VLDB 2026 Research / reviewers in the wild / expert
Jun Cai 0002
dblp:72/3887-2
· DBLP profile ↗
37ranked-venue papers
15as first author
30since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 7 first-author · 15 since 2021Systems, architecture and hardware · 6 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Security and privacy · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Optimizing When, How, and What to Communicate in Shared ML Clusters
Tianxiang Huang, Waixi Liu 0001, Jun Cai 0002, Shipeng Fan |
IPDPS | 3 |
| 2026 | Adaptive gradient sparsification with layer and stage-wise for accelerating distributed DNN training
Waixi Liu 0001, Jun Cai 0002, Zhen-Xin Zhang, Kongyang Chen |
Comput. Networks | 2 |
| 2026 | DRL-BM: Intelligent buffer management in data center network
Waixi Liu 0001, Xin-Jian Zhong, Zhen-xin Zhang, Jun Cai 0002, Zhiquan Liu 0001, Chao-Xuan Zheng, Zhen-zheng Guo |
Comput. Networks | 4 |
| 2026 | Fed-GPD: Federated Graph Process Distillation for Anomaly Detection in Lights-Out ManufacturingabstractAs an essential component of the Industrial Internet of Things (IIoT), lights-out manufacturing (LoM) relies heavily on the rapid detection of anomalies. However, LoM anomalies often arise from complex, cross-modal correlations, and traditional detection models struggle with the dual challenges of limited local data and stringent data privacy requirements, leading to poor generalization. To address these challenges, this paper introduces a novel Federated Graph Process Distillation framework (Fed-GPD) for multi-modal anomaly detection. Our approach first represents heterogeneous industrial data as unified graph structures to effectively model the underlying device relationships. We then propose a new graph knowledge distillation paradigm designed for Graph Neural Networks (GNNs) in a federated setting. Instead of merely distilling final predictions, we introduce two novel distillation mechanisms: 1) Neighborhood Aggregation Process Distillation (NAPD), which transfers the knowledge of how a model processes local neighborhood information at each GNN layer, and 2) Relational Knowledge Matrix Distillation (RKMD), which aligns the global understanding of node-to-node relationships learned by the models. These mechanisms are integrated into an asynchronous mentor-mentee architecture, enabling efficient and deep knowledge transfer from powerful, private mentor models to a lightweight, global mentee model. Simulation results on multiple real-world datasets demonstrate that Fed-GPD significantly outperforms existing federated and graph-based anomaly detection methods. Notably, our in-depth ablation studies validate the effectiveness of the proposed process distillation mechanisms, showing substantial improvements in model accuracy and communication efficiency. Jun Cai 0002, Manshan Mo, Zhongwei Huang, F. Richard Yu |
IEEE Internet Things J. | 1 |
| 2026 | Cooperative Traffic Scheduling in Transportation Network: A Knowledge Transfer MethodabstractDeep reinforcement learning (DRL) has shown significant potential in adaptive traffic signal control (ATSC) by adapting to real-time traffic conditions. However, controlling multiple intersections faces challenges, mainly due to the isolated actions of agents and non-stationary caused by other intersections. To address these issues, this paper proposes a novel knowledge collaboration-based actor-critic policy gradient (KCACPG) method to achieve cooperative traffic scheduling across multiple intersections. KCACPG includes a knowledge collaboration learning mechanism that allows heterogeneous agents to exchange knowledge across experience tuples, achieving globally optimal decision-making and coordination. KCACPG also integrates an off-policy prioritized experience replay mechanism to improve knowledge reuse efficiency and reduce the negative impact of knowledge transfer. Simulation results show that KCACPG converges quickly, generalizes to fluctuant traffic and load well, improves the network throughput by up to 17.8%, and reduces the pressure imbalance by up to 11.6% compared with the existing collaborative methods. The proposed method has significant implications for intelligent transportation systems and smart cities. Zhongwei Huang, Wenlong Dai, Yuntao Zou, Dagang Li 0001, Jun Cai 0002, G. Thippa Reddy, Wei Wang 0077 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | A Lightweight Dynamic Hierarchical Neural Network Model and Learning ParadigmabstractIn image analysis scenarios such as the Internet of Things and the metaverse, the introduction of federated learning (FL) is an effective solution to safeguard user data security and meet low‐latency requirements during the machine learning process. However, due to the constrained computational power and memory of devices, facilitating the local training of complex models becomes challenging, thereby posing a significant obstacle to the application of FL. Consequently, a lightweight dynamic hierarchical neural network model and its learning paradigm are proposed in this study. Specifically, a