VLDB 2026 Research / reviewers in the wild / expert
Lei Zhang 0157
dblp:97/8704-157
· DBLP profile ↗
11ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-7991-2915ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 7 since 2021Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Toward Efficient LLM Agents for Emulator-Based Network Experiment AutomationabstractAgent-driven scientific experimentation is emerging across domains such as chemistry, biology, and materials, yet each tool class imposes its own execution discipline. Network experimentation requires more than one-shot topology or configuration synthesis: an experimenter must plan a task, operate a live and evolving network, interpret feedback, refine intermediate state, and validate the resulting behavior. This poster presents a Network Experimentation Harness for emulator-backed network experiments, helping LLM agents operate across these stateful workflows. The Harness pairs a semantic action interface with reusable experimentation skills to handle sequencing, timing, and verification that a careful experimenter would perform by hand. A preliminary study on GNS3-based network protocol experiments shows that this approach reduces wall-clock time by 47% and 37%, and token use by 81% and 76%, on average versus raw GNS3 access and a Python wrapper (GNS3Fy), respectively. Chenguang Du, Chang Liu 0021, Lei Zhang 0157, Yong Cui 0001 |
APNet | 3 |
| 2026 | MalMoE: Mixture-of-Experts Enhanced Encrypted Malicious Traffic Detection Under Graph Drift
Yunpeng Tan, Qingyang Li 0010, Mingxin Yang, Yannan Hu, Lei Zhang 0157, Xinggong Zhang |
INFOCOM | 5 |
| 2026 | NetRadar: Enabling Robust Carpet Bombing DDoS Detection
Junchen Pan, Lei Zhang 0157, Xiaoyong Si, Xinggong Zhang, Yong Cui 0001 |
NDSS | 2 |
| 2025 | FlowSentry: Accelerating NetFlow-based DDoS DetectionabstractDistributed Denial of Service (DDoS) attacks threaten the stability of online services by overwhelming them with excessive traffic. NetFlow-based DDoS detection systems are widely adopted by Internet Service Providers (ISPs) in upstream multi-point detection scenarios to provide robust detection for volumetric DDoS attacks. However, these systems face inherent delays, as NetFlow detection is non-instantaneous—routers aggregate and summarize flow records over a period before reporting, which impacts timely detection. Existing research primarily focuses on optimizing the NetFlow reporting mechanism at the router side. Unfortunately, the need for either software or hardware upgrades for routers would incur a high deployment cost, which is impractical for ISPs in the short term. In this paper, we propose FlowSentry, a novel NetFlow detection framework to accelerate DDoS attack identification at the server side. The system operates on a dual-layer filtering paradigm to handle the high-frequency NetFlow records, incorporating two core technologies: ADWindow and STAnalyzer. ADWindow is a sketch-based sliding window mechanism designed to retain possibly anomalous flow information, filtering out benign flows to reduce the computational overhead. STAnalyzer leverages the cross-router traffic correlation to efficiently infer abnormal growth patterns of potential malicious traffic based on partially reported flow records, thus significantly reducing the detection delay. Our extensive experiments in simulated backbone network environments demonstrate that FlowSentry achieves better detection accuracy while reducing the detection delay by up to 65.63% compared to existing methods. Xiaohui Xie, Xin Wang 0001, Lei Zhang 0157, Kun Xie 0001, Yong Cui 0001 |
CCS | 4 |
| 2025 | BCT: Modeling Block Completion Time for Transport ProtocolsabstractMany applications based on block transmission have strict latency requirements. Existing solutions to reduce latency primarily focus on enhancing packet loss resistance through redundancy and scheduling transmission orders. However, the performance of these algorithms depends on accurate block transmission time estimation. Current evaluation methods, which do not account for the impacts of complex network protocols and packet loss, result in significant estimation errors.In this paper, we propose Block Completion Time (BCT) as a transmission delay index for block-based applications. We develop a BCT distribution model that incorporates packet-level block transmission under complex protocols and apply it to predict BCT for typical TCP and QUIC protocols. As a use case, we demonstrate how our model can assist in optimizing redundancy configurations. The model is evaluated under varying network conditions, application types, and transport protocols, showing improved accuracy in predicting both the mean and distribution of BCT compared to baseline methods. Gang Yi, Lei Zhang 0157, Yong Cui 0001 |
