VLDB 2026 Research / reviewers in the wild / expert
Ziling Wei
dblp:75/10312
· DBLP profile ↗
45ranked-venue papers
6as first author
38since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 6 first-author · 18 since 2021Security and privacy · 6 · 6 since 2021Systems, architecture and hardware · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ELSA: An Elastic Snn Inference Architecture for Efficient Neuromorphic Computing
Kang You, Chen Nie, Lee Jun Yan, Ziling Wei, Yu Feng 0007, Honglan Jiang, Zhezhi He |
ISCA | 4 |
| 2026 | Exploring the android TLS certificate ecosystem in ChinaabstractAbstract The HTTPS certificate ecosystem has long been a key topic in cybersecurity, yet the certificate landscape of Android applications remains insufficiently studied. In particular, while China has actively promoted the adoption of China’s national cryptographic algorithms in recent years, their actual deployment within the Chinese Android certificate ecosystem remains unclear. In this study, we analyzed TLS traffic from 19,980 applications in the Huawei App Market and extracted 131,933 certificate chains. While most certificates are properly configured, we identified 530 certificates with security risks, affecting 2043 applications. Notably, three SDK-related risk certificates were propagated across 1462 applications, substantially widening their security impact. Only 94 certificates using China’s national cryptographic algorithms were found, all within 89 financial applications, indicating deployment driven mainly by regulatory compliance. Furthermore, nearly 99% of leaf certificates chain back to foreign root Certificate Authorities, underscoring a strong dependency that may pose digital sovereignty risks under geopolitical uncertainty. This study highlights the existing challenges in the Chinese Android certificate ecosystem, particularly in terms of security and digital sovereignty, and offers relevant recommendations for improvement. Shuhui Chen, Ziling Wei, Fei Wang 0076, Zhenhao Luo |
Cybersecur. | 3 |
| 2026 | Blocking Is Not Stagnation: A Synchronous FPGA-CPU Architecture for Regular Expression Matching in Real-Time DPIabstractRegular expression matching is a crucial step in traffic analysis. Many hardware-based architectures are proposed to improve the matching throughput, such as FPGA. To date, however, the existing FPGA-CPU architectures are difficult to implement in DPI systems due to the following two reasons. First, existing architectures use asynchronous workflows to interact data between FPGA and CPU, making them difficult to be compatible with synchronous DPI systems. Second, asynchronous architectures require batch input, which does not meet the requirements of real-time environments. In this paper, we concentrate on the real-time deployment of a regular expression matching architecture. To improve the deployment throughput, we propose an FPGA-CPU architecture with a parallel layer between the driver and DPI systems. Then, coroutines are introduced and proved to have significant advantages. Meanwhile, some optimization methods are proposed to address idle time, memory allocation, and MMIO control. Our experiments demonstrate that directly deploying an asynchronous architecture on a synchronous DPI would result in a throughput degradation of 3 orders of magnitude. Our approach enhances throughput by 2-3 orders of magnitude. This indicates that we reach a throughput in synchronous mode that is comparable to that in asynchronous mode, and it is over 10 times faster than the software solution, making the direct deployment of asynchronous architectures on mainstream DPI systems feasible. To the best of our knowledge, this is the first attempt to improve hardware-based regular expression matching under synchronous logic, achieving both high throughput and usability. Shuhui Chen, Ziling Wei, Jincheng Zhong, Puguang Liu |
IEEE Trans. Netw. | 3 |
| 2025 | VISTREAM: Improving Computation Efficiency of Visual Streaming Perception via Law-of-Charge-Conservation Inspired Spiking Neural NetworkabstractVisual streaming perception (VSP) involves online intelligent processing of sequential frames captured by vision sensors, enabling real-time decision-making in applications such as autonomous driving, UAVs, and AR/VR. However, the computational efficiency of VSP on edge devices remains a challenge due to power constraints and the under-utilization of temporal dependencies between frames. While spiking neural networks (SNNs) offer biologically inspired event-driven processing with potential energy benefits, their practical advantage over artificial neural networks (ANNs) for VSP tasks remains unproven. In this work, we introduce a novel framework, ViStream, which leverages the Law of Charge Conservation (LoCC) property in ST-BIF neurons and a differential encoding (DiffEncode) scheme to optimize SNN inference for VSP. By encoding temporal differences between neighboring frames and eliminating frequent membrane resets, ViStream achieves significant computational reduction while maintaining accuracy equivalent to its ANN counterpart. We provide theoretical proofs of equivalence and validate ViStream across diverse VSP tasks, including object detection, tracking, and segmentation, demonstrating substantial energy savings without compromising performance. ViStream is publicly available at: https://github.com/Intelligent-Computing-Research-Group/ViStream Kang You, Ziling Wei, Qinghai Guo, Zhezhi He |
CVPR | 2 |
| 2025 | Cellular-Snooper: A General and Real-Time Mobile Application Fingerprinting Attack in LTE Networks
Wenao Zhang, Shuhui Chen, Ziling Wei, Qianqian Xing, Jinshu Su |
ICIC (4) | 3 |
