VLDB 2026 Research / reviewers in the wild / expert
Kai Wang 0014
dblp:78/2022-14
· DBLP profile ↗
29ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0003-3044-9047ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hierarchical GNN Message Passing for Node-Level Anomaly Detection in Industrial Control SystemsabstractAdvances in Graph Neural Networks (GNNs) have prompted remarkable progress in anomaly detection for securing the Industrial Control Systems (ICSs). As the core functioning block of a GNN network, message passing in most of the current frameworks is conducted via local aggregation, in which a node's vector representation is updated with messages from its directly connected neighbours. However, despite its efficiency over numerous application scenarios, such neighbouring aggregation mechanism tends to be highly biased towards a node's locality, and hence may not accurately profile the hierarchical semantics in layered ICS architectures, such as the supervisory relations among controllers and field devices. The resulting node embeddings, in this case, may not be knowledgeable enough to instruct downstream tasks such as fine-grained device-wise ICS anomaly detection. To address this issue, we introduce the Hierarchical Message Analyzer (the HMA), a new message passing scheme that explores a network's supervisory structural features and regulates a message's transmission paths to create balanced embeddings for node-level ICS anomaly detection. This model comprises in its architecture a Preprocessor that condenses the original data flow into initial node vectors, an Adjacency Parser that regulates how messages are transmitted in the aggregation process, an Encoder performing message passing in compliance with the adjacency info obtained from the Adjacency Parser, and a Decoder for label inference. We assess the HMA's performance over multiple evaluation metrics and compare it against various state-of-the-art baselines. Results on multiple datasets certify the HMA's validity and superiority in device-wise ICS anomaly detection. Shuaiyi Lyu, Kai Wang 0014, Bailing Wang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | StatGraph: Effective In-Vehicle Intrusion Detection via Multi-View Statistical Graph LearningabstractIn-vehicle networks (IVNs) face growing threats from advanced cyber-attacks, particularly stealthy masquerade attacks that mimic legitimate message patterns. This paper proposes STATGRAPH, a fine-grained intrusion detection frame work based on multi-view statistical graph learning over the Controller Area Network (CAN) messages within IVNs. STAT GRAPH constructs two graphs per detection window: a Timing Correlation Graph (TCG) capturing temporal ID dependencies, and a Coupling Relationship Graph (CRG) modeling short term contextual relations. TCG and CRG are further used to generate graph structure encoding payload variations and embedded signal co-occurrence. A lightweight multi-layered Graph Convolutional Network (GCN) is then applied to classify each message, leveraging the expressive representations from TCG and CRG. To ensure effectiveness against diverse attacks, we evaluate STATGRAPH on two real-world CAN datasets featuring five underexplored masquerade attacks. Experimental results show that STATGRAPH significantly improves detection granularity and outperforms state-of-the-art methods, with F1-score gains of 7% and 22%, while maintaining the highest accuracy. Code is available at https://github.com/wangkai-tech23/StatGraph Kai Wang 0014, Qiguang Jiang, Bailing Wang, Yulei Wu, Hongke Zhang |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | An original model for multi-target learning of logical rules for knowledge graph reasoning
Bailing Wang, Kai Wang 0014, Rui Zhang 0050, Yuliang Wei |
Appl. Intell. | 3 |
| 2025 | KDRSFL: A knowledge distillation resistance transfer framework for defending model inversion attacks in split federated learning
Renlong Chen, Hui Xia 0001, Kai Wang 0014, Rui Zhang 0050 |
Future Gener. Comput. Syst. | 3 |
