Zixu Huang

dblp:325/4203 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
10since 2021 · last 2025
0009-0002-8292-1999ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Seeing Through NAT: A Frequency Domain Approach to Enterprise Device Detection via Adaptive Fingerprint Fusion
abstract
Network asset auditing constitutes a systematic assessment of organizational IT infrastructures, encompassing comprehensive identification of active hosts, operating systems, and service configurations. This foundational process plays a pivotal role in discovering and managing potential vulnerabilities that adversaries may exploit. While various existing network scanning tools (e.g., Nmap, Masscan, ZMap) provide elementary auditing capabilities, their efficacy is fundamentally constrained in detecting devices/services concealed behind Network Address Translation (NAT) gateways. To address this critical limitation, we propose DMIF (Detection framework based on Multiple Inherent Fingerprints), which introduces two methodological innovations: (1) a frequency domain analytical approach for extracting inherent traffic characteristics, and (2) an adaptive multi-fingerprint aggregation mechanism. Our DMIF builds upon the key observation that different hosts and different operating systems exhibit distinctive traffic fingerprints stemming from their hardware architectures and protocol implementations. The framework’s feature extraction module employs spectral analysis to capture these device-specific patterns, while the fingerprint aggregation module dynamically optimizes weight assignments across multiple fingerprint dimensions through machine learning techniques. We evaluate DMIF in two scenarios and consider the effects of network fluctuations and user behaviors. Experimental results demonstrate that DMIF’s detection F1 score exceeds 0.91 for a wide range of device types, including personal computers, mobile phones, and IoT devices.
Dengfeng Fu, Lutong Chen, Xuanbo Huang, Zixu Huang, Kaiping Xue
GLOBECOM5
2025 PureFlow: An Unsupervised Autoencoder-Based Dataset Purification Framework for Malicious Traffic Detection
abstract
Malicious traffic detection is an important technique for network management, assisting network administrators in identifying malicious hosts and activities. With the growing proportion of encrypted traffic, recent studies incorporate Machine Learning (ML) and Deep Learning (DL) methods. These methods can achieve effective classification but rely heavily on large-scale and high-quality datasets. Due to the coarse-grained traffic collection at the level of hosts or switches in existing datasets, the introduction of noisy traffic degrades the performance of malicious traffic detection models. In this paper, to tackle the efficacy challenge caused by noisy traffic, we propose a traffic dataset purification framework named PureFlow. Specifically, PureFlow adopts an unsupervised clustering algorithm to categorize the collected traffic based on their sources, and thus overcome the feature confusion caused by mixing noisy traffic from different sources. With a set of autoencoders based on reconstruction loss, PureFlow can distinguish the feature differences between noisy and valid traffic. We conduct extensive experiments on public datasets. The results show that PureFlow can effectively filter noisy traffic and significantly enhance the performance of several malicious traffic detection models without additional modifications, achieving average accuracy and F1-score improvements of 5.58% and 0.056, respectively.
Dongfang Hu, Lutong Chen, Jian Li 0031, Zixu Huang, Chensa Du, Kaiping Xue
GLOBECOM4
2025 A Shared Infrastructure Verification Framework with Transient Perturbation Probing for SDN Topology Poisoning Defense
Xuanbo Huang, Lutong Chen, Zixu Huang, Kaiping Xue
GLOBECOM5
2025 Unveiling Stealthy DGA Traffic: A Hybrid Threshold-Behavior Analysis Framework for Detecting Botnet Domains
abstract
In recent years, most botnets have utilized Domain Generation Algorithms (DGAs) to dynamically generate domains to establish communication with Command and Control (C&C) servers, enabling malicious activities. However, recent research mainly proposes methods based on labeled DGA domain datasets that already yield high detection rates, but cannot be applied directly to realistic network environments. In this paper, we propose a novel hybrid threshold-behavior analysis system that examines and processes network traffic in several layers to detect DGA domains precisely. Our system incorporates a multi-level filtering approach that dramatically increases the precision of domain identification. At the system’s center lies its innovative hybrid threshold-behavior analysis framework, which employs a cascaded filtering process to enhance malicious domain identification while efficiently preserving computational resources. To address the issue of separating highly random DGA domains from their legitimate ones, we utilize adaptive thresholding combined with contextual analysis of domain query patterns to enable stealthy DGA domain detection. We test on realistic network traffic datasets to verify the performance of our system. The experiments show that our system has a 97.88% recall rate for labeled DGA domains and can correctly identify a huge number of previously unlabeled DGA domains, demonstrating its effectiveness and feasibility.
