Zhiyuan Tan 0001

dblp:08/8276 · also Zhiyuan Thomas Tan · DBLP profile ↗
← Back
68ranked-venue papers
7as first author
37since 2021 · last 2026
0000-0001-5420-2554ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 18 · 12 since 2021Security and privacy · 18 · 3 first-author · 7 since 2021Systems, architecture and hardware · 14 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 9 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Collaborative Fault Tolerance Computing for Emergency Tasks in Lunar Radiation Environment
abstract
With the rapid development of lunar exploration, devices deployed on the lunar surface will encounter emergency events including meteor impacts and lunar dust storms. Additionally, the extreme lunar environment characterized by intense radiation and the high latency of Earth-based cloud computing pose severe challenges to real-time and reliable task processing. Existing collaborative computing and fault-tolerant schemes are not fully efficient in dynamic radiation environments. To address these challenges, a collaborative computing architecture integrating lunar surface devices and lunar orbit satellites is proposed for lunar emergency tasks. Comprehensive network, radiation, communication and computing models are established to support this architecture. The problem is then formulated as a multi-objective optimization problem and solved by the Radiation-aware hiErarchical collAborative Fault-Tolerant Reinforcement Learning (REAFTRL) algorithm, which integrates radiation-aware, hierarchical decision-making, and fault-tolerant execution with feedback mechanisms. Simulations show the proposed collaborative computing scheme outperforms traditional fault-tolerant strategies in task completion time, completion rate, and error rate, providing a reliable solution for future lunar exploration.
Liang Zhao 0004, Ammar Hawbani, Zhiyuan Tan 0001, Zhi Liu 0002, Daniele Tarchi
IWCMC4
2026 Toward Efficient Deep Learning in RF Fingerprint Identification With OverlapConv
abstract
In resource-constrained Internet of Things (IoT) environments, lightweight deep learning is crucial for Radio Frequency Fingerprint Identification (RFFI). However, existing lightweight designs primarily rely on group convolution with a “hard split" topology, which strictly isolates channels and blocks inter-group information sharing, impairing feature extraction. To address this, we propose overlap convolution, a novel operator employing a “soft coverage" mechanism to facilitate inter-group interaction. By enabling tunable channel overlapping, this method unifies and generalizes standard and group convolutions, restoring inter-group interaction without requiring additional mixing. We then analyze the approach by introducing structural constraint entropy as an interpretive framework to investigate the information flow capacity. Theoretical analysis demonstrates that overlap convolution offers expanded structural flexibility to achieve enhanced learning ability. Furthermore, we establish the OverlapConv framework for systematic integration of the operator into networks. Within this framework, we develop an automatic parameter acquisition strategy based on a differentiable-to-discrete transition mechanism to efficiently narrow down the search space for optimal settings. Extensive evaluations across diverse datasets (LoRa and UAV RFFI) and multiple backbones (MobileNet, ShuffleNet, and EfficientNet) confirm the method’s effectiveness as a universal plug-and-play module. Notably, our approach achieves an accuracy gain of 29.22% on the Fire block, and improves the accuracy (averaging 2.1% and 2.47% on the two datasets) of FasterNet, EfficientNet, and LMSCNet with reduced FLOPs.
Yuxiang Shen, Shuiguang Zeng, Zhiyuan Tan 0001, Yulong Shen 0001, Dongmei Zhao, Houbing Song
IEEE Internet Things J.3
2026 A Collaborative Caching and Offloading Approach for Vehicular Edge Computing
abstract
Vehicular Edge Computing (VEC) leverages promising technologies, namely the vehicle-to-vehicle (V2V) computation offloading approach and edge service caching, to address latency-sensitive tasks. The V2V offloading method efficiently harnesses idle resources from neighboring vehicles. Edge service caching facilitates the offloading task through pre-caching pertinent service data. However, formulating an efficient caching mechanism to support V2V offloading poses significant challenges, given the dynamic vehicle environment, varying computational resources, and limited caching resources of Roadside Units (RSUs). This paper introduces a collaborative caching and offloading (CACO) scheme. First, to mitigate resource wastage caused by inter-vehicle communication interruptions, we employ Generative Adversarial Network (GAN) for trajectory prediction. This process generates a relationship matrix, predicting the stability of inter-vehicle link connections to assist in V2V offloading decisions. Second, to circumvent redundant uploads and computations for recurring offloading tasks, we analyze the popularity of historical offloading tasks using the Page-Hinkley test (PHT) technique, caching frequently offloaded tasks to reduce the processing latency of offloading tasks. Subsequently, a matching scheme for caching and offloading contents is devised. Finally, the Deep Reinforcement Learning (DRL) algorithm is employed to train the offloading strategy. Results from extensive experiments substantiate that CACO attains superior performance in both system computational latency and offloading success rate.
Zijia Zhao, Liang Zhao 0004, Lexi Xu, Na Lin 0001, Zhiyuan Tan 0001
IEEE Trans. Sustain. Comput.6
2025 FedBT: Effective and Robust Federated Unlearning via Bad Teacher Distillation for Secure Internet of Things
abstract
Smart Internet of Things (IoT) devices generate vast, distributed data, and their limited computational and storage capacities complicate data protection. Federated Learning (FL) enables collaborative model training across clients, enhancing performance and protecting data privacy. The Right to be Forgotten (RTBF) raises the demand for precise data removal. Federated Unlearning (FU) offers a solution for accurate data deletion in FL systems. Existing FU methods often struggle to simultaneously ensure effective data forgetting and preserve model generalization. To mitigate these challenges, an effective and robust FU framework has been proposed, which is based on the “Bad Teacher” knowledge distillation (KD), termed FedBT. First, the “Bad Teacher" KD guides the trained model to eliminate specific client contributions from the global model. Next, the frequency domain extracts the global model’s generalization components. Finally, orthogonal constraints are applied to the KD-generated gradients within the orthogonal subspace of these components, ensuring the gradients preserve the trained model’s generalization ability. FedBT eliminates the need to store historical records of parameter updates. Using orthogonal space constraints, the generalization ability of the trained model is safeguarded during unlearning. Extensive experiments on three datasets with various metrics show our method reduces accuracy by only 0.53% on MNIST, 0.26% on Fashion-MNIST, and 4.67% on CIFAR10, surpassing the best approach. Furthermore, FedBT obtains an unlearning performance that most closely approximates the results obtained from retraining from scratch. FedBT boosts IoT security by enabling the “forgetting" of certain client data, crucial for protecting user privacy and ensuring secure device interactions.
Fangwei Wang, Jiashuai Huo, Yan Liu 0014, Zhiyuan Tan 0001, Changguang Wang
IEEE Internet Things J.6
2025 Multiagent Deep-Reinforcement-Learning-Based Cooperative Perception and Computation in VEC
abstract
Connected and autonomous vehicles (CAVs) are an important paradigm of intelligent transportation systems. Cooperative perception (CP) and vehicular edge computing (VEC) enhance CAVs’ perception capacity of the region of interest (RoI) while alleviating the pressure of intensive computation on onboard resources. However, existing CP and computation schemes are based on inefficient broadcast communications and still face challenges, such as highly dynamic communication link channel conditions caused by vehicle mobility, and limited computing resources in VEC environments. Considering the delay sensitivity of CAVs’ perception tasks and the need for enhanced perception, we propose a unicast-based cooperative perception and computation scheme to achieve more efficient resource utilization and perception task execution in VEC scenarios. Our goal is to maximize CP gain and minimize task execution delay by optimizing the decision of each ego CAVs. To solve the sequential decision-making problem of multiobjective optimization, we propose a solution based on improved multiagent proximal policy optimization deep reinforcement learning, where CAVs agents make adaptive decisions distributed based on partial observations. Simulation results show that compared with the baseline algorithm, our proposed scheme effectively reduces the execution delay of ego CAVs perception tasks and ensures a high perception gain.