lightweight compression method is designed based on enlarged receptive fields and separable convolutions to reduce redundancy in convolutional layer feature maps. A dynamic model partitioning method is devised, grounded in the Q‐Learning reinforcement learning algorithm, to enable collaborative model training across multiple devices and enhance the utilization efficiency of device computing and storage resources. Furthermore, a hierarchical federated partition learning (HFSL) paradigm based on complete weight sharing is introduced to facilitate the compatibility of partitioned models with FL. Experimental results show that our lightweight model outperforms existing models in terms of accuracy, lightweight degree, and efficiency on image analysis tasks. Moreover, the proposed HFSL paradigm achieves performance comparable to centralized training. Liping Liao, Junlong Lin, Wenjing Zhang 0004, Jun Cai 0002 |
Int. J. Intell. Syst. | 4 |
| 2025 | Multi-Party Reversible Data Hiding in Ciphertext Binary Images Based on Visual CryptographyabstractExisting methods for reversible data hiding in ciphertext binary images only involve one data hider to perform data embedding. When the data hider is attacked, the original binary image cannot be perfectly reconstructed. To this end, this letter proposes multi-party reversible data hiding in ciphertext binary images, where multiple data hiders are involved in data embedding. In this solution, we use visual cryptography technology to encrypt a binary image into multiple ciphertext binary images, and transmit the ciphertext binary images to different data hiders. Each data hider can embed data into a ciphertext binary image and generate a marked ciphertext binary image. The original binary image is perfectly reconstructed by collecting a portion of marked ciphertext binary images from the unattacked data hiders. Compared with existing solutions, the proposed solution enhances the recoverability of the original binary image. Besides, the proposed solution maintains a stable embedding capacity for different categories of images. Bing Chen 0004, Jingkun Yu, Bingwen Feng, Wei Lu 0001, Jun Cai 0002 |
IEEE Signal Process. Lett. | 5 |
| 2025 | STMBAD: Spatio-Temporal Multimodal Behavior Anomaly Detector for Industrial Control SystemsabstractModern cyber attacks against industrial control systems (ICSs) are highly stealthy, persistent, and targeted. Existing anomaly detection methods are mainly based on a set of rules defining correct behaviors and use loosely bounded detection thresholds, which can be exploited by attackers to evade detection. In this article, we propose STMBAD, a spatio-temporal multimodal behavior anomaly detector based on spatio-temporal ICS behavior analysis to improve the performance of ICS anomaly detection. STMBAD leverages the rich information available in industrial multimodal data to achieve a deep understanding of complex ICS behaviors and enhance the ability to detect stealthy attacks. To avoid data processing cross heterogeneous type/structure and temporal confusion caused by unsynchronized time series, STMBAD embeds time series of individual modality separately into variate tokens and applies the attention mechanism and feedforward network to capture multivariate correlations and interdependencies. Meanwhile, based on the attention mechanisms, temporal evolution law and spatial correlation of different modalities can be captured to model the characteristics of the spatio-temporal multimodal behavior of ICS. When detecting attacks, an adaptive detection mechanism combining global and local detection is proposed to utilize dynamic thresholds at different levels and reduce errors caused by a loose global threshold. The simulation results show that the proposed method outperforms the baseline methods and yields the highest F1 score, reaching 95%. Jian-Zhen Luo, Yan Cai 0022, Jun Cai 0002, Wanhan Fang, Wenwei Zheng |
IEEE Trans. Ind. Informatics | 3 |
| 2025 | Corrections to "STMBAD: Spatio-Temporal Multimodal Behavior Anomaly Detector for Industrial Control Systems"abstractPresents corrections to the article “STMBAD: Spatio-Temporal Multimodal Behavior Anomaly Detector for Industrial Control Systems”. Jian-Zhen Luo, Yan Cai 0022, Jun Cai 0002, Wanhan Fang, Wenwei Zheng |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | A super-twisting algorithm combined zeroing neural network with noise tolerance and finite-time convergence for solving time-variant Sylvester equation
Jun Cai 0002, Wenjing Zhang 0004, Shitao Zhong, Chenfu Yi |
Expert Syst. Appl. | 1 |
