VLDB 2026 Research / reviewers in the wild / expert
Yi Sun 0006
dblp:65/2709-6
· DBLP profile ↗
25ranked-venue papers
5as first author
17since 2021 · last 2025
0000-0002-1427-8682ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 2 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | KeBugFix: Automated Program Repair Framework Based on Code Retrieval Enhancement and LLM Agent
Chaopeng Wang, Yi Sun 0006, Chao Wang 0061, Zan Zhou 0001, Yujiao Yuan, Xu Xiang, Fei Xiao 0005 |
IEEE Big Data | 2 |
| 2025 | PLAA: Packet-level Adversarial Attacks in Network Traffic DetectionabstractDeep neural networks (DNNs) are widely applied in Network-based Intrusion Detection System (NIDS) due to their high accuracy. However, DNNs are highly susceptible to adversarial attacks, which generate malicious traffic to evade NIDS detection. Existing approaches often adapt adversarial attacks from computer vision (CV) tasks to the NIDS domain, overlooking the fundamental differences between CV and NIDS. This results in two major issues: 1) The generated network traffic may become invalid, 2) The generated traffic may lose its original attack semantics. To address these issues, this paper proposes an adversarial attack specifically designed for NIDS. Instead of directly generating flow-level features, our approach incrementally generates packet-level features to construct adversarial traffic. During the generation process, the semantic integrity of the traffic is monitored at each stage, effectively avoiding the issues of invalid traffic and semantic loss observed in existing methods. We evaluate our attack algorithm against current NIDS models using the CIC-UNSW-NB15, CIC-DDoS2019, and CIC-IDS-2017 datasets. The proposed method achieves an average evasion success rate of 92.78%, while ensuring that the generated adversarial traffic remains semantically consistent with the original malicious traffic. Jinhao You, Zan Zhou 0001, Yi Sun 0006, Lei Zhang 0157, Changqiao Xu |
TrustCom | 4 |
| 2025 | A Fairness-aware Incentive Framework for Heterogeneous Federated Learning with Bifurcated Reverse Auction DesignabstractFederated Learning (FL) is an emerging distributed learning framework designed to address isolated data island and protect privacy. Besides, Clustered Federated Learning (CFL) is introduced as an efficient multitask scheme to solve heterogeneous problems in FL where clients' data is distributed in non-i.i.d. (non-independent and identically distributed) scenarios. However, due to bandwidth limitation and latency tolerance, the server can only select a subset of clients to participate. Average selection and only selecting low heterogeneous client groups lead to severe results. How to fairly select clients and improve efficient model performance in heterogeneous scenarios with limited communication has become a key issue. We propose a fairness-aware clustered federated learning (FACFL) incentive framework which balances collective and individual fairness. Specifically, our framework models CFL as a bifurcated reverse auction that consists of a first-layer cluster auction and a second-layer client auction. Our framework can dynamically adjust the par-ticipation of clusters and clients according to the communication capabilities. The experimental results on the CIFAR-10 dataset demonstrate that FACFL improves the model performance in severely heterogeneous and communication limited scenarios. Additionally, FACFL can maintain a high level of the training fairness with different numbers of clients. Sizhe Huang, Zan Zhou 0001, Xiping Li, Yi Sun 0006, Changqiao Xu |
WCNC | 6 |
| 2025 | ADPF: Anti-inference differentially private protocol for federated learning
Zirun Zhao, Zhaowen Lin, Yi Sun 0006 |
Comput. Networks | 3 |
| 2025 | Automatic Toxicity Evaluation for Human-LLM Conversations in Flexible Manufacturing System With Duplex Fine-Tuned LLMsabstractFlexible manufacturing systems (FMS), empowered by the Industrial Internet of Things (IIoT), have become a cornerstone of Industry 6.0 by enabling dynamic production adaptation, real-time equipment monitoring, and intelligent scheduling. As these systems increasingly incorporate large language models (LLMs) to support functions such as knowledge querying, decision assistance, and predictive maintenance, ensuring the safety and reliability of human-LLM conversations has become a pressing concern. Specifically, LLMs may generate toxic, biased, or privacy-violating outputs when interacting with sensitive IIoT data and production logic, potentially compromising operational safety. To address this challenge, we propose AugLLMSen, an automated toxicity evaluation framework tailored to the IIoT-driven FMS context. AugLLMSen integrates a question automatic expansion mechanism (Q-Judge) and an output toxicity evaluation model (O-Judge) into a closed-loop pipeline, enabling large-scale assessment of LLM safety across diverse industrial scenarios. Experimental results on open- and closed-source LLMs demonstrate the effectiveness and accuracy of our approach in identifying toxic responses and guiding safe deployment of LLMs in flexible manufacturing environments. Chao Wang 0061, Zan Zhou 0001, Yi Sun 0006, Yuning Cui 0002, Yasser D. Al-Otaibi, Ali Kashif Bashir, Changqiao Xu |