Liang Zhao 0004, Longjia Li, Zhiyuan Tan 0001, Ammar Hawbani, Qiang He 0002, Zhi Liu 0002
IEEE Internet Things J.3
2025 A Multi-UAV Cooperative Task Scheduling in Dynamic Environments: Throughput Maximization
abstract
Unmanned aerial vehicle (UAV) has been considered a promising technology for advancing terrestrial mobile computing in the dynamic environment. In this research field, throughput, the number of completed tasks and latency are critical evaluation indicators used to measure the efficiency of UAVs in existing studies. In this paper, we transform these metrics to a single optimization objective, i.e., throughput maximization. To maximize the throughput, we consider realizing this goal in two respects. The first is to adapt the formation of the UAVs to provide cooperative computing service in a dynamic environment, we integrate a policy-based gradient algorithm and the task factorization network as a new reinforcement learning algorithm to improve the cooperation of UAVs. The second is to optimize the association process between UAVs and users, where the heterogeneity of tasks is considered. This algorithm is modified from the Gale-Shapley stability concept to optimize the appropriate association between tasks and UAVs in a dynamic time-varying condition to get the near-optimal association with few iterations. The scheduling of dependent tasks and independent tasks jointly also has to be considered. Finally, simulation results demonstrate the improvement of cooperation performance and the practicability of the association process.
Liang Zhao 0004, Zhiyuan Tan 0001, Ammar Hawbani, Stelios Timotheou, Keping Yu
IEEE Trans. Computers3
2025 Dynamic Caching Dependency-Aware Task Offloading in Mobile Edge Computing
abstract
Mobile Edge Computing (MEC) is a distributed computing paradigm that provides computing capabilities at the periphery of mobile cellular networks. This architecture empowers Mobile Users (MUs) to offload computation-intensive applications to large-scale computing nodes near the edge side, reducing application latency for MUs. The resource allocation and task offloading in MEC has been widely studied. However, the burgeoning complexity inherent to modern applications, often represented as Directed Acyclic Graphs (DAGs) comprising a multitude of subtasks with interdependencies, poses huge challenges for application offloading and resource allocation. Meanwhile, previous work has neglected the impact of edge caching on the offloading execution of dependent tasks. Therefore, this paper introduces a novel dynamiccaching dependency-aware taskoffloading (CachOf) scheme. First, to effectively enhance the rationality of cache and computing resource allocation, we develop a subtask priority computation scheme based on DAG dependencies. This scheme includes the execution sequence priority of subtasks on a single MU and the offloading sequence priority of subtasks from multiple MUs. Second, a dynamic caching scheme, designed to cater to dependent tasks, is proposed. This caching approach can not only assist offloading decisions, but also contribute to load balancing by harmonizing caching resources among edge servers. Finally, based on the task prioritization results and caching results, this paper presents a Deep Reinforcement Learning (DRL)-based offloading scheme to judiciously allocate resources and improve the execution efficiency of applications. Extensive simulation experiments demonstrate that CachOf outperforms other baseline schemes, achieving improved execution efficiency for applications.
Liang Zhao 0004, Zijia Zhao, Ammar Hawbani, Zhi Liu 0002, Zhiyuan Tan 0001, Keping Yu
IEEE Trans. Computers5
2024 How Much Do Robots Understand Rudeness? Challenges in Human-Robot Interaction
abstract
This paper concerns the pressing need to understand and manage inappropriate language within the evolving human-robot interaction (HRI) landscape. As intelligent systems and robots transition from controlled laboratory settings to everyday households, the demand for polite and culturally sensitive conversational abilities becomes paramount, especially for younger individuals. This study explores data cleaning methods, focussing on rudeness and contextual similarity, to identify and mitigate inappropriate language in real-time interactions. State-of-the-art natural language models are also evaluated for their proficiency in discerning rudeness. This multifaceted investigation highlights the challenges of handling inappropriate language, including its tendency to hide within idiomatic expressions and its context-dependent nature. This study will further contribute to the future development of AI systems capable of engaging in intelligent conversations and upholding the values of courtesy and respect across diverse cultural and generational boundaries.
Michael Andrew Orme, Yanchao Yu, Zhiyuan Tan 0001
LREC/COLING3
2024 Graph Injection Attack Based on Node Similarity and Non-Linear Feature Injection Strategy
Qingru Li, Fangwei Wang, Changguang Wang, Kehinde O. Babaagba, Zhiyuan Tan 0001
SecureComm (4)6
2024 MalSort: Lightweight and efficient image-based malware classification using masked self-supervised framework with Swin Transformer
Fangwei Wang, Xipeng Shi, Ruixin Song, Qingru Li, Zhiyuan Tan 0001, Changguang Wang
J. Inf. Secur. Appl.6
2024 Deep Learning and Dempster-Shafer Theory Based Insider Threat Detection
Zhihong Tian 0001, Wei Shi 0001, Zhiyuan Tan 0001, Jing Qiu 0002, Yanbin Sun, Feng Jiang 0001, Yan Liu 0014
Mob. Networks Appl.3
2024 MedOptNet: Meta-Learning Framework for Few-Shot Medical Image Classification
abstract
In the medical research domain, limited data and high annotation costs have made efficient classification under few-shot conditions a popular research area. This paper proposes a meta-learning framework, termed MedOptNet, for few-shot medical image classification. The framework enables the use of various high-performance convex optimization models as classifiers, such as multi-class kernel support vector machines, ridge regression, and other models. End-to-end training is then implemented using dual problems and differentiation in the paper. Additionally, various regularization techniques are employed to enhance the model's generalization capabilities. Experiments on the BreakHis, ISIC2018, and Pap smear medical few-shot datasets demonstrate that the MedOptNet framework outperforms benchmark models. Moreover, the model training time is also compared to prove its effectiveness in the paper, and an ablation study is conducted to validate the effectiveness of each module.
Xudong Cui, Zhiyuan Tan 0001, Yulei Wu
IEEE Trans. Comput. Biol. Bioinform.3
2024 STIDNet: Identity-Aware Face Forgery Detection With Spatiotemporal Knowledge Distillation
abstract
The impressive development of facial manipulation techniques has raised severe public concerns. Identity-aware methods, especially suitable for protecting celebrities, are seen as one of promising face forgery detection approaches with additional reference video. However, without in-depth observation of fake video’s characteristics, most existing identity-aware algorithms are just naive imitation of face verification model and fail to exploit discriminative information. In this article, we argue that it is necessary to take both spatial and temporal perspectives into consideration for adequate inconsistency clues and propose a novel forgery detector named SpatioTemporal IDentity network (STIDNet). To effectively capture heterogeneous spatiotemporal information in a unified formulation, our STIDNet is following a knowledge distillation architecture that the student identity extractor receives supervision from a spatial information encoder (SIE) and a temporal information encoder (TIE) through multiteacher training. Specifically, a regional sensitive identity modelling paradigm is proposed in SIE by introducing facial blending augmentation but with uniform identity label, thus encourage model to focus on spatial discriminative region like outer face. Meanwhile, considering the strong temporal correlation between audio and talking face video, our TIE is devised in a cross-modal pattern that the audio information is introduced to supervise model exploiting temporal personalized movements. Benefit from knowledge transfer from SIE and TIE, STIDNet is able to capture individual’s essential spatiotemporal identity attributes and sensitive to even subtle identity deviation caused by manipulation. Extensive experiments indicate the superiority of our STIDNet compared with previous works. Moreover, we also demonstrate STIDNet is more suitable for real-world implementation in terms of model complexity and reference set size.