| 2025 | Anomaly Detection via Semantically Conjugate View Learning on Industrial Temporal DataabstractAnomaly detection based on knowledge discovery from the industrial temporal data via Graph Neural Networks (GNNs) has been extensively prevailing over the past decade. So far, massive contributions have been made in deriving superior anomaly detection solutions by leveraging the sophisticated associativity among nodes in a graph topology. While this node-oriented fashion is at its fancy, the idea of utilizing a graph’s edges in anomaly detection tends to be equivalently significant, in that the edges are the other core component that construct a graph and are, more essentially, rich in convoluted correlational properties. As current methods seldom take these edge-level correlations into account, we aim at constructing a dual-channel graph learning scheme attempting to adequately utilize these edge-level contextual semantics in anomalous pattern detection. In specific, we design and develop the Node-Edge Conjugate Network (NECN), a GNN-based solution that conducts device-wise anomaly detection leveraging not only the complex associativity among the nodes but also the sophisticated correlations among the edges via knowledge discovery from the industrial temporal data. With the in-depth contextual features of the nodes and edges profiled in their respective channel, the resulting embeddings are a more appropriate reflection of the graph’s topological properties in terms of both nodes and edges, and hence serve as a more solid basis for subsequent anomaly detection. The NECN’s effectiveness in achieving a superior anomaly detection accuracy is demonstrated in a comprehensive comparative analysis with multiple state-of-the-art baselines over 3 popular datasets specifically developed for the study of ICS security. Kai Wang 0014, Shuaiyi Lyu, Bailing Wang |
IEEE Internet Things J. | 1 |
| 2025 | KERMIT: Knowledge graph completion of enhanced relation modeling with inverse transformation
Bin Yu 0019, Yuliang Wei, Kai Wang 0014, Bailing Wang |
Knowl. Based Syst. | 4 |
| 2025 | XIPHOS: Adaptive In-Vehicle Intrusion Detection via Unsupervised Graph Contrastive Learning
Qiguang Jiang, Kai Wang 0014, Yuliang Wei, Hongri Liu, Bailing Wang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | LiPar: A Lightweight Parallel Learning Model for Practical In-Vehicle Network Intrusion DetectionabstractWith the development of intelligent transportation systems, vehicles are exposed to a complex network environment. As the mainstream in-vehicle network (IVN), the controller area network (CAN) has many potential security hazards. Existing deep learning-based intrusion detection methods have security performance advantages, however, they consume too much resources and are therefore not suitable to be directly implemented into the IVN. In this paper, we explore computational resource allocation schemes in the IVNs and propose the LiPar, which is a parallel neural network structure using lightweight multi-dimensional spatial and temporal feature fusion learning to perform intrusion detection tasks in the resource-constrained in-vehicle environment. In particular, LiPar adaptively allocates task loads to in-vehicle computing devices, such as multiple electronic control units, domain controllers, and computing gateways by evaluating whether a computing device is suitable to undertake the branch computing tasks according to its real-time resource occupancy. Experiment results show that LiPar achieves better detection performance, running efficiency, and optimized lightweight model size over existing methods, and can be well adapted to the resource-constrained in-vehicle environment and practically protect the in-vehicle CAN bus security. Code is available athttps://github.com/wangkai-tech23/LiPar Aiheng Zhang, Qiguang Jiang, Kai Wang 0014, Ming Li 0042, Bailing Wang |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | DRL-Based Time-Varying Workload Scheduling With Priority and Resource AwarenessabstractWith the proliferation of cloud services and the continuous growth in enterprises’ demand for dynamic multi-dimensional resources, the implementation of effective strategy for time-varying workload scheduling has become increasingly significant. In this paper, we propose a deep reinforcement learning (DRL)-based method for time-varying workload scheduling, aiming to allocate resources efficiently across servers in the cluster. Specifically, we integrate a classifier and queue scorer to construct a priority queue that exploits temporal resource utilization patterns across different workload classes. Then, we design parallel graph attention layers to capture the dimensional features and temporal dynamics of cloud server cluster. Moreover, we propose a DRL algorithm to generate scheduling strategies that can adapt to dynamic environments. Validation on real-world traces from Google cluster demonstrates that our method outperforms existing approaches in key metrics of cloud server cluster management. Qilin Fan, Xu Zhang 0006, Xiuhua Li 0001, Kai Wang 0014, Qingyu Xiong |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | Optimizing