Wei Su 0006

dblp:50/4091-6 · DBLP profile ↗
← Back
29ranked-venue papers
0as first author
22since 2021 · last 2026
0000-0002-7424-3123ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 24 · 20 since 2021Systems, architecture and hardware · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Joint Covertness and Secrecy Design for Wireless Communications Under Active Attacks
Huihui Wu, Yucong Wang, Wei Su 0006, Feifei Gao 0001
WCNC4
2026 KONTROL: Offloading Data-Driven Congestion Control Intelligence for IoT Networks
abstract
Congestion control is a cornerstone of reliable data transport, but current fixed-rule algorithms struggle with the diverse link characteristics of Internet of Things deployments. A more critical challenge is that many resource-constrained Internet of Things devices lack the computational power to run advanced, data-driven methods locally, hindering performance and adaptability. To address this, we introduce KONTROL, a service framework that decouples congestion control intelligence from end devices by offloading the decision-making logic to a centralized congestion control server. This enables lightweight clients to leverage sophisticated control strategies without bearing the computational burden. As a critical instance within our framework, we implement Deep Reinforcement Learning agents on the server, which learn to optimize window adjustments for each sender based on real-time relayed network statistics via kernel modifications. Our experimental evaluation across challenging simulated environments shows that the proposed scheme achieves consistently high throughput and low latency while maintaining fairness. These results validate the viability of the offloading paradigm, paving the way for more flexible transport protocols for the broader Internet of Things ecosystem.
Liang Wang 0058, Wei Su 0006, Fei Song 0001
IEEE Internet Things J.4
2026 Exploiting Fine-Grained CSI for Covert Communications in RIS-Assisted Integrated Sensing and Communication System
abstract
In this paper, we explore the fine-grained channel state information (CSI) obtained through the sensing function in an reconfigurable intelligent surface (RIS)-assisted integrated sensing and communication (ISAC) system to support the efficient covert communications in the system. We first construct a new fine-grained CSI model for the RIS-assisted ISAC system and propose a novel covert communication scheme based on the new CSI model. We then develop theoretical models for the detection error probability, Cramér-Rao Bound and covert rate to depict the covertness, sensing and covert communication performances under the proposed scheme. Based on these theoretical models, we further formulate an optimization problem for covert rate maximization through optimizing the reflection coefficient in RIS and the transmit powers for covert/probing signals. With the help of the homogenization for quadratic constrained quadratic programming, semi-definite relaxation and Dinkelbach transform, an efficient alternating optimization (AO) algorithm is devised to tackle this complex optimization problem. Finally, extensive numerical results are presented to demonstrate the performance enhancement for covert communication in the RIS-assisted ISAC system from exploring the fine-grained CSI and AO-based parameter optimization therein.
Huihui Wu, Wei Su 0006, Feifei Gao 0001, Hongke Zhang, Xiaohong Jiang 0001
IEEE J. Sel. Areas Commun.2
2026 D2D and Edge Server-Enabled Computation Offloading for Resource-Constrained Wireless Networks
abstract
For the computation offloading via device-to-device (D2D) terminals and edge servers in a resource-constrained wireless network (RCWN), mobile users can choose to offload their tasks to nearby D2D terminals or edge servers according to quality of service (QoS) requirements (e.g., load balancing at the network edge) by mobile edge computing. To this end, we first formulate computation offloading as a multi-user collaborative resource dynamic management optimization problem that aims to maximize user satisfaction utility function, carefully considering critical issues like the non-uniform distribution of computational resources, user's risk awareness, and the dynamic changes between computing-intensive regions and computing-sparse regions. This is a nonlinear and nonconvex optimization problem, which is generally difficult to be solved. We then construct a resource management scheme for resource allocation of the edge server based on convex optimization. Furthermore, we propose a dynamic offloading update strategy achieving the maximum of user satisfaction utility function based on game theory. The simulation results are presented to show that our proposed method can increase the total system satisfaction utility by nearly 20% and reduce the system energy consumption by nearly 10% compared to the benchmark methods.