Jiankang Sun, Lutong Chen, Xuanbo Huang, Xuanchao Xie, Zixu Huang, Kaiping Xue
GLOBECOM5
2025 Defending Against Link-Flooding Attacks With Adversary Interest Prediction and Grouped Online Load Balancing
abstract
A Link Flooding Attack (LFA) is a type of link-aimed Distributed Denial of Service (DDoS) attack that can overwhelm the Internet critical links to cut off connections with lots of low-rate, seemingly benign traffic. To defend against such threats, a promising solution involves mitigating the attack through load balancing. However, adaptive attacks employ two effective means to circumvent existing load balancing strategies. The first is the frequent changing of targets, known as rolling attacks. Rolling attacks exploit the delay between attack detection feedback and the mitigation of load balancing, depleting the defender’s resources. The second is the strategical selection of target links to create the worst-case scenario for load balancing algorithms. To address these challenges, we propose LinkDam. Specifically, LinkDam adopts a proactive approach by tracking and predicting potential victim links, providing defense against all targets of rolling attacks. Subsequently, we introduce a robust load balancing strategy to prevent the exploitation of selected link combinations. Additionally, LinkDam introduces a partial deployment approach, demanding a mere 40% of nodes be programmable (i.e., SDN nodes) while maintaining an acceptable 10% performance reduction from the maximum achievable. The experimental results indicate that LinkDam surpasses an 80% accuracy threshold, and exhibits a 57% higher tolerance to attack budgets compared to state-of-the-art solutions.
Zixu Huang, Xuanbo Huang, Kaiping Xue, Jiangping Han, Lutong Chen, Qibin Sun, Jun Lu 0001
IEEE Trans. Netw.1
2025 SpiderNet: Enabling Bot Identification in Network Topology Obfuscation Against Link Flooding Attacks
abstract
Link-flooding attacks (LFAs) pose a significant challenge to Internet availability by attacking critical network links with high volumes of seemingly legitimate traffic. In response, researchers have developed network topology obfuscation (NTO) to safeguard critical links. However, state-of-the-art NTO defenses are coarse-grained, leading to less efficient security and usability. In addition, once under attack, NTO schemes cannot identify the attacker’s bot and launch counter-defensive measures. To address these issues, this paper introduces SpiderNet, which employs advanced obfuscation techniques to secure critical links while using strategically created honeypot links for effective bot identification. When adversaries probe the network, SpiderNet captures their probing behavior and deliberately feeds back misinformation about honeypot links. By analyzing the attack patterns directed at these decoy targets, SpiderNet correlates them with adversarial probing activities to effectively identify the bots. Our experiments demonstrate that SpiderNet is more robust than state-of-the-art NTO schemes in terms of security and usability, while also being capable of identifying LFA bots.