IWQoS | 2 |
| 2025 | PLAA: Packet-level Adversarial Attacks in Network Traffic DetectionabstractDeep neural networks (DNNs) are widely applied in Network-based Intrusion Detection System (NIDS) due to their high accuracy. However, DNNs are highly susceptible to adversarial attacks, which generate malicious traffic to evade NIDS detection. Existing approaches often adapt adversarial attacks from computer vision (CV) tasks to the NIDS domain, overlooking the fundamental differences between CV and NIDS. This results in two major issues: 1) The generated network traffic may become invalid, 2) The generated traffic may lose its original attack semantics. To address these issues, this paper proposes an adversarial attack specifically designed for NIDS. Instead of directly generating flow-level features, our approach incrementally generates packet-level features to construct adversarial traffic. During the generation process, the semantic integrity of the traffic is monitored at each stage, effectively avoiding the issues of invalid traffic and semantic loss observed in existing methods. We evaluate our attack algorithm against current NIDS models using the CIC-UNSW-NB15, CIC-DDoS2019, and CIC-IDS-2017 datasets. The proposed method achieves an average evasion success rate of 92.78%, while ensuring that the generated adversarial traffic remains semantically consistent with the original malicious traffic. Jinhao You, Zan Zhou 0001, Yi Sun 0006, Lei Zhang 0157, Changqiao Xu |
TrustCom | 5 |
| 2024 | ShieldGPT: An LLM-based Framework for DDoS MitigationabstractThe constantly evolving Distributed Denial of Service (DDoS) attacks pose a significant threat to the cyber realm, which underscores the importance of DDoS mitigation as a pivotal area of research. While existing AI-driven approaches, including deep neural networks, show promise in detecting DDoS attacks, their inability to elucidate prediction rationales and provide actionable mitigation measures limits their practical utility. The advent of large language models (LLMs) offers a novel avenue to overcome these limitations. In this work, we introduce ShieldGPT, a comprehensive DDoS mitigation framework that harnesses the power of LLMs. ShieldGPT comprises four components: attack detection, traffic representation, domain-knowledge injection and role representation. To bridge the gap between the natural language processing capabilities of LLMs and the intricacies of network traffic, we develop a representation scheme that captures both global and local traffic features. Furthermore, we explore prompt engineering specific to the network domain and design two prompt templates that leverage LLMs to produce traffic-specific, comprehensible explanations and mitigation instructions. Our preliminary experiments and case studies validate the effectiveness and applicability of ShieldGPT, demonstrating its potential to enhance DDoS mitigation efforts with nuanced insights and tailored strategies. Tongze Wang, Xiaohui Xie, Lei Zhang 0157, Chuyi Wang, Yong Cui 0001 |
APNet | 3 |
| 2024 | NetSentry: Scalable Volumetric DDoS Detection with Programmable SwitchesabstractDistributed Denial of Service (DDoS) attack is a critical and persistent threat to the Internet. Recent DDoS detection schemes based on emerging programmable switches can achieve higher processing throughput and improve detection accuracy. However, with limited data plane memory, such schemes are not suitable for handling a large number of concurrent flows. Prior arts that attempt to increase memory efficiency have failed to do so without the expense of cost and accuracy. In this paper, we propose NetSentry, the first programmable switch based dynamic pooled testing DDoS detector. NetSentry detects DDoS in a pooled testing manner, where multiple flows are grouped to share the same storage unit on the data plane. NetSentry designs an elastic flow aggregation mechanism to dynamically adjust the detection granularity. Further, to achieve accurate DDoS detection for aggregated flows, NetSentry implements frequency domain DDoS detection on programmable switches. Evaluations of NetSentry’s hardware prototype show that NetSentry can achieve better accuracy while saving up to 91% of the data plane memory required to store flow features compared to the state-of-the-art programmable switch-based flow classification scheme. Junchen Pan, Kunpeng He, Lei Zhang 0157, Zhuotao Liu, Xinggong Zhang, Yong Cui 0001 |
IWQoS | 3 |