| 2025 | ByteGT: A Hybrid Sequential-Attention Network for Enhancing File Fragment Classification on Raw DataabstractIn digital forensics practice, the precise determination of file fragment types serves as an essential prerequisite for successful file carving. Recent advancements in neural network-based methods have shown promise in this area, though challenges remain regarding temporal pattern capture in byte data and feature representation scalability within individual architectures. We propose ByteGT, the first hybrid neural network that integrates sequential modeling and attention mechanisms to further enhance the classification performance for file fragments. The model operates end-to-end on raw byte data without manual preprocessing through two novel components. The first component is a deep sequence perception module combining byte embeddings with bidirectional GRU to capture comprehensive temporal dependencies, and the second component is a fine-grained feature enhancement module using convolution-based attention layers to amplify discriminative features. Extensive evaluations on standard datasets demonstrate ByteGT’s superiority. Specifically, in most complex classification scenarios, we achieve 6.9% and 7% accuracy gains over state-of-the-art methods for 512-byte and 4096-byte sector sizes, respectively. When tested in other scenarios, ByteGT exhibits strong generalizability and robustness. Shuhui Chen, Ziling Wei |
IJCNN | 4 |
| 2025 | TrafficBM: A Dual-Modality Pre-Training Framework for Network Traffic ClassificationabstractNetwork traffic classification is critical for ensuring network quality, security, and stability. However, the increasing complexity of network environments and the growth of encrypted traffic bring significant challenges. Traditional rule-based, machine learning-based, and deep learning-based approaches are limited by the scarcity of plaintext, reliance on handcrafted features, and the need for large labeled datasets. Pre-training methods have alleviated these issues, but existing models mainly focus on payload semantics and lack dedicated learning of traffic behavior patterns essential for encrypted traffic characterization. Motivated by this, we propose TrafficBM, a dual-modality pre-training framework that jointly models semantic features and traffic behavior patterns. Our approach extracts dualmodality features from network traffic and applies modalityspecific data augmentation to mitigate data imbalance and scarcity. During pre-training, BERT leverages masked bigram modeling (MBM) to capture semantic information, while Mamba uses a masked autoencoder (MAE) architecture to learn traffic behavior patterns. An adaptive gating network, together with a parameter-preserving warm-up strategy, fuses features from both pre-trained models during fine-tuning to improve downstream classification performance. TrafficBM achieves state-of-the-art results on six tasks across eight datasets, including over 0.99 accuracy on five datasets and a 10 % improvement over the best baseline on Datacon2021 Part 2, demonstrating strong generalization and robustness in network traffic classification. Minxin Wang, Junhong Liao, Jinshu Su, Ziling Wei, Shuhui Chen, Zhengpeng Li, Biying Wang |
IPCCC | 4 |
| 2025 | I Know Who You are: An Identity Mapping Attack Based on Time Series Similarity in Mobile NetworksabstractIdentity privacy leakage through the wireless interface in mobile networks represents a persistent security challenge and a long-standing concern that network designers have aimed to address. Despite the remediation introduced in 5G standards, identity privacy attacks targeting the wireless interface continue to pose a potential threat. In this paper, we present an identity mapping attack based on time series similarity in 4G and 5G networks. This attack enables an adversary with no privileges to map a victim's social media account to their RNTI by sending a single image message to the victim and measuring the similarity of time series extracted from the generated downlink traffic. To improve the attack success rate, we specifically design an elastic similarity measure for time series, tailored to the properties of the data collected during the attack. We investigate the feasibility of the attack under various scenarios, achieving a success rate of 83% for a single attempt and nearly 100% when conducting two or three attempts. Our work provides new insights into the vulnerability of 4G/5G standards to identity privacy attacks. Wenao Zhang, Shuhui Chen, Junhong Liao, Ziling Wei, Mengyi Gong |
IPCCC | 4 |
| 2025 | PSSketch: Finding Persistent and Sparse Flow with High Accuracy and EfficiencyabstractFinding persistent sparse (PS) flow is critical to early warning of various threats. Previous works have predominantly focused on either heavy or persistent flows, with limited attention given to PS flows. Although some recent studies pay attention to PS flows, they struggle to establish an objective criterion due to insufficient data-driven observations, resulting in reduced accuracy. In this paper, we define a new criterion ''anomaly boundary'' to distinguish PS flows from regular flows. Specifically, a flow whose persistence exceeds a threshold will be protected, while a protected flow with a density lower than a threshold is reported as a PS flow. We then introduce PSSketch, a high-precision layered sketch, to find PS flows. PSSketch employs variable-length bitwise counters, where the first layer tracks the frequency and persistence of all flows, and the second layer protects potential PS flows and records overflow counts from the first layer. Some optimizations have also been implemented to reduce memory consumption further and improve accuracy. The experiments show that PSSketch reduces memory consumption by 1-2 orders of magnitude compared to the strawman solution combined with existing work. Compared with SOTA solutions for finding PS flows, it outperforms up to 2.94x higher in F1 score and reduces ARE by 1-2 orders of magnitude. Meanwhile, PSSketch achieves a higher throughput than these solutions. Qilong Shi, Xiyan Liang, Han Wang 0022, Wenjun Li 0004, Ziling Wei, Weizhe Zhang, Shuhui Chen |