| 2024 | Knowledge-Collaboration-Based Resource Allocation in 6G IoT: A Graph Attention RL ApproachabstractIn future 6G-enabled Internet of Things (IoT), users and devices will be divided into numerous distributed domains with smaller base station coverage due to the utilization of terahertz high-frequency band communication. Deep reinforcement learning (DRL) agents will be increasingly deployed in the domain to achieve intelligent service provisioning and resource allocation. However, the existing DRL-based method faces the problem of repeated model training and poor generalization ability when service demand fluctuates and environmental changes occur. In addition, limited training samples in each domain also lead to insufficient model training. Inspired by the collaborative learning of human knowledge, we propose a knowledge collaboration-based resource allocation mechanism for future 6G-enabled IoT and address two basic issues: 1) which agent should collaborate with and 2) how to collaborate. Specifically, we first model the distributed network as a graph and use graph attention (GAT) to capture the fluctuant service demands and time-varying resource capacities in temporal and spatial domains, and then calculate the similarity between the agents. We further propose a collective reinforcement learning (CRL) algorithm that facilitates knowledge collaboration between the agents through the policy distribution. Simulation results verify that the proposed GAT-CRL achieves fast convergence as deep deterministic policy gradient (DDPG) in 4K steps, computing the similarity score more accurately with the increasing attention heads, and achieves higher successful flow than the soft actor-critic (about 3.6%–5.4%) and DDPG (about 14.6%–21%) when adapting to unseen traffic patterns/loads and increasing topology scales. Zhongwei Huang, F. Richard Yu, Jun Cai 0002 |
IEEE Internet Things J. | 3 |
| 2024 | ICS Anomaly Detection Based on Sensor Patterns and Actuator Rules in Spatiotemporal DependencyabstractData-driven methods, such as deep learning, are widely adopted to detect cyberattacks for Industrial control systems (ICSs). Due to the neglect of entity spatial relationships (ESR), however, there is a potential discrepancy between the learned device topology and the real physical process. Meanwhile, existing methods confuse sensor patterns, actuator rules, and some interference within spatiotemporal dependence, suffering from undetected attack issue. To achieve precise detection without using design knowledge, we propose a sensor-actuator separated anomaly detection method (SA2) that distinguishes sensor patterns and actuator rules, constructing prediction models for sensors (PM-SEN) and actuators (PM-ACT) separately. Moreover, we propose an ESR-based topology construction method for providing process-conformed topology and an attack span-based evaluation method for validating the undetected attack issue. The experimental results show that SA2 outperforms all baselines in the F1 score, effectively detecting all attacks (zero undetected rate), compared to an optimal baseline with an undetected rate of close to 50%. Jun Cai 0002, Zeheng Wei, Jian-Zhen Luo |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | Privacy-Preserving Deployment Mechanism for Service Function Chains Across Multiple DomainsabstractNetwork function virtualization (NFV) has attracted attention because of its flexible configuration and management of network functions. Based on NFV, the service function chain (SFC) defines a group of virtual network functions (VNFs) connected sequentially, enabling flexible customization and provisioning of network services. In the large-scale and heterogeneous Internet of Things (IoT) environment, e.g., industrial IoT, servers provided by a single infrastructure provider (InP) cannot support the deployment of all VNFs, and SFCs must be deployed across multiple domains. However, SFCs deployed across multiple domains will inevitably bring privacy leakage and resource coordination difficulties, thereby reducing the efficiency of network services. To address these issues, this paper proposes a privacy-preserving deployment mechanism (PPDM) for SFCs that achieves near-optimal SFC deployment across multiple domains while protecting resource and topology privacy. PPDM first performs virtual resource prediction and forms the service intention response matrix (SIRM) based on SFC requests (SFCRs). Second, the multi-domain controller (MDC) discovers a near-optimal SFCs deployment strategy by deep Q-network (DQN) using SIRM as input to protect domains’ privacy. Finally, the learned strategies are distributed to intra-domain controllers (IDCs) to implement specific services. Simulation results demonstrate that the proposed method outperforms privacy-preserving and non-privacy-preserving methods. Jun Cai 0002, Zirui Zhou, Zhongwei Huang, Wenlong Dai, F. Richard Yu |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | QALL: Distributed Queue-Behavior-Aware Load Balancing Using Programmable Data PlanesabstractExisting load-balancing methods used in data center networks involve some shortcomings such as excessively large decision delays during reactions to microbursts and large overheads involved in active probing. Programmable data planes have provided new opportunities for local decision-making on switches to address these issues. We observe that queue behavior (i.e., queue occupancy, queuing trend, and dequeue time interval) in switches can reflect the current or future congestion degree on a network. Furthermore, following data-driven