VLDB 2026 Research / reviewers in the wild / expert
Hongli Zhang 0001
dblp:z/HongliZhang
· DBLP profile ↗
147ranked-venue papers
13as first author
59since 2021 · last 2026
0000-0002-8167-7106ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 64 · 10 first-author · 13 since 2021Artificial intelligence and machine learning · 24 · 18 since 2021Systems, architecture and hardware · 15 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 13 · 10 since 2021Security and privacy · 10 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 9 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TGCL: Target-aware Graph Contrastive Learning for Stance Detection
Chao Meng 0001, Hongli Zhang 0001, Gongzhu Yin, Kun Lu 0006, Binxing Fang |
ICC | 2 |
| 2026 | TriTSP: A triangular joint reasoning networks for target-stance prediction
Hongli Zhang 0001, Zeshu Tian, Chao Meng 0001 |
Comput. Speech Lang. | 2 |
| 2026 | Information-Maximized Optimal Transport for interpretable and robust unsupervised graph alignment
Zeshu Tian, Hongli Zhang 0001 |
Knowl. Based Syst. | 4 |
| 2026 | AdaptiveWordBug: Generating adversarial texts with an adaptive scoring strategy against deep learning classifiers
Yunting Zhang, Baisong Li, Hongli Zhang 0001 |
Neural Networks | 4 |
| 2026 | HIER: Heterogeneous Information Bottleneck and Expert Routing for Social Bot DetectionabstractSocial bots constitute a substantial fraction of active accounts on digital platforms, fundamentally threatening information authenticity and democratic discourse. Contemporary detection methods confront critical limitations: information imbalance across heterogeneous relations, computational challenges in processing massive neighborhoods, and inadequate multi-scale representation learning. We propose HIER (Heterogeneous Information Bottleneck and Expert Routing), a pioneering framework that integrates variational information theory with mixture-of-experts paradigms for social network analysis. HIER introduces relation-aware variational information bottleneck for optimal compression across relationship types, dynamic sparse expert routing that extends mixture-of-experts to edge-level graph processing, and dual-scale mutual information maximization enhancing representation discriminability through neighborhood consistency and graph-level contrastive learning. Experimental validation demonstrates HIER's superior performance across real-world datasets, establishing new benchmarks for heterogeneous social bot detection. Kun Lu 0006, Hongli Zhang 0001, Yuchen Yang 0004, Chao Meng 0001, Binxing Fang |
IEEE Signal Process. Lett. | 2 |
| 2026 | CL-DRW: Curriculum Learning-Based Deep Robust Watermarking for Social NetworksabstractThe development of the internet has greatly facilitated the transmission of images over social networks, while also triggering serious copyright issues. Deep robust watermarking serves as a crucial technique for image copyright protection. However, the image distortions caused by Social Network Transmission Operations (SNTOs) make existing deep robust watermarking methods fragile in real-world social network scenarios. To address this, we propose a Curriculum Learning-based Deep Robust Watermarking method, called CL-DRW, to generate watermarks that can be resilient to SNTOs. Specifically, we develop a watermarking model constructed with an invertible neural network and present a multi-stage training framework based on curriculum learning to train it effectively. We incrementally introduce noise attacks based on their disruptive impact on the watermark, from weak to strong, thereby enabling our model to build robustness against SNTOs gradually. Additionally, we design an SNTOs simulation noise layer, which is built upon a transformer-based deep network and incorporates differentiable JPEG, to simulate the black-box distortions caused by SNTOs. Extensive experiments indicate that our proposed CL-DRW outperforms state-of-the-art deep watermarking methods in terms of robustness against real-world social network transmission operations. Source code is available at https://github.com/yingshuai-zhao/CL-DRW. Yingshuai Zhao, Guopu Zhu, Jiantao Zhou 0001, Xiaolong Li 0001, Hongli Zhang 0001, Xinpeng Zhang 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 5 |
| 2026 | Test-Time Adaptation for Detecting Image Inpainting ForgeriesabstractThe rapid development of deep learning-based image inpainting poses serious challenges to image authenticity. As inpainting methods continue to evolve, the inpainted images exhibit extremely high visual fidelity, presenting recognition difficulties to the forgery detection model due to differences in operational mode and forgery traces among methods. In particular, the detection performance tends to drop significantly in the testing phase when the test samples differ from the training data. To address this issue, we propose a test-time adaptive detection framework for image inpainting forgeries. First, we propose an image gradient-based metric that quantifies model uncertainty and orchestrates the entire adaptation process. Integrating this metric with sample-specific batch normalization (BN) statistics enhances the ability of pretrained models in the inference stage. Second, we introduce a cross-attention module as a side-tuning module, enabling the model to adapt dynamically to reliable test samples without altering the backbone network. To validate the effectiveness of the proposed method, we construct a dataset comprising synthetic images of multiple inpainting methods and design experiments under two scenarios of distributional bias. The results demonstrate that our proposed framework outperforms the existing baseline method, enhancing the adaptability and detection performance of the forgery detection model in dynamic environments. Guopu Zhu, Hongli Zhang 0001, Xinpeng Zhang 0001, Yicong Zhou, Ligang Wu 0001 |
IEEE Trans. Cybern. | 3 |
| 2026 | SHL-Net: Semantics-Enhanced Network for Localizing Harmonized Image Splicing
Xiwen Fu, Guopu Zhu, Hongli Zhang 0001, Jiwu Huang, Tao Xiang 0001, Yicong Zhou, Ligang Wu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Information Disclosure Risk of Thumbnail-Preserving EncryptionabstractWith the rapid growth of cloud services, the storage of images in cloud environments requires secure and effective data encryption methods. Many thumbnail-preserving encryption (TPE) methods have thus been proposed to balance privacy and usability of image data. However, the exposure of thumbnail information in TPE methods may introduce privacy leakage risk, and a systematic evaluation of their security has not yet been conducted. In this paper, we propose a new Mamba-Transformer cooperation Network (MTNet) to recover the original images from the limited exposed thumbnail information, highlighting the information disclosure problem in TPE. Specifically, the core model component integrates a Mamba block and a Transformer block, which employ the powerful capabilities of the Mamba for wide field dependency modeling and the Transformer for effective channel interaction. Besides, the cascade architecture incorporates an intermediate output that provides supplementary information and achieves multilevel supervision, thereby improving the quality of the final output. Finally, to better utilize the subtle details in different levels, we propose a multi-scale fusion module that adaptively integrates features from various stages of the encoding process. The experimental results achieved by our proposed MTNet reveal that the privacy risk associated with TPE is significantly underestimated and more robust defense mechanisms are required. Source code is available athttps://github.com/HITLiXincodes/MTNet. Xin Li 0154, Guopu Zhu, Hongli Zhang 0001, Tao Xiang 0001, Xiangyang Luo 0001, Sam Kwong |
IEEE Trans. Multim. | 3 |
| 2026 | MHGCA: Multi-scale heterogeneous graph learning with content-structure alignment for social spammer detectionabstractSocial spammers pose a serious threat to online social networks by manipulating topics, promoting malicious campaigns, and spreading low-quality or deceptive content at scale. Existing detection methods, including text-based classifiers, graph neural networks, and hybrid models, still suffer from three key limitations: they usually operate at a single structural scale, they treat content and network structure as loosely coupled signals, and they often assign equal importance to all edges within the same relation type. To address these issues, we propose MHGCA, a M ulti-scale H eterogeneous G raph learning framework with C ontent–Structure A lignment for robust spammer detection. MHGCA jointly encodes motif-, community-, and global-level structures, detects structural anomaly patterns, and employs a relation-aware transformer to adaptively align content similarity with relation-specific message passing. Experiments on two real-world Twitter datasets show that MHGCA consistently outperforms strong baselines under severe class imbalance and limited supervision, and remains stable across different training ratios and hyperparameter settings. These results suggest that explicitly aligning content with multi-scale heterogeneous structures is crucial for reliable spammer detection in social networks. Kun Lu 0006, Hongli Zhang 0001, Yuchen Yang 0004, Gongzhu Yin, Binxing Fang |
World Wide Web (WWW) | 2 |
| 2025 | PwnGPT: Automatic Exploit Generation Based on Large Language ModelsabstractAutomatic exploit generation (AEG) refers to the automatic discovery and exploitation of vulnerabilities against unknown targets. Traditional AEG often targets a single type of vulnerability and still relies on templates built from expert experience. To achieve intelligent exploit generation, we establish a comprehensive benchmark using Binary Exploitation (pwn) challenges in Capture the Flag (CTF) competitions and investigate the capabilities of Large Language Models (LLMs) in AEG based on the benchmark. To improve the performance of AEG, we propose PwnGPT, an LLM-based automatic exploit generation framework that automatically solves pwn challenges. The structural design of PwnGPT is divided into three main components: analysis, generation, and verification modules. With the help of a modular approach and structured problem inputs, PwnGPT can solve challenges that LLMs cannot directly solve. We evaluate PwnGPT on our benchmark and analyze the outputs of each module. Experimental results show that our framework is highly autonomous and capable of addressing various challenges. Compared to direct input LLMs, PwnGPT increases the completion rate of exploit on our benchmark from 26.3% to 57.9% with the OpenAI o1-preview model and from 21.1% to 36.8% with the GPT-4o model. Wanzong Peng, Xuetao Du, Hongli Zhang 0001, Dongyang Zhan, Yunting Zhang, Yicheng Guo |
ACL (1) | 4 |
| 2025 | Ignite Forecasting with SPARK: An Efficient Generative Framework for Refining LLMs in Temporal Knowledge Graph Forecasting
Gongzhu Yin, Hongli Zhang 0001, Yuchen Yang 0004, Kun Lu 0006, Chao Meng 0001 |
DASFAA (2) | 2 |
| 2025 | GMCL: Graph-Enhanced Multimodal Contrastive Learning for Rumor DetectionabstractMultimedia rumor content has been widely disseminated with the rise of generative technologies. Existing rumor detection approaches typically focus independently on multi-modal data (such as text and images) or social structure analysis, and only a few researchers have attempted to integrate all three modalities for comprehensive rumor detection. Due to the complexity of the relationships between these heterogeneous data, combining them effectively remains a challenge. In this work, we present a novel Graph-Enhanced Multimodal Contrastive Learning (GMCL) to integrate textual, visual, and social graph features more efficiently for rumor detection. We utilize semantic correlation to assist cross-modal contrastive learning to capture fine-grained alignment between text and image and enhance node representations through graph contrastive learning without relying on negative samples. By aligning and integrating these different representations, our method can detect rumors more accurately. Extensive experimental results show that our model outperforms current state-of-the-art methods in multimodal rumor detection. Kun Lu 0006, Hongli Zhang 0001, Tianze Sun, Yuchen Yang 0004, Chao Meng 0001, Gongzhu Yin, Binxing Fang |
ICASSP | 2 |
| 2025 | Multi-Relation Aware Heterogeneous Graph Transformer for Robust Spammer Detection via Contrastive Learning in Social NetworksabstractThe rapid growth of social networks has significantly increased the prevalence of spammer activities, which poses substantial challenges to user trust, experience, and public safety. Existing spam detection methods primarily rely on easily circumvented handcrafted features and fail to capture the complexities of user behavior and social relationships fully. These methods often struggle to differentiate users in highly heterogeneous networks and do not adequately address the issue of class imbalance. To overcome these limitations, we propose a novel framework, Multi-Relation Aware Heterogeneous Graph Transformer (MRHGT), which effectively integrates heterogeneous graph representation learning to capture complex social structures. Our approach introduces a novel aggregation mechanism that combines relation-aware multi-head attention, relation-specific graph convolution networks, and cross-attention feature fusion. Additionally, we incorporate a heterogeneous graph contrastive learning strategy to handle class imbalance. Extensive experiments on real-world datasets demonstrate that our method outperforms state-of-the-art approaches in accuracy and robustness. Kun Lu 0006, Hongli Zhang 0001, Yuchen Yang 0004, Binxing Fang |
ICC | 2 |
| 2025 | Implicit Sign-Enhanced Stance Detection Model with Semantic Graph Attention NetworkabstractStance detection aims to automatically identify social users' attitudes on specific targets by analyzing their textual content and various relationships within social networks. Existing stance detection models predominantly focus on textual content. Although some stance detection methods based on graph neural networks have achieved performance improvements by integrating textual content and social relationships, they overlook the implicit polarity signs of links between nodes. Meanwhile, many real-world social networks do not provide explicit sign information for links, which limits the applicability of existing signed network representation learning methods to these scenarios. This paper proposes a novel social network stance detection model named 'Implicit Sign-enhanced Stance Detection Model with Semantic Graph Attention Network' (ISSDM-SemGAN). Firstly, we propose a semantic graph attention network (SemGAN) that leverages Direction-distance Fusion Scoring Function (DFSF) to enhance the differences between nodes, which lays the foundation for capturing implicit link signs. Additionally, we design implicit sign-enhanced stance detection network to introduce the signed link prediction task and social balance theory to facilitate understanding and learning the implicit link polarity between nodes, thereby enhancing the performance of stance detection tasks. Extensive experiments were conducted on real social network dataset. The experimental results demonstrate that ISSDM-SemGAN achieves state-of-the-art performance. Chao Meng 0001, Hongli Zhang 0001, Gongzhu Yin, Yuchen Yang 0004, Binxing Fang |
ICC | 2 |
| 2025 | Inductive Link Prediction on N-ary Relational Facts via Semantic Hypergraph ReasoningabstractN-ary relational facts represent semantic correlations among more than two entities. While recent studies have developed link prediction (LP) methods to infer missing relations for knowledge graphs (KGs) containing n-ary relational facts, they are generally limited to transductive settings. Fully inductive settings, where predictions are made on previously unseen entities, remain a significant challenge. As existing methods are mainly entity embedding-based, they struggle to capture entity-independent logical rules. To fill in this gap, we propose an n-ary subgraph reasoning framework for fully inductive link prediction (ILP) on n-ary relational facts. This framework reasons over local subgraphs and has a strong inductive inference ability to capture n-ary patterns. Specifically, we introduce a novel graph structure, the n-ary semantic hypergraph, to facilitate subgraph extraction. Moreover, we develop a subgraph aggregating network, NS-HART, to effectively mine complex semantic correlations within subgraphs. Theoretically, we provide a thorough analysis from the score function optimization perspective to shed light on NS-HART's effectiveness for n-ary ILP tasks. Empirically, we conduct extensive experiments on a series of inductive benchmarks, including transfer reasoning (with and without entity features) and pairwise subgraph reasoning. The results highlight the superiority of the n-ary subgraph reasoning framework and the exceptional inductive ability of NS-HART. Gongzhu Yin, Hongli Zhang 0001, Yuchen Yang 0004 |
KDD (1) | 2 |
| 2025 | Exploring and Exploiting the Resource Isolation Attack Surface of WebAssembly Containers
Zhaofeng Yu, Dongyang Zhan, Haining Yu, Hongli Zhang 0001, Zhihong Tian 0001 |
USENIX Security Symposium | 5 |
| 2025 | ChatGPT in threefold: As attacker, target, and evaluator in adversarial attacks
