VLDB 2026 Research / reviewers in the wild / expert
Liyi Zeng
dblp:298/3593
· DBLP profile ↗
13ranked-venue papers
2as first author
13since 2021 · last 2026
0009-0009-1627-5811ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 1 first-author · 6 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pyramid graph neural network knowledge distillation with pre-trained language model for medical question answering
Xuening Li, Fangjiong Chen, Liyi Zeng, Zhaoquan Gu, Yanchun Zhang |
Eng. Appl. Artif. Intell. | 4 |
| 2026 | An interpretable intrusion detection framework based on ensemble neural networks for dynamic network environments
Haiyan Wang 0009, Liyi Zeng, Rongxin Hu, Zhaoquan Gu |
Expert Syst. Appl. | 3 |
| 2026 | VDM-IoT: Context Enhanced Knowledge Graph-Prompted LLMs for Internet of Things Vulnerability Description Mappings
Liyi Zeng, Ye Wang 0015, Zhaoquan Gu, Yanchun Zhang |
IEEE Internet Things J. | 2 |
| 2026 | ContrastMatcher: Adaptive Contrastive Provenance Graph Matching for Host-Based Attack DetectionabstractProvenance graphs have emerged as a promising approach for detecting host-based attacks, particularly on Internet of Things (IoT) endpoints where audit logs are available but resources are constrained. Such graphs integrate fine-grained system audit logs and formulate the attack detection process as subgraph matching within the provenance graph. Existing methods relying on exact subgraph matching are computationally intensive and time-consuming, while supervised learning for approximate subgraph matching, although a potential alternative, requires extensive labeled data that is prohibitively costly for annotating provenance graphs at scale. To tackle these problems, we propose ContrastMatcher, a self-supervised adaptive graph contrastive learning for provenance subgraph matching which needs no label for training. ContrastMatcher consists of three modules: reduction, adaptive self-supervised learning, and lightweight detection. By graph reduction and process-centric ego partitioning, the reduction module identifies likely regions where attacks may occur, substantially reducing computational complexity and runtime. The adaptive self-supervised learning module selects effective augmentations to learn the subgraph representations with a carefully designed self-attention encoder, enabling ContrastMatcher to work without any label. Finally, the lightweight detection module classifies the attack relations between each query and the candidates from the learned representations automatically, which avoids setting the approximation manually. Experiments on the DARPA Engagement 3 datasets show that ContrastMatcher can reduce irrelevant host-based log events by 80% − 90%. In addition, without any label in the provenance graph, it achieves a competitive performance regarding the detection accuracy with only 1% training time compared to the existing supervised learning methods. Wenhao Liao, Liyi Zeng, Zhaoquan Gu, Binxing Fang |
IEEE Internet Things J. | 5 |
| 2026 | Nontargeted Delay Attacks on Blockchain P2P Network: Feasibility and Financial ImplicationsabstractThe growing popularity of blockchain technology has underscored the need for robust network security. However, public blockchain networks remain vulnerable to attacks in which adversaries exploit numerous nonfunctional peer connections to disrupt block propagation across the entire network. In this article, we propose a practical nontargeted delay attack method and validate its feasibility, scalability, and significant impacts on blockchain networks of varying sizes, including EthereumPoW (ETHW) and premerge Ethereum Mainnet. In the ETHW network with 95 nodes, our adversarial peers introduce delays ranging from 0.33 to 2.8 s for half the nodes, with nearly one-third experiencing delays exceeding 5.9 s, derived from the 90th percentile of delay times. When in the premerge Ethereum network with 5739 nodes, over 80% of peers experience prolonged block propagation, resulting in a 77% increase in delay time, underlining the attacks' scalability and efficacy in large-scale environments. We also optimize the Ethereum client Geth by relaxing certain connection restriction, significantly reducing attack costs. Delving deeper, we analyze the implications of delay attacks on proof-of-work (PoW) and proof-of-stake (PoS) consensus mechanisms, illustrating how attackers can gain extra revenues through such attacks. Specifically, we propose a novel combined strategy to facilitate reorganization attacks under PoS. These findings highlight the urgent need to strengthen network-layer defenses and reinforce peer-to-peer (P2P) network protocol security against real-world delay exploits. Liyi Zeng, Zhaoquan Gu, Yanchun Zhang |
IEEE Trans. Cybern. | 1 |
| 2025 | Credibility-Driven Quality Assessment of Multi-source Cyber Threat Intelligence
Liyi Zeng, Xiayu Xiang, Zhaoquan Gu |
ADMA (2) | 2 |
| 2025 | From IPs to Threat Groups: Community Detection on Rule-Enhanced Homology Graphs
Qisheng Zheng, Liyi Zeng, Zhaoquan Gu |
ADMA (4) | 2 |
| 2025 | ADMatcher: Self-supervised Subgraph Matching via Adaptive Dense-Aware Graph Contrastive Learning
Yan Jia 0001, Liyi Zeng, Zhaoquan Gu |
DASFAA (3) | 6 |
