Patrick C. K. Hung

dblp:h/PCKHung · also Patrick Hung · DBLP profile ↗
← Back
133ranked-venue papers
14as first author
31since 2021 · last 2026
0000-0002-9903-4862ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 49 · 3 first-author · 8 since 2021Databases, data management, data science and information retrieval · 22 · 4 first-author · 2 since 2021Systems, architecture and hardware · 17 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 14 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 1 first-author · 4 since 2021Computer networks · 11 · 8 since 2021Human-computer interaction and ubiquitous computing · 9 · 3 first-author · 2 since 2021Security and privacy · 4 · 2 first-author · 1 since 2021Theory of computation · 3
YearPublicationVenuePosition
2026 MHP-RCA: Multivariate Hawkes Process-based Root Cause Analysis in microservice systems
Jian Wang 0018, Bing Li 0010, Yu Liu 0038, Hongyue Wu, Patrick C. K. Hung
Inf. Softw. Technol.6
2026 ADmM: Anomaly Detection for Microservice Systems with Incomplete Metrics
abstract
The rapid development of the internet has led to an exponential increase in the scale of computing, storage, networking, and service resources. Traditional monolithic architectures are increasingly insufficient for managing these complexities. In contrast, microservice architectures have emerged as the mainstream solution with their inherent flexibility in deployment and scalability. To ensure system reliability, modern microservice architectures rely heavily on observability data, including logs, metrics, and traces. However, challenges such as network instability, service instance restarts, and system overloads frequently lead to intermittent loss of metric data. These missing data points impede comprehensive assessments of system health, significantly threatening system stability and reliability. To address the above challenge, we propose an anomaly detection model, ADmM, which integrates logs, metrics, and traces. ADmM first extracts template-level and semantic-level features from multimodal inputs. Then, a multi-scale autoencoder module is applied to impute missing metrics. For anomaly detection, the model represents microservice dependencies as a directed acyclic graph and leverages a graph neural network to learn generative patterns from normal system behavior. By measuring the deviation between observed values and reconstructed values, ADmM assigns anomaly scores to identify anomalies. Experiments conducted on three open-source benchmarks demonstrate that ADmM outperforms state-of-the-art methods across multiple anomaly detection metrics. Notably, it achieves F1-Score improvements of 5.77%, 5.48%, and 2.16% in scenarios with 40% incomplete metrics.
Jian Wang 0018, Bing Li 0010, Liuxiaoxiao Zhang, Yu Liu 0038, Patrick C. K. Hung
ACM Trans. Web6
2025 Towards a DIY Robotic Tail Toolkit for Future Service Robot and Computing Education
abstract
A service robot is an Internet of Things (IoT) or a cyberphysical system comprising a robotic body integrated with one or more Cloud-based services. This architecture enables sophisticated human-machine interaction and expands the functional capabilities of conventional robotic systems. A service robot can take the form of anthropomorphic, zoomorphic, or even theomorphic design. Our research team is collaborating with the Canadian National Institute for the Blind (CNIB) to develop a prototype service dog robot. Due to this, this paper presents our current experiences in designing, developing, and evaluating a Do-It-Yourself (DIY) articulated robotic tail toolkit for zoomorphic robots at Ontario Tech University. We detail the design process that led to the development of a robotic tail mechanism, driven by microservices, which emphasizes reliability and expressive while utilizing readily accessible components. We range also conducted experiments and evaluations of the robotic tail during a hands-on workshop with students from diverse backgrounds, using a services computing approach. We continue to develop an effective DIY educational tool that promotes student engagement in Human-Robot Interaction (HRI) design for future service computing education.
Marco Antonio Martínez Cano, Carolina Padilla Velasco, Patrick C. K. Hung, Hao-An Tseng, Kai-Xuan Koh
SSE3
2025 The Symbolic Interplay of Korean Pensive Buddha Statue and Colour: A Case Study in Thailand
abstract
In winter 2025, an observational experiment was conducted at Mahidol University, Thailand, to investigate how lighting colour influences individuals’ perceptions of religious imagery. The study examined how participants emotionally and symbolically respond to a pensive Korean Buddha statue when presented under different colored lighting conditions. We experimented with 116 participants who viewed the statue inside a black box illuminated by five colors-red, yellow, blue, green, and white-in randomized order. After each exposure, participants completed semantic differential scales measuring formality, authenticity, sacredness, memorability, perceived value, and durability. White lighting received the highest ratings for sacredness, perceived value, and authenticity; yellow excelled in memorability and sacredness; blue scored lowest on authenticity and formality; red was near-neutral. These findings inform the design of religious spaces and the presentation of sacred artifacts.
Young Yoon, Patrick C. K. Hung, Chen-Wei Hsieh, Lalita Narupiyakul, Hao-An Tseng, Khusrav Badalov, Tsz Lock Vien Cheung, Annie Jiang
AICCSA2
2025 Evaluating Social Dynamics and Uncanny Valley Perceptions in Human-Robot Interaction: Insights from the ROSaS Questionnaire
Rodrigo Marques Duarte, Danilo F. da Silva, Marco T. A. Silva, André de Lima Salgado, Gustavo Jose Giardini Lahr, Patrick C. K. Hung, Luiz Henrique A. Correia, Ahmed Ali Abdalla Esmin
INTERACT (4)6
2025 An Integrated Social Robot and Virtual Assistant Solution to Support Medical Management for Older Adults
abstract
ABSTRACT Introduction The global aging population leads to increased demand for professional caregivers and innovative assistive technologies. Traditional aids such as canes and hearing devices have long supported older adults, but emerging solutions involving robotics and AI open new opportunities for enhanced care and independence. Objectives This study aimed to design and evaluate an assistive solution that integrates a social robot and a virtual assistant to support older adults in managing medical treatments and daily schedules. Methods An assistive system was developed combining a social robot and a virtual assistant. Its potential was assessed through an exploratory evaluation involving seven older adults who interacted with the solution in simulated care and schedule management scenarios. Data were collected through structured interviews to capture participants' perceptions and experiences. Results The developed solution supported effective interaction between users and the technologies, despite minor usability challenges during initial use. Participants were generally able to complete tasks such as medication reminders, appointment management, and basic conversational interactions, although some required occasional assistance or clarification. Evaluation The participants expressed positive feedback regarding usability and perceived usefulness. The combined use of social robots and virtual assistants was considered intuitive and supportive, especially in reducing cognitive load and fostering adherence to treatment routines. Conclusion The integrated assistive solution presents a promising approach to supporting older adults' independence and well‐being. By combining social presence with functional assistance, it contributes to bridging the gap between human‐centered care and technological innovation.
Matheus Ancelmo Bonfim Pita, Marcelo Fantinato, Patrick C. K. Hung
Expert Syst. J. Knowl. Eng.3
2025 Service Migration for Delay-Sensitive IoT Applications in Edge Networks
abstract
The proliferation ofInternetofThings (IoT) applications prompts extraordinary demands for the collaboration of large amounts of computational resources provided byIoTdevices in edge networks, and these applications are mostly delay-sensitive. Generally, these resources are encapsulated asIoTservices. Thereafter,IoTapplications can be performed, such that the collaboration of their sub-tasks is achieved through the composition of functionally complementary and geographically contiguousIoTservices. The status of computational resources inIoTdevices may change continuously along with their occupancy and release byIoTservices. Considering the resource-scarceness ofIoTdevices, when the workload ofIoTdevices increases due to more services to be processed, certainIoTdevices may hardly have enough remaining resources to co-host more instances of certainIoTservices prescribed by forthcomingIoTapplications with strict constraints. As a result, the delay satisfaction of both on-running and forthcomingIoTapplications may be negatively impacted, or even hardly be satisfied any longer. To solve this issue, this paper proposes a rEsource-Efficient serviceConfiguration ($E^{2}$rC) mechanism, which aims to optimize the configuration of computational resources provided byIoTdevices with respect to complex requirements prescribed byIoTapplications, through service migration techniques. This service migration problem is formulated as markov multi-phases decisions, which is solved through our enhancedDeepReinforcementLearning (DRL) approach with a two-layerQ-network. Extensive experiments have been conducted upon the dataset of our testbed system. Evaluation results show that our$E^{2}$rCis more efficient than the state-of-art counterparts in satisfying delay constraints ofIoTapplications, while reducing the energy consumption and improving the resource utilization efficiency ofIoTdevices.
Zhangbing Zhou, Yasha Wang, Shuiguang Deng, Patrick C. K. Hung
IEEE Trans. Serv. Comput.5
2024 From Anthropomorphic to Zoomorphic Social Robots: Our Experiences
Patrick C. K. Hung
IoTBDS1
2024 Payment Routing Across IoT Blockchain Shards using Deep Reinforcement Learning
abstract
Payment channel network (PCN) routing is crucial for ensuring a high system throughput and transaction (TX) success ratio. However, designing PCN routing across IoT blockchain shards is not straightforward. First, the sharded architecture isolates information among multiple shards, increasing difficulties and costs associated with channel probing. Second, the dynamic nature of IoT, e.g., frequent changes in PCN topology and channel states, makes traditional mathematical routing approaches inefficient and even invalid. These challenges inevitably result in a high TX failure ratio and low throughput. This paper presents a novel cross-shard PCN routing IoT blockchain framework that optimizes TX scheduling to maximize long-term throughput and success ratio. Specifically, we propose an efficient cross-shard PCN routing protocol that distinctly categorizes channels into intra-shard and inter-shard types, simplifying cross-shard channel probing and reducing costs. Then, to optimize PCN routing policies in dynamic sharding environments, we propose a deep reinforcement learning algorithm, which includes: 1) multi-agent collaborative learning for the view of incomplete information across shards; 2) a two-layer network architecture to reduce computational complexity on resource-constrained IoT devices. Experiment results show that the proposed cross-shard routing improves 48.4 % of the TX success ratio averaged over baselines, which is 1.56 times of average throughput compared with other routing algorithms in cross-shard PCNs.
Ting Cai 0002, Chuqi Li, Yuxin Wu 0003, Zhiwei Ye, Patrick C. K. Hung
SECON7
2024 Robust multimodal federated learning for incomplete modalities
Songcan Yu, Junbo Wang 0001, Walid Hussein, Patrick C. K. Hung
Comput. Commun.4
2024 Introduction to the Special Issue on Thriving Amidst Disruptive Technologies
abstract
Disruptive technologies are thriving to replace the dominant technologies in many industry sectors.Thus, there is a need for a set of theories and technical works that can predict the probability of success of disruptive technologies at their early stages.Referring to the Technology-Organization-Environment (TOE) framework, technological, organizational, and environmental readiness affect enterprises' success in adopting and implementing disruptive technologies.For example, people believe that artificial intelligence (AI) and blockchain are two of the most disruptive technologies that make our world increasingly connected.Further, it is essential to consider the implications of these disruptive technologies and their integrations on security and privacy.For example, blockchain introduces challenging Internet of Things (IoT) security problems.The theme of this special issue is to provide a platform to discuss theoretical and technical approaches, strategies, solutions, and applications to support business transformation in a disruptive technological environment.We solicited research and industry papers related to these specific challenges and others driving innovation in this topic and related research issues, including ( 1) Big Data, Data Analytics, and Business Intelligence; (2) Enterprise Systems and Knowledge Management; (3) Digital Transformation, Management, and Governance; (4) Information Security, Privacy, and Risk Management; (5) Digital Information Systems in the Public Sector, Healthcare, Telecommunications, Transport and Education; (6) Digital Business Platforms, Blockchain, Social Networking, and the IoT; (7) Regional Perspectives on Digital Information Systems; (8) Artificial Intelligence (AI), Robotics, and Machine Learning; (9) Augmented Reality (AR) and Mixed Reality (XR); and (10) Case Studies (e.g., healthcare, customer service, aviation, etc.).This special issue provides the fundamentals of thriving amidst disruptive technologies, covering their computational development, technical capabilities, and roles in academic, societal, corporate, and governmental strategies.The special issue also provides clear evidence that disruptive technologies play an ever-increasingly essential and critical role in supporting our daily life and future, a new discipline for interdisciplinary research in business, information systems, and even social sciences.Two research papers have been presented on this special issue.Referring to the first paper, Ho et al. [ 2024 ] summarized the discussion of how blockchain and distributed ledger technologies can help tackle the fake news and misinformation problem at the 15th International Conference on Information Resources Management [Conf-IRM 2022 ] on October 18, 2022.In the second paper, Zhao et al. [ 2024 ] presented a quantitative metric and language-dependent single qualitative analysis of conformance between legal and smart contracts for constructing the secure blockchain.For future research directions, the AI-driven capability allows companies to gather real-time data from multiple sources, aiding strategy formulation and decision-making [Raj et al. 2023 ].Generative AI (GAI) should be imperative to imbue it with empathy, ethical considerations, and a human-centric approach, referred to as
Jairo A. Gutiérrez, Amarolinda Klein, Patrick C. K. Hung
Distributed Ledger Technol. Res. Pract.3
2024 TEMP: Cost-Aware Two-Stage Energy Management for Electrical Vehicles Empowered by Blockchain
abstract
Developing effective platforms for economic energy management is considered a pivotal issue in the field of electric vehicles (EVs). To implement a cost-effective energy management platform (EMP), developers must overcome two major challenges. The first challenge lies in the environmental dynamic nature, such as EV location, energy price fluctuations, storage levels, and parking availability at charging stations. This causes most traditional one-shot optimizations to fail. The second challenge pertains to the lack of regulation in EV energy exchanges. To address these challenges, we propose a cost-aware two-stage EMP based on blockchain and deep reinforcement learning (DRL), namely, TEMP. Specifically, TEMP first develops a sharding-based blockchain energy management framework, which guarantees trust, security, privacy, traceability, and accountability without the need for intermediaries. Then, considering the complex and high-dimensional environment, TEMP devises a two-stage cooperative scheduling scheme by combining ant colony optimization (ACO) with proximal policy optimization (PPO) to enhance learning effectiveness. Evaluations show that TEMP outperforms the two state-of-the-art baselines by 12.3% and 4.4% in terms of long-term profits while reducing costs by 6.7% and 2.8%, respectively. Moreover, energy transaction efficiency can be ensured when the EV number of blockchain networks is gradually increased.
