EDBT 2026 Demo / reviewers in the wild / expert
Jian-Zhen Luo
dblp:130/0283 · also Jianzhen Luo
· DBLP profile ↗
18ranked-venue papers
4as first author
12since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 4 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Reliable broadcasting-based content acquisition for named data MANETsabstractAbstract Traditional IP-based unicast routing cannot utilize the inherent broadcast property of wireless network, and unicast path can be broken down frequently due to node mobility. Based on the nature of named data networking (NDN) which faces “content” rather than “host”, broadcast mode can be applied for content delivery in named data mobile ad hoc networks (ND-MANETs). However, since there are no acknowledgment and retransmission mechanisms in the broadcast mode of IEEE 802.11 protocol, it would cause the problem of transmission unreliability. Moreover, if all forwarding nodes transmit packet concurrently, it can easily lead to collision and redundancy. This paper presents a reliable broadcasting-based content acquisition scheme for highly dynamic ND-MANETs, which makes full use of the inherent broadcast nature of wireless network, and solves the unreliability, collision, and redundancy problems. We define Transmission Reliability Degree ($TRD$) for broadcast mode, and estimate its value through Markov model. A content-oriented and $TRD$ of sending node-based resend algorithm is proposed to improve reliability of broadcast transmission. An area divided and $TRD$ of receiving node-based reforwarding algorithm is proposed to reduce collision and redundancy. Simulation results demonstrate the effectiveness and efficiency of the proposed mechanism. Jian Kuang 0003, Bailin Xie, Jian-Zhen Luo |
Comput. J. | 3 |
| 2025 | STMBAD: Spatio-Temporal Multimodal Behavior Anomaly Detector for Industrial Control SystemsabstractModern cyber attacks against industrial control systems (ICSs) are highly stealthy, persistent, and targeted. Existing anomaly detection methods are mainly based on a set of rules defining correct behaviors and use loosely bounded detection thresholds, which can be exploited by attackers to evade detection. In this article, we propose STMBAD, a spatio-temporal multimodal behavior anomaly detector based on spatio-temporal ICS behavior analysis to improve the performance of ICS anomaly detection. STMBAD leverages the rich information available in industrial multimodal data to achieve a deep understanding of complex ICS behaviors and enhance the ability to detect stealthy attacks. To avoid data processing cross heterogeneous type/structure and temporal confusion caused by unsynchronized time series, STMBAD embeds time series of individual modality separately into variate tokens and applies the attention mechanism and feedforward network to capture multivariate correlations and interdependencies. Meanwhile, based on the attention mechanisms, temporal evolution law and spatial correlation of different modalities can be captured to model the characteristics of the spatio-temporal multimodal behavior of ICS. When detecting attacks, an adaptive detection mechanism combining global and local detection is proposed to utilize dynamic thresholds at different levels and reduce errors caused by a loose global threshold. The simulation results show that the proposed method outperforms the baseline methods and yields the highest F1 score, reaching 95%. Jian-Zhen Luo, Yan Cai 0022, Jun Cai 0002, Wanhan Fang, Wenwei Zheng |
IEEE Trans. Ind. Informatics | 1 |
| 2025 | Corrections to "STMBAD: Spatio-Temporal Multimodal Behavior Anomaly Detector for Industrial Control Systems"abstractPresents corrections to the article “STMBAD: Spatio-Temporal Multimodal Behavior Anomaly Detector for Industrial Control Systems”. Jian-Zhen Luo, Yan Cai 0022, Jun Cai 0002, Wanhan Fang, Wenwei Zheng |
IEEE Trans. Ind. Informatics | 1 |
| 2024 | ICS Anomaly Detection Based on Sensor Patterns and Actuator Rules in Spatiotemporal DependencyabstractData-driven methods, such as deep learning, are widely adopted to detect cyberattacks for Industrial control systems (ICSs). Due to the neglect of entity spatial relationships (ESR), however, there is a potential discrepancy between the learned device topology and the real physical process. Meanwhile, existing methods confuse sensor patterns, actuator rules, and some interference within spatiotemporal dependence, suffering from undetected attack issue. To achieve precise detection without using design knowledge, we propose a sensor-actuator separated anomaly detection method (SA2) that distinguishes sensor patterns and actuator rules, constructing prediction models for sensors (PM-SEN) and actuators (PM-ACT) separately. Moreover, we propose an ESR-based topology construction method for providing process-conformed topology and an attack span-based evaluation method for validating the undetected attack issue. The experimental results show that SA2 outperforms all baselines in the F1 score, effectively detecting all