Di Lu 0001

dblp:70/5794-1 · DBLP profile ↗
← Back
21ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0002-9923-6405ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 2 since 2021Systems, architecture and hardware · 4 · 3 since 2021Security and privacy · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021
YearPublicationVenuePosition
2026 PathFusion-Net: A Rough Path Theory-Based Deep Learning Model for ECG Arrhythmia Classification
abstract
This study introduces a novel electrocardiogram (ECG) arrhythmia classification model, PathFusion-Net, which integrates Rough Path Theory with deep learning technologies. The model combines Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM), Path Signatures, and Path Development to extract spatial morphological features from ECG images and multi-order temporal representations from ECG signals. By adopting an inter-patient split paradigm, our approach more closely reflects real-world clinical diagnostic settings compared to intra-patient methods. The model demonstrates state-of-the-art overall classification performance on both the MIT-BIH Arrhythmia Database and a private clinical dataset, achieving 94.7% and 95.1% accuracy, respectively, under the AAMI four-class standard with an inter-patient split paradigm. On the MIT-BIH dataset, the proposed method attains competitive precision and recall across multiple arrhythmia types, including 95.2% /87.9% for ventricular ectopic beats (V) and 75.7% /92.3% for supraventricular ectopic beats (S), indicating balanced performance across clinically diverse categories. This research highlights the potential of Rough Path Theory in time-series analysis and offers a novel deep learning framework for automated early detection and monitoring of ECG arrhythmias. The code used in this study is available at: https://github.com/Rand2AI/PathFusion-Net.
Tianlong Feng, Qingchen Li, Yongzhi Liao, Di Lu 0001, Jianqin Zhao, Hao Ni 0001, Hongying Liu 0001, Jingjing Deng 0001
IEEE J. Biomed. Health Informatics5
2025 LLM-Pot: A High-Interaction Honeypot System Driven by Large Language Model
abstract
Honeypots are commonly used tools in network security protection. However, low-interaction honeypots cannot obtain in-depth attack information, while the deployment of high-interaction honeypots is costly. This paper presents LLM-Pot, a novel high-interaction honeypot architecture powered by the Large Language Model (LLM), which explores the direction of intelligent honeypots and addresses the limitations of conventional honeypot solutions. LLM-Pot utilizes LLM to generate dynamic, context-aware responses that accurately simulate the behaviors of real operating systems. To demonstrate the effectiveness of LLM-Pot, this work used offline and online evaluations. The offline evaluation compared LLM-Pot and Cowrie by analyzing their responses to selected commands, and the results demonstrated LLM-Pot’s superior ability in handling complex operations. Online evaluation deployed honeypots in the cloud and captured extensive attack data over two weeks. The evaluation results demonstrate that our LLM-driven approach outperforms traditional honeypots across multiple key metrics, validating LLM-Pot’s superior deception capabilities.
Xuan Lyu, Pengbin Feng, Ning Xi 0002, XinDi Ma, Li Yang 0005, Di Lu 0001, Jianfeng Ma 0001
GLOBECOM6
2025 BiTDB: Constructing A Built-in TEE Secure Database for Embedded Systems (Extended Abstract)
abstract
In this paper, we propose BiTDB, a built-in Trusted Execution Environment (TEE) database for embedded systems, to realize higher system availability while ensuring data confidentiality. With BiTDB, dilemmas that the state-of-the-art research work on secure embedded databases has to face can be significantly reduced and eliminated, including (i) complicated research and realization on searchable encryption algorithms (SEA), (ii) limited support to all database operations, and (iii) almost none of specific design and optimizations toward built-in TEE embedded databases. Through BiTDB, all database operations can process plaintext in TEE instead of retrieving ciphertext by developing complicated SEAs. To enable BiTDB to handle database files in Rich Execution Environment (REE) as local ones, we extend the TEE OS with generic file I/O libraries. Then, we contribute three critical optimizations to significantly reduce redundant memory and file operations between TEE and REE, and BiTDB achieve better system performance and availability in embedded systems. Finally, we have implemented the prototype system based on OP-TEE and SQLite for several typical platforms, including virtualization and hardware environments. The TPC-H test shows BiTDB can achieve 85% (on average) of the original database performance while guaranteeing data confidentiality and integrity.