experiments, we found an accurate fitting function of congestion degree to queue behavior. Thus, we propose an in-network load-balancing scheme based on a programmable switch, called queue-behavior-aware localized load balancing (QALL). In QALL, each switch independently selects egress ports probabilistically according to fine-grained-measured local queue behavior. The key concept of QALL is to take account the evolutionary process of reaching the current queue state into its decision basis for load balancing. Experimental results under actual DCN workloads (including web search and data mining workloads) demonstrate the effectiveness of QALL. In terms of flow completion time, decision delay, network shock, load sharing accuracy, and packet reordering, QALL outperformed recent perpacket (DRILL), per-flowlet (LetFlow and CONGA), and per-flow (ECMP) load balancers, particularly under heavy load. For example, under asymmetrical topology with 90% load level, the flow completion time of QALL was lower than that of ECMP, LetFlow, CONGA, and DRILL by up to 54.7%, 46.5%, 38.9%, and 18.9%, respectively. Waixi Liu 0001, Jun Cai 0002, Sen Ling, Jian-Yu Zhang, Qingchun Chen |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Task Decomposition and Hierarchical Scheduling for Collaborative Cloud-Edge-End ComputingabstractThe emerging computing paradigms offer effective resolutions for the escalating conflict arising from the heightened computational demands of portable terminals and their constrained capacity. Concurrently, the architecture has transitioned from a single-tier structure to a multi-tier collaborative framework, enhancing flexibility and enabling fine-grained computation offloading. Nevertheless, existing research on multi-tier computation offloading faces challenges, including inefficient resource perception and task decomposition; there is a notable absence of an effective hierarchical task scheduling strategy within the multi-tier collaborative architecture. To bridge these gaps, our paper investigates the multi-granularity task decomposition and hierarchical task scheduling in a cloud-edge-end collaborative computing network. We first introduce a large-small resource tree (LST) model to facilitate efficient resource perception across three-tier network nodes. Then we propose a multi-granularity task decomposition algorithm (MTDA) based on long short-term memory (LSTM) network resource prediction to fully utilize the distributed node resources. Finally, we propose a parallelized LST-DDQN task offloading algorithm to maximize the delay and energy consumption weighted utility function. Simulation results demonstrate the efficacy of our proposed task decomposition and parallel scheduling methods, showcasing a reduction in utility by approximately 6.31% to 13.01% compared to baseline algorithms. Jun Cai 0002, Wei Liu 0268, Zhongwei Huang, F. Richard Yu |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | Load balancing inside programmable data planes based on network modeling prediction using a GNN with network behaviors
Waixi Liu 0001, Jun Cai 0002, Yinghao Zhu, Junming Luo, Jin Li 0002 |
Comput. Networks | 2 |
| 2023 | LogBASA: Log Anomaly Detection Based on System Behavior Analysis and Global Semantic AwarenessabstractSystem log anomaly detection is important for ensuring stable system operation and achieving rapid fault diagnosis. System log sequences include data on the execution paths and time stamps of system tasks in addition to a large amount of semantic information, which enhances the reliability and effectiveness of anomaly detection. At the same time, considering the correlation between system log sequences can effectively improve fault diagnosis efficiency. However, the existing system log anomaly detection methods mostly consider only the sequence patterns or semantic information on the logs, so their anomaly detection results show a high rate of missed and false alarms. To solve these problems, this paper proposed an unsupervised log anomaly detection model (LogBASA) based on the system behavior analysis and global semantic awareness, aiming to decrease the leakage rate and increase the log sequence anomaly detection accuracy. First, a system log knowledge graph was constructed based on massive, unstructured, and multilevel system log data to represent log sequence patterns, which facilitates subsequent anomaly detection and localization. Then, a self‐attention encoder‐decoder transformer model was developed for log spatiotemporal association analysis. This model combines semantic mapping and spatiotemporal features of log sequences to analyze system behavior and log semantics in multiple dimensions. Furthermore, a system log anomaly detection method that combines adaptive spatial boundary delineation and sequence reconstruction objective functions was proposed. This method uses special words to characterize the log sequence states, delineates anomaly boundaries automatically, and reconstructs log sequences through unsupervised training for anomaly detection. Finally, the proposed method was verified by numerous experiments on three real datasets. The results indicate that the proposed method can achieve an accuracy rate of 99.3%, 95.1%, and 97.2% on HDFS, BGL, and Thunderbird datasets, which proves the effectiveness and superiority of the LogBASA model. Liping Liao, Jian-Zhen Luo, Jun Cai 0002 |
