Tong Li 0012

dblp:29/3826-12 · DBLP profile ↗
← Back
24ranked-venue papers
0as first author
19since 2021 · last 2026
0000-0003-3470-7963ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 6 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Learning general-purpose and robust representations of microservice system states from multi-modal data
Jingguo Ge, Yulei Wu, Hui Li 0098, Bingzhen Wu, Tong Li 0012
Inf. Process. Manag.7
2025 System States Forecasting of Microservices Based on Spatio-Temporal Relationships
abstract
In the AIOps realm, precise system state forecasting is essential, particularly within microservices architectures, where may have dynamic deployments, varied call paths, and cascading effects complicate spatio-temporal relationships. Existing time series forecasting methods, which emphasize temporal patterns, fall short in capturing the critical spatial dimensions. Spatio-temporal graph methods, while useful, often overlook temporal trends and the length of forecast horizons. Furthermore, existing research about microservices tends to undervalue the role of network metrics and topological structures in reflecting system dynamics. This paper presents STMformer, a novel model designed for microservices state forecasting, adept at managing multi-node and multivariate time series based on diverse spatio-temporal relationships. It harnesses dynamic network connections and topological insights to model complex spatio-temporal interactions and incorporates a PatchCrossAttention module for global cascading effect analysis. Based on a microservices-based dataset we collect with our developed tool, we demonstrated that STMformer outperformed existing methods, reducing MAE by 8.6% and MSE by 2.2% in forecasting tasks. The source code is available at https://github.com/xuyifeiiie/STMformer.
Yuhao Gao, Jingguo Ge, Yuepeng E, Tong Li 0012
CSCWD6
2025 Multi-Dimensional Series Forecasting for Multi-Node Microservices: Leveraging Specialized Embedding in LLMs
abstract
Currently, time series prediction in microservice systems suffers from inaccurate forecasts due to the complex interdependencies and highly dynamic workload characteristics. Traditional small-scale models struggle to understand the temporal patterns embedded within multi-dimensional metrics, leading to suboptimal performance. The advent of large language models (LLMs) offers a promising solution, as their powerful representation learning capabilities can effectively capture these complex temporal patterns. In this study, we propose a novel approach tailored for multi-dimensional time series forecasting in microservice environments. Our method leverages specialized embedding techniques that combine dynamic receptive field convolution and adaptive attention masks to capture temporal dependencies and feature relationships across multiple nodes. Additionally, we fine-tune a pre-trained LLaMA model to enhance its applicability for time series forecasting within microservice contexts. Experimental results demonstrate that our approach achieves higher prediction accuracy compared to baseline methods in different datasets. This research's achievements in time series forecasting provide new insights for downstream tasks such as resource allocation and fault prediction.
Lefan Cheng, Jingguo Ge, Quanfeng Lv, Tong Li 0012, Bingzhen Wu
HPCC4
2025 PaSTS: Parameter-affined Seasonal-Trend Synthesis for Multi-dimensional Long-Term Time Series Forecasting within LLM
abstract
Large Language Models (LLMs) have demonstrated remarkable performance across various domains, showcasing significant potential for long-term time series forecasting (LTSF), and consequently attracting substantial research interest. In LTSF, temporal decomposition has been widely adopted in existing models, including both Transformer-based and linear models, to enhance predictive capabilities. However, our experiments indicate that a simplistic integration of these decomposition methods into LLMs can lead to overfitting, even though they are effective in traditional models. In this paper, we propose PaSTS, a novel framework designed to integrate decomposition methods into LLMs through a specialized temporal synthesis layer, thereby improving predictive accuracy and mitigating overfitting of LLMs in LTSF tasks. Empirical evaluation of our framework provides evidence supporting the effective integration of LLMs with temporal decomposition techniques. Furthermore, applying our synthesis method to the decomposed series in several traditional models that employ seasonal-trend decomposition demonstrates its adaptability.
