VLDB 2026 Research / reviewers in the wild / expert
Kexian Liu
dblp:310/5596
· DBLP profile ↗
11ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0003-3975-5606ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 3 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PPTADI: A privacy-preserving training and accelerated distributed inference framework in low-resource AIoT scenarios
Haoyang Meng, Yizhong Hu, Kexian Liu, Jianfeng Guan |
Future Gener. Comput. Syst. | 3 |
| 2026 | OMEGA: A Comprehensive Cloud-Edge-Device Authentication and Key Agreement Scheme for Collaborative Multi-Factory Manufacturing in IIoTabstractCloud Manufacturing (CMfg) has revolutionized traditional manufacturing by enabling resource sharing across factory boundaries. As industry increasingly adopts cloud-edge-device collaborative ecosystems, effective authentication and key agreement (AKA) mechanisms play a critical role in safeguarding security across these complex multi-factory environments. Existing schemes, however, focus primarily on isolated binary security relationships (e.g., device-edge, device-cloud, or edge-cloud pairs individually), neglecting the integrated cloud-edge-device collaborative security demands inherent in multi-factory environments, while often relying on trusted authorities and high-overhead cryptographic mechanisms. This leads to redundant authentication processes, increased latency, and security vulnerabilities as devices must separately establish connections with each entity. To bridge these gaps, this paper introduces OMEGA: a comprehensive Cloud-Edge-Device Authentication and Key Agreement scheme for collaborative multi-factory manufacturing that pioneers an integrated security architecture. OMEGA’s distinctive advantage lies in its ability to establish all necessary secure connections (device-edge, device-cloud, and edge-cloud) through a single authentication request from the smart manufacturing device (SMD), significantly reducing authentication overhead. By leveraging lightweight hash operation, OMEGA creates a cohesive security fabric that enables SMDs to concurrently access specialized capabilities from multiple clouds while leveraging edge computing for time-sensitive operations. Security analysis using both Real-Or-Random (ROR) model and ProVerif formal verification tool demonstrates OMEGA achieves robust security while performance evaluation confirms its superior efficiency in industrial environments. Kexian Liu, Jianfeng Guan, Su Yao, Ilsun You, Hongke Zhang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | MENTOR: Malicious Network Traffic Detection Through Optimized LLM-Based Recognition
Junxiang Jia, Haoyang Meng, Yizhong Hu, Kexian Liu, Jianfeng Guan |
ICIC (15) | 4 |
| 2025 | MPCSFL: A Privacy-Preserving Split Federated Learning Framework in Edge NetworkabstractWith the intelligent multimedia development, it is very common to use artificial intelligence methods to process multimedia data, but the problem of protecting the privacy of data is very critical. This paper focuses on privacy-protected split federated learning in processing images and we propose a framework called MPCSFL, which avoids the transmission of data labels and makes use of secure multi-party computation to enhance privacy protection. Compared with traditional privacy protection methods based on differential privacy, MPCSFL can keep the gradient matching loss above 0.4 in iDLG attack. In the model inversion attack scenario, MPCSFL will not expose the effective information of the raw data when the traditional protection method is cracked, which means that MPCSFL can protect the privacy more effectively. Jianfeng Guan, Haoyang Meng, Yizhong Hu, Kexian Liu |
ICME | 5 |
| 2025 | PIPE: Identity-Aware Privacy-Enhanced Source and Path Verification for Strengthened Network AccountabilityabstractNetwork-layer security threats have become increasingly sophisticated, exposing significant vulnerabilities in the current Internet architecture. Despite various proposed solutions, the field faces fundamental challenges in balancing user privacy with network security and achieving practical deployment. This paper presents a novel approach called PIPE (Privacy-preserving Identity and Path Enhancement), which leverages a distributed infrastructure of Key Distribution Servers (KDS) to integrate Decentralized Identity (DID) with source and path verification. Our solution binds user identity, address, path, and data while maintaining privacy through encryption and per-hop address transformation. By embedding DID information in address and implementing encrypted path verification, we achieve enhanced network accountability without compromising privacy. Experimental results demonstrate PIPE’s practicality and advantages over existing approaches in terms of deployment flexibility and security guarantees. Our work contributes to the evolution of secure network architectures by balancing accountability requirements with privacy protection while ensuring practical deployability. Jianfeng Guan, Kexian Liu, Su Yao, Ye Qin, Songtao Fu, Ke Xu 0002 |
ICNP | 2 |
