VLDB 2026 Research / reviewers in the wild / expert
Gang Ren 0003
dblp:75/3931-3
· DBLP profile ↗
18ranked-venue papers
0as first author
7since 2021 · last 2026
0000-0003-3560-6435ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Clustering: A Hybrid Framework for Target Generation in Sparse IPv6 Networks
Gang Ren 0003, Xia Yin 0001, Lin He 0004, Haoxiang Yang |
ICC | 2 |
| 2026 | Comprehensive Network Configuration Verification via Effective Environment Reduction
Han Zhang 0009, Renrui Tian, Xia Yin 0001, Xingang Shi, Gang Ren 0003, Jilong Wang 0001, Jiangyuan Yao |
INFOCOM | 7 |
| 2026 | Beyond Random Probing: Intelligent IPv6 Discovery via Ensemble Learning and Contextual Expansion
Haoxiang Yang, Gang Ren 0003, Wenying Jiang |
IWQoS | 2 |
| 2025 | PMAPD: A Passive-Enhanced Multi-Level Aliased Prefix Detection Approach for IPv6 ScanningabstractIPv6 scanning is a critical technique for network security assessment and Internet measurement. However, the prevalence of aliased prefixes significantly distorts scan results and severely interferes with target generation algorithms (TGAs) that rely on dynamic density feedback. To address the limitations of existing aliased prefix detection methods, such as insufficient accuracy and excessive overhead, this paper proposes PMAPD, a Passive-Enhanced Multi-Level Aliased Prefix Detection approach. PMAPD integrates passive analysis with active probing. The passive analysis component reuses existing scan data—primarily host responsiveness obtained at no extra cost from the main address scan, and opportunistically uses port and service information if available, to enhance detection accuracy and efficiency. The active probing component builds upon the strengths of prior active methods while incorporating optimizations to achieve a better balance between detection precision and cost. Experimental results demonstrate PMAPD’s superiority in improving the discovery of de-aliased active addresses, reducing aliased addresses in scanning results, and significantly lowering detection overhead. Across three different TGAs tested (6Tree, DET, 6Sense), PMAPD significantly outperforms the widely used traditional method MAPD: it improves the de-aliased hits by 12% to 57%, substantially reduces the aliased ratio in scan results by over 9% to 94%, and dramatically lowers detection overhead, costing only 3% to 17% of MAPD’s overhead. PMAPD offers a novel and effective aliased prefix detection solution for efficient and accurate IPv6 network scanning. Gang Ren 0003, Xia Yin 0001, Lin He 0004 |
ICNP | 2 |
| 2025 | RGen: A Real-Time Pattern Mining Approach to Target Generation for Internet-Wide IPv6 ScanningabstractTarget generation is a crucial step for efficient Internet-wide IPv6 scanning, yet existing techniques are hindered by limited pattern discovery and biased target distribution. We introduce RGen, a novel target generation algorithm employing real-time pattern mining and a stochastic generation strategy. RGen minimizes pattern loss, dynamically incorporates new addresses, and promotes balanced target distribution, overcoming prior limitations. Experiments show RGen achieves the highest overall hit rate (58%), surpassing the previous best (AddrMiner-S) by 60%, while simultaneously leading in network discovery, finding the most new BGP prefixes and new / 64 prefixes. Gang Ren 0003, Xia Yin 0001, Lin He 0004 |
IWQoS | 2 |
| 2021 | Towards securing Duplicate Address Detection using P4
Lin He 0004, Peng Kuang, Ying Liu 0024, Gang Ren 0003, Jiahai Yang 0001 |
Comput. Networks | 4 |
| 2021 | PAVI: Bootstrapping Accountability and Privacy to IPv6 InternetabstractAccountability and privacy are considered valuable but conflicting properties in the Internet, which at present does not provide native support for either. Past efforts to balance accountability and privacy in the Internet have unsatisfactory deployability due to the introduction of new communication identifiers, and because of large-scale modifications to fully deployed infrastructures and protocols. The IPv6 is being deployed around the world and this trend will accelerate. In this paper, we propose a private and accountable proposal based on IPv6 called PAVI that seeks to bootstrap accountability and privacy to the IPv6 Internet without introducing new communication identifiers and large-scale modifications to the deployed base. A dedicated quantitative analysis shows that the proposed PAVI achieves satisfactory levels of accountability and privacy. The results of the evaluation of a PAVI prototype show that it incurs little performance overhead, and is widely deployable. Lin He 0004, Gang Ren 0003, Ying Liu 0024, Jiahai Yang 0001 |
IEEE/ACM Trans. Netw. | 2 |