Quanfeng Lv, Jingguo Ge, Tong Li 0012, Liangxiong Li
ICASSP4
2025 Automated Cloud-Native Dynamic Network Policy Generation Based on Microservices Topology
Weiqiang Huang, Junling You, Tong Li 0012, Jingguo Ge, He Kong 0003, Liangxiong Li
ICIC (15)3
2025 Betastack: Enhancing base station traffic prediction with network-specific Large Language Models
Quanfeng Lv, Tong Li 0012, Jingguo Ge
Comput. Networks3
2025 ANT-ET: An end-to-end multimodal framework for fine-grained encrypted traffic fingerprinting
abstract
The widespread use of encryption protocols and increasing privacy demands have significantly increased encrypted traffic, creating new challenges for network monitoring and threat detection. Current methods struggle with diverse scenarios and distinguish between subtle traffic patterns within webpages of the same application. To address these challenges, we introduce ANT-ET, an end-to-end multimodal framework designed for fine-grained encrypted webpage traffic fingerprinting. ANT-ET leverages a transformer to model payload semantics and constructs a traffic interaction graph to capture both temporal and spatial characteristics of packet interactions. Additionally, ANT-ET incorporates a gradient reversal layer to improve generalization by facilitating domain-invariant feature learning across related webpages. Experimental results demonstrate ANT-ET’s superior performance compared to various baseline models, which were evaluated using a proprietary encrypted webpage traffic dataset and three public datasets. Ablation studies confirm the effectiveness of different framework components, while sensitivity and complexity analyses further validate ANT-ET’s robustness and flexibility.
He Kong 0003, Liqun Yang, Jingguo Ge, Tong Li 0012, Hui Li 0098
J. Comput. Secur.4
2024 On Improved Efficiency and Forward Security of 0-RTT Key Exchange for SDP
abstract
The Transport Layer Security (TLS) protocol has been widely used in software-defined perimeter (SDP) to establish secure, encrypted connections between distributed SDP components. To improve communication efficiency of its handshake protocol, the latest TLS standard (i.e., TLS 1.3) introduces a zero round-trip-time (0-RTT) handshake. However, traditional 0-RTT handshake protocols lack a forward secure key exchange scheme, so encrypted data that have already been transmitted could be potentially leaked to attackers after the pre-shared key (PSK) is compromised. To achieve secure TLS handshake with minimal communication cost, several forward secure 0-RTT key exchange schemes based on puncturable encryption were proposed. However, they are not applicable to real world SDP environments, because they either need to pre-store a large number of secret keys in the host onboard phase, or require a large number of complex cryptography operations (e.g., bilinear-pairing) in the access phase. Therefore, to avoid high computational overhead while still maintaining communication efficiency and forward security, a novel 0-RTT key exchange scheme based on efficient puncturable key encapsulation mechanism is proposed in this paper. Experimental results show that, with reasonable (and configurable) memory consumption, the latency performance of the proposed scheme is about 30% better than FFDHE3072, which is a practical 1-RTT key exchange scheme in TLS 1.3.
