Shuaizong Si

dblp:347/2797 · DBLP profile ↗
← Back
18ranked-venue papers
0as first author
18since 2021 · last 2026
0000-0001-8805-1221ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 6 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A tolerance analysis framework for microservice-based systems against cascading failures
abstract
Abstract Microservice has become a dominant approach for building large-scale Internet applications. The microservice-based system (MS) consists of thousands of services, and its complex interactions make it highly susceptible to unforeseen cascading failures. Cascading failure models are commonly used to analyze the system’s tolerance, while the existing models overlook MS’s features and fail to incorporate real-world events, leading to bias in simulation results. To address these, we proposed a comprehensive tolerance analysis framework of MS named the MSTAF. Specifically, we extracted the real-world failure-triggering scenarios and constructed the Workload-based Cascading Failure Model (WL-CFM) to model the load initialization and redistribution. Then, we implemented the Business Loss Assessment Method (BLAM) to quantify the impact by calculating the workload loss. To validate our MSTAF, we conducted experiments on the WL-CFM and BMAL and performed an analysis on the TrainTicket (TT). The results confirm the MSTAF’s superiority. Specifically, the WL-CFM outperforms baselines, reducing simulation error by 10– 48%. The BMAL demonstrates greater accuracy, with deviations from the ground truth ranging from $$-45$$ - 45 % to + 7%. Overall, the MSTAF offers valuable insights for enhancing tolerance and provides an effective solution for developers and researchers.
Chunyang Zheng, Shuaizong Si, Xiaoxi Wang, Jinfa Wang, Shichao Lv, Limin Sun 0001
Cybersecur.2
2025 BSN-OCF: Businesses Sink Node-Oriented Cascading Failure Model in Microservice Applications
abstract
Thousands of service units interact through dependency chains in the Microservice Application (MA) to handle various business functions. As a result, microservice applications feature complex interaction structures. Furthermore, these service units are distributed across multiple devices in the network, making them highly susceptible to cascading failures from single points of failure. Considerable efforts have been made to address and mitigate the significant risks posed by cascading failures. However, as an emerging network architecture, microservices have not yet been fully studied in terms of cascading failure modeling specific to microservice applications. This paper leverages the characteristics of the MA and proposes the Business Sink Node-Oriented Cascading Failure (BSN-OCF) model. The model extracts the network and application layers to describe the MA and models the load and capacity of service units and physical devices. The concept of a business sink node is introduced to address the challenge of directly calculating load. Furthermore, the Assessment Method of Structural Loss (AMSL) is proposed to quantify the vulnerability of the MA. This method overcomes the limitations of previous approaches, which focused solely on the loss of topology. Experiments and results validate the effectiveness of the proposed model. This work provides a self-assessment method for the MA and offers valuable support for optimizing its deployment structure in the future.
Chunyang Zheng, Jinfa Wang, Shuaizong Si, Zhiwen Pan, Limin Sun 0001
CSCWD3
2025 Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program Exploration
abstract
Protocol reverse engineering (PRE) aims to infer the protocol formats of unknown protocols. Existing techniques, whether Network-Trace based or Execution-Trace based methods, face two main limitations: a reliance on the quality and scale of traffic datasets, which often leads to low accuracy and poor generalization; and a failure to adequately consider the multi-format characteristic prevalent in real-world protocols (i.e., the same protocol may support multiple different formats).To address these challenges, we propose ProbePRE—a PRE tool that performs multi-format extraction on protocol handlers by autonomously generating packets. ProbePRE employs three key techniques: (1) an execution tracing strategy enhanced with implicit data flow analysis to obtain more detailed execution information; (2) constraint extraction methods tailored for different program structures to pass protocol validation; and (3) an innovative constraint combination algorithm to construct effective packets that guide the protocol handler to execute diverse protocol parsing paths. In our experimental evaluation, we compared ProbePRE with 4 state-of-the-art PRE tools in terms of field segmentation accuracy. The results demonstrated that ProbePRE achieved an F1 score of 0.88, significantly outperforming existing methods. Furthermore, evaluations on 6 protocol handlers indicated that ProbePRE attained 83% completeness in multi-format extraction tasks. Notably, in basic block coverage tests, ProbePRE achieved a 67% improvement over traditional traffic dataset methods, which fully validates the effectiveness of its path exploration capabilities.
