VLDB 2026 Research / reviewers in the wild / expert
Liang Fang 0009
dblp:45/705-9
· DBLP profile ↗
19ranked-venue papers
2as first author
11since 2021 · last 2026
0009-0007-6448-5720ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 2 since 2021Security and privacy · 4 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | How Far Are We from Automatically Identifying Violations of the Data Minimization Principle in Privacy Policies?abstractData protection laws and regulations require service providers to disclose data practices in privacy policies, specifying what personal information is processed and for what purposes. For compliance, these data practices must adhere to the data minimization principle, limiting the processing of personal information to what is directly relevant and necessary for the service purposes. However, data minimization is context-dependent, making violations difficult to define and quantify in privacy policies. Meanwhile, privacy policies are semantically complex and unstructured, hindering accurate extraction of fine-grained data practices and large-scale automated evaluation. To address these issues, we propose DataMini, a human--LLM collaborative evaluation framework for identifying violations of the data minimization principle in privacy policies. First, DataMini categorizes data minimization violations into two dimensions: inherent violations and contextual violations, establishing fine-grained evaluation criteria. Second, we construct a compliance baseline by mining high-frequency patterns from large-scale privacy policies and integrating expert knowledge to derive compliance mappings for human--LLM collaborative evaluation. Finally, the compliance baseline can automatically verify data practices that satisfy the data minimization principle, enabling the framework to focus exclusively on identifying suspected violations to improve efficiency and accuracy. Extensive evaluations demonstrate that DataMini exhibits superior data practice extraction accuracy of 83.46% and achieves an F1-score of 0.8180 for identifying data minimization violations in privacy policies, reducing manual evaluation effort by approximately 80%. Ziyan Zhou 0001, Yanru He, Yunchuan Guo, Liang Fang 0009, Fenghua Li 0001 |
SIGIR | 5 |
| 2025 | BitInfer: An Automated Field Semantic Inference Method Based on Genetic AlgorithmabstractPrivate protocols are widely used on the network to improve efficiency and protect privacy. However, it lacks standard protocols to unify the communication process and improve security. Protocol Reverse Engineering (PRE) aims to infer the syntax, semantics, and timing of the unknown protocol. In detail, it always infers the field information and the state machine. Yet, the results of existing PRE methods focus byte-level, and the target setting is an empirical process. To overcome the shortage, we proposed BitInfer for binary protocols. BitInfer uses a set of field detectors, including Length Detector, Timestamp Detector, Entropy Detector, Sequence Detector and Reserve Detector to divide the protocols into bit-level field and get the confidence of them. Then we randomly choose the combination of detector tuples to get the init population by repeating the process for a specific times. Finally, we use NSGA2 as the intergrade algorithm to deal with the field conflict. Experiments show that the result of BitInfer precisely solve the conflict and extend to bit level. Liang Fang 0009, Junhai Yang, Zifu Li, Fenghua Li 0001 |
COMPSAC | 2 |
| 2025 | Automatic State Machine Inference for Binary Protocol Reverse EngineeringabstractProprietary protocols are widely used to ensure efficient data transmission, enhance privacy, and meet specific application requirements. However, the lack of public standards often leaves their security inadequately evaluated, posing significant challenges for network security. Protocol Reverse Engineering (PRE) is used to analyze protocols by inferring their structure and behavior. However, existing PRE methods primarily focus on protocol format analysis, neglecting Protocol State Machine (PSM) analysis, which can lead to insufficient detection of abnormal behaviors and potential vulnerabilities. To address this, we propose an automatic PSM inference framework for unknown protocols, incorporating a fuzzy membership-based auto-converging DBSCAN algorithm for protocol format clustering, followed by a session clustering algorithm based on Needleman-Wunsch and K-Medoids algorithm to classify sessions by protocol type. Finally, we refine a probabilistic PSM algorithm to infer protocol states and transitions. Experiments show that our method can infer PSMs while enabling precise protocol classification. Junhai Yang, Fenghua Li 0001, Liang Fang 0009, Yunchuan Guo, Zifu Li |
GLOBECOM | 4 |
| 2025 | SEHAP: Secure and Efficient Handover Authentication Protocol in LEO Satellite Non-Terrestrial NetworksabstractLEO satellite non-terrestrial networks (NTN) utilize satellites in Low Earth Orbit (LEO) to dynamically establish global communication service and own significant promise. The dynamic nature of LEO satellite NTN necessities efficient handover authentication protocols. However existing schemes cannot be directly applied in LEO satellite NTN because of their low efficiency and security. To address these problems, we propose a handover authentication protocol to quickly and securely authenticate the user’s identity during the handover process. In our scheme, we incorporate an implicit session-bound random challenge to facilitate mutual authentication and key agreement between the User Equipments (UEs) and satellites. To improve authentication efficiency, we propose a batch handover mechanism to transfer the necessary security contexts, largely reducing the handover authentication cost. We verify our protocol’s security using BAN logic and Tamarin prover. The performance evaluation shows that SEHAP outperforms other schemes in both communication and computational efficiency in LEO satellite NTN. Yunchuan Guo, Jing Wang 0174, Kui Geng, Zifu Li, Fenghua Li 0001, Liang Fang 0009 |