Lei Zhang 0116, Jingguo Ge, Yulei Wu, Tong Li 0012, Hui Li 0098, Yuepeng E
ICCCN4
2024 TSIV: A Two-Stage Approach for Identifying Encrypted Video Traffic in Unstable Network
Die Hu 0004, Jingguo Ge, Tong Li 0012, Hui Li 0098, Liangxiong Li, Weitao Tang
ICONIP (6)3
2024 Power Microservices Troubleshooting by Pretrained Language Model with Multi-source Data
abstract
Microservice has become the mainstream paradigm for developing cloud-native applications, but the intricate interdependencies between microservices and the vast amount of heterogeneous observable data (i.e. metrics, logs and traces) pose challenges for rapid troubleshooting. Several anomaly detection and root cause localization approaches that integrate multi-source data have been proposed. However, they are plagued with issues such as scarcity of high-quality data and insufficient model generalization. This is particularly evident when domain-specific models are trained from scratch for specific tasks. Recently, Large Language Models (LLMs) have shown outstanding capabilities in time series analysis, due to multi-source data generated by distributed microservices exhibit intrinsic spatio-temporal characteristics. In view of this, we propose LLM4MST, an LLM-empowered microservice troubleshooting model. We first unify and represent multi-source data by extracting service invocation graphs, and model dependencies between microservices by using a message-passing based graph neural network to generate graph-level sequences. The graph-level representation is then aligned with the LLM, and the LLM is fine-tuned to capture complex spatio-temporal patterns, generating a global vector that represents the state of microservice system within a timeslot. LLM4MST achieves accurate anomaly detection and root cause localization by jointly training the end-to-end model. Experiments on real datasets show that LLM4MST exhibits excellent performance in both full-sample and few-shot scenarios, demonstrating the powerful ability of LLMs in cross-domain knowledge transfer and few-shot learning.
Zhuang Lu, Fan Tang, Tong Li 0012, Jingguo Ge
ISPA5
2024 Enhancing fault localization in microservices systems through span-level using graph convolutional networks
He Kong 0003, Tong Li 0012, Jingguo Ge, Lei Zhang 0116, Liangxiong Li
Autom. Softw. Eng.2
2024 Few-Shot Log Anomaly Detection Based on Matching Networks
abstract
In order to address the problem of log anomaly detection in scenarios with limited labeled log datasets, this paper proposes Log-MatchNet, a novel few-shot log anomaly detection method. To tackle issues such as unstructured log data, diversity, and evolution over time, we employ structured processing and log parsing to convert log content information and template ID into vectors. Feature extraction is performed using the BERT model. Additionally, by integrating multiple datasets and conducting post-training on the BERT model for domain adaptation, we obtain BERT_Post, a module with universal feature extraction capabilities in the log domain. Compared to BERTbase and CyBERT, our method demonstrates superior performance in log anomaly detection, especially in situations with limited labeled datasets. With only 2 annotated normal logs and 2 annotated abnormal logs, BERT_Post achieves a remarkable 16.14% increase in F1-score. Addressing the challenge of imbalanced data, we introduce a matching network that learns the similarity scores between input and prototype vectors, showcasing strong generalization capabilities with an average accuracy of 99.6%. In few-shot scenarios, our method, Log-MatchNet outperforms traditional methods and Proto-Siamese network in terms of F1-score. In an unstable log evolution environment, our method exhibits robustness against noisy data, achieving an F1-score of 81.2% even with 20% injected noise. Compared to LogAnMeta, our approach yields a 31.71% increase in F1-score. Experimental results demonstrate the effectiveness of Log-MatchNet in detecting anomalies in the presence of limited labeled log data and its robust performance in log evolution scenarios.
Chunjing Han, Bohai Guan, Tong Li 0012, Jifeng Qin, Yulei Wu
IEEE Trans. Netw. Serv. Manag.3
2023 Contrastive Learning at the Relation and Event Level for Rumor Detection
abstract
Existing studies for rumor detection rely heavily on a large number of labeled data to operate in a fully-supervised manner. However, manual data annotation in realistic cases is very expensive and time-consuming. In this paper, we propose a novel self-supervised Relation-Event based Contrastive Learning (RECL) framework for rumor detection to address the above issue. Specifically, we present both the relation-level and event-level augmentation strategies to generate contrastive samples, which capture both the semantics revealed by repost relations and the structural features of rumor events. Moreover, contrastive learning tasks are devised to generate informative graph representations by utilizing self-supervision signals of unlabeled data. Extensive experimental results on real-world datasets demonstrate the effectiveness of our model, especially with limited labeled data.
