Likun Liu

dblp:39/3116 · DBLP profile ↗
← Back
13ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0002-2113-4679ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 3 · 2 since 2021Systems, architecture and hardware · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Measuring security weaknesses in underground mobile app ecosystems at scale
Yicheng Guo, Zhichao Hu, Likun Liu, Mengmeng Ge 0003, Wanzong Peng, Xueshan Wang, Xiangzhan Yu
Comput. Secur.4
2025 TND: Two-stage non-invasive defense of intrusion detection system from adversarial attack
Zhichao Hu, Dewen Kong, Junzhong Miao, Gang Du, Likun Liu, Xiangzhan Yu
Comput. Networks6
2025 TOPLDM: Towards dynamic low overhead traffic obfuscation based on packet length distribution modification
Zhichao Hu, Likun Liu, Jiaxing Gong, Mengmeng Ge 0003, Xiangzhan Yu
Comput. Networks2
2025 CCLog: Actionable APT forensics via fused log semantics and provenance graph topology
Zhichao Hu, Likun Liu, Mengmeng Ge 0003, Xiangzhan Yu
Comput. Networks2
2025 Enmob: Unveil the Behavior with Multi-flow Analysis of Encrypted App Traffic
abstract
Abstract In the contemporary digital landscape, mobile applications have become the predominant conduit for internet connectivity and daily tasks. Simultaneously, the advent of application encryption technology has safeguarded users’ privacy. However, this encryption, while fortifying privacy, introduces challenges to security by hindering the effective management of network applications within encrypted data streams. Conventional detection methods for encrypted application traffic, relying heavily on statistical metrics like payload, packet size, and distribution, are constrained to single traffic flows, often yielding results of limited specificity. To address this limitation, our paper introduces an innovative approach that elucidates the multi-flow nature of application behavior traffic and provides context to encrypted application traffic. This method offers a more nuanced and comprehensive perspective for understanding and representing network traffic, even when encrypted. The efficacy of our approach was evaluated using a substantial volume of real network traffic data. Results indicate that our method achieves an average accuracy of 0.958 in identifying application behavior traffic and 0.955 in classifying application traffic. These outcomes signify a substantial enhancement over single network flow-based detection methods, demonstrating a notable 5.3% improvement.
Mengmeng Ge 0003, Likun Liu, Xiangzhan Yu, Vinay Sachidananda, Xiaofei Xie, Yang Liu 0003
Cybersecur.3
2025 SinkFlow: Fast and traceable root-cause localization for multidimensional anomaly events
Zhichao Hu, Likun Liu, Xiangzhan Yu
Eng. Appl. Artif. Intell.2
2024 An effective deep learning adversarial defense method based on spatial structural constraints in embedding space
Junzhong Miao, Xiangzhan Yu, Zhichao Hu, Yanru Song 0002, Likun Liu
Pattern Recognit. Lett.5
2023 GenéLive! Generating Rhythm Actions in Love Live!
abstract
This article presents our generative model for rhythm action games together with applications in business operation. Rhythm action games are video games in which the player is challenged to issue commands at the right timings during a music session. The timings are rendered in the chart, which consists of visual symbols, called notes, flying through the screen. We introduce our deep generative model, GenéLive!, which outperforms the state-of-the-art model by taking into account musical structures through beats and temporal scales. Thanks to its favorable performance, GenéLive! was put into operation at KLab Inc., a Japan-based video game developer, and reduced the business cost of chart generation by as much as half. The application target included the phenomenal "Love Live!", which has more than 10 million users across Asia and beyond, and is one of the few rhythm action franchises that has led the online era of the genre. In this article, we evaluate the generative performance of GenéLive! using production datasets at KLab as well as open datasets for reproducibility, while the model continues to operate in their business. Our code and the model, tuned and trained using a supercomputer, are publicly available.
