EDBT 2026 Demo / reviewers in the wild / expert
Chen Li 0066
dblp:164/3294-66
· DBLP profile ↗
20ranked-venue papers
0as first author
20since 2021 · last 2026
0000-0003-4307-0896ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 9 since 2021Human-computer interaction and ubiquitous computing · 9 · 9 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Efficient packet classification with updatable learned index for online network defenseabstractAbstract Packet classification is a cornerstone of network security functions, such as firewalls, access control, and network metering. It involves taking different actions on packets based on security rules to implement these network security functions. As networks continue to evolve and the number of network instances rapidly increases, the complexity and size of network security rule sets are also expanding. Additionally, autonomous defense systems with artificial intelligence that can detect and block online attacks have become a new trend in network security. Packet classifiers need to not only achieve fast rule matching under large rule sets but also support rapid rule updates in order to deploy security rules issued by online defense systems in a timely manner. However, existing packet classification methods struggle to balance lookup speed with update performance. To achieve rapid rule matching and support fast rule updates in networks, we propose a novel approach called the Learned Index Updatable Tree (LIPT) to address this challenge. LIPT partitions the rule set into single-field non-overlapping subsets and constructs dynamic learned index trees for each subset using keys obtained by sampling. To implement rule updates directly within the learned index tree without reconstruction, LIPT employs a gap array layout in the data nodes, which reserves space for rule insertion. To enhance lookup and update performance, LIPT addresses the challenge of direct range validation in the data node through payload-assisted validation, which helps quickly identify lookup and insertion locations. Furthermore, LIPT employs a simple linear regression model to construct the learned index tree, enabling swift lookup based on the predictive results of the linear regression model; it also utilizes a cost model to simplify the construction process. We conduct a comprehensive evaluation of LIPT’s performance, showing that both lookup and update speeds are significantly improved compared to existing algorithms that support rule updating. Compared to the benchmark algorithm PSTSS, LIPT’s update speed increases by 25%, and its classification speed increases by 242%. Chen Li 0066, Zixuan Ma, Xuefei Chen, Bibo Tu |
Cybersecur. | 2 |
| 2025 | Lightweight Distributed Cloud-Native Service Function Chain Anomaly Detection for Edge-Cloud NetworksabstractAnomaly detection in Service Function Chains (SFCs) is essential for ensuring the security of edge-cloud networks. However, edge servers in Industrial Internet of Things (IIoT) face challenges in meeting the real-time processing requirements for high-precision anomaly detection due to limited computational resources. In order to address this issue, we initially propose an architectural framework for in-band measurement of cloud-native SFC, which can efficiently detect the state information of virtual network functions (VNFs). Secondly, we propose LightSFC, a lightweight distributed edge-cloud network service function chain anomaly detection model. LightSFC achieves comprehensive awareness of the SFC state by collecting multi-source information from both the data plane and the control plane, and utilizes a lightweight deep Autoencoder model for proactive anomaly detection. Our experimental results show that LightSFC is capable of rapidly detecting anomalies with lower resource overhead. Compared to other methods, LightSFC exhibits superior performance in terms of accuracy, precision, recall, and F1-score, thereby substantiating its efficacy in SFC anomaly detection for edge-cloud networks. Xuefei Chen, Chen Li 0066, Bibo Tu |
CSCWD | 4 |
| 2025 | CPRAM: Cryptographic Performance-Aware Resource Affinity Management in Para-virtualized EnvironmentabstractThe rapid growth of cloud computing has made security a key challenge, with cryptographic technology playing a central role in ensuring the integrity and confidentiality of cloud services. Cryptographic services in the cloud are typically implemented using virtualized cryptographic resources, such as Virtual Cryptographic Machines (VCMs), which allow multiple tenants to share hardware cryptographic cards. The DPDK-based para-virtualized cryptographic card solution experiences performance degradation in NUMA-based multi-core systems due to cross-node memory access and resource affinity. This paper addresses these challenges by proposing Cryptographic Performance-Aware Resource Affinity Management (CPRAM), a method that optimizes cryptographic resource allocation while maintaining load balancing across shared system resources. CPRAM enhances VCM performance by considering both global hardware resource affinity and the impact of Intel DDIO on cryptographic card throughput. We establish priori models for affinity optimization. Our approach also mitigates the overhead of memory page migration through a multi-threaded migration strategy. We implement the prototype system and demonstrate the effectiveness of CPRAM on an Intel platform. The results show significant improvements in cryptographic performance, making CPRAM an efficient and scalable solution for cloud cryptographic services. Yanchang Feng, Chen Li 0066, Bibo Tu |
CSCWD | 3 |