Bin Yang 0010, Wei Su 0006, Hongke Zhang, Tarik Taleb
IEEE Trans. Mob. Comput.3
2026 Service Request Recovery Against Satellite Failure in Space-Terrestrial Integrated Networks
abstract
Space-Terrestrial Integrated Networks (STINs) serve as the crucial infrastructure for future 6G Networks, while network failures in STINs pose serious threats to the services provided by such networks. This paper focuses on the service request recovery in STINs against a satellite failure. For the uplink requests, downlink requests, and relay requests disrupted by a satellite failure, we explore both independent recovery and joint recovery. In independent recovery where each type of requests is recovered independently and sequentially, an Integer Linear Programming (ILP) model and related heuristic are proposed to identify the optimal recovery solution for each type of requests. We further explore the joint recovery where all requests are recovered jointly and simultaneously to achieve a high recovery efficiency. The ILP formulation and time-efficient heuristic are developed as well for the joint recovery. Finally, extensive numerical results are provided to demonstrate the effectiveness of the joint recovery and proposed heuristics in service recovery under a satellite failure.
Lisheng Ma, Wei Su 0006, Xiaohong Jiang 0001
IEEE Trans. Netw. Serv. Manag.3
2025 AoI and Energy-Driven Dynamic Cache Updates for Wireless Edge Networks
abstract
Wireless edge networks (WENTs) can provide edge services to support various time-critical Internet of Things (IoT) applications, like autonomous vehicles, where cache content updates are significant to maintaining information freshness quantified as Information of Age (AoI). However, frequent content updates result in high energy consumption at the edge nodes. This article investigates the cache content updates in WENTs, aiming to ensure information freshness and low energy consumption. To this end, we propose a rainbow deep reinforcement learning-based cache content update scheme (RB-DRN). In the RB-DRN scheme, we first establish a Markov decision process (MDP) to characterize the process of cache update. By fully taking advantage of R-Learning empowered Rainbow DQN, we then make optimal strategy to obtain the minimum long-term average overhead associated with energy consumption and information freshness. Extensive simulation results are presented to validate our proposed RB-DRN scheme and also to illustrate that our RB-DRN scheme outperforms the benchmark scheme in terms of information freshness and energy consumption.
Bin Yang 0010, Wei Su 0006, Haoru Li, Tarik Taleb
IEEE Internet Things J.3
2025 Service Migration Optimization for System Overhead Minimization in VECNs via Deep Reinforcement Learning
abstract
In vehicular edge computing networks (VECNs), service migration among edge servers is critical to addressing the challenge of service interruption caused by high mobility of vehicles and limited coverage of each edge server. In this article, we tackle this challenge by optimizing service migration among edge servers through a joint management of resource scheduling and dynamic server selection. Specifically, we aim to minimize system overhead consisting of system time and energy consumption taking account for resource scheduling and dynamic server selection, which is formulated as a constrained optimization problem. To solve this optimization problem, we propose a learning-driven joint resource scheduling and dynamic server selection strategy (LD-JRS3) based on deep reinforcement learning. Under the LD-JRS3 strategy, we first model joint resource scheduling and dynamic server selection as a Markov decision process (MDP). Then, we adopt a recurrent neural network (RNN)-empowered feedback mechanism based on historical information to achieve the optimal system performance. We fully consider the advantages of the soft actor-critic (SAC) algorithm to obtain the optimal decision (i.e., computational resources allocation and servers selection). Notably, we employ an improved SAC algorithm, which takes into account prioritized experience replay and automatic tuning of temperature parameters. Extensive simulation results are presented to verify the effectiveness of our proposed LD-JRS3 algorithm, and also to illustrate the advantage of our algorithm on improving the time consumption and energy consumption compared with the baseline schemes. LD-JRS3 has 19%, 24%, and 11% higher utility values than DDRN, DQN-based, and multiarmed bandit-based systems, respectively.