IEEE Internet Things J. | 4 |
| 2024 | A Hierarchical PoW-Powered Access Mechanism for Shuffling-Based Moving Target Defense SystemabstractFor DDoS attacks, Moving Target Defense (MTD) has emerged as a promising solution. However, existing MTD defense systems often overlook the issue of user access. In this paper, we implement a hierarchical Proof of Work (PoW) authentication mechanism for user access in a shuffling-based proxy-switching MTD system. Our mechanism integrates the PoW authentication with the proxy cluster architecture and dynamically adjusts the difficulty level of PoW based on information from multiple proxies. The mechanism was deployed on a real MTD defense system for performance evaluation. By adapting the PoW scheduling approach for MTD systems, the experimental results demonstrate that our mechanism can adapt to and leverage dynamic network structures. In terms of mitigating DDoS attacks and ensuring user experience, it shows improvements compared to directly migrating traditional methods. Zeyuan Guo, Changjun Ren, Lin Yan 0006, Yi Sun 0006 |
IWCMC | 5 |
| 2024 | Stealthy Adversarial Attacks on Intrusion Detection Systems: A Functionality-Preserving ApproachabstractIntrusion Detection Systems (IDS) are essential tools in network security, which aims to identify malicious traffic to safeguard computers. In recent years, with the application and advancement of machine learning in fields such as image recognition, autonomous driving, and natural language processing (NLP), machine learning-based intrusion detection systems have also rapidly developed. Unfortunately, such IDSs exhibit poor defensive capabilities when facing carefully crafted and imperceptible adversarial attacks. Adversarial attacks manipulate adversarial samples, causing malicious traffic to be misclassified as normal traffic, thereby bypassing intrusion detection systems. Given that adversarial attacks on IDSs in the real world largely operate under the premise of model agnosticism, this paper proposes a black-box attack based on Generative Adversarial Networks (GANs) and active learning. During the iterative training of GANs, the discriminator is covertly constructed as a shadow model of the target IDS, and a generator capable of generating adversarial malicious traffic is trained. Finally, leveraging the transferability of adversarial attacks to DNN, the attack implemented on the shadow model is transferred to the target model, thereby attacking the intrusion detector: Unlike adversarial attacks against image classifiers, adversarial attacks against IDSs must also consider whether the added adversarial perturbations will affect the semantics and functionality of the original malicious traffic. Therefore, the constraint mechanism for modifying feature values is also an important consideration in this paper. Xiping Li, Yi Sun 0006, Detong Kong |
IWCMC | 3 |
| 2023 | BcIIS: Blockchain-Based Intelligent Identification Scheme of Massive IoT DevicesabstractWith the rapid development of loT technology, various loT devices enter our daily life. The continuously increasing scale of the massive loT devices in both of numbers and types further bring heavy pressure on loT network management and security. Therefore, how to accurately identify and efficiently manage so massive loT devices has become a challenge. In this paper, we propose BcllS, Blockchain-based Intelligent Identification Scheme of Massive loT Devices. It applies a decentralized identification architecture and realizes learning sustainably as well as efficiently identifying by updating the identification model constantly according to the ledger which is maintained by all gateways collaboratively. Experiments show that the identification accuracy can achieve up to 99.5 %. Yi Sun 0006, Ali Kashif Bashir, Marwan Omar |
GLOBECOM | 1 |
| 2023 | DroidHook: a novel API-hook based Android malware dynamic analysis sandbox
Yuning Cui 0002, Yi Sun 0006, Zhaowen Lin |
Autom. Softw. Eng. | 2 |