Mingqi Fang, Lingyun Yu 0002, Hongtao Xie 0001, Qingfeng Tan, Zhiyuan Tan 0001, Amir Hussain 0001, Zezheng Wang 0002, Zhihong Tian 0001
IEEE Trans. Comput. Soc. Syst.5
2024 Overtaking Feasibility Prediction for Mixed Connected and Connectionless Vehicles
abstract
Intelligent transportation systems (ITS) utilize advanced technologies to enhance traffic safety and efficiency, contributing significantly to modern transportation. The integration of Vehicle-to-Everything (V2X) further elevates road safety and fosters the progress of ITS through enabling direct vehicle communication and interaction with infrastructure. However, the penetration rate of V2X vehicles is advancing gradually. Consequently, there will be mixed scenarios on the road, involving both on-board units (OBUs)-equipped and non-equipped vehicles. This results in disparities in communication capabilities, highlighting the need to ensure the efficient and safe operation of vehicles in such mixed scenarios. This paper addresses this challenge by presenting a feasibility analysis and prediction method for lane-changing overtaking maneuvers in mixed scenarios, specifically for vehicles equipped with OBUs. This method assists vehicles in completing overtaking maneuvers by offering a non-binary lane-changing overtaking feasibility index along with corresponding speed guidance. First, vehicle sensors are used to sense the state of surrounding vehicles, addressing any missing sensor data due to occlusions. Moreover, the future driving behavior of the vehicle is taken into account to more accurately predict the future state of the vehicle. Then, a deep reinforcement learning algorithm is deployed to process the hybrid action space to train a lane-changing overtaking model, which also takes into account the influence of the flow of each lane in front of the vehicle, and finally predicts the feasibility of the vehicle performing lane-changing overtaking. Experimental results demonstrate that our method can accurately predict the vehicle’s future state and effectively assist the vehicle in completing lane-changing overtaking maneuvers. This research provides strong support for the integration of ITS and V2X technologies.
Liang Zhao 0004, Hui Qian 0012, Ammar Hawbani, Ahmed Yassin Al-Dubai, Zhiyuan Tan 0001, Keping Yu, Albert Y. Zomaya
IEEE Trans. Intell. Transp. Syst.5
2023 TouchEnc: a Novel Behavioural Encoding Technique to Enable Computer Vision for Continuous Smartphone User Authentication
abstract
We are increasingly required to prove our identity when using smartphones through explicit authentication processes such as passwords or physiological biometrics, e.g., authorising online banking transactions or unlocking smartphones. However, these methods are often annoying to input and do not guarantee that the genuine user remains the same. Thus, a modern verification process should differ from traditional authentication. In touch-based biometrics, a new approach must not verify what we draw but how we draw it. Our research proposes TouchEnc, a Deep Learning approach that outperforms conventional methods. Unlike Machine Learning methods, TouchEnc automates the feature extraction from touch gestures. TouchEnc achieves this by transforming and encoding touch behaviour into images, enabling continuous authentication through modern computer vision. Our approach has been tested on a popular and publicly available dataset to demonstrate its effectiveness. Results show that users can authenticate using TouchEnc with a single gesture containing users’ on-screen navigational behaviour, independent of drawing up, down, left, or right. TouchEnc achieves an 8.4% Equal Error Rate and a 96.7% Area Under the Curve using a single gesture. Furthermore, TouchEnc achieves up to 65% better Equal Error Rates when combining gestures compared to the related work.
Peter Aaby, Mario Valerio Giuffrida, William J. Buchanan, Zhiyuan Tan 0001
TrustCom4
2023 Challenges and Considerations in Data Recovery from Solid State Media: A Comparative Analysis with Traditional Devices
abstract
Data recovery for forensic analysis of both hard drives and solid state media presents its own unique set of challenges. Hard drives face mechanical failures and data fragmentation, but their sequential storage and higher success rates make recovery more feasible. Solid State Drives (SSDs), with no moving parts and no data fragmentation, provide faster access to data but may pose challenges due to wear levelling and data retention issues. This project examines the challenges of data recovery between hard drives and solid-state media and compares them against each other. This was achieved by running several tests on four types of storage media, one of which is a hard drive, and the others are different types of solid-state media. The tests indicated that most SSDs perform as expected; however, the Intel Optane drive retained a much higher percentage of deleted data than the other drives. Despite this, all of the evaluated SSDs retained less deleted data than the hard drive. It can therefore be argued that traditional forensic processes are incapable of recovering as much deleted data from solid-state media and that these processes must be re-examined.
Aidan Spalding, Zhiyuan Tan 0001, Kehinde O. Babaagba
TrustCom2
2023 Self-attention is What You Need to Fool a Speaker Recognition System
abstract
Speaker Recognition Systems (SRSs) are becoming increasingly popular in various aspects of life due to advances in technology. However, these systems are vulnerable to cyber threats, particularly adversarial attacks. Traditional adversarial attack methods, such as the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD), are designed for a white-box setting where attackers have complete knowledge of the inner workings of the target systems. This limits the practicality of these attacks. To overcome this limitation, we propose a new attack model that uses a neural network to generate adversarial examples directly, without the need for full knowledge of the recognition model in a target SRS. In addition, we have designed a novel loss function to balance the effectiveness and confidentiality of adversarial examples. Our new approach was evaluated against SincNet, a state-of- the-art SRS. Experimental results show that our approach achieves outstanding performance, with the best attack success rate of 99.83% and the best Signal-to-Noise Ratio (SNR) value of 41.30.
Fangwei Wang, Ruixin Song, Zhiyuan Tan 0001, Qingru Li, Changguang Wang
TrustCom3
2023 An omnidirectional approach to touch-based continuous authentication
abstract
This paper focuses on how touch interactions on smartphones can provide a continuous user authentication service through behaviour captured by a touchscreen. While efforts are made to advance touch-based behavioural authentication, researchers often focus on gathering data, tuning classifiers, and enhancing performance by evaluating touch interactions in a sequence rather than independently. However, such systems only work by providing data representing distinct behavioural traits. The typical approach separates behaviour into touch directions and creates multiple user profiles. This work presents an omnidirectional approach which outperforms the traditional method independent of the touch direction - depending on optimal behavioural features and a balanced training set. Thus, we evaluate five behavioural feature sets using the conventional approach against our direction-agnostic method while testing several classifiers, including an Extra-Tree and Gradient Boosting Classifier, which is often overlooked. Results show that in comparison with the traditional, an Extra-Trees classifier and the proposed approach are superior when combining strokes. However, the performance depends on the applied feature set. We find that the TouchAlytics feature set outperforms others when using our approach when combining three or more strokes. Finally, we highlight the importance of reporting the mean area under the curve and equal error rate for single-stroke performance and varying the sequence of strokes separately.
Peter Aaby, Mario Valerio Giuffrida, William J. Buchanan, Zhiyuan Tan 0001
Comput. Secur.4
2023 A Digital Twin-Assisted Intelligent Partial Offloading Approach for Vehicular Edge Computing
abstract
Vehicle Edge Computing (VEC) is a promising paradigm that exposes Mobile Edge Computing (MEC) to road scenarios. In VEC, task offloading can enable vehicles to offload the computing tasks to nearby Roadside Units (RSUs) that deploy computing capabilities. However, the highly dynamic network topology, strict low-delay constraints, and massive data of tasks of VEC pose significant challenges for implementing efficient offloading. Digital Twin-based VEC is emerging as a promising solution that enables real-time monitoring of the state of the VEC network through mapping and interaction between the physical and virtual worlds, thus assisting in making sound offload decisions in the physical world. Thus, this paper proposes an intelligent partial offloading scheme, namely, Digital Twin-Assisted Intelligent Partial Offloading (IGNITE). First, to find the optimal offloading space in advance, we combine the improved clustering algorithm with the Digital Twin (DT) technique, in which unreasonable decisions can be avoided by reducing the size of the decision space. Second, to reduce the overall cost of the system, Deep Reinforcement Learning (DRL) algorithm is employed to train the offloading strategy, allowing for automatic optimization of computational delay and vehicle service price. To improve the efficiency of cooperation between digital and physical spaces, a feedback mechanism is established. It can adjust the parameters of the clustering algorithm based on the final offloading results in this clustering. To the best of our knowledge, this is the first study on DT-assisted vehicle offloading that proposes a feedback mechanism, forming a complete closed loop as prediction-offloading-feedback. Extensive experiments demonstrate that IGNITE has significant advantages in terms of total system computational cost, total computational delay, and offloading success rate compared with its counterparts.