Int. J. Intell. Syst. | 4 |
| 2023 | Multitask Multiobjective Deep Reinforcement Learning-Based Computation Offloading Method for Industrial Internet of ThingsabstractEdge computing has emerged as a promising paradigm to deploy computing resources to the network edge. However, most existing computation offloading strategies consider only one objective, including latency, energy consumption, and weighted sum of latency and energy consumption. It is challenging to meet different requirements of the heterogeneous Industrial Internet of Things (IIoT) systems, simultaneously. To address this challenge, a multiagent deep reinforcement learning (MADRL)-based computation offloading method is proposed for cloud–edge–device computing, which aims to meet various requirements of different tasks. In the proposed model, two typical types of tasks are considered: 1) latency-sensitive tasks and 2) energy-sensitive tasks. Each type of task can be executed in one of the three layers, i.e., cloud, edge, or device layer. In addition, in the MADRL model, two agents are defined to make global offloading decisions for the two types of tasks according to the task characteristics and network resource status. The experimental results show that the proposed model can guarantee the quality of service in a heterogeneous IIoT system and achieve better system performance in terms of latency and energy consumption than weighted-sum optimization methods. Jun Cai 0002, Hongtian Fu, Yan Liu 0042 |
IEEE Internet Things J. | 1 |
| 2023 | EdgeSFG: A matching game mechanism for service function graph deployment in industrial edge computing environment
Liping Liao, Jun Cai 0002, Jian-Zhen Luo, Wenjing Zhang 0004 |
Inf. Sci. | 3 |
| 2023 | Collective reinforcement learning based resource allocation for digital twin service in 6G networks
Zhongwei Huang, Dagang Li 0001, Jun Cai 0002, Hua Lu 0012 |
J. Netw. Comput. Appl. | 3 |
| 2023 | Deep Reinforcement Learning for Reactive Content Caching With Predicted Content Popularity in Three-Tier Wireless NetworksabstractWith the explosive growth of micro-video applications, the mobile traffic generated by retrieving a few user-generated micro-videos has brought a massive burden to backhaul links and backbone networks. Unlike other types of videos, user-generated micro-videos are typically requested by a large number of users within an extremely short period after their release. Therefore, it is crucial to predict the content popularity and make caching decision for the newly requested content timely. To predict content popularity in different locations, the request probabilities of the content in different locations are translated into rating scores. Then, a recommendation system-based prediction model is designed to predict rating scores of the newly requested content in different locations. To increase caching diversity and realize vertically collaboration in a three-tier wireless network, a deep reinforcement learning-based reactive content caching strategy is proposed to make caching decision for the newly requested content. The main goal is to obtain a higher caching gain at a lower caching space cost. To evaluate the caching performance, a new metric, cache benefit rate, is defined as the download latency reduction brought by each bit of cache. Compared with matrix factorization, the performance of prediction model can be increased by 23.98% and 12.44% in terms of mean absolute error and root mean square error, respectively. Extensive simulations demonstrate that the proposed reactive caching strategy outperforms other caching strategies under different system parameters in terms of the cache hit rate, average download time, and cache benefit rate. Yan Liu 0042, Jinling Jia, Jun Cai 0002, Taiqin Huang |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | Graph convolutional networks with higher-order pooling for semisupervised node classificationabstractSummary The information propagation mechanism in graph‐structured networks such as social networks is the foundation of network security. The graph convolutional network (GCN) is a powerful approach for semisupervised node classification on graph‐structure data. The vertex features which pass through the graph network are affected by the k‐hop neighborhood vertices. However, current high‐order GCN approaches merged the k‐hop neighborhood using coarse pooling and complicated weight parameters. To reduce the computational complexity and preserve topological of the graph data, with weight sharing mechanism we propose a novel GCN based on a novel higher‐order pooling layer for semisupervised classification. The proposed model and its variants are experimental studied on several large‐scale citation network datasets using semisupervised learning. The experimental results show that the proposed model and its variants have lower computational complexity and achieve the state‐of‐the‐art in the node classification accuracy. Fangyuan Lei, Jianjian Jiang, Liping Liao, Jun Cai 0002, Huimin Zhao 0001 |