Xuanbo Huang, Kaiping Xue, Zixu Huang, Jiangping Han, Lutong Chen, David S. L. Wei, Qibin Sun, Jun Lu 0001
IEEE Trans. Netw.3
2024 Passersby-Anonymizer: Safeguard the Privacy of Passersby in Social Videos
abstract
In the current era of pervasive short video content, the exposure of passersby’s data frequently raises privacy concerns. Traditional anonymization techniques for passersby, like blurring and mosaicing, are often used before uploading such videos. However, these methods tend to degrade the informational richness of the visual content, markedly reducing the quality of the anonymized videos. Recent advancements of diffusion models have paved the way for text-guided image and video synthesis, yet applying these models to the anonymization of passersby poses three main challenges: i) bridging the domain gap between specific passersby data and high-quality image/video datasets that are used for pre-training diffusion models, ii) ensuring temporal consistency in the anonymized videos, and iii) preserving the integrity of video subjects’ content while exclusively anonymizing passersby-related information. To address these challenges, we propose the Passersby-Anonymizer, a novel diffusion-based framework for anonymizing identity-specific attributes in video content. At its core, our model introduces a spatial content adapter (SCA) to adapt to the visual patterns of passersby image datasets. We introduce a Temporal Content Stabilizer (TCS) to maintain the temporal consistency of the anonymized videos. Furthermore, we design a mask-aware training strategy that specifically targets the anonymization of the mask region while preserving the integrity of other contents. Our experimental evaluations demonstrate that our model effectively addresses the challenge of anonymizing passersby without compromising the informational integrity of the social videos. The source code is available at https://github.com/HappyDeepLearning/Passersby-Anonymizer.
Jingzhe Ma, Haoyu Luo, Zixu Huang, Dongyang Jin, Johann A. Briffa, Norman Poh, Shiqi Yu 0001
IJCB3
2023 Dim Moving Target Detection Based on Imaging Uncertainty Analysis and Hybrid Entropy
Erwei Zhao, Zixu Huang
PRCV (4)2
2023 Fast Detection of Infrared Small Target Based on Energy Difference and Structural Difference Measurement
abstract
Infrared (IR) small target detection is a central technology used in IR detection systems. However, it is challenging to quickly and accurately detect small targets of different sizes and shapes in complex scenes. In this letter, we propose a method based on energy difference and structural difference measurement (EDASDM) for the fast detection of small IR targets. First, based on a center-edge distribution, we categorize the target into central and edge regions to perform the novel three-layer window measurement (NTWM) and extract target candidate pixels. Subsequently, target and background clutter are further distinguished by their energy difference (ED) and structural difference (SD). Second, the small IR targets of different sizes and shapes are extracted using adaptive threshold segmentation. The experimental results showed that our algorithm achieves superior detection and real-time performance to some state-of-the-art algorithms.
Zixu Huang, Erwei Zhao, Xiaodong Peng, Zhen Yang 0024
IEEE Geosci. Remote. Sens. Lett.1
2022 LLDM: Low-Latency DoS Attack Detection and Mitigation in SDN
abstract
Software-Defined Networking (SDN) is a new and highly flexible network architecture, but the bottleneck between the control plane and the data plane makes it vulnerable to the control plane saturation DoS attacks. When the attack happens, traditional schemes in DoS scrubbing agent use a binary classification and a First In First Out (FIFO) queue to filter attack flows. However, this scheme is inimical to the end-to-end latency of benign traffic. To tackle this issue, we propose LLDM, leveraging a dynamic priority scheme and a priority queue to detect, mitigate the attacks while ensuring low latency for benign traffic. After detecting the attack, LLDM leverages a two-phase scheme for mitigation. First, LLDM marks packets from the ports under attack as suspicious and migrates them to the mitigation agent. Then, the dynamic priority manager assigns each packet a priority corresponding to its legality, which is used in the priority queue for DoS scrubbing. We evaluate LLDM in a simulation SDN environment. The experimental results show that LLDM can reduce 90.4% of the queuing delay compared with the traditional scheme under a 5000 Packets Per Second (PPS) attack, and it is also resistant to more sophisticated attacks. Under the high rate attack of 50000 PPS, LLDM installs a flow rule for legitimate traffic in 0.2 seconds. Moreover, for benign HTTP requests, LLDM can keep the request time at 1.39 seconds.
Zixu Huang, Xuanbo Huang, Jian Li 0031, Kaiping Xue, Qibin Sun, Jun Lu 0001
HPSR1