Consistency in Distributed Data Services: The CP-Raft Protocol for High-Performance and Fault-Tolerant ReplicationabstractThe data consistency protocol is a core component of distributed data services that provide fault-tolerance and data consistency across distributed data centers and even edge networks. Raft is a popular approach due to its ease of implementation and superior performance. However, Raft adopts a sequential log entry processing strategy, where log entries without dependencies are not allowed to be processed in parallel, limiting system performance in high-concurrency scenarios. To address this challenge, researchers propose Raft-based protocols that supportout-of-orderapply(OOApply), which is called OORaft. Existing OORaft protocols adopt the Paxos-style election and replication process to merge missing entries on leader candidates. It leads to problems such as extra overhead on dependency analysis, availability when the network is partitioned, and incomplete correctness verification. This paper proposes aconciseparalleledRaftprotocol called CP-Raft, which is the first OORaft protocol to focus on dependency analysis overhead and to use full TLA$^+$validation for the leader election process. Specifically, 1) CP-Raft proposes a Raft-aligned three-step election method that significantly simplifies the difficulty of understanding and solves the availability problem when the network is partitioned. 2) CP-Raft applies a leader-side bitmap-based dependency analysis and representation method to break through the performance bottleneck caused by the high overhead of dependency analysis. 3) CP-Raft discusses why existing methods cannot achieve OORaft correctness verification using TLA$^+$in a limited time and uses phased verification methods to ensure its correctness. Finally, we implement CP-Raft based on an open-source Raft protocol and discuss its potential performance bottlenecks in various scenarios. The experimental results under high dependency strength workloads demonstrate that CP-Raft achieves 1.5× transaction per second (TPS) performance of DP-Raft and 2× of ParallelRaft-CE. It also provides better availability than state-of-the-art OORaft protocols. Haiwen Du, Kai Wang 0014, Yulei Wu, Hongke Zhang |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | Power Allocation and Client Selection For Privacy-Preserving Federated Learning in IoMTabstractIn recent years, the Internet of Medical Things (IoMT) has significantly boosted the healthcare industry. In the IoMT, federated learning (FL) can be applied, which can increase the utilization of patient data while protecting patient privacy. This work proposes a cutting-edge framework that combines differential privacy (DP) with FL and utilizes game theory to optimize power allocation and client selection in IoMT environments. Utilizing a Stackelberg game model, we orchestrate power allocation strategies among IoMT devices to enhance communication efficiency while meeting stringent privacy standards. We propose non-uniform and uniform pricing strategies based on the availability of network state information. Then, we derive the optimal interference price and power for the IoMT devices using nonlinear programming and convex optimization. In addition, our approach integrates DP to protect patients’ data, carefully balancing between privacy and the accuracy of the learning model. The conducted simulations show that our proposed method is effective in terms of communication efficiency, privacy preservation and FL performance. Zheng Chang 0001, Kai Wang 0014, Geyong Min |
GLOBECOM | 3 |
| 2024 | Multi-agent DRL for edge computing: A real-time proportional compute offloading
Kunkun Jia, Hui Xia 0001, Rui Zhang 0050, Kai Wang 0014 |
Comput. Networks | 5 |
| 2024 | Energy-Efficient and Privacy-Preserved Incentive Mechanism for Mobile Edge Computing-Assisted Federated Learning in Healthcare SystemabstractRecent advancements in the Internet of Medical Things (IoMT) have significantly influenced the development of smart healthcare systems. Mobile edge computing (MEC)-assisted federated learning (FL) has emerged as a promising technology for providing fast, efficient, and reliable healthcare services while ensuring patient privacy. However, concerns about the privacy and security of sensitive information often make patients hesitant to share their data. Moreover, MEC servers face challenges accessing the necessary radio resources for data transmission. To address these issues, designing an effective incentive mechanism that encourages healthcare user participation in FL and