Yunting Zhang, Kai Tan 0007, Zeshu Tian, Baisong Li, Hongli Zhang 0001 |
Neurocomputing | 6 |
| 2025 | Stance classification model with knowledge-aware multi-feature attention network
Chao Meng 0001, Binxing Fang, Hongli Zhang 0001, Yuchen Yang 0004, Gongzhu Yin, Kun Lu 0006 |
Neural Comput. Appl. | 3 |
| 2025 | Paths in the cloud: Geolocation mapping of Amazon's cross-border connectivity
Yu Zhang 0036, Yunan Wang, Hongli Zhang 0001, Binxing Fang |
Peer Peer Netw. Appl. | 4 |
| 2025 | Sign-Aware Graph Learning Framework for Stance Detection
Chao Meng 0001, Hongli Zhang 0001, Gongzhu Yin, Binxing Fang |
IEEE Signal Process. Lett. | 2 |
| 2025 | Multi-Level Feature Fusion Network for Shadow Removal DetectionabstractBy now, many works have been done on shadow removal for image manipulation. As a result, detecting shadow removal has become a critical part to reveal the traces of image manipulation. However, there are only a few works conducted on shadow removal detection, and these works cannot accurately localize the image regions where the shadows have been removed. In this paper, we present a novel model called Multi-level Feature Fusion Network (MFF-Net) for shadow removal detection. MFF-Net consists of two parts: a dual-branch feature extraction encoder and a dense prediction decoder. The encoder anchors the approximate position of the manipulated regions, while the decoder progressively fills in the details of the estimated shadow masks by integrating multi-level information. In the encoder part, a global modeling branch is constructed to capture long-range dependencies, while a local feature extraction branch is designed to extract local structural information. The features extracted by these two branches are integrated using a feature fusion module. In the decoder part, a multi-scale feature upsampling module is proposed to upsample the input features and integrate them with the low-level features obtained from the encoder part. Meanwhile, the cross attention mechanism is introduced to guide the multi-level feature fusion process. Finally, the features of different resolutions are employed to estimate the shadow masks in a coarse-to-fine manner. Extensive experiments on shadow removal detection demonstrate the superiority of MFF-Net over the state-of-the-art methods. The source code of MFF-Net is publicly available athttps://github.com/HITFuxiwen/MFF-Net. Xiwen Fu, Guopu Zhu, Hongli Zhang 0001, Xinpeng Zhang 0001, Anthony Tung Shuen Ho, Sam Kwong |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2025 | Anomaly Detection in Industrial Control Systems Based on Cross-Domain Representation LearningabstractIndustrial control systems (ICSs) are widely used in industry, and their security and stability are very important. Once the ICS is attacked, it may cause serious damage. Therefore, it is very important to detect anomalies in ICSs. ICS can monitor and manage physical devices remotely using communication networks. The existing anomaly detection approaches mainly focus on analyzing the security of network traffic or sensor data. However, the behaviors of different domains (e.g., network traffic and sensor physical status) of ICSs are correlated, so it is difficult to comprehensively identify anomalies by analyzing only a single domain. In this article, an anomaly detection approach based on cross-domain representation learning in ICSs is proposed, which can learn the joint features of multi-domain behaviors and detect anomalies within different domains. After constructing a cross-domain graph that can represent the behaviors of multiple domains in ICSs, our approach can learn the joint features of them by leveraging graph neural networks. Since anomalies behave differently in different domains, we leverage a multi-task learning approach to identify anomalies in different domains separately and perform joint training. The experimental results show that the performance of our approach is better than existing approaches for identifying anomalies in ICSs. Dongyang Zhan, Wenqi Zhang 0006, Xiangzhan Yu, Hongli Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | A high-performance real-time container file monitoring approach based on virtual machine introspection
Kai Tan 0007, Dongyang Zhan, Hongli Zhang 0001, Binxing Fang, Zhihong Tian 0001 |
J. Supercomput. | 4 |
| 2025 | Chinese legal adversarial text generation based on interpretable perturbation strategies
Yunting Zhang, Shang Li 0003, Baisong Li, Hongli Zhang 0001 |
World Wide Web (WWW) | 6 |
| 2024 | Multi-Stage Defense: Enhancing Robustness in Sequence-Based Log Anomaly DetectionabstractSequence-based deep learning models are commonly used to detect anomalies in system logs to ensure the security of communication and information systems. However, recent research has shown that adversarial attack methods against these detection models reveal their vulnerabilities. Attackers can bypass these sequence-based classifiers by tampering with the sequence (e.g., adding or replacing sequence events). In this paper, we propose a novel Multi-Stage Defensive strategy for sequence-based log anomaly detection aimed at combating adversarial attacks. Systematically integrated, this strategy spans the entire detection process, from data embedding representation to anomaly classification, thereby forming a robust defensive approach that is strategically orchestrated to ensure comprehensive protection against a variety of adversarial attacks. Firstly, we compress the semantic feature space of sequences to enhance the anti-interference ability of attack operations on substitution sequences. Then, we propose a novel adaptive sparse multi-head attention mechanism to improve the Transformer model, allowing it to adaptively extract different key patterns in the sequence, thus eliminating irrelevant sequence events added in adversarial sequences. Our approach also integrates the learning of temporal patterns, offering enhanced robustness against deletion operations. Through extensive experiments on two public datasets, the experimental results demonstrate that our approach has high detection performance and robustness against different adversarial attacks. Kai Tan 0007, Dongyang Zhan, Zhaofeng Yu, Hongli Zhang 0001, Binxing Fang |
ICC | 5 |
| 2024 | Reinforcement-Based Denoising for Crowdsourcing Named Entity Recognition in Social NetworksabstractCrowdsourced Named Entity Recognition (CNER) is an effective method in social network data mining, enabling the swift identification and categorization of vast textual data, thereby enhancing the understanding and analysis of user behaviors and communication patterns. However, the diversity of such data often leads to inconsistent annotation quality, compromising recognition accuracy. We propose a novel framework that synergizes reinforcement learning with multi-source domain adaptation to bolster the accuracy of social CNER. By filtering out low-quality instances and considering annotator reliability in the multi-source domain adaptation crowdsourcing method, our framework not only adapts to the varied quality of annotations but also mitigates the impact of annotation noise. Validated on both the social network crowdsourced benchmark dataset FMKKM11 and the general-purpose CoNLL03, our method consistently outperforms state-of-the-art methods in terms of model accuracy and noise robustness. Zeshu Tian, Hongli Zhang 0001, Yan Wang 0002 |
ICC | 2 |
| 2024 | Exploring trajectory embedding via spatial-temporal propagation for dynamic region representations
Hongli Zhang 0001, Guopu Zhu, Haotian Guan, Sam Kwong |
Inf. Sci. | 2 |
| 2024 | An efficient cheating-detectable secret image sharing scheme with smaller share sizes
Zuquan Liu, Guopu Zhu, Yu Zhang 0036, Hongli Zhang 0001, Sam Kwong |
J. Inf. Secur. Appl. | 4 |
| 2024 | Personalised soft prompt tuning in pre-trained language models: Bridging multitask transfer learning and crowdsourcing learning
Zeshu Tian, Hongli Zhang 0001, Yan Wang 0002 |
Knowl. Based Syst. | 2 |
| 2024 | Kalt: generating adversarial explainable chinese legal texts
Yunting Zhang, Shang Li 0003, Hongli Zhang 0001, Binxing Fang |
Mach. Learn. | 4 |
| 2024 | UCTT: universal and low-cost adversarial example generation for tendency classification
Yunting Zhang, Zeshu Tian, Hongli Zhang 0001, Baisong Li, Binxing Fang |
Neural Comput. Appl. | 5 |
| 2024 | A Practical Adversarial Attack Against Sequence-Based Deep Learning Malware ClassifiersabstractSequence-based deep learning models (e.g., RNNs), can detect malware by analyzing its behavioral sequences. Meanwhile, these models are susceptible to adversarial attacks. Attackers can create adversarial samples that alter the sequence characteristics of behavior sequences to deceive malware classifiers. The existing methods for generating adversarial samples typically involve deleting or replacing crucial behaviors in the original data sequences, or inserting benign behaviors that may violate the behavior constraints. However, these methods that directly manipulate sequences make adversarial samples difficult to implement or apply in practice. In this paper, we propose an adversarial attack approach based on Deep Q-Network and a heuristic backtracking search strategy, which can generate perturbation sequences that satisfy practical conditions for successful attacks. Subsequently, we utilize a novel transformation approach that maps modifications back to the source code, thereby avoiding the need to directly modify the behavior log sequences. We conduct an evaluation of our approach, and the results confirm its effectiveness in generating adversarial samples from real-world malware behavior sequences, which have a high success rate in evading anomaly detection models. Furthermore, our approach is practical and can generate adversarial samples while maintaining the functionality of the modified software. Kai Tan 0007, Dongyang Zhan, Hongli Zhang 0001, Binxing Fang |
IEEE Trans. Computers | 4 |
| 2024 | Impulse Noise Image Restoration Using Nonconvex Variational Model and Difference of Convex Functions AlgorithmabstractIn this article, the problem of impulse noise image restoration is investigated. A typical way to eliminate impulse noise is to use an$L_{1}$norm data fitting term and a total variation (TV) regularization. However, a convex optimization method designed in this way always yields staircase artifacts. In addition, the$L_{1}$norm fitting term tends to penalize corrupted and noise-free data equally, and is not robust to impulse noise. In order to seek a solution of high recovery quality, we propose a new variational model that integrates the nonconvex data fitting term and the nonconvex TV regularization. The usage of the nonconvex TV regularizer helps to eliminate the staircase artifacts. Moreover, the nonconvex fidelity term can detect impulse noise effectively in the way that it is enforced when the observed data is slightly corrupted, while is less enforced for the severely corrupted pixels. A novel difference of convex functions algorithm is also developed to solve the variational model. Using the variational method, we prove that the sequence generated by the proposed algorithm converges to a stationary point of the nonconvex objective function. Experimental results show that our proposed algorithm is efficient and compares favorably with state-of-the-art methods. Benxin Zhang, Guopu Zhu, Hongli Zhang 0001, Yicong Zhou, Sam Kwong |
IEEE Trans. Cybern. | 4 |
| 2023 | Enhancing LSTM and Fusing Articles of Law for Legal Text Summarization
Hongli Zhang 0001 |
ICONIP (14) | 3 |
| 2023 | Beyond Individuals: Modeling Mutual and Multiple Interactions for Inductive Link Prediction between GroupsabstractLink prediction is a core task in graph machine learning with wide applications. However, little attention has been paid to link prediction between two group entities. This limits the application of the current approaches to many real-life problems, such as predicting collaborations between academic groups or recommending bundles of items to group users. Moreover, groups are often ephemeral or emergent, forcing the predicting model to deal with challenging inductive scenes. To fill this gap, we develop a framework composed of a GNN-based encoder and neural-based aggregating networks, namely the Mutual Multi-view Attention Networks (MMAN). First, we adopt GNN-based encoders to model multiple interactions among members and groups through propagating. Then, we develop MMAN to aggregate members' node representations into multi-view group representations and compute the final results by pooling pairwise scores between views. Specifically, several view-guided attention modules are adopted when learning multi-view group representations, thus capturing diversified member weights and multifaceted group characteristics. In this way, MMAN can further mimic the mutual and multiple interactions between groups. We conduct experiments on three datasets, including two academic group link prediction datasets and one bundle-to-group recommendation dataset. The results demonstrate that the proposed approach can achieve superior performance on both tasks compared with plain GNN-based methods and other aggregating methods. Gongzhu Yin, Hongli Zhang 0001, Chao Meng 0001, Yuchen Yang 0004, Kun Lu 0006 |
WSDM | 3 |
| 2023 | Multi-label classification of legal text based on label embedding and capsule network
Shang Li 0003, Hongli Zhang 0001 |
Appl. Intell. | 4 |
| 2023 | Securing Operating Systems Through Fine-Grained Kernel Access Limitation for IoT SystemsabstractWith the development of Internet of Things (IoT), it is gaining a lot of attention. It is important to secure the embedded systems with low overhead. The Linux Seccomp is widely used by developers to secure the kernels by blocking the access of unused syscalls, which introduces less overhead. However, there are no systematic Seccomp configuration approaches for IoT applications without the help of developers. In addition, the existing Seccomp configuration approaches are coarse-grained, which cannot analyze and limit the syscall arguments. In this article, a novel static dependent syscall analysis approach for embedded applications is proposed, which can obtain all of the possible dependent syscalls and the corresponding arguments of the target applications. So, a fine-grained kernel access limitation can be performed for the IoT applications. To this end, the mappings between dynamic library APIs and syscalls according with their arguments are built, by analyzing the control flow graphs and the data dependency relationships of the dynamic libraries. To the best of our knowledge, this is the first work to generate the fine-grained Seccomp profile for embedded applications. Dongyang Zhan, Zhaofeng Yu, Xiangzhan Yu, Hongli Zhang 0001, Likun Liu |
IEEE Internet Things J. | 4 |
| 2023 | An Adversarial Robust Behavior Sequence Anomaly Detection Approach Based on Critical Behavior Unit LearningabstractSequential deep learning models (e.g., RNN and LSTM) can learn the sequence features of software behaviors, such as API or syscall sequences. However, recent studies have shown that these deep learning-based approaches are vulnerable to adversarial samples. Attackers can use adversarial samples to change the sequential characteristics of behavior sequences and mislead malware classifiers. In this paper, an adversarial robustness anomaly detection method based on the analysis of behavior units is proposed to overcome this problem. We extract related behaviors that usually perform a behavior intention as a behavior unit, which contains the representative semantic information of local behaviors and can be used to improve the robustness of behavior analysis. By learning the overall semantics of each behavior unit and the contextual relationships among behavior units based on a multilevel deep learning model, our approach can mitigate perturbation attacks that target local and large-scale behaviors. In addition, our approach can be applied to both low-level and high-level behavior logs (e.g., API and syscall logs). The experimental results show that our approach outperforms all the compared methods, which indicates that our approach has better performance against obfuscation attacks. Dongyang Zhan, Kai Tan 0007, Xiangzhan Yu, Hongli Zhang 0001 |
IEEE Trans. Computers | 5 |
| 2023 | CNN-Transformer Based Generative Adversarial Network for Copy-Move Source/ Target DistinguishmentabstractCopy-move forgery can be used for hiding certain objects or duplicating meaningful objects in images. Although copy-move forgery detection has been studied extensively in recent years, it is still a challenging task to distinguish between the source and the target regions in copy-move forgery images. In this paper, a convolutional neural network-transformer based generative adversarial network (CNN-T GAN) is proposed to distinguish the source and target regions in a copy-move forged image. A generator is first utilized to generate a mask that is similar to the groundtruth mask. Then, a discriminator is trained to discriminate the true image pairs from the false ones. When the discriminator cannot discriminate the true/false image pairs accurately, the generator can be used to obtain the final localization maps of copy-move forgery. In the generator, convolutional neural network (CNN) and transformer are exploited to extract the local features and global representations in copy-move forgery images, respectively. In addition, feature coupling layers are designed to integrate the features in CNN branch and transformer branch in an interactive way. Finally, a new Pearson correlation layer is introduced to match the similarity features in source and target regions, which can improve the performance of copy-move forgery localization, especially the localization performance on source regions. To the best of our knowledge, this is the first work to utilize transformer for feature extraction in copy-move forgery localization. The proposed method can not only detect the copy-move regions, but also distinguish the source and target regions. Extensive experimental results on several commonly used copy-move datasets have shown that the proposed method outperforms the state-of-the-art methods for copy-move detection. Yulan Zhang, Guopu Zhu, Xiangyang Luo 0001, Yicong Zhou, Hongli Zhang 0001, Ligang Wu 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 6 |