KDD (2) | 6 |
| 2025 | PolymorPIC: Embedding Polymorphic Processing-in-Cache in RISC-V based Processor for Full-stack Efficient AI Inference
Ziling Wei, Jun Yan Lee, Chen Nie, Kang You, Zhezhi He |
MICRO | 2 |
| 2025 | A survey of existing attacks on 5G SA
Mengyi Gong, Ziling Wei, Shuhui Chen, Wanrong Yu, Fei Wang 0076 |
Comput. Networks | 2 |
| 2025 | MFSI: Multi-flow based service identification for encrypted network traffic
Biying Wang, Ziling Wei, Shuhui Chen, Zhengpeng Li, Minxin Wang |
Comput. Networks | 3 |
| 2025 | Toward an Effective Few-Shot Website Fingerprinting Attack With Quadruplet Networks and Deep Local Fingerprinting FeaturesabstractWebsite fingerprinting (WF) attacks can reveal the users' online privacy by the traffic analysis technique, even with the protection of the Tor anonymity network. Recent WF attacks tend to leverage the deep learning (DL) models, which require a large number of traffic samples for training. In this case, it is impractical for low-resource adversaries in reality. Thus, we propose a lightweight WF attack to tackle this challenge, i.e., Deep Quadruplet Fingerprinting (DQF), which only needs one training sample to obtain an accuracy of 87.1%. Regarding the overall design, DQF first combines the metric learning and meta-learning schemes. To improve the generalization ability of the trained model, DQF leverages the quadruplet networks as the architecture and modifies the quadruplet loss function. Besides, by taking the deep local fingerprinting features (DLFFs), DQF avoids losing a lot of discriminative information, which is a problem with previous attacks. To evaluate DQF, we use multiple typical datasets and conduct 11 different experiments. In closed-world settings, the accuracy of DQF can exceed the best baseline attack by 10%. In open-world settings, DQF steadily performs the best even in the most challenging scenario, namely, 1-shot learning, where previous attacks significantly degrade the performance or even fail. Hongcheng Zou, Jinshu Su, Ziling Wei, Shuhui Chen, Chunfang Yang, Mantun Chen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | KP-WF: Cross-Domain Few-Shot Website Fingerprinting
Lin Liu 0018, Ziling Wei, Shuhui Chen, Jinshu Su |
ICDF2C (2) | 2 |
| 2024 | FingerMamba: Mamba-based Efficient Multi-tab Website FingerprintingabstractNowadays, protecting user privacy on the Internet is paramount, especially with the increasing use of the Tor network to anonymize online activities. However, Tor is vulnerable to website fingerprinting (WF), where patterns in encrypted traffic are analyzed to infer visited websites. It can be utilized to monitor and investigate illegal activities on the dark web. Existing website fingerprinting techniques typically assume single-tab browsing, which is unrealistic as users often open multiple tabs consecutively or within a short period due to Tor’s slow loading speeds and typical user habits. Moreover, current multi-tab approaches face challenges in classification speed, which is crucial for high-throughput networks. FingerMamba, our proposed model, addresses these gaps by efficiently extracting local information and establishing long-range dependencies using a Mamba-based structured state-space model. It significantly enhances the accuracy and speed of multi-tab website fingerprinting. Extensive experiments on the largest real-world multi-tab dataset demonstrate that FingerMamba effectively improves classification accuracy in both closed-world and open-world settings. Furthermore, with maintaining similar accuracy performance, FingerMamba can increase inference speed by up to four times compared to the existing methods. To our knowledge, FingerMamba is the first model to tailor the Mamba architecture for website fingerprinting. Lin Liu 0018, Ziling Wei, Shuhui Chen, Zixuan Dong, Jinshu Su |
IPCCC | 2 |
| 2024 | AST-Trans: Detecting Web Tracking using Transformer-based Deep Learning with Abstract Syntax TreeabstractWeb tracking has become a key tool for service providers to collect online data and analyze user behaviors, raising concerns about the privacy of Internet users. In this paper, we propose a new web tracking detection method, namely AST-Trans, which detects and removes web tracking behavior using Transformer-based deep learning with abstract syntax trees. In the method, the abstract syntax tree is built for the detected website codes. Then, a sequence generation algorithm is proposed to convert tree-like code structures into one-dimensional sequences for deep models. To enhance training efficiency, we devise a reduction strategy to simplify the code tree structure by introducing equivalent nodes. After that, a Transformer-based deep learning algorithm is introduced to realize web tracking detection. By the proposed method, the exact tracking code blocks can be identified, and thus, we can implement the tracking code removal with minimum website breakage. To verify the effectiveness of the proposed method, an HTTPS proxy with AST-Trans on it is implemented to detect and remove tracking codes. We evaluate AST-Trans with the TrackSign-labeled dataset. The results show that the proposed method can detect the tracking behavior with high precision. In addition, we validate the feasibility of the method by measuring the website page breakage. Ziling Wei, Lin Liu 0018, Shuhui Chen, Jinshu Su |