attacks (zero undetected rate), compared to an optimal baseline with an undetected rate of close to 50%. Jun Cai 0002, Zeheng Wei, Jian-Zhen Luo |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | LogBASA: Log Anomaly Detection Based on System Behavior Analysis and Global Semantic AwarenessabstractSystem log anomaly detection is important for ensuring stable system operation and achieving rapid fault diagnosis. System log sequences include data on the execution paths and time stamps of system tasks in addition to a large amount of semantic information, which enhances the reliability and effectiveness of anomaly detection. At the same time, considering the correlation between system log sequences can effectively improve fault diagnosis efficiency. However, the existing system log anomaly detection methods mostly consider only the sequence patterns or semantic information on the logs, so their anomaly detection results show a high rate of missed and false alarms. To solve these problems, this paper proposed an unsupervised log anomaly detection model (LogBASA) based on the system behavior analysis and global semantic awareness, aiming to decrease the leakage rate and increase the log sequence anomaly detection accuracy. First, a system log knowledge graph was constructed based on massive, unstructured, and multilevel system log data to represent log sequence patterns, which facilitates subsequent anomaly detection and localization. Then, a self‐attention encoder‐decoder transformer model was developed for log spatiotemporal association analysis. This model combines semantic mapping and spatiotemporal features of log sequences to analyze system behavior and log semantics in multiple dimensions. Furthermore, a system log anomaly detection method that combines adaptive spatial boundary delineation and sequence reconstruction objective functions was proposed. This method uses special words to characterize the log sequence states, delineates anomaly boundaries automatically, and reconstructs log sequences through unsupervised training for anomaly detection. Finally, the proposed method was verified by numerous experiments on three real datasets. The results indicate that the proposed method can achieve an accuracy rate of 99.3%, 95.1%, and 97.2% on HDFS, BGL, and Thunderbird datasets, which proves the effectiveness and superiority of the LogBASA model. Liping Liao, Jian-Zhen Luo, Jun Cai 0002 |
Int. J. Intell. Syst. | 3 |
| 2023 | EdgeSFG: A matching game mechanism for service function graph deployment in industrial edge computing environment
Liping Liao, Jun Cai 0002, Jian-Zhen Luo, Wenjing Zhang 0004 |
Inf. Sci. | 4 |
| 2022 | I Can Still Observe You: Flow-level Behavior Fingerprinting for Online Social NetworkabstractThe privacy of online social networks (OSNs) remains a major concern for today's Internet. Researchers have demonstrated that by analyzing inter-packet or packet-level network traffic, a third-party analyzer is able to fingerprint a user's OSN behavior information even when the traffic is encrypted. In this paper, we propose a learning-based approach that steps further to perform OSN behavior fingerprinting only through highly compressed, flow-level network traffic (e.g., NetFlow). By preprocessing flow records, segmenting traffic flows into bursts, and leveraging a long short-term memory network to classify the bursts, our approach can identify major OSN behaviors (e.g., Facebook post, Twitter Read, Weibo video, etc.) with nearly 90% accuracy. Compared with packet-level fingerprinting approaches, our approach significantly improves the fingerprinting efficiency in evaluations, making large-scale OSN usage monitoring feasible only with limited computing resources and coarse-grained network traffic. This work also reveals the huge risks facing privacy of OSN users on today's Internet today. Yebo Feng, Jian-Zhen Luo, Chengyan Ma 0001, Teng Li 0003, Liang Hui |
GLOBECOM | 2 |
| 2022 | SARM: Service function chain active reconfiguration mechanism based on load and demand predictionabstractNetwork function virtualization is a promising technology for providing personalized services via agile service function chains (SFCs). Flexible SFC orchestration and rational resource allocation are pivotal for improving the SFC's quality of service (QoS). However, the requirements for computational load and resources have frequently been changing. Consequently, static resource allocation can result in resource insufficiency when SFCs turn busy and resource waste due to resource overplus when SFCs are idle. Since a dynamic resource allocation is necessary, the existing dynamic resource allocation methods' responses have often been delayed. This paper proposes an SFC active reconfiguration mechanism (SARM) based on computational load and resource demand. The SARM predicts nodes' computation loads and SFCs' resource demands and uses these predictions to estimate future QoS and develop the SFC reconfiguration strategy. The SARM considers multiple factors and applies a heuristic algorithm to achieve the tradeoff between migration cost and QoS preservation. The experiments demonstrate that the SARM can effectively predict the nodes' load and the resource demand of SFCs. In addition, the SARM can successfully identify the SFCs to reconfigure and reduce the QoS maintenance costs. The simulation results indicate that the average delays of the SFCs can be reduced by at least 26%. Jun Cai 0002, Kaili Qian, Jian-Zhen Luo |