Chengyan Ma 0001, Di Lu 0001, Chaoyue Lv, Ning Xi 0002, Xiaohong Jiang 0001, Yulong Shen 0001, Jianfeng Ma 0001
ICDE2
2025 AsyncSC: An Asynchronous Sidechain for Multi-Domain Data Exchange in Internet of Things
Lingxiao Yang, Xuewen Dong, Zhiguo Wan, Sheng Gao 0002, Wei Tong 0003, Di Lu 0001, Yulong Shen 0001, Xiaojiang Du
INFOCOM6
2025 FC-TEE: Lightweight Trusted Execution Environment for Low-Cost UAV Flight Control Systems
abstract
Unmanned Aerial Vehicle (UAV) flight control systems are increasingly exposed to software-level security threats. However, existing Trusted Execution Environment (TEE) technologies that can effectively defend against software attacks are difficult to deploy on the low-cost UAVs due to: (1) the lack of onboard security hardware, (2) limited Memory Protection Unit (MPU) resources, and (3) strict real-time requirements. To address these issues, we design FC-TEE, a lightweight TEE framework tailored for low-cost UAV platforms, which integrates fine-grained memory isolation and a multi-level task scheduling strategy. By analyzing the flight control code and control principles, we provide three key attributes (task priority, maximum invocation frequency, and required argument types) of flight control tasks and classify these tasks into two categories (privileged tasks and common tasks) based on the attributes. Then, we run the privileged tasks in FC-TEE to achieve memory isolation from common tasks, protecting the privileged tasks from software attacks. Meanwhile, we design multi-level task scheduling based on the task priority and categories to ensure the real-time requirements of the flight control system. Compared with existing UAV protection solutions such as MINION and TrustZone-based RT-TEE, the average additional execution overhead introduced by FC-TEE only is 2.7%. We prototype FC-TEE on a real quadrotor platform and validate its effectiveness through task-level performance and security evaluations.
Peixue Lu, Ning Xi 0002, Chengyan Ma 0001, Qin Wang 0008, Di Lu 0001, Chuang Tian 0001, Jianfeng Ma 0001
IEEE Internet Things J.5
2025 HiCoCS: High Concurrency Cross-Sharding on Permissioned Blockchains
abstract
As the foundation of the Web3 trust system, blockchain technology faces increasing demands for scalability. Sharding emerges as a promising solution, but it struggles to handle highly concurrent cross-shard transactions (CSTxs), primarily due to simultaneous ledger operations on the same account. Hyperledger Fabric, a permissioned blockchain, employs multi-version concurrency control for parallel processing. Existing solutions use channels and intermediaries to achieve cross-sharding in Hyperledger Fabric. However, the conflict problem caused by highly concurrent CSTxs has not been adequately resolved. To fill this gap, we propose HiCoCS, a high concurrency cross-shard scheme for permissioned blockchains. HiCoCS creates a unique virtual sub-broker for each CSTx by introducing a composite key structure, enabling conflict-free concurrent transaction processing while reducing resource overhead. The challenge lies in managing large numbers of composite keys and mitigating intermediary privacy risks. HiCoCS utilizes virtual sub-brokers to receive and process CSTxs concurrently while maintaining a transaction pool. Batch processing is employed to merge multiple CSTxs in the pool, improving efficiency. We explore composite key reuse to reduce the number of virtual sub-brokers and lower system overhead. Privacy preservation is enhanced using homomorphic encryption. Evaluations show that HiCoCS improves cross-shard transaction throughput by 3.5-20.2 times compared to the baselines.
Lingxiao Yang, Xuewen Dong, Zhiguo Wan, Di Lu 0001, Yushu Zhang 0001, Yulong Shen 0001
IEEE Trans. Computers4
2024 DP-CLMI:Differentially Private Contrastive Learning Against Membership Inference Attack
Yiwen Xia, XinDi Ma, Qi Jiang 0001, Ning Xi 0002, Di Lu 0001, Pengbin Feng, Sheng Gao 0002, Jianfeng Ma 0001
ICA3PP (5)6
2024 CToMP: a cycle-task-oriented memory protection scheme for unmanned systems
Chengyan Ma 0001, Ning Xi 0002, Di Lu 0001, Yebo Feng, Jianfeng Ma 0001
Sci. China Inf. Sci.3
2024 BiTDB: Constructing A Built-in TEE Secure Database for Embedded Systems
abstract
In this paper, we propose BiTDB, a built-in Trusted Execution Environment (TEE) database for embedded systems, to realize higher system availability while ensuring data confidentiality. With BiTDB, dilemmas that the state-of-the-art research work on secure embedded databases has to face can be significantly reduced and eliminated, including (i) complicated research and realization on searchable encryption algorithms (SEA), (ii) limited support to all database operations, and (iii) almost none of specific design and optimizations toward build-in TEE embedded databases. Through BiTDB, all database operations can process plaintext in TEE instead of retrieving ciphertext by developing complicated SEAs. To enable BiTDB to handle database files in Rich Execution Environment (REE) as local ones, we extend the TEE OS with generic file I/O libraries. Then, we contribute three critical optimizations to significantly reduce redundant memory and file operations between TEE and REE, and BiTDB achieve better system performance and availability in embedded systems. Finally, we have implemented the prototype system based on OP-TEE and SQLite for several typical platforms, including virtualization and hardware environments. The TPC-H test shows BiTDB can achieve 85% (on average) of the original database performance while guaranteeing data confidentiality and integrity. Our project repository is athttps://github.com/CharlieMCY/BiTDB.