| 2023 | pSafety: Privacy-Preserving Safety Monitoring in Online Ride Hailing ServicesabstractOnline Ride Hailing (ORH) services gain remarkable development in the past decade, which enable riders and drivers to establish optimized rides via mobile device. To guarantee user safety, ORH service providers often monitor the ride trajectory and report the abnormal behavior once a trajectory deviation occurs. Along with the advantage of safety monitoring raises some vital privacy concerns on user location information leakage. In this paper, we propose a privacy-preserving safety monitoring scheme for ORH services, called pSafety. It enables an ORH service provider to detect user’s trajectory deviation without learning anything about users’ locations. In pSafety, we propose two secure trajectory similarity computation algorithms by using somewhat homomorphic encryption, which are used to plan an agreed path and measure trajectory deviation, respectively. Furthermore, we also design a ciphertext compression algorithm and a secure comparison protocol to improve efficiency. Theoretical analysis and experimental evaluations show that pSafety is secure, accurate and efficient. Haining Yu, Hongli Zhang 0001, Xiaohua Jia, Xiangzhan Yu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Estimating the Secret Key of Spread Spectrum Watermarking Based on Equivalent KeysabstractThe security of spread spectrum (SS) watermarking largely depends on the difficulty of estimating its secret key. Some estimators have been proposed to estimate the secret key in the known-message attack (KMA) scenario. However, the estimation accuracies of existing estimators are not satisfactory when the number of observations is not large enough. Currently, it is still a challenging and open problem to design more effective estimators. In this paper, we propose an equivalent keys (EK)-based estimator to estimate the secret key for both the traditional and more secure SS watermarking methods. Equivalent keys form an equivalent region, which is the intersection of a unit hypersphere and a hypercone. According to the Monte Carlo simulation, we find that the secret key can be estimated by adding up the equivalent keys uniformly sampled from the equivalent region. Thus, the proposed estimator selects equivalent keys from randomly-generated vectors by exploiting the pairs of watermarked signals and their embedded messages. A theoretical analysis is performed for the proposed estimator to evaluate the estimation accuracy. Experimental results verify the theoretical analysis and show the superiority of the proposed estimator over existing estimation methods. Furthermore, this paper also shows the insecurity of the more secure SS watermarking methods in the KMA scenario from a practical perspective for the first time. Jinkun You, Yuan-Gen Wang, Guopu Zhu, Ligang Wu 0001, Hongli Zhang 0001, Sam Kwong |
IEEE Trans. Multim. | 5 |
| 2023 | Higher-Order Community Detection: On Information Degeneration and Its EliminationabstractCommunity detection aims to identify the cohesive vertex sets in a network. It is widely used in many domains, e.g., World Wide Web, online social networks, and communication networks. Many clustering models are proposed in the literature. However, most of them are designed directly on the original structure of a network, they usually achieve low accuracy in practice, since real-world networks are presenting fuzzy community structures. Recently, higher-order network units are introduced to community detection, these models typically define a higher-order hypergraph, where communities are extracted. Although the higher-order models are effective in terms of accuracy, many essential edges are completely eliminated or trivialized in the hypergraph. To address the problem, we propose a novel connectivity pattern with a mixture of standard edges and higher-order connections, whereby we define biased personalized PageRank diffusion for local community detection and develop a local approach to compute the PageRank vectors. Moreover, we present a higher-order seeding strategy to derive the starting seeds. Extensive experiments demonstrate that the proposed framework largely outperforms the approaches in the state of the art in terms of accuracy. Hongli Zhang 0001, Xiangzhan Yu |
IEEE/ACM Trans. Netw. | 2 |
| 2023 | Shrinking the Kernel Attack Surface Through Static and Dynamic Syscall LimitationabstractLinux Seccomp is widely used by the program developers and the system maintainers to secure the operating systems, which can block unused syscalls for different applications and containers to shrink the attack surface of the operating systems. However, it is difficult to configure the whitelist of a container or application without the help of program developers. Docker containers block about only 50 syscalls by default, and lots of unblocked useless syscalls introduce a big kernel attack surface. To obtain the dependent syscalls, dynamic tracking is a straight-forward approach but it cannot get the full syscall list. Static analysis can construct an over-approximated syscall list, but the list contains many false positives. In this paper, a systematic dependent syscall analysis approach, sysverify, is proposed by combining static analysis and dynamic verification together to shrink the kernel attack surface. The semantic gap between the binary executables and syscalls is bridged by analyzing the binary and the source code, which builds the mapping between the library APIs and syscalls systematically. To further reduce the attack surface at best effort, we propose a dynamic verification approach to intercept and analyze the security of the invocations of indirect-call-related or rarely invoked syscalls with low overhead. Dongyang Zhan, Zhaofeng Yu, Xiangzhan Yu, Hongli Zhang 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | ErrHunter: Detecting Error-Handling Bugs in the Linux Kernel Through Systematic Static AnalysisabstractError handling is essential for operating systems, thus, there are many bugs in error-handling code, which could result in serious consequences. In this paper, we revisit the problem of error miss-handling bugs and analyze the root cause of the most common ones in the Linux kernel. Based on the analysis, we propose a systematic static taint-analysis-based approach, ErrHunter, to detect multiple kinds of error miss-handling bugs in the Linux kernel. An automated critical variable identification approach is proposed to identify critical variables in the error-handling paths. A static cross-control-flow taint analysis approach is proposed to construct critical-variable control flow graphs (CCFGs), which describe the processing of critical variables in separate control flows. Based on the CCFGs, ErrHunter can target the root cause of the most common error miss-handling bugs and detect the bugs in a systematic way. ErrHunter is designed for kernel bug detection, so it can handle many specific features of the Linux kernel, such as memory management mechanisms, etc. Dongyang Zhan, Xiangzhan Yu, Hongli Zhang 0001 |
IEEE Trans. Software Eng. | 3 |
| 2022 | DWBFT: A Weighted Byzantine Fault Tolerant Protocol with Decentralized TrustabstractThe surprising wave of blockchain has led to rapid progress of Byzantine fault tolerant protocol. However, most researches concentrate on the centralized trust such as PBFT, in which all participants trust each other equally. This paper presents DWBFT, a weighted Byzantine fault tolerant protocol with decentralized trust under the weak synchrony assumption. In DWBFT, the nodes can assign weights to each other depending on their decentralized trust relationship, which are adopted to make decisions. DWBFT can achieve safety under the condition that the weight of Byzantine nodes is less than 1/5 of the total weight of all nodes under any weight assignment. The experimental results show that DWBFT can achieve a throughput of nearly 13,000 tps under 32 nodes, and has no significant performance degradation compared with PBFT. Chuanwang Ma, Yu Zhang 0036, Binxing Fang, Hongli Zhang 0001 |
ICC | 4 |
| 2022 | Graph clustering using triangle-aware measures in large networks
Xiangzhan Yu, Hongli Zhang 0001 |
Inf. Sci. | 3 |
| 2022 | A progressive learning method on unknown protocol behaviors
Fanghui Sun, Shen Wang 0004, Hongli Zhang 0001 |
J. Netw. Comput. Appl. | 3 |
| 2022 | Cost-effective CNNs-based prototypical networks for few-shot relation classification across domains
Gongzhu Yin, Hongli Zhang 0001 |
Knowl. Based Syst. | 3 |
| 2022 | Reversible Data Hiding for Color Images Based on Adaptive 3D Prediction-Error Expansion and Double Deep Q-NetworkabstractReversible data hiding (RDH) for color images has attracted increasing attention in recent years. Due to its effective utilization of the correlation between prediction errors, high-dimensional prediction-error expansion (PEE) can achieve much better performance for color image RDH than low-dimensional PEE. However, existing studies only focus on high-dimensional PEE with nonadaptive embedding. To further improve the embedding performance for color images, we propose a novel three-dimensional PEE method that is adaptive to image content. Double deep Q-network (DDQN), introduced to RDH for the first time, is adopted to find the optimal mapping paths for PEE. In addition, an action selection scheme is presented for DDQN to efficiently find the reversible mapping paths. Extensive experiments show that the proposed method outperforms existing color image RDH methods in image quality. Guopu Zhu, Hongli Zhang 0001, Yicong Zhou, Xiangyang Luo 0001, Ligang Wu 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2022 | Multi-Task SE-Network for Image Splicing LocalizationabstractImage splicing can be easily used for illegal activities such as falsifying propaganda for political purposes and reporting false news, which may result in negative impacts on society. Hence, it is highly required to detect spliced images and localize the spliced regions. In this work, we propose a multi-task squeeze and excitation network (SE-Network) for splicing localization. The proposed network consists of two streams, namely label mask stream and edge-guided stream, both of which adopt convolutional encoder-decoder architecture. The information from the edge-guided stream is transmitted to the label mask stream for enhancing the discrimination of features between the spliced and host regions. This work has three main contributions. First, image edges, along with label masks and mask edges, are exploited to supply more comprehensive supervision for the localization of spliced regions. Second, the low-level feature maps extracted from shallow layers are fused with the high-level feature maps from deep layers to provide more reliable feature for splicing localization. Finally, several squeeze and excitation attention modules are incorporated into the network to recalibrate the fused features to enhance the feature expression. Extensive experiments show that the proposed multi-task SE-Network outperforms existing splicing localization methods evidently on two synthetic splicing datasets and four benchmark splicing datasets. Yulan Zhang, Guopu Zhu, Ligang Wu 0001, Sam Kwong, Hongli Zhang 0001, Yicong Zhou |
IEEE Trans. Circuits Syst. Video Technol. | 5 |
| 2022 | Toward Physical Layer Security and Efficiency for SAGIN: A WFRFT-Based Parallel Complex-Valued Spectrum Spreading ApproachabstractSpace-air-ground integrated network (SAGIN), as an integration of interconnected space, air, and ground network segments, is expected to see prevalent usage as part of intelligent transportation systems (ITS), providing an enhanced service provision in terms of coverage, flexibility and reliability. However, restricted by the limited and unbalanced network resources, the efficiency and security of the underlying connectivities of SAGIN are of utmost concern for ITS applications. In this paper, a weighted fractional Fourier transform (WFRFT) based parallel complex spreading (PCS) approach is proposed to improve the communication efficiency and security of SAGIN at the physical (PHY-) layer. The concept of WFRFT along with the direct sequence spread spectrum technology establish the security kernel of the proposed scheme. The practicability of the complex-valued WFRFT-spreading architecture is verified by studying the correlation properties of the WFRFT-spreading signals. Taking advantages of the signal uniqueness of WFRFT, the proposed scheme is capable of providing more flexibility in signal characteristic control. Moreover, the complex-valued WFRFT-spreading processing makes the proposed scheme inherently robust against the large Doppler shift distortions in SAGIN. Simulation results demonstrate the superiority of the proposed WFRFT-PCS scheme in terms of communication efficiency and PHY-layer security. Finally, as a proof of concept, an all-digital FPGA prototype system is designed to show the practicability and the performance enhancement of the proposed scheme. Xiaojie Fang, Zhaopeng Du, Xinyu Yin, Lei Liu 0031, Xuejun Sha, Hongli Zhang 0001 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2022 | Secure Task Offloading in Blockchain-Enabled Mobile Edge Computing With Deep Reinforcement LearningabstractMobile Edge Computing (MEC) is a promising and fast-developing paradigm that provides cloud services at the edge of the network. MEC enables IoT devices to offload and execute their real-time applications at the proximity of these devices with low latency. Such applications include efficient manufacture inspection, virtual/augmented reality, image recognition, Internet of Vehicles (IoV), and e-Health. However, task offloading experiences security and privacy attacks such as data tampering, private data leakage, data replication, etc. To this end, in this paper, we propose a new blockchain-based framework for secure task offloading in MEC systems with guaranteed performance in terms of execution delay and energy consumption. First, blockchain technology is introduced as a platform to achieve data confidentiality, integrity, authentication, and privacy of task offloading in MEC. Second, we formulate an integration model of resource allocation and task offloading for a multi-user with multi-task MEC systems to optimize the energy and time cost. This is an NP-hard problem because of the curse-of-dimensionality and dynamic characteristics challenges of the considered scenario. Therefore, a deep reinforcement learning-based algorithm is developed to derive the close-optimal task offloading decision efficiently. Theoretical analysis and experimental results demonstrate that the proposed framework is resilient to several task offloading security attacks and it can save about 22.2% and 19.4% of system consumption with respect to the local and edge execution scenarios. Moreover, the benchmark analysis proves that the framework consumes few resources in terms of memory and disk usage, CPU utilization, and transaction throughput. Ahmed Samy, Ibrahim A. Elgendy, Haining Yu, Weizhe Zhang, Hongli Zhang 0001 |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2022 | Efficient and Privacy-Preserving Ride Matching Using Exact Road Distance in Online Ride Hailing ServicesabstractOnline Ride Hailing (ORH) services enable a rider to request a taxi via a smartphone app in real time. When using ORH services, users (including riders and taxis) have to submit their locations to the ORH server. With received locations, the ORH server makes online ride matching between riders and taxis. There are serious privacy concerns for users to reveal location information to ORH servers. In this article, we propose an efficient and privacy-preserving ride matching scheme for ORH services, named EPRide. EPRide can find the taxi with the minimum road distance to serve an incoming rider, while protecting the location information of both taxis and riders against ORH servers or other curious servers. In EPRide, we propose an efficient exact shortest road distance computation approach over encrypted data, which converts road distance computation into Hamming distance computation over packed ciphertexts by using road network hypercube embedding and somewhat homomorphic encryption. Meanwhile, we design a secure comparison protocol, which efficiently compares encrypted distances in parallel by using ciphertexts blinding and packing, without leaking any distance. Theoretical analysis and experimental evaluations show that EPRide is secure, accurate and efficient. Haining Yu, Xiaohua Jia, Hongli Zhang 0001, Jiangang Shu |