Ting Cai 0002, Zhiwei Ye, Qiyi He, Xiaoli Li 0016, Yuquan Zhang, Patrick C. K. Hung
IEEE Internet Things J.9
2024 PBScaler: A Bottleneck-Aware Autoscaling Framework for Microservice-Based Applications
abstract
Autoscaling is critical for ensuring optimal performance and resource utilization in cloud applications with dynamic workloads. However, traditional autoscaling technologies are typically no longer applicable in microservice-based applications due to the diverse workload patterns and complex interactions between microservices. Specifically, the propagation of performance anomalies through interactions leads to a high number of abnormal microservices, making it difficult to identify the root performance bottlenecks (PBs) and formulate appropriate scaling strategies. In addition, to balance resource consumption and performance, the existing mainstream approaches based on online optimization algorithms require multiple iterations, leading to oscillation and elevating the likelihood of performance degradation. To tackle these issues, we propose PBScaler, a bottleneck-aware autoscaling framework designed to prevent performance degradation in a microservice-based application. The key insight of PBScaler is to locate the PBs. Thus, we propose TopoRank, a novel random walk algorithm based on the topological potential to reduce unnecessary scaling. By integrating TopoRank with an offline performance-aware optimization algorithm, PBScaler optimizes replica management without disrupting the online application. Comprehensive experiments demonstrate that PBScaler outperforms existing state-of-the-art approaches in mitigating performance issues while conserving resources efficiently.
Shuaiyu Xie, Jian Wang 0018, Bing Li 0010, Duantengchuan Li, Patrick C. K. Hung
IEEE Trans. Serv. Comput.6
2023 A privacy-preserving scheme to support the detection of multiple similar request-real-time services in IoT application systems
Abdulrahman Alamer, Sultan Basudan, Patrick C. K. Hung
Expert Syst. Appl.3
2023 A Blockchain-Assisted Intelligent Edge Cooperation System for IoT Environments With Multi-Infrastructure Providers
abstract
While edge computing has the potential to offer low-latency services and overcome the limitations of traditional cloud computing, it presents new challenges in terms of trust, security, and privacy (TSP) in Internet of Things environments. Cooperative edge computing (CEC) has emerged as a solution to address these challenges through resource sharing among edge nodes. However, for multi-infrastructure providers, incentive and trust mechanisms among edge nodes are crucial technical issues that must be addressed alongside system latency and reliability to meet performance requirements. In this article, we propose a blockchain-assisted intelligent edge cooperation system (BIECS) to systematically solve these issues. By leveraging blockchain technology, we construct trust among edge nodes and employ an incentive mechanism for resource sharing among multi-infrastructure providers. We formulate the system performance optimization as a multiobjective joint optimization problem and solve it efficiently through a two-stage strategy for selecting edge nodes. We first design an improved long short term memory (LSTM) model for resource prediction and then select edge nodes for executing offloaded tasks and handling the corresponding blockchain process related to each task execution. To evaluate the performance of BIECS, we implement the system based on Hyperledger Fabric and design extensive experiments. Our proposed system achieves better performance in terms of system delay, throughput, and resource utilization compared to state-of-the-art schemes for edge cooperation.
Xin Du 0002, Xuzhao Chen, Zhihui Lu 0002, Qiang Duan 0002, Jie Wu 0003, Patrick C. K. Hung
IEEE Internet Things J.7
2023 Accurate Anomaly Detection With Energy Efficiency in IoT-Edge-Cloud Collaborative Networks
abstract
With the applicability of edge intelligence in various domains, anomaly detection, which aims to identify unusual and infrequent circumstances, is regarded as a regularly performed task to guarantee the health of the Internet of Things (IoT) applications. Generally, sensory data are gathered at the network edge and completely transmitted to the cloud, where computational-heavy algorithms are mostly adopted to determine the locations of anomaly. Considering the occurrence infrequency of anomalies, this strategy may transmit relatively huge volume of sensory data, which may reflect a healthy situation indeed, to the cloud. To mitigate this problem, this article proposes an accurate anomaly detection mechanism with energy efficiency in three-tier IoT–edge–cloud collaborative networks. Specifically, after gathering sensory data provided by IoT nodes in certain edge networks, the edge node applies the marching squares algorithm to generate isopleths, where an isopleth may capture the boundary of anomaly. A sensory data filtering mechanism is conducted at the edge tier, such that anomaly-relevant sensory data are transmitted to the cloud and, thus, the network traffic is decreased significantly. Thereafter, the boundary of anomaly is obtained, and the locations of candidate boundary nodes are determined by adopting the Kriging spatial interpolation algorithm at the cloud tier. These locations are traversed by mobile sensing nodes at edge networks, and their sensory data are gathered for boundary refinement. Extensive experiments are conducted on an air quality hazardous gas data set from Toward Data Science, and evaluation results show that our technique outperforms the state-of-the-art counterparts in boundary accuracy and energy consumption.
Yi Li 0059, Zhangbing Zhou, Xiao Xue 0001, Deng Zhao, Patrick C. K. Hung
IEEE Internet Things J.5
2023 An Adaptive Mechanism for Dynamically Collaborative Computing Power and Task Scheduling in Edge Environment
abstract
Edge computing can provide high bandwidth and low-latency service for big data tasks by leveraging the edge side’s computing, storage, and network resources. With the development of microservice and docker technology, service providers can flexibly and dynamically cache microservice at the edge side to respond efficiently with limited resources. Automatically caching needed services on the nearest edge nodes and dynamically scheduling users’ requests can realize that computing power and software services flow with the users to provide continuous services. However, achieving the goal needs to overcome many challenges, such as the significant fluctuation of user devices’ requests at the edge side and the lack of collaboration among edge nodes. In this article, dynamic computing power scheduling and collaborative task scheduling among edge nodes are comprehensively developed. The problem is considered a multiobjective optimization problem, including sequentially minimizing the deadline missing rate of requests and the average task completion time. We propose an adaptive mechanism for dynamically collaborative computing power and task scheduling (ADCS) in the edge environment to solve this problem. It adopts the greedy decision method to schedule computing tasks to meet their deadline requirements. At the same time, it uses the best-fit method to adjust the computing resources according to the changes of users’ requests. The simulation results show that ADCS can decrease the deadline missing rate and reduce the average completion time. Compared with DSR and CoDSR, the deadline missing rate is reduced by 59.91% and 19.95%, respectively. The average completion time is decreased by 37.87% and 6.71%.
Yangchuan Xu, Lulu Chen, Zhihui Lu 0002, Xin Du 0002, Jie Wu 0003, Patrick C. K. Hung
IEEE Internet Things J.6
2023 An experimental design for facial and color emotion expression of a social robot
Pei-Chun Lin, Patrick C. K. Hung, Carolina Padilla Velasco, Marco Antonio Martínez Cano
J. Supercomput.2
2023 CTL-Based Adaptive Service Composition in Edge Networks
abstract
With the recent adoption of edge computing,Internet ofThings (IoT) devices collaborate at the network edge to facilitate edge-native applications. In this setting,IoTdevices are typically encapsulated asIoTservices to encode their functionalities, and their collaboration is achieved throughIoTservice composition. Due to the continuous resource occupancy, release, and consumption ofIoTdevices at runtime, a composition, which is functionally compatible and non-functionally optimal at this moment, may not hold in the forthcoming time durations, when certainIoTservices may significantly downgrade in theirQuality-of-Services (QoS). To guarantee the compatibility of compositions withQoSvariations, this article proposes an adaptive composition mechanism leveragingComputationTreeLogic (CTL) specifications. Specifically, we formalize the composition as a temporal task, and convert it toCTLformulae with the abstractions of required functionalities and composite structures. Functional compatibility is formally interpreted byCTLsemantics during the execution of compositions. Besides, we construct aQoSDependencyGraph (QoSDG) to captureQoSvariations, and achieve adaptive composition with dynamicQoSsatisfactions. Extensive experiments are conducted upon publicly-available datasets, and comparison results demonstrate that our technique outperforms the state-of-the-art counterparts in heterogenous scenarios with higherQoSdependencies ranging from 0.3$\%$to 27.8$\%$.
Deng Zhao, Zhangbing Zhou, Patrick C. K. Hung, Shuiguang Deng, Xiao Xue 0001, Walid Gaaloul
IEEE Trans. Serv. Comput.3
2022 Positive Facial and Verbal Sentiments of a Social Robot Mitigates Negative User Perceptions in Attitudinally Dissimilar Interactions
abstract
Social robots are increasingly used in different services such as education, hospitality, healthcare, and elderly care. These robots are often adopted to provide people with information and guidance, which sometimes can be quite different from people’s expectations. Therefore, it is important to understand whether similar or dissimilar opinions or attitudes of a focal subject held by the user and robot affects the user’s perception of the robot and future adoption intentions. We propose that robot design (positive facial expressions and verbal sentiments) may moderate the effect of attitude dissimilarity on robot perception. It is well-documented in the psychology literature that attitude similarity affects human-human relationships; however, no such study has been undertaken in human-robot interactions. Our results showed that when the robot expressed its views using a neutral facial expression and verbal sentiment, attitude similarity influenced robot perception, i.e., those participants who had similar (vs. dissimilar) attitudes as the robot perceived the robot to be positive (vs. negative). However, when the robot expressed its opinion with a positive facial expression and verbal sentiment, participants judged the robot as positive regardless of attitude similarity between the user and the robot. These results indicate that positive facial expressions and the verbal sentiment of a robot can nullify any negative effect when a user and a robot share very different opinions.
Curtis Gittens, Patrick C. K. Hung
RO-MAN3
2022 A new model for trustworthy web service QoS prediction
abstract
Abstract The number of web services available on the internet has exploded, and as a result, the number of services with the same functionality has exploded as well. Therefore, selecting the best web service from functionally similar services is a critical task in the web service domain. The Quality of Service (QoS) is one of the most common criteria used to select the best web service. Collaborative filtering (CF) has been utilized in several studies to predict the values of QoS attributes of web services for each user in a personalized way. The QoS histories of other users are employed in these methods to predict the QoS values of the active user. Although these methods function well and produce acceptable prediction results, the accuracy of their predictions can be harmed by incorrect data provided by untrustworthy users. In this study, we propose a new model that reduces the impact of unreliable user data, resulting in a trustworthy prediction. This model can be applied to any existing prediction method. In experiments, the proposed model was applied to seven known prediction methods. The results indicate that this model is able to eliminate the impact of unreliable users.
Seyyed Mohsen Hashemi, Seyyed Hamid Ghafouri, Patrick C. K. Hung
Concurr. Comput. Pract. Exp.3
2022 Service Configuration Optimization in Edge-Cloud Networks Leveraging Log Analysis
abstract
The edge–cloud collaboration network is promising to support complex requirements with temporal constraints, where a requirement can be achieved through the composition of computation-demanding and delay-sensitive services. In this setting, most services should be optimally configured at the network edge, in order to decrease service response latency and reducing network resource consumption. To address this challenge, this article proposes an optimal service configuration mechanism, where temporal constraints between services are mined from event logs through our temporal interval discovery mechanism. Service configuration is formulated as a constrained multiobjective optimization problem, which is solved by our improved nondominated sorting geneticalgorithm II. Extensive experiments are conducted, and evaluation results demonstrate that our approach can find the close-to-optimal service configuration in comparison with the state-of-the-art techniques in terms of delay sensitivity and energy efficiency, especially when edge nodes can co-host a relatively large number of services.