| 2019 | Multi-modal Representation Learning for Successive POI RecommendationabstractSuccessive POI recommendation is a fundamental problem for location-based social networks (LBSNs). POI recommendation takes a variety of POI context information (e.g. spatial location and textual comment) and user preference into consideration. Existing POI recommendation systems mainly focus on part of the POI context and user preference with a specific modeling, which loses valuable information from other aspects. In this paper, we propose to construct a multi-modal check-in graph, a heterogeneous graph that combines five check-in aspects in a unified way. We further propose a multi-modal representation learning model based on the graph to jointly learn POI and user representations. Finally, we employ an attentional recurrent neural network based on the representations for successive POI recommendation. Experiments on a public dataset studies the effects of modeling different aspects of check-in records and demonstrates the effectiveness of the method in improving POI recommendation performance. Lishan Li, Ying Liu 0024, Lin He 0004, Gang Ren 0003 |
ACML | 5 |
| 2019 | NFVMP: An Architecture for NFV Applications from Multiple ProvidersabstractWith the evolution of Network Function Virtualization (NFV), small- and medium-size enterprises are increasingly outsourcing their network functions (NFs) to the cloud. In order to obtain cost-effective and high-performance services, customers may utilize NFs from various cloud providers. Current NFV architectures are mostly designed on the assumption of one provider, which utilize centralized controllers for orchestration. In multi-provider scenario, autonomy of each provider leads to infeasibility of a centralized controller. In this paper, we propose NFVMP, a novel NFV architecture that enables cooperation of providers to compose intended chains, while maintaining dependency of each provider. NFVMP adopts a fresh view that regards the sub-chain of each provider as first-class entity, and supports sub-chain composition and flexibility. We implement a prototype, which demonstrates that NFVMP supports correct chain deployment across providers with a negligible performance overhead on latency and throughput. Lishan Li, Ying Liu 0024, Gang Ren 0003 |
APNOMS | 4 |
| 2019 | Address Protection-as-a-Service an Inter-AS Framework for IP Spoofing ResilienceabstractIP spoofing, which is generally used for anonymity and amplification, constantly leads to pervasive distributed denial-of-service (DDoS) attacks. To mitigate IP spoofing, source address validation is divided into access network, intra-autonomous system (AS), and inter-AS levels. However, because of ambiguous incentives, heterogeneous demands, and fragile trust, techniques for the inter-AS level fail in practice, and thus, IP spoofing is still considered as an almost open vulnerability of the entire Internet. In this study, we aim to transform the inter-AS source address validation into an "address protection" service, and we mitigate IP spoofing through an economics-driven framework - apf ('a'ddress 'p'rotection 'f'ramework). In such a protection, the addresses belonging to one AS can be prevented from being spoofed by others. Behind the framework, such a service will be consolidated by a unified trust anchor with a uniform interface, and deployer ASes will be free to select their preferred techniques and invoke the service when needed. Based on the empirical data and theoretical analysis, we prove that the service is acceptable for triggering economics-driven implementation under the guidance of the apf framework. Yihao Jia, Ying Liu 0024, Gang Ren 0003 |
GLOBECOM | 3 |
| 2019 | GSDM: Graph-Based Scaling Detection Model in Network Function VirtualizationabstractNetwork function virtualization (NFV) is an emerging technology, which aims at replacing proprietary network function hardware devices with software- based network function (NF) applications. In NFV, it is critical to conduct dynamic and elastic resource allocation in accordance with varying workloads. State- of-the-art scaling detection algorithms are designed based on either traffic rate or runtime status. However, they cannot make precise and agile scaling decisions due to diversity of input traffic and noisy measurements. In this paper, we propose a novel graph-based scaling detection model (GSDM) using deep learning techniques. GSDM is a neural network model, which selects scaling action based on feature sequences of each NF and its adjacent NFs. Neural network provides a scalable way to incorporate both traffic rate and runtime status into control policy. Furthermore, adjacent NFs' feature information is also injected. As a result, GSDM empirically learns policies that achieves precise and agile scaling detections and improves system performance. Our implemented prototype demonstrates that GSDM achieves superior performance in precision and recall, and outperforms other schemes in a variety of network conditions. Lishan Li, Ying Liu 0024, Gang Ren 0003 |
GLOBECOM | 4 |