IEEE Trans. Serv. Comput. | 3 |
| 2021 | TenLa: an approach based on controllable tensor decomposition and optimized lasso regression for judgement prediction of legal cases
Xiaoding Guo, Hongli Zhang 0001, Shang Li 0003 |
Appl. Intell. | 2 |
| 2021 | Overlapping community detection by constrained personalized PageRank
Xiangzhan Yu, Hongli Zhang 0001 |
Expert Syst. Appl. | 3 |
| 2021 | PGRide: Privacy-Preserving Group Ridesharing Matching in Online Ride Hailing ServicesabstractAn online ride hailing (ORH) service creates a typical supply-and-demand two-sided market, which enables riders and drivers to establish optimized rides conveniently via mobile applications. Group ridesharing is a novel form of ridesharing, which allows a group of riders to share a vehicle that holds the minimum aggregate distance to the whole group. Accompanied by the advantage of ORH services, there comes some vital privacy concerns. In this article, we propose a privacy-preserving online group ridesharing matching scheme for ORH services, called PGRide. PGRide can select the nearest driver to serve a group of riders, without leaking the location privacy of both riders and drivers. In PGRide, we propose an encrypted aggregate distance computation approach by using somewhat homomorphic encryption with ciphertexts packing, which efficiently computes the aggregate distances from a group of riders to large-scale dynamic drivers in encrypted form. Meanwhile, we design a secure minimum selection protocol by using ciphertexts packing and blinding, which efficiently finds the minimum element from a set of encrypted integers without leaking any actual element value. Theoretical analysis and performance evaluations prove that PGRide is secure, accurate, and efficient. Haining Yu, Hongli Zhang 0001, Xiangzhan Yu, Xiaojiang Du, Mohsen Guizani |
IEEE Internet Things J. | 2 |
| 2021 | PSRide: Privacy-Preserving Shared Ride Matching for Online Ride Hailing SystemsabstractOnline Ride Hailing (ORH) has extensively made our trip more convenient. With mobile devices, riders can request taxis through ORH systems in a short time. However, to enjoy ORH services, users need to submit their location information to ORH systems, which raises serious privacy concerns. In this paper, we study the privacy leakage of online ridesharing matching, a more complex and economy ORH service that allows riders to share rides with others, and propose a privacy-preserving shared ride matching scheme, called PSRide. PSRide can find the taxi with the minimum additional travel time to serve a new rider based on its existing schedule, while protecting the location privacy of both riders and taxis. In PSRide, we propose a zone-based minimum road travel time estimation approach and a secure comparison protocol to efficiently optimize the schedules of taxis for a new rider over encrypted data. We implement PSRide and analyze it thoroughly. Theoretical analysis and experimental evaluations show that PSRide is secure and efficient for ORH systems. Haining Yu, Xiaohua Jia, Hongli Zhang 0001, Xiangzhan Yu, Jiangang Shu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Blockchain-Based DNS Root Zone Management Decentralization for Internet of ThingsabstractDomain Name System (DNS) is a widely used infrastructure for remote control and batch management of IoT devices. As a critical Internet infrastructure, DNS is structured as a tree‐like hierarchy with single root zone authority at the top, which puts the operation of DNS at risk from single point of failure. The current root zone management is lack of transparency and accountability, since only the root zone file is published as the final outcome of operations inside the root zone authority. Towards distributed root zone operation in DNS, this paper presents a blockchain‐based root operation architecture—RootChain, composed of multiple root servers. On the basis of maintaining the single root authority for top‐level domain (TLD), RootChain decentralizes TLD data publication by empowering delegated TLD authorities to publish authenticated data directly. The transparency and accountability of root zone operation are attained by smart‐contracting the whole life cycle of TLD operation and logging all operations on the chain. RootChain is transparent to recursive/stub resolver and DNS/DNSSEC‐compatible. A proof‐of‐concept prototype of RootChain has been implemented with Hyperledger Fabric and evaluated by experiments. Yu Zhang 0036, Zhongda Xia, Zhongze Wang, Weizhe Zhang, Hongli Zhang 0001, Binxing Fang |
Wirel. Commun. Mob. Comput. | 7 |
| 2020 | A secure domain name resolution and management architecture based on blockchainabstractThe domain name system (DNS) is the infrastructure of many services and applications, thus the availability and consistency of the domain name resolution process are crucial but have long troubled DNS. The availability problem is caused by a denial-of-service (DoS) attack or a single point of failure (SPOF). The consistency problem originates from the lack of a forced data synchronization mechanism between authoritative server replicas or between parent/child authoritative servers. We proposed a novel blockchain-based domain name resolution and management architecture named FI-DNS to solve the above problems fundamentally. FI-DNS solves availability and consistency problems in the name resolution process from the mechanism level and guarantees the authenticity and integrity of name resolution results by using public-key cryptography. FIDNS also supports root zone collaborative management based on smart contracts, which is compatible with the current governance model led by Internet Corporation for Assigned Names and Numbers (ICANN). We implemented the prototype system to prove the feasibility and effectiveness of the FI-DNS architecture. We built an experimental environment with real domain name data, evaluated the name resolution performance and stability of the FI-DNS prototype system, and compared the prototype system with DNS. Yu Zhang 0036, Hongli Zhang 0001, Binxing Fang |
ISCC | 5 |
| 2020 | Clustering of unknown protocol messages based on format comparison
Fanghui Sun, Shen Wang 0004, Chunrui Zhang 0002, Hongli Zhang 0001 |
Comput. Networks | 4 |
| 2020 | Predicting the security threats on the spreading of rumor, false information of Facebook content based on the principle of sociology
Binxing Fang, Hongli Zhang 0001 |
Comput. Commun. | 3 |
| 2020 | Physical-Layer Authentication for Internet of Things via WFRFT-Based Gaussian Tag EmbeddingabstractInternet of Things (IoT) is regarded as the fundamental platform for many emerging services, such as smart city, smart home, and intelligent transportation systems. With ever-increasing penetration of IoT, it becomes of great importance to ensure the IoT security, as the security threats are extended from the cyber world to the physical world. In this article, we investigate physical-layer authentication to help verify the identity of IoT entities for preventing unauthorized access to information or service. Specifically, we propose a Gaussian-tag-embedded physical-layer authentication (GTEA) scheme by using a weighted fractional Fourier transform (WFRFT). Through the superimposition of a low-power Gaussian WFRFT tag onto the message signal, the legitimate receiver can verify the authenticity of the received signal at the physical layer, without being detected by adversaries. Moreover, security analysis shows that with the deliberately designed Gaussian tag, the GTEA scheme is robust against spoofing and replaying attacks. In addition, tradeoff analysis and simulation results are provided to demonstrate the capability of the GTEA scheme in achieving reliability of the message delivery, stealth of the embedded tag signal, and balancing the tradeoff among the robustness of user authentication. Moreover, a prototype is further developed using FPGA and experiments are conducted to demonstrate the effectiveness and performance improvement of the proposed GTEA scheme. Ning Zhang 0007, Xiaojie Fang, Ye Wang 0002, Shaohua Wu 0002, Huici Wu, Dulal C. Kar, Hongli Zhang 0001 |
IEEE Internet Things J. | 7 |
| 2020 | Uncovering overlapping community structure in static and dynamic networks
Xiangzhan Yu, Hongli Zhang 0001 |
Knowl. Based Syst. | 3 |
| 2020 | Hail the Closest Driver on Roads: Privacy-Preserving Ride Matching in Online Ride Hailing ServicesabstractOnline ride hailing (ORH) services enable a rider to request a driver to take him wherever he wants through a smartphone app on short notice. To use ORH services, users have to submit their ride information to the ORH service provider to make ride matching, such as pick-up/drop-off location. However, the submission of ride information may lead to the leakages of users’ privacy. In this paper, we focus on the issue of protecting the location information of both riders and drivers during ride matching and propose a privacy-preserving online ride matching scheme, called pRMatch. It enables an ORH service provider to find the closest available driver for an incoming rider over a city-scale road network, while protecting the location privacy of both riders and drivers against the ORH service provider and other unauthorized participants. In pRMatch, we compute the shortest road distance over encrypted data by using road network embedding and partially homomorphic encryption and further efficiently compare encrypted distances by using ciphertext packing and shuffling. The theoretical analysis and experimental results demonstrate that pRMatch is accurate and efficient, yet preserving users’ location privacy. Haining Yu, Hongli Zhang 0001, Xiangzhan Yu |
Secur. Commun. Networks | 2 |
| 2019 | No Way to Evade: Detecting Multi-Path Routing Attacks for NIDSabstractIn order to protect intranet security, the enterprises or organizations usually deploy one or multiple NIDS at ingress points. Each works independently and monitors the complete TCP flow. That said, a malicious signature to be detected can only be obtained from a TCP flow. Drawing on the feature, an attacker can split malicious signature into multiple substrings and transfer them in different flows to evade detection, which is named multi-path routing attack. In particular, the emerging new technology Multi-Path TCP (MPTCP) offers a hotbed for such attacks. To monitor multi-path routing attacks, this literature proposed a distributed asynchronous NIDS detection model (DANDM) which consists of three algorithms. In this model, each NIDS scans its own received data packets independently and the adjacent contents between two data packets with consecutive sequence numbers. For the latter, all NIDS scans cooperatively through broadcast state information. To demonstrate the validity of our model, we take attack density and number of segmented signatures as parameters to compare with Ma's algorithm.The results show that the performance of our DANDM is significantly better than that of Ma's, especially in the case of large number of segmented signatures. Likun Liu, Hongli Zhang 0001, Xiangzhan Yu |
GLOBECOM | 3 |
| 2019 | EDCleaner: Data Cleaning for Entity Information in Social NetworkabstractThe application of social network has produced a large amount of entity data in different formats, which accompanied by problems such as data offset and attribute missing. The existing research on dealing with multiple data scenarios and accuracy performance is insufficient. To solve the problem of data cleaning, EDCleaner is carried out on transforming entity information into structured data with attribute labeling. The method of attribute recognition and data normalization for semi-structured data is proposed in EDCleaner, which efficiently identifies the attribute tag relationship of data and obtains the structured data with uniform specifications. Furthermore, a data cleaning model with active learning extension is established. The machine learning classifier is used to further improve the accuracy of attribute recognition, and finally form an efficient and accurate data cleaning method. Experimental results show that EDCleaner improves the cleaning accuracy and other performing indicators of entity information and exceeds the level of state of the art. Hongli Zhang 0001, Binxing Fang, Gongzhu Yin, Ximiao Yu |
ICC | 2 |
| 2019 | A Low-Overhead Kernel Object Monitoring Approach for Virtual Machine IntrospectionabstractMonitoring kernel object modification of virtual machine is widely used by virtual-machine-introspection-based security monitors to protect virtual machines in cloud computing, such as monitoring dentry objects to intercept file operations, etc. However, most of the current virtual machine monitors, such as KVM and Xen, only support page-level monitoring, because the Intel EPT technology can only monitor page privilege. If the out-of-virtual-machine security tools want to monitor some kernel objects, they need to intercept the operation of the whole memory page. Since there are some other objects stored in the monitored pages, the modification of them will also trigger the monitor. Therefore, page-level memory monitor usually introduces overhead to related kernel services of the target virtual machine. In this paper, we propose a low-overhead kernel object monitoring approach to reduce the overhead caused by page-level monitor. The core idea is to migrate the target kernel objects to a protected memory area and then to monitor the corresponding new memory pages. Since the new pages only contain the kernel objects to be monitored, other kernel objects will not trigger our monitor. Therefore, our monitor will not introduce runtime overhead to the related kernel service. The experimental results show that our system can monitor target kernel objects effectively only with very low overhead. Dongyang Zhan, Huhua Li, Hongli Zhang 0001, Binxing Fang, Xiaojiang Du |
ICC | 4 |
| 2019 | Element-Aware Legal Judgment Prediction for Criminal Cases with Confusing ChargesabstractLegal judgment prediction (LJP) plays an important role in legal assistant systems and aims to provide feasible judgment suggestions, including the charges, applicable law articles, and prison term. In practice, there exist many confusing charges which result in the decline of LJP performance of the existing works. To address this issue, we introduce the legal constitutive elements as the discriminative features to distinguish confusing charges. We propose an element-driven attentive neural network model, EDA-NN, which takes the textual description of a criminal case as the input and learns both element-free and element-aware case representations. Moreover, the element-driven attention mechanism is incorporated with the hierarchical sequence encoders, to generate crucial representations oriented to the legal constitutive elements at both the word and sentence levels. With the concatenation of element-free and element-aware representations, the EDA-NN can jointly predict the legal constitutive elements and judgment results. The experiments are conducted on a real-world dataset of criminal cases in mainland China. The experimental results demonstrate that our approach significantly outperforms all the baseline models on the LJP task for criminal cases with confusing cases. Shang Li 0003, Hongli Zhang 0001, Binxing Fang |
ICTAI | 4 |
| 2019 | Unsupervised field segmentation of unknown protocol messages
Fanghui Sun, Shen Wang 0004, Chunrui Zhang 0002, Hongli Zhang 0001 |
Comput. Commun. | 4 |
| 2019 | SAVM: A practical secure external approach for automated in-VM managementabstractSummary In‐VM management is usually needed by cloud service providers for cloud management, which includes monitoring the in‐VM application running state, reconfiguring VM system settings, etc. In‐VM management is also very useful in green cloud computing, because it provides the abilities of in‐VM monitoring, VM reconfiguration, performance measurement, etc. Leveraging a shell or an in‐VM agent to manage VMs is faced with generality and security challenges. In this paper, we propose a secure automated in‐VM management approach, ie, SAVM, which likes a hypervisor‐based shell managing the VMs in an out‐of‐box way. To bridge the semantic gap, we reuse the target VM's system calls to process the semantic information automatically. More importantly, we introduce a secure instruction fetch approach to enhance the system security. As a result, SAVM does not rely on the target VM's kernel integrity. In addition, we also present a dummy process selection and a system call injection method to further enhance the system security and transparency. After the implementation, we evaluate the prototype. The experimental results show that SAVM can achieve most of the in‐VM management operations. Furthermore, SAVM can work correctly under the target VM attacked by several popular rootkits. Dongyang Zhan, Binxing Fang, Hongli Zhang 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2019 | Imbalanced learning based on adaptive weighting and Gaussian function synthesizing with an application on Android malware detection
Ying Pang, Lizhi Peng, Bo Yang 0001, Hongli Zhang 0001 |
Inf. Sci. | 5 |