Mengyu Sun, Zhangbing Zhou, Xiao Xue 0001, Wenbo Zhang 0006, Patrick C. K. Hung
IEEE Internet Things J.5
2022 Coordinate-based efficient indexing mechanism for intelligent IoT systems in heterogeneous edge computing
Songtao Tang, Xin Du 0002, Zhihui Lu 0002, Keke Gai, Jie Wu 0003, Patrick C. K. Hung, Kim-Kwang Raymond Choo
J. Parallel Distributed Comput.6
2022 EVFL: An explainable vertical federated learning for data-oriented Artificial Intelligence systems
Peng Chen 0030, Xin Du 0002, Zhihui Lu 0002, Jie Wu 0003, Patrick C. K. Hung
J. Syst. Archit.5
2022 A Resource Recommendation Model for Heterogeneous Workloads in Fog-Based Smart Factory Environment
abstract
The wide deployment of advanced robots with industrial IoT (IIoT) technologies in smart factories generates a large volume of data during production and a wide variety of data processing workloads are launched to maintain productivity and safety of smart manufacture. The emerging fog computing paradigm offers a promising solution to enhancing data processing performance in a smart factory environment while on the other hand brings in new challenges to resource management, which call for a more effective approach for recommending resource configurations to heterogeneous workloads. In this paper, we propose an Optimized Recommendations of Heterogeneous Resource Configurations (ORHRC) model that employs machine learning techniques to provide resource configuration recommendations for the heterogeneous workloads in a fog computing-based smart factory environment. ORHRC learns a recommendation model by leveraging the operating characteristics and execution time of workloads on fog servers with different configurations. We also design a decision model in ORHRC to further improve prediction accuracy and reduce operational overheads. Experiment results show that ORHRC outperforms the state of art configuration recommendation methods in terms of average prediction accuracy.Note to Practitioners—The various data processing workloads in a smart factory environment need to be processed by the computational resources with optimal configurations for meeting their performance requirements. In this paper, we employ machine learning technologies for enabling automatic recommendation of resource configurations to heterogeneous workloads. Specifically, we develop an Optimized Recommendations of Heterogeneous Resource Configurations (ORHRC) model that can identify the optimal resource configurations for various workloads. We also conducted extensive experiments that verify the effectiveness of the proposed ORHRC model.
Lulu Chen, Zhihui Lu 0002, Ai Xiao, Qiang Duan 0002, Jie Wu 0003, Patrick C. K. Hung
IEEE Trans Autom. Sci. Eng.6
2022 Recommendations for a smart toy parental control tool
Otávio de Paula Albuquerque, Marcelo Fantinato, Patrick C. K. Hung, Sarajane Marques Peres, Farkhund Iqbal, Umair Rehman, Muhammad Umair Shah
J. Supercomput.3
2022 A Survey on Web Service QoS Prediction Methods
abstract
Nowadays, there are many Web services with similar functionality on the Internet. Users consider Quality of Service (QoS) of the services to select the best service from among them. The prediction of QoS values of the Web services and recommendations of the best service based on these values to the users is one of the major challenges in the web service area. Major studies in this field use collaboration filtering based methods for prediction. The paper introduced prediction methods and divided them into three main categories: memory-based methods, model-based methods, and Collaborative Filtering (CF) methods combined with other methods. In each category, some of the most famous studies were introduced, and then the problems and benefits of each category were reviewed. Finally, we have a discussion about these methods and propose suggestions for future works.
Seyyed Hamid Ghafouri, Seyyed Mohsen Hashemi, Patrick C. K. Hung
IEEE Trans. Serv. Comput.3
2021 IoT Microservice Deployment in Edge-Cloud Hybrid Environment Using Reinforcement Learning
abstract
The edge-cloud hybrid environment requires complex deployment strategies to enable the smart Internet-of-Things (IoT) system. However, current service deployment strategies use simple, generalized heuristics and ignore the heterogeneous characteristics in the edge-cloud hybrid environment. In this article, we devise a method to find a microservice-based service deployment strategy that can reduce the average waiting time of IoT devices in the hybrid environment. For this purpose, we first propose a microservice-based deployment problem (MSDP) based on the heterogeneous and dynamic characteristics in the edge-cloud hybrid environment, including heterogeneity of edge server capacities, dynamic geographical information of IoT devices, and changing device preference for applications and complex application structures. We then propose a multiple buffer deep deterministic policy gradient (MB_DDPG) to provide more preferable service deployment solutions. Our algorithm leverages reinforcement learning and neural network to learn a deployment strategy without any human instruction. Therefore, the service provider can make full use of limited resources to improve the Quality of Service (QoS). Finally, we implement MB_DDPG based on real-world data sets and some synthetic data, and we also implement another two algorithms, genetic algorithm and random algorithm, as a contrast. The experimental results demonstrate that MB_DDPG is able to learn a preferable strategy which, in terms of average waiting time, outperforms genetic algorithm and the random algorithm by 32% and 44%, respectively.
Lulu Chen, Yangchuan Xu, Zhihui Lu 0002, Jie Wu 0003, Keke Gai, Patrick C. K. Hung, Meikang Qiu
IEEE Internet Things J.6
2021 A Review on the Integration of Deep Learning and Service-Oriented Architecture
abstract
In recent years, machine learning has been used for data processing and analysis, providing insights to businesses and policymakers. Deep learning technology is promising to further revolutionize this processing leading to better and more accurate results. Current trends in information and communication technology are accelerating widespread use of web services in supporting a service-oriented architecture (SOA) consisting of services, their compositions, interactions, and management. Deep learning approaches can be applied to support the development of SOA-based solutions, leveraging the vast amount of data on web services currently available. On the other hand, SOA has mechanisms that can support the development of distributed, flexible, and reusable infrastructures for the use of deep learning. This paper presents a literature survey and discusses how SOA can be enabled by as well as facilitate the use of deep learning approaches in different types of environments for different levels of users.
Marcelo Fantinato, Sarajane Marques Peres, Eleanna Kafeza, Dickson K. W. Chiu, Patrick C. K. Hung
J. Database Manag.5
2021 Service-enabled systems and applications: current and future trends
Karim Benouaret, Patrick C. K. Hung, Ladjel Bellatreche
Serv. Oriented Comput. Appl.2
2021 SOLAR: Services-Oriented Deep Learning Architectures-Deep Learning as a Service
abstract
Deep learning has been an emerging field of machine learning during past decades. However, the diversity and large scale data size have posed significant challenge to construct a flexible and high performance implementations of deep learning neural networks. In order to improve the performance as well to maintain the scalability, in this paper we present SOLAR, a services-oriented deep learning architecture using various accelerators like GPU and FPGA. SOLAR provides a uniform programming model to users so that the hardware implementation and the scheduling is invisible to the programmers. At runtime, the services can be executed either on the software processors or the hardware accelerators. To leverage the trade-offs between the metrics among performance, power, energy, and efficiency, we present a multitarget design space exploration. Experimental results on the real state-of-the-art FPGA board demonstrate that the SOLAR is able to provide a ubiquitous framework for diverse applications without increasing the burden of the programmers. Moreover, the speedup of the GPU and FPGA hardware accelerator in SOLAR can achieve significant speedup comparing to the conventional Intel i5 processors with great scalability.
Chao Wang 0003, Lei Gong 0003, Xi Li 0003, Aili Wang 0003, Patrick C. K. Hung, Xuehai Zhou
IEEE Trans. Serv. Comput.6
2020 4P based forensics investigation framework for smart connected toys
abstract
Smart Connected Toys (SCTs) have the potential to collect terabytes of sensitive personal, contextual, and usage information which may be a subject of cybercrime or used as a conduit for cybercrime resulting in a digital forensic investigation which requires the examination of the digital artifact stored, processed or transmitted by the SCT. SCT forensics is challenging in most cases due to non-availability of specialized forensics tools and standardized evidence acquisition interface port. We explore the various privacy and security challenges plaguing the SCT industry and the possible safety risk SCT poses to children as a result of a lack of serious consideration technical controls surrounding the collection, processing, and storage of children's information and possible exposure to crime which will require digital forensic investigation. As a result of this gap in research and industry, we investigate current digital forensic solutions for SCTs and present an abstract forensics investigation framework with the focus on using non-conventional means which allow Investigators to successfully "Plan," "Preserve" "Process" and "Present" (4P) as a systematic means to conduct digital forensic analysis on an SCT in a situation where SCT is complicit in a criminal investigation or a subject of crime.
Benjamin Yankson, Farkhund Iqbal, Patrick C. K. Hung
ARES3
2020 DUGRA: Dual-Graph Representation Learning for Health Information Networks
abstract
With the rapidly growing volume and variety of Electronic Health Records (EHR) data, deep-learning models exhibit state-of-the-art performance for many predictive tasks in the health domain. To overcome the challenge of high dimensionality in EHR data, many representation learning methods have been proposed to learn low-dimensional diagnosis representations. Another challenge is how to effectively incorporate the domain knowledge, such as the International Classification of Diseases (ICD) medical ontology, into the learned embeddings. Albeit the medical ontology is a knowledge graph, none of the existing methods take advantage of Graph Neural Network (GNN), which has demonstrated its ability in other domains. The problem is that a GNN with multiple hidden layers, which are required to propagate information from the leaf of the medical ontology graph to the root, dilutes the differences among the nodes, degrading the quality of the learned embeddings. In this paper we introduce a densely connected graph derived from the original ontology graph to tackle the problem. Furthermore, to model the information in patient records, we construct a single co-occurrence graph based on the co-occurrence of diagnoses and a patient's diagnosis history. Experimental results show that the diagnosis embeddings learned from our model, DUal-GRAph Representation Learning (DUGRA), outperform the current state-of-the-art models in terms of diagnosis prediction accuracy.
Benjamin C. M. Fung, Patrick C. K. Hung
IEEE BigData3
2020 A Novel Data Placement Strategy for Data-Sharing Scientific Workflows in Heterogeneous Edge-Cloud Computing Environments
abstract
The deployment of datasets in the heterogeneous edge-cloud computing paradigm has received increasing attention in state-of-the-art research. However, due to their large sizes and the existence of private scientific datasets, finding an optimal data placement strategy that can minimize data transmission as well as improve performance, remains a persistent problem. In this study, the advantages of both edge and cloud computing are combined to construct a data placement model that works for multiple scientific workflows. Apparently, the most difficult research challenge is to provide a data placement strategy to consider shared datasets, both within individual and among multiple workflows, across various geographically distributed environments. According to the constructed model, not only the storage capacity of edge micro-datacenters, but also the data transfer between multiple clouds across regions must be considered. To address this issue, we considered the characteristics of this model and identified the factors that are causing the transmission delay. The authors propose using a discrete particle swarm optimization algorithm with differential evolution (DE-DPSO) to distribute dataset during workflow execution. Based on this, a new data placement strategy named DE-DPSO-DPS is proposed. DE-DPSO-DPS is evaluated using several experiments designed in simulated heterogeneous edge-cloud computing environments. The results demonstrate that our data placement strategy can effectively reduce the data transmission time and achieve superior performance as compared to traditional strategies for data-sharing scientific workflows.
Xin Du 0002, Songtao Tang, Zhihui Lu 0002, Jie Wu 0003, Keke Gai, Patrick C. K. Hung
ICWS6
2020 ORHRC: Optimized Recommendations of Heterogeneous Resource Configurations in Cloud-Fog Orchestrated Computing Environments
abstract
The cloud-fog orchestrated computing environments devolve computing tasks from the cloud center to the fog nodes, providing more heterogeneous configurations for the operation of workloads. Compared to the conventional cloud computing environment, the physical conditions at the fog nodes in the cloud-fog orchestrated computing environments are more complex and changeable. Therefore, the configurations that the fog nodes provide are heterogeneous and varying. This requires the configuration selection model to adapt to changeable configurations. The previous configuration selection models are applied to the limited and fixed configurations in the conventional cloud environment, but not to the complex cloud-fog orchestrated computing environments. To address this problem, we propose Optimized Recommendations of Heterogeneous Resource Configurations(ORHRC), a model that provides users with a reliable cloud configuration recommendation service. ORHRC uses the matrix factorization algorithm and neural network to build a recommendation model, which combines the operating characteristics of workloads as the explicit ratings and implicit feedback, to give configuration recommendations. Comprehensive experiments on a real-world dataset demonstrate that the hit rate of configurations of ORHRC is 24% higher than Micky and 15% higher than Selecta.
Ai Xiao, Zhihui Lu 0002, Xin Du 0002, Jie Wu 0003, Patrick C. K. Hung
ICWS5
2020 A Secure Tracing Method in Fog Computing Network for the IoT Devices
abstract
This paper proposes a Secure and Privacy-preserving Tracing (SPT) mechanism in the Fog Computing (FC) network. The proposed SPT mechanism employs a Counting Bloom Filter (CBF) method as a tree framework (CBF-tree) to model a secure tracing system in the FC network. With the proposed SPT mechanism, the fog node can trace a particular Internet of Things (IoT) device in a secure manner, which means that the fog node can trace IoT devices in order to provide them with their requested services without revealing their private data such as the device's identities or locations. Analysis shows that the SPT mechanism is both efficient and resilient against tracing attacks. Simulation results are provided to show that the proposed mechanism is beneficial to the FC network.
Abdulrahman Alamer, Sultan Basudan, Patrick C. K. Hung
MEDES3
2020 A Study of Parental Control Requirements for Smart Toys
abstract
Smart toys raises new concerns for parents and researchers. Children are more likely to share sensitive data and are unaware or rarely care about online risks. Parents play a relevant role in protecting the children, and parental control tools are necessary to take control and properly manage their child's data, according to their preferences. However, current tools neither meet parental needs nor are compliant with a standard for toy makers. We present a study of requirements for the development of a parental control tool for smart toys.