Yingrui Xu, Jingguo Ge, Yulei Wu, Tong Li 0012, Hui Li 0098
ICASSP5
2023 A New Federated Learning Model for Host Intrusion Detection System Under Non-IID Data
abstract
Host Intrusion Detection System (HIDS) is an important research topic in the field of cyberspace security. With the explosion in the number of malicious attacks in recent years, machine learning-based detection method is now the most common and efficient approach. While traditional centralized machine learning needs to transmit data to the central server for training, which not only requires the central server to have large computing resources, but also causes problems such as sensitive data leakage and communication overhead. As a distributed machine learning paradigm, Federated Learning (FL) can achieve multi-party collaborative training and aggregate a unified global model without data sharing, which can well alleviate these problems. It is worth noting that existing studies on the use of FL in HIDS are all conducted in the scenario where the data is independent and identically distributed (IID). However, due to the different context of hosts, the data generated by hosts is usually non-independent and identically distributed (Non-IID) in reality. Therefore, We investigate the impact of Non-IID data with different skew levels on FL in HIDS. On this basis, we propose a data augmentation FL algorithm based on Synthetic Minority Over-Sampling Technique (SMOTE) to reduce the impact of Non-IID data. We also develop a data collection module using extended Berkeley Packet Filter (eBPF) technology to collect a dataset for experiments. Experimental results show that our proposed FL algorithm can effectively improve the performance of HIDS under Non-IID data.
Yongfei Liu, Lanxue Zhang, Liangxiong Li, Tong Li 0012, Bingzhen Wu
SMC6
2022 Design of an Autoencoder-based Anomaly Detection for the DoH traffic System
abstract
DNS has encountered complex and diversified attacks over the years due to its special status on the Internet. The concept of DNS-over-HTTPS (DoH) has been proposed to protect user privacy by encapsulating DNS into HTTPS, which increases the difficulty of DNS tunnel detection but also faces some new attacks. In recent years, many researchers have discussed the detection methods of DoH tunnel. However, most of them need large-scale labeled datasets and extract statistical features, which is time-consuming and costs immense manpower, so it is impractical to be used in the real-world. In this paper, we developed a system called AADDS: an Autoencoder-based Anomaly Detection for the DoH traffic System consists of Traffic Capture module and Anomaly Detection module. The Traffic Capture module is developed based on nff-go, which can collect features stably in a high-speed Ethernet environment and greatly reduce the workload. For the Anomaly Detection module, we used bidirectional Long and Short-Term Memory (Bi-LSTM) to build an autoencoder network. Several essential experiments proved that our method has fewer parameters while ensuring higher accuracy, and it outperforms the state-of-the-art methods.
Xinhui Du, Dongxin Liu, Zhongji Liu, Xiaowei Yuan, Tong Li 0012, Haojiang Deng
CSCWD6
2022 SelectAug: A Data Augmentation Method for Distracted Driving Detection
Wei Mi, Jingguo Ge, Hui Li 0098, Daoqing Zhang, Tong Li 0012
PAKDD (2)7
2021 Network Automation for Path Selection: A New Knowledge Transfer Approach
abstract
Due to the ever-increasing complexity of modern communication networks, network operators are making tremendous efforts on achieving objectives for the network to meet the diversified requirements of many real-world applications. However, network operators are repeatedly taking a lot of time on some common tasks shared by different networks. In order to reduce repetitive human efforts on network management, advanced machine learning paradigms, such as deep reinforcement learning, has received numerous attention in the networking community. Nevertheless, it encounters great difficulty in transferring learned policies to new environments, resulting in new model training and testing for each changed environment setting. To tackle this important issue, in this paper we propose a new framework that is the first of its kind to enable an agent to have transferable knowledge for network management, specifically, for network path selection tasks. Through this framework, an agent can efficiently learn and express the transferable network knowledge for achieving task objectives. Extensive experimental results show that the learned knowledge through the proposed framework can realize some common objectives of path selection tasks across different network environments. In addition, the knowledge learned from one network task can significantly improve the learning performance of another similar but different task.