| 2023 | Potentially Unwanted App Detection for Blockchain-Based Android App MarketplaceabstractAndroid is a mobile operating system with a high degree of openness, which attracts an increasing number of developers. Android application (or simply, app) marketplace provides a trusted source of apps for users and a more equitable competition environment for individual developers and commercial teams. Blockchain’s advantages of decentralization and data immutability are suitable for the Android app marketplace, which is mainly characterized by openness, equality, and security. However, this may also facilitate malicious developers to publish low-quality apps to display ads or steal users’ privacy for revenue. Therefore, blockchain-based app marketplaces have a strong need to identify those potentially unwanted apps (PUAs). In this article, we first introduce our blockchain-based app marketplace model. Then, we propose a new PUA detection method, mainly based on metadata and user ratings, and they are easily accessible from blockchain-based app marketplaces. Moreover, we introduce dynamic analysis to check whether the URLs visited by the app are in malicious URL blacklists since apps with massive access to these URLs tend to affect user experience. After that, we preprocess those complex and redundant features and represent each app as an embedding. Finally, to validate the effectiveness of our method, we utilize several clustering algorithms to represent these apps as clusters and search for suspicious PUA clusters. Our study reveals several characteristics of PUA and suggests that PUAs are still present and need to be urgently removed. Yuning Cui 0002, Yi Sun 0006, Zhaowen Lin, Baoquan Ma, Yujie Li 0001 |
IEEE Internet Things J. | 2 |
| 2023 | Hedera: A Permissionless and Scalable Hybrid Blockchain Consensus Algorithm in Multiaccess Edge Computing for IoTabstractMultiaccess edge computing (MEC) network, as one of the key infrastructures of IoT, provides cloud computing capabilities at the edge of the radio access network (RAN) by integrating telecommunication and IT services. Integrating blockchain into the MEC network can provide users with secure, private, and traceable edge computing services at the near end, thereby improving IoT security, privacy, and automated use of resources. Due to some characteristics of the MEC network, there are still some challenges to integrate blockchain and edge computing into one system, especially the consensus algorithm of blockchain. The resources of edge computing nodes are limited, and the scale of the network is constantly expanding. Therefore, the blockchain consensus algorithm for the MEC network should occupy as little computing resources as possible, be green, and be permissionless. This article proposes a permissionless and scalable consensus algorithm “Hedera” for MEC network, which has the advantages of permissionless, security, decentralization, scalability, and greenness. The Hedera consensus algorithm is a hybrid blockchain consensus algorithm that combines the permissionless Proof-of-Capacity algorithm and the permissioned asynchronous Byzantine algorithm. This article tests the fairness, throughput, scalability, latency, and resource consumption of the algorithm by developing and deploying a prototype system. The experimental results show that the Hedera algorithm proposed in this article is fair, the throughput reaches 13986.3 TPS, and the resource consumption is much lower than the PoW consensus. By analyzing its security and liveness, it can resist the sybil attack, nothing-at-stake attack, selfish mining attack, and message hijacking attack, and has good liveness. Chinmay Chakraborty, Yi Sun 0006 |
IEEE Internet Things J. | 4 |
| 2023 | Bl-IEA: A Bit-Level Image Encryption Algorithm for Cognitive Services in Intelligent Transportation SystemsabstractIn Intelligent Transportation Systems, images are the main data sources to be analyzed for providing intelligent and precision cognitive services. Therefore, how to protect the privacy of sensitive images in the process of information transmission has become an important research issue, especially in future no non-private data era. In this article, we design the Rearrangement-Arnold Cat Map (R-ACM) to disturb the relationship between adjacent pixels and further propose an efficient Bit-level Image Encryption Algorithm ($\text{B}{l}$-IEA) based on R-ACM. Experiments show that the correlation coefficients of two adjacent pixels are 0.0022 in the horizontal direction, -0.0105 in the vertical direction, and -0.0035 in the diagonal direction respectively, which are obviously weaker than that of the original image with high correlations of adjacent pixels. What’s more, the NPCR is 0.996120172, and the UACI is 0.334613406, which indicate that$\text{B}{l}$-IEA has stronger ability to resist different attacks compared with other solutions. Especially, the lower time complexity and only one round permutation make it particularly suitable to be used in the time-limited intelligent transportation field. Yi Sun 0006, Keping Yu, Ali Kashif Bashir, Xin Liao 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Web-based practical privacy-preserving distributed image storage for financial services in cloud computing