Otávio de Paula Albuquerque, Marcelo Fantinato, Marcelo Medeiros Eler, Sarajane Marques Peres, Patrick C. K. Hung
SMC5
2020 Preliminary Tendencies of Users' Expectations about Privacy on Connected-Autonomous Vehicles
abstract
Connected-Autonomous Vehicles (CAV) is an emerging and fast-paced transportation field where diverse companies, as traditional transportation companies and software companies, compete for dominance. CAV's benefits are promising, and this has led to an increasing interest in the literature. Despite different levels of autonomy, people might stay (to some extent) on the control of CAV, because full autonomy remains rare in transportation. Consequently, human errors are vulnerabilities that remain as potential reasons for malware infections in CAV. Usability becomes a vital attribute to mitigate the occurrence of such errors or prevent them from occurring. We aimed to understand users' expectations of privacy towards CAV's most autonomous levels, part of users' satisfaction and CAV's usability. Our survey gathered 50 responses, among 40 vehicle owners and ten non-owners. Responses showed six tendencies of users' behavior about CAV and its privacy issues. From the tendencies, we discuss implications for the design of CAV for future works.
André de Lima Salgado, Ben Singh, Patrick C. K. Hung, Annie Jiang, Yen-Hung Liu, Anna Priscilla de Albuquerque, Hossam A. Gabbar
SMC3
2020 Distributed gas concentration prediction with intelligent edge devices in coal mine
Yiwen Zhang 0001, Haishuai Guo, Zhihui Lu 0002, Lu Zhan, Patrick C. K. Hung
Eng. Appl. Artif. Intell.5
2020 Topic-based crossing-workflow fragment discovery
Zhangbing Zhou, Jinfeng Wen, Yasha Wang, Xiao Xue 0001, Patrick C. K. Hung, Long Dinh Nguyen
Future Gener. Comput. Syst.5
2020 BPS: A reliable and efficient pub/sub communication model with blockchain-enhanced paradigm in multi-tenant edge cloud
Yibo Huang 0005, Rui Zhang 0112, Zhihui Lu 0002, Yiming Zhang 0018, Jie Wu 0003, Lu Zhan, Patrick C. K. Hung
J. Parallel Distributed Comput.7
2020 ARVMEC: Adaptive Recommendation of Virtual Machines for IoT in Edge-Cloud Environment
Junnan Li 0003, Zhihui Lu 0002, Jie Wu 0003, Patrick C. K. Hung, Abdulhameed Alelaiwi
J. Parallel Distributed Comput.5
2020 BoR: Toward High-Performance Permissioned Blockchain in RDMA-Enabled Network
abstract
Known as a distributed ledger, blockchain is becoming prevalent due to its decentralization, traceability and tamper resistance. Particularly, permissioned blockchain such as Hyperledger Fabric shows great application prospects as the infrastructure of IoT security, credit management, etc. Many cloud platforms like AWS, Azure, Oracle and IBM cloud currently provide blockchain as a service, in which tenants can quickly build permissioned blockchain and run smart contract based applications. However, the transactions throughput and scalability in the permissioned blockchain are not ideal, despite many optimization efforts in consensus protocol and parallel chain. Existing solutions still reveals some limitations like excessive CPU scheduling, inefficient block broadcast and high latency of initial blocks synchronization when new nodes join blockchain network. Inspired by the emerging RDMA (Remote Direct Memory Access) network, we propose BoR, an RDMA-based permissioned blockchain framework. By offloading the block transfer transaction into RDMA NICs, it can increase block broadcast speed and reduce block sync delay. We exploit the RDMA primitives to redesign the block synchronization protocol and accelerate DPoS (Delegated Proof of Stake) consensus process for higher throughput and lower latency in kernel-bypass manner. As demonstrated in our evaluation with different workloads, BoR with lower CPU utilization significantly outperforms the state-of-the-art EoS blockchain.
Yibo Huang 0005, Zhihui Lu 0002, Xin Zhou 0009, Jie Wu 0003, Qifeng Tang, Patrick C. K. Hung
IEEE Trans. Serv. Comput.7
2019 Children Privacy Identification System in LINE Chatbot for Smart Toys
abstract
Children's privacy concerns about smart toys are becoming more and more critical in the toy industry. Parents and guardians continue to strive to protect their children from unnecessary privacy risks such as collection, and unconsented use of or access to their children's information. However, there is still no standardized privacy framework, which focuses on smart toys in this paradigm; making it difficult to determine possible privacy violation in for example determining whether a phrase shared with a smart toy is sensitive or not. To overcome this challenge, we build a privacy identification system through Chatbot technology. We call this system a Children Privacy Identification (CPI) system. To develop CPI system, we divide our research works into two parts: (1) Collect the phrase from the smart toys; and (2) Explore privacy Identification based on Personally Identifiable Information (PII) and Children's Online Privacy Protection Act (COPPA). For illustration, we integrate the CPI system in LINE Chatbot. The result shows that people feel more comfortable in talking to LINE Chatbot with privacy protection.
Pei-Chun Lin, Benjamin Yankson, Zhihui Lu 0002, Patrick C. K. Hung
CLOUD4
2019 IoT Service Composition for Concurrent Timed Applications
abstract
Concurrent applications may share certain components which can be conducted once for all, while mandating the satisfaction of their spatial-temporal constraints. A mechanism is proposed in this paper to identify common components, and to integrate and optimize concurrent service requests, where a component corresponds to a snippet of IoT service compositions. Consequently, composing IoT services with respect to concurrent requests can be reduced to a constrained multi-objective optimization problem, which can be solved by heuristic algorithms. Experimental results demonstrate the efficiency of this technique in comparison with the state of art's techniques, especially when the number of IoT nodes and functionality-overlapping are relatively large.
Mengyu Sun, Zhangbing Zhou, Wenbo Zhang 0006, Patrick C. K. Hung
ICWS4
2019 Robot Computing for Music Visualization
Pei-Chun Lin, David Mettrick, Patrick C. K. Hung, Farkhund Iqbal
TAMC3
2019 Special issue on Internet of Things (IoT) for in-vehicle systems
Shih-Chia Huang, Jenq-Neng Hwang, Sy-Yen Kuo, Alécio Pedro Delazari Binotto, Devesh Upadhyay, Patrick C. K. Hung
Eng. Appl. Artif. Intell.6
2019 QaMeC: A QoS-driven IoVs application optimizing deployment scheme in multimedia edge clouds
Zhihui Lu 0002, Patrick C. K. Hung, Shih-Chia Huang, Zhenfang Wang
Future Gener. Comput. Syst.3
2019 Bigdata logs analysis based on seq2seq networks for cognitive Internet of Things
Pin Wu, Zhihui Lu 0002, Zhidan Lei, Xiaoqiang Li 0002, Meikang Qiu, Patrick C. K. Hung
Future Gener. Comput. Syst.7
2019 RDMA-driven MongoDB: An approach of RDMA enhanced NoSQL paradigm for large-Scale data processing
Yibo Huang 0005, Zhihui Lu 0002, Ming Yan 0009, Jie Wu 0003, Patrick C. K. Hung, Qifeng Tang
Inf. Sci.6
2019 Efficiently querying large process model repositories in smart city cloud workflow systems based on quantitative ordering relations
Hua Huang 0006, Zhihui Lu 0002, Rong Peng, Zaiwen Feng, Xiaohua Xuan, Patrick C. K. Hung, Shih-Chia Huang
Inf. Sci.6
2019 Computing in smart toys and the related Internet of Things (IoT) applications
Patrick C. K. Hung, Marcelo Fantinato, Jorge Roa, Renata Pontin de Mattos Fortes, Shih-Chia Huang
J. Syst. Archit.1
2019 Transformation-Based Streaming Workflow Allocation on Geo-Distributed Datacenters for Streaming Big Data Processing
abstract
The cost-minimization problem for streaming workflow (SW) has already become increasingly important and even critical in stream big data processing, particularly for geographically distributed datacenters, because of its huge demand on computing and communicating resources. Existing virtual machine (VM) allocation algorithms in cloud computing have been widely applied to batch-processing models; however, none of them can be successfully applied to SW because: 1) they failed to adapt the continuous execution characteristic of SW; and 2) most of them are all based on the assumption that the price of traffic and VMs among datacenters are uniform. In this paper, we propose a transformation-based SW allocation algorithm with the goal of cost-minimization for stream big data processing in geographically distributed datacenters, considering the characteristics of SW and price heterogeneity among geographically distributed datacenters. We first propose a cost-aware workflow transformation framework based on eight well-designed and verified transformation rules for cost reduction to adapt the continuous execution characteristic of SW. We then formulate the joint VM-traffic optimization problem and show that it is NP-hard. To produce the optimal solution in polynomial time, we then transform the SW allocation problem into the minimum-cost maximum-flow problem, considering both traffic and VMs price heterogeneity. Finally, our experimental results validate the high cost efficiency of our approach with lower computing and communicating costs by optimizing the workflow specification and joint VM-traffic cost optimization.
Wuhui Chen, Incheon Paik, Patrick C. K. Hung
IEEE Trans. Serv. Comput.3
2018 Evaluation of the Perception of Brazilians about Smart Toys and Children's Privacy
abstract
The concept of children's toys has undergone many changes over the years, evolving from simple physical products to toys that add elements of the digital world using software and hardware components. This evolution has raised concerns about potential child privacy issues regarding the use of smart toys. A smart toy consists of a physical component connected to a computer system with online services to enhance the functionality of a traditional toy. This type of toy is still not widely known in Brazil and hence the opinion of Brazilian consumers regarding the acceptance of this technology when it is widespread in this country is not known yet. This paper aims to present the results of an evaluation about the perception of potential Brazilian consumers about issues involving children's privacy with the use of smart toys and whether this technology would be accepted when available in the Brazilian toy market. Semi-structured interviews were conducted with 14 participants producing data that were analyzed through the content analysis technique. The results showed concern on the part of parents when their children are connected to the internet. Moreover, parental control in smart toys would be well accepted by these potential consumers.
Fernanda Amâncio, Marcelo Fantinato, Patrick C. K. Hung, Gustavo Coutinho, Jorge Roa
CLEI3
2018 Enhancing Project Management for Cyber-physical Systems Development
abstract
In this paper, specific practices are proposed for better managing Cyber-physical Sytems (CPS) projects, called CPS-PMBOK approach.CPS-PMBOK is based on the Project Management Institute's PMBOK body of knowledge.It is focused on the integration, scope, human resource and stakeholder knowledge areas; which were chosen considering a systematic literature review conducted to identify the main CPS challenges.
Marcelo Fantinato, Filipe E. S. P. Palma, Laura Rafferty, Patrick C. K. Hung
FedCSIS4
2018 Personalized LSTM Based Matrix Factorization for Online QoS Prediction
abstract
Quality of Service (QoS) prediction is an important task in services computing, which has been extensively investigated in the past decade. Many time-aware QoS prediction approaches have been proposed and achieved encouraging prediction performance. However, they did not provide effective model updating mechanisms, and thus have to periodically retrain the whole models to deal with the newly coming data. How to timely update the prediction model to precisely predict missing QoS values of candidate services becomes an urgent issue. In this paper, we propose a novel personalized LSTM based matrix factorization approach for online QoS prediction. Our approach can capture the dynamic latent representations of multiple users and services, and the prediction model can be timely updated to deal with the new data. Experiments conducted on a real-world dataset show that our approach outperforms several state-of-the-art approaches in online prediction performance.
Ruibin Xiong, Jian Wang 0018, Zhongqiao Li, Bing Li 0010, Patrick C. K. Hung
ICWS5
2018 SERAC3: Smart and economical resource allocation for big data clusters in community clouds
Junnan Li 0003, Zhihui Lu 0002, Wei Zhang 0085, Jie Wu 0003, Bo Li 0025, Patrick C. K. Hung
Future Gener. Comput. Syst.7
2018 Energy-aware composition for wireless sensor networks as a service
Zhangbing Zhou, Deng Zhao, Lu Liu 0001, Patrick C. K. Hung
Future Gener. Comput. Syst.4
2018 EPLA: efficient personal location anonymity
Dapeng Zhao, Xiaoling Wang 0004, Patrick C. K. Hung, Wendi Ji
GeoInformatica5
2018 Improving interpretations of topic modeling in microblogs
abstract
Topic models were proposed to detect the underlying semantic structure of large collections of text documents to facilitate the process of browsing and accessing documents with similar ideas and topics. Applying topic models to short text documents to extract meaningful topics is challenging. The problem becomes even more complicated when dealing with short and noisy micro‐posts in Twitter that are about one general topic. In such a case, the goal of applying topic models is to extract subtopics. This results in topics represented by similar sets of keywords, which in turn makes the process of topic interpretation more confusing. In this paper we propose a new method that incorporates Twitter‐LDA, WordNet, and hashtags to enhance the keyword labels that represent each topic. We emphasize the importance of different keywords to different topics based on the semantic relationships and the co‐occurrences of keywords in hashtags. We also propose a method to find the best number of topics to represent the text document collection. Experiments on two real‐life Twitter datasets on fashion suggest that our method performs better than the original Twitter‐LDA in terms of perplexity, topic coherence, and the quality of keywords for topic labeling.