Dingzhao Xue, Yibo Qu, Xin Chen 0123, Shuaizong Si, Shichao Lv, Zhiqiang Shi, Limin Sun 0001
ASE5
2025 Automated Flaw Detection for Industrial Robot RESTful Service
Puzhuo Liu, Yaowen Zheng, Dongliang Fang, Shuaizong Si, Zhiwen Pan, Limin Sun 0001
VMCAI (2)5
2025 Discovering PLC Web Application Vulnerabilities Impacting Physical Control Using LLM-Based Fuzzing
Jiaxing Cheng, Dongliang Fang, Zhongwei Gu, Shichao Lv, Shuaizong Si, Limin Sun 0001
WASA (1)5
2025 Asynchronous federated learning based zero trust architecture for the next generation industrial control systems
Feifei Lv, Hangyu Wang, Zhiwen Pan, Rongkang Sun, Shuaizong Si, Shichao Lv, Limin Sun 0001
Comput. Networks5
2025 Detection of cyberattack in Industrial Control Networks using multiple adaptive local kernel learning
Fei Lv 0010, Hangyu Wang, Rongkang Sun, Zhiwen Pan, Shuaizong Si, Shichao Lv, Limin Sun 0001
Comput. Secur.5
2025 Task-oriented and attractor regularized multi-task learning for environmental spatial-temporal time series prediction
Fei Lv 0010, Shuaizong Si
Knowl. Inf. Syst.2
2024 Hierarchical Aligned Multimodal Learning for NER on Tweet Posts
abstract
Mining structured knowledge from tweets using named entity recognition (NER) can be beneficial for many downstream applications such as recommendation and intention under standing. With tweet posts tending to be multimodal, multimodal named entity recognition (MNER) has attracted more attention. In this paper, we propose a novel approach, which can dynamically align the image and text sequence and achieve the multi-level cross-modal learning to augment textual word representation for MNER improvement. To be specific, our framework can be split into three main stages: the first stage focuses on intra-modality representation learning to derive the implicit global and local knowledge of each modality, the second evaluates the relevance between the text and its accompanying image and integrates different grained visual information based on the relevance, the third enforces semantic refinement via iterative cross-modal interactions and co-attention. We conduct experiments on two open datasets, and the results and detailed analysis demonstrate the advantage of our model.
Hong Li 0004, Yimo Ren, Jie Liu 0079, Shuaizong Si, Hongsong Zhu, Limin Sun 0001
AAAI5
2024 MOMR: A Threat in Web Application Due to the Malicious Orchestration of Microservice Requests
abstract
Microservice is an increasingly favored architecture for constructing modern web applications and the fast-paced business requirements facilitate the transmission of microservice traffic among distributed servers. In contrast to traditional architectures, microservice architecture has tight inherent dependencies between microservice units when supporting web application business. Attackers can excavate these dependencies to maliciously orchestrate microservice requests, scheduling microservice traffic to converge on the target link. This attack disrupts link and application quality of service, bringing new potential threats to web applications and cyberspace security. This work analyzes and evaluates the threat due to the malicious orchestration of microservice requests (MOMR) with the initial intention of promoting microservice application security and other information system security based on the microservice architecture. A Cross-Layer Coupling (CLC) model is proposed that aims to describe microservice traffic transmission, which efficiently supports the threat evaluation. A Path-aware Microservice Traffic Scheduling (PMTS) attack method is imposed on the CLC model so that it can construct the MOMR threat accurately. To demonstrate the effectiveness of the proposed method in evaluating the MOMR threat, a comprehensive analysis is performed on a typical microservice application and a semi- physical simulation platform. The result shows the threat causes performance degradation and impacts the network, such as a packet loss rate of up to 79% and an RTT increase of 600% of the target link.
