VLDB 2026 Research / reviewers in the wild / expert
Meng Yue 0002
dblp:84/10773-2
· DBLP profile ↗
24ranked-venue papers
10as first author
18since 2021 · last 2026
0000-0002-1473-3729ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 4 first-author · 9 since 2021Computer networks · 5 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OCREN: A countermeasure for ADS-B attacks in the context of air traffic controlabstractAutomatic dependent surveillance–broadcast (ADS-B) is a surveillance technology widely endorsed by the International Civil Aviation Organization (ICAO). It has seen extensive use in both commercial and general aviation, playing a vital role in supporting air traffic control (ATC) operations. However, the inherent openness of the ADS-B protocol leaves it vulnerable to malicious network attacks. Previous research has largely overlooked ATC application scenarios in commercial air transportation, and existing detection algorithms suffer from low attack detection rates. Furthermore, current research lacks effective and reliable methods for responding to identified attacks. This paper primarily investigates ADS-B attack detection and recovery within the context of ATC. We integrate flight plans with ADS-B data to create a flight data restriction domain and employ the online classification restriction-extreme learning machine (OCR-ELM) model to detect and flag abnormal data streams. Subsequently, the nonlinear autoregressive neural network (NARX) model, combined with a recovery strategy, is utilized to restore the flagged abnormal data. The proposed method enables precise and rapid identification of abnormal targets in ADS-B data and eases targeted recovery of the affected data points. We employed real flight data to simulate anomalous data caused by various malicious attacks, evaluating detection and recovery performance using several performance metrics. The results show that our method achieves an average detection accuracy of 98.6%, a false positive rate of 1.69%, a false negative rate of 0.93%, and an average structural similarity index of 0.9895 for the recovered data. This method ensures the security of information and continuous accessibility of ADS-B, thus enhancing the operational safety and robustness of air traffic control. Meng Yue 0002, Sunshuo Shi, Zhijun Wu 0001 |
Expert Syst. Appl. | 1 |
| 2026 | Defending PoW Blockchains Against Game-Theoretic DoS Attacks: A Rational Strategy AnalysisabstractGame-theoretic denial-of-service (GDoS) attacks exploit rational miners' incentives to degrade the throughput and security of proof-of-work (PoW) blockchains, even when the attacker controls less than 20% of the total hash power. Existing defenses commonly rely on protocol modifications, which risk hard forks and destabilize the system. This paper presents the first rational, protocol-preserving defense against GDoS attacks. We formalize GDoS by unifying selfish-mining-based and blockchain-based denial-of-service variants under a common definition, and establish its theoretical foundation through a dynamic game model with a subgame perfect Nash equilibrium (SPNE). Unlike prior protocol-level defenses, our strategy maintains consensus integrity without introducing any changes to PoW. We propose a cooperative hash-power hopping mechanism in which miners temporarily reallocate hash power to larger pools when under attack to preserve expected payoffs and suppress attacker incentives. To quantify miner utilities under different strategies, we develop a combined game-theoretic and Markov-chain analytical framework and derive closed-form critical profitability thresholds. Simulations calibrated to real-world Bitcoin hash-power distributions show that the proposed strategy reduces attacker revenue gains by more than 20% and prevents throughput degradation across the entire attack range. These results demonstrate that rational, incentive-compatible cooperation can effectively strengthen PoW blockchains against emerging strategic threats. Zhijun Wu 0001, Zhiquan Liu 0001, Meng Yue 0002, Yanrong Lu |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | SPRLP: Spatial-aware Pathfinding Routing for Aeronautical Ad-Hoc Networks based on Location PredictionabstractThe global aviation industry's swift expansion is nearing the capacity limits of civil aviation communications system, with transoceanic flights being particularly affected. To counter these challenges, we propose the Spatial-aware Pathfinding Routing based on Location Prediction (SPRLP) for aeronautical ad-hoc networks (AANET). SPRLP addresses the unique challenges of AANET, such as vast network space, low node density, node mobility, dynamic topology, and bandwidth constraints. It enhances communication efficiency and reliability by combining packet transmission time with predicted neighbor locations to mitigate transmission interruptions. The routing algorithm incorporates aircraft position predictions, flight paths, and node congestion to establish stable and efficient communication paths within the aviation network. Additionally, an adaptive beacon interval mechanism is introduced to minimize routing overhead. Simulations using OMNeT++ demonstrate that SPRLP significantly outperforms other Mobile Ad-Hoc Network routing protocols in terms of efficiency and reliability. Meng Yue 0002, Baoxu Chen, Zhijun Wu 0001 |