Cai Xiaohong, Yi Sun 0006, Zhaowen Lin, Muhammad Imran 0001, Keping Yu |
World Wide Web (WWW) | 2 |
| 2022 | PMRSS: Privacy-Preserving Medical Record Searching Scheme for Intelligent Diagnosis in IoT HealthcareabstractIn medical field, previous patients’ cases are extremely private as well as intensely valuable to current disease diagnosis. Therefore, how to make full use of precious cases while not leaking out patients’ privacy is a leading and promising work especially in future privacy-preserving intelligent medical period. In this article, we investigate how to securely invoke patients’ records from past case-database while protecting the privacy of both current diagnosed patient and the case-database and construct a privacy-preserving medical record searching scheme based on ElGamal Blind Signature. In our scheme, by blinded the healthy data of the patient and the database of the iDoctor, respectively, the patient can securely make self-helped medical diagnosis by invoking past case-database and securely comparing the blinded abstracts of current data and previous records. Moreover, the patient can obtain target searching information intelligently at the same time he knows whether the abstracts match or not instead of obtaining it after matching. It greatly increases the timeliness of information acquisition and meets high-speed information sharing requirements, especially in 5G era. What's more, our proposed scheme achieves bilateral security, that is, whether the abstracts match or not, both of the privacy of the case-database and the private information of the current patient are well protected. Besides, it resists different levels of violent ergodic attacks by adjusting the number of zeros in a bit string according to different security requirements. Yi Sun 0006, Keping Yu, Mamoun Alazab, Kaixiang Lin |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | IIS: Intelligent Identification Scheme of Massive IoT DevicesabstractDevice identification is of great importance in system management and network security. Especially, it is the priority in industrial internet of things (IIoT) scenario. Since there are massive devices producing various kinds of information in manufacturing process, the robustness, reliability, security and real-time control of the whole system is based on the identification of the massive IIoT devices. Previous IIoT device identification solutions are mostly based on a centralized architecture, which brings a lot of problems in scalability and security. In addition, most traditional identification systems can only identify inherent types of devices which is not suitable for the adaptive device management in IIoT. In order to solve these problems, this paper proposes a Intelligent Identification Scheme(IIS) of Massive IoT Devices, a completely distributed intelligent identification scheme of massive IIoT devices. The scheme changes the traditional centralized architecture and realizes more efficient clustering identification of massive IIoT devices. Moreover, IIS can identify more and more types of devices intelligently with the continuous learning ability since the identification model is constantly updated according to the ledger which is maintained by all gateways collaboratively. We also conduct experiments to evaluate the performance of IIS based on the data obtained from real IIoT devices, which proves that IIS is efficient in device identification and intelligent for the adaptive device management in IIoT. Yi Sun 0006, Fengkai Xu, Keping Yu, Ali Kashif Bashir, Zhaoli Liu |
COMPSAC | 2 |
| 2021 | Effective malware detection scheme based on classified behavior graph in IIoT
Yi Sun 0006, Ali Kashif Bashir, Usman Tariq, Fei Xiao 0005 |
Ad Hoc Networks | 1 |