facilitates resource provision from the base station (BS) is vital. This work proposes an efficient and privacy-preserving incentive scheme that considers the interaction among the BS, MEC servers, and MEC users in the MEC-assisted FL healthcare system. Utilizing the Stackelberg game model, we investigate the allocation of transmit power, determination of differential privacy (DP) budgets for MEC users, reward strategies, radio resource demands for MEC servers, and pricing for radio resources at the BS. Furthermore, we analyze the Stackelberg equilibrium and empirically validate the effectiveness of our proposed scheme using a real-world medical dataset. Zheng Chang 0001, Kai Wang 0014, Timo Hämäläinen 0002 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Process-Oriented heterogeneous graph learning in GNN-Based ICS anomalous pattern recognitionabstractOver the past few years, massive penetrations targeting an Industrial Control System (ICS) network intend to compromise its core industrial processes. So far, numerous advanced methods have been proposed to detect anomalous patterns in the numeric data streams with respect to the heterogeneous field devices involved in the industrial processes. These methods, despite reporting decent results, usually conduct system-wise detection instead of fine-grained anomalous pattern recognition at the device level. Furthermore, lacking explicit consideration of the exclusive process-related features with respect to each differentiated device, the fitness of their application in specified industrial processes is undermined. To tackle these issues, a GNN-based Attributed Heterogeneous Graph Analyzer (the AHGA) is designed to perform device-wise anomalous pattern detection via in-depth process-oriented associativity learning. The AHGA’s framework is constructed with four building blocks : a graph processor, a feature analyzer, a link inference decoder, and an anomaly detector . Its performance is assessed and compared against multiple link inference and anomaly detection baselines over 2 popular ICS datasets (SWaT and WADI). Comparative results demonstrate the AHGA’s reliability in capturing sophisticated process-oriented relations among heterogeneous devices as well as its effectiveness in boosting the performance of anomalous pattern recognition at device-level granularity . Shuaiyi L(y)u, Kai Wang 0014, Liren Zhang, Bailing Wang |
Pattern Recognit. | 2 |
| 2023 | GNN-based Advanced Feature Integration for ICS Anomaly DetectionabstractRecent adversaries targeting the Industrial Control Systems (ICSs) have started exploiting their sophisticated inherent contextual semantics such as the data associativity among heterogeneous field devices. In light of the subtlety rendered in these semantics, anomalies triggered by such interactions tend to be extremely covert, hence giving rise to extensive challenges in their detection. Driven by the critical demands of securing ICS processes, a Graph-Neural-Network (GNN) based method is presented to tackle these subtle hostilities by leveraging an ICS’s advanced contextual features refined from a universal perspective, rather than exclusively following GNN’s conventional local aggregation paradigm. Specifically, we design and implement the Graph Sample-and-Integrate Network (GSIN), a general chained framework performing node-level anomaly detection via advanced feature integration, which combines a node’s local awareness with the graph’s prominent global properties extracted via process-oriented pooling. The proposed GSIN is evaluated on multiple well-known datasets with different kinds of integration configurations, and results demonstrate its superiority consistently on not only anomaly detection performance (e.g., F1 score and AUPRC) but also runtime efficiency over recent representative baselines. Shuaiyi L(y)u, Kai Wang 0014, Yuliang Wei, Hongri Liu, Qilin Fan, Bailing Wang |
ACM Trans. Intell. Syst. Technol. | 2 |