ICASSP | 6 |
| 2025 | Dynamically Optimize MTD Strategy in Satellite Computing Systems Using A2C Reinforcement LearningabstractThe Satellite Computing System (SCS) faces an increasing number of attacks. Although Moving Target Defense (MTD) can effectively mitigate attacks in ground networks, it is not well-suited for SCS due to the highly dynamic nature of both SCS traffic and attackers’ scanning behaviors. In this paper, we propose a dynamic MTD strategy optimization scheme using Advantage Actor-Critic (A2C) reinforcement learning. Specifically, we formulate the MTD strategy optimization for SCS as a Markov Decision Process (MDP). Furthermore, by accounting for the uncertainty in attack behavior changes, we apply A2C reinforcement learning to optimize the MTD strategy within the MDP framework. Experimental results demonstrate that our scheme effectively reduces the frequency of scanning hits, shortens the duration attackers can hold addresses, and minimizes the impact of MTD on quality of service. Yunchuan Guo, Shoukun Guo, Fenghua Li 0001, Faqun Jiang, Liang Fang 0009 |
ICASSP | 6 |
| 2025 | An on-the-fly framework for usable access control policy mining
Yunchuan Guo, Mingjie Yu, Fenghua Li 0001, Zhen Pang, Liang Fang 0009 |
Comput. Secur. | 6 |
| 2025 | OPMonitor: Continuously monitoring residual over-granted permissions in verified access control policies
Yunchuan Guo, Zhe Sun 0005, Mingjie Yu, Fenghua Li 0001, Liang Fang 0009 |
Comput. Secur. | 6 |
| 2024 | Missing Data Completion for Network Traffic with Continuous Mutation Based on Tensor Ring DecompositionabstractThe completion of missing network traffic is of great significance for network operation and maintenance. In recent years, the low-rank tensor completion (LRTC) techniques based on tensor ring (TR) decomposition have attracted much attention. In general, the LRTC model requires the stability of the whole tensor space. However, continuous mutation of network traffic is very common in real networks. At this time, existing completion work has difficulty in capturing the global low-rank feature of normal data and ignores the local continuous feature of mutation data, leading to a decrease in completion performance. To solve the above problems, we propose a low-rank tensor completion model that can adapt to various continuous mutation patterns of network traffic. The original tensor is represented as the sum of a normal tensor and a mutation tensor to extract their features respectively. Then, an algorithm based on the alternating direction method of multipliers (ADMM) is developed to solve the proposed model. Finally, our experimental results on both synthetic and real datasets indicate that our model can adapt to various missing data completion under different continuous mutation patterns, and has more accurate completion performance compared to advanced models. Fanfan Hao, Zhu Wang 0005, Yaobing Xu, Siyuan Leng, Liang Fang 0009, Fenghua Li 0001 |
CSCWD | 5 |
| 2024 | Custominer: Mining Customized Access Control Policies under User-Defined ConstraintsabstractAccess control policies play a critical role in securing sensitive data and protecting personal rights in environments such as cloud computing and IoT. These policies, typically created by sysadmins, specify which users are authorized to access specific resources under certain conditions. However, the manual creation and revision of these policies to align with security objectives is often error-prone and labor-intensive. In this paper, we present Custominer, a policy mining tool designed to assist sysadmins in proactively generating and customizing access control policies that meet predefined security requirements. Custominer enables sysadmins to define security goals as constraints, and then automatically mines policies that satisfy these constraints from access logs. The policy mining task is framed as a local search optimization problem, utilizing a MaxSAT solver to efficiently eliminate suboptimal policy candidates. Our experiments, conducted on four real-world datasets, show that Custominer outperforms existing state-of-the-art methods in terms of both accuracy and efficiency. Yunchuan Guo, Mingjie Yu, Ziyan Zhou 0001, Liang Fang 0009, Fenghua Li 0001 |
HPCC | 5 |
| 2022 | DICOF: A Distributed and Collaborative Framework for Hybrid DDoS Attack DetectionabstractHybrid distributed denial-of-service (DDoS) attack, which utilizes multiple types of DDoS attack to launch one attack event, has become more rampant. However, existing researches for DDoS attack detection mainly focus on the single attack scene and ignore the hybrid attack incident. To deal with the hybrid DDoS attack detect problem, we propose a distributed and collaborative DDoS detection framework(DICOF) to detect and classify multiple DDoS attack simultaneously. Firstly, we propose an entropy-based method to quickly identify the DDoS attack events by measuring the distribution of the total length of inbound and outbound packets for network traffics. Then, we adopt a GRU(Gated Recurrent Unit) based classification method to distinguish the type of different DDoS attacks contained in one attack event. Experiment results show that the DICOF is able to detect hybrid DDoS attack events at millisecond level and classify different DDoS attacks precisely. Siyuan Leng, Yingke Xie, Yunchuan Guo, Liang Fang 0009, Fenghua Li 0001 |