IPCCC | 2 |
| 2024 | A Large-Scale Mobile Traffic Dataset For Mobile Application IdentificationabstractAbstract With Internet access shifting from desktop-driven to mobile-driven, application-level mobile traffic identification has become a research hotspot. Although considerable progress has been made in this research field, two obstacles are hindering its further development. Firstly, there is a lack of sharable labeled mobile traffic datasets. Although it is easy to capture mobile traffic, labeling traffic at the application level is non-trivial. Besides, researchers usually hold a conservative attitude toward publishing their datasets for privacy concerns. Secondly, most of the datasets used by existing studies are inadequate to evaluate the proposed methods, since they usually have the problems of inaccurate labels, small scale and simple collection configurations. To tackle these two obstacles, a mobile traffic collection is carried out in this paper. The collected traffic has the advantages of large-scale data size, accurate application-level labels and diverse collection configurations. Then, the collected traffic is anonymized carefully to make it public. Several mobile traffic identification methods are compared based on our anonymized dataset, which proves the applicability of our dataset. Shuhui Chen, Fei Wang 0076, Ziling Wei, Jincheng Zhong, Jianbing Liang |
Comput. J. | 4 |
| 2024 | Protecting unauthenticated messages in LTE/5G mobile networks: A two-level Hierarchical Identity-Based Signature (HIBS) solution
Chuan Yu 0003, Shuhui Chen, Qianqian Xing, Ziling Wei |
Comput. Networks | 4 |
| 2024 | Relation-CNN: Enhancing website fingerprinting attack with relation features and NFS-CNN
Hongcheng Zou, Ziling Wei, Jinshu Su, Shuhui Chen |
Expert Syst. Appl. | 2 |
| 2024 | A multi-agent collaboration scheme for energy-efficient task scheduling in a 3D UAV-MEC spaceabstractMulti-access edge computing (MEC) presents computing services at the edge of networks to address the enormous processing requirements of intelligent applications. Due to the maneuverability of unmanned aerial vehicles (UAVs), they can be used as temporal aerial edge nodes for providing edge services to ground users in MEC. However, MEC environment is usually dynamic and complicated. It is a challenge for multiple UAVs to select appropriate service strategies. Besides, most of existing works study UAV-MEC with the assumption that the flight heights of UAVs are fixed; i.e., the flying is considered to occur with reference to a two-dimensional plane, which neglects the importance of the height. In this paper, with consideration of the co-channel interference, an optimization problem of energy efficiency is investigated to maximize the number of fulfilled tasks, where multiple UAVs in a three-dimensional space collaboratively fulfill the task computation of ground users. In the formulated problem, we try to obtain the optimal flight and sub-channel selection strategies for UAVs and schedule strategies for tasks. Based on the multi-agent deep deterministic policy gradient (MADDPG) algorithm, we propose a curiosity-driven and twin-networks-structured MADDPG (CTMADDPG) algorithm to solve the formulated problem. It uses the inner reward to facilitate the state exploration of agents, avoiding convergence at the sub-optimal strategy. Furthermore, we adopt the twin critic networks for update stabilization to reduce the probability of Q value overestimation. The simulation results show that CTMADDPG is outstanding in maximizing the energy efficiency of the whole system and outperforms the other benchmarks. Yang Li 0052, Ziling Wei, Jinshu Su, Baokang Zhao |
Frontiers Inf. Technol. Electron. Eng. | 2 |
| 2024 | Toward a Truly Secure Telecom Network: Analyzing and Exploiting Vulnerable Security Configurations/ Implementations in Commercial LTE/IMS NetworksabstractAuthentication and data protection (both integrity and confidentiality) between the network and cellular devices are two fundamental security features in LTE and IMS networks. The first is implemented via authentication and key agreement mechanisms and can be compromised by relaying authentication parameters. The second security feature builds on the first one and is activated through corresponding security setup procedures. This work intends to investigate whether these basic security procedures are securely implemented and deployed in commercial networks. We analyzed the de facto situation of these security features in three major operators in China and found several new and previously disclosed configuration and implementation flaws that do not conform to specifications. These vulnerabilities allow attackers to disable LTE and IMS data protection mechanisms. We further propose novel proof-of-concept attacks to exploit the identified vulnerabilities includingIMEIandPhone Number Catching,SMSandCall ImpersonationandInterceptionattacks. To show the urgency of addressing these security issues and thus secure the real-world telecom networks, we successfully demonstrated these attacks in practice using open-source SDR tools as they have serious implications. For instance, the interception attacks undermine the widely-used SMS verification code security mechanism. We also discuss countermeasures to resist the proposed attacks. Chuan Yu 0003, Shuhui Chen, Ziling Wei, Fei Wang 0076 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | GPT-LS: Generative Pre-Trained Transformer with Offline Reinforcement Learning for Logic SynthesisabstractLogic synthesis (LS) is a process that transforms a high-level logic circuit description