| 2019 | Learning Users' Intention of Legal Consultation through Pattern-Oriented Tensor Decomposition with Bi-LSTMabstractOnline legal consultation plays an increasingly important role in the modern rule-of-law society. This study aims to understand the intention of legal consultation of users with different language expressions and legal knowledge background. A critical issue is a method through which users’ legal consultation data are classified and the feature of each category is extracted. Traditional classification methods rely considerably on lexical and syntactic features and frequently require strict sentence formatting, which eliminates substantial energy and may not be universally applicable. We aim to extract the patterns of users’ consultation on different categories, which minimally depend on lexical, syntax, and sentence formatting. However, research in this area has rarely been conducted in previous legal advisory service studies. In this study, a classification approach for multiclass users’ intention based on pattern-oriented tensor decomposition and Bi-LSTM is proposed, and each user’s legal consulting statement is expressed as a tensor. Moreover, we propose a pattern-oriented tensor decomposition method that can obtain a core tensor that approximates the patterns of users’ consultation. These patterns can improve the accuracy of classifying users’ intention of legal consultation. We use Bi-LSTM to automatically learn and optimize these patterns. Evidently, Bi-LSTM with a pattern-oriented tensor decomposition layer performs better than a recurrent neural network only. Results show that our method is more accurate than the previous work, and the factor matrix and core tensor calculated by the pattern-oriented tensor decomposition are interpretable. Xiaoding Guo, Hongli Zhang 0001, Shang Li 0003 |
Wirel. Commun. Mob. Comput. | 2 |
| 2018 | BPDS: A Blockchain Based Privacy-Preserving Data Sharing for Electronic Medical RecordsabstractElectronic medical record (EMR) is a crucial form of healthcare data, currently drawing a lot of attention. Sharing health data is considered to be a critical approach to improve the quality of healthcare service and reduce medical costs. However, EMRs are fragmented across decentralized hospitals, which hinders data sharing and puts patients' privacy at risks. To address these issues, we propose a blockchain based privacy-preserving data sharing for EMRs, called BPDS. In BPDS, the original EMRs are stored securely in the cloud and the indexes are reserved in a tamper-proof consortium blockchain. By this means, the risk of the medical data leakage could be greatly reduced, and at the same time, the indexes in blockchain ensure that the EMRs can not be modified arbitrarily. Secure data sharing can be accomplished automatically according to the predefined access permissions of patients through the smart contracts of blockchain. Besides, the joint-design of the CP-ABE-based access control mechanism and the content extraction signature scheme provides strong privacy preservation in data sharing. Security analysis shows that BPDS is a secure and effective way to realize data sharing for EMRs. Hongli Zhang 0001, Xiaojiang Du, Mohsen Guizani |
GLOBECOM | 4 |
| 2018 | A high-performance virtual machine filesystem monitor in cloud-assisted cognitive IoT
Dongyang Zhan, Hongli Zhang 0001, Binxing Fang, Huhua Li, Yang Liu 0039, Xiaojiang Du, Mohsen Guizani |
Future Gener. Comput. Syst. | 3 |
| 2018 | JPEG image width estimation for file carvingabstractImage width is an important factor for making the partially recovered data perceptually meaningful in image file carving. The authors conduct a comprehensive comparison of the performance of the representative methods for estimating the JPEG image width. Experimental results show that the best methods based on pixels are always better than the best methods based on quantised discrete cosine transform (DCT) coefficients. To keep the good performance of the pixel‐based methods when the correct quantisation tables are unavailable, the authors replace the correct quantisation tables with the standard ones. Experimental results certify that such a replacement has only a little effect on the performance of the pixel‐based methods, the best of which still outperform the best methods based on quantised DCT coefficients. The two results indicate that it may be enough to just focus on the pixel‐based methods for future work. Finally, they propose a pixel‐based method, which derives the candidate image widths from the most likely adjacent minimum coded unit (MCU) pairs in the vertical direction. The candidate width which appears most frequently is chosen as the estimated image width. Experimental results show that the proposed method usually has the best performance when most MCUs of an image are recovered. Xianyan Wu, Qi Han 0002, Xiamu Niu, Hongli Zhang 0001, Siu-Ming Yiu |
IET Image Process. | 4 |
| 2018 | User-perceived quality aware adaptive streaming of 3D multi-view video plus depth over the internet
Nabin Kumar Karn, Hongli Zhang 0001, Feng Jiang 0001 |
Multim. Tools Appl. | 2 |
| 2018 | Checking virtual machine kernel control-flow integrity using a page-level dynamic tracing approach
Dongyang Zhan, Binxing Fang, Hongli Zhang 0001, Xiaojiang Du |
Soft Comput. | 4 |
| 2018 | Towards Privacy Preserving Publishing of Set-Valued Data on Hybrid CloudabstractStorage as a service has become an important paradigm in cloud computing for its great flexibility and economic savings. However, the development is hampered by data privacy concerns: data owners no longer physically possess the storage of their data. In this work, we study the issue of privacy-preserving set-valued data publishing. Existing data privacy-preserving techniques (such as encryption, suppression, generalization) are not applicable in many real scenes, since they would incur large overhead for data query or high information loss. Motivated by this observation, we present a suite of new techniques that make privacy-aware set-valued data publishing feasible on hybrid cloud. On data publishing phase, we propose a data partition technique, named extended quasi-identifierpartitioning (EQI-partitioning), which disassociates record terms that participate in identifying combinations. This way the cloud server cannot associate with high probability a record with rare term combinations. We prove the privacy guarantee of our mechanism. On data querying phase, we adopt interactive differential privacy strategy to resist privacy breaches from statistical queries. We finally evaluate its performance using real-life data sets on our cloud test-bed. Our extensive experiments demonstrate the validity and practicality of the proposed scheme. Hongli Zhang 0001, Xiaojiang Du |
IEEE Trans. Cloud Comput. | 1 |
| 2018 | An Efficient Security System for Mobile Data MonitoringabstractDuring the last decade, rapid development of mobile devices and applications has produced a large number of mobile data which hide numerous cyber‐attacks. To monitor the mobile data and detect the attacks, NIDS/NIPS plays important role for ISP and enterprise, but now it still faces two challenges, high performance for super large patterns and detection of the latest attacks. High performance is dominated by Deep Packet Inspection (DPI) mechanism, which is the core of security devices. A new TTL attack is just put forward to escape detecting, such that the adversary inserts packet with short TTL to escape from NIDS/NIPS. To address the above‐mentioned problems, in this paper, we design a security system to handle the two aspects. For efficient DPI, a new two‐step partition of pattern set is demonstrated and discussed, which includes first set‐partition and second set‐partition. For resisting TTL attacks, we set reasonable TTL threshold and patch TCP protocol stack to detect the attack. Compared with recent produced algorithm, our experiments show better performance and the throughput increased 27% when the number of patterns is 106. Moreover, the success rate of detection is 100%, and while attack intensity increased, the throughput decreased. Likun Liu, Hongli Zhang 0001, Xiangzhan Yu, Yi Xin 0002, Muhammad Shafiq 0003, Mengmeng Ge 0003 |
Wirel. Commun. Mob. Comput. | 2 |
| 2017 | An approximate search framework for big dataabstractIn the age of big data, a traditional scanning search pattern is gradually becoming unfit for a satisfying user experience due to its lengthy computing process. In this paper, we propose a sampling-based approximate search framework called Hermes, to meet user's query demand for both accurate and efficient results. A novel metric, (ε,δ)-approximation, is presented to uniformly measure accuracy and efficiency for a big data search service, which enables Hermes to work out a feasible searching job. Based on this, we employ the bootstrapping technique to further speed up the search process. Moreover, an incremental sampling strategy is investigated to process homogeneous queries; in addition, the reuse theory of historical results is also studied for the scenario of appending data. Theoretical analyses and experiments on a real-world dataset demonstrate that Hermes is capable of producing approximate results meeting the preset query requirements with both high accuracy and efficiency. Shang Li 0003, Hongli Zhang 0001, Binxing Fang |
ICC | 3 |
| 2017 | Succinct and practical greedy embedding for geometric routing
Yanbin Sun, Yu Zhang 0036, Binxing Fang, Hongli Zhang 0001 |
Comput. Commun. | 4 |
| 2017 | A fast feature weighting algorithm of data gravitation classification
Lizhi Peng, Hongli Zhang 0001, Haibo Zhang 0001, Bo Yang 0001 |
Inf. Sci. | 2 |
| 2016 | LPPS: Location privacy protection for smartphonesabstractLocation-based service (LBS) is useful for many applications. However, LBS has raised serious concerns about users' location privacy. Utilizing the computation and storage capacity of smart phones, we propose a novel system architecture, called Location Privacy Protection for Smartphone (LPPS), to provide a privacy-preserving top-k query. LPPS does not rely on a trust third party (TTP), nor does it requires LBS servers to change their business model. The main idea of LPPS is to rank the Points of Interests (POIs) on the client side of the application using a small amount of metadata and then to make a request to the LBS server for real-time and detailed information about the POIs. Based on LPPS, we propose a novel metric called location indistinguishability to evaluate the privacy level of users in the proposed scheme. Then, we propose two dummy-POI selection algorithms to generate a superset of the actual top-k POIs when the query cannot meet the privacy requirement. Our experimental results demonstrate the validity and practicality of the proposed schemes. Hongli Zhang 0001, Zhikai Xu, Xiangzhan Yu, Xiaojiang Du |
ICC | 1 |
| 2016 | CAPR: context-aware participant recruitment mechanism in mobile crowdsourcingabstractAbstract With the advances of sensing, wireless communication, and mobile computing, mobile crowdsourcing has become a new paradigm for data collection and retrieval that has attracted considerable attention. This paper addresses the fundamental research issue in mobile crowdsourcing: Which participants should be selected as winners in each time slot with the aim of maximizing the total utility of the service provider in the long term? First, a double‐sided combinatorial auction model is introduced to describe the relationships between the mobile users and requesters from the perspective of supply and demand at a given time. Then, the coupling between the utility values of the system in different time slots is investigated. Based on the aforementioned analyses, this paper proposes a context‐aware participant recruitment mechanism, in which the mobile crowdsourcing system dynamically adjusts the participant recruitment mechanism depending on the ratio between the numbers of mobile users and requesters. Context‐aware participant recruitment consists of two main components: (1) a heuristic algorithm based on the greedy strategy to determine the winning participants and (2) a critical payment scheme, which guarantees the rationality of the proposed mechanism. Finally, extensive simulations demonstrate that the proposed mechanism achieves high system utility in the long term. Copyright © 2016 John Wiley & Sons, Ltd. Hongli Zhang 0001, Zhikai Xu, Xiaojiang Du |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | Cuckoo: flexible compute-intensive task offloading in mobile cloud computingabstractAbstract Mobile cloud computing (MCC) is an emerging technology to facilitate complex application execution on mobile devices. Mobile users are motivated to implement various tasks using their mobile devices for great flexibility and portability. However, such advantages are challenged by the limited battery life of mobile devices. This paper presents Cuckoo, a scheme of flexible compute‐intensive task offloading in MCC for energy saving. Cuckoo seeks to balance the key design goals: maximize energy saving (technical feasibility) and minimize the impact on user experience with limited cost for offloading (realistic feasibility). Specifically, using a combination of static analysis and dynamic profiling, compute‐intensive tasks are fine‐grained marked from mobile application codes offline. According to the network transmission technologies supported in mobile devices and the runtime network conditions, adopting “task‐bundled” strategy online offloads these tasks to MCC. In the task‐hosted stage, we propose a skyline‐based online resource scheduling strategy to satisfy the realistic feasibility of MCC. In addition, we adopt resource reservation to reduce the extra energy consumption caused by the task multi‐offloading phenomenon. Further, we evaluate the performance of Cuckoo using real‐life data sets on our MCC testbed. Our extensive experiments demonstrate that Cuckoo is able to balance energy consumption and execution performance. Copyright © 2016 John Wiley & Sons, Ltd. Hongli Zhang 0001, Xiaojiang Du |
Wirel. Commun. Mob. Comput. | 2 |
| 2015 | Geometric Routing on Flat Names for ICNabstractThis paper presents Griffin, a scheme of geometric routing on flat names to conduct massive content distribution and retrieval. A tree-based metric space T is proposed according to the concept of hierarchical division of symbol space. In Griffin, the network topology is embedded into the T-space, and content names are mapped to the T-space. Content publication and retrieval are supported by geometric routing in the T-space. Different from previous embedding schemes, Griffin constructs the T-space according to the network topology before embedding. In contrast to prior name resolution schemes, Griffin operates directly on the network topology without establishing an overlay. The correctness of Griffin is proved by the greediness of geometric routing. The experiments by simulation demonstrate that Griffin is efficient and scalable. Yanbin Sun, Yu Zhang 0036, Hongli Zhang 0001, Binxing Fang, Xiaojiang Du |
GLOBECOM | 3 |
| 2015 | A novel stochastic-encryption-based P2P Digital Rights Management schemeabstractDigital right protection in P2P systems is attracting more and more attentions. In this paper, we present a new stochastic-encryption-based Digital Rights Management (DRM) scheme for P2P content delivery networks. The files are encrypted such that unpaid users cannot access the plaintext content. We exploit the random characteristics of P2P to increase the key space, which can defense collusion attacks. We add piece validation policy during a download process to prevent poisoning attacks. In our scheme, peers make a payment after downloading, and this prevents user loss due to download failures (caused by the dynamics of P2P). Our scheme does not have frequent user authentications or state maintenance. Analysis and simulation experiments show that our scheme can defend against collusion attacks and poisoning attacks with a fairly high probability. Majing Su, Hongli Zhang 0001, Xiaojiang Du, Qiong Dai |
ICC | 2 |
| 2015 | Towards real-time route leak events detectionabstractMalicious attack and misconfiguration can cause unreachable websites, network outages, and other damages. Such incidents are usually observed together with anomalous AS paths which violate a “valley-free” policy. Existing techniques to infer routing policy cannot satisfy industrial demand of real-time route leak detection because they are very likely to trigger false positives. In this paper, we propose an online detection scheme dedicated to detect route leak AS paths. Based on long-lived routing paths, and route anomalous concurrency, we manage to filter possible false positives in online scenarios. Applying this scheme to Oregon's routing data from 2009 to 2013, we detect 136 route leak events. Our evaluation shows that our scheme triggers no false positives, and most of these events are previously unknown to the research and operation communities at large. Shen Su, Beichuan Zhang 0001, Hongli Zhang 0001, Nathan Yee |
ICC | 4 |