| 2022 | DeepCC: Bridging the Gap Between Congestion Control and Applications via Multiobjective OptimizationabstractThe increasingly complicated and diverse applications have distinct network performance demands, e.g., some desire high throughput while others require low latency. Traditional congestion controls (CC) have no perception of these demands. Consequently, literatures have explored the objective-specific algorithms, which are based on either offline training or online learning, to adapt to certain application demands. However, once generated, such algorithms are tailored to a specific performance objective function. Newly emerged performance demands in a changeable network environment require either expensive retraining (in the case of offline training), or manually redesigning a new objective function (in the case of online learning). To address this problem, we propose a novel architecture, DeepCC. It generates a CC agent that is generically applicable to a wide range of application requirements and network conditions. The key idea of DeepCC is to leverage both offline deep reinforcement learning and online fine-tuning. In the offline phase, instead of training towards a specific objective function, DeepCC trains its deep neural network model using multi-objective optimization. With the trained model, DeepCC offers near Pareto optimal policies w.r.t different user-specified trade-offs between throughput, delay, and loss rate without any redesigning or retraining. In addition, a quick online fine-tuning phase further helps DeepCC achieve the application-specific demands under dynamic network conditions. The simulation and real-world experiments show that DeepCC outperforms state-of-the-art schemes in a wide range of settings. DeepCC gains a higher target completion ratio of application requirements up to 67.4% than that of other schemes, even in an untrained environment. Lei Zhang 0157, Yong Cui 0001, Mowei Wang, Kewei Zhu, Yibo Zhu 0001, Yong Jiang 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2021 | Deadline-Aware Transmission Control for Real-Time Video StreamingabstractThe deadline requirements of real-time applications rapidly increase in recent years (e.g., cloud gaming, cloud VR, online conferencing). Due to diverse network conditions, meeting deadline requirements for these applications has become one of the research hotspots. However, the current schemes focus on providing high bitrate instead of meeting deadline requirements. In this paper, we propose D3T, a flexible deadline-aware transmission mechanism that aims to improve user quality of experience (QoE) for real-time video streaming. To fulfill the diverse deadline requirements over fluctuating network conditions, D3T uses a deadline-aware scheduler to select the high priority frame before the deadline. To reduce congestion and retransmission delay, we leverage a deep reinforcement learning algorithm to make decisions of sending rate and FEC (forward error correction) redundancy ratio based on observed network status and frame information. We evaluate D3T via trace-driven simulator spanning diverse network environments, video contents and QoE metrics. D3T significantly improves the frame completion rate by reducing the bandwidth waste before the deadline. In the considered scenarios, D3T outperforms previously approaches with the improvements in average QoE of 57%. Lei Zhang 0157, Yong Cui 0001, Junchen Pan, Yong Jiang 0001 |
ICNP | 1 |
| 2020 | Reinforcement Learning Based Congestion Control in a Real EnvironmentabstractCongestion control plays an important role in the Internet to handle real-world network traffic. It has been dominated by hand-crafted heuristics for decades. Recently, reinforcement learning shows great potentials to automatically learn optimal or near-optimal control policies to enhance the performance of congestion control. However, existing solutions train agents in either simulators or emulators, which cannot fully reflect the real-world environment and degrade the performance of network communication. In order to eliminate the performance degradation caused by training in the simulated environment, we first highlight the necessity and challenges to train a learningbased agent in real-world networks. Then we propose a framework, ARC, for learning congestion control policies in a real environment based on asynchronous execution and demonstrate its effectiveness in accelerating the training. We evaluate our scheme on the real testbed and compare it with state-of-the-art congestion control schemes. Experimental results demonstrate that our schemes can achieve higher throughput and lower latency in comparison with existing schemes. Lei Zhang 0157, Kewei Zhu, Junchen Pan, Yong Jiang 0001, Yong Cui 0001 |
ICCCN | 1 |