| 2025 | ZTKA: A Zero-Trust Based Kernel Encryption Architecture for Transparent Data ProtectionabstractThe risk of data leakage has become a major challenge for various organizations. However, recent research has highlighted certain deficiencies in traditional data encryption schemes, significantly compromising the overall usability and security of systems especially for data in use. To address these challenges, this paper proposes a novel Linux kernellevel architecture based on zero-trust principles, named ZTKA. This architecture systematically integrates Zero Trust concepts, strictly adhering to the principle of least privilege access, and does not trust any other users or applications running on the same system. It achieves secure data isolation and protection of data in use. Our architecture ensures data security even in the event of partial system compromise by implementing secure key management, real-time data encryption, strict file isolation, and a series of performance optimization measures at the kernel level. The paper reviews the relevant theoretical background and provides empirical results from runtime measurements to compare performance and security with and without the kernel module. Observations indicate that the kernel-level architecture based on Zero Trust principles operates effectively across its modules, significantly enhancing the security of data usage in Linux while maintaining superior performance. Yanchang Feng, Xuefei Chen, Chen Li 0066, Bibo Tu |
CSCWD | 6 |
| 2025 | End-to-End Security Policy Automation with Multi-LLM Agents in Cloud-Native SystemsabstractMicroservice architectures have gained widespread adoption in cloud-native environments due to their flexibility and scalability. However, these architectures pose significant challenges in the automated generation and dynamic updating of fine-grained security policies. This paper presents LLM2policy, a novel framework that utilizes large language models (LLMs) for end-to-end automated security policy generation. LLM2policy extracts microservice entity information from deployment YAML files and identifies RPC call relationships from distributed tracing data, consolidating this information into a structured knowledge base. This knowledge base is then used to automatically generate Istio-compatible access control policies in YAML format, enabling dynamic policy updates. Evaluation results from five benchmark microservice systems demonstrate that LLM2policy achieves 100% accuracy in entity recognition and dependency extraction, over 98.81% accuracy in semantic extraction by the LLM, and unit test pass rates ranging from 93.75% to 100% for the generated policies. Furthermore, attack simulations confirm that the generated policies effectively mitigate unauthorized access, highlighting the practical applicability and robustness of LLM2policy in automated cloud-native security policy management. Xuefei Chen, Haohao Liu, Chen Li 0066, Bibo Tu |
TrustCom | 5 |
| 2025 | End-to-end anomaly detection of service function chain through multi-source data in cloud-native systems
Xuefei Chen, Jinfeng Kou, Haiqiang Li, Chen Li 0066, Bibo Tu |
Comput. Secur. | 6 |
| 2025 | Zero-trust based dynamic access control for cloud computingabstractAbstract Most corporations and organizations rely heavily on access control to protect data accessibility and enable resource sharing across networks and departments. However, with the development of cloud computing, traditional boundary protection struggles to mitigate the increasing attacks and threats. In addition, most existing dynamic access control methods match static rules with dynamic metrics, which cause system damage through their delayed responses to threats and attacks. The zero-trust architecture (ZTA) provides continuous authentication and dynamic authorization for all users to accommodate the security demands of cloud computing. Drawing inspiration from the ZTA, we first present a TBAC (Trust-based Access Control) model and design a trust assessment methodology to update user trustworthiness. Then, we introduce dynamic rules in the TBAC model to implement a dynamic access control system DR-TBAC (TBAC with Dynamic Rule). We apply the DQN (Deep Q-Network) algorithm to dynamically update the trust thresholds based on static rules comparing dynamic trust with predefined trust thresholds to achieve adaptive access control policies. In this paper, we rebuild the cloud security access environment from the perspective of dynamic trust and rule optimization and strengthen the constraints on user behaviors throughout the access control lifecycle of cloud computing. Finally, a thorough analysis and assessment regarding offline training models and the online deployment of the DR-TBAC system into the cloud platform highlight its security and accuracy relative to baseline models. Ri Wang, Chen Li 0066, Kun Zhang 0016, Bibo Tu |
Cybersecur. | 2 |
| 2025 | Behavioral Biometrics-Based Continuous Authentication Using a Lightweight Latent Representation Masked One-Class AutoencoderabstractBehavioral biometrics-based continuous authentication has proven to be an excellent supplement to one-time authentication schemes that applies behavioral biometrics to authenticate smartphone users’ identities throughout the session. However, it still has two key issues that need to be addressed: 1) Due to behavioral biometrics from attackers are not available a priori, continuous authentication models should be trained only with normal samples in an unsupervised manner rather than treated as binary or multi-class classification tasks; 2) Differences in behavioral biometrics between attackers and legitimate users are fine-grained, it is challenging to extract rich semantic information to model users’ behavioral patterns. To fill this gap, we propose a lightweight latent representation masked one-class autoencoder, which is trained only with legitimate users’ behavioral biometrics. It consists of two parts: masked latent representation generator (MLRG) and Reconstructor. First, we apply the MLRG to generate discriminative latent representation with low dimension and then as a mask to cover important parts of the latent representation generated from the Reconstructor. Second, we apply the Reconstructor to reconstruct input based on masked latent representation. Experimental results demonstrate that our approach achieves superior authentication performance of 0.68% EER, 0.94% EER, 2.14% EER, and 1.87% EER on four datasets, respectively. Ding Wang 0002, Chen Li 0066, Bibo Tu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | IMS: Towards Computability and Dynamicity for Intent-Driven Micro-SegmentationabstractMicro-segmentation (MSG), a pillar of Zero-Trust, provides fine-grained access