Sarah A. Alkhodair, Benjamin C. M. Fung, Osmud Rahman, Patrick C. K. Hung
J. Assoc. Inf. Sci. Technol.4
2018 A data-driven approach of performance evaluation for cache server groups in content delivery network
Zhihui Lu 0002, Wei Zhang 0085, Jie Wu 0003, Shalin Huang, Patrick C. K. Hung
J. Parallel Distributed Comput.6
2018 Differentially private multidimensional data publishing
Khalil Al-Hussaeni, Benjamin C. M. Fung, Farkhund Iqbal, Junqiang Liu, Patrick C. K. Hung
Knowl. Inf. Syst.5
2017 Mining unstructured processes: An exploratory study on a distance learning domain
abstract
Modern techniques widely applied in data mining, including computational intelligence and machine learning, have been fairly neglected in process mining. We conducted an exploratory study to use artificial neural networks to extract knowledge from an unstructured process in the distance learning domain. We discuss some possible benefits and limitations regarding the mining of unstructured processes. Results suggest that applying either classical process mining or modern data mining techniques would result in significant benefits for this domain. Our work helps to guide new studies related to the application of modern mining techniques in process mining.
Ana Rocío Cárdenas Maita, Marcelo Fantinato, Sarajane Marques Peres, Lucinéia Heloisa Thom, Patrick C. K. Hung
IJCNN5
2017 Organized topology based routing protocol in incompletely predictable ad-hoc networks
Jian Shen 0001, Chen Wang 0015, Anxi Wang, Xingming Sun, Sangman Moh, Patrick C. K. Hung
Comput. Commun.6
2017 InSTechAH: Cost-effectively autoscaling smart computing hadoop cluster in private cloud
Zhihui Lu 0002, Jie Wu 0003, Patrick C. K. Hung
J. Syst. Archit.4
2017 Multi-policy-aware MapReduce resource allocation and scheduling for smart computing cluster
Zhihui Lu 0002, Nini Wang, Jie Wu 0003, Patrick C. K. Hung
J. Syst. Archit.5
2017 Guest Editorial: In Search of a New Alignment in Service Research-Dual-Journal Special Sections
abstract
IEEETransactions on Services Computingand INFORMSService Scienceissued a joint call for papers targeting the bridging of service perspectives from business (e.g., service science, services marketing and information systems) to services computing. The intent was to advance transdisciplinary research agendas that could generate advances that go beyond the sum of independent research streams. As with all transdisciplinary research ideals, these efforts are extremely difficult, as pioneers need to overcome significant barriers, including different vocabularies, different research methods and differences in each field's historical evolution. This special section provides a snapshot of research efforts that begin to break down barriers. We offer special thanks to those authors who took the risk of having their manuscripts processed by an esteemed set of invited guest editors who have expertise from across the services spectrum.
Michael Goul, Paul P. Maglio, Patrick C. K. Hung
IEEE Trans. Serv. Comput.3
2016 EPLA: Efficient Personal Location Anonymity
Dapeng Zhao, Xiaoling Wang 0004, Patrick C. K. Hung, Wendi Ji
APWeb (2)5
2016 Layer-Hierarchical Scientific Workflow Recommendation
abstract
This article proposes to identify and recommend scientific workflows to promote their reuse and repurposing. Specifically, a scientific workflow is converted into a layer hierarchy, which specifies hierarchical relations between this workflow, its sub-workflows, and activities. Semantic similarity is calculated between layer hierarchies of workflows in order to construct a scientific workflow network model. A graph-skeleton based clustering method is adopted for grouping layer hierarchies into clusters. Barycenters in clusters are identified for facilitating cluster identification and workflow ranking and recommendation. Experimental result shows that this technique is efficient and accurate on ranking and recommending appropriate clusters and scientific workflows.
Zehui Cheng 0001, Zhangbing Zhou, Patrick C. K. Hung, Liang-Jie Zhang
ICWS3
2016 SOLAR: Services-Oriented Learning Architectures
abstract
Deep learning has been an emerging field of machine learning during past decades. However, the diversity and large scale data sizes have posed significant challenge to construct a flexible and high efficient implementations of deep learning neural networks. In order to improve the performance as well to maintain the scalability, in this paper we present SOLAR, a services-oriented deep learning architecture using various accelerators like GPU and FPGA based approaches. SOLAR provides a uniform programming model to users so that the hardware implementation and the scheduling is invisible to the programmers. At runtime, the services can be executed either on the software processors or the hardware accelerators. Experimental results on the real state-of-the-art FPGA board demonstrate that the SOLAR is able to provide a ubiquitous framework for diverse applications without increasing the burden of the programmers. Moreover, the speedup of the GPU and FPGA hardware accelerator in SOLAR can achieve significant speedup comparing to the conventional Intel i5 processors with great scalability.
Chao Wang 0003, Xi Li 0003, Aili Wang 0003, Patrick C. K. Hung, Xuehai Zhou
ICWS5
2016 Improved global motion estimation via motion vector clustering for video stabilization
Andrey Kopylov, Shih-Chia Huang, Oleg Seredin, Roman Karpov, Sy-Yen Kuo, K. Robert Lai, Tan-Hsu Tan, Munkhjargal Gochoo, Damdinsuren Bayanduuren, Cihun-Siyong Alex Gong, Patrick C. K. Hung
Eng. Appl. Artif. Intell.12
2016 Self-regularized causal structure discovery for trajectory-based networks
Victor W. Chu, Raymond K. Wong 0001, Fang Chen 0001, Simon Fong 0001, Patrick C. K. Hung
J. Comput. Syst. Sci.5
2016 Service Pricing Decision in Cyber-Physical Systems: Insights from Game Theory
abstract
In cyber-physical systems (CPS), service organizers (SOs) aim to collect service from service entities at lower price and provide better combined services to users. However, each entity receives payoffs when providing services, which leads to competition between SOs and service entities or within internal service entities. In this paper, we first formulate the price competition model of SOs where the SOs dynamically increase and decrease their service prices periodically according to the number of collected services from entities. A game based services price decision (GSPD) model which depicts the process of price decisions is proposed in this paper. In the GSPD model, entities game with other entities under the rule of “survival of the fittest” and calculate payoffs according to their own payoff-matrix, which leads to a Pareto-optimal equilibrium point. Numerous experiments demonstrate that the GSPD model can explain the price dynamics in the real world, and also can help decision makers a lot under various scenarios.
Xiao Liu 0007, Mianxiong Dong, Kaoru Ota, Patrick C. K. Hung, Anfeng Liu
IEEE Trans. Serv. Comput.4
2016 A Highly Accurate Prediction Algorithm for Unknown Web Service QoS Values
abstract
Quality of service (QoS) guarantee is an important component of service recommendation. Generally, some QoS values of a service are unknown to its users who has never invoked it before, and therefore the accurate prediction of unknown QoS values is significant for the successful deployment of web service-based applications. Collaborative filtering is an important method for predicting missing values, and has thus been widely adopted in the prediction of unknown QoS values. However, collaborative filtering originated from the processing of subjective data, such as movie scores. The QoS data of web services are usually objective, meaning that existing collaborative filtering-based approaches are not always applicable for unknown QoS values. Based on real world web service QoS data and a number of experiments, in this paper, we determine some important characteristics of objective QoS datasets that have never been found before. We propose a prediction algorithm to realize these characteristics, allowing the unknown QoS values to be predicted accurately. Experimental results show that the proposed algorithm predicts unknown web service QoS values more accurately than other existing approaches.
Shangguang Wang, Patrick C. K. Hung, Ching-Hsien Hsu, Qibo Sun, Fangchun Yang
IEEE Trans. Serv. Comput.3
2016 Editorial Preface: Special Issue on Big Data Analytics, Infrastructure, and Applications
abstract
The 13 papers in this special issue provide deep research results to report the advance of Big Data Analytics, Infrastructure, and Applications.
Stanislav Sobolevsky, Suzanne McIntosh, Patrick C. K. Hung
IEEE Trans. Serv. Comput.3
2016 Fast Service Process Fragment Indexing and Ranking
abstract
Service searching and ranking are the bases of service-oriented software development. However, the existing service searching and ranking methods are confined to the atomic services or processes encapsulated as stand-alone services. How to find and reuse arbitrary granularities of service process fragment (SPF) is a challenging problem with great application value. In this paper, we propose a new mechanism to support searching and ranking on massive SPFs. In this mechanism, SPFs are organized by a tree, where both the functional and non-functional information of SPFs are encoded and stored on each tree node. Then, starting from the tree root, an integrated searching and ranking process is recursively conducted on each tree layer, excluding a great deal of irrelevant SPFs each time, until leaf nodes are reached. To verify the feasibility and effectiveness, we construct a sample dataset which contains four million processes and one billion atomic services based on the Web Service Challenge Testset Generator (CTG), and each atomic service has up to 10 QoS values. The experimental results show an effective and efficient approach for SPF-Query.
Patrick C. K. Hung
IEEE Trans. Serv. Comput.3
2015 A Novel Reactive-Predictive Hybrid Resource Provision Method in Cloud Datacenter
Guorui Sun, Zhihui Lu 0002, Jie Wu 0003, Patrick C. K. Hung
APSCC5
2015 Privacy Issues in SOAP Message Exchange Pattern for Social Services
abstract
A Web service is defined as an autonomous unit of application logic that provides either some business functionality or information to other applications through an Internet connection. Web services are based on a set of eXtensible Markup Language (XML) standards such as Universal Description, Discovery and Integration (UDDI), Web Services Description Language (WSDL), and Simple Object Access Protocol (SOAP). Nowadays Web services are becoming more and more popular for supporting different social applications, thus there are also increasing demands and discussions about Web services privacy protection in information. In general, privacy policies describe an organization's data practices on what information they collect from individuals (e.g., consumers) and what (e.g., purposes) they do with it. To enable privacy protection for Web service consumers across multiple domains and services, the World Wide Web Consortium (W3C) published a document called “Web Services Architecture (WSA) Requirements” that defines some specific privacy requirements for Web services as a future research topic. This paper presents a mathematical model to construct the privacy policies in SOAP Message Exchange Patterns (MEP) for social services. Further, this paper also presents the privacy policies in security tokens with SOAP messages.
Wuhui Chen, Incheon Paik, Patrick C. K. Hung
Fundam. Informaticae3
2015 Constructing a Global Social Service Network for Better Quality of Web Service Discovery
abstract
Web services have had a tremendous impact on the Web for supporting a distributed service-based economy on a global scale. However, despite the outstanding progress, their uptake on a Web scale has been significantly less than initially anticipated. The isolation of services and the lack of social relationships among related services have been identified as reasons for the poor uptake. In this paper, we propose connecting the isolated service islands into a global social service network to enhance the services' sociability on a global scale. First, we propose linked social service-specific principles based on linked data principles for publishing services on the open Web as linked social services. Then, we suggest a new framework for constructing the global social service network following linked social service-specific principles based on complex network theories. Next, an approach is proposed to enable the exploitation of the global social service network, providing Linked Social Services as a Service. Finally, experimental results show that our approach can solve the quality of service discovery problem, improving both the service discovering time and the success rate by exploring service-to-service based on the global social service network.
Wuhui Chen, Incheon Paik, Patrick C. K. Hung
IEEE Trans. Serv. Comput.3
2014 D-Mash: A Framework for Privacy-Preserving Data-as-a-Service Mashups
abstract
Data-as-a-Service (DaaS) mashup enables data providers to dynamically integrate their data on demand depending on consumers' requests. Utilizing DaaS mashup, however, involves some challenges. Mashing up data from multiple sources to answer a consumer's request might reveal sensitive information and thereby compromise the privacy of individuals. Moreover, data integration of arbitrary DaaS providers might not always be sufficient to answer incoming requests. In this paper, we provide a cloud-based framework for privacy-preserving DaaS mashup that enables secure collaboration between DaaS providers for the purpose of generating an anonymous dataset to support data mining. Experiments on real-life data demonstrate that our DaaS mashup framework is scalable and can efficiently and effectively satisfy the data privacy and data mining requirements specified by the DaaS providers and the data consumers.
Mahtab Arafati, Gaby G. Dagher, Benjamin C. M. Fung, Patrick C. K. Hung
IEEE CLOUD4
2014 Web Service Orchestration Topic Mining
abstract
Due to the popularity of using web services to deliver services on the Web, a clear view of how they are being consumed is becoming critical. Researchers have been trying multiple methods to reveal actual service orchestration patterns from service logs. However, most of the discovery methods have taken deterministic approaches, and hence, they do not provide enough allowance to cater for incomplete data and noises. On the other hand, most investigations do not take combinatorial explosion into consideration leading to scalability problem. Moreover, asynchronous web service invocations and distributed executions also make it difficult to identify service patterns due to the randomness in log record generation. In this paper, probabilistic topic mining class of solutions are applied to reveal web service orchestration patterns from service logs, in which robust approximation methods are available to provide scalability. Data sparsity problem in service log is also investigated by using biterm topic model (BTM) and comparing its results with traditional latent Dirichlet allocation (LDA) model. In addition, a topic matching method is introduced based on the Hungarian method on Jensen-Shannon divergence matrix, whilst notions of aggJSD and autoJSD are also introduced to measure topic diversity between matched topic sets and within a single topic set respectively. Experiment results confirm that BTM can be used for service logs with short log entries and with sparsity larger than 90% approximately.