Int. J. Intell. Syst. | 3 |
| 2022 | CapBad: Content-Agnostic, Payload-Based Anomaly Detector for Industrial Control ProtocolsabstractEfficient anomaly detection methods are urgently needed to prevent attacks in the application layer of the Industrial Internet of Things (IIoT). The existing intrusion detection systems have certain limitations in detecting abnormal packets exploited by the application-layer attacks. In this article, a content-agnostic-payload-based anomaly detector named the CapBad is proposed to detect malicious packets in the application layer of the IIoT system. Specifically, a phase-aware hidden semi-Markov model (pHSMM) is used to model the industrial control protocol packets and automatically learn the packets’ payload characteristics. The packet types are then inferred based on the packet likelihoods obtained by the pHSMM. In addition, the probabilistic suffix tree is employed to analyze the packets’ contextual similarity to the historical packets. The abnormal packets are finally detected by comparing their contextual similarity with that of the historical normal packets. The proposed algorithm is verified by simulations, and the results show that the CapBad has an excellent performance in detecting abnormal packets in the application layer. Jun Cai 0002, Jian-Zhen Luo, Yan Liu 0042, Liping Liao |
IEEE Internet Things J. | 3 |
| 2022 | SeMiner: Side-Information-Based Semantics Miner for Proprietary Industrial Control ProtocolsabstractIndustrial control protocols (ICPs) are critical for Industrial Internet of Things to achieve interconnection and interaction between the industrial devices. To fully understand a large number of nonstandard and proprietary ICPs, protocol reverse engineering (PRE) techniques are commonly used to reconstruct the ICP specifications. However, existing PRE tools face difficulties in inferring the ICP semantics. Accordingly, this article proposes SeMiner as an ICP semantics analysis framework to achieve the packet field identification, protocol semantics inference, and behavior semantics modeling. Based on the collected graphical side information about the industrial processes, a series of semantic channels is identified using image processing techniques, and a modified Apriori algorithm is used to extract the frequent patterns of each semantic channel. Afterward, a heuristic method based on sequence alignment is designed to simultaneously identify the set of relevant packets and the position of packet fields relevant to the semantic channels. Finally, relying on the packet field semantics, the behavior semantics of industrial processes are modeled and the association rules between the semantic channels are extracted. Thorough experimental results reported herein verify the effectiveness of SeMiner and show the superior performance of SeMiner compared with the several other state-of-the-art algorithms. Jun Cai 0002, Weijian Zhong, Jian-Zhen Luo |
IEEE Internet Things J. | 3 |
| 2021 | APPM: Adaptive Parallel Processing Mechanism for Service Function ChainsabstractBy replacing traditional hardware-based middleboxes with software-based Virtual Network Functions (VNFs) running on general-purpose servers, network function virtualization represents a promising technique to reduce the cost of service creation and increase the agility of network operations. Typically, Service Function Chains (SFCs) are adopted to orchestrate dynamical network services and facilitate management of network applications. Recently, SFC parallelism that implements parallel processing of VNFs has been investigated to further improve SFC service quality. However, the unreasonable service graph of parallel processing in existing parallelized SFCs (PSFCs) might cause excessive resource consumption; incoordination between PSFC deployment and scheduling also increases the queuing delay of VNFs and degrades PSFC performance. In this article, an adaptive parallel processing optimization mechanism (APPM) is proposed to self-adaptively adjust the service graph of PSFCs and intelligently solve the joint problem of PSFC deployment and scheduling. Specifically, APPM uses a parallelism optimization algorithm (POA) based on the bin packing problem with soft bin capacity to optimize the structure of the PSFC service graph. Afterward, APPM employs a joint optimization algorithm based on reinforcement learning (JORL) to jointly deploy and schedule the PSFCs optimized by POA via the online perception of environment status. Simulation results showed that POA reduces the SFC parallelism degree and resource consumption by about 