IWCMC | 1 |
| 2025 | Trustworthy Management of Network Resources Based on BlockchainabstractWith the increasing demand for network resource management, traditional centralized management approaches face challenges such as single point of failure, excessive permissions, and privacy breaches when sharing resources across multiple domains. To address these issues, this paper proposes a blockchain-based trustworthy management solution for network resources. The proposed solution ensures data privacy and security through a decentralized blockchain mechanism, while providing fair and transparent resource allocation. The system design encompasses privacy protection, data immutability, authorized access control, as well as fairness and incentive compatibility in resource distribution. Analysis indicates that this solution enables effective and equitable resource management in the face of DDoS attacks, thereby providing an innovative pathway for building a secure and scalable network management system. Meng Yue 0002, Zhijun Wu 0001, Yanrong Lu |
IWCMC | 1 |
| 2025 | Blockchain security threats: A comprehensive classification and impact assessment
Zhijun Wu 0001, Meng Yue 0002, Yanrong Lu |
Comput. Networks | 3 |
| 2025 | TrustCNAV: Certificateless aggregate authentication of civil navigation messages in GNSSabstractThe Global Navigation Satellite System (GNSS) is capable of accurate positioning because it can provide high-precision data. These data are transmitted to the receiver in the form of navigation messages, called civil navigation messages (CNAV). As it is transmitted in an open, transparent environment without data integrity protection mechanisms and secure data transmission measures, the CNAV is suspected to spoofing attacks. In 2023, the OPSGROUP has received approximately 50 reports of GPS spoofing activity. A spoofed plane's navigation system will show it as being in a different place - a security risk if a jet is guided to fly into a hostile country's airspace. To prevent the forging of GNSS positioning data by spoofing attacks targeting CNAV, we propose a certificateless aggregation authentication for CNAV by using the elliptic curve discrete logarithm problem and the combination of the GNAV structural characteristics, called TrustCNAV. Security proof and performance analysis indicate that this authentication scheme can resist spoofing attacks and ensure data security of CNAV, also it avoids pairing operations with high computational complexity, thus meeting security requirements without causing too much time and communication consumption. Zhijun Wu 0001, Liang Liu 0012, Meng Yue 0002 |
Comput. Secur. | 5 |
| 2025 | A DDoS attack detection method based on IQR and DFFCNN in SDN
Meng Yue 0002, Huayang Yan, Rui-Ze Han, Zhijun Wu 0001 |
J. Netw. Comput. Appl. | 1 |
| 2024 | Data Source Authentication Protocol for Aviation Broadband Communication SystemabstractThe Aviation Broadband Communication System (ABCS) plays a crucial role in the modern civil aviation field. However, when controlling the broadcast information of Broadcast Control Channel (BC), the system faces network security issues such as man in the middle attacks and pseudo base station attacks, which have become increasingly serious. Therefore, when designing and developing aviation broadband communication systems, it is necessary to fully consider the guarantee mechanism for ensuring secure data transmission. This article focuses on the BC control channel and successfully implements source authentication for broadcast control data using the Timed Efficient Stream Loss Tolerant Algorithm Protocol (TESLA) combined with the SM3 algorithm. The proposed method effectively solves the security issues faced by broadcast data. By analyzing the security overhead brought by the added security mechanisms, we have proven that this method is superior to packet-by-packet signature authentication protection and hash chain authentication schemes, thus meeting the requirements of aviation digital communication application scenarios. Yongqiang Huang 0005, Zhijun Wu 0001, Meng Yue 0002 |