Victor W. Chu, Raymond K. Wong 0001, Chihung Chi, Patrick C. K. Hung
ICWS4
2014 Time-Aware Web Service Recommendations Using Implicit Feedback
abstract
With the rapid development of SOA (Service Oriented Architecture), an increasing number of Web services have been published on the Internet. How to recommend suitable Web services to users becomes a challenging problem. Existing Web services recommendation approaches based on collaborative filtering mainly focus on QoS (Quality of Service) prediction. Recommending services based on users' ratings on services are seldom reported since such explicit feedback data is difficult to collect. In this paper, we report a dataset of implicit feedback on real-world Web services, which consist of more than 280,000 user-service interaction records, 65,000 service users and 15,000 Web services or mashups. In addition, time is becoming an increasingly important factor in recommenders since time effects influence users' preferences to a large extent. Based on the collected dataset, we propose a time-aware service recommendation approach. Temporal information is sufficiently considered in our approach, where three time effects are analyzed and modeled including user bias shifting, Web service bias shifting, and user preference shifting. Experimental results show that the proposed approach outperforms seven existing collaborative filtering approaches on the prediction accuracy.
Gang Tian, Jian Wang 0018, Keqing He 0002, Patrick C. K. Hung, Chengai Sun
ICWS4
2014 A rule-based approach for availability of service by automated service substitution
abstract
High availability of software components has long been studied. For a software system, when unavailability of a component has caused a suspension of the system, the system has to be recovered or resumed as soon as possible. To substitute an unavailable software component with a backup copy is therefore unavoidable in achieving high availability of software systems. In this paper, in comparison with using redundancies, we take an alternative approach that steps away from the physical code equivalence of the software but focuses more on the equivalence in using the function unit without concerning about the implementation itself. We investigate the problem of Web service availability in service-oriented software systems and then report a framework for Web service availability in such systems using automated and rule-based Web service substitution. The framework takes a novel approach to manage the runtime replacement of services, combining (i) an approach that classifies services using co-occurrence of terms in various tags of the service descriptions, (ii) an approach to establish the compatibility and substitution of service operation interfaces and (iii) a middleware for handling service replacements. Our approach is designed to address the problem of Web service availability from the client side and assumes that the client has no control of the Web service providers. This is a completely distributed approach in comparison with other related work and presents a valuable benefit of client orientation. As two additional distinguishing characteristics, our framework also meets the challenges of (i) semantic heterogeneity of Web services in identifying substitute service and (ii) transparency and independence in handling unavailability at the level of Web services. We show in our experiments that the service substitute identification based on the proposed framework achieves a best precision of 85%. We demonstrate our implementation of the middleware for service unavailability handling in the framework. We also present experiments on service substitution within a demo business application in the presence of unavailability. Copyright © 2012 John Wiley & Sons, Ltd.
Qianhui Althea Liang, Bu-Sung Lee, Patrick C. K. Hung
Softw. Pract. Exp.3
2014 Optimized BS assignment and resource allocation in cooperative OFDM networks
Bin Lin 0001, Pin-Han Ho, Hsiang-Fu Yu, Patrick C. K. Hung
Wirel. Networks5
2013 Variable Granularity Index on Massive Service Processes
abstract
Service reuse aims at improving the efficiency of software development and providing common functionalities which are not linked to any particular business process. However, the existing service reuse methods are confined to the reuse of atomic services or processes encapsulated as stand-alone services. How to reuse arbitrary granularities of Service Process Fragment (SPF) is a challenging problem with great application value. This paper presents a novel Variable Granularities Index (VGI) based on SSM-Tree on service processes. VGI could realize the unified index on both atomic and composite services and maximize reuse of them. To verify the feasibility and effectiveness, we construct a sample dataset which contains 500 thousand processes and 127 million atomic services based on the Web Service Challenge Testset Generator (CTG). The experimental results show an effective and efficient approach for SPF query.
Jian Wang 0018, Patrick C. K. Hung, Jilei Tian
ICWS4
2012 Linked Social Service: Connecting Isolated Services into a Global Social Service Network
abstract
It is considered that Web services have had a tremendous impact on the Web as a potential silver bullet for supporting a distributed service-based economy on a global scale. However, despite the outstanding progress, their uptake on a Web scale has been significantly less than initially anticipated. The reasons are: first, the existing Web service frameworks such as gtraditionalh Web services, semantic Web services, and Web APIs have had a limited impact, second, isolated service islands without links to related services have hampered service discovery and composition. In this paper, we propose a methodology to drive innovation from isolated service islands into the global social service network to connect the islands. First, we propose Linked social service-specific principles based on Linked Data principles for publishing services on the open Web as linked social services using our new service model, and suggest a new platform for constructing a global social service network. Then, an approach is proposed to enable exploitation of a global social service network, providing Linked social service as a service. Finally, experimental results show that the Linked social service can solve the service discovery problem by enabling exploring service to service based on the global social service network.
Wuhui Chen, Incheon Paik, Patrick C. K. Hung
APSCC3
2012 Service-Oriented Architecture for High-Dimensional Private Data Mashup
abstract
Mashup is a web technology that allows different service providers to flexibly integrate their expertise and to deliver highly customizable services to their customers. Data mashup is a special type of mashup application that aims at integrating data from multiple data providers depending on the user's request. However, integrating data from multiple sources brings about three challenges: 1) Simply joining multiple private data sets together would reveal the sensitive information to the other data providers. 2) The integrated (mashup) data could potentially sharpen the identification of individuals and, therefore, reveal their person-specific sensitive information that was not available before the mashup. 3) The mashup data from multiple sources often contain many data attributes. When enforcing a traditional privacy model, such as K-anonymity, the high-dimensional data would suffer from the problem known as the curse of high dimensionality, resulting in useless data for further data analysis. In this paper, we study and resolve a privacy problem in a real-life mashup application for the online advertising industry in social networks, and propose a service-oriented architecture along with a privacy-preserving data mashup algorithm to address the aforementioned challenges. Experiments on real-life data suggest that our proposed architecture and algorithm is effective for simultaneously preserving both privacy and information utility on the mashup data. To the best of our knowledge, this is the first work that integrates high-dimensional data for mashup service.
Benjamin C. M. Fung, Thomas Trojer, Patrick C. K. Hung, Li Xiong 0001, Khalil Al-Hussaeni, Rachida Dssouli
IEEE Trans. Serv. Comput.3
2012 Guest Editorial: Special Section on Enforcement and Management in Services Computing
abstract
SERVICE solutions are typically comprised of rather complex and continuously evolving service-oriented systems. While such systems may be under the sole control of an individual organizational unit, more often than not, they are deployed in interorganizational environments, must comply with various corporate and/or governmental governance regulations, and much more. Security and, in particular, privacy and trust are major concerns in almost all facets of such service solutions. In order to enable individual services or collections of services to easily interact, integrate, or be composed, it is often necessary to establish, manage, maintain, adapt, and enforce various service-level agreements, privacy policies, and/or rules across service and/or organizational boundaries. These tasks become only more challenging during the life-cycle of an evolving service solution. In this Special Issue on Enforcement and Management in Services Computing, we present seven high quality research articles on enforcement and management issues that are prevalent in current and emerging service solutions with a particular focus on privacy, security, trust, provenance, service solution (design and delivery) management, and service solution integration. Following the 2009 IEEE Asia-Pacific Services Computing Conference (APSCC) in Singapore, we launched an open call for submissions to this special issue of the IEEE Transactions on Services Computing. We received more than 30 submissions; the following seven articles were selected through a rigorous review process:
Markus Kirchberg, Patrick C. K. Hung
IEEE Trans. Serv. Comput.2
2012 Adaptive BU association and resource allocation in integrated PON-WiMAX networks
abstract
ABSTRACT This paper addresses the issues of Base station—User Association and Resources Allocation (BUA‐RA) in OFDM‐TDMA based broadband wireless access (BWA) networks under passive optical networks (PON)‐WiMAX integration. With the powerful coordination capability at the optical line terminal (OLT), a key technology of inter‐cell cooperative transmission (CT) is incorporated in the integrated network architecture, which is called cooperative PON‐WiMAX network (CPWN). To achieve an efficient integration and inter‐cell cooperative transmission in the CPWNs, the BUA‐RA scheme is critical to the Quality of Service (QoS) provisioning for each user. In order to minimize the network resource usage, we provide three new BUA‐RA schemes which first time employ the cooperative transmission in a multi‐cell BWA network. The three schemes are designed for three kinds of subscribers with different moving types, and can be adaptively applied based on the network load. Simulations are conducted to verify the proposed BUA‐RA schemes by comparing with those without cooperative transmission technology. Our results demonstrate the efficiency of our proposed schemes, which are based on mathematical formulations and linearization. Copyright © 2010 John Wiley & Sons, Ltd.
Bin Lin 0001, Pin-Han Ho, Patrick C. K. Hung
Wirel. Commun. Mob. Comput.4
2011 Leveraging Fragmental Semantic Data to Enhance Services Discovery
abstract
As one foundational technology of cloud computing, services computing is playing a critical role to enable provisioning of software as a service (SaaS). However, how to effectively and efficiently discover proper available services from the cloud of resources remains a big challenge. This paper reports our continuous efforts on semantic services discovery. We extend the Support Vector Machine (SVM)-based text clustering technique in the context of service-oriented categorization in a service repository, and propose an iterative process to incrementally enrich domain ontology. A popular Web 2.0 mashup platform is used as a testbed; and preliminary evaluation results are reported.
Jian Wang 0018, Jia Zhang 0001, Patrick C. K. Hung, Jianxiao Liu, Keqing He 0002
HPCC3
2011 Service Composition and Interaction in a SOC Middleware Supporting Separation of Concerns with Flows and Views
abstract
Service-Oriented Computing (SOC) has recently gained attention both within industry and academia; however, its characteristics cannot be easily solved using existing distributed computing technologies. Composition and interaction issues have been the central concerns, because SOC applications are composed of heterogeneous and distributed processes. To tackle the complexity of inter-organizational service integration, the authors propose a methodology to decompose complex process requirements into different types of flows, such as control, data, exception, and security. The subset of each type of flow necessary for the interactions with each partner can be determined in each service. These subsets collectively constitute a process view, based on which interactions can be systematically designed and managed for system integration through service composition. The authors illustrate how the proposed SOC middleware, named FlowEngine, implements and manages these flows with contemporary Web services technologies. An experimental case study in an e-governmental environment further demonstrates how the methodology can facilitate the design of complex inter-organizational processes.
Dickson K. W. Chiu, Qing Li 0001, Patrick C. K. Hung, Zhe Shan 0001, Shing-Chi Cheung, Matthias Farwick
J. Database Manag.3
2010 A Reference Model for Master of Science Program in Services Computing
abstract
Services Computing has become an increasingly important area in the IT and business sectors. In particular, Services now account for more than half of the economy in the United States and other countries. Numerous Services Computing-related degree programs and accreditation processes are being created. However, very few systematic guidelines exist for building graduate programs for Services Computing. In this paper, we present a reference model of the Masters Program in Services Computing for academic institutions and accreditation agencies as a relevant curriculum guideline. Specifically, the core and elective courses are introduced to help build the reference program. The inter-connections between core and elective courses are also illustrated to help create concentration programs based on the introducing sequences of the courses. Some practices of delivering Services Computing related courses and conducting accreditation application process are presented in this paper to help others more rapidly initiate the adoption process of the Services Computing curriculum.
Liang-Jie Zhang, Zhixiong Chen 0005, Jia Zhang 0001, Patrick C. K. Hung
SERVICES5
2010 Centralized and Distributed Anonymization for High-Dimensional Healthcare Data
abstract
Sharing healthcare data has become a vital requirement in healthcare system management; however, inappropriate sharing and usage of healthcare data could threaten patients’ privacy. In this article, we study the privacy concerns of sharing patient information between the Hong Kong Red Cross Blood Transfusion Service (BTS) and the public hospitals. We generalize their information and privacy requirements to the problems of centralized anonymization and distributed anonymization , and identify the major challenges that make traditional data anonymization methods not applicable. Furthermore, we propose a new privacy model called LKC-privacy to overcome the challenges and present two anonymization algorithms to achieve LKC-privacy in both the centralized and the distributed scenarios. Experiments on real-life data demonstrate that our anonymization algorithms can effectively retain the essential information in anonymous data for data analysis and is scalable for anonymizing large datasets.
