VLDB 2026 Research / reviewers in the wild / expert
Ling Hu 0001
dblp:42/5567-1
· DBLP profile ↗
13ranked-venue papers
6as first author
13since 2021 · last 2026
0009-0004-4191-0630ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM Services
Zhihuang Liu, Ling Hu 0001, Yonghao Tang, Tongqing Zhou, Fang Liu 0002, Zhiping Cai |
WWW | 2 |
| 2026 | BIFM: an effective similar payload attribution approach for cybercriminal detection using bitmap index table and fuzzy matchingabstractAbstract The payload attribution system has been proposed to analyze network traffic and assist investigators in identifying flows containing specific excerpts to locate criminals and potential victims. However, various attacks or data leakage behaviors can obscure and scatter the crucial portion of flow payloads to evade detection. Although existing payload attribution techniques strive to enhance the data reduction ratio and reduce false positive rates, research on similar payload querying is notably lacking. In this study, we introduce bitmap index table fuzzy matching (BIFM), a method for digesting network traffic to query and trace variants of malicious traffic. Unlike deterministic bitmap-index PAS that require deterministic bit co-occurrence/alignment between the query excerpt and the stored flow bitmap, an assumption violated when payloads are split or jumbled, BIFM overcomes this limitation via progressive relaxation with fuzzy matching and verification. Leveraging the bitmap index table and fuzzy matching, BIFM efficiently identifies flows containing excerpts or their variants (excerpts that change their appearance by splitting or jumbling) by relaxing the matching conditions for candidate malicious flows. To enhance BIFM’s accuracy, we also propose no-shingling and packet caching mechanisms. We extensively evaluate BIFM’s performance using a dataset constructed from real campus network IP-trace data. Our results demonstrate that BIFM outperforms existing state-of-the-art solutions, achieving an accuracy improvement of $\sim $10% without significantly increasing processing time. Changsheng Hou, Ling Hu 0001, Xionglve Li, Bingnan Hou, Zhiping Cai |
Comput. J. | 3 |
| 2026 | Efficient router fingerprinting in IPv6 networksabstractAbstract The pervasive interconnection of heterogeneous routing devices forms the fundamental infrastructure of modern Internet communication, making accurate router vendor identification a critical capability for multiple domains including network topology mapping, intelligent traffic engineering, and proactive cybersecurity defense. While Internet Protocol version 6 (IPv6) has achieved widespread global deployment as the next-generation Internet protocol, the opaque nature of its addressing mechanisms and protocol behaviors has created significant challenges in router attribute detection across IPv6 networks, leaving a crucial gap in network visibility and security analytics. To address this pressing challenge, we present IPv6 Router FingerPrinting (6RFP), an innovative lightweight fingerprinting methodology that establishes a new paradigm for IPv6 router vendor identification by systematically combining two complementary analytical dimensions: (i) comprehensive EUI-64 interface identifier analysis that captures vendor-specific hardware encoding patterns embedded in IPv6 addresses, and (ii) sophisticated IPv6 Identification Field characteristic profiling that reveals distinctive vendor implementations. Through extensive evaluation across diverse network environments, 6RFP demonstrates highly effective detection capabilities, achieving 85.79% accuracy—representing a remarkable 86.01% improvement over current state-of-the-art techniques—while maintaining minimal computational overhead suitable for real-time deployment. Ling Hu 0001, Tao Yang 0041, Xionglve Li, Bingnan Hou, Zhiping Cai |
Comput. J. | 2 |
| 2026 | 6CAI: Efficient large-scale IPv6 cellular address identification
Ling Hu 0001, Xionglve Li, Bingnan Hou, Zhiyuan Jiang, Zhiping Cai |
Comput. Networks | 1 |