Chunyang Zheng, Jinfa Wang, Shuaizong Si, Zhi Li 0018, Limin Sun 0001
ICC3
2024 MSGFuzzer: Message Sequence Guided Industrial Robot Protocol Fuzzing
abstract
Industrial robots are widely used in industrial control systems (ICS). Once compromised, it could be maliciously controlled by attackers, endangering manufacturing processes or even human lives. Therefore, timely discovery of vulnerabilities in industrial robots is essential. Protocol fuzzing is a popular method for discovering protocol implementation vulnerabilities. However, the intricate workflow of industrial robots imposes strict message sequence constraints on message execution. Moreover, the overhead of sequence constraint satisfaction is exacerbated by the redundant messages in message sequences and the inherent delays in physical domain execution. These challenges make it difficult for fuzzers to penetrate deep code paths for fuzzing effectively. In this paper, we propose MSGFuzzer, a message sequence-guided industrial robot protocol fuzzer. Specifically, we filter the original traffic based on message byte characteristics and gener-ate message sequences. After that, we distinguish the sequence constraints for each message through the feedback mechanism of the industrial robot. To reduce state-guidance time, we construct the minimal message sequence based on the constraint conditions of messages. We evaluated MSGFuzzer on a real industrial robot. The results show that MSGFuzzer discovered 12 unique crashes. Note that this is at least 71.4% more effective than state-of-the-art protocol fuzzers in crash discoveries
Yang Zhang 0145, Dongliang Fang, Puzhuo Liu, Laile Xi, Xin Chen 0123, Shuaizong Si, Limin Sun 0001
ICST7
2024 MICABAC: Multidimensional Industrial Control Attribute-Based Access Control Model
abstract
As the Industrial Control System (ICS) increasingly merges with the Internet, the security threats have been increasing from internal users and external hackers. These challenges are further intensified by the facts: industrial control devices and protocols, leading to the inadequacy of traditional access control models in tackling the intricacies of ICS. We identify attributes that are optimally aligned with the specific needs of the ICS environment and propose the Multidimensional Industrial Control Attribute-Based Access Control Model (MICABAC) as a customized solution. MICABAC model significantly improves access control security and is finer granularity by selecting and evaluating required attributes within various ICS. We have been validated in two real-world ICS environments: the Gas Pipe Network System (GPNS) and the Computer Numerical Control (CNC) machine tool. Experiments indicate that by integrating MICABAC into the existing system, the maximum delay for access requests is 63.83 ms. In terms of accuracy in defending against malicious attacks, the GPNS achieves 96.49% and the CNC reaches 94.86%. Finally, we discuss the advantages and limitations of MICABAC and explore potential directions for future research.
Hangyu Wang, Fei Lv 0010, Yuqi Chen 0001, Shuaizong Si, Zhiwen Pan, Degang Sun, Limin Sun 0001
SMC4
2024 Modified local Granger causality analysis based on Peter-Clark algorithm for multivariate time series prediction on IoT data
abstract
Abstract Climate data collected through Internet of Things (IoT) devices often contain high‐dimensional, nonlinear, and auto‐correlated characteristics, and general causality analysis methods obtain quantitative causality analysis results between variables based on conditional independence tests or Granger causality, and so forth. However, it is difficult to capture dynamic properties between variables of temporal distribution, which can obtain information that cannot be obtained by the mean detection method. Therefore, this paper proposed a new causality analysis method based on Peter‐Clark (PC) algorithm and modified local Granger causality (MLGC) analysis method, called PC‐MLGC, to reveal the causal relationships between variables and explore the dynamic properties on temporal distribution. First, the PC algorithm is applied to compute the relevant variables of each variable. Then, the results obtained in the previous stage are fed into the modified local Granger causality analysis model to explore causalities between variables. Finally, combined with the quantitative causality analysis results, the dynamic characteristic curves between variables can be obtained, and the accuracy of the causal relationship between variables can be further verified. The effectiveness of the proposed method is further demonstrated by comparing it with standard Granger causality analysis and a two‐stage causal network learning method on one benchmark dataset and two real‐world datasets.
Fei Lv 0010, Shuaizong Si, Xing Xiao
Comput. Intell.2
2024 RIETD: A Reputation Incentive Scheme Facilitates Personalized Edge Tampering Detection
abstract
Edge nodes provide service cooperatively in edge computing, where third-party nodes are common. However, they cannot be fully trusted and can intentionally alter service results (e.g., edge tampering). Although some mechanisms can help detect edge tampering, they come with additional detection overhead. It is essential to note that most edge nodes are willing to serve honestly. Therefore, it is reasonable to decrease the detection frequency for those nodes, which helps reduce the overhead. Reputation is the common way to evaluate trustworthiness. In this article, we propose a reputation incentive scheme called RIETD, which evaluates the reputations of edge nodes using their detection results. Moreover, RIETD is loosely coupled with detection mechanisms as an external service. Reputation is the fundamental parameter in RIETD, as it determines an acrlong EN’s appraisal weight on other nodes, personalized detection strategy, and node’s obtained revenues in one service. We demonstrate that RIETD does not significantly reduce the overall detection capability while the overhead is reduced effectively. For instance, when the tampering rate of edge nodes is 10%, and the target detection rate is 90% of a specific detection mechanism, RIETD reduces overhead by approximately 60%. If a full-reputation node is detected to have tampered with the results, its reputation recovery time is similar to the time required for reputation to improve from 0 to 1. Moreover, a node’s expected revenue is lower than that of an honest node, emphasizing the importance of serving honestly and continuously for edge nodes to earn higher revenue.