| 2021 | High-Performance Isolation Computing Technology for Smart IoT Healthcare in Cloud EnvironmentsabstractThe development of the smart medical industry and equipment has made great progress due to the fusion of the IoT, cloud computing, and big data. In smart IoT healthcare, patients can collect vital parameters from various medical sensors attached to them to detect diseases and make initial diagnoses by themselves. With the powerful storage and computing functions of cloud computing, medical sensor devices deployed in a cloud environment can effectively solve the problems that the devices are highly dispersed, heterogeneous, and have limited processing capabilities. As a result, this method can effectively provide customized and scalable smart medical services for patients. However, because these medical resources share computing resources on the cloud platform, changes in equipment workloads will lead to service performance competition among tenants. Therefore, determining how to achieve performance isolation between tenants and guarantee the service-level agreements (SLAs) of the tenants has become the most concerning issue for cloud service providers. In this article, we propose a performance isolation algorithm for multitenant IoT clouds, which can effectively provide performance isolation between tenants. Experiments show that the message processing delay of tenants working within the allocated quota can be reduced by 82%. Yin Zhang 0002, Yi Sun 0006, Renchao Jin, Kaixiang Lin |
IEEE Internet Things J. | 2 |
| 2018 | Editorial: Intelligent Industrial IoT Integration with Cognitive Computing
Yin Zhang 0002, Limei Peng, Yi Sun 0006, Huimin Lu 0001 |
Mob. Networks Appl. | 3 |
| 2015 | A New Economic Model in Cloud Computing: Cloud Service Provider vs. Network Service ProviderabstractCloud computing has emerged as a new computing paradigm and its economics has opened up a new research area. Though progress has been made toward address competitions among Cloud service providers (CSPs) or among network service providers (NSPs), few studies have focused on the relationship between CSPs and NSPs. In this paper, we investigate this problem and present a new economic model to characterize the competition between CSPs and NSPs. We then conduct thorough theoretical analysis and numeric experiments to validate the proposed model. The results show that the replacement coefficient, connection rate, service coefficient, the equilibrium will affect the market share and the profit of CSPs and NSPs. Through this study, we believe that the developed economic model is general and practical, thus it is applicable to model the Cloud computing market. Jun Huang 0002, Fang Fang 0004, Yi Sun 0006, Huifang Yan, Cong-Cong Xing, Qiang Duan 0002, Wei Wang 0015 |
GLOBECOM | 3 |
| 2015 | Game theoretic resource allocation for multicell D2D communications with incomplete informationabstractResource allocation plays a critical role in implementing D2D communications underlaying a cellular network. Game-based approaches are recently proposed to address the resource allocation issue. Most existing approaches employ deterministic game models while implicitly assuming that each player in the game is completely willing to exchange transmission parameters with other players. Thus each player knows the complete information of all others. However, this assumption may not be satisfied in practice. For example, users may be reluctant to disclose all their parameters to peers. In this paper, we fully consider this scenario, i.e., players have incomplete information of others, and investigate the resource allocation problem for multicell D2D communications where a D2D link utilizes common resources of multiple cells. To attack this problem, a game-theoretic approach under the incomplete information condition is proposed. Specifically, we characterize the Base Stations (BSs) as players competing for resource allocation quota from the D2D demand, formulate the utility of each player as payoff from both cellular and D2D communications leasing the resources, and design the strategy for each player that is determined based on prior probabilistic payoff information of other players. We conduct extensive simulations to examine the proposed approach and the results demonstrate that the utility, sum rate, and sum rate gain of each player under the incomplete information condition are surprisingly higher than the counterparts under the complete information condition. Jun Huang 0002, Yi Sun 0006, Yanxiao Zhao, Cong-Cong Xing, Qiang Duan 0002 |
ICC | 3 |