| 2025 | IL-IDS: an incremental learning approach with confined data streams for intrusion detectionabstractAbstract In cyberspace, intrusion and detection constitute dynamic and continuous game processes, where data streams are generated incrementally during intrusion. To mitigate intrusions and safeguard assets effectively, it is imperative to take prompt actions based on real-time detection and analysis of the currently available data streams. However, existing approaches that rely on complete and clean data struggle to keep pace with the continuous real-time flow of new network data. To address this issue, we introduce IL-IDS (Incremental Learning for Intrusion Detection Systems), a novel intrusion detection approach that utilizes incremental learning to enable accurate and timely detection of intrusions in real-world scenarios, where the need for real-time processing and learning from newly generated traffic data is paramount. IL-IDS performs in scenarios with limited data availability, where it initially transforms textual data streams into vectorized representations and leverages a variation autoencoder (VAE) to compress these vectors, efficiently extracting their latent features. Then a classifier is trained to distinguish attack and normal behaviors, and a three-way decision method is employed to establish a boundary for ambiguous data that pose challenges in direct classification. Concurrently, threat intelligence is integrated into this process to enhance the accuracy of decision-making. We validate the effectiveness and efficiency of IL-IDS with experiments on real-world deployments during an international activity, highlighting its robustness and reliability in intrusion detection applications, especially under conditions of confined data streams. Notably, IL-IDS has exhibited comparable accuracy and recall results, and attains exceptional 99.93% precision and 96.83% F1-score, which demonstrates a notable improvement of 5.27% and 2.59% respectively in comparison to intrusion detection models trained on complete and readily available data. Jianming Li, Ye Wang 0015, Yan Jia 0001, Liyi Zeng, Wenying Feng 0003, Xiao Jing, Cui Luo, Zhaoquan Gu, Binxing Fang |
Cybersecur. | 4 |
| 2025 | GBFKAN: An Adaptive Multilayer Interpretable Architecture for Intrusion Detection in Various Internet of Things ScenariosabstractAs Internet of Things (IoT) technologies continue to evolve and gain widespread integration across various sectors, IoT devices have become increasingly interconnected and ubiquitous. However, this surge has also led to more sophisticated, diverse, and covert attacks, posing severe security challenges to IoT ecosystems and their defense mechanisms. Intrusion Detection Systems (IDS) are instrumental in securing the IoT by uncovering and mitigating malicious behaviors in real-time. Nevertheless, the growing complexity of network traffic presents significant challenges for IDS, often resulting in a higher false alarm rate and a lower detection rate, due to the intricate characteristics of space and notable temporal dependencies present in network traffic. We conduct an in-depth dimensionality reduction analysis using the t-distributed Stochastic Neighbor Embedding methodology to examine the relationships among attack examples. Then, to enhance the generalization and robustness of IDS, we propose GBFKAN, a novel interpretable three-layer network architecture. The structured design of GBFKAN can comprehensively extract and perceive key information from multiple abstract levels in the raw traffic, enhancing the architecture’s generalization ability and robustness. Furthermore, we utilize the SHapley Additive ExPlanations method to provide detailed explanations of the detection outcomes, augmenting its credibility. Building on this, we successfully identify the erroneous decision-making paradigms within GBFKAN by incorporating empirical knowledge. Extensive simulation experiments conducted on the four widely recognized intrusion detection datasets have conclusively demonstrated that our proposed GBFKAN model surpasses existing methods in terms of intrusion detection performance. Liyi Zeng, Haonan Tan, Le Wang 0008, Zhaoquan Gu |
IEEE Internet Things J. | 2 |
| 2024 | FreqAT: An Adversarial Training Based on Adaptive Frequency-Domain Transform
Denghui Zhang 0001, Yanming Liang, Qiangbo Huang, Xvxin Huang, Peixin Liao, Liyi Zeng |
ADMA (6) | 7 |
| 2023 | Mercury: Fast Transaction Broadcast in High Performance Blockchain SystemsabstractBlockchain systems must be secure and offer high performance. These systems rely on transaction broadcast mechanisms to provide both of these features. Unfortunately, in today’s systems, the broadcast mechanisms are highly inefficient.We present Mercury, a new transaction broadcast protocol designed for high performance blockchains. Mercury shortens the transaction propagation delay using two techniques: a virtual coordinate system and an early outburst strategy. Simulation results show that Mercury outperforms prior propagation schemes and decreases overall propagation latency by up to 44%. When implemented in Conflux, an open-source high-throughput blockchain system, Mercury reduces transaction propagation latency by over 50% with less than 5% bandwidth overhead. Mingxun Zhou, Liyi Zeng, Peilun Li, Fan Long, Dong Zhou 0006, Ivan Beschastnikh, Ming Wu 0007 |
INFOCOM | 2 |
| 2021 | Characterizing Ethereum's Mining Power Decentralization at a Deeper LevelabstractFor proof-of-work blockchains such as Ethereum, the mining power decentralization is an important discussion point in the community. Previous studies mostly focus on the aggregated power of the mining pools, neglecting the pool participants who are the source of the pools' power. In this paper, we present the first large-scale study of the pool participants in Ethereum's mining pools. Pool participants are not directly observable because they communicate with their pools via private channels. However, they leave "footprints" on chain as they use Ethereum accounts to anonymously receive rewards from mining pools. For this study, we combine several data sources to identify 62,358,646 pool reward transactions sent by 47 pools to their participants over Ethereum's entire near 5-year history. Our analyses about these transactions reveal interesting insights about three aspects of pool participants: the power decentralization at the participant level, their pool-switching behavior, and why they participate in pools. Our results provide a complementary and more balanced view about Ethereum's mining power decentralization at a deeper level. Liyi Zeng, Shuo Chen 0001, Xian Zhang 0001, Zhongxin Guo, Thomas Moscibroda |
INFOCOM | 1 |