into a gate-level netlist, typically via a heuristic algorithm. Such a process can be decomposed into a series of transformation primitives, where each primitive optimizes the netlist while preserving the functional equivalence. However, identifying a desirable primitive sequence (PS) to achieve design goals is challenging, due to the immense design space. Recent advances in artificial intelligence offer the opportunity to leverage machine learning techniques to tackle the combinatorial optimization problem associated with PS. Unfortunately, the existing works either require time-consuming training for each circuit or incur high computational costs. To address these issues, we redefine the optimization of LS as a sequence generation problem and propose a generative pre-trained transformer (GPT) with offline reinforcement learning, which is named as GPT-LS. Thanks to the OpenABC-D dataset, GPT-LS is pre-trained on diverse circuits and its massive intermediate data during the synthesis, by utilizing the offline reinforcement learning technique of decision transformer. Then, GPT-LS is able to generate PS for unseen circuits to conduct optimized LS. According to our comprehensive experiments, GPT-LS achieves results that match those of previous state-of-the-art methods in a significantly shorter time. It is available at: github.com/Intelligent-Computing-Research-Group/GPT-LS. Chenyang Lv, Ziling Wei, Weikang Qian, Junjie Ye 0002, Chang Feng, Zhezhi He |
ICCD | 2 |
| 2023 | SecChecker: Inspecting the security implementation of 5G Commercial Off-The-Shelf (COTS) mobile devices
Chuan Yu 0003, Shuhui Chen, Ziling Wei, Fei Wang 0076 |
Comput. Secur. | 3 |
| 2023 | TupleTree: A High-Performance Packet Classification Algorithm Supporting Fast Rule-Set UpdatesabstractPacket classification plays a crucial role in various network functions such as access control and routing. In recent years, the rapid development of SDN and NFV poses new challenges for packet classification to support fast rule-set updates as introducing strong dynamics for the structure of networks. To this end, this paper proposes a novel scheme, TupleTree, to perform high-speed packet classification while providing fast rule-set update ability. TupleTree is a hybrid scheme combining decision tree and tuple space. In TupleTree, it organizes rules in a decision tree-like structure, but distributes rules in each node into child nodes through hashing rather than cutting or splitting. With the decision tree structure, for each classification, one leaf node containing a few rules can be rapidly indexed. Hence, a high classification performance can be achieved. Meanwhile, with hashing instead of cutting or splitting, it is easy to support fast rule-set updates due to having avoided the rule replication problem. Compared to state-of-the-art schemes that support fast rule-set updates, experimental results show that our proposed scheme achieves a classification performance improvement of 85% to 237% while retaining close update performance for large rule-sets. Jincheng Zhong, Ziling Wei, Shuhui Chen |
IEEE/ACM Trans. Netw. | 2 |
| 2022 | Multi-Level Text Importance Classification Architecture Based on Deep LearningabstractIn the era of information explosion, the Internet is full of spam and false information, making it more difficult for people to obtain effective information. Since text data is the main carrier for disseminating information and knowledge, we propose a multi-level text importance classification architecture based on deep learning to enable Internet users to quickly and accurately access text content of interest. Experiments demonstrate that the proposed architecture can achieve a good performance. Meizhen Huang, Jinshu Su, Zhong Liao, Shuhui Chen, Ziling Wei |
APNet | 5 |
| 2022 | FATSS: Filter-Assisted Tuple Space Search for Packet ClassificationabstractPacket Classification is a key part of supporting lots of network functions. Various algorithms have been proposed over the years to meet the increasing performance requirements of packet classification. Tuple space search (TSS) is one of the most popular algorithms and well-suited to scenarios requiring efficient online updates. However, the huge number of tuples in the algorithm leads to numerous memory accesses during packet classification, which limits the classification performance. This paper proposes a novel model named FATSS, which uses Filters to Assist the Tuple Space Search algorithm and reduces the number of tuple accesses. We first create the ImCuckoo Filter by improving the Cuckoo Filter from its structure, capacity and hash calculation. Then, we embed ImCuckoo Filter into TSS in two ways (online and offline) to adapt to diverse scenarios and requirements. By the experiments, it can be found that the ImCuckoo Filter can reduce more than 80% of tuple accesses. Furthermore, the access time of the filter is no more than 60% compared with that of the hash table. The experimental results show that the classification time of FATSS is 17%–19% faster than that of existing widely used algorithms. Jiayao Wang 0002, Ziling Wei, Jincheng Zhong, Shuhui Chen |
IPCCC | 2 |