| 2015 | Multiple Service Providers with IP Flow Mobility: From an Economic PerspectiveabstractThe proliferation of the mobile Internet and social networks reshapes the proportion of uploaded data in the entire Internet traffic. IFOM (IP Flow Mobility) technology, which offloads the cellular data to the WiFi or Femtocells or other complementary networks, plays a crucial role in improving the throughput of cellular systems. Although there have been many studies on the IFOM technology, most of them are done from a technical perspective, and the issues related the dissemination and utilization of the IFOM technology are largely overlooked. Unlike prior research works, this paper addresses issues involved with the IFOM technology from an economic perspective. Specifically, we model the competitions among multiple service providers supporting or not supporting the IFOM technology by leveraging the Game Theory, and then analyze the Nash Equilibrium for the ensuing game model. We also conduct extensive simulations to determine the factors that affect the market share and profit of the service providers. We believe that this research work will provide valuable guidance to service providers for the promotion and utilization of the IFOM technology. Jun Huang 0002, Yi Sun 0006, Fang Fang 0004, Cong-Cong Xing, Yanxiao Zhao, Kun Hua |
ICCCN | 2 |
| 2015 | A Distributed Game-Theoretic Power Control Mechanism for Device-to-Device Communications Underlaying Cellular Network
Jun Huang 0002, Yi Sun 0006, Cong-Cong Xing, Yanxiao Zhao, Qianbin Chen |
WASA | 2 |
| 2015 | GALLERY: A Game-Theoretic Resource Allocation Scheme for Multicell Device-to-Device Communications Underlaying Cellular NetworksabstractDevice-to-device (D2D) communication has recently emerged as a promising technology to improve the capacity and coverage of cellular systems. Coordinating interference between D2D and cellular users plays a crucial role in realizing D2D communications underlaying cellular networks successfully. While most of prior mechanisms for D2D have focused on mitigating interference within a single-cell system, they fail to address intercell interference with multiple cell settings. In this paper, we investigate the intercell interference issue in a cellular network where a D2D link reuses the available spectrum resources of multiple cells. We propose a game-theoretic resource allocation scheme, termed GALLERY, to address this problem. Unlike existing works that typically treat D2D users as players, we characterize base stations (BSs) as players competing for resources allocation quota of D2D demand, and define the utility of each player as the payoff gained from both cellular and D2D. We also propose a resource allocation protocol based on the equilibrium derivation. Extensive simulations are conducted to verify the proposed scheme and the results show that it can considerably enhance the system performance in terms of sum rate and sum rate gain. It is expected that GALLERY provides systematical insights into resource configurations of multiple cells for D2D communications. Jun Huang 0002, Yi Sun 0006, Qianbin Chen |
IEEE Internet Things J. | 2 |
| 2015 | A general two-party bi-input private function evaluation protocolabstractAbstract In the past, researchers have discussed the problem of two‐party single‐input private function evaluation (PFE), where P1 holds a private input x while P2 holds a private circuit Cf, and their goal is to securely compute Cf(x) without revealing x and Cf. Herein, we further consider a more general case, two‐party bi‐input PFE, where P2 also participates in the PFE by contributing a private input y. The research in this general case is of great value not only in theory but also in practice. In this paper, we focus on this problem and propose the first constant‐round two‐party bi‐input PFE protocol, which is with linear complexity and without relying on universal circuit or fully homomorphic encryption. Copyright © 2015 John Wiley & Sons, Ltd. Yi Sun 0006, Qiaoyan Wen |
Secur. Commun. Networks | 1 |
| 2014 | Modeling and analysis on congestion control in the Internet of ThingsabstractThe large amount of data collected in the Internet of Things (IoT) need to be transmitted to servers for processing in order to provide various services. Due to the limited amount of resources in IoT, including network bandwidth, node processing abilities, and server capacities, congestion control in IoT plays a crucial role for meeting service performance requirements. In this paper, we propose a model for congestion control in IoT with an improved Random Early Discard (IRED) algorithm. We employ queueing theory to analyze the performance of the proposed control mechanism. We also conduct extensive simulations to evaluate performance of the proposed control and compare it with regular RED algorithm. Our analysis and simulation results show that the proposed control achieves comparable delay performance and better throughput performance compared to standard RED. The simple control mechanism of IRED makes it more suitable to be implemented in IoT. Jun Huang 0002, Donggai Du, Qiang Duan 0002, Yi Sun 0006, Tiantian Zhou, Yanguang Zhang |
ICC | 4 |