Guozhi Lin, Jingguo Ge, Yulei Wu, Hui Li 0098, Tong Li 0012, Wei Mi, Yuepeng E
Networking5
2021 MATEC: A lightweight neural network for online encrypted traffic classification
Jin Cheng 0008, Yulei Wu, Yuepeng E, Junling You, Tong Li 0012, Hui Li 0098, Jingguo Ge
Comput. Networks5
2021 A Survey On Log Research Of AIOps: Methods and Trends
Jiang Zhaoxue, Tong Li 0012, Jingguo Ge, Junling You, Liangxiong Li
Mob. Networks Appl.2
2020 Real-Time Encrypted Traffic Classification via Lightweight Neural Networks
abstract
The fast growth of encrypted traffic puts forward burning requirements on the efficiency of traffic classification. Although deep learning models perform well in the classification, they sacrifice the efficiency to obtain high-precision results. To reduce the resource and time consumption, a novel and lightweight model is proposed in this paper. Our design principle is to “maximize the reuse of thin modules A thin module adopts the multi-head attention and the 1D convolutional network. Attributed to the one-step interaction of all packets and the parallelized computation of the multi-head attention mechanism, a key advantage of our model is that the number of parameters and running time are significantly reduced. In addition, the effectiveness and efficiency of 1D convolutional networks are proved in traffic classification. Besides, the proposed model can work well in a real time manner, since only three consecutive packets of a flow are needed. To improve the stability of the model, the designed network is trained with the aid of ResNet, layer normalization and learning rate warm up. The proposed model outperforms the state-of-the-art works based on deep learning on two public datasets. The results show that our model has higher accuracy and running efficiency, while the number of parameters used is 1.8% of the 1D convolutional network and the training time halves.
Jin Cheng 0008, Runkang He, Yuepeng E, Yulei Wu, Junling You, Tong Li 0012
GLOBECOM6
2020 Mining DApp Repositories: Towards In-Depth Comprehension and Accurate Classification
Yeming Lin, Tong Li 0012, Jingguo Ge, Bingzhen Wu
SEKE3
2020 Attention-based bidirectional GRU networks for efficient HTTPS traffic classification
Junling You, Yulei Wu, Tong Li 0012, Liangxiong Li, Jingguo Ge
Inf. Sci.4
2020 Automatic Virtual Network Embedding: A Deep Reinforcement Learning Approach With Graph Convolutional Networks
abstract
Virtual network embedding arranges virtual network services onto substrate network components. The performance of embedding algorithms determines the effectiveness and efficiency of a virtualized network, making it a critical part of the network virtualization technology. To achieve better performance, the algorithm needs to automatically detect the network status which is complicated and changes in a time-varying manner, and to dynamically provide solutions that can best fit the current network status. However, most existing algorithms fail to provide automatic embedding solutions in an acceptable running time. In this paper, we combine deep reinforcement learning with a novel neural network structure based on graph convolutional networks, and propose a new and efficient algorithm for automatic virtual network embedding. In addition, a parallel reinforcement learning framework is used in training along with a newly-designed multi-objective reward function, which has proven beneficial to the proposed algorithm for automatic embedding of virtual networks. Extensive simulation results under different scenarios show that our algorithm achieves best performance on most metrics compared with the existing state-of-the-art solutions, with upto 39.6% and 70.6% improvement on acceptance ratio and average revenue, respectively. Moreover, the results also demonstrate that the proposed solution possesses good robustness.
Zhongxia Yan 0002, Jingguo Ge, Yulei Wu, Liangxiong Li, Tong Li 0012
IEEE J. Sel. Areas Commun.5
2019 Efficient Identification of TOP-K Heavy Hitters over Sliding Windows
Haina Tang, Yulei Wu, Tong Li 0012, Chunjing Han, Jingguo Ge, Xiangpeng Zhao
Mob. Networks Appl.3