| 2019 | Bootstrapping Accountability and Privacy to IPv6 Internet without Starting from ScratchabstractAccountability and privacy are considered valuable but conflicting properties in the Internet, which at present does not provide native support for either. Past efforts to balance accountability and privacy in the Internet have unsatisfactory deployability due to the introduction of new communication identifiers, and because of large-scale modifications to fully deployed infrastructures and protocols. The IPv6 is being deployed around the world and this trend will accelerate. In this paper, we propose a private and accountable proposal based on IPv6 called PAVI that seeks to bootstrap accountability and privacy to the IPv6 Internet without introducing new communication identifiers and large-scale modifications to the deployed base. A dedicated quantitative analysis shows that the proposed PAVI achieves satisfactory levels of accountability and privacy. The results of evaluation of a PAVI prototype show that it incurs little performance overhead, and is widely deployable. Lin He 0004, Gang Ren 0003, Ying Liu 0024 |
INFOCOM | 2 |
| 2018 | GAGMS: a requirement-driven general address generation and management system
Ying Liu 0024, Lin He 0004, Gang Ren 0003 |
Sci. China Inf. Sci. | 3 |
| 2017 | Revisiting inter-AS IP spoofing let the protection drive source address validationabstractIP spoofing, which is prevalently used for anonymity and reflection attacks, has shown increasing destructive power in recent years. Although certain source address validation solutions have been standardized by the Internet Engineering Task Force, few networks are willing to adopt them in view of the deficiency of deployment benefits. Actually, all the source address validation solutions face the problem of a lack of deployability. In this paper, we summarize the key points describing deployability and propose a new security service-inter-autonomous-system (AS) Source Address Protection (iSAP). Technically, by increasing the possibility of keeping the source address belonging to one AS from being the victim of reflection flooding, iSAP improves the deployers ability to prevent IP spoofing and increases incremental deployability. In reality, such a service can also be regarded as a new profit opportunity for ASes and it could progress gradually once it is well commercialized. Based on simulations with real Internet topology data, the results illustrate that iSAP can protect ASes from being reflected with only a few deployers, exhibiting a high potential to mitigate reflection flooding with modest resource consumption. Yihao Jia, Ying Liu 0024, Gang Ren 0003, Lin He 0004 |
IPCCC | 3 |
| 2015 | An inter-AS path vector filter: towards elimination of false negativesabstractIP spoofing based attacks remains a serious and open security problem due to the fact that the current Internet implements no source address authentication mechanisms. A series of anti-spoofing practices have long been proposed while their actual implementation seems far from satisfactory. Route based filters were extensively studied in the design of Inter-AS source address validation methods. Traditional route based filters only use route direction information to establish filtering rules, causing inherited fake negatives. A novel inter-AS filter based on route path vector is proposed to reduce or even eliminate such fake negatives in this article. We name the filter IPVF (Inter-AS Path Vector Filter), which utilizes the route information of both path and distance, exhibits measurable increase in performance and incurs acceptable additional bandwidth cost. Moreover, traditional route based filtering rules is easy to be deduced by attackers. Since the filtering rules of IPVF could change over time by setting parameters, its actual improvement in performance could be exponentially increased. Zhou Zhang 0008, Ying Liu 0024, Gang Ren 0003, Jun Bi |
LANMAN | 4 |
| 2015 | Building an IPv6 address generation and traceback system with NIDTGA in Address Driven Network
Ying Liu 0024, Gang Ren 0003, Shenglin Zhang, Lin He 0004, Yihao Jia |
Sci. China Inf. Sci. | 2 |
| 2008 | Building a next generation Internet with source address validation architecture
Gang Ren 0003, Xing Li 0001 |
Sci. China Ser. F Inf. Sci. | 2 |
| 2007 | Source Address Validation: Architecture and Protocol DesignabstractThe current Internet addressing architecture does not verify the source address of a packet received and forwarded. This causes serious security and accounting problems. Based on the drastically increased IPv6 address space, a "source address validation architecture" (SAVA) is proposed in this paper, which can guarantee that every packet received and forwarded holds an authenticated source IP address. The design goals of the architecture are lightweight, loose coupling, "multi-fence support" and incremental deployment. This paper discusses the details of design and implementation for the architecture, including inter-AS, intra-AS and local subnet. This architecture is deployed into the CNGI-CERNET2 infrastructure -a large-scale native IPv6 backbone network of the China Next Generation Internet project. We believe that the source address validation architecture will help the transition to a new, more secure and sustainable Internet. Gang Ren 0003, Xing Li 0001 |
ICNP | 2 |