Chengyan Ma 0001, Di Lu 0001, Chaoyue Lv, Ning Xi 0002, Xiaohong Jiang 0001, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Knowl. Data Eng.2
2023 Smaug: A TEE-Assisted Secured SQLite for Embedded Systems
abstract
As one of the most popular relational databases for embedded devices, SQLite is lightweight to be embedded into applications without installing a specific database management system. However, simplicity and easy-to-use are double-edged swords; while bringing convenience, they also make data processing and storage risky. For example, an attacker can obtain data from a database file or memory and tamper with it once he has gained higher privileges, threatening the database's confidentiality and integrity. To address such security issues, based on a trusted execution environment (TEE) and a trusted platform module (TPM), we have proposed Smaug, a general secure scheme to ensure the confidentiality and integrity of SQLite and similar databases. With Smaug, all the critical data is stored in ciphertext, and data integrity protection is also provided. Besides, with TEE, all the sensitive operations are isolated from the untrusted environment, which can effectively resist attacks against memory. In addition, we use TPM to provide a solid root-of-trust (RoT) for the system. Finally, we have implemented a prototype system, and the performance evaluations have clarified the dominant factors that affect the system availability, providing a reference to the design and implementation of similar systems.
Di Lu 0001, Minqiang Shi, XinDi Ma, Ximeng Liu, Tianfang Zheng, Yulong Shen 0001, Xuewen Dong, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.1
2023 BejaGNN: behavior-based Java malware detection via graph neural network
Pengbin Feng, Li Yang 0005, Di Lu 0001, Ning Xi 0002, Jianfeng Ma 0001
J. Supercomput.3
2023 A Two-Dimensional Sybil-Proof Mechanism for Dynamic Spectrum Access
abstract
Achieving higher spectrum utilization, auction-based mechanisms has been regarded as a popular tool in dynamic spectrum access (DSA). Recently, Sybil attacks in auction-based DSA mechanisms have been investigated, where a cheating bidder can manipulate an auction by submitting bids under multiple fake identities. Existing Sybil-proof mechanisms in DSA are limited to prevent Sybil attacks from primary users (PUs) or secondary users (SUs). However, both of PUs and SUs may perform Sybil attacks in DSA, i.e., double Sybil attacks. The challenge of solving the double Sybil attacks is that fictitious identities and fake bids can directly affect allocation results, but the malicious bidders cannot be straightforwardly distinguished from all bidders. To resist the double Sybil attacks, we propose STEAM, the first double Sybil-proof and two-dimensional Truthful spEctrum Auction Mechanism for DSA. Specifically, STEAM merges suspicious buyers based on geographic characteristics and sorts sellers by a bid-independent sorting method to minimize the impact of untruthful bids and Sybil attacks on the allocation results. Theoretical analysis and extensive evaluations prove that STEAM is double Sybil-proof, two-dimensional truthful, individual rational and budget-balanced, while the performance loss in various metrics within 8% compared to the existing auction-based mechanisms.
Xuewen Dong, Zhichao You, Yulong Shen 0001, Di Lu 0001, Yang Xu 0012, Jia Liu 0009
IEEE Trans. Mob. Comput.4
2021 xTSeH: A Trusted Platform Module Sharing Scheme Towards Smart IoT-eHealth Devices
abstract
IoT based eHealth system brings a revolution to healthcare industry, with which the old healthcare systems can be updated into smarter and more personalized ones. The practitioners can continue monitoring the physical status of the patients at anytime and anywhere, and develop more precise treatment plans by analyzing the collected data, such as heart rate, blood pressure, blood glucose. Actually, these smart sensors used in eHealth system are smart embedded devices (SED). Due to the limitations on hardware capabilities, these inter-connected SEDs lack of security considerations in design and implementation, and face the threats from the network. To prevent the malicious users (or programs) from tampering with the SEDs, trusted platform module (TPM) is adopted, which can guarantee the system integrity via detecting unauthorized modifications to data and system environment. However, due to the limited scalability and insufficient system resources, not all SEDs can be deployed with TPM chips. To address this issue, in this paper, a TPM extension scheme (xTSeH) is proposed. In xTSeH, we have extended the functions of a TPM deployed in a SED (TSED) to those non-TPM-protected SEDs (N-TSED) via network. A shadow TPM in the form of a kernel module is designed as the trust base for the N-TSED, which is the representative of the TPM in TSED. Then, three protocols are proposed to implement the integrity verification and inter-SED authentication. Finally, a Raspberry Pi based prototype system is designed and implemented. The feasibility and usability of our scheme are proved by the analysis of the experimental results of system performance.