Noman Mohammed, Benjamin C. M. Fung, Patrick C. K. Hung, Cheuk-kwong Lee
ACM Trans. Knowl. Discov. Data3
2009 Privacy-preserving data mashup
abstract
Mashup is a web technology that combines information from more than one source into a single web application. This technique provides a new platform for different data providers to flexibly integrate their expertise and deliver highly customizable services to their customers. Nonetheless, combining data from different sources could potentially reveal person-specific sensitive information. In this paper, we study and resolve a real-life privacy problem in a data mashup application for the financial industry in Sweden, and propose a privacy-preserving data mashup (PPMashup) algorithm to securely integrate private data from different data providers, whereas the integrated data still retains the essential information for supporting general data exploration or a specific data mining task, such as classification analysis. Experiments on real-life data suggest that our proposed method is effective for simultaneously preserving both privacy and information usefulness, and is scalable for handling large volume of data.
Noman Mohammed, Benjamin C. M. Fung, Ke Wang 0001, Patrick C. K. Hung
EDBT4
2009 Behavioral Attestation for Business Processes
abstract
Service oriented architecture (SOA) is an architectural paradigm that enables dynamic composition of heterogeneous, independent, multi-vendor business services. A prerequisite for such inter-organizational workflows is the establishment of trustworthiness, which is mostly achieved through non-technical measures such as legislation, and/or social consent that businesses, or organizations simply pledge themselves to adhere. In our viewpoint, a business process can only be trustworthy if the behavior of all services in it is trustworthy. Trusted Computing Group (TCG) has defined an open set of specifications for the establishment of trustworthiness through a hardware root-of-trust. This paper has three objectives: firstly, the behavior of individual services in a business process is formally specified. Secondly, in order to overcome the inherent weaknesses of trust management through software alone, a hardware root of-trust devised by the TCG, is used for the measurement of the behavior of individual services in a business process. Finally, a verification mechanism is detailed through which the trustworthiness of a business process can be verified.
Masoom Alam, Mohammad Nauman, Xinwen Zhang, Tamleek Ali, Patrick C. K. Hung
ICWS5
2009 Service-Oriented Architecture for Privacy-Preserving Data Mashup
abstract
Mashup is a Web technology that combines information from more than one source into a single Web application.This technique provides a new platform for different data providers to flexibly integrate their expertise and deliver highly customizable services to their customers. None the-less, combining data from different sources could potentially reveal person-specific sensitive information. In this paper, we study and resolve a real-life privacy problem in a data mashup application for the financial industry in Sweden. Therefore we propose a service-oriented architecture for privacy-preserving data mashup together with a multi-party protocol to securely integrate private data from different data providers, whereas the integrated data still retains the essential information for supporting general data exploration or a specific data mining task, such as classification analysis. Experiments on real-life data suggest that our proposed method is effective for simultaneously preserving both privacy and information usefulness.
Thomas Trojer, Benjamin C. M. Fung, Patrick C. K. Hung
ICWS3
2009 Anonymizing healthcare data: a case study on the blood transfusion service
abstract
Sharing healthcare data has become a vital requirement in healthcare system management; however, inappropriate sharing and usage of healthcare data could threaten patients' privacy. In this paper, we study the privacy concerns of the blood transfusion information-sharing system between the Hong Kong Red Cross Blood Transfusion Service (BTS) and public hospitals, and identify the major challenges that make traditional data anonymization methods not applicable. Furthermore, we propose a new privacy model called LKC-privacy, together with an anonymization algorithm, to meet the privacy and information requirements in this BTS case. Experiments on the real-life data demonstrate that our anonymization algorithm can effectively retain the essential information in anonymous data for data analysis and is scalable for anonymizing large datasets.
Noman Mohammed, Benjamin C. M. Fung, Patrick C. K. Hung, Cheuk-kwong Lee
KDD3
2009 Privacy-preserving data publishing for cluster analysis
Benjamin C. M. Fung, Ke Wang 0001, Lingyu Wang 0001, Patrick C. K. Hung
Data Knowl. Eng.4
2008 Web Service-Based Business Process Development, Threat Modeling and Security Assessment Tool
abstract
Summary form only given. A business process is a collection of related structures and activities, undertaken by organizations in order to achieve certain business goals. The Web services-based business processes with a new set of protocols bring a new set of security challenges. As security has become an essential component for all software, several security solutions for XML and Web services have been proposed. In general, a security threat model is an organized representation of relevant threats, attacks, and vulnerabilities to a system. In this context, security threat modeling is an engineering technique which can be used to shape the Web service-based business processes with security requirements. The topic of security threat modeling in business process is becoming increasingly important to industry. This tutorial strives to reflect recent trends in research and developments of business processes integration and management with security concerns. In addition this tutorial will cover the fundamental concepts of security threat modeling from the perspectives of Web service-based business process. This tutorial will also address the common practices and related tools/procedures for addressing the security vulnerabilities, especially in XML attacks. A research prototype of security assessment will also be presented and demonstrated in the tutorial.
Jianxin Li 0002, Teodor Sommestad, Patrick C. K. Hung
ICWS3
2008 A Rule-Based Approach for Availability of Web Service
abstract
Sustainable success of service oriented applications relies on capabilities to manage possible service failures. To substitute a failed service with some other equivalent service is unavoidable in recovering a suspended application due to failure of a constituent service. In this paper, we report a rule based approach to Web service substitution in order to secure availability of services. Availability provides delivery assurance for each Web service so that Simple Object Access Protocol (SOAP) messages cannot be lost undetectably, especially in a Web service composition. The rules are written in Semantic Web Rule Language. The rules are a formal representation of a categorization-based scheme to identify exchangeable Web services. This scheme not only tackles the issue of heterogeneity of domain ontology in describing the Web services, it also adapts itself by learning newly discovered ontology instances. A technical framework of Web service substitution using rule based deduction is demonstrated. Experiments on service substitution based on the proposed framework achieve a best precision of 85%.
Qianhui Althea Liang, Herman Lam, Lalita Narupiyakul, Patrick C. K. Hung
ICWS4
2008 Emergency Response Framework for Aviation XML Services on MANET
abstract
A XML service is a software component that supports interoperable application-to-application interaction over a network. Each service makes its functionality available through well-defined or standardized XML interfaces. Aviation XML services refer to the services that make operating an airplane in air and on ground possible. In this paper, we present an emergency response framework to organize the aviation XML services to work cooperatively on mobile ad hoc networks (MANETs). A MANET is defined as a self-organized and rapidly deployed network of XML services in order to exchange information without using any pre-existing fixed network infrastructure. Note that the framework does not have to be limited to the aviation sector. The methodology can also be adopted into other MANET computing scenarios including: natural disaster communications (e.g., tsunami, earthquakes), emergency relief scenarios, car-based networks, and the provision of wireless connectivity in remote areas.
Teodor Sommestad, Casey K. Fung, Patrick C. K. Hung
ICWS4
2008 Guest Editors' Introduction
George Yee, Ali A. Ghorbani 0001, Patrick C. K. Hung
J. Comput. Secur.3
2008 Special issue on service intelligence and service science (SISS)
Dickson K. W. Chiu, Patrick C. K. Hung, Ho-fung Leung
Serv. Oriented Comput. Appl.2
2008 Guest Editorial Foreword to the Special Issue on Enterprise Services Computing and Industrial Applications
abstract
The two review papers and four regular papers in this special issue focus on enterprise computing and industrial applications.
Patrick C. K. Hung, Markus Aleksy, Zoran Milosevic
IEEE Trans. Syst. Man Cybern. Part C1
2007 A Virtual Travel Agent System for M-Tourism with Semantic Web Service Based Design and Implementation
abstract
With the recent advances in Internet and mobile technologies and infrastructures, there are increasing demands for ubiquitous access to tourist information systems for service coordination and integration. However, disparate tourist information and service resources such as airlines, hotels, tour operators, etc., make it difficult for tourist to use them effectively when planning their trips and/or during their trips. Motivated by the emerging technologies of multi-agent information system (MAIS) and its ability to aid Internet and mobile users, together with semantic Web that can effectively organize information and service resources. In this paper, we propose a virtual travel agent system (VTAS), which is built upon these technologies. In this paper, we formulate a scalable, flexible, and intelligent MAIS architecture for VTAS with agent clusters based on a case study of a large service-oriented travel agency. Agent clusters may comprise several types of agents to achieve the goals of the major processes of a tourist's trip. We show how agents can make use of ontology from the semantic web help tourists better plan, understand, and specify their requirements. We further illustrate how this can be successfully implemented with Web service technologies to integrate disparate Internet tourist resources.
Yves T. F. Yueh, Dickson K. W. Chiu, Ho-fung Leung, Patrick C. K. Hung
AINA4
2007 Developing a Distributed e-Monitoring System for Enterprise Website and Web Services: An Experience Report with Free Libraries and Tools
abstract
Enterprises value monitoring as it provides dependable e-services, whether it is an interactive Web site or programmatic Web service. However, this task becomes non-trivial when enterprises begin to require support from thousands of servers across geographical areas. How can the communications between a monitoring systems and remote servers be minimized? Could the task be achieved easily based on a readily available technology such as SNMP? How can we monitor thousands of servers powered by, say, Tomcat, which lacks SNMP support? How may a poorly responsive site be identified prior to being reported as a failure by SNMP? In this paper, we propose a unified e-monitoring system that enables system administrators to remotely monitor the health of distributed e-services in both the form of Web site and Web services. We further discuss our implementation experience based on a pragmatic prototype.
Frank K. W. Cheong, Dickson K. W. Chiu, Shing-Chi Cheung, Patrick C. K. Hung
ICWS4
2007 Web Services Security and Privacy
abstract
Web services are becoming widely deployed to implement the automation of business processes such as supply chain management, inventory tracking, and healthcare management, just to name a few. A Web service is a new breed of web application that supports interoperable application-to-application interaction over a network based on a set of XML standards.
Patrick C. K. Hung, Casey K. Fung
ICWS1
2007 WS-CDL+: An Extended WS-CDL Execution Engine for Web Service Collaboration
abstract
Web services are becoming the prominent paradigm for distributing, computing, and electronic business, while there is an increasing surge to provide online business- to-business collaborations. The Web services choreography description language (WS-CDL) is a Web service specification developed by W3C, in order to provide peer-to-peer collaborations for participants from different parties. Despite the great research interests it has received during recent years, no practical or even prototype execution engine has been built for WS-CDL, which is, however, essential to test and evaluate the properties of WS-CDL when doing research on it, and promote its application fields in business. This paper implements an execution engine of WS-CDL, which has never been built before, and experiments on the functionalities and performance of the engine. We also address the extensions toward WS-CDL, namely WS- CDL+, which are built into our execution engine. Finally, the whole paper is concluded, addressing the application perspectives of WS-CDL/WS-CDL+.
Zuling Kang, Patrick C. K. Hung
ICWS3
2007 A New Approach to Describe Web Services
abstract
This paper is based on the theory of Finite State Automata (FSA's), models a web service as a FSA, extends WSDL for conceptually describing the behaviors of Web services, and introduces the concept of Temporal Logic of Actions (short for TLA) to describe and specify the behavior of a service in a formal way.
Chen Wang 0015, Patrick C. K. Hung
Web Intelligence4
2007 Toward a Service-Oriented Development Through a Case Study
abstract
The rapidly emerging technology of Web services paves a new cost-effective way of engineering software to quickly develop and deploy Web applications by dynamically integrating other independently developed Web-service components to conduct new business transactions. This paper reports our efforts on designing and developing a Web service of pass-through authentication (PTA) for 12 online electronic-payment Web applications. In accordance with how a PTA service is developed and integrated with a corresponding back-end e-payment system, our strategies can be categorized in three stages: end-to-end integration stage, Web-services-enabled stage, and Web-services-oriented stage. Derived from real-world industrial experience, this three-stage pathway can be applied to a broad range of Web-application development projects to guide smooth transformation from a specific application-oriented design and development model toward a reusable Web-services-oriented model. Furthermore, this paper contributes to an engineering process that leads to practical Web-services-oriented software development. New research issues revealed by this project are also reported.
Jia Zhang 0001, Carl K. Chang, Liang-Jie Zhang, Patrick C. K. Hung
IEEE Trans. Syst. Man Cybern. Part A4
2006 Alert Based Monitoring of Stock Trading Systems
abstract
Nowadays stocks are traded electronically instead of manually with an open outcry approach. As a result, business activities of investment banking organizations rely heavily on the availability of their trading systems. Any system failure will directly affect their business and in turn damage their reputation. Due to the complexity of the business, trading of stock requires services provided by many systems even within the same company. Any failure of a single system may stop the business. However, the monitoring of many systems simultaneously is not an easy task. This paper proposes a Web service approach to monitor all the systems related to stock trading within an investment banking organization. We develop a model for specifying how to detect potential system problems quickly, how to escalate the issues to relevant parities on time with an alert mechanism, and how to manage system outages properly
Edward W. Y. Ho, Dickson K. W. Chiu, Patrick C. K. Hung
COMPSAC (1)3
2006 Security Conscious Web Service Composition
abstract
A Web service is a software system designed to support interoperable application-to-application interactions over the Internet. Web services are based on a set of XML standards, such as Web Services Description Language (WSDL), Simple Object Access Protocol (SOAP) and Universal Description, Discovery and Integration (UDDI). Recently, there has been a growing interest in Web service composition, and some languages (e.g., WSBPEL, BPML) for modeling the composition have been proposed. In this paper, we focus on security constraints of Web service composition, which have not been deeply investigated so far. We propose a method for modeling security constraints and a brokered architecture to build composite Web services according to the specified security constraints.