Atsushi Takada, Daichi Yamazaki, Yudai Yoshida, Nyamkhuu Ganbat, Takayuki Shimotomai, Naoki Hamada, Likun Liu, Taiga Yamamoto, Daisuke Sakurai
AAAI7
2023 Securing Operating Systems Through Fine-Grained Kernel Access Limitation for IoT Systems
abstract
With the development of Internet of Things (IoT), it is gaining a lot of attention. It is important to secure the embedded systems with low overhead. The Linux Seccomp is widely used by developers to secure the kernels by blocking the access of unused syscalls, which introduces less overhead. However, there are no systematic Seccomp configuration approaches for IoT applications without the help of developers. In addition, the existing Seccomp configuration approaches are coarse-grained, which cannot analyze and limit the syscall arguments. In this article, a novel static dependent syscall analysis approach for embedded applications is proposed, which can obtain all of the possible dependent syscalls and the corresponding arguments of the target applications. So, a fine-grained kernel access limitation can be performed for the IoT applications. To this end, the mappings between dynamic library APIs and syscalls according with their arguments are built, by analyzing the control flow graphs and the data dependency relationships of the dynamic libraries. To the best of our knowledge, this is the first work to generate the fine-grained Seccomp profile for embedded applications.
Dongyang Zhan, Zhaofeng Yu, Xiangzhan Yu, Hongli Zhang 0001, Likun Liu
IEEE Internet Things J.6
2019 No Way to Evade: Detecting Multi-Path Routing Attacks for NIDS
abstract
In order to protect intranet security, the enterprises or organizations usually deploy one or multiple NIDS at ingress points. Each works independently and monitors the complete TCP flow. That said, a malicious signature to be detected can only be obtained from a TCP flow. Drawing on the feature, an attacker can split malicious signature into multiple substrings and transfer them in different flows to evade detection, which is named multi-path routing attack. In particular, the emerging new technology Multi-Path TCP (MPTCP) offers a hotbed for such attacks. To monitor multi-path routing attacks, this literature proposed a distributed asynchronous NIDS detection model (DANDM) which consists of three algorithms. In this model, each NIDS scans its own received data packets independently and the adjacent contents between two data packets with consecutive sequence numbers. For the latter, all NIDS scans cooperatively through broadcast state information. To demonstrate the validity of our model, we take attack density and number of segmented signatures as parameters to compare with Ma's algorithm.The results show that the performance of our DANDM is significantly better than that of Ma's, especially in the case of large number of segmented signatures.
Likun Liu, Hongli Zhang 0001, Xiangzhan Yu
GLOBECOM1
2018 An Efficient Security System for Mobile Data Monitoring
abstract
During the last decade, rapid development of mobile devices and applications has produced a large number of mobile data which hide numerous cyber‐attacks. To monitor the mobile data and detect the attacks, NIDS/NIPS plays important role for ISP and enterprise, but now it still faces two challenges, high performance for super large patterns and detection of the latest attacks. High performance is dominated by Deep Packet Inspection (DPI) mechanism, which is the core of security devices. A new TTL attack is just put forward to escape detecting, such that the adversary inserts packet with short TTL to escape from NIDS/NIPS. To address the above‐mentioned problems, in this paper, we design a security system to handle the two aspects. For efficient DPI, a new two‐step partition of pattern set is demonstrated and discussed, which includes first set‐partition and second set‐partition. For resisting TTL attacks, we set reasonable TTL threshold and patch TCP protocol stack to detect the attack. Compared with recent produced algorithm, our experiments show better performance and the throughput increased 27% when the number of patterns is 106. Moreover, the success rate of detection is 100%, and while attack intensity increased, the throughput decreased.
Likun Liu, Hongli Zhang 0001, Xiangzhan Yu, Yi Xin 0002, Muhammad Shafiq 0003, Mengmeng Ge 0003
Wirel. Commun. Mob. Comput.1
2010 A Transparently-Scalable Metadata Service for the Ursa Minor Storage System
Shafeeq Sinnamohideen, Raja R. Sambasivan, James Hendricks, Likun Liu, Gregory R. Ganger
USENIX ATC4
2007 An Analytical Framework and Its Applications for Studying Brick Storage Reliability
abstract
The reliability of a large-scale storage system is influenced by a complex set of inter-dependent factors. This paper presents a comprehensive and extensible analytical framework that offers quantitative answers to many design tradeoffs. We apply the framework to a number of important design strategies that a designer and/or administrator must face in reality, including topology-aware replica placement, proactive replication that uses small background network bandwidth and unused disk space to create additional copies. We also quantify the impact of slow (but potentially more accurate) failure detection and lazy replacement of failed disks. We use detailed simulation to verify and refine our analytical model. These results demonstrate the versatility of the framework and serve as a solid step towards more quantitative studies of fundamental system tradeoffs between reliability, performance, and cost in large-scale distributed storage systems.
Ming Chen 0004, Wei Chen 0013, Likun Liu, Zheng Zhang 0001
SRDS3