| 2022 | Robust Packet Classification with Field MissingabstractPacket classification shows a key role in kinds of network functions, such as access control, routing, and quality of service (QoS). With the rapid growth of the network size, users have to ignore some fields in packet classification due to resource constraints. In addition, some fields may not always be available in some networks. However, traditional packet classification algorithms can hardly handle packet classification if some fields are missing. In this paper, we propose a novel model to build a robust classifier. In the classifier, we utilize the advantage of Recursive Flow Classification (RFC) in handling fields concurrently. Then, we design a new workflow to deal with field missing based on flows. In addition, two complementary bitmap models are designed to accelerate matching packets to flows, and a buffer mechanism is introduced to further improve the classification accuracy. Our experiments show that the proposed classifier can classify packets with an accuracy of 94%-99.5% when the field missing probability is lower than 0.3. Jiayao Wang 0002, Ziling Wei, Baokang Zhao, Jincheng Zhong |
LCN | 2 |
| 2022 | RTSS: Robust Tuple Space Search for Packet ClassificationabstractPacket classification shows an essential role in net-work functions. Traditional classification algorithms assume that all field values are available and valid. However, such a premise is being challenged as networks become more complex now. Scenarios with field-missing poses great challenges to packet classifiers. Existing approaches can only list all possible situations in such cases, increasing the workload exponentially. RFC algorithm is proved to be helpful for this issue in our previous work, but its spacial performance is much poor. In this paper, we propose a novel classification scheme using Tuple Space Search (TSS) to deal with missing fields. We redesign the hash calculation method and raise a new data structure to recover field-missing packets. The experiment shows that RTSS reduce the memory consumption and construction time by several orders of magnitude. At the same time, RTSS has better classification performance than previous work, while supporting fast updates. Jiayao Wang 0002, Ziling Wei, Shuhui Chen, Jincheng Zhong |
MSN | 2 |
| 2022 | An efficient cross-domain few-shot website fingerprinting attack with Brownian distance covariance
Hongcheng Zou, Jinshu Su, Ziling Wei, Shuhui Chen, Baokang Zhao |
Comput. Networks | 3 |
| 2022 | HAGDetector: Heterogeneous DGA domain name detection modelabstractThe botnet relies on the Command and Control (C&C) channels to conduct its malicious activities remotely. The Domain Generation Algorithm (DGA) is often used by botnets to hide their Command and Control (C&C) server and evade take-down attempts, which allows the bot to generate a large number of domain names until it finds its C&C server. The lengths of domain names generated by DGAs are different. Our research finds that the length of the domain name has an impact on the performance of the DGA domain name detection model. In other words, the model is sensitive to the length of the domain name. In this case, attackers can evade detection simply by designing domain names of specific lengths. Moreover, the detection accuracy of DGA domain names still needs to be further improved. To solve these problems, three feature extraction methods adapted to the length of the domain name are proposed in this paper. For extra-short domain names, we use the attention-based method to extract features, which can make use of the character-level semantic feature. For moderate-length domain names, a two-dimensional structure, namely Right Shifted Tensor (RST), is constructed to make the domain name present apparent features similar to images. For the extra-long domain name, the effective classification of domain names can be achieved by manually crafted easy-to-calculate features. Then, different detection structures are designed based on these tree feature extraction methods to form a heterogeneous DGA detection model, namely HAGDetector. In addition, the public suffix is an important part of the domain name. We further analyze the public suffix to evaluate its impact on the detection of DGA domain names. Finally, the experiments are conducted to assess the validity of HAGDetector, as well as compare our approach with the current state-of-the-art and highlight the impact of the domain name length. The experimental results show that our method greatly improves the detection performance. Jianbing Liang, Shuhui Chen, Ziling Wei |
Comput. Secur. | 3 |
| 2022 | Moving direction-based adaptive task migration in MECabstractAbstract Edge computing is expected to be a promising paradigm to provide low‐latency services. Tasks from resource‐limited users can be offloaded to edge servers for efficient execution within a limit time. This innovative technique has attracted widespread attention. Task migration is one of the important problems in mobile edge computing (MEC). Taking vehicle network as an example, during the moving process, a vehicle passes through multiple edge servers and decisions about where to migrate the task need to be made. The moving direction should be emphasized since it directly determines a vehicle's trajectory. Nevertheless, few existing works take the moving direction into consideration. In this paper, task migration issue during the vehicle's mobility process is investigated and the moving direction is specifically considered. The direction helps exclude meaningless selections. The moving process can be formulated as a Markov decision process (MDP) and effort is made to design an adaptive algorithm with direction consideration, aiming at minimizing the total communication time while satisfying the deadline of each task. Based on deep Q network (DQN), we devise a Soft update and parameter Noise applied algorithm DQN‐SN, trying to enlarge action exploration space and stabilize the target network's parameter placement in training process. Besides, with the goal of building credible MEC, a credit‐based scheme is also introduced to establish a trusted edge environment. Extensive experiments are conducted to evaluate the performance of our proposed algorithm. Compared to Greedy algorithm and DQN, the total consumed task communication time of DQN‐SN shows 10–20% reduction. Furthermore, the algorithms with the direction factor always outperform the algorithms without direction consideration. Yang Li 0052, Ziling Wei, Jinshu Su |