Bin Yang 0010, Wei Su 0006, Yihua Peng, Tarik Taleb
IEEE Internet Things J.3
2025 A Joint Caching and Offloading Strategy Using Reinforcement Learning for Multi-access Edge Computing Users
Wei Su 0006, Gaofeng Hong, Haoru Li
Mob. Networks Appl.2
2025 Correction: A Joint Caching and Offloading Strategy Using Reinforcement Learning for Multi-access Edge Computing Users
Wei Su 0006, Gaofeng Hong, Haoru Li
Mob. Networks Appl.2
2025 ByteTuning: Watermark Tuning for RoCEv2
abstract
RDMA over Converged Ethernet v2 (RoCEv2) is one of the most popular high-speed datacenter networking solutions. Watermark is the general term for various trigger and release thresholds of RoCEv2 flow control protocols, and its reasonable configuration is an important factor affecting RoCEv2 performance. In this paper, we propose ByteTuning, a centralized watermark tuning system for RoCEv2. First, three real cases of network performance degradation caused by non-optimal or improper watermark configuration are reported, and the network performance results of different watermark configurations in three typical scenarios are traversed, indicating the necessity of watermark tuning. Then, based on the RDMA Fluid model, the influence of watermark on the RoCEv2 performance is modeled and evaluated. Next, the design of the ByteTuning is introduced, which includes three mechanisms. They are (1) using simulated annealing algorithm to make the real-time watermark converge to the near-optimal configuration, (2) using network telemetry to optimize the feedback overhead, (3) compressing the search space to improve the tuning efficiency. Finally, We validate the performance of ByteTuning in multiple real datacenter networking environments, and the results show that ByteTuning outperforms existing solutions.
Lizhuang Tan, Zhuo Jiang, Kefei Liu 0004, Pengfei Huo, Huiling Shi, Wei Zhang 0049, Wei Su 0006
IEEE Trans. Cloud Comput.8
2025 Joint Relay and Mode Selection for Covert Communication in Wireless Relay Systems
abstract
This paper investigates the joint relay and transmission mode selection for covert communication in a wireless relay system with amplify-and-forward (AF) forwarding mode, which consists of one source, multiple AF relays, one destination, one friendly jammer and one warden, and each relay can switch between the half-duplex (HD) and full-duplex (FD) transmission modes. We first explore the fundamental covert performance of the system when it works in either the fixed HD or fixed FD mode. Based on this result, we then investigate the covert performance of the system with optimal (resp. random) relay selection and random (resp. optimal) mode selection, so as to reveal the achievable covert performance in the system with solely the relay selection or mode selection. Building upon above results, we further design the optimal joint relay and mode selection scheme, and develop related theoretical models for performance analysis. Finally, we provide extensive numerical results to conduct a comprehensive comparison between the relay selection and mode selection on their achievable covert performance and to illustrate the performance enhancement from adopting the joint relay and mode selection in the relay system.
Yan Liu 0051, Huihui Wu, Wei Su 0006, Yulong Shen 0001, Xiaohong Jiang 0001
IEEE Trans. Commun.3
2024 CCRA: Covert Channel-based Reliable Authentication Scheme for UAV-assisted RAN
abstract
UAVs can significantly improve the access networks of next-generation mobile networks during the building of smart cities. Drones equipped with base stations can expand the coverage of communication networks and assist more users’ devices to access the 5G/6G network, in which reliable authentication for drones becomes essential. However, traditional authentication methods still utilize the overt channel to transmit identity and key information, which are vulnerable and very easy to be eavesdropped, hijacked, and forged by malicious third parties. Therefore, this paper proposes an authentication scheme (CCRA). It includes 1) covert channels to assist authentication and key negotiation, and 2) a covert channel algorithm (EIDOP). Specifically, CCRA transmits fake identity information, part of the key information, and unimportant data in the overt channel, while using the covert channel to transmit important data and another part of the key for authentication and key negotiation to enhance the reliability of authentication. In addition, this paper proposes an algorithm called EIDOP based on the order of packet delay intervals to establish the covert channel for embedding and hiding important information. Finally, we conduct experiments on physical machines and compare EIDOP with other covert timing mechanisms to conclude that our algorithm has better concealment and latency overhead and still guarantees a very low BER under such circumstances.