| 2015 | Effective task scheduling in proximate mobile device based communication systemsabstractDespite the increasing capabilities, mobile devices still cannot satisfy the computation requirement of many applications. Intuitively, this can be solved by outsourcing tasks to external resources such as a remote server, cloud, or closely deployed cloudlet. However, all of them require extra infrastructures. In this paper, we consider a proximate-mobile-device based communication system in which all tasks and resources are under the control of a central scheduler. We propose a friendship-based task scheduling algorithm to address the contentions when resources are not sufficient. We also present two attack models including the denial-of-service (DoS) attack and the collusion attack. We evaluate the performance of the proposed algorithm along with another contribution-based task scheduling algorithm through extensive experiments. Longfei Wu, Xiaojiang Du, Hongli Zhang 0001, Wei Yu 0002, Chonggang Wang |
ICC | 3 |
| 2015 | Matrix-based parallel pattern matching methodabstractThis study presents pattern matching algorithms, based on vector and matrix models that are suitable for parallel pattern matching. On these two models, we further proposed the vector-based single-pattern matching (VBSP) and the matrix-based multi-pattern matching (MBMP) algorithms, as well as the matrix-based multi-pattern approximate (MBMPA) algorithm and the matrix-based multi-pattern exact (MBMPE) algorithm. The G-MBMP algorithm refers to the implementation of the MBMP algorithm on a graphics processing unit (GPU). The performance of the G-MBMPA is better than that of the G-impMASM. The performance of the G-MBMPE is better than that of the G-WM (GPU-based WM algorithm) and that of the G-AC algorithms (GPU-based AC algorithm). The memory of the G-MBMPE algorithm is the least of the three algorithms and is significantly less than that of the G-AC algorithm. Hongli Zhang 0001, Dongliang Xu, Lei Zhang 0065, Yanbin Sun |
ICC | 1 |
| 2015 | CLPP: Context-aware location privacy protection for location-based social networkabstractLocation-based social network (LBSN) has grown exponentially over the past several years. Given its high utility value, LBSN, however, has raised serious concerns about users' location privacy. Although users may avoid releasing geo-content in sensitive locations, this, however, does not necessarily prevent the adversary from inferring users' privacy through spatial-temporal correlations and historical information. In this paper, we introduce a new location privacy problem: context-aware location privacy protection (CLPP) problem where the privacy requirements of users are not constant and isolated. We propose a novel metric to quantify the privacy risks. Then the CLPP is formalized as how to accurately and efficiently evaluate whether the users' published geo-content meet the user's privacy requirement. To achieve online evaluating, we design two novel algorithms to calculate the correlation between the locations. Eventually, our experimental results demonstrate the validity and practicality of the proposed strategy. Hongli Zhang 0001, Zhikai Xu, Xiaojiang Du |
ICC | 1 |
| 2015 | Continuous resource allocation in cloud computingabstractWith the advent of cloud computing, more and more enterprises and individuals are motivated to outsource their local complex applications into the cloud for its great flexibility and economic savings. For cloud server, however, the problem of how to optimize scheduling cloud resources to maximize the resource utilization and incorporate energy optimization is not trivial. In this paper, we present a continuous resource allocation strategy to solve this issue. Specifically, we first map all the remaining resources of the cloud into a ZBtree. Based on this, we propose an efficient resource allocation strategy for processing cloud resource requests, which adopts minimal domination matching as the greedy strategy to navigate the tradeoff space. Moreover, to reduce the rate of application migration, we propose a continuous monitoring strategy which adopts a resource reserve scheme to reduce the probability of application migration to the maximum extent. The extensive experiments further demonstrate the validity of the proposed mechanism with low computation overhead. Hongli Zhang 0001, Xiangzhan Yu, Junwu Guo |
ICC | 2 |
| 2015 | Audit meets game theory: Verifying reliable execution of SLA for compute-intensive program in cloudabstractCloud computing provides convenient on-demand computing resources which enables users to outsource their computational tasks to the cloud. However, users lose direct control of tasks, which inevitably causes new challenges: users have no way to audit whether the cloud server provides services along the service level agreement (SLA). To this end, we present an audit model based on cloud service broker (CSB) that can verify the reliable execution of SLA for compute-intensive program in cloud. Specifically, we propose a program structure mapping model called concept tree, which transforms the target application into a tree structure. Then, we split it into several independent computable units. Based on this, CSB can fine-grained audit the task execution process in cloud by comparing the running time and the similarity of the computable units. We also adopt game theory to motivate the credible implementation of SLA, in addition to defend against the semi-honest cloud model. We implement our scheme on Hadoop and the extensive experiments demonstrate that our scheme has the high prediction accuracy. Hongli Zhang 0001, Xiangzhan Yu, Junwu Guo |
ICC | 2 |
| 2015 | An efficient parallel algorithm for exact multi-pattern matchingabstractAbstract This paper presents a parallel algorithm Parallel Extended Bloom Filter (PEBF) for exact multi‐pattern matching based on Bloom filter. To improve the throughput and parallelism of the algorithm, we divided the pattern set intoNsubsets where the length of patterns is the same, and different subsets would not intersect each other. We construct an EBF for each subset and useNthreads to simultaneously process the subsets in parallel. We implement our solution on the graphics processing unit, called G‐PEBF. Experimental results demonstrate that PEBF performs better than the Wu–Manber (WM) algorithm in terms of time and space. And G‐PEBF outperforms the G‐WM (WM algorithm implemented on graphics processing unit). The speedup of G‐PEBF is up to 60 times at peak performance and almost 10 times at worst performance to the PEBF algorithm. Copyright © 2014 John Wiley & Sons, Ltd. Hongli Zhang 0001, Dongliang Xu, Zhihong Tian 0001, Yujian Fan |
Secur. Commun. Networks | 1 |
| 2014 | Modeling Leechers attack in BitTorrentabstractAs one of the most widely-used Peer-to-Peer applications, BitTorrent system has gained a lot of successes in last decade. BitTorrent has been extensively studied in the literature. However, few research studies vulnerabilities of BitTorrent, and the abuses of BitTorrent have already impeded the wide adoption of the system. In this paper, we study a common attack on BitTorrent - the Leechers attack, which tries to take over valid connections of legitimate users without paying for them. It is harmful to a swarm if certain percentage of users perform the selfish behavior. We present an analytical model for the Leechers attack and we use the model to estimate the distribution of valid connections. Our model discovers the important factors that determine how harmful the attack is, and it can quantitatively predict the duration of downloading process under the attack. The real-world experimental results match well with our model, which demonstrates that the model is correct and useful. Hongli Zhang 0001, Xiaojiang Du |
GLOBECOM | 2 |
| 2014 | Contention-based adaptive position update for intermittently connected VANETsabstractPosition information of nodes in vehicular ad hoc networks (VANETs) plays a key role in geographic routing. A sender or intermediate node employs position information of its neighbors and destination node to make routing decision. Under a greedy forwarding algorithm, the neighboring node closest to the destination node is selected as the next hop. Hence, it is critical in geographic routing to ensure that the selected next hop has a better position than other neighboring nodes. Position information is usually propagated to local nodes through periodical beaconing. In most geographic routing protocols, each node broadcasts beacons in a fixed interval, but this method can not always achieve both position accuracy and low overhead. In this paper, we propose a contention-based adaptive position update (CAPU) scheme for intermittently connected VANETs. CAPU concentrates on the position accuracy of the next hop when data transmission happens. If the position deviation of the next hop is greater than the permitted deviation range, the next hop updates its position. A special next hop timeout approach is proposed to find and delete the unreachable next hop as soon as possible. CAPU can find key nodes in local topology for greedy forwarding and intermittent connectivity. In addition, contention beacons broadcasted by key nodes maintain the local topology. Experimental results show that the proposed approach provides key position information for routing decision and exhibits better routing performance with acceptable overhead. Hongli Zhang 0001, Xiaojiang Du, Shen Su |
GLOBECOM | 2 |
| 2014 | Privacy-preserving granular data retrieval indexes for outsourced cloud dataabstractStorage as a service has become an important paradigm in cloud computing for its great flexibility and economic savings. Since data owners no longer physically possess the storage of their data, it also brings many new challenges for data security and management. Several techniques have been investigated, including encryption, as well as fine-grained access control for enabling such services. However, these techniques just expresses the "Yes or No" problem, that is, whether the user has permissions to access the corresponding data. In this paper, we investigate the issue of how to provide different granular information views for different users. Our mechanism first constructs the relationship between the keywords and data files based on a Galois connection. And then we exploit data retrieval indexes with variable threshold, where granular data retrieval service can be supported by adjusting the threshold for different users. Moreover, to prevent privacy disclosure, we propose a differentially privacy release scheme based on the proposed index technique. We prove the privacy-preserving guarantee of the proposed mechanism, and the extensive experiments further demonstrate the validity of the proposed mechanism. Hongli Zhang 0001 |
GLOBECOM | 2 |
| 2014 | Feature Evaluation for Early Stage Internet Traffic Identification
Lizhi Peng, Hongli Zhang 0001, Bo Yang 0001, Yuehui Chen |
ICA3PP (1) | 2 |
| 2014 | Quantifying AS-level routing policy changesabstractTo study Internet's routing behavior on the granularity of Autonomous Systems (ASes), one needs to understand inter-domain routing policy. Routing policy changes over time, and may cause route oscillation, network congestion, and other problems. However, there are few works on routing policy changes and their impact on BGP's routing behaviors. In this paper, we model inter-domain routing policy as the preference to neighboring ASes, noted as neighbor preference, and propose an algorithm for quantifying routing policy changes based on neighbor preference. As a further analysis, we study the routing policy changes for the year of 2012, and find that generally an AS may experience a routing policy change for at least 20% prefixes within 6 months. An AS changes its routing policy mainly by exchanging two neighboring ASes' preference. In most cases, an AS changes a stable fraction of its prefixes' routing policy, but non-tier1 ASes may endure a large scale routing policy changing event. We also analyse the main reasons of routing policy changes, and exclude the possibilities of AS business relationship changes and topology changes. Shen Su, Hongli Zhang 0001, Binxing Fang |
ICC | 2 |
| 2014 | A new approach for imbalanced data classification based on data gravitation
Lizhi Peng, Hongli Zhang 0001, Bo Yang 0001, Yuehui Chen |
Inf. Sci. | 2 |
| 2014 | Verifying cloud service-level agreement by a third-party auditorabstractABSTRACT In this paper, we study the important issue of verifying service‐level agreement (SLA) with an untrusted cloud and present an SLA verification framework that utilizes a third‐party auditor (TPA). A cloud provides users with elastic computing and storage resources in a pay‐as‐you‐go way. An SLA between the cloud and a user is a contract that specifies the computing resources and performances that the cloud should provide to the user. A cloud service provider (CSP) has incentives to cheat on the SLA, for example, providing a user with less central processing unit and memory resources than specified in the SLA, which allows the CSP to support more users and make more profits. A malicious CSP can easily disrupt the existing SLA monitoring/verification techniques by interfering with the monitoring/measurement process. A TPA resolves the trust dilemma between a CSP and its users. Under the TPA framework and the untrusted‐cloud threat model, we design two effective testing algorithms that can detect an SLA violation of the virtual machine memory size. Using real experiments, we demonstrate that our algorithms can detect cloud cheating on a virtual machine's memory size (i.e., SLA violations). Furthermore, we show that our testing algorithms can defend various attacks from a malicious CSP, which tries to hide an SLA violation. Copyright © 2013 John Wiley & Sons, Ltd. Hongli Zhang 0001, Xiaojiang Du, Mohsen Guizani |
Secur. Commun. Networks | 1 |
| 2014 | Designing robust routing protocols to protect base stations in wireless sensor networksabstractABSTRACT A base station is the controller and the data‐receiving center of a wireless sensor network. Hence, a reliable and secure base station is critical to the network. Once an attacker locates the base station, he or she can do many damages to the network. In this paper, we examine the base station location privacy problem from both the attack and defense sides. First, we present a new attack on base station: parent‐based attack scheme (PAS). PAS can locate a base station within one radio (wireless transmission) range of sensors in high‐density sensor networks. Different from existing methods, PAS determines the base station location on the basis of parent–child relationship of sensor nodes. Existing base station protection schemes cannot defend against PAS. Second, on the basis of PAS, we propose a two‐phase parent‐based attack scheme (TP‐PAS). Our simulation results demonstrate that TP‐PAS is able to determine the base station successfully in both low‐density and high‐density sensor networks. Then, to defend against PAS and TP‐PAS, we design a child‐based routing protocol and a parent‐free routing protocol for sensor networks. Our theory analysis and experiment results show that the parent‐free routing protocol has more communication cost and less end‐to‐end latency compared with the child‐based routing protocol. Copyright © 2012 John Wiley & Sons, Ltd. Hongli Zhang 0001, Xiaojiang Du, Binxing Fang, Liu Yan |
Wirel. Commun. Mob. Comput. | 2 |
| 2013 | Protecting private cloud located within public cloudabstractMany studies use cryptographic technologies to protect sensitive data in public cloud. However, these approaches may introduce large overheads. Recently, hybrid cloud started to gain a lot of attentions. A hybrid cloud consists of a private cloud and a public cloud. Hybrid cloud allows users to store sensitive data in their private cloud and hence enables efficient and secure data outsourcing. In this paper, we consider a new hybrid cloud model “Cloud-in-Cloud” (CIC). Our CIC model uses a new architecture to form a hybrid cloud: placing a small number of private computers (i.e., a small private cloud) within a public cloud. The private cloud can be used to store sensitive user data. Furthermore, it is within the public cloud, so the communications between private and public clouds have small overhead. And then we study how to protect a private cloud that locates within a semi-trusted environment. We present two methods that can detect attacks that try to obtain data and information in the private cloud. Our methods are able to efficiently detect physical attacks, such as the cold boot attack and the USB autorun attack. Experimental results show that our methods have small overhead. Hongli Zhang 0001, Xiaojiang Du, Mohsen Guizani |
GLOBECOM | 1 |
| 2013 | Practical and privacy-assured data indexes for outsourced cloud dataabstractCloud computing allows individuals and organizations outsource their data to cloud server due to the flexibility and cost savings. However, data privacy is a major concern that hampers the wide adoption of cloud services. Data encryption ensures data content confidentiality and fine-grained data access control prevents unauthorized user from accessing data. An unauthorized user may still be able to infer privacy information from encrypted data by using indexing techniques. In this paper, we investigate the problem of sensitive information leakage caused by orthogonal use of these two kinds of techniques. Based on that, we propose “core attribute”-aware techniques that can ensure privacy of outsourced data. The techniques focus on confidential attribute set of outsourced data. We adopt k-anonymity technique for the attribute indexes to prevent user from inferring privacy from unauthorized data. We formally prove the privacy-preserving guarantee of the proposed mechanism. Our extensive experiments demonstrate the practicality of the proposed mechanism, which has low computation and communication overhead. Hongli Zhang 0001, Xiaojiang Du, Xiangzhan Yu |