| 2025 | Learning to Co-Design Routing and Processing in Computing Power NetworksabstractOrchestrating the intertwined computing and network resources at the foundational fabric level of Computing Power Networks (CPNs) remains a critical challenge. Current network architectures often lead to resource fragmentation and performance bottlenecks because routing decisions are decoupled from the dynamic, intrinsic processing loads of network nodes. This fundamental disconnect creates inefficiencies and security risks that undermine the entire CPN substrate. To address this, we introduce GAT-GRPO, a Deep Reinforcement Learning (DRL) framework designed for the fine-grained Joint Routing and in-Network Processing Placement (JR-PP) task. GAT-GRPO features a novel dual-path Graph Attention Network (GAT) that explicitly models the distinct heterogeneity of link states and nodal capacity. To master the complex combinatorial action space, we are the first to leverage Group Relative Policy Optimization (GRPO)—a stable, critic-free algorithm—for network resource orchestration. Extensive evaluations show GAT-GRPO boosts network revenue by 3.7%-5.3% over latest baselines. Mininet emulations further validate its superiority, with a 6.7% reduction in peak queue length and a 6% decrease in peak link utilization against the latest DRL agent. Our work delivers a practical, high-performance solution for foundational resource orchestration in CPNs, enabling a more intelligent and resilient networking substrate for higher-level services. Ye Qin, Kexian Liu, Zejun Lan, Jianfeng Guan |
TrustCom | 2 |
| 2025 | Blockchain-based cross-domain IoT data sharing: A lightweight, secure edge-assisted approach
Kexian Liu, Jianfeng Guan, Su Yao, Hongke Zhang |
Comput. Networks | 1 |
| 2025 | ScaIR: Scalable Intelligent Routing based on Distributed Graph Reinforcement Learning
Jianfeng Guan, Kexian Liu, Yizhong Hu, Yuyin Ma |
Comput. Networks | 3 |
| 2024 | DTAME: A Interpretable and Efficient Approach for ABAC Policy Mining and Evaluation Using Decision TreesabstractAttribute-Based Access Control (ABAC) has been chosen to replace the traditional access control model due to its dynamics, flexibility and scalability recently. However, during the migration and deployment process of ABAC policies, the key issue is how to mine accurate access control policies and quickly evaluate the policies when an access request arrives. Previous approaches typically addressed these two aspects separately, and the emergence of integrated solutions has provided new insights for addressing this issue. However, despite the high accuracy of the integrated solution in policy evaluation, it still falls short in terms of interpretability and performance. Therefore, this paper proposes a decision tree based ABAC policy mining and policy evaluation (DTAME) scheme, which employs different policy mining and evaluation algorithms based on various datasets. For access control lists, we utilize decision tree algorithms to mine ABAC policies and conduct policy evaluations based on policy trees. For access control logs, we adopt a decision tree to achieve performance approximating that of XGBoost. Experimental results show that the scheme offers superior interpretability and policy evaluation performance at the expense of a certain degree of accuracy. Zejun Lan, Jianfeng Guan, Xianming Gao, Kexian Liu, Jianbang Chen |
TrustCom | 5 |
| 2024 | DKGAuth: Blockchain-Assisted Distributed Key Generation and Authentication for Cross-Domain Intelligent IoTabstractThe widespread adoption of intelligent Internet of Things (IoT) has sparked increased efforts to foster extensive data interaction and collaboration across diverse fields, leading to a trust crisis in cross-domain scenarios. Moreover, cross-domain collaboration increases the complexity of key management, especially in resource-constrained IoT environments where high computational costs are impractical. This situation poses risks of key leakage and inefficient key updates. This paper introduces DKGAuth, a blockchain-based method for distributed key generation and authentication tailored for resource-constrained cross-domain intelligent IoT systems. Initially, we propose a lightweight cross-domain authentication architecture based on blockchain to address the trust crisis effectively among different domains in the intelligent IoT. Secondly, building upon this architecture, we introduce a distributed key generation method that revolutionizes the key infrastructure to address key management concerns. Additionally, we design an algorithm to combine key factors, minimizing costs associated with both key generation and updates. Finally, we establish a simulation environment to assess the computational, storage, and read/write overheads of our approach. In the same configuration, compared to other solutions, the efficiency of key updates improves by 83% when updated 100 times. Kexian Liu, Jianfeng Guan, Su Yao, Hongke Zhang |
IEEE Internet Things J. | 1 |
| 2023 | An Anonymous Authentication Scheme with Low Overhead for Cross-Domain IoT
Long Fan, Jianfeng Guan, Kexian Liu |
ICA3PP (7) | 3 |