Wei Quan 0001, Xiaoting Ma, Mingyuan Liu 0001, Jinfa Wang, Wei Su 0006
GLOBECOM7
2024 Achieving Covertness and Secrecy in Wireless Communications with Active Attackers
abstract
In this paper, we investigate the covertness and secrecy guarantees of wireless communications in an active attacker scenario where attackers perform detection/eavesdropping and jamming simultaneously. Both detection and eavesdropping attacks need to be counteracted, such that the covertness and secrecy guarantees in wireless communications can be achieved. To understand the covertness and secrecy performances, we provide theoretical modeling for covertness outage probability and secrecy outage probability, respectively. Based on the the-oretical model, we conduct theoretical analysis to identify the covert secrecy rate (CSR) under power control (PC)-based secure transmission scheme. Extensive numerical results are provided to illustrate the achievable performances and also reveal the impact of the active attackers on the CSR.
Huihui Wu, Feifei Gao 0001, Ling Xing 0001, Wei Su 0006
WCNC5
2024 Integrating Smart Computility for Subflow Orchestration in Remote Virtual Services
abstract
The burgeoning domain of the metaverse has sparked significant interest from a diverse array of industries, including healthcare services. However, the metaverse and its associated applications present various challenges to existing networks. First, to meet the increasing demands of the metaverse, there is a need for enhanced bandwidth, reduced latency, and improved packet loss control. Furthermore, the transmission mechanism should exhibit flexibility to automatically adapt to the diverse hybrid needs of different healthcare services. In this article, a multipath transmission-based paradigm tailored for the metaverse-based healthcare services is developed. Significantly, we devise an orchestration framework to reconcile edge-side subflow management with diverse healthcare applications. Using machine learning techniques, the framework can produce near-optimal subflow adjustment strategies for client nodes and miscellaneous services. Comprehensive experiments are performed on applications with diverse requirements to validate the adaptability of the framework to the application needs. The experimental results demonstrate that the proposed method enables the network to autonomously adapt to changing network conditions and service requirements. This includes applications' preferences for high throughput, low delay, and high stability. Moreover, the test results show that the proposed approach can notably decrease the occurrences of network quality falling below the minimum requirement. Given its adaptability and impact on network quality, this work paves the way for future metaverse-based healthcare services.
Liang Wang 0058, Wei Su 0006, Fei Song 0001, Ilsun You
IEEE J. Biomed. Health Informatics2
2023 GrayINT - Detection and Localization of Gray Failures via Hybrid In-band Network Telemetry
Kuichao Zhang, Wei Su 0006, Huiling Shi, Wei Zhang 0049
APNOMS2
2022 Jamming and Link Selection for Joint Secrecy/Delay Guarantees in Buffer-Aided Relay System
abstract
This paper explores the joint secrecy and delay guarantees based on opportunistic jamming and link selection in a wireless relay system consisting of a source, a destination, multiple buffer-aided relays and a passive eavesdropper wiretapping over both hops. Based on the information of link state and buffer status, we design a novel transmission scheme based on link selection and jammer selection, which dynamically grants transmission links different priorities for packet delivery, such that the constraints on both secrecy outage probability and packet delay are jointly satisfied. To understand the performance of the new scheme, we then apply the bitmap technique and Markov chain theory to develop a complete theoretical framework for the modelling of three fundamental metrics, namely reliability outage probability, packet discarding probability and secrecy/delay constrained throughput (SDT). Finally, we provide extensive simulation and numerical results to validate our theoretical modelling, as well as to demonstrate that the proposed scheme is superior to the benchmarks in terms of SDT.
Ji He 0002, Jia Liu 0009, Wei Su 0006, Yulong Shen 0001, Xiaohong Jiang 0001, Norio Shiratori
IEEE Trans. Commun.3
2022 NetChain: A Blockchain-Enabled Privacy-Preserving Multi-Domain Network Slice Orchestration Architecture
abstract
Multi-domain networking slice orchestration is an essential technology for the programmable and cloud-native 5G network. However, existing research solutions are either based on the impractical assumption that operators will reveal all the private network information or time-consuming secure multi-party computation which is only applicable to limited computation scenarios. To provide agile and privacy-preserving end-to-end network slice orchestration services, this paper proposes NetChain, a multi-domain network slice orchestration architecture based on blockchain and trusted execution environment. Correspondingly, we design a novel consensus algorithm CoNet to ensure the strong security, scalability, and information consistency of NetChain. In addition, a bilateral evaluation mechanism based on game theory is proposed to guarantee fairness and Quality of Experience by suppressing the malicious behaviors during multi-domain network slice orchestration. Finally, the prototype of NetChain is implemented and evaluated on the Microsoft Azure Cloud with confidential computing. Experiment results show that NetChain has good performance and security under the premise of privacy-preserving.