35%; JORL lowers SFC delay by reducing the queuing delay and has better overall performance than the state of the art algorithms even with limited resources. Jun Cai 0002, Zhongwei Huang, Liping Liao, Jian-Zhen Luo, Waixi Liu 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | On the Effective Parallelization and Near-Optimal Deployment of Service Function ChainsabstractNetwork operators compose Service Function Chains (SFCs) by tying different network functions (e.g., packet inspection, flow shaping, network address translation) together and process traffic flows in the order the network functions are chained. Leveraging the technique of Network Function Virtualization (NFV), each network function can be “virtualized” and decoupled from its dedicated hardware, and therefore can be deployed flexibly for better performance at any appropriate location of the underlying network infrastructure. However, an SFC often incurs high latency as traffic goes through the virtual network functions one after another. In this article, we first design an algorithm that leverages virtual network function dependency to convert an original SFC into a parallelized SFC (p-SFC). Then, to deploy multiple p-SFCs over the network for serving a large number of users, we model the deployment problem as an Integer Linear Program and propose a heuristic, ParaSFC, based on the Viterbi dynamic programming algorithm to estimate each p-SFC's occupation of the bottleneck resources and adjust the processing order of the p-SFCs in order to approximate the optimal solution. Finally, we conduct extensive trace-driven evaluations and exhibit that, compared to the Greedy method and the state-of-the-art CoordVNF method, ParaSFC reduces the average service latency of all the deployed p-SFCs by about 15 percent through parallelization while accommodating more SFC deployment requests over resource-limited networks. Jian-Zhen Luo, Jun Li 0001, Lei Jiao 0002, Jun Cai 0002 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2020 | Composing and deploying parallelized service function chains
Jun Cai 0002, Zhongwei Huang, Jian-Zhen Luo, Yan Liu 0042, Huimin Zhao 0001, Liping Liao |
J. Netw. Comput. Appl. | 3 |
| 2019 | Node importance to community based caching strategy for information centric networkingabstractSummary Information Centric Networking (ICN) is a novel future network architecture that is focusing on content distribution. Its ubiquitous caching schemes can improve network performance. In this paper, we propose a node importance to community based caching scheme with network coding in ICN, which is named as NICNC. For each community, content router makes cache decision depending on its node importance to community to make content cached more reasonable in temporal and spatial distribution. Moreover, by applying network coding into ICN, one coded blocks containing information of multiple chunks can satisfy multiple interests for different chunks sent by different consumers. This can significantly enhance cache diversity and cache hit rate without increasing cache capacity. Experimental results show that our scheme can improve the network performance at many aspects, such as average download time, cache hit rate, and instantaneous hop reduction rate. Chun Shan, Jun Cai 0002, Yan Liu 0042, Jian-Zhen Luo |
Concurr. Comput. Pract. Exp. | 4 |
| 2018 | A network community restructuring mechanism for transport efficiency improvement in scale-free complex networksabstractSummary Recent studies have demonstrated that network community structure can significantly reduce the network transport efficiency. In this paper, the weakening community structure (WCS) strategy based on adding of edges that can effectively weaken the network community characteristics and improve the network transport efficiency is proposed. The WCS performance was validated by experiments, which were performed on pseudo‐random network, scale‐free artificial network with community structures, and real internet, using the shortest path routing and the local routing. The experimental results have demonstrated that the WCS strategy can greatly improve the network load capacity and reduce the average length of the shortest path by adding a small amount of edges between communities. The proposed mechanism not only provides the improvement of network transport efficiency but also can be adapted for restraining of malicious information propagation through the network. Jun Cai 0002, Jian-Zhen Luo, Yan Liu 0042, Wenguo Wei, Fangyuan Lei |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | Enhancing network capacity by weakening community structure in scale-free network
Jun Cai 0002, Yu Wang 0017, Yan Liu 0042, Jian-Zhen Luo, Wenguo Wei, Xiaoping Xu |
Future Gener. Comput. Syst. | 4 |
| 2017 | Toward Fuzz Test Based on Protocol Reverse Engineering
Jun Cai 0002, Jian-Zhen Luo, Jianliang Ruan, Yan Liu 0042 |
ISPEC | 2 |
| 2013 | Position-based automatic reverse engineering of network protocols
Jian-Zhen Luo, Shunzheng Yu |
J. Netw. Comput. Appl. | 1 |