GLOBECOM | 1 |
| 2013 | A performance prediction scheme for computation-intensive applications on cloudabstractAs cloud computing services are gaining popularity, many organizations are considering migrating their large-scale computing applications to cloud. Different cloud service providers (CSPs) may have different computing platforms and billing methods. Most cloud customers don't know which CSP is more suitable for their applications and how much computing resource should be purchased. To address this issue, in this paper, we present a performance prediction scheme that allows a cloud customer to accurately predict computing resource (e.g., running time) for an application. The proposed scheme identifies application's control flow and scaling blocks, constructs a miniature version program to run in local machines, and then replays it in cloud to get the performance ratio between local and cloud. Our real-network experiments show that the scheme can achieve high prediction accuracy with low overhead. Hongli Zhang 0001, Xiaojiang Du, Weizhe Zhang |
ICC | 1 |
| 2013 | Glaucus: Predicting Computing-Intensive Program's Performance for Cloud Customers
Xiaojiang Du, Hongli Zhang 0001, Junchao Wu |
ICIC (1) | 4 |
| 2013 | PPBD: A piracy preventing system for BT DHT networksabstractIn this paper, we study several important issues that can be used to prevent pirated content propagation in BitTorrent (BT) Distributed Hash-Tables (DHT) networks. We design a system called PPBD to stop pirated content propagation by utilizing several attacking methods. First, the system can efficiently deal with massive concurrent connections to reduce bandwidth consumption, schedule peers to cooperate and optimize the protection methods according to clients. Second, we construct two mathematical models for BT DHT attacks, and we theoretically analyze the system performance. Third, we take into account some countermeasures of different BT clients and make corresponding optimizations of our PPBD system. Our realworld experiments show that: (1) our system can extend the download duration at least three times by the fake-block attacking method and it is more effective in a small swarm; (2) DHT index poison and routing pollution methods can limit the sharing swarm to a small swarm. Hongli Zhang 0001, Xiaojiang Du |
INFOCOM | 1 |
| 2013 | Prometheus: Privacy-aware data retrieval on hybrid cloudabstractWith the advent of cloud computing, data owner is motivated to outsource their data to the cloud platform for great flexibility and economic savings. However, the development is hampered by data privacy concerns: Data owner may have privacy data and the data cannot be outsourced to cloud directly. Previous solutions mainly use encryption. However, encryption causes a lot of inconveniences and large overheads for other data operations, such as search and query. To address the challenge, we adopt hybrid cloud. In this paper, we present a suit of novel techniques for efficient privacy-aware data retrieval. The basic idea is to split data, keeping sensitive data in trusted private cloud while moving insensitive data to public cloud. However, privacy-aware data retrieval on hybrid cloud is not supported by current frameworks. Data owners have to split data manually. Our system, called Prometheus, adopts the popular MapReduce framework, and uses data partition strategy independent to specific applications. Prometheus can automatically separate sensitive information from public data. We formally prove the privacy-preserving feature of Prometheus. We also show that our scheme can defend against the malicious cloud model, in addition to the semi-honest cloud model. We implement Prometheus on Hadoop and evaluate its performance using real data set on a large-scale cloud test-bed. Our extensive experiments demonstrate the validity and practicality of the proposed scheme. Hongli Zhang 0001, Xiaojiang Du, Xiangzhan Yu |
INFOCOM | 2 |
| 2013 | A Measurement Study on the Topologies of BitTorrent NetworksabstractBitTorrent (BT) is a widely-used peer-to-peer (P2P) application. Most of BT's characteristics (except the topology) have been studied extensively by measurement approaches. In this paper, we deploy a measurement system to examine some performance-related topology properties of BT. Our goal is to provide a measurement view of the real-world BT topologies and to verify the previous estimations via simulations and real-world experiments. We observe that at the steady stage, a BT topology has short distances and low clustering coefficients, and its degree-frequency exhibits a Gaussian-like distribution. These indicate that a BT network is very close to a random network rather than a scale-free network or a small world. The proportion of peers with large download percentages is very high at the steady stage, showing that the swarm is robust from the resource perspective. We also find out that most high-degree peers have a very fast download speed. However, the low Spearman's rank correlation coefficient indicates that there is no strong correlation between the peer connection degree and the download speed. Different from previous results, we find that the diameter of a BT network at the initial stage is small even when 95% of peers use the peer exchange extension. Majing Su, Hongli Zhang 0001, Xiaojiang Du, Binxing Fang, Mohsen Guizani |
IEEE J. Sel. Areas Commun. | 2 |
| 2013 | Preventing Piracy Content Propagation in Peer-to-Peer NetworksabstractPeer-to-Peer (P2P) networks have been widely used in various Internet applications. However, P2P networks also cause serious concerns of copyrighted contents piracy: P2P helps to pirate copyrighted contents, which impedes wide application of P2P networks. In this paper, we investigate several important issues on the ways to prevent pirated content propagation in P2P networks. We propose a system to stop pirated content propagation by utilizing several attacks to BitTorrent (BT). First, we design a system that can handle a large number of concurrent connections to reduce bandwidth consumption. Second, we build two mathematical models for BT attacks, including leechers behavior model and fake-block behavior model, and we analyze the performance of the system using these models. Third, we optimize BT clients by taking into account different implementations and counter-measure designs. We conducted several experiments in real networks, the results of which verified that our system is suitable for most current BT clients, and BT clients' download duration is extended at least three times longer, which is much better than the results reported in the literature. Hongli Zhang 0001, Xiaojiang Du, Hsiao-Hwa Chen |
IEEE J. Sel. Areas Commun. | 1 |
| 2012 | An efficient and sustainable self-healing protocol for Unattended Wireless Sensor NetworksabstractDue to the unattended operation nature, nodes in Unattended Wireless Sensor Networks (UWSNs) are susceptible to physical attacks. Once a sensor is compromised, the adversary will be able to learn all its secrets. While some previous works tried to address the node self-healing issue in UWSNs, little effort has been devoted to ensure the sustainability of node self-healing. In this paper, we present a novel sustainable node self-healing protocol for UWSNs. We generate unpredictable random data for key update and thus the node self-healing capability doesn't decrease when the number of attack rounds increases. We show both analytically and through simulation experiments that our protocol provides efficient and sustainable node self-healing capabilities with small overheads. Hongli Zhang 0001, Binxing Fang, Xiaojiang Du, Haining Yu, Xiangzhan Yu |
GLOBECOM | 2 |
| 2012 | Understanding the topologies of BitTorrent networks: A measurement viewabstractBitTorrent (BT) is one of the most popular Peer-to-Peer (P2P) network applications. Most characteristics (except the topology) of BT network have been examined extensively by measurement approaches. In this work, we deploy a measurement system to study the performance-related properties of BT topologies. We also use our measurement system to verify some previous simulation and experiment results obtained by other researchers. Different from previous results, we observe that a BT swarm has short distance, low clustering coefficient and Gaussian-like degree-frequency distribution. This indicates that a BT swarm is very close to a random network rather than a scale-free network or a small world. We observe that the diameter of a BT network at the initial stage is small even when 95% of peers use the peer exchange extension but the networks are not fully connected at the steady stages. Majing Su, Hongli Zhang 0001, Xiaojiang Du, Binxing Fang, Mohsen Guizani |
GLOBECOM | 2 |
| 2012 | Verifying cloud Service Level AgreementabstractIn this paper we study the important issue of verifying Service Level Agreement (SLA) in a semi-trusted (or untrusted) cloud. Cloud computing services promise elastic computing and storage resources in a pay-as-you-go way. A SLA between a cloud service provider (CSP) and a user is a contract which specifies the resources and performances that the cloud should offer. However, the CSP has the incentive to cheat on SLA, e.g., providing users with less CPU and memory resources than that specified in the SLA, which allows the CSP to support more users and make more profits. A malicious CSP can disrupt the existing SLA monitoring/verification techniques by interfering the monitoring/measurement process. Therefore, we present a SLA verification framework that leverages a third party auditor (TPA). Under the TPA framework, we propose an effective testing algorithm that can detect SLA violations of physical memory size in virtual machine (VM). Using real experiments, we show that the algorithm can detect cloud cheating on VM memory size (i.e., SLA violations). Furthermore, our algorithm can defend various attacks from a malicious CSP, which tries to hide a SLA violation. Hongli Zhang 0001, Xiaojiang Du |
GLOBECOM | 2 |
| 2012 | Base station location protection in wireless sensor networks: Attacks and defenseabstractA base station (BS) is the controller and the data receiving center of a wireless sensor network. Hence, a reliable and secure BS is critical to the network. Once an attacker locates the BS, he can do a lot of damages to the network. In this paper, we study the BS location protection issue. First, we present a new attack on BS: the Parent-based Attack Scheme (PAS). The PAS can locate a BS within one radio (wireless transmission) range of sensors. Different from existing methods, the PAS determines the BS location based on parent-child relationship of sensor nodes. The PAS cannot be defended by existing BS protection schemes. To defend against the PAS, we design a new parent-free (PF) secure routing protocol for sensor networks. Our simulation results show that the PF protocol has small communication and computation costs, while ensuring the security of the BS. Hongli Zhang 0001, Xiaojiang Du, Binxing Fang, Yan Liu 0028, Haining Yu |
ICC | 2 |
| 2012 | DDoS vulnerability of BitTorrent Peer Exchange extension: Analysis and defenseabstractBitTorrent (BT) is a well-known Peer-to-Peer (P2P) downloading protocol and has been implemented in several versions. New features and extensions used to improve performance of BitTorrent systems also bring some security issues. In this paper, we analyze potential DDoS vulnerabilities of BT and its Peer Exchange extension. We show the ways of launching connection-exhausted DDoS attacks. Our experiments demonstrate these attacks are persistent and incur few costs for the attacker. By analyzing the main causes we find that both the defect of implement and the lack of trust and authentication mechanism are to blame, while the latter is critical. To defend against the DDoS attacks, we propose a score-based peer Reputation Exchange (REX) mechanism. Using REX, the score of a malicious peer is less than that of a good peer after several iterations, hence has less chance to be connected. REX makes it difficult to launch a DDoS attack and it can effectively mitigate the effect of the attack. Majing Su, Hongli Zhang 0001, Binxing Fang, Xiaojiang Du |
ICC | 2 |
| 2012 | A Novel Cache Replacement Policy for ISP Merged CDNabstractThe cache replacement policy is the key factor affecting the performance of the ISP merged Content Delivery Networks. Current cache replacement schemes only consider the frequency and locality as the basis of replacement. However, we argue the access interval change rate is more valuable in predicting the new objects arrival through analyzing the real network logs. Considering this new metric, we propose a novel cache replacement algorithm based on access density. Using this novel method, the cache can achieve higher hit rate. Experiments with real network data show that our method improves 3% to 5% hit rate than the typical cache schemes and ISP can reduce 3% to 7% network traffic. Qiao Li 0002, Binxing Fang, Hongli Zhang 0001 |
ICPADS | 4 |
| 2012 | Feature selection for optimizing traffic classification
Hongli Zhang 0001, Mahmoud T. Qassrawi, Yu Zhang 0036, Xiangzhan Yu |
Comput. Commun. | 1 |
| 2011 | Towards Efficient Anonymous Communications in Sensor NetworksabstractAnonymous communication is a challenging task in resource constrained wireless sensor networks (WSN). However, anonymity is important for many sensor networks, in which we want to conceal the location and identify of important nodes (such as source nodes and base stations) from attackers. Existing WSN anonymous protocols either cannot achieve complete anonymity, or have large computation and/or storage overheads. In this paper, we present an efficient anonymous communication protocol for sensor networks. Our protocol can achieve sender/source anonymity, communication -relationship anonymity, and the base station anonymity simultaneously, while having small overheads on computation, storage and communication. Hongli Zhang 0001, Binxing Fang, Xiaojiang Du, Lihua Yin, Xiangzhan Yu |
GLOBECOM | 2 |
| 2011 | Lightweight Source Anonymity in Wireless Sensor NetworksabstractIn many applications of Wireless Sensor Networks (WSN), the source of an event needs to be protected. In resource constrained WSN, providing source anonymity is a challenging task. A traditional approach for hiding source in WSN is to let all nodes generate dummy data packets even if they have no event to report. However, this kind of approach introduces large overhead. In order to reduce the large overhead of sending dummy data packets, we propose using a much shorter control packet to achieve source anonymity. The short control packets are used to coordinate the transmissions of dummy data packets, which prevent revealing the source node and hence provides source anonymity in WSN. We evaluate the performance of our anonymity scheme via ns-2 simulations. The simulations show that our scheme has much less traffic overhead than an existing anonymity scheme. Phillip Reindl, Xiaojiang Du, Kendall E. Nygard, Hongli Zhang 0001 |
GLOBECOM | 4 |
| 2011 | A Framework to Quantify the Pitfalls of Using Traceroute in AS-Level Topology MeasurementabstractAlthough traceroute has the potential to discover AS links that are invisible to existing BGP monitors, it is well known that the common approach for mapping router IP addresses to AS numbers based on BGP routing tables is highly error-prone. We develop a systematic framework to quantify the potential errors of traceroute measurement in AS-level topology inference. In comparing traceroute-derived AS paths with BGP AS paths, we take a novel approach to identifying mismatched path segments and then inferring the causes of these mismatches through a set of tests. Our results show that about 60% of mismatches are due to routers using IP addresses belonging to peering neighbors. This result helps settle a debate in previous works regarding the major cause of errors in traceroute measurement. With the approximate ground truth of the ASes with BGP monitors inside, we identify the inaccuracy of publicly available traceroute-derived topology datasets and find that between 8% and 42% of AS adjacencies on the monitored ASes are false. With a new method to characterize AS links, we show that the derived (false) links between Tier-1/large ISPs and their customers' customers appear more frequently than real links do. Yu Zhang 0036, Ricardo V. Oliveira, Yangyang Wang 0001, Shen Su, Baobao Zhang, Jun Bi, Hongli Zhang 0001, Lixia Zhang 0001 |
IEEE J. Sel. Areas Commun. | 7 |
| 2010 | A General Distributed Object Locating Architecture in the Internet of ThingsabstractThis paper proposes a novel platform for object locating application in the Internet of Things environment. In this platform, objects and inquirers access and query locations using uniform service entry interfaces in heterogeneous services. To build a virtual storage system, services entries integrate enterprise database clusters and a DHT peer-to-peer network built with inquirers' devices. The DHT network is originally designed for accurate object locating, to enable fuzzy object locating we construct a hierarchical storage overlay network based on the DHT network. This LBS platform simplifies the object locating operation for ordinary inquirers greatly, moreover it provides huge virtual computing and storage resources for small companies and individual developers. Wenmao Liu, Lihua Yin, Weizhe Zhang, Hongli Zhang 0001 |