| 2023 | Analysis of Recent Deep-Learning-Based Intrusion Detection Methods for In-Vehicle NetworkabstractThe development and popularity of vehicle-to-everything communication have caused more risks to the in-vehicle networks security. As a result, an increasing number of various and effective intrusion detection methods appear to guarantee the security of in-vehicle networks, especially deep-learning-based methods. Nevertheless, the state-of-the-art deep-learning-based intrusion detection methods lack a quantitative and fair horizontal performance comparison analysis. Also, they have no comparative analysis of the detection capability for the unknown attacks as well as on the time and hardware resource consumption of their intelligent intrusion detection models. Therefore, this paper investigates ten representative advanced deep-learning-based intrusion detection methods and illustrates the characteristics and advantages of each method. Moreover, quantitative and fair experiments are set to make horizontal comparison analyses. Also, this study provides some significant suggestions on baseline method selection and valuable guidance, for the direction of future research about lightweight models and the ability to detect unknown attacks. Kai Wang 0014, Aiheng Zhang, Bailing Wang |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | Global-local integration for GNN-based anomalous device state detection in industrial control systems
Shuaiyi L(y)u, Kai Wang 0014, Liren Zhang, Bailing Wang |
Expert Syst. Appl. | 2 |
| 2022 | Heterogeneous graph neural network for attribute completion
Kai Wang 0014, Yanwei Yu, Chao Huang 0001, Zhongying Zhao 0001, Junyu Dong |
Knowl. Based Syst. | 1 |
| 2021 | PA-Cache: Evolving Learning-Based Popularity- Aware Content Caching in Edge NetworksabstractAs ubiquitous and personalized services are growing boomingly, an increasingly large amount of traffic is generated over the network by massive mobile devices. As a result, content caching is gradually extending to network edges to provide low-latency services, improve quality of service, and reduce redundant data traffic. Compared to the conventional content delivery networks, caches in edge networks with smaller sizes usually have to accommodate more bursty requests. In this article, we propose an evolving learning-based content caching policy, named PA-Cache in edge networks. It adaptively learns time-varying content popularity and determines which contents should be replaced when the cache is full. Unlike conventional deep neural networks (DNNs), which learn a fine-tuned but possibly outdated or biased prediction model using the entire training dataset with high computational complexity, PA-Cache weighs a large set of content features and trains the multi-layer recurrent neural network from shallow to deeper when more requests arrive over time. We extensively evaluate the performance of our proposed PA-Cache on real-world traces from a large online video-on-demand service provider. The results show that PA-Cache outperforms existing popular caching algorithms and approximates the optimal algorithm with only a 3.8% performance gap when the cache percentage is 1.0%. PA-Cache also significantly reduces the computational cost compared to conventional DNN-based approaches. Qilin Fan, Xiuhua Li 0001, Jian Li 0008, Qiang He 0001, Kai Wang 0014, Junhao Wen 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2020 | InterestFence: Simple but efficient way to counter interest flooding attack
Jiaqing Dong, Kai Wang 0014, Wei Quan 0001 |
Comput. Secur. | 2 |
| 2020 | Shape-optimizing mesh warping method for stereoscopic panorama stitching
Weiqing Yan, Guanghui Yue 0001, Yanwei Yu, Kai Wang 0014, Chang Tang, Xiangrong Tong |
Inf. Sci. | 5 |
| 2020 | An Edge IDS Based on Biological Immune Principles for Dynamic Threat DetectionabstractEdge computing solves such questions as the massive multisource data and resource consuming computing tasks in edge devices. Some new security problems especially the data security and privacy issues have been introduced into the edge computing scenario. Through analyzing the biological immune principles, a novel idea for the problem of intrusion detection in edge computing is provided. Specifically, an edge intrusion detection system (Edge IDS) with a distributed structure, which has the characteristics of an imprecise model, self-learning, and strong interactivity, is constructed in a systematic way inspired by the biological immune principles. Moreover, a newly proposed gene immune detection algorithm (GIDA) is designed. In order that Edge IDS can deal with the dynamic data problem efficiently, the key functional components such as the remaining gene, niching strategy, and extracting vaccine are embedded into the GIDA algorithm. Furthermore, extensive simulation experiments are conducted, and the results show that the proposed Edge IDS can be adapted to the domain of edge computing with comparative performance advantages. Yajing Zhang 0002, Kai Wang 0014 |
Wirel. Commun. Mob. Comput. | 3 |
| 2019 | Graph structure and statistical properties of Ethereum transaction relationships
Dongchao Guo, Jiaqing Dong, Kai Wang 0014 |
Inf. Sci. | 3 |
