VLDB 2026 Research / reviewers in the wild / expert
Liang Jiao
dblp:28/10186
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2026
0009-0005-1860-6419ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PEDTA: Parallel Analysis for High-Precision Website Fingerprinting in Real-World Networks
Lizhi Peng, Liang Jiao, Yutong Yan, Ze Kang |
ICIC (2) | 3 |
| 2025 | IPv6 Target Generation Driven by Fine-tuned Large Language ModelabstractThe rapid advancement of the Internet has brought the exploration and management of the IPv6 address space to the forefront of network research. With its 128-bit addressing scheme, IPv6 provides approximately 340 undecillion addresses, effectively mitigating the address exhaustion issue inherent in IPv4. The immense address space of IPv6 renders traditional brute-force scanning, once effective for IPv4, no longer feasible. This challenge calls for the development of efficient and precise IPv6 address generation methods to ensure the stability and security of the Internet. To tackle this challenge, this study introduces an innovative IPv6 address generation method leveraging a fine-tuned Large Language Model (LLM), enhanced by the vLLM inference framework to improve generation efficiency. This approach leverages the strong learning and generalization capabilities of LLMs to effectively handle the complexities of IPv6 address generation. We begin with an initial classification of IPv6 addresses to reduce the model’s learning complexity. Next, we curate a fine-tuning dataset and apply the LoRA technique to fine-tune the Qwen-7B-chat model. The results show that the fine-tuned LLM outperforms existing methods in generating IPv6 addresses, especially in terms of generation speed and accuracy. Xingqi Cheng, Shan Jing, Liang Jiao |
SMC | 3 |
| 2024 | 6GAI: Active IPv6 Address Generation via Adversarial Training with Leaked InformationabstractGlobal IPv6 scanning has always been a challenge for researchers because of the limited network speed and computational power. In this paper, we introduce 6GAI to implement more efficient target address generation. 6GAI is built with Generative Adversarial Net (GAN) integrated with Convolutional Bottleneck Attention Module (CBAM). 6GAI allows the discriminative net to leak generated address’s high-level features extracted by CBAM to the generative net, while the generative net incorporates such informative signals into all generation steps through an additional Manger module, which takes the extracted features of current generated address nybbles and outputs a latent vector to guide the Worker module for active IPv6 address generation. This work outperformed the state-of-the-art target generation algorithms on two datasets including one public dataset and one independently collected dataset. Liang Jiao, Yujia Zhu, Wen-Xiu Zhang, Qingyun Liu 0001 |
CSCWD | 1 |
| 2024 | Measuring Encrypted DNS Service with TLS1.3 Support over IPv6abstractThe Encrypted Domain Name System (DNS) and Encrypted Server Name Indication (ESNI) are recently proposed to enhance network security and privacy protection; we refer to these schemes collectively as domain name encryption technologies. Previous research has shown that the destination IP address accessed by the user cannot be associated with common web services such as websites because a large number of websites are hosted through cloud or CDN over IPv6. However, encrypted DNS, as an internet infrastructure service, is typically deployed independently by the service provider rather than hosted through cloud or CDN. In this paper, we propose a method to discover the unique service provider of encrypted DNS resolvers on a large-scale encrypted traffic with TLS1.3 support over IPv6. The model utilizes a Siamese Network to determine whether two IPv6 resolver addresses belong to the same service provider of encrypted DNS, even if the DNS query is protected by ESNI. Through a comprehensive analysis of two real-world datasets, which include encrypted DNS data and common web data, we find that the implementation of TLS1.3, especially ESNI, does not impact the association of encrypted DNS server addresses. Our model achieves an accuracy rate of 95.29%. Liang Jiao, Wen-Xiu Zhang, Tianyu Cui, Yujia Zhu, Qingyun Liu 0001 |
ISCC | 1 |
| 2023 | DualDNSMiner: A Dual-Stack Resolver Discovery Method Based on Alias Resolution
Dingkang Han, Yujia Zhu, Liang Jiao, Dikai Mo, Qingyun Liu 0001 |
CollaborateCom (3) | 3 |