IET Commun. | 2 |
| 2022 | Technology trends in large-scale high-efficiency network computingabstractNetwork technology is the basis for large-scale high-efficiency network computing, such as supercomputing, cloud computing, big data processing, and artificial intelligence computing. The network technologies of network computing systems in different fields not only learn from each other but also have targeted design and optimization. Considering it comprehensively, three development trends, i.e., integration, differentiation, and optimization, are summarized in this paper for network technologies in different fields. Integration reflects that there are no clear boundaries for network technologies in different fields, differentiation reflects that there are some unique solutions in different application fields or innovative solutions under new application requirements, and optimization reflects that there are some optimizations for specific scenarios. This paper can help academic researchers consider what should be done in the future and industry personnel consider how to build efficient practical network systems. Jinshu Su, Baokang Zhao, Jijun Cao, Ziling Wei, Congxi Song, Yusheng Xia |
Frontiers Inf. Technol. Electron. Eng. | 5 |
| 2022 | Event-Driven Computation Offloading in IoT With Edge ComputingabstractEdge computing, which provides computation services at the edge of networks, has become a promising method to meet the massive computation demands of Internet of Things (IoT). To make full use of resources, a computation offloading scheme is needed in edge computing system. In this work, we propose an event-driven computation offloading scheme for the first time. Compared with the existing time-driven schemes, the proposed scheme has a smaller implementation complexity in some scenarios with computation-intensive task computing. In the proposed scheme, the priority of different tasks is jointly considered. To decide the optimal offloading action of the scheme, we formulate the offloading problem as a semi-Markov decision process (SMDP). Then, a model-based method is proposed to derive the optimal offloading policy under fully explored system by addressing the challengs of modeling. On the other hand, considering partially explored system, we propose an online double deep Q-network algorithm, which can deal with the poor scalability of the standard Q-learning algorithm, to derive the optimal offloading policy. In addition, we also introduce some tricks to accelerate the learning procedure. The simulation results show the superior performance of our proposed scheme. Ziling Wei, Baokang Zhao, Jinshu Su |
IEEE Trans. Wirel. Commun. | 1 |
| 2021 | A Novel 3D Intelligent Cluster Method for Malicious Traffic Fine-Grained Classification
Baokang Zhao, Murao Lin, Ziling Wei, Qin Xin 0001, Jinshu Su |
ICA3PP (1) | 3 |
| 2021 | A Probabilistic Resilient Routing Scheme for Low-Earth-Orbit Satellite Constellations
Ziling Wei, Baokang Zhao, Jinshu Su, Qin Xin 0001 |
WASA (3) | 2 |
| 2021 | CMT: An Efficient Algorithm for Scalable Packet ClassificationabstractAbstract Packet classification plays an essential role in diverse network functions such as quality of service, firewall filtering and load balancer. However, implementing an efficient packet classifier is a challenging problem. The problem even gets worse in the era of software-defined network, in which frequent rule updates are performed, and complex flow tables are used. This paper proposes CMT, a new software algorithm named by its novel data structure—common mask tree—to implement an efficient multi-field packet classifier. The core idea of CMT is to combine the strengths of both decision-tree and tuple-space schemes by employing tree-like structures and hash tables simultaneously. The objective of CMT is to achieve both high classification performance and fast rule updates. In the evaluation section, CMT is compared with decision-tree and tuple-space schemes. Compared to the state-of-the-art decision-tree methods, CMT performs rule updates at two orders of magnitude faster. CMT has a stable performance on different rulesets and achieves a 40% improvement in memory access compared to the state-of-the-art tuple-space method. Shuhui Chen, Jincheng Zhong, Ziling Wei |
Comput. J. | 4 |
| 2021 | Improving 4G/5G air interface security: A survey of existing attacks on different LTE layers
Chuan Yu 0003, Shuhui Chen, Fei Wang 0076, Ziling Wei |
Comput. Networks | 4 |
| 2021 | RF-RISA: A novel flexible random forest accelerator based on FPGA
Shuhui Chen, Fei Wang 0076, Ziling Wei |
J. Parallel Distributed Comput. | 5 |
| 2020 | Distributed Opportunistic Scheduling in Cooperative Networks With RF Energy HarvestingabstractIn this paper, the problem of distributed opportunistic channel access in wireless cooperative networks is investigated. To cope with the energy limitation problem of relay nodes, radio-frequency (RF) energy harvesting is considered, and thus, no external energy is needed for each relay node. Then, a novel distributed opportunistic scheduling (DOS) scheme is proposed. In the scheme, users contend for the channel access opportunity by random access, and then, the user with a successful contention makes a decision whether to give up the opportunity after probing the source-to-relay link and relay-to-destination link by following a strategy. To maximize the average throughput of the network, the optimal strategy of the proposed scheme, which is to help the user to decide whether to give up the transmission opportunity, is derived by optimal stopping theory. The obtained optimal strategy has a threshold-based structure, and thus, it is easy to implement in practice. In addition, the threshold can be calculated off-line by a proposed low-complexity algorithm. Simulation results are provided to demonstrate the superior performance of the proposed DOS scheme. Ziling Wei, Jinshu Su, Baokang Zhao, Xicheng Lu |