Guobiao He, Wei Su 0006, Ningchun Liu, Sajal K. Das 0001
IEEE Trans. Netw. Serv. Manag.2
2022 Joint Emergency Data and Service Evacuation in Cloud Data Centers Against Early Warning Disasters
abstract
As important network infrastructures to support data storage and service delivery for worldwide users, cloud data centers are facing great threaten by frequent disasters around the world and thus the survivability of cloud data centers becomes a critical issue. Since both data and service evacuations are desired at the same time under a real disaster scenario, this paper studies a joint design of them to fight against disasters. We consider a disaster that can present an early warning time before it really affects cloud data centers, and by exploiting the intrinsic interplay between data and service evacuations and efficiently utilizing the early warning time we propose a joint data and service evacuation scheme for emergency protection. We first formulate the joint design as two optimal Integer Linear Program (ILP) models. Notice that the protection process is highly time-sensitive due to the early warning time constraint, two time-efficient heuristics are then designed by carefully selecting evacuated services and candidate evacuation nodes to achieve a better sharing of network resources between data backup and service migration. Extensive numerical results demonstrate the efficiency of the proposed scheme on improving survivability of data and services in cloud data centers. With a set of given resource and early warning time constraints, this work can guide data center operators to achieve a tradeoff between data backup and service migration.
Lisheng Ma, Wei Su 0006, Bin Wu 0002, Bin Yang 0010, Xiaohong Jiang 0001
IEEE Trans. Netw. Serv. Manag.2
2021 In-band Network Telemetry Task Orchestration based on Multi-objective Optimization
abstract
In-band network telemetry task orchestration is to study how to reasonably select business flows to carry in-band network telemetry tasks to cover all necessary switches and ports. An inappropriate orchestration scheme not only fails to meet the requirements, but may reduce the performance of network telemetry. This paper proposes a multi-objective optimization-based in-band network telemetry task orchestration algorithm, while taking into account both the aspects of telemetry: freshness and intrusion. The experimental results show that the proposed scheme outperforms in terms of freshness and intrusion.
Wei Su 0006, Lizhuang Tan
APNOMS2
2021 In-band Network Telemetry: A Survey
Lizhuang Tan, Wei Su 0006, Wei Zhang 0049, Jianhui Lv, Jingying Miao
Comput. Networks2
2021 ROAchain: Securing Route Origin Authorization With Blockchain for Inter-Domain Routing
abstract
The inter-domain routing with BGP is highly vulnerable to malicious attacks, due to the lack of a secure means of verifying authenticity and legitimacy of inter-domain routes. Resource Public Key Infrastructure (RPKI) is a new security infrastructure to prevent the most devastating prefix hijacks in BGP by maintaining a Route Origin Authorization (ROA) repository. However, RPKI is a centralized hierarchical architecture that may empower the centralized authorities to unilaterally revoke or compromise any IP prefixes under their control. To eliminate the risks of RPKI, we present ROAchain, a novel BGP security infrastructure based on blockchain. Different from RPKI, ROAchain is a decentralized architecture, in which each AS maintains a globally consistent and tamper-proof ROA repository, authenticating the legitimacy of route origin and preventing BGP prefix hijacks. To ensure the strong consistency, scalability, and security of ROAchain, a novel consensus algorithm is proposed, in which the credence value, collective signing, sharding, and a penalty mechanism are introduced. Moreover, a compatibility design is proposed without changing the current BGP protocol. Finally, ROAchain is implemented in Golang and validated on the Google Cloud.