Liang Zhao 0004, Zijia Zhao, Enchao Zhang, Ammar Hawbani, Ahmed Yassin Al-Dubai, Zhiyuan Tan 0001, Amir Hussain 0001
IEEE J. Sel. Areas Commun.6
2023 Evaluation Mechanism for Decentralized Collaborative Pattern Learning in Heterogeneous Vehicular Networks
abstract
Collaborative machine learning, especially Federated Learning (FL), is widely used to build high-quality Machine Learning (ML) models in the Internet of Vehicles (IoV). In this paper, we study the performance evaluation problem in an inherently heterogeneous IoV, where the final models across the network are not identical and are computed on different standards. Previous studies assume that local agents are receiving data from the same phenomenon, and a same final model is fitted to them. However, this “one model fits all” approach leads to a biased performance evaluation of individual agents. We propose a general approach to measure the performance of individual agents, where the common knowledge and correlation between different agents are explored. Experimental results indicate that our evaluation scheme is efficient in these settings.
Cheng Qiao, Jing Qiu 0002, Zhiyuan Tan 0001, Geyong Min, Albert Y. Zomaya, Zhihong Tian 0001
IEEE Trans. Intell. Transp. Syst.3
2023 CDTier: A Chinese Dataset of Threat Intelligence Entity Relationships
abstract
Cyber Threat Intelligence (CTI), which is knowledge of cyberspace threats gathered from security data, is critical in defending against cyberattacks.However, there is no open-source CTI dataset for security researchers to effectively apply enormous CTI information for security analysis in the field of threat intelligence, particularly in the field of Chinese threat intelligence. As a result, for network security research and development, this article constructed a Chinese CTI entity relationship dataset–CDTier, which includes: 1) A threat entity extraction dataset composed of 100 CTI reports, 3744 threat sentences and 4259 threat knowledge objects; 2) A dataset for entity relation extraction including 100 CTI reports, 2598 threat sentences and 2562 knowledge object relations. CDTier is, as far as we know, the first CTI dataset. On the CDTier, we trained 4 models for threat entity extraction and relation extraction using well-established and widely used deep learning methods in the NLP. The results showed that the model trained on CDTier extracts knowledge objects and their relationships described in threat intelligence more accurately. This significantly minimizes threat intelligence analysts’ work while assessing threat intelligence.
Yinghai Zhou, Yitong Ren, Yanjun Xiao 0001, Zhiyuan Tan 0001, Nour Moustafa, Zhihong Tian 0001
IEEE Trans. Sustain. Comput.5
2022 Special Issue on Adversarial AI to IoT Security and Privacy Protection: Attacks and Defenses
abstract
The prosperity of social IoT data brings revolutionary changes to our daily lives and greatly increases the existing data volume. But IoT data are vulnerable due to security and privacy issues. Over the past few years, malicious adversaries exploited various vulnerabilities of AI algorithms and thus compromised the security of AI systems. For example, obfuscating malware code within benign programs or applications to fool the AI-based intrusion detection systems. Thus, applying adversarial AI is supposed to be one of the most useful methods to protect IoT data, including big data mining and analysis, information diffusion, sentiment analysis and opinion mining, social event detection, trend prediction and influence maximization. This special issue brings together leading researchers and developers presenting their latest research and 10 high-quality papers are selected. A summary of these accepted papers is outlined below. In the paper entitled ‘AWFC: Preventing Label Flipping Attacks towards Federated Learning for Intelligent IoT’ by Zhuo Lv et al., the authors are motivated to prevent label flipping poisoning attacks by observing the changes in model parameters that were trained by different single labels. They propose a novel detection method, called AWFC, that label flipping attacks are detected by identifying the differences of classes in the data. The weight assignments in a fully connected layer of the neural network model are used and the statistical algorithm is applied to find the malicious clients. The experiments are conducted on benchmark data, such as Fashion-MNIST and Intrusion Detection Evaluation Dataset (CIC-IDS2017), where results demonstrate that the method’s detection accuracy is better.
Honghao Gao, Zhiyuan Tan 0001
Comput. J.2
2022 Toward machine intelligence that learns to fingerprint polymorphic worms in IoT
abstract
Internet of Things (IoT) is fast growing. Non-personal computer devices under the umbrella of IoT have been increasingly applied in various fields and will soon account for a significant share of total Internet traffic. However, the security and privacy of IoT and its devices have been challenged by malware, particularly polymorphic worms that rapidly self-propagate once being launched and vary their appearance over each infection to escape from the detection of signature-based intrusion detection systems. It is well recognized that polymorphic worms are one of the most intrusive threats to IoT security. To build an effective, strong defense for IoT networks against polymorphic worms, this study proposes a machine intelligent system, termed Gram-Restricted Boltzmann Machine (Gram-RBM), which automatically generates generic fingerprints/signatures for the polymorphic worm. Two augmented N-gram-based methods are designed and applied in the derivation of polymorphic worm sequences, also known as fingerprints/signatures. These derived sequences are then optimized using the Gaussian–Bernoulli RBM dimension-reduction algorithm. The results, gained from the experiments involved three different types of polymorphic worms, show that the system generates accurate fingerprints/signatures even under “noisy” conditions and outperforms related methods in terms of accuracy and efficiency.
Fangwei Wang, Changguang Wang, Qingru Li, Kehinde O. Babaagba, Zhiyuan Tan 0001
Int. J. Intell. Syst.6
2022 A novel flow-vector generation approach for malicious traffic detection
Jian Hou 0009, Fang'ai Liu, Hui Lu 0005, Zhiyuan Tan 0001, Xuqiang Zhuang, Zhihong Tian 0001
J. Parallel Distributed Comput.4
2022 A VMD and LSTM Based Hybrid Model of Load Forecasting for Power Grid Security
abstract
As the basis for the static security of the power grid, power load forecasting directly affects the safety of grid operation, the rationality of grid planning, and the economy of supply–demand balance. However, various factors lead to drastic changes in short-term power consumption, making the data more complex and thus more difficult to forecast. In response to this problem, a new hybrid model based on variational mode decomposition and long short-term memory with seasonal factors elimination and error correction is proposed in this article. Comprehensive case studies on four real-world load datasets from Singapore and the United States are employed to demonstrate the effectiveness and practicality of the proposed hybrid model. The experimental results show that the prediction accuracy of the proposed model is significantly higher than that of the contrast models.