IWCMC | 4 |
| 2024 | VLDoS: Variable Low-Rate DoS Attack Model for BBR Algorithm in TCP
Meng Yue 0002, Zihan Lai, Zhijun Wu 0001 |
SecureComm (2) | 1 |
| 2024 | A Reliable Encrypted Traffic Classification Method Based on Attention MechanismsabstractIn online encrypted traffic classification, existing machine learning methods face the challenge of manually extracting flow-level statistical features. Deep learning methods encounter complex preprocessing issues, requiring models to balance complexity and accuracy. Therefore, this paper proposes a reliable method for encrypted traffic classification based on attention mechanism. The method designs a neural network model based on the Transformer architecture. The model employs embedding operations to extract byte features and utilizes position encoding to capture spatial features, which enables efficient packet-level classification of encrypted traffic. By using only the first 40 bytes of the packet header as input, the model avoids analyzing the payload, thereby reducing the risk of privacy breaches. Moreover, the simplified input features reduce the time overhead for feature extraction, enhancing training speed and making the model suitable for deployment in high real-time scenarios. This paper validates the proposed method experimentally using two public datasets: ISCX VPN-nonVPN and ISCX Tor-nonTor. The experimental results indicate that the proposed method outperforms existing approaches, achieving an improvement of at least 1.5% in classification accuracy and 1.6% in F1 score. Additionally, with a memory usage of 533 MB, it meets the performance requirements for low-resource scenarios. Zhijun Wu 0001, Shanhe Niu, Meng Yue 0002 |
TrustCom | 3 |
| 2024 | CCS: A Cross-Plane Collaboration Strategy to Defend Against LDoS Attacks in SDNabstractSoftware-Defined Networking (SDN) actualizes the separation of control and forwarding, innovates network functionality with a logically centralized controller, and facilitates network-wide collaboration. Contemporary SDN infrastructure exposes potential bottlenecks which are prone to engaging low-rate denial of service (LDoS) attacks. Currently, a great deal of detection methods are deployed in the controller, and the controller needs to poll the switch frequently, which brings heavy load to the controller and the southbound link. According to the analysis of existing researches, we focused on the how to decrease the frequent polling of the controller and improve the detection rate. In this paper, we adopted the idea of cross-plane collaboration and proposed a two-phase detection framework, which carried out the lightweight detection method in the data plane and the in-depth detection based on Bayesian voting mechanism in the control plane. Once LDoS attacks are detected, the controller recalculates routes for the bottleneck nodes using the optimized Dijkstra algorithm to complete mitigation. Theoretical analyses and extensive experiments are conducted to validate the performance of our proposed method. Test results show that our method outperforms other traditional methods in terms of the detection rate of 99.1%, the detection delay of 1.3s and the communication overhead of 1068 Byte/s, the average CPU utilization of controller remains at approximately 3.5%. The proposed method takes a step forward to enhance the security of SDN. Meng Yue 0002, Qingxin Yan, Zichao Lu, Zhijun Wu 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | GAN-LSTM-Based ADS-B Attack Detection in the Context of Air Traffic ControlabstractAutomatic dependent surveillance–broadcasting (ADS-B) is a surveillance technology strongly promoted by the International Civil Aviation Organization. It has been widely used in commercial and general aviation, to provide support for the normal operation of air traffic control (ATC) in commercial aviation. However, the openness of the ADS-B protocol makes it extremely vulnerable to cyber attacks. Previous research did not specifically consider the application scenarios of ATC in commercial air transport, and there is a problem of low attack detection rates. This article focuses on ADS-B attack detection under the background of ATC. We combine the flight plan with ADS-B information to construct an airspace flight image stream and process the image stream using a generative adversarial network–long short-term memory (GAN-LSTM) model to predict future images. Then, we identify abnormal images based on the normalized cross-correlation and mark anomalous targets. Our method can quickly locate anomalous targets in the controlled airspace. Based on real flight data, abnormal data for various malicious attacks were forged. We evaluated the detection performance of the method through a confusion matrix and several performance indices. The final experimental results showed that our detection scheme exhibited good detection performances for various attacks, with an average detection accuracy of 92.3%, a false positive rate of 11.9%, and a false negative rate of 6.2%. This approach guarantees the information security of ADS-B, thereby improving the operational security of ATC. Meng Yue 0002, Han Zheng 0003, Zhijun Wu 0001 |