Concurr. Comput. Pract. Exp. | 5 |
| 2022 | Deep reinforcement learning-based multitask hybrid computing offloading for multiaccess edge computingabstractBy deploying computing units in edge servers, the device-generated computation-intensive tasks can be offloaded from the cloud, lessening the core network's traffic and reducing the tasks' completion latency. To mitigate the burden on edge server and improve user experience, this paper proposes a deep reinforcement learning (DRL)-based multiuser multitask hybrid computing offloading model for offloading a set of computation-intensive tasks generated by multiple users to edge server and adjacent devices. The proposed model makes global computing offloading decisions for multiple computation-intensive tasks simultaneously rather than via one-by-one decision-making, which takes the impact of users' offloading decisions on the system's overall performance in multitask offloading scenarios into account. The main goal of this study is to reduce the long-term overall system delay. The model uses the recurrent neural network to extract the feature information of task and network state, improving the convergence speed and stability of the DRL model. The experimental results demonstrate that the global offloading decision-making model outperforms other methods regarding long-term overall system delay and device energy consumption. Jun Cai 0002, Hongtian Fu, Yan Liu 0042 |
Int. J. Intell. Syst. | 1 |
| 2022 | SARM: Service function chain active reconfiguration mechanism based on load and demand predictionabstractNetwork function virtualization is a promising technology for providing personalized services via agile service function chains (SFCs). Flexible SFC orchestration and rational resource allocation are pivotal for improving the SFC's quality of service (QoS). However, the requirements for computational load and resources have frequently been changing. Consequently, static resource allocation can result in resource insufficiency when SFCs turn busy and resource waste due to resource overplus when SFCs are idle. Since a dynamic resource allocation is necessary, the existing dynamic resource allocation methods' responses have often been delayed. This paper proposes an SFC active reconfiguration mechanism (SARM) based on computational load and resource demand. The SARM predicts nodes' computation loads and SFCs' resource demands and uses these predictions to estimate future QoS and develop the SFC reconfiguration strategy. The SARM considers multiple factors and applies a heuristic algorithm to achieve the tradeoff between migration cost and QoS preservation. The experiments demonstrate that the SARM can effectively predict the nodes' load and the resource demand of SFCs. In addition, the SARM can successfully identify the SFCs to reconfigure and reduce the QoS maintenance costs. The simulation results indicate that the average delays of the SFCs can be reduced by at least 26%. Jun Cai 0002, Kaili Qian, Jian-Zhen Luo |
Int. J. Intell. Syst. | 1 |
| 2022 | CapBad: Content-Agnostic, Payload-Based Anomaly Detector for Industrial Control ProtocolsabstractEfficient anomaly detection methods are urgently needed to prevent attacks in the application layer of the Industrial Internet of Things (IIoT). The existing intrusion detection systems have certain limitations in detecting abnormal packets exploited by the application-layer attacks. In this article, a content-agnostic-payload-based anomaly detector named the CapBad is proposed to detect malicious packets in the application layer of the IIoT system. Specifically, a phase-aware hidden semi-Markov model (pHSMM) is used to model the industrial control protocol packets and automatically learn the packets’ payload characteristics. The packet types are then inferred based on the packet likelihoods obtained by the pHSMM. In addition, the probabilistic suffix tree is employed to analyze the packets’ contextual similarity to the historical packets. The abnormal packets are finally detected by comparing their contextual similarity with that of the historical normal packets. The proposed algorithm is verified by simulations, and the results show that the CapBad has an excellent performance in detecting abnormal packets in the application layer. Jun Cai 0002, Jian-Zhen Luo, Yan Liu 0042, Liping Liao |
IEEE Internet Things J. | 1 |