Lingling Lv, Zongyu Wu 0002, Lei Zhang 0115, Zhiyuan Tan 0001, Zhihong Tian 0001
IEEE Trans. Ind. Informatics5
2022 Editorial: Big data technologies and applications
Yulei Wu, Yi Pan 0001, Payam M. Barnaghi, Zhiyuan Tan 0001, Jingguo Ge, Hao Wang 0003
Wirel. Networks4
2022 NgramPOS: a bigram-based linguistic and statistical feature process model for unstructured text classification
Sepideh Foroozan Yazdani, Zhiyuan Tan 0001, Mohsen Kakavand, Aida Mustapha
Wirel. Networks2
2021 Newly engineered energy-based features for supervised anomaly detection in a physical model of a water supply system
Andres Robles-Durazno, Naghmeh Moradpoor Sheykhkanloo, James McWhinnie, Gordon Russell 0001, Zhiyuan Tan 0001
Ad Hoc Networks5
2021 A novel tensor-information bottleneck method for multi-input single-output applications
Xiaohan Ren, Chenwei Cui 0001, Zhiyuan Tan 0001, Yulei Wu, Zhizhen Qin
Comput. Networks4
2021 Towards an energy balancing solution for wireless sensor network with mobile sink node
Craig Thomson, Isam Wadhaj, Zhiyuan Tan 0001, Ahmed Yassin Al-Dubai
Comput. Commun.3
2021 Conceptual text region network: Cognition-inspired accurate scene text detection
Chenwei Cui 0001, Zhiyuan Tan 0001, Amir Hussain 0001
Neurocomputing3
2021 Block-Sparse Coding-Based Machine Learning Approach for Dependable Device-Free Localization in IoT Environment
abstract
Device-free localization (DFL) locates targets without equipping with wireless devices or tag under the Internet-of-Things (IoT) architectures. As an emerging technology, DFL has spawned extensive applications in the IoT environment, such as intrusion detection, mobile robot localization, and location-based services. Current DFL-related machine learning (ML) algorithms still suffer from low localization accuracy and weak dependability/robustness because the group structure has not been considered in their location estimation, which leads to an undependable process. To overcome these challenges, we propose in this work a dependable block-sparse scheme by particularly considering the group structure of signals. An accurate and robust ML algorithm named block-sparse coding with the proximal operator (BSCPO) is proposed for DFL. In addition, a severe Gaussian noise is added in the original sensing signals for preserving network-related privacy as well as improving the dependability of the model. The real-world data-driven experimental results show that the proposed BSCPO achieves robust localization and signal-recovery performance even under severely noisy conditions and outperforms state-of-the-art DFL methods. For single-target localization, BSCPO retains high accuracy when the signal-to-noise ratio exceeds -10 dB. BSCPO is also able to localize accurately under most multitarget localization test cases.
Lingjun Zhao, Huakun Huang, Chunhua Su, Shuxue Ding, Huawei Huang, Zhiyuan Tan 0001, Zhenni Li
IEEE Internet Things J.6
2021 Blockchain for edge-enabled smart cities applications
Mian Ahmad Jan, Kuo-Hui Yeh, Zhiyuan Tan 0001, Yulei Wu
J. Inf. Secur. Appl.3
2021 A Novel Web Attack Detection System for Internet of Things via Ensemble Classification
abstract
Internet of Things (IoT) has become one of the fastest-growing technologies and has been broadly applied in various fields. IoT networks contain millions of devices with the capability of interacting with each other and providing functionalities that were never available to us before. These IoT networks are designed to provide friendly and intelligent operations through big data analysis of information generated or collected from an abundance of devices in real time. However, the diversity of IoT devices makes the IoT networks’ environments more complex and more vulnerable to various web attacks compared to traditional computer networks. In this article, we propose a novel ensemble deep learning based web attack detection system (EDL-WADS) to alleviate the serious issues that IoT networks faces. Specifically, we have designed three deep learning models to first detect web attacks separately. We then use an ensemble classifier to make the final decision according to the results obtained from the three deep learning models. In order to evaluate the proposed WADS, we have performed experiments on a public dataset as well as a real-word dataset running in a distributed environment. Experimental results show that the proposed system can detect web attacks accurately with low false positive and negative rates.
Chaochao Luo, Zhiyuan Tan 0001, Geyong Min, Wei Shi 0001, Zhihong Tian 0001
IEEE Trans. Ind. Informatics2
2021 Vehicular Computation Offloading for Industrial Mobile Edge Computing
abstract
Due to the limited local computation resource, industrial vehicular computation requires offloading the computation tasks with time-delay sensitive and complex demands to other intelligent devices (IDs) once the data is sensed and collected collaboratively. This article considers offloading partial computation tasks of the industrial vehicles (IVs) to multiple available IDs of the industrial mobile edge computing (MEC), including unmanned aerial vehicles (UAVs), and the fixed-position MEC servers, to optimize the system cost including execution time, energy consumption, and the ID rental price. Moreover, to increase the access probability of IV by the UAVs, the geographical area is divided into small partitions and schedule the UAVs regarding the regional IV density dynamically. A minimum incremental task allocation algorithm is proposed to divide the whole task and assign the divided units for the minimum cost increment each time. Experimental results show the proposed solution can significantly reduce the system cost.
Liang Zhao 0004, Kaiqi Yang 0002, Zhiyuan Tan 0001, Houbing Song, Ahmed Yassin Al-Dubai, Albert Y. Zomaya, Xianwei Li 0002
IEEE Trans. Ind. Informatics3
2021 A Novel Cost Optimization Strategy for SDN-Enabled UAV-Assisted Vehicular Computation Offloading
abstract
Vehicular computation offloading is a well-received strategy to execute delay-sensitive and/or compute-intensive tasks of legacy vehicles. The response time of vehicular computation offloading can be shortened by using mobile edge computing that offers strong computing power, driving these computation tasks closer to end users. However, the quality of communication is hard to guarantee due to the obstruction of dense buildings or lack of infrastructure in some zones. Unmanned Aerial Vehicles (UAVs), therefore, have become one of the means to establish communication links for the two ends owing to its characteristics of ignoring terrain and flexible deployment. To make a sensible decision of computation offloading, nevertheless vehicles need to gather offloading-related global information, in which Software-Defined Networking (SDN) has shown its advances in data collection and centralized management. In this paper, thus, we propose an SDN-enabled UAV-assisted vehicular computation offloading optimization framework to minimize the system cost of vehicle computing tasks. In our framework, the UAV and the Mobile Edge Computing (MEC) server can work on behalf of the vehicle users to execute the delay-sensitive and compute-intensive tasks. The UAV, in a meanwhile, can also be deployed as a relay node to assist in forwarding computation tasks to the MEC server. We formulate the offloading decision-making problem as a multi-players computation offloading sequential game, and design the UAV-assisted Vehicular computation Cost Optimization (UVCO) algorithm to solve this problem. Simulation results demonstrate that our proposed algorithm can make the offloading decision to minimize the Average System Cost (ASC).
Liang Zhao 0004, Kaiqi Yang 0002, Zhiyuan Tan 0001, Xianwei Li 0002, Suraj Sharma, Zhi Liu 0002
IEEE Trans. Intell. Transp. Syst.3
2021 A mobility aware duty cycling and preambling solution for wireless sensor network with mobile sink node
abstract
Abstract Utilising the mobilisation of a sink node in a wireless sensor network to combat the energy hole, or hotspot issue, is well referenced. However, another issue, that of energy spikes may remain. With the mobile sink node potentially communicating with some nodes more than others. In this study we propose the Mobility Aware Duty Cycling and Dynamic Preambling Algorithm (MADCaDPAL). This algorithm utilises an existing solution where a communication threshold is built between a mobile sink node using predictable mobility and static nodes on its path. MADCaDPAL bases decisions relating to node sleep function, moving to clear channel assessment and the subsequent sending of preambles on the relation between the threshold built by the static node and the position of the mobile sink node. MADCaDPAL achieves a reduction in average energy consumption of up to 80%, this when used in conjunction with a lightweight carrier-sense multiple access based MAC implementation. Maximum energy consumption amongst individual nodes is also brought closer to the average, reducing energy spikes and subsequently improving network lifetime. Additionally, frame delivery to the sink is improved overall.