ISCC | 5 |
| 2022 | Efficiently Constructing Topology of Dynamic NetworksabstractAccurately constructing dynamic network topology is one of the core tasks to provide on-demand security services to the ubiquitous network. Existing schemes cannot accurately construct dynamic network topologies in time. In this paper, we propose a novel scheme to construct the ubiquitous network topology. Firstly, ubiquitous network nodes are divided into three categories: terminal node, sink node, and control node. On this basis, we propose two operation primitives (i.e., addition and subtraction) and three atomic operations (i.e., intersection, union, and fusion), and design a series of algorithms to describe the network change and construct the network topology. We further use our scheme to depict the specific time-varying network topologies, including Satellite Internet and Internet of things. It demonstrates that their communication and security protection modes can be efficiently and accurately constructed on our scheme. The simulation and theoretical analysis also prove that the efficiency of our scheme, and effectively support the orchestration of protection capabilities. Fenghua Li 0001, Cao Chen, Yunchuan Guo, Liang Fang 0009, Chao Guo 0002, Zifu Li |
TrustCom | 4 |
| 2020 | The Linear Geometry Structure of Label Matrix for Multi-label Learning
Tianzhu Chen, Fenghua Li 0001, Fuzhen Zhuang, Yunchuan Guo, Liang Fang 0009 |
DEXA (2) | 5 |
| 2020 | Decision-Making for Intrusion Response: Which, Where, in What Order, and How Long?abstractGenerating fine-grained response policies is a fundamental problem for Intrusion Response Systems (IRSs). Although existing schemes determine countermeasures and defense points efficiently, they ignore the deployment orders and execution durations of the selected countermeasures, which may impact response performance. To address this problem, by considering four attributes (i.e., attack damage, deployment cost, negative impact on QoS, and security benefit), we propose a decisionmaking framework for IRSs to reach fine-grained decisions to balance attack damage and response cost. We formulate decisionmaking as a single-objective optimization problem. To efficiently solve this problem, a Genetic Algorithm with Three-dimensional Encoding (GATE) is proposed to not only select countermeasures and defense points, but also determine deployment orders and execution durations. Simulation results demonstrate the efficiency of our approach. Yunchuan Guo, Zifu Li, Fenghua Li 0001, Liang Fang 0009, Lihua Yin, Jin Cao 0001 |
ICC | 5 |
| 2020 | Dynamic countermeasures selection for multi-path attacks
Fenghua Li 0001, Siyuan Leng, Yunchuan Guo, Kui Geng, Zhen Wang 0013, Liang Fang 0009 |
Comput. Secur. | 7 |
| 2020 | Incentive mechanism for cooperative authentication: An evolutionary game approach
Liang Fang 0009, Guozhen Shi, Lianhai Wang, Shujiang Xu, Yunchuan Guo |
Inf. Sci. | 1 |
| 2020 | Securing instruction interaction for hierarchical management
Fenghua Li 0001, Zifu Li, Liang Fang 0009, Yaobing Xu, Yunchuan Guo |
J. Parallel Distributed Comput. | 3 |
| 2018 | Real-Time Data Incentives for IoT SearchesabstractEffectively collecting real-time data is a fundamental problem in IoT (Internet of Things) searches. In the IoT, most data are linked with the owner's private information and cannot be publicly released on the Internet. This invalidates the use of crawlers to collect data in IoT searches. As a result, effectively motivating potential data providers (PDPs) to provide real-time on demand data becomes a key requirement for the development of an IoT search service. To address this problem, we acknowledge the realistic assumption of incomplete information, and propose a buyout-auction framework, with the constraint of QoD (Quality of Data), to collect real-time data and maximize bidders' payoff. Simulation results demonstrate that our approach can drive PDPs to participate in bidding in a timely manner and provide data under the constraints of QoD to IoT search service providers. Yunchuan Guo, Liang Fang 0009, Kui Geng, Lihua Yin, Fenghua Li 0001 |
ICC | 2 |
| 2017 | Who Is Visible: Resolving Access Policy Conflicts in Online Social NetworksabstractMillions of the co-owned items, such as photos, comments etc., are uploaded to OSNs everyday. These co-owned items contain plenty of privacy information. One important information is the social relations which can be inferred from the items. When sharing these items, the owners may just want to make themselves visible alone while hiding these social relations. It leaves us a problem that making each single co-owner visible alone is acceptable, but showing them together is not allowed. To avoid the privacy leakage, we should choose proper owners to be visible to the visitor. Unfortunately, traditional access control for OSNs cannot fit this concern thus cannot provide a suitable answer. To deal with this problem, we first define the `dislike relation' and its corresponding conflicts. Then we propose a communication-intensity-based scheme to measure the social intimacies between the visitor and co-owners of the accessed item. Based on the social intimacies, we can provide a decision support when conflicts occur. Case studies and user studies are performed to illustrate the effectiveness of our proposed scheme. Liang Fang 0009, Lihua Yin, Qiaoduo Zhang, Fenghua Li 0001, Binxing Fang |
GLOBECOM | 1 |
| 2017 | Pricing Privacy Leakage in Location-Based Services
Fenghua Li 0001, Liang Fang 0009, Ben Niu 0001, Kui Geng, Hui Li 0006 |
WASA | 3 |