IEEE Internet Things J. | 1 |
| 2023 | Consumer-source authentication with conditional anonymity in information-centric networking
Yanrong Lu, Chenzhuo Wang, Meng Yue 0002, Zhijun Wu 0001 |
Inf. Sci. | 3 |
| 2022 | LDoS attack detection method based on traffic classification predictionabstractAbstract Aiming at the low rate and strong concealment of low‐rate Denial of Service (LDoS) attacks, the calculation of traffic Hurst index is combined with traffic classification, and a machine learning LDoS attack detection method based on search sorting is proposed. The method first calculates the segmentation Hurst exponent of each flow, and constructs a traffic similarity matrix as a statistical feature. Then, using the improved model XGBoost of the Gradient Boosting Decision Tree (GBDT), the traffic is classified and predicted. The network angle distinguishes between normal traffic and abnormal Origin‐Destination (OD) flows containing LDoS attacks, thereby achieving the purpose of detecting LDoS attacks. The method in this study was validated using the US public network dataset Abilene. The experimental results show that the global LDoS attack traffic detection method based on the Hurst index and GBDT algorithm achieves better detection results under different attack rates. Liang Liu 0012, Zhijun Wu 0001, Qingbo Pan, Meng Yue 0002 |
IET Inf. Secur. | 5 |
| 2021 | I-CIFA: An improved collusive interest flooding attack in named data networkingabstractNamed Data Network (NDN) as a new network architecture, in recent years become a hot research, its security has been widespread concern. With the continuous updating of distributed denial of service (DDoS) attack methods in NDN networks, this article designs a new type of attack, called the Improved Collusive Flooding Attack (I-CIFA). I-CIFA attack combines the advantages of mainstream DDoS attack in NDN network, and is an attack method generated by low-rate DDoS attack and the cooperation of collusive producer. On the basis of the existing DDoS attack, the I-CIFA attack further improves the ability to destroy the network and the ability to resist the existing defense scheme. I-CIFA is designed on the basis of CIFA by improving the attack nodes and so on. In addition to redefining and configuring the attack parameters, improvements were also made in two aspects. First, the probing mode to probe the pending interest table (PIT) capacity of the routing nodes was added before attack started. Second, the way in which each attacker requests a packet from the collusive producer in each attack cycle has been further improved. Test results show that I-CIFA can cause 87.5% of the legitimate interest packets in the whole network to be discarded, and it is not only has a strong attack range on the network, but it is also difficult to be detected by existing CIFA-countermeasures. Zhijun Wu 0001, Wenzhi Feng, Jin Lei, Meng Yue 0002 |
J. Inf. Secur. Appl. | 4 |
| 2021 | Coherent Detection of Synchronous Low-Rate DoS AttacksabstractLow-rate denial-of-service (LDoS) attacks are characterized by low average rate and periodicity. Under certain conditions, the high concealment of LDoS attacks enables them to transfer the attack stream to the network without being detected at all before the end. In this article, plenty of LDoS attack traffic is spread to the victim end to detect LDoS attacks. Through experimental analysis, it is found that the attack pulses at the victim end have sequence correlation, so the coherence detection technology in spread spectrum communication is proposed to detect LDoS attacks. Therefore, this paper proposes an attack detection method based on coherent detection, which adopts bivariate cyclic convolution algorithm. Similar to the generation of receiving terminal phase dry detection code in spread spectrum communication, we construct a local detection sequence to complete the extraction of LDoS attack stream from the background traffic of the victim terminal, that is, the coherent detection of LDoS attacks. When predicting the features of an LDoS attack, how to construct the parameters of the detection sequence (such as period, pulse duration, amplitude, and so on) is very important. In this paper, we observe the correlation of LDoS attacks and use coherence detection to detect LDoS attacks. By comparing calculated cross-correlation values with designed double threshold rules, the existence of attacks can be determined. The simulation platform and experiments show that this method has high detection performance. Zhijun Wu 0001, Guang Li 0006, Meng Yue 0002 |