Craig Thomson, Isam Wadhaj, Zhiyuan Tan 0001, Ahmed Yassin Al-Dubai
Wirel. Networks3
2020 Improving Classification of Metamorphic Malware by Augmenting Training Data with a Diverse Set of Evolved Mutant Samples
abstract
Detecting metamorphic malware provides a challenge to machine-learning models as trained models might not generalise to future mutant variants of the malware. To address this, we explore whether machine-learning models can be improved by augmenting training data-sets with samples of potential variants. These variants are generated using an evolutionary algorithm that evolves a behaviourally diverse set of mutants, optimised to avoid detection by a large set of existing detection-engines. Using features calculated from the behavioural trace of a sample as input, we evaluate the ability of five machine-learning methods to detect the new variants, show that the detection rate is considerably improved by including the new samples as training data, and that the classifiers still generalise over a range of malware. We then repeat this experiment using a sequence-based deep-learning method as the classifier, which is shown to out-perform the feature-based classifiers.
Kehinde O. Babaagba, Zhiyuan Tan 0001, Emma Hart
CEC2
2020 Automatic Generation of Adversarial Metamorphic Malware Using MAP-Elites
Kehinde O. Babaagba, Zhiyuan Tan 0001, Emma Hart
EvoApplications2
2020 A comprehensive survey of security threats and their mitigation techniques for next-generation SDN controllers
abstract
Summary Software Defined Network (SDN) and Network Virtualization (NV) are emerged paradigms that simplified the control and management of the next generation networks, most importantly, Internet of Things (IoT), Cloud Computing, and Cyber‐Physical Systems. The Internet of Things (IoT) includes a diverse range of a vast collection of heterogeneous devices that require interoperable communication, scalable platforms, and security provisioning. Security provisioning to an SDN‐based IoT network poses a real security challenge leading to various serious security threats due to the connection of various heterogeneous devices having a wide range of access protocols. Furthermore, the logical centralized controlled intelligence of the SDN architecture represents a plethora of security challenges due to its single point of failure. It may throw the entire network into chaos and thus expose it to various known and unknown security threats and attacks. Security of SDN controlled IoT environment is still in infancy and thus remains the prime research agenda for both the industry and academia. This paper comprehensively reviews the current state‐of‐the‐art security threats, vulnerabilities, and issues at the control plane. Moreover, this paper contributes by presenting a detailed classification of various security attacks on the control layer. A comprehensive state‐of‐the‐art review of the latest mitigation techniques for various security breaches is also presented. Finally, this paper presents future research directions and challenges for further investigation down the line.
Tao Han 0004, Syed Rooh Ullah Jan, Zhiyuan Tan 0001, Muhammad Usman 0015, Mian Ahmad Jan, Rahim Khan, Yongzhao Xu
Concurr. Comput. Pract. Exp.3
2020 Double-Arc Parallel Coordinates and its Axes re-Ordering Methods
abstract
Abstract The Parallel Coordinates Plot (PCP) is a popular technique for the exploration of high-dimensional data. In many cases, researchers apply it as an effective method to analyze and mine data. However, when today’s data volume is getting larger, visual clutter and data clarity become two of the main challenges in parallel coordinates plot. Although Arc Coordinates Plot (ACP) is a popular approach to address these challenges, few optimization and improvement have been made on it. In this paper, we do three main contributions on the state-of-the-art PCP methods. One approach is the improvement of visual method itself. The other two approaches are mainly on the improvement of perceptual scalability when the scale or the dimensions of the data turn to be large in some mobile and wireless practical applications. 1) We present an improved visualization method based on ACP, termed as double arc coordinates plot (DACP). It not only reduces the visual clutter in ACP, but use a dimension-based bundling method with further optimization to deals with the issues of the conventional parallel coordinates plot (PCP). 2)To reduce the clutter caused by the order of the axes and reveal patterns that hidden in the data sets, we propose our first dimensional reordering method, a contribution-based method in DACP, which is based on the singular value decomposition (SVD) algorithm. The approach computes the importance score of attributes (dimensions) of the data using SVD and visualize the dimensions from left to right in DACP according the score in SVD. 3) Moreover, a similarity-based method, which is based on the combination of nonlinear correlation coefficient and SVD algorithm, is proposed as well in the paper. To measure the correlation between two dimensions and explains how the two dimensions interact with each other, we propose a reordering method based on non-linear correlation information measurements. We mainly use mutual information to calculate the partial similarity of dimensions in high-dimensional data visualization, and SVD is used to measure global data. Lastly, we use five case scenarios to evaluate the effectiveness of DACP, and the results show that our approaches not only do well in visualizing multivariate dataset, but also effectively alleviate the visual clutter in the conventional PCP, which bring users a better visual experience.
Zhiyuan Tan 0001
Mob. Networks Appl.3
2020 Secure Information Transmissions in Wireless-Powered Cognitive Radio Networks for Internet of Medical Things
abstract
In this paper, we consider the issue of the secure transmissions for the cognitive radio-based Internet of Medical Things (IoMT) with wireless energy harvesting. In these systems, a primary transmitter (PT) will transmit its sensitive medical information to a primary receiver (PR) by a multi-antenna-based secondary transmitter (ST), where we consider that a potential eavesdropper may listen to the PT’s sensitive information. Meanwhile, the ST also transmits its own information concurrently by utilizing spectrum sharing. We aim to propose a novel scheme for jointly designing the optimal parameters, i.e., energy harvesting (EH) time ratio and secure beamforming vectors, for maximizing the primary secrecy transmission rate while guaranteeing secondary transmission requirement. For solving the nonconvex optimization problem, we transfer the problem into convex optimization form by adopting the semidefinite relaxation (SDR) method and Charnes–Cooper transformation technique. Then, the optimal secure beamforming vectors and energy harvesting duration can be obtained easily by utilizing the CVX tools. According to the simulation results of secrecy transmission rate, i.e., secrecy capacity, we can observe that the proposed protocol for the considered system model can effectively promote the primary secrecy transmission rate when compared with traditional zero-forcing (ZF) scheme, while ensuring the transmission rate of the secondary system.
Wenjuan Tang, Zhiyuan Tan 0001, Weizhi Meng 0001, Lianyong Qi
Secur. Commun. Networks4
2020 Hybrid Tree-Rule Firewall for High Speed Data Transmission
abstract
Traditional firewalls employ listed rules in both configuration and process phases to regulate network traffic. However, configuring a firewall with listed rules may create rule conflicts, and slows down the firewall. To overcome this problem, we have proposed a Tree-rule firewall in our previous study. Although the Tree-rule firewall guarantees no conflicts within its rule set and operates faster than traditional firewalls, keeping track of the state of network connections using hashing functions incurs extra computational overhead. In order to reduce this overhead, we propose a hybrid Tree-rule firewall in this paper. This hybrid scheme takes advantages of both Tree-rule firewalls and traditional listed-rule firewalls. The GUIs of our Tree-rule firewalls are utilized to provide a means for users to create conflict-free firewall rules, which are organized in a tree structure and called 'tree rules'. These tree rules are later converted into listed rules that share the merit of being conflict-free. Finally, in decision making, the listed rules are used to verify against packet header information. The rules which have matched with most packets are moved up to the top positions by the core firewall. The mechanism applied in this hybrid scheme can significantly improve the functional speed of a firewall.