Barbara Carminati, Elena Ferrari 0001, Patrick C. K. Hung
ICWS3
2006 Dynamic Regeneration of Workflow Specification with Access Control Requirements in MANET
abstract
Distributed software systems are the basis for innovative applications. The key for achieving survivable and maintainable distributed systems is agility because the nondeterministic nature of distribution would otherwise leave the system uncontrollable, especially in emerging mobile ad-hoc networks. A mobile ad-hoc network (MANET) is based on a self-organizing and rapidly deployed network of mobile services to collaborate without using any pre-existing fixed network infrastructure. Survivability is defined as the capability of a service to fulfill its mission in a timely manner, even in the presence of attacks, failures, or accidents. There are four key survivability properties: resistance, recognition, recovery and adaptation. Recovery, a hallmark of survivability, is the capability to maintain critical components and resource during attack, limit the extent of damage, and restore full services following attack. Exception handling is a way to deals with the recovery aspect of survivability. Resistance can be viewed as the process of limiting access to critical and vulnerable resources only to authorized users, programs, processes, or other systems. This paper bridges the analysis of secure business process and its recovery aspect in terms of exception handling in the context of access control requirements. We propose an integrated approach to engineer a survivable distributed system through dynamic regeneration of workflow specifications in the context of Business Process Execution Language for Web Services (BPEL) and eXtensible Access Control Markup Language (XACML).
Casey K. Fung, Patrick C. K. Hung, William M. Kearns, Stephen A. Uczekaj
ICWS2
2006 Guest Editors' Introduction
Markus Aleksy, Patrick C. K. Hung, Zoran Milosevic
Int. J. Cooperative Inf. Syst.2
2005 Towards end-to-end privacy control in the outsourcing of marketing activities: a web service integration solution
abstract
With the recent adoption of marketing activities outsourcing, there have been increasing demands and concerns for privacy control. The traditional approach of a bulk transmission of the customers' information to a marketing company cannot meet such demands, especially in the finance and healthcare businesses. Therefore, we propose a layered architecture and a development methodology for end-to-end privacy control over the export of each individual customer's records through a Web services platform, according to the corresponding enterprise's privacy control policies. A Web services system, with up-dated security and privacy facilities, can provide a suitable interoperation platform for required application-to-application interactions over the Internet. We further develop a conceptual model and an interaction protocol to send only the required part of a customer's records at a time. We illustrate our approach for end-to-end privacy control with a tele-marketing case study and show how the software of the outsourced call center can be integrated effectively with the Web services of a bank to protect privacy. Copyright 2005 ACM.
Patrick C. K. Hung, Dickson K. W. Chiu, W. W. Fung, William Kwok-Wai Cheung, Raymond K. Wong 0001, Samuel P. M. Choi, Eleanna Kafeza, James T. Kwok, Joshua C. C. Pun, Vivying S. Y. Cheng
ICEC1
2005 A Study of Service Composition with QoS Management
abstract
Quality of service (QoS) management in compositions of services requires careful consideration of QoS characteristics of the services and effective QoS management in their execution. A Web service is a software system that supports interoperable application-to-application interaction over the Internet. Web services are based on a set of XML standards such as simple object access protocol (SOAP). The interactions of SOAP messages between Web services form the theoretical model of SOAP message exchange patterns (MEP). Web Services Business Process Execution Language (WSBPEL) defines an interoperable integration model that facilitates automated process integration in intra- and inter-corporate environments. A service-level agreement (SLA) is a formal contract between a Web services requestor and provider guaranteeing quantifiable issues at defined levels only through mutual concessions. Based on a prior research work on message detail record (MDR), this paper further proposes a SOAP message tracking model for supporting QoS end-to-end management in the context of WSBPEL and SLA. This paper motivates the study of QoS management in a Web service composition framework with the evolution of a distributed toolkit in an industrial setting.
Casey K. Fung, Patrick C. K. Hung, Guijun Wang, Richard C. Linger, Gwendolyn H. Walton
ICWS2
2005 Quality of Service Specification and Management for XML Web Services
abstract
Summary form only given. This tutorial will introduce the participants to the area of QoS specification and management for XML Web services. It will explain the importance of this topic and why the widely used basic Web service technologies are not enough. Further, it will give an overview of a number of languages developed for QoS specification for Web services, as well as a number of research infrastructures, industrial products, and standardization proposals that offer some forms of QoS management for Web services. The achieved results and open topics for future research will be critically analyzed.
Vladimir Tosic, Patrick C. K. Hung
ICWS2
2005 System Recovery through Dynamic Regeneration of Workflow Specification
abstract
Distributed software systems are the basis for innovative applications (e.g., pervasive computing, telecommunication services, and grid utility services). The key for achieving survivable and maintainable distributed systems is agility because otherwise the non-deterministic nature of distribution would leave the system uncontrollable. Survivability is defined as the capability of a service to fulfill its mission in a timely manner, even in the presence of attacks, failures, or accidents. Because of the severe consequences of failure, organizations are focusing on service survivability as a key risk management strategy for business processes. There are three key survivability properties: resistance, recognition, and recovery. Recovery, a hallmark of survivability, is the capability to maintain critical components and resource during attack, limit the extent of damage, and restore full services following attack. Exception handling is a way to deals with the recovery aspect of survivability. Business Process Execution Language for Web services (BPEL) has been proposed for formal specification of business processes and interaction protocols. BPEL defines an interoperable integration model that facilitates expansion of automated process integration in both intra- and inter-corporate environments. A business process description requires the specification of both the normal flow and the possible variations due to exceptional situations that can be anticipate and monitored. This paper bridges the analysis of business process survivability and its recovery aspect in terms of exception handling in the context of BPEL. We propose an integrated approach to engineer a survivable distributed system through dynamic regeneration of workflow specifications when the system encounters attacks and failures.
Casey K. Fung, Patrick C. K. Hung
ISORC2
2005 Towards a Privacy Access Control Model for e-Healthcare Services
Patrick C. K. Hung
PST1
2005 Developing e-Negotiation support with a meta-modeling approach in a Web services environment
Dickson K. W. Chiu, Shing-Chi Cheung, Patrick C. K. Hung, Sherina Y. Y. Chiu, Andriy K. K. Chung
Decis. Support Syst.3
2004 Towards Standardized Web Services Privacy Technologies
abstract
A Web service is defined as an autonomous unit of application logic that provides either some business functionality or information to other applications through an Internet connection. Web services are based on a set of XML standards such as universal description, discovery and integration (UDDI), Web services description language (WSDL), and simple object access protocol (SOAP). Recently there are increasing demands and discussions about Web services privacy technologies in the industry and research community. In general, privacy policies describe an organization's data practices what information they collect from individuals (e.g., consumers) and what (e.g., purposes) they do with it. To enable privacy protection for Web service consumers across multiple domains and services, the World Wide Web Consortium (W3C) published a document called "Web services architecture (WSA) requirements" that defines some specific privacy requirements for Web services as a future research topic. At this moment, there is still no standardized Web services privacy technology. This paper briefly overviews the research issues of Web services privacy technologies.
Patrick C. K. Hung, Elena Ferrari 0001, Barbara Carminati
ICWS1
2003 Implementing Watermark Token in WS-Security for Digital Content Distribution
Shing-Chi Cheung, Hanif Curreem, Dickson K. W. Chiu, Patrick C. K. Hung
ICWS4
2003 Developing e-Negotiation Process Support by Web Services
Dickson K. W. Chiu, Shing-Chi Cheung, Patrick C. K. Hung
ICWS3
2003 Workflow-Based Information Integration in a Web Services Environment
Patrick C. K. Hung, Dickson K. W. Chiu
ICWS1
2003 Illustrating Conflict of Interest Assertions in WS-Policy with a Financial Application Example
Guang-Sha Qui, Patrick C. K. Hung
ICWS2
2003 Through the Looking Glass: Towards A Formalization of Aggregation Issues in Health Data Integration (HDI)
Patrick C. K. Hung, Joseph Tan
J. Comput. Inf. Syst.1
2002 A Meta-model for e-Contract Template Variable Dependencies Facilitating e-Negotiation
Shing-Chi Cheung, Patrick C. K. Hung, Dickson K. W. Chiu
ER2
1999 Least Privilege Security in CapBasED-AMS
abstract
Workflow systems are becoming very popular and are being used to support many of the day to day activities in large organizations. One of the major problems with workflow systems is that they often use heterogeneous and distributed hardware and software systems to execute a given activity. This gives rise to decentralized security policies and mechanisms, which, in order to enable activity execution, give too many privileges (for accessing resources like documents) to the agents (humans or systems) for executing the work. We develop the concept of least priviledge, wherein the set of agents are given just enough privileges to complete the given activities. We develop our concepts in the context of CapBasED-AMS (Capability-based and Event-driven Activity Management System). The CapBasED-AMS deals with the management and execution of activities. An activity consists of multiple inter-dependent tasks (atomic activities, each executed by a single agent) that need to be coordinated, scheduled and executed by a set of agents. We formalize the concept of least privilege security and present algorithms to statically assign least privilege assignment to the agents. Further, we develop the concept of dynamic least privilege enforcement, wherein an agent is given its privileges only during the duration of the task for which those privileges were assigned. We also develop the concept of dynamic evolution of least privileges by taking into consideration the changes in the way resources are accessed by the agents in executing their tasks. Finally, we address the trade-off between resilience to agent failure and least privilege.
Patrick C. K. Hung, Kamalakar Karlapalem, James W. Gray III
Int. J. Cooperative Inf. Syst.1
1998 A Study of Least Privilege in CapBasED-AMS
abstract
Workflow systems are becoming very popular and are being used to support many of the day to day activities in large organizations. One of the major problems with workflow systems is that they often use heterogeneous and distributed hardware and software systems to execute a given activity. This gives rise to decentralized security policies and mechanisms, which, in order to enable activity execution, give too many privileges to agents (humans or systems) for executing the work. We develop the concept of least privilege, wherein the set of agents are given just enough privileges to complete the given activities. We develop our concepts in the context of CapBasED-AMS (Capability-based and Event-driven Activity Management System). CapBasED-AMS deals with the management and execution of activities. An activity consists of multiple inter-dependent tasks (atomic activities, each executed by a single agent) that need to be coordinated, scheduled and executed by a set of agents. We formalize the concept of least privilege and present algorithms to statically assign least privilege assignment to the agents. We develop the concept of dynamic least privilege enforcement, wherein an agent is given its privileges only during the duration of the task for which those privileges were assigned. Finally, we introduce a metric, security risk factor and use it to evaluate the trade-off between least privilege and resilience to agent failure.
Patrick C. K. Hung, Kamalakar Karlapalem, James W. Gray III
CoopIS1
1997 A Paradigm for Security Enforcement in CapBasED-AMS
abstract
The CapBasED-AMS (CAPability-BASed and Event-Driven Activity Management System) deals with the management and execution of activities. A problem-solving agent (PSA) is a human, a hardware system or a software system having the ability to execute activities. An activity consists of multiple interdependent tasks that need to be coordinated, scheduled and executed by a set of PSAs. Since security is an essential and integral part of activities, the activity management system has to manage and execute the activities in a secure way. In the CapBasED-AMS, threats such as unauthorized access or modification are identified as events. The security pilferage or illegal violation of privacy through the accessing of specification-time, compile-time or run-time data from the activity management system and the PSAs is monitored, controlled and reported. We present a secure CapBasED-AMS by taking into consideration: the system infrastructure; secure match-making with additional security constraints; security policies and a secure PSA; the task coordination model for security resource control from the PSA viewpoint, the organization viewpoint, the task viewpoint and the activity viewpoint by adapting a role-based resource security model; and secure execution of tasks with the PSA role-based security model.
Patrick C. K. Hung, Kamalakar Karlapalem
CoopIS1
1997 A Logical Framework for Security Enforcement in CAPBASED-AMS
abstract
The CapBasED-AMS (Capability-based and Event-driven Activity Management System) deals with the management and execution of activities. A Problem Solving Agent (PSA) is a human, or a hardware system, or a software system having an ability to execute activities. An activity consists of multiple inter-dependent tasks that need to be coordinated, scheduled and executed by a set of PSAs. Since security is essential and integral part of activities, the activity management system has to manage and execute the activities in a secure way. In the CapBasED-AMS, threats, such as, unauthorized access or modification are identified as events. In this paper, we develop a logical framework for security enforcement in CapBasED-AMS by taking into consideration the system infrastructure, secure match-making under security constraints, security policies and secure PSA, the task coordination model for security enforcement during activity execution.
Patrick C. K. Hung, Kamalakar Karlapalem
Int. J. Cooperative Inf. Syst.1
1996 CapBasED-AMS: A Capability-based and Event-driven Activity Management System
abstract
No abstract available.
Patrick C. K. Hung, Helen P. Yeung, Kamalakar Karlapalem
SIGMOD Conference1
1995 CapBasED-AMS - A Framework for Capability-Based and Event-Driven Activity Management System
Kamalakar Karlapalem, Helen P. Yeung, Patrick C. K. Hung
CoopIS3