Secur. Commun. Networks | 4 |
| 2021 | Low-High Burst: A Double Potency Varying-RTT Based Full-Buffer Shrew Attack ModelabstractThe full-buffer Shrew (FB-Shrew) denial of service (DoS) attack is a variant of the classic Shrew attack that exploits the congestion control mechanism of transmission control protocol (TCP). Here, an attacker sends a high-rate burst of attack packets only after the router buffer is filled with TCP packets, causing the router to drop legitimate packets, and forcing the retransmission of TCP packets. As such, an FB-Shrew attack can cause maximum damage with minimum resources. In this paper, we challenge an assumption of constant round trip time adopted in the original FB-Shrew model. As a result, this model fails to achieve its expected attack effect. In response, we analyze the TCP congestion window and queue behaviors to develop two low-high burst models for maximizing the potency of the FB-Shrew attack. Model 1 is designed to achieve the attack effect expected of the original model. Then, the attack potency of Model 1 is enhanced by simply adjusting the starting time of the attack burst to form Model 2. Mode 1 only exploits the retransmission timeout (RTO) mechanism. Model 2 takes advantage of both the RTO mechanism and the fast retransmission mechanism. In this way, Model 2 further slows down the growth of the congestion window and extends the attack period. A combination of theoretical analyses and simulations are adopted to first validate the proper functioning and effectiveness of the two models for a standard network configuration, and then we assess their attack performances with variations in different network parameters. Our performance assessment demonstrates that one attack unit of Model 2 damages almost twice the number of TCP units as one attack unit of Model 1, which represents an increase in attack potency of nearly 200 percent. The present study provides an expanded basis to explore FB-Shrew attack patterns that may be utilized by attackers. Moreover, the damage that could be inflicted by such attack and the extent to which defense strategies are capable of mitigating the attack's impact could be assessed more precisely by defenders. Meng Yue 0002, Minxiao Wang, Zhijun Wu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | High-Potency Models of LDoS Attack Against CUBIC + REDabstractA TCP-targeted low-rate denial of service (LDoS) attack exploits the vulnerabilities of TCP congestion control mechanism. The most widely used TCP congestion control algorithm, CUBIC, increases the resilience to LDoS. This paper explores high-potency patterns of LDoS attacks against CUBIC TCP under the RED queue management scenario, and develops two attack models, the D- and S-models to maximize attack potency (i.e., the damage-to-cost ratio). Theoretical analyses and extensive experiments are conducted to validate the proper function of the models and evaluate their performance. Test results show that the models can effectively throttle CUBIC TCP throughput. Under standard-configured network parameters, one attack unit can damage up to about 21 and 26 TCP units for the D- and S-models, respectively, which represents an increase in attack potency about 20%. The attack potencies of our proposed models are at least 250% greater than that of the traditional attack model. In addition, with variations in different network parameters, these two models are still efficient and alternatively maximize the attack potency. Finally, attack countermeasures are outlined. The present study offers a basis to explore new attack manners which may be exploited by attackers and inspires researchers to develop new measurements against such attack. Meng Yue 0002, Jing Li 0103, Zhijun Wu 0001, Minxiao Wang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Mitigation measures of collusive interest flooding attacks in named data networking
Zhijun Wu 0001, Wenzhi Feng, Meng Yue 0002, Xinran Xu, Liang Liu 0012 |
Comput. Secur. | 3 |