Thawatchai Chomsiri, Xiangjian He, Priyadarsi Nanda, Zhiyuan Tan 0001
IEEE Trans. Cloud Comput.4
2020 Introduction to the Special Issue on Privacy and Security in Evolving Internet of Multimedia Things
abstract
introduction Introduction to the Special Issue on Privacy and Security in Evolving Internet of Multimedia Things Share on Editors: Suraj Sharma View Profile , Xuyun Zhang View Profile , Hesham El-Sayed View Profile , Zhiyuan Tan View Profile Authors Info & Claims ACM Transactions on Multimedia Computing, Communications, and ApplicationsVolume 16Issue 3sOctober 2020 Article No.: 93pp 1–3https://doi.org/10.1145/3423955Online:17 December 2020Publication History 0citation77DownloadsMetricsTotal Citations0Total Downloads77Last 12 Months38Last 6 weeks1 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Suraj Sharma, Xuyun Zhang, Hesham El-Sayed, Zhiyuan Tan 0001
ACM Trans. Multim. Comput. Commun. Appl.4
2019 A Multi-attributes-Based Trust Model of Internet of Vehicle
Wei Ou, Zhiyuan Tan 0001, Lihong Xiang, Qin Yi, Chen Tian 0009
NSS3
2019 Urban data management system: Towards Big Data analytics for Internet of Things based smart urban environment using customized Hadoop
Muhammad Babar 0002, Fahim Arif, Mian Ahmad Jan, Zhiyuan Tan 0001, Fazlullah Khan
Future Gener. Comput. Syst.4
2019 A caching and spatial K-anonymity driven privacy enhancement scheme in continuous location-based services
Shaobo Zhang 0001, Xiong Li 0002, Zhiyuan Tan 0001, Tao Peng 0011, Guojun Wang 0001
Future Gener. Comput. Syst.3
2019 Deriving ChaCha20 key streams from targeted memory analysis
Peter McLaren, William J. Buchanan, Gordon Russell 0001, Zhiyuan Tan 0001
J. Inf. Secur. Appl.4
2019 SmartEdge: An end-to-end encryption framework for an edge-enabled smart city application
Mian Ahmad Jan, Muhammad Usman 0015, Zhiyuan Tan 0001, Fazlullah Khan
J. Netw. Comput. Appl.4
2019 Design of multi-view based email classification for IoT systems via semi-supervised learning
Wenjuan Li 0001, Weizhi Meng 0001, Zhiyuan Tan 0001, Yang Xiang 0001
J. Netw. Comput. Appl.3
2019 Copy-move forgery detection using combined features and transitive matching
Cong Lin 0003, Wei Lu 0001, Xinchao Huang, Wei Sun 0007, Hanhui Lin, Zhiyuan Tan 0001
Multim. Tools Appl.7
2018 Performance of Cognitive Radio Sensor Networks Using Hybrid Automatic Repeat ReQuest: Stop-and-Wait
Fazlullah Khan, Ateeq Ur Rehman 0001, Muhammad Usman 0015, Zhiyuan Tan 0001, Deepak Puthal
Mob. Networks Appl.4
2017 A framework for data security in cloud using collaborative intrusion detection scheme
abstract
Cloud computing offers an on demand, elastic, global network access to a shared pool of resources that can be configured on user demand. The advantages of cloud computing are lucrative for well-established organizations looking to reduce infrastructure cost overheads. However, the users are not quite confident in entrusting their data to the cloud due to security threats and risks perceived in the cloud domain. Issues involving privacy requirements for the cloud and best practices in the cloud are suggested in this paper. Although the cloud provider ensures security in the cloud yet the flow of data, storage location, data computing process and security breaches are not transparent to the cloud customer. This distrust and lack of control on data is a major hindrance for potential cloud customers in adopting the cloud models for their businesses. Intrusion Detection Systems (IDSs) are widely used to detect malicious activities. However existing solutions with IDSs involving DDoS and other non-detectable events may not be suitable in applying to the cloud due to distributed data storage and a major shift in Internet access mechanisms offered by cloud providers. Hence there is a strong need to analyze an appropriate IDS to counter DDoS attacks in the cloud. In this paper we propose a novel framework for data security in the cloud using Collaborative Intrusion Detection (CIDS) scheme. The benefits of CIDS scheme in cloud are enabling the end user to get comprehensive information in the event of a distributed attack on cloud.
Upasana T. Nagar, Priyadarsi Nanda, Xiangjian He, Zhiyuan Tan 0001
SIN4
2016 Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm
abstract
Redundant and irrelevant features in data have caused a long-term problem in network traffic classification. These features not only slow down the process of classification but also prevent a classifier from making accurate decisions, especially when coping with big data. In this paper, we propose a mutual information based algorithm that analytically selects the optimal feature for classification. This mutual information based feature selection algorithm can handle linearly and nonlinearly dependent data features. Its effectiveness is evaluated in the cases of network intrusion detection. An Intrusion Detection System (IDS), named Least Square Support Vector Machine based IDS (LSSVM-IDS), is built using the features selected by our proposed feature selection algorithm. The performance of LSSVM-IDS is evaluated using three intrusion detection evaluation datasets, namely KDD Cup 99, NSL-KDD and Kyoto 2006+ dataset. The evaluation results show that our feature selection algorithm contributes more critical features for LSSVM-IDS to achieve better accuracy and lower computational cost compared with the state-of-the-art methods.
Mohammed A. Ambusaidi, Xiangjian He, Priyadarsi Nanda, Zhiyuan Tan 0001
IEEE Trans. Computers4
2015 Detection of Denial-of-Service Attacks Based on Computer Vision Techniques
abstract
Detection of Denial-of-Service (DoS) attacks has attracted researchers since 1990s. A variety of detection systems has been proposed to achieve this task. Unlike the existing approaches based on machine learning and statistical analysis, the proposed system treats traffic records as images and detection of DoS attacks as a computer vision problem. A multivariate correlation analysis approach is introduced to accurately depict network traffic records and to convert the records into their respective images. The images of network traffic records are used as the observed objects of our proposed DoS attack detection system, which is developed based on a widely used dissimilarity measure, namely Earth Mover's Distance (EMD). EMD takes cross-bin matching into account and provides a more accurate evaluation on the dissimilarity between distributions than some other well-known dissimilarity measures, such as Minkowski-form distance Lpand X2statistics. These unique merits facilitate our proposed system with effective detection capabilities. To evaluate the proposed EMD-based detection system, ten-fold cross-validations are conducted using KDD Cup 99 dataset and ISCX 2012 IDS Evaluation dataset. The results presented in the system evaluation section illustrate that our detection system can detect unknown DoS attacks and achieves 99.95 percent detection accuracy on KDD Cup 99 dataset and 90.12 percent detection accuracy on ISCX 2012 IDS evaluation dataset with processing capability of approximately 59,000 traffic records per second.
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001, Jiankun Hu
IEEE Trans. Computers1
2014 A Novel Feature Selection Approach for Intrusion Detection Data Classification
abstract
Intrusion Detection Systems (IDSs) play a significant role in monitoring and analyzing daily activities occurring in computer systems to detect occurrences of security threats. However, the routinely produced analytical data from computer networks are usually of very huge in size. This creates a major challenge to IDSs, which need to examine all features in the data to identify intrusive patterns. The objective of this study is to analyze and select the more discriminate input features for building computationally efficient and effective schemes for an IDS. For this, a hybrid feature selection algorithm in combination with wrapper and filter selection processes is designed in this paper. Two main phases are involved in this algorithm. The upper phase conducts a preliminary search for an optimal subset of features, in which the mutual information between the input features and the output class serves as a determinant criterion. The selected set of features from the previous phase is further refined in the lower phase in a wrapper manner, in which the Least Square Support Vector Machine (LSSVM) is used to guide the selection process and retain optimized set of features. The efficiency and effectiveness of our approach is demonstrated through building an IDS and a fair comparison with other stateof-the-art detection approaches. The experimental results show that our hybrid model is promising in detection compared to the previously reported results.