| 2019 | Betweenness Centrality Based Software Defined Routing: Observation from Practical Internet DatasetsabstractSoftware-defined networking (SDN) enables routing control to program in the logically centralized controllers. It is expected to improve the routing efficiency even in highly dynamic situations. In this article, we make an in-depth observation of practical Internet datasets and investigate the relationship between betweenness centrality and network throughput . Furthermore, we propose a new routing observation factor, differential ratio of betweenness centrality (DRBC), to denote the varying amplitude of betweenness centrality to node degree. We reveal an interesting phenomenon that DRBC is proportional to the routing efficiency when the maximum betweenness centrality varies in a small range. Based on this, a DRBC-based routing scheme is proposed to improve routing efficiency. The experimental results verify that DRBC-based routing can improve the network throughput and accelerate the routing optimization. Kai Wang 0014, Wei Quan 0001, Nan Cheng 0001, Mingyuan Liu 0001, H. Anthony Chan |
ACM Trans. Internet Techn. | 1 |
| 2018 | InterestFence: Countering Interest Flooding Attacks by Using Hash-Based Security Labels
Jiaqing Dong, Kai Wang 0014, Yongqiang Lyu 0001, Libo Jiao |
ICA3PP (4) | 2 |
| 2018 | Software-Defined Collaborative Offloading for Heterogeneous Vehicular NetworksabstractVehicle‐assisted data offloading is envisioned to significantly alleviate the problem of explosive growth of mobile data traffic. However, due to the high mobility of vehicles and the frequent disruption of communication links, it is very challenging to efficiently optimize collaborative offloading from a group of vehicles. In this paper, we leverage the concept of Software‐Defined Networking (SDN) and propose a software‐defined collaborative offloading (SDCO) solution for heterogeneous vehicular networks. In particular, SDCO can efficiently manage the offloading nodes and paths based on a centralized offloading controller. The offloading controller is equipped with two specific functions: the hybrid awareness path collaboration (HPC) and the graph‐based source collaboration (GSC). HPC is in charge of selecting the suitable paths based on the round‐trip time, packet loss rate, and path bandwidth, while GSC optimizes the offloading nodes according to the minimum vertex cover for effective offloading. Simulation results are provided to demonstrate that SDCO can achieve better offloading efficiency compared to the state‐of‐the‐art solutions. Wei Quan 0001, Kai Wang 0014, Yana Liu, Nan Cheng 0001, Hongke Zhang, Xuemin Shen |
Wirel. Commun. Mob. Comput. | 2 |
| 2017 | Operators of preference composition for CP-nets
Xuejiao Sun, Jinglei Liu, Kai Wang 0014 |
Expert Syst. Appl. | 3 |
| 2014 | Detecting and mitigating interest flooding attacks in content-centric networkabstractThe original architecture of content-centric network CCN may suffer from interest flooding attacks. In this paper, we focus on one type of interest flooding attacks called denial of service against content source DACS attack. To damage CCN, it floods a large number of malicious interests requesting content that does not exist, which guarantees that no cache hit can occur at routers until these malicious interests reach the target content source. Thus, it can directly exhaust the resource of the victim. To counter it, we propose a threshold-based detecting and mitigating TDM scheme. The basic idea is to detect DACS attack on the basis of the frequency that pending interest table items in CCN routers expire recording this frequency by introducing two counters with their corresponding thresholds and one indicator for counter mode and to mitigate it by implementing the rate limiter in each router. From the viewpoint of a CCN router, we analyze the performance of TDM in terms of detection ability and effect on mitigating malicious traffic. In addition, we briefly analyze the overhead of TDM. The results show that TDM achieves high detection ability and good effect on mitigating malicious traffic while bringing in small overhead on countering DACS attack. To the best of our knowledge, this is the first attempt to design a detailed scheme embedded with corresponding algorithms on countering this attack. Copyright © 2013 John Wiley & Sons, Ltd. Kai Wang 0014, Huachun Zhou, Hongbin Luo, Jianfeng Guan, Yajuan Qin, Hongke Zhang |
Secur. Commun. Networks | 1 |
| 2014 | Cooperative-Filter: countering Interest flooding attacks in named data networking
Kai Wang 0014, Huachun Zhou, Yajuan Qin, Hongke Zhang |
Soft Comput. | 1 |