| 2023 | CCSv6: A Detection Model for DNS-over-HTTPS Tunnel Using Attention Mechanism over IPv6abstractIn this paper, we first show DNS-over-HTTPS (DoH) tunneling detection methods verified to be effective over IPv4 can be applied to IPv6, and then propose a new model called CCSv6, using attention-based convolution neural network to build classifiers with flow-based features to detect DoH tunneling over IPv6, achieve 99.99% accuracy on the IPv6 dataset. In addition, we discuss the influence of various factors such as locations or DoH resolvers on the detection results in detail over IPv6. All the more important, our model shows better transfer learning ability, which can achieve the F1-score of 96% when trained on the IPv6 dataset and tested on the IPv4 dataset. Liang Jiao, Yujia Zhu, Fenglin Qin, Qingyun Liu 0001 |
ISCC | 1 |
| 2023 | Before Toasters Rise Up: A View into the Emerging DoH Resolver's Deployment RiskabstractAs an encryption protocol for DNS queries, DNS-over-HTTPS (DoH) is becoming increasingly popular, and it mainly addresses the last-mile privacy protection problem. However, the security of DoH is in urgent need of measurement and analysis due to its reliance on certificates and upstream servers. In this paper, we focus on the DoH ecosystem and conduct a one-month measurement to analyze the current deployment of DoH resolvers. Our findings indicate that some of these resolvers use invalid certificates, which can compromise the security and privacy advantages of the protocol. Furthermore, we found that many providers are at risk of certificate outages, which could cause significant disruptions to the DoH ecosystem. Additionally, we observed that the centralization of DoH resolvers and upstream DNS servers is a potential issue that needs addressing to ensure the stability of the ecosystem. Yuqi Qiu, Baiyang Li, Zhiqian Li, Liang Jiao, Yujia Zhu, Qingyun Liu 0001 |
ISCC | 4 |
| 2023 | Measuring DNS-over-Encryption Performance Over IPv6abstractIn recent years, encrypted DNS such as DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) has gained significant traction as privacy-preserving alternative to conventional DNS. While several studies have measured the performance of encrypted DNS relative to conventional DNS, they are only performed over IPv4, little has been done to understand their status over IPv6. Besides, previous studies can not obtain the absolute query latency due to lack of control over vantage points.This paper performs by far the fist end-to-end performance measurements on encrypted DNS over IPv6. By analyzing measurement results, we have gained several insights. In general, the quality of service for encrypted DNS is satisfying. Over IPv6, encrypted DNS performance varies across resolvers, and is affected by the location issuing DNS queries, the type of encrypted DNS protocol used and the latency to resolvers. Compared with IPv4, the performance of encrypted DNS of different resolvers over IPv6 is improved to some extent. In addition, we also find other problems such as the quality of service of resolver Ahadns is significantly low both over IPv6 and IPv4, as well as the performance of encrypted DNS for resolver Alidns significantly deteriorates when switching from IPv4 to IPv6. Based on our observations, we provide recommendations and discuss situations in which switching to IPv6 may be beneficial. We hope that our tools developed for performing measurements can help people in different regions to choose to the right recursive resolver and network environment, and that our findings can contribute to improve IPv6 Internet infrastructure and inform continuing encrypted DNS deployment over IPv6. Liang Jiao, Yujia Zhu, Baiyang Li, Qingyun Liu 0001 |
TrustCom | 1 |
| 2022 | Detection of DoH Tunnels with Dual-Tier ClassifierabstractDNS over HTTPS (DoH) has been deployed to provide confidentiality in the DNS resolution process. However, encryption is a double-edged sword in providing security while increasing the risk of data tunneling attacks. Current approaches for plaintext DNS tunnel detection are disabled. Due to the diversity of tunneling tool variations and the low proportion of tunneled traffic in real situations, detecting malicious behaviors is becoming more and more challenging. In this paper, we propose a novel behavior-based model with Dual-Tier Tunnel Classifier (DTC) for tool-level DoH tunneling detection. The major advantage of DTC is that it can not only capture existing tunneling tools but also explore unknown ones in the wild. In particular, DTC considers data imbalance, which improves robustness of the model in the open environment. Our method has been proven successful in both closed and open scenarios, achieving 99.99 % accuracy in detecting known malicious DoH traffic, 96.93% accuracy in unknown and 95.31 % accuracy in identifying malicious DoH tunnel tools. Yuqi Qiu, Baiyang Li, Liang Jiao, Yujia Zhu, Qingyun Liu 0001 |
MSN | 3 |