Mohammed A. Ambusaidi, Xiangjian He, Zhiyuan Tan 0001, Priyadarsi Nanda, Upasana T. Nagar
TrustCom3
2014 A Stateful Mechanism for the Tree-Rule Firewall
abstract
In this paper, we propose a novel connection tracking mechanism for Tree-rule firewall which essentially organizes firewall rules in a designated Tree structure. A new firewall model based on the proposed connection tracking mechanism is then developed and extended from the basic model of Net filter's Conn Track module, which has been used by many early generation commercial and open source firewalls including IPTABLES, the most popular firewall. To reduce the consumption of memory space and processing time, our proposed model uses one node per connection instead of using two nodes as appeared in Net filter model. This can reduce memory space and processing time. In addition, we introduce an extended hash table with more hashing bits in our firewall model in order to accommodate more concurrent connections. Moreover, our model also applies sophisticated techniques (such as using static information nodes, and avoiding timer objects and memory management tasks) to improve its processing speed. Finally, we implement this model on Linux Cent OS 6.3 and evaluate its speed. The experimental results show that our model performs more efficiently in comparison with the Net filter/IPTABLES.
Thawatchai Chomsiri, Xiangjian He, Priyadarsi Nanda, Zhiyuan Tan 0001
TrustCom4
2014 A Robust Authentication Scheme for Observing Resources in the Internet of Things Environment
abstract
The Internet of Things is a vision that broadens the scope of the internet by incorporating physical objects to identify themselves to the participating entities. This innovative concept enables a physical device to represent itself in the digital world. There are a lot of speculations and future forecasts about the Internet of Things devices. However, most of them are vendor specific and lack a unified standard, which renders their seamless integration and interoperable operations. Another major concern is the lack of security features in these devices and their corresponding products. Most of them are resource-starved and unable to support computationally complex and resource consuming secure algorithms. In this paper, we have proposed a lightweight mutual authentication scheme which validates the identities of the participating devices before engaging them in communication for the resource observation. Our scheme incurs less connection overhead and provides a robust defence solution to combat various types of attacks.
Mian Ahmad Jan, Priyadarsi Nanda, Xiangjian He, Zhiyuan Tan 0001, Ren Ping Liu 0001
TrustCom4
2014 Towards Designing an Email Classification System Using Multi-view Based Semi-supervised Learning
abstract
The goal of email classification is to classify user emails into spam and legitimate ones. Many supervised learning algorithms have been invented in this domain to accomplish the task, and these algorithms require a large number of labeled training data. However, data labeling is a labor intensive task and requires in-depth domain knowledge. Thus, only a very small proportion of the data can be labeled in practice. This bottleneck greatly degrades the effectiveness of supervised email classification systems. In order to address this problem, in this work, we first identify some critical issues regarding supervised machine learning-based email classification. Then we propose an effective classification model based on multi-view disagreement-based semi-supervised learning. The motivation behind the attempt of using multi-view and semi-supervised learning is that multi-view can provide richer information for classification, which is often ignored by literature, and semi-supervised learning supplies with the capability of coping with labeled and unlabeled data. In the evaluation, we demonstrate that the multi-view data can improve the email classification than using a single view data, and that the proposed model working with our algorithm can achieve better performance as compared to the existing similar algorithms.
Wenjuan Li 0001, Weizhi Meng 0001, Zhiyuan Tan 0001, Yang Xiang 0001
TrustCom3
2014 Improving cloud network security using the Tree-Rule firewall
Xiangjian He, Thawatchai Chomsiri, Priyadarsi Nanda, Zhiyuan Tan 0001
Future Gener. Comput. Syst.4
2014 A System for Denial-of-Service Attack Detection Based on Multivariate Correlation Analysis
abstract
Interconnected systems, such as Web servers, database servers, cloud computing servers and so on, are now under threads from network attackers. As one of most common and aggressive means, denial-of-service (DoS) attacks cause serious impact on these computing systems. In this paper, we present a DoS attack detection system that uses multivariate correlation analysis (MCA) for accurate network traffic characterization by extracting the geometrical correlations between network traffic features. Our MCA-based DoS attack detection system employs the principle of anomaly based detection in attack recognition. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Furthermore, a triangle-area-based technique is proposed to enhance and to speed up the process of MCA. The effectiveness of our proposed detection system is evaluated using KDD Cup 99 data set, and the influences of both non-normalized data and normalized data on the performance of the proposed detection system are examined. The results show that our system outperforms two other previously developed state-of-the-art approaches in terms of detection accuracy.
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
IEEE Trans. Parallel Distributed Syst.1
2013 RePIDS: A multi tier Real-time Payload-based Intrusion Detection System
Aruna Jamdagni, Zhiyuan Tan 0001, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
Comput. Networks2
2012 Triangle-Area-Based Multivariate Correlation Analysis for Effective Denial-of-Service Attack Detection
abstract
Cloud computing plays an important role in current converged networks. It brings convenience of accessing services and information to users regardless of location and time. However, there are some critical security issues residing in cloud computing, such as availability of services. Denial of service occurring on cloud computing has even more serious impact on the Internet. Therefore, this paper studies the techniques for detecting Denial-of-Service (DoS) attacks to network services and proposes an effective system for DoS attack detection. The proposed system applies the idea of Multivariate Correlation Analysis (MCA) to network traffic characterization and employs the principal of anomaly-based detection in attack recognition. This makes our solution capable of detecting known and unknown DoS attacks effectively by learning the patterns of legitimate network traffic only. Furthermore, a triangle area technique is proposed to enhance and speed up the process of MCA. The effectiveness of our proposed detection system is evaluated on the KDD Cup 99 dataset, and the influence of both non-normalized and normalized data on the performance of the detection system is examined. The results presented in the system evaluation section illustrate that our DoS attack detection system outperforms two state-of-the-art approaches.
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
TrustCom1
2011 Multivariate Correlation Analysis Technique Based on Euclidean Distance Map for Network Traffic Characterization
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
ICICS1
2011 Denial-of-Service Attack Detection Based on Multivariate Correlation Analysis
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001
ICONIP (3)1
2010 A Two-Tier System for Web Attack Detection Using Linear Discriminant Method
Zhiyuan Tan 0001, Aruna Jamdagni, Xiangjian He, Priyadarsi Nanda, Ren Ping Liu 0001, Wenjing Jia, Wei-Chang Yeh 0001
ICICS1
2010 Intrusion detection using GSAD model for HTTP traffic on web services
abstract
Intrusion detection systems are widely used security tools to detect cyber-attacks and malicious activities in computer systems and networks. Hypertext Transport Protocol (HTTP) is used for new applications without much interference. In this paper, we focus on intrusion detection of HTTP traffic by applying pattern recognition techniques using our Geometrical Structure Anomaly Detection (GSAD) model. Experimental results reveal that features extracted from HTTP request using GSAD model can be used to distinguish anomalous traffic from normal traffic, and attacks carried out over HTTP traffic can be identified. We evaluate and compare our results with the results of PAYL intrusion detection systems for the test of DARPA 1999 IDS data set. The results show GSAD has high detection rates and low false positive rates.
Aruna Jamdagni, Zhiyuan Tan 0001, Priyadarsi Nanda, Xiangjian He, Ren Ping Liu 0001
IWCMC2
2009 Web Service Locating Unit in RFID-Centric Anti-counterfeit System
abstract
The problem of piracy has disturbed people’s daily life for hundreds of years and has not been relieved until now, though many existing anti-counterfeit solutions have been applied. However, due to the emergences of Radio Frequency IDentification (RFID) technologies, there is a more reliable alternative solution to construct authentication system. On the other hand, there arises another issue of how to simplify the deployment of RFID-centric anti-counterfeit system over the Internet. In this article, we propose an approach, Web Service Locating Unit (WSLU), to achieve this goal to manage numbers of RFID-centric authentication services (relied on web services).
Zhiyuan Tan 0001, Xiangjian He, Priyadarsi Nanda
ISPA1