| 2026 | HMap: Efficient Internet-Wide IPv6 Scanning With Dynamic SearchabstractInternet-wide scanning is integral to network measurement and security analysis, but the expansive address space of IPv6 limits existing approaches in achieving efficient global-scale scans. This study introduces HMap, an innovative IPv6 scanner that markedly improves scan efficiency and coverage through the implementation of a dynamic search (DS) technique, relying solely on IPv6 routeable BGP prefixes. DS employs a dynamic feedback-driven probing strategy that uses information from previous replies to prioritize more promising address regions in subsequent scans. In Internet-wide scans over IPv6, encompassing both ping-like and traceroute-like scans with DS, HMap has demonstrated its capability to discover 2.29 million non-alias active target addresses, 0.13 million peripheries/middleboxes, and 1.61 million router interfaces, using only million-scale probes. This represents a noteworthy improvement of 1.91 times, 1.63 times, and 12.38 times, respectively, compared to current state-of-the-art alternatives. Additionally, by utilizing an efficient target generation algorithm (TGA) that more effectively leverages seed addresses, HMap expands the non-alias active address count to 44.05 million. This coverage spans 18.97 thousand ASes with a one-hour scan at a limited probing speed of 100 Kpps. The volume of active IPv6 addresses is 4.88 times larger than the currently disclosed largest IPv6 hitlists, providing a more diverse set of IPv6 networks. Unlike prior IPv6 scan studies that preclude their use for Internet-scale security analysis, we also conduct the Internet-wide security scans of IPv6 networks, focusing on the exposed internal IPv6 devices and security-sensitive services in IPv6 routers. Bingnan Hou, Zhenzhong Yang, Xianzheng Meng, Ling Hu 0001, Xionglve Li, Zhiping Cai |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2026 | Comprehensive Measurement of IPv6 Inbound Source Address Validation Deployment via Global Counter Side-Channel
Ling Hu 0001, Zhihuang Liu, Xionglve Li, Bingnan Hou, Zhiyuan Jiang, Bo Yu 0008, Zhiping Cai |
IEEE Trans. Netw. | 1 |
| 2025 | Pruning as Scanning: Towards Internet-Wide IPv6 Network Periphery Discovery
Tao Yang 0041, Ling Hu 0001, Bingnan Hou, Zhenzhong Yang, Zhiping Cai |
INFOCOM | 2 |
| 2025 | 6CNIS: An Efficient IPv6 Cellular Network Identification SystemabstractWith the rapid development of 5G technology and the Internet of Things, the high-speed, low-latency, and massive connectivity capabilities have made cellular networks a critical infrastructure. However, IPv6 cellular address identification, crucial in cellular network measurement, remains a significant gap. On the one hand, the combination of IPv6 with 5G renders existing methods ineffective; on the other hand, the vast address space of IPv6 makes large-scale network scanning infeasible. To address this gap, we propose a novel IPv6 cellular network identification system, leveraging round-trip time and IPv6 interface identifiers to classify network connection types for / 48 prefixes accurately. Our method achieves an accuracy of over 99% on publicly available global datasets. Furthermore, by incorporating target generation scans, we have first achieved large-scale probing worldwide. Ling Hu 0001, Bingnan Hou, Zhiping Cai |
IWQoS | 1 |
| 2025 | Grey Rhino Warning: IPv6 is Becoming Fertile Ground for Reflection Amplification AttacksabstractDistributed Denial-of-Service (DDoS) attacks represent a cost-effective and potent threat to network stability. While extensively studied in IPv4 networks, DDoS implications in IPv6 remain underexplored. The vast IPv6 address space renders brute-force scanning and amplifier testing for all active addresses impractical. Innovatively, this work investigates ASlevel vulnerabilities to reflection amplification attacks in IPv6. One prerequisite for amplification presence is that it is located in a vulnerable autonomous system (AS) without inbound source address validation (ISAV) deployment. Hence, the analysis focuses on two critical aspects: global detection of ISAV deployment and identification of amplifiers within vulnerable ASes. Specifically, we develop a methodology combining ICMP Time Exceeded mechanisms for ISAV detection, employ IPv6 address scanning for amplifier identification, and utilize dual vantage points for amplification verification. Experimental results reveal that 4,460 ASes (61.36% of measured networks) lack ISAV deployment. Through scanning approximately 47 M active addresses, we have identified reflection amplifiers in 3,507 ASes. The analysis demonstrates that current IPv6 networks are fertile ground for reflection amplification attacks, alarming network security. Ling Hu 0001, Tao Yang 0041, Bingnan Hou, Zhiping Cai, Bo Yu 0008 |
IWQoS | 1 |