Guobiao He, Wei Su 0006, Jiarui Yue, Sajal K. Das 0001
IEEE Trans. Netw. Serv. Manag.2
2021 A Packet Loss Monitoring System for In-Band Network Telemetry: Detection, Localization, Diagnosis and Recovery
abstract
Network measurement provides rich data for network monitoring, control, and management. In-band network telemetry (INT) is a new network measurement technology that uses normal data packet to collect network information hop-by-hop. However, the design and implementation of INT protocol cannot do anything about packet loss: (1) The end-to-end telemetry mechanism makes INT unable to detect packet loss; (2) Since data packets may be lost due to various reasons, INT telemetry information will inevitably be lost. In summary, INT system by itself is unreliable. Incomplete telemetry data will seriously affect the performance of upper-layer network telemetry applications. In this paper, we present our successful experience in INT packet loss monitoring. We design, implement, and open source a powerful packet loss monitoring system for INT, called LossSight. The functions of LossSight include the detection of packet loss events, the deduction of the time and location of the losses, the diagnose of the root cause of the losses, and the recovery of the lost INT information. Experiment results show that LossSight provides excellent performance and extremely low overhead, including detection accuracy and diagnostic precision close to 100%, and detection latency of just milliseconds. In particular, LossSight uses a generative adversarial network to recover lost telemetry information, with excellent accuracy and reliability. LossSight has been running stably in the supercomputing interconnection environment of the National Supercomputing Center in Jinan. We suggest that all INT applications that require reliable telemetry information should be implemented based on LossSight.
Lizhuang Tan, Wei Su 0006, Wei Zhang 0049, Huiling Shi, Jingying Miao, Pilar Manzanares-Lopez
IEEE Trans. Netw. Serv. Manag.2
2020 OpenQUIC: software-defined transmission like building blocks
Lizhuang Tan, Wei Su 0006, Xiaochuan Gao, Wei Zhang 0049
CoNEXT2
2020 Proactive Connection Migration in QUIC
abstract
QUIC provides a secure, reliable and low-latency communication foundation for HTTP. QUIC uses the connection ID to uniquely determine a connection from client to server. After the user switches the network, the server recognizes the user request according to the connection ID and continues to provide services through the connection migration technology. This paper proposes a Proactive Connection Migration (PCM) mechanism for QUIC. PCM gives QUIC the ability to select the optimal network in a heterogeneous network environment. Firstly, PCM actively perceives the different networks available to users. Then, PCM integrates the network quality exploration of different paths into the user’s multiple request actions. Finally, PCM takes response delay and jitter into account, and uses online learning to find the optimal network for current Internet service. Experimental results show that, compared with original QUIC, the average response delay of QUIC with PCM is reduced by 59.43% at most.
Lizhuang Tan, Wei Su 0006, Xiaochuan Gao, Wei Zhang 0049
MobiQuitous2
2020 Securing Route Origin Authorization with Blockchain for Inter-Domain Routing
Guobiao He, Wei Su 0006, Jiarui Yue
Networking2
2020 A DDoS attack detection based on deep learning in software-defined Internet of things
abstract
With the popularity of Internet of Things (IoT) applications, security has become extremely important. A recent distributed denial-of-service (DDoS) attack revealed vulnerabilities that are prevalent in IoT, and many IoT devices accidentally contributed to the DDoS attack. software-defined network provides a way to securely manage IoT devices. In this paper, we first present a general framework for software-defined Internet of Things (SD-IoT). The proposed framework consists of a SD-IoT controller, SD-IoT switches integrated with an IoT gateway, and IoT devices. We then propose a deep learning detection algorithm based on time series using the proposed SD-IoT framework. Finally, experimental results show that the proposed algorithm has good performance.
Jiushuang Wang, Ying Liu 0018, Wei Su 0006, Huifen Feng
VTC Fall3
2020 Early warning disaster-aware service protection in geo-distributed data centers
Lisheng Ma, Wei Su 0006, Bin Wu 0002, Bin Yang 0010, Xiaohong Jiang 0001
Comput. Networks2
2020 TD-Root: A trustworthy decentralized DNS root management architecture based on permissioned blockchain
Guobiao He, Wei Su 0006, Jiarui Yue
Future Gener. Comput. Syst.2
2011 On the convergence condition and convergence time of BGP
Huaming Guo, Wei Su 0006, Hongke Zhang, Sy-Yen Kuo
Comput. Commun.2