ICPADS | 4 |
| 2010 | Traffic identification using flexible neural treesabstractTraditional traffic classification techniques like port-based and payload-based techniques are becoming ineffective owning to more and more Internet applications using dynamic port number and encryption techniques. Therefore, in the past few years, many researches have addressed machine learning-based techniques. Most researches of machine learning-based traffic identification use traffic samples collected on key nodes of networks for their learning. These samples do not have accurate application information i. e. the ground truth which is crucial for machine learning algorithms. In this paper, we first designed a distributed host based traffic collecting platform (DHTCP) to gather traffic samples with accurate application information on user hosts. Then we built a data set using DHTCP, and applied Flexible Neural Trees (FNT) - a special kind of artificial neural network which has been successfully applied in many areas, for traffic identification. Web and P2P traffics were studied in our work. Although the proposed technique is at an early stage of development, experimental results show that it is a promising solution of Internet traffic identification. Lizhi Peng, Hongli Zhang 0001, Bo Yang 0001, Yuehui Chen, Mahmoud T. Qassrawi |
IWQoS | 2 |
| 2010 | Scale-Adaptable Recrawl Strategies for DHT-Based Distributed Web Crawling System
Weizhe Zhang, Hongli Zhang 0001, Binxing Fang |
NPC | 3 |
| 2010 | Quantifying the Pitfalls of Traceroute in AS Connectivity Inference
Yu Zhang 0036, Ricardo V. Oliveira, Hongli Zhang 0001, Lixia Zhang 0001 |
PAM | 3 |
| 2009 | A Forwarding-Based Task Scheduling Algorithm for Distributed Web Crawling over DHTsabstractDistributed Web crawling (DWC) over DHTs is proposed to solve the bottlenecks in the traditional Web crawling. The core of this kind of system is its fully distributed task scheduling mechanism in which the crawlers are treated as peers and the crawlees are treated as resources maintained by the peers. A system model based on the content addressable network (CAN) can further optimize the scheduling mechanism by exploiting the network proximity of the crawlers and the crawlees. In this paper, we propose a new method for CAN in order to achieve load balancing in the CAN-based DWC system. The method not only keeps the load balancing among peers but also keeps the distance between peers and resources very short in our simulations. The shortened peer-resource distance fulfills the need of shortening crawler-crawlee latencies. Weizhe Zhang, Hongli Zhang 0001, Binxing Fang |
ICPADS | 3 |
| 2009 | Measurement and Analysis of BitTorrent AvailabilityabstractOf the many peer-to-peer (P2P) systems in existence, BitTorrent is one of the most appealing that has managed to attract millions of users in the past few years. In this paper we present an extensive study of BitTorrent availability through measurement and analysis. Previous studies are limited to tracker without distributed hash tables (DHT), which have been used widely already. We first discuss the difference of measurement methods, and then develop a new parallel method based on threshold with bounding measurement errors. Afterwards, we focus on three issues: the availability of tracker and DHT, the availability of pieces and the variability of availability over time. Our analysis provides several new findings: (1) Overall dynamics of peers are similar across different index. (2) Compared to tracker, DHT does not have better performance as expected. (3) Seeds contribute most of piece replicas. When they are of offline, the availability of pieces will decrease dramatically. (4) The replicas of all pieces are almost the same without very rare pieces and the distribution of pieces is equal and effective. (5) The variability of availability shows a typical life cycle pattern over time, which means it is difficult for users to obtain files in the latter half of stage. In summary, this paper advances our understanding of availability by comparing different index, exploring the distribution of pieces and analyzing the fluctuation of availability. Hongli Zhang 0001, Weizhe Zhang |
ICPADS | 2 |
| 2009 | A Steady Network Coordinate System for Network Distance EstimatingabstractA lot of large distributed system can benefit from the implement of network coordinate system, which can estimate latencies among Internet hosts. In this paper, we focus on problems in building network coordinate system. Firstly, we analyze the disadvantages of some algorithms that based on fixed reference nodes and algorithms based on unfixed reference nodes. Then we propose a new architecture of network coordinate system, in which, network delay space is divided into several global clustering firstly, and a new way to select reference nodes and acquire coordinates is applied. According to the experiments on PlanetLab, our method proved to be accurate and steady. Hongli Zhang 0001 |
ICPADS | 2 |
| 2009 | HiFiP2P: The Simulator Capable of Massive Nodes and MeasuredUnderlayabstractPeer-to-peer (P2P) systems, which are realized as overlays on top of the underlying Internet routing architecture, contribute a significant portion of today's Internet traffic. They have recently absorbed a lot of attention from the Internet users and the research community. Regarding the difficulty and cost for a large scale living deployment, many proposed P2P protocols were evaluated by a simulator. However, most of current P2P simulators have common draw backs including the poor scalability with massive simulated peers and the lack of realistic underlay network layer support. Unfortunately, those functionalities are critical to understand how a P2P protocol would be-have in the real circumstance. In this paper, we present some approaches to overcome such defects, and the design considerations of HiFiP2P, our novel large-scale parallel peer-to-peer simulator with a measured realistic Internet data as its network layer support. Comparison experiments show that HiFiP2P simulator outperforms the existing simulation platform J-Sim & PlanetSim in both aspects of scalability and efficiency. Guangyu Shi, Youshui Long, Hao Gong 0002, Changqing Wan, Chuanliang Yu, Xianqing Yang, Hongli Zhang 0001 |
PDP | 7 |
| 2009 | Intrusion detection alarms reduction using root cause analysis and clustering
Safaa O. Al-Mamory, Hongli Zhang 0001 |
Comput. Commun. | 2 |
| 2008 | Alertclu: A Realtime Alert Aggregation and Correlation SystemabstractIntrusion detection can be defined as the process of identifying malicious behavior that targets a network and its resources. An important problem in the field of intrusion detection is the management of alerts. This paper describes a realtime aggregation and correlation system named Alertclu. With the aid of similarity-based alert clustering analysing technology, Alertclu can improve the aggregation of intrusion detection system outputs and allow one to seamlessly incorporate additional information. In addition, Alertclu supports the operators by classifying alerts into true positives and false positives. The results of experiment show that the proposed system is able to reduce the numerous redundant alerts and effectively reduces the analyst operators' workload. Zhihong Tian 0001, Baoshan Qin, Jianwei Ye, Hongli Zhang 0001 |
CW | 4 |
| 2008 | Modeling network attacks for scenario constructionabstractThe Intrusion detection system (IDS) is a security technology that attempts to identify network intrusions. Defending against multistep intrusions which prepare for each other is a challenging task. In this paper, the Context-Free Grammar (CFG) was used to describe the multistep attacks using alerts classes. Based on the CFGs, the modified LR parser was employed to generate the parse trees of the scenarios presented in the alerts. Instead of searching all the received alerts for those that prepare for a new alert, we only search for the latest alertpsilas type of each scenario. Consequently, the proposed system has an attractive time complexity. The experiments were performed on two different sets of network traffic traces, using different open-source and commercial IDSs. The detected scenarios are represented by Correlation Graphs (CGs). The experimental results show that the CFG can describe multistep attacks explicitly and the modified LR parser, based on the CFG, can construct scenarios successfully. Safaa O. Al-Mamory, Hongli Zhang 0001, Ayad R. Abbas |
IJCNN | 2 |
| 2008 | IDS alarms reduction using data miningabstractThe Intrusion Detection Systems (IDSs) are one of robust systems which can effectively detect penetrations and attacks. However, they generate large number of alarms most of which are false positives. Fortunately, there are reasons for triggering alarms where most of these reasons are not attacks. In this paper, a new approximation algorithm has developed to group alarms and to produce clusters. Hereafter, each cluster abstracted as a generalized alarm; most of the generalized alarms are root causes. The proposed algorithm makes use of nearest neighboring and generalization concepts. As a clustering algorithm, the proposed algorithm uses a new measure to compute distances between alarms features values. This algorithm was verified with many datasets, and its reduction ratio was about 93% of the total alarms. The resulting generalized alarms help the security analyst in writing filters. Safaa O. Al-Mamory, Hongli Zhang 0001, Ayad R. Abbas |
IJCNN | 2 |
| 2008 | A High Scalability P2P Simulation Framework with Measured Realistic Network Layer SupportabstractThe Peer-to-Peer (P2P) technology being widely adopted in today's both academic research and practical service providing, has many potential advantages, including high scalability and cost-effectiveness. However, the behavior of these P2P systems under large scale and complex interactions is still poorly understood and many challenges in improving their performance remain. A fundamental problem in studying peer-to-peer networks is the evaluation of new protocols. So the technology of P2P network simulation has become a main method for understanding, researching and evaluating the P2P network algorithms and protocols. In this paper, we present a novel large-scale parallel Peer-to-Peer Simulation Framework with High Scalability (HiFiP2P) which uses message-level parallel process. By performing the comparison experiments, we show that HiFiP2P outperforms the existing simulation platform in both aspects of scalability and efficiency. And we show that with HiFiP2P simulations of networks with up to 500,000 nodes are feasible. Guangyu Shi, Youshui Long, Hao Gong 0002, Changqing Wan, Chuanliang Yu, Xianqing Yang, Hongli Zhang 0001 |
IPCCC | 7 |
| 2008 | 2MC-Match: A topology matching technique with 2-means clustering algorithm in P2P systemsabstractA peer-to-peer (P2P) system is built upon an overlay network whose logical topology is independent of the underlying physical network. A lot of research work has been presented to address this issue, but most results still have some drawbacks, such as complexity or deployment difficulty. In order to alleviate the mismatching problem, we propose a topology matching technique with 2-means clustering algorithm called 2MC-Match, which uses the 2-means clustering algorithm to classify the Internet peers and build efficient ldquocloserdquo cluster. By performing the measured realistic Internet data (China), we show that 2MC-Match outperforms the well-known GNP in both aspects of accuracy and maintenance cost. Guangyu Shi, Youshui Long, Jian Chen 0041, Hao Gong 0002, Hongli Zhang 0001 |
ISCC | 5 |
| 2008 | T2MC: A Peer-to-Peer Mismatch Reduction Technique by Traceroute and 2-Means Classification Algorithm
Guangyu Shi, Youshui Long, Jian Chen 0041, Hao Gong 0002, Hongli Zhang 0001 |
Networking | 5 |
| 2006 | User-Perceived Web QoS Measurement and Evaluation System
Hongjie Sun, Binxing Fang, Hongli Zhang 0001 |
APWeb | 3 |
| 2006 | Multisite co-allocation scheduling algorithms for parallel jobs in computing grid environments
Weizhe Zhang, Binxing Fang, Mingzeng Hu, Hongli Zhang 0001 |
Sci. China Ser. F Inf. Sci. | 5 |
| 2006 | Defending against distributed denial-of-service attacks with an auction-based method
Zhihong Tian 0001, Mingzeng Hu, Hongli Zhang 0001 |
Web Intell. Agent Syst. | 5 |
| 2005 | On the Effectiveness of multi-similarity for early detection of wormsabstractIn this paper, an effective algorithm for early detection of worms is proposed. The early detection algorithm based on multi-similarity integrates the worms’ behavior attributes with their traffic distribution and detects abnormal behavior by their similarity distribution change of some attributes. Three groups of experiments are conducted to evaluate the effectiveness of the algorithm. The results show that the multi-similarity owning the specialty of higher true positive, lower false positive and false negative. It can be conclude that the algorithm can detect the worm attack ahead of its overspreading on the large-scale network. Mingzeng Hu, Hongli Zhang 0001, Zhenjiang Tang |
PDCAT | 3 |
| 2005 | A Distributed Architecture for Network Performance Measurement and Evaluation SystemabstractQuality of Service (QoS) has now become a central issue in network design and application. This article describes a distributed architecture for linking geographically distributed network performance measurement and evaluation system (NPMES) based on in-depth research on the key techniques of network QoS. The prototype implementation of NPMES and the performance evaluation criteria based on performance aggregation are carefully introduced. Our contribution is presenting a new performance evaluation criteria based on performance aggregation to access QoS. Experiment results indicate the scalable NPMES can do the real-time detection on network performance of ISPs from the end user’s perspective. The performance aggregation approach is a bran-new idea, and of a definite practicability. Hongjie Sun, Binxing Fang, Hongli Zhang 0001 |
PDCAT | 3 |
| 2005 | Load Balance Heuristics for Synchronous Iterative Applications on Heterogeneous Cluster SystemsabstractHeterogeneous computing systems are emerging as a computing infrastructure that will enable the use of distributed heterogeneous clusters for a variety of challenging applications. The actual challenge is the load balance for tightly-coupled applications. In this paper, we focus on the important subclass of tightlycoupled applications, synchronous iterative applications and formally define their load balance problem. Two novel static meta heuristic algorithms are proposed for the load distribution: a genetic tabu hybrid search (GTHS) algorithm and a host clustering based iterative search (HCIS) algorithm, when different communication computation ratios are considered. To this end, the analysis and experiment results demonstrate the effectiveness of heuristic algorithms. Weizhe Zhang, Mingzeng Hu, Hongli Zhang 0001 |
PDCAT | 3 |
| 2004 | Developing a user-level middleware for out-of-core computation on GridsabstractScientists and engineers are faced with more and more out-of-core problems which involve solving large amounts of data. The Grid infrastructure is a large-scale distributed software system that provides a wide and scalable environment for out-of-core computations. This paper constructs a framework of out-of-core computation service on Grids. To provide the users an easy and efficient out-of-core computing interface on computational Grids, a user-level middleware upon the Globus platform is described, which is implemented by adopting the Grid portal technique and the message passing programming model as well as template classes. Jianqi Tang, Binxing Fang, Mingzeng Hu, Hongli Zhang 0001 |
CCGRID | 4 |
| 2004 | Multisite Resource Selection and Scheduling Algorithm on Computational GridabstractSummary form only given. Multisite resource selection and task scheduling is paid more and more attention under the grid environment nowadays with the emergence of high speed WAN. Especially in a distributed computational grid, multisite resource selection and scheduling can significantly reduce the average execution time of grand applications with a limited demand in communication. Therefore we present a CGRS resource selection algorithm based on a new density-based grid resource-clustering algorithm, and implement it in our scalable environment. The analysis and experimental results show the correctness and effectiveness of our resource selection algorithm. Weizhe Zhang, Binxing Fang, Hongli Zhang 0001, Mingzeng Hu |
IPDPS | 4 |
| 2004 | Explaining BitTorrent Traffic Self-Similarity
Mingzeng Hu, Binxing Fang, Hongli Zhang 0001 |
PDCAT | 4 |
| 2004 | The Practice of I/O Optimizations for Out-of-Core Computation
Jianqi Tang, Binxing Fang, Mingzeng Hu, Hongli Zhang 0001 |
PDCAT | 4 |
| 2004 | Intrusion detection system for high-speed network
Binxing Fang, Hongli Zhang 0001 |
Comput. Commun. | 4 |