| 2019 | A secret classified label control model based on the identity-based cryptographyabstractAiming at the defects of complex certificate management and high waste of resources in the traditional secure electronic file label management system, a secret classified label (SCL) control model was established based on the identity-based cryptography (IBC). In the secure controlling model of SCL, the digital signature method and the hierarchical access method of electronic documents based on the identity-based cryptography are used to digitally sign the confidential labels and encrypt the confidential documents respectively. Through the modeling of confidential clients, file servers, and key generation centers, the irreproachability of file-level identification and the hierarchical access to files are achieved. Finally, the feasibility, practicability and security of the model are verified by testing the system performance and analyzing the system security. Zhijun Wu 0001, Shan Tian, Meng Yue 0002 |
IWCMC | 4 |
| 2019 | Sequence alignment detection of TCP-targeted synchronous low-rate DoS attacks
Zhijun Wu 0001, Qingbo Pan, Meng Yue 0002, Liang Liu 0012 |
Comput. Networks | 3 |
| 2019 | Detecting LDoS attack bursts based on queue distributionabstractLow‐rate denial of service (LDoS) attacks exploit the congestion control mechanism to degrade the network quality of service. As a classic active queue management algorithm, random early detection (RED) algorithm is widely used to avoid network congestion. However, RED is vulnerable to LDoS attacks. LDoS attacks with well‐configured attack parameters force RED queue to fluctuate severely, thereby throttling transmission control protocol (TCP) senders’ sending rate. A feedback control model is proposed to describe the process of the congestion control, by which the congestion window and queue behaviours are analysed combined. After that, a two‐dimensional queue distribution model composed of the instantaneous queue and the average queue is designed to extract the attack feature. Moreover then, a combination of a simple distance‐based approach and an adaptive threshold algorithm is proposed to detect every LDoS attack burst. Test results of network simulator (NS)‐2 simulation and test‐bed experiments indicate that the proposed detection strategy can almost completely detect LDoS attack bursts and is especially robust to legitimate short bursts. Meng Yue 0002, Zhijun Wu 0001 |
IET Inf. Secur. | 1 |
| 2016 | Low-Rate DoS Attacks Detection Based on Network MultifractalabstractLow-rate denial of service (LDoS) attacks send periodic pulse sequences with relative low rate to form aggregation flows at the victim end. LDoS attack flows have the characteristics of low average rate and great concealment. It is hard to detect LDoS attack flows from normal traffic due to low rate property. Network traffic measurement shows that aggregate network traffic is multifractal. In order to characterize and analyze network traffic, researchers have developed concise mathematical models to explore complex multifractal structure. Although the LDoS attack flows are very small, it will inevitably lead to the change of multifractal characteristics of network traffic. This paper targets at exploiting and estimating the changes in multifractal characteristics of network traffic for detecting LDoS attack flows. The algorithm of multifractal detrended fluctuation analysis (MF-DFA) is used to explore the change in terms of multifractal characteristics over a small scale of network traffic due to LDoS attacks. Through wavelet analysis, the singularity and bursty of network traffic under LDoS attacks are estimated by using Hölder exponent. The difference values (D-value) of Hölder exponent of network traffic between normal and under LDoS attack situations are calculated. The D-value is used as the basis to determine LDoS attacks. A detection threshold is set based on the statistical results. The presence of LDoS attacks can be confirmed through comparing D-value with detection threshold. Experiments on detection performance have been performed in the test-bed network and simulation platform. The extensive experimental results are congruent with the theoretical analysis. Zhijun Wu 0001, Liyuan Zhang 0009, Meng Yue 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2012 | Research on Time Synchronization and Flow Aggregation in LDDoS Attack Based on Cross-correlationabstractThis paper addresses time synchronization and flow aggregation in Low-rate Distributed Denial of Service (LDDoS) attack, which is formed by a number of well-organized LDoS attack. A cross-correlation algorithm is proposed to ensure that each distributed attack pulse is aggregated and synchronous accurately to form a powerful pulse at the victim end. Simulation results show that the LDDoS attack effects can be improved significantly by using cross-correlation algorithm to coordinate attack pulses. Zhijun Wu 0001, Meng Yue 0002 |
TrustCom | 4 |