| 2025 | Prevalence Overshadows Concerns? Understanding Chinese Users' Privacy Awareness and Expectations Towards LLM-Based Healthcare ConsultationabstractLarge Language Models (LLMs) are increasingly gaining traction in the healthcare sector, yet expanding the threat of sensitive health information being easily exposed and accessed without authorization. These privacy risks escalate in regions like China, where privacy awareness is notably limited. While some efforts have been devoted to user surveys on LLMs in healthcare, users' perceptions of privacy remain unexplored. To fill this gap, this paper contributes the first user study (n=846) in China on privacy awareness and expectations in LLM-based healthcare consultations. Specifically, a healthcare chatbot is deployed to investigate users' awareness in practice. Information flows grounded in contextual integrity are then employed to measure users' privacy expectations. Our findings suggest that the prevalence of LLMs amplifies health privacy risks by raising users' curiosity and willingness to use such services, thus overshadowing privacy concerns. 77.3% of participants are inclined to use such services, and 72.9% indicate they would adopt the generated advice. Interestingly, a paradoxical “illusion” emerges where users' knowledge and concerns about privacy contradict their privacy expectations, leading to greater health privacy exposure. Our extensive discussion offers insights for future LLM-based healthcare privacy investigations and protection technology development. Zhihuang Liu, Ling Hu 0001, Tongqing Zhou, Yonghao Tang, Zhiping Cai |
SP | 2 |
| 2025 | Split Learning on Segmented Healthcare DataabstractSequential data learning is vital to harnessing the encompassed rich knowledge for diverse downstream tasks, particularly in healthcare (e.g., disease prediction). Considering data sensitiveness, privacy-preserving learning methods, based on federated learning (FL) and split learning (SL), have been widely investigated. Yet, this work identifies, for the first time, existing methods overlook that sequential data are generated by different patients at different times and stored in different hospitals, failing to learn the sequential correlations between different temporal segments. To fill this void, a novel distributed learning frameworkSTSLis proposed by training a model on the segments in order. Considering that patients have different visit sequences,STSLfirst implements privacy-preserving visit ordering based on a secure multi-party computation mechanism. Then batch scheduling participates patients with similar visit (sub-)sequences into the same training batch, facilitating subsequent split learning on batches. The scheduling process is formulated as an NP-hard optimization problem on balancing learning loss and efficiency and a greedy-based solution is presented. Theoretical analysis proves the privacy preservation property ofSTSL. Experimental results on real-world eICU data show its superior performance compared with FL and SL ($5\% \sim 28\%$better accuracy) and effectiveness (a remarkable 75% reduction in communication costs). Ling Hu 0001, Tongqing Zhou, Zhihuang Liu, Fang Liu 0002, Zhiping Cai |
IEEE Trans. Big Data | 1 |
| 2024 | Split Learning on Multi-source Cross-Streams
Ling Hu 0001, Tongqing Zhou, Zhihuang Liu, Fang Liu 0002, Zhiping Cai |
ICONIP (5) | 1 |
| 2024 | SeCoSe: Toward Searchable and Communicable Healthcare Service Seeking in Flexible and Secure EHR SharingabstractCloud-assisted electronic health record (EHR) sharing plays an important role in modern healthcare systems but faces threats of distrust and non-traceability. The advent of blockchain offers an attractive solution to overcome this issue. Many efforts are devoted to promoting secure, flexible, and multi-featured blockchain-based EHR sharing. Yet, the problem of seeking out suitable healthcare providers and communicating information beyond the EHR has unfortunately been ignored. In this paper, we propose SeCoSe, a novel EHR sharing scheme to address these concerns. SeCoSe enables patients and their general practitioners to autonomously seek out and stay in touch with their preferred healthcare professionals. Specifically, a searchable and repeatable transformation identity-based encryption (SRTIBE) is proposed to achieve dynamic and flexible authorization updates. Moreover, we design attribute-identity mapping contracts and evidence-based contracts on the blockchain to enable on-demand retrieval of anonymous identities and ensure tamper resistance and traceability of system transactions. Furthermore, we employ the advanced messages on-chain protocol (AMOP) to facilitate the online communication of off-chain messages. Detailed security analysis and extensive evaluations demonstrate that SeCoSe is privacy-secure, traceable, and attack-resistant. SeCoSe has lower overhead for repeated authorization and transformation, on-chain transactions can be responded to within seconds, and online communication can handle the transmission of 49,000 messages in about 6 seconds. Zhihuang Liu, Ling Hu 0001, Zhiping Cai, Ximeng Liu |
IEEE Trans. Inf. Forensics Secur. | 2 |