Di Lu 0001, Ruidong Han, Yulong Shen 0001, Xuewen Dong, Jianfeng Ma 0001, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.1
2020 Towards Primary User Sybil-proofness for Online Spectrum Auction in Dynamic Spectrum Access
abstract
Dynamic spectrum access (DSA) is a promising platform to solve the spectrum shortage problem, in which auction based mechanisms have been extensively studied due to good spectrum allocation efficiency and fairness. Recently, Sybil attacks were introduced in DSA, and Sybil-proof spectrum auction mechanisms have been proposed, which guarantee that each single secondary user (SU) cannot obtain a higher utility under more than one fictitious identities. However, existing Sybil-poof spectrum auction mechanisms achieve only Sybil-proofness for SUs, but not for primary users (PUs), and simulations show that a cheating PU in those mechanisms can obtain a higher utility by Sybil attacks. In this paper, we propose TSUNAMI, the first Truthful and primary user Sybil-proof aUctioN mechAnisM for onlIne spectrum allocation. Specifically, we compute the opportunity cost of each SU and screen out cost-efficient SUs to participate in spectrum allocation. In addition, we present a bid-independent sorting method and a sequential matching approach to achieve primary user Sybil-proofness and 2-D truthfulness, which means that each SU or PU can gain her maximal utility by bidding with her true valuation of spectrum. We evaluate the performance and validate the desired properties of our proposed mechanism through extensive simulations.
Xuewen Dong, Qiao Kang, Qingsong Yao, Di Lu 0001, Yang Xu 0012, Jia Liu 0009
INFOCOM4
2020 A secured TPM integration scheme towards smart embedded system based collaboration network
Di Lu 0001, Ruidong Han, Yue Wang 0063, Yongzhi Wang 0001, Xuewen Dong, XinDi Ma, Teng Li 0003, Jianfeng Ma 0001
Comput. Secur.1
2020 BTNC: A blockchain based trusted network connection protocol in IoT
Junwei Zhang 0001, Di Lu 0001, Jianfeng Ma 0001
J. Parallel Distributed Comput.4
2020 An incentive mechanism with bid privacy protection on multi-bid crowdsourced spectrum sensing
Xuewen Dong, Guangxia Li, Tao Zhang 0029, Di Lu 0001, Yulong Shen 0001, Jianfeng Ma 0001
World Wide Web4
2018 Information flow control on encrypted data for service composition among multiple clouds
Ning Xi 0002, Jianfeng Ma 0001, Cong Sun 0001, Di Lu 0001, Yulong Shen 0001
Distributed Parallel Databases4
2017 Credit-based scheme for security-aware and fairness-aware resource allocation in cloud computing
Di Lu 0001, Jianfeng Ma 0001, Cong Sun 0001, XinDi Ma, Ning Xi 0002
Sci. China Inf. Sci.1
2017 APPLET: a privacy-preserving framework for location-aware recommender system
XinDi Ma, Hui Li 0006, Jianfeng Ma 0001, Qi Jiang 0001, Sheng Gao 0002, Ning Xi 0002, Di Lu 0001
Sci. China Inf. Sci.7
2016 Dynamic game model of botnet DDoS attack and defense
abstract
Botnet has become a popular technique for deploying Internet crimes. The command of botnet has evolved into a major way for attackers to launch Distributed Denial of Service attacks on network servers. Modelized analysis methods need to be studied for botnet attacks implements, defense, and prediction. In this paper, we propose a novel game theory-based model to describe the scenario, in which the botmaster launching Distributed Denial of Service attacks using a botnet while the defender equipped a firewall defending. In our model, we consider the following: firstly, the botmaster and the defender can be rational or irrational; secondly, the interaction between the botmaster and the defender is modeled as a dynamic game; thirdly, their supporting or not self-learning databases. We detail the analysis of eight sub-scenarios for the assumptions and give an easy-to-use algorithm for adjustment of offensive and defensive strategy. We use the OPNET to validate our model and its effectiveness. The experiment result shows that our strategy can improve the firewall abilities to lower false alarm rate FR and improve the botmaster lower exposure rate of botnet to avoid detection. Furthermore, the model is helpful to evaluate defense ability of the defender towards current botmaster attacks by analyzing attack log in sandbox. Copyright © 2016 John Wiley & Sons, Ltd.
Yichuan Wang 0003, Jianfeng Ma 0001, Liumei Zhang, Wenjiang Ji, Di Lu 0001, Xinhong Hei 0001
Secur. Commun. Networks5