| 2022 | SeMiner: Side-Information-Based Semantics Miner for Proprietary Industrial Control ProtocolsabstractIndustrial control protocols (ICPs) are critical for Industrial Internet of Things to achieve interconnection and interaction between the industrial devices. To fully understand a large number of nonstandard and proprietary ICPs, protocol reverse engineering (PRE) techniques are commonly used to reconstruct the ICP specifications. However, existing PRE tools face difficulties in inferring the ICP semantics. Accordingly, this article proposes SeMiner as an ICP semantics analysis framework to achieve the packet field identification, protocol semantics inference, and behavior semantics modeling. Based on the collected graphical side information about the industrial processes, a series of semantic channels is identified using image processing techniques, and a modified Apriori algorithm is used to extract the frequent patterns of each semantic channel. Afterward, a heuristic method based on sequence alignment is designed to simultaneously identify the set of relevant packets and the position of packet fields relevant to the semantic channels. Finally, relying on the packet field semantics, the behavior semantics of industrial processes are modeled and the association rules between the semantic channels are extracted. Thorough experimental results reported herein verify the effectiveness of SeMiner and show the superior performance of SeMiner compared with the several other state-of-the-art algorithms. Jun Cai 0002, Weijian Zhong, Jian-Zhen Luo |
IEEE Internet Things J. | 1 |
| 2022 | DRL-PLink: Deep Reinforcement Learning With Private Link Approach for Mix-Flow Scheduling in Software-Defined Data-Center NetworksabstractIn datacenter networks, bandwidth-demanding elephant flows without deadline and delay-sensitive mice flows with strict deadline coexist. They compete with each other for limited network resources, and the effective scheduling of such mix-flows is extremely challenging. We propose a deep reinforcement learning with private link approach (DRL-PLink), which combines the software-defined network and deep reinforcement learning (DRL) to schedule mix-flows. DRL-PLink divides the link bandwidth and establishes some corresponding private-links for different types of flows to isolate them such that the competition among different types of flows can decrease accordingly. DRL is used to adaptively and intelligently allocate bandwidth resources for these private-links. Furthermore, to improve the scheduling policy, DRL-PLink introduces the novel clipped double Q-learning, exploration with noise, and prioritized experience replay technology for DDPG to address function approximation error, to induce lager and more randomness for exploration, as well as more effective and efficient experience replay in DRL respectively. The experiment results under actual datacenter network workloads (including Web search and data mining workload) indicate that DRL-PLink can effectively schedule mix-flows at a small system overhead. Compared with ECMP, pFabric, and Karuna, the average flow completion time of DRL-PLink decreased by 77.79%, 65.61%, and 23.34% respectively, when the deadline meet rate is increased by 16.27%, 0.02%, and 0.836% respectively. Additionally, DRL-PLink can also well achieve load balance between paths. Waixi Liu 0001, Jinjie Lu, Jun Cai 0002, Yinghao Zhu, Sen Ling, Qingchun Chen |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | DRL-R: Deep reinforcement learning approach for intelligent routing in software-defined data-center networks
Waixi Liu 0001, Jun Cai 0002, Qing Chun Chen, Yu Wang 0017 |
J. Netw. Comput. Appl. | 2 |
| 2021 | APPM: Adaptive Parallel Processing Mechanism for Service Function ChainsabstractBy replacing traditional hardware-based middleboxes with software-based Virtual Network Functions (VNFs) running on general-purpose servers, network function virtualization represents a promising technique to reduce the cost of service creation and increase the agility of network operations. Typically, Service Function Chains (SFCs) are adopted to orchestrate dynamical network services and facilitate management of network applications. Recently, SFC parallelism that implements parallel processing of VNFs has been investigated to further improve SFC service quality. However, the unreasonable service graph of parallel processing in existing parallelized SFCs (PSFCs) might cause excessive resource consumption; incoordination between PSFC deployment and scheduling also increases the queuing delay of VNFs and degrades PSFC performance. In this article, an adaptive parallel processing optimization mechanism (APPM) is proposed to self-adaptively adjust the service graph of PSFCs and intelligently solve the joint problem of PSFC deployment and scheduling. Specifically, APPM uses a parallelism optimization algorithm (POA) based on the bin packing problem with soft bin capacity to optimize the structure of the PSFC service graph. Afterward, APPM employs a joint optimization algorithm based on reinforcement learning (JORL) to jointly deploy and schedule the PSFCs optimized by POA via the online perception of environment status. Simulation results showed that POA reduces the SFC parallelism degree and resource consumption by about 35%; JORL lowers SFC delay by reducing the queuing delay and has better overall performance than the state of the art algorithms even with limited resources. Jun Cai 0002, Zhongwei Huang, Liping Liao, Jian-Zhen Luo, Waixi Liu 