Fei Lyu 0001, Shuaizong Si, Hongsong Zhu, Limin Sun 0001
IEEE Internet Things J.4
2023 Intrusion Detection Based on Sampling and Improved OVA Technique on Imbalanced Data
abstract
Network-based Intrusion Detection(NID) is an effective means to deal with network attacks. NID is able to detect different types of network attacks by analyzing network traffic. However, in the real world, network traffic contains majority and minority class attacks as well as a large number of normal traffic samples. The imbalance in the number of training samples of various types of network traffic makes network intrusion detection very poor. Due to the lack of training samples, traditional NID can’t learn the characteristics of minority class attacks, which leads to the failure of NID to detect minority class attacks. Therefore, in order to solve the problem brought by imbalanced data, we propose a network intrusion detection algorithm based on the sampling and improved One-vs-All(OVA) technique. The dataset is balanced by downsampling the majority class data based on K-means clustering and oversampling the minority class data based on Auxiliary Classifier Generative Adversarial Network(ACGAN), improve classification accuracy through OVA-based model training and testing. We conduct validation experiments on the NSL-KDD dataset, and the experimental results show that the proposed method achieves excellent results in terms of Accuracy, Precision, Recall and F1-score. Compared with existing state-of-the-art methods, the proposed method not only achieves excellent detection performance with low false positive rate, but also addresses the learning problem of imbalanced data more effectively.
Yongfei Liu, Hong Li 0004, Wenyuan Zhang 0002, Fei Lyu 0001, Shuaizong Si
CSCWD5
2023 CSEDesc: CyberSecurity Event Detection with Event Description
Gaosheng Wang, Shuaizong Si, Hongsong Zhu, Limin Sun 0001
ICANN (3)4
2023 ChainDet: A Traffic-Based Detection Method of Microservice Chains
abstract
With the increasing prevalence of contemporary web applications built upon microservice architecture, intricate dependencies emerge among numerous microservices within specific network areas. These microservice dependencies contain critical information that can significantly aid network managers in optimizing network performance and enhancing application security. This paper introduces ChainDet, a traffic-based method specifically designed for detecting microservice dependencies. Notably, ChainDet is non-intrusive, and capable of handling mixed and encrypted traffic, making it suitable for network managers’ requirements. By leveraging the TSLC and TPD algorithms, ChainDet effectively detects both Inter-microservice Dependencies and Microservice Chains. Experimental results confirm the high accuracy and completeness rate of ChainDet in identifying microservice dependencies in both open-world and isolated environments. This method offers valuable insights for network managers seeking to accurately detect and model microservice dependencies.
Chunyang Zheng, Jinfa Wang, Shuaizong Si
IPCCC3
2023 CNN-PSO-KELM: A Deep Learning Intrusion Detection Model for Imbalanced IoT Data
abstract
Both the real network environment of IoT devices and the most of publicly available datasets suffer from the problem of sample imbalance. Traditional intrusion detection models fail to effectively identify minority samples. Therefore, this paper proposes a CNN-PSO-KELM model aimed at enhancing the model’s detection capabilities in imbalanced data, particularly, for minority samples. This model employs an improved dual-layer convolutional neural network (CNN) for feature extraction, followed by label classification using kernel extreme learning machine (KELM). It achieves the combination of the generalization ability of CNN and the high learning ability of KELM. To address the performance degradation caused by the random initialization of KELM parameters, particle swarm optimization (PSO) is introduced to assist in parameter acquisition for KELM. The effectiveness of this improvement has been verified on three IoT datasets: NSL-KDD, CIC-IDS2017, and Bot-IoT. Compared to traditional deep learning algorithms, CNN-PSO-KELM significantly improves the detection accuracy for imbalanced data.
Fei Lv 0010, Rongkang Sun, Hangyu Wang, Shuaizong Si, Zhe Bu, Chengsheng Zhou, Limin Sun 0001
MSN5