IEEE/ACM Trans. Netw. | 1 |
| 2019 | Cooperative Sensing in Cognitive Radio Ad Hoc NetworksabstractCognitive radio technology can largely enhance spectrum utilization efficiency by dynamic spectrum access. In cognitive radio, spectrum sensing is essential to protect the transmission of primary users (PUs). To improve the sensing accuracy, cooperative sensing has been introduced in the literature. However, there are still some challenges on cooperative sensing, especially in Cognitive Radio Ad Hoc Networks (CRAHNs) in which a centralized coordinator does not exist. In this paper, we deal with the challenges of cooperative sensing in CRAHNs, with focus on sensing data fusion and security. An overview of existing research efforts is given first, and thus, the research challenges are identified and discussed in details. To solve those challenges, we propose a cooperative sensing scheme for CRAHNs. In order to reduce the communication overhead, we partition the secondary users (SUs) to several clusters, and in each cluster, a cluster head is selected to serve as the representative for the cluster. An efficient consensus-based method with security consideration is proposed to obtain the accurate final sensing result. Extensive simulation is conducted based on real scenarios to evaluate the performance of the proposed scheme. Ziling Wei, Baokang Zhao, Jinshu Su |
ICC | 1 |
| 2019 | Dynamic Edge Computation Offloading for Internet of Things With Energy Harvesting: A Learning MethodabstractMobile edge computing (MEC) has recently emerged as a promising paradigm to meet the increasing computation demands in Internet of Things (IoT). However, due to the limited computation capacity of the MEC server, an efficient computation offloading scheme, which means the IoT device decides whether to offload the generated data to the MEC server, is needed. Considering the limited battery capacity of IoT devices, energy harvesting (EH) is introduced to enhance the lifetime of the IoT systems. However, due to the unpredictability nature of the generated data and the harvested energy, it is a challenging problem when designing an effective computation offloading scheme for the EH MEC system. To cope with this problem, we model the computation offloading process as a Markov decision process (MDP) so that no prior statistic information is needed. Then, reinforcement learning algorithms can be adopted to derive the optimal offloading policy. To address the large time complexity challenge of learning algorithms, we first introduce an after-state for each state-action pair so that the number of states in the formulated MDP is largely decreased. Then, to deal with the continuous state space challenge, a polynomial value function approximation method is introduced to accelerate the learning process. Thus, an after-state reinforcement learning algorithm for the formulated MDP is proposed to obtain the optimal offloading policy. To provide efficient instructions for real MEC systems, several analytical properties of the offloading policy are also presented. Our simulation results validate the great performance of our proposed algorithm, which significantly improves the achieved system reward under a reasonable complexity. Ziling Wei, Baokang Zhao, Jinshu Su, Xicheng Lu |
IEEE Internet Things J. | 1 |
| 2015 | Providing adaptive quality of security in quantum networks
Baokang Zhao, Ziling Wei, Bo Liu 0013, Jinshu Su, Ilsun You |
QSHINE | 2 |
| 2014 | SPS: A Novel Semantics-Aware Scheme for Location Privacy in People-Centric Sensing Network
Ziling Wei, Jinshu Su, Baokang Zhao |
WASA | 1 |
| 2013 | Qphone: a quantum security VoIP phoneabstractThis work presents a novel quantum security VoIP phone, called Qphone. Qphone integrates quantum key distribution (QKD) and VoIP steganography, and achieves peer-to-peer communication with information-theoretical security (ITS) guaranteeing. Qphone consists of three parts, a real-time QKD system, RT-QKD, a steganography software, VS-Phone, and an audio encryption and authentication hardware, AE-KEY. RT-QKD explores QKD technologies, and is able establish a shared key between two peers ensuring ITS. VS-Phone utilizes VoIP steganography to protect transmission channels of sensitive information. Qphone can provide efficient and real-time security protections to meet different security demands. Bo Liu 0013, Baokang Zhao, Ziling Wei, Chunqing Wu, Jinshu Su, Wanrong Yu, Fei Wang 0007, Shihai Sun |
SIGCOMM | 3 |
| 2011 | VISOR: A Pratical VoIP Steganography PlatformabstractRecently, streaming steganography has attracted a lot of research efforts, however, since multimedia processing requires high performance hardware and software, most literatures in the streaming steganography community focus on simulations due to lack of a practical streaming steganography platform. Towards this issue, we design and develop VISOR, a novel VoIP Steganography Oriented platfoRm. VISOR consists of both hardware(named "VISOR-Key") and software(named "VISORPhone"). In general, VISOR provides an open, high performance and portable platform to the streaming steganography community. Ziling Wei, Bo Liu 0012, Erci Xu, Baokang Zhao, Jinshu Su |
MSN | 1 |