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | On the Effective Parallelization and Near-Optimal Deployment of Service Function ChainsabstractNetwork operators compose Service Function Chains (SFCs) by tying different network functions (e.g., packet inspection, flow shaping, network address translation) together and process traffic flows in the order the network functions are chained. Leveraging the technique of Network Function Virtualization (NFV), each network function can be “virtualized” and decoupled from its dedicated hardware, and therefore can be deployed flexibly for better performance at any appropriate location of the underlying network infrastructure. However, an SFC often incurs high latency as traffic goes through the virtual network functions one after another. In this article, we first design an algorithm that leverages virtual network function dependency to convert an original SFC into a parallelized SFC (p-SFC). Then, to deploy multiple p-SFCs over the network for serving a large number of users, we model the deployment problem as an Integer Linear Program and propose a heuristic, ParaSFC, based on the Viterbi dynamic programming algorithm to estimate each p-SFC's occupation of the bottleneck resources and adjust the processing order of the p-SFCs in order to approximate the optimal solution. Finally, we conduct extensive trace-driven evaluations and exhibit that, compared to the Greedy method and the state-of-the-art CoordVNF method, ParaSFC reduces the average service latency of all the deployed p-SFCs by about 15 percent through parallelization while accommodating more SFC deployment requests over resource-limited networks. Jian-Zhen Luo, Jun Li 0001, Lei Jiao 0002, Jun Cai 0002 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2020 | Composing and deploying parallelized service function chains
Jun Cai 0002, Zhongwei Huang, Jian-Zhen Luo, Yan Liu 0042, Huimin Zhao 0001, Liping Liao |
J. Netw. Comput. Appl. | 1 |
| 2020 | Fine-grained flow classification using deep learning for software defined data center networks
Waixi Liu 0001, Jun Cai 0002, Yu Wang 0017, Qing Chun Chen, Jia-Qi Zeng |
J. Netw. Comput. Appl. | 2 |
| 2019 | Node importance to community based caching strategy for information centric networkingabstractSummary Information Centric Networking (ICN) is a novel future network architecture that is focusing on content distribution. Its ubiquitous caching schemes can improve network performance. In this paper, we propose a node importance to community based caching scheme with network coding in ICN, which is named as NICNC. For each community, content router makes cache decision depending on its node importance to community to make content cached more reasonable in temporal and spatial distribution. Moreover, by applying network coding into ICN, one coded blocks containing information of multiple chunks can satisfy multiple interests for different chunks sent by different consumers. This can significantly enhance cache diversity and cache hit rate without increasing cache capacity. Experimental results show that our scheme can improve the network performance at many aspects, such as average download time, cache hit rate, and instantaneous hop reduction rate. Chun Shan, Jun Cai 0002, Yan Liu 0042, Jian-Zhen Luo |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | A network community restructuring mechanism for transport efficiency improvement in scale-free complex networksabstractSummary Recent studies have demonstrated that network community structure can significantly reduce the network transport efficiency. In this paper, the weakening community structure (WCS) strategy based on adding of edges that can effectively weaken the network community characteristics and improve the network transport efficiency is proposed. The WCS performance was validated by experiments, which were performed on pseudo‐random network, scale‐free artificial network with community structures, and real internet, using the shortest path routing and the local routing. The experimental results have demonstrated that the WCS strategy can greatly improve the network load capacity and reduce the average length of the shortest path by adding a small amount of edges between communities. The proposed mechanism not only provides the improvement of network transport efficiency but also can be adapted for restraining of malicious information propagation through the network. Jun Cai 0002, Jian-Zhen Luo, Yan Liu 0042, Wenguo Wei, Fangyuan Lei |
Concurr. Comput. Pract. Exp. | 1 |
| 2018 | Enhancing network capacity by weakening community structure in scale-free network
Jun Cai 0002, Yu Wang 0017, Yan Liu 0042, Jian-Zhen Luo, Wenguo Wei, Xiaoping Xu |
Future Gener. Comput. Syst. | 1 |
| 2017 | Toward Fuzz Test Based on Protocol Reverse Engineering
Jun Cai 0002, Jian-Zhen Luo, Jianliang Ruan, Yan Liu 0042 |
ISPEC | 1 |
| 2017 | Information-centric networking with built-in network coding to achieve multisource transmission at network-layer
Waixi Liu 0001, Shunzheng Yu, Guang Tan, Jun Cai 0002 |
Comput. Networks | 4 |