi Xiong
IPDPS1
2008 SLA-based resource allocation in cluster computing systems
abstract
Resource allocation is a fundamental but challenging problem due to the complexity of cluster computing systems. In enterprise service computing, resource allocation is often associated with a service level agreement (SLA) which is a set of quality of services and a price agreed between a customer and a service provider. The SLA plays an important role in an e-business application. A service provider uses a set of computer resources to support e-business applications subject to an SLA. In this paper, we present an approach for computer resource allocation in such an environment that minimizes the total cost of computer resources used by a service provider for an e-business application while satisfying the quality of service (QoS) defined in an SLA. These QoS metrics include percentile response time, cluster utilization, packet loss rate and cluster availability. Simulation results show the applicability of the approach and validate its accuracy.
Kaiqi Xiong, Harry G. Perros
IPDPS1
2008 SLA-Based Service Composition in Enterprise Computing
abstract
The composition of services has been a useful approach to integrating business applications within and across organizational boundaries. In this approach, individual services are federated into composite services which are able to execute a given task subject to a service level agreement (SLA). An SLA is a contract agreed between a customer and a service provider who define a set of several quality of services (QoS). An SLA violation penalty is a way to ensure the credibility of an advertised SLA by a service provider. In this paper, we consider a set of computer resources used by a service broker who represents service providers to host enterprise applications for differentiated customer services subject to an SLA and its violation penalty. We present a novel framework for a QoS-constrained resource provisioning problem, and propose a capacity planning approach to optimizing computer resources for all service sites owned by service providers subject to multiple QoS metrics defined in the SLA and their violation penalties. Simulation results show that the proposed approach is efficient for reliable resource planning in service composition.
Kaiqi Xiong, Harry G. Perros
IWQoS1
2008 Efficient Localization Schemes in Sensor Networks with Malicious Nodes
Kaiqi Xiong, David J. Thuente
SECRYPT1
2006 Resource Optimization Subject to a Percentile Response Time SLA for Enterprise Computing
abstract
We consider a set of computer resources used by a service provider to host enterprise applications subject to service level agreements. We present an approach for resource optimization in such an environment that minimizes the total cost of computer resources used by a service provider for an enterprise application while satisfying the QoS metric that the response time for executing service requests is statistically bounded. That is, gamma% of the time the response time is less than a pre-defined value. This QoS metric is more realistic than the mean response time typically used in the literature. Numerical results show the applicability of the approach and validate its accuracy.
Kaiqi Xiong, Harry G. Perros
GLOBECOM1
2006 Trust-based Resource Allocation in Web Services
abstract
With the number of e-Business applications dramatically increasing, service level agreement (SLA) plays an important part in Web services. A SLA is a combination of several quality of services (QoS), such as security, performance, and availability, agreed between a customer and a service provider. Most existing research addresses only one QoS metric, and in the case of the response time, the average time to process and complete a job is typically used. In this paper, we study trustworthiness, percentile response time and availability. We consider all these qualities for a trust-based resource allocation problem which typically arises in Web services applications. We formulate the trust-based resource allocation problem as an optimization problem under SLA constraints, and we solve it using an efficient numerical procedure
Kaiqi Xiong, Harry G. Perros
ICWS1
2006 Computer Resource Optimization for Differentiated Customer Services
abstract
In enterprise computing, customer requests often need to be distinguished, with different request characteristics and customer’s different service requirements. In this paper, we consider a set of computer resources used by a service provider to host enterprise applications for differentiated customer services subject to a service level agreement. We present an approach for resource optimization in such an environment that minimizes the total cost of computer resources used by a service provider for such an application while satisfying the QoS metric that the response time for executing differentiated service requests is statistically bounded. That is, each ã(r)% of the time the response time is less than a pre-defined value for class r customers. This QoS metric is more realistic than the mean response time typically used in the literature. Numerical results show the applicability of the approach and validate its accuracy.
Kaiqi Xiong, Harry G. Perros
MASCOTS1
1999 On the analysis of neural networks with asymmetric connection weights or noninvertible transfer functions
abstract
This paper extends the energy function to the analysis of the stability of neural networks with asymmetric interconnections and noninvertible transfer functions. Based on the new energy function, stability theorems and convergent criteria are derived which improve the available results in the literature. A simpler proof of a previous result for complete stability is given. Theorems on complete stability of neural networks with noninvertible output functions are presented.
Kaiqi Xiong
IEEE Trans. Syst. Man Cybern. Part B2