control for east-west traffic between cloud endpoints (VMs/containers). Admins formulate strict whitelisting MSG policies that allow necessary traffic. However, current MSG systems lack the computability foundation to resolve policy inconsistencies, where policy overlap can cause conflicts that violate the security requirements, and to verify policy reachability to avoid erroneously blocking necessary traffic. Meanwhile, current MSG systems lack comprehensive dynamicity processing, including maintaining invariants when updating MSG policies and promptly adjusting policy enforcement for endpoint status changes. We propose IMS, the first intent-driven MSG system towards computability and dynamicity. IMS innovatively defines the endpoint group space and algebra, providing the computability foundation for formally and automatically verifying and processing MSG policies. Based on this, IMS implements functionalities to resolve policy inconsistencies and to verify policy reachability. Meanwhile, IMS achieves comprehensive and prompt dynamicity processing. IMS fulfils the verification and dynamicity processing requirements of intent-driven systems. We implement a prototype and evaluations show that the processing time of IMS functionalities scales linearly with the number of policies, and the average endpoint dynamicity processing time is 5.05 ms in the setup of 1,000 endpoints, illustrating that IMS is scalable and can process dynamicity promptly. Zixuan Ma, Chen Li 0066, Ruibang You, Bibo Tu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Towards Unsupervised Time-Series Anomaly Detection for Virtual Cloud NetworksabstractVirtual cloud network (VCN) is a fundamental cloud resource for endpoints (VMs or containers) to communicate with each other and with the outside. Anomaly detection, a key security approach for VCNs, faces serious challenges: 1) Current feature models are difficult to apply to VCNs with significant differences from traditional networks. 2) Current anomaly detection models lack the adaptability to learn multiple normal patterns simultaneously. The need to train a dedicated model for each endpoint causes serious scalability problems in VCNs. 3) Current anomaly detection models have difficulty addressing the complex temporal dependency and non-stationarity of VCNs. To address these challenges, we propose a new multilevel feature model MFM and a new unsupervised time-series anomaly detection model GTGmVAE. By combining the basic features with the topology features specifically designed for VCNs, MFM effectively characterizes the patterns of VCNs. GTGmVAE combines the new local-global feature extractor with the latent space following a Gaussian mixture distribution to achieve the strong adaptability to learn multiple normal patterns simultaneously, and achieves the strong temporal modeling capability to effectively address the complex temporal dependency and non-stationarity of VCNs by adequately modeling the global temporal dependencies of the input samples and latent variables. Extensive experiments on the VCN anomaly detection dataset CIC-IDS2018 and the time-series anomaly detection benchmark dataset SMD show that GTGmVAE with MFM achieves the desirable performance, and GTGmVAE outperforms all nine representative state-of-the-art detection models. Zixuan Ma, Chen Li 0066, Kun Zhang 0016, Bibo Tu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Desktop Virtualization Optimization Methods Based on IDV ArchitectureabstractWith the growing demand for users’ flexible use of office desktops and enterprises’ centralized management of information resources, desktop virtualization technologies, represented by remote desktops, have become a prominent approach in current desktop management. Among the mainstream desktop virtualization technologies, Intelligent Desktop Virtualization (IDV) architecture offers significant advantages regarding network dependency and resource utilization. However, the IDV scenario presents challenges on the server, such as the increasing number of centrally managed images, resource consumption due to frequent image pulling, and low efficiency in image synchronization. Moreover, the terminal faces an issue of not fully leveraging hardware resources. Considering the IDV-specific characteristics, we design and implement a set of optimization methods for desktop virtualization, which outperform traditional IDV solutions. Haojun Xia, Chen Li 0066, Bibo Tu |
CSCWD | 3 |
| 2024 | An Efficient Caching Mechanism for End-host Network FunctionsabstractThe end host serves as a natural enforcement point for various network functions (NFs), such as network address translators (NATs), firewalls, and load balancers. However, due to the limitations of the Linux networking stack, NFs struggle to achieve high performance when utilizing high-speed network interfaces. The eXpress Data Path (XDP) is a high-performance framework for packet processing within the Linux kernel. It operates as an optimized execution point before the networking stack. In contrast to kernel-bypass solutions like DPDK, XDP offers an appealing alternative by providing comparable performance with lower CPU usage.In this paper, we propose PFC, a novel approach that leverages XDP for Pre-Function table Caching. PFC acts as a packet header processor for incoming packets, it consists of two distinct facets: one involves traffic management within the end host, and the other focuses on processing requests from distributed applications. Experimental results show that PFC can significantly increase throughput and achieve the equivalent performance compared to DPDK. Furthermore, PFC can integrate seamlessly with existing systems without requiring any modifications to the applications. Haojun Xia, Chen Li 0066, Bibo Tu |
CSCWD | 3 |
| 2024 | EI-XIDS: An explainable intrusion detection system based on integration frameworkabstractThe application of Deep Learning (DL) in Intrusion Detection Systems (IDS) has become a focal point of research due to its outstanding performance. However, the black-box nature of these systems has raised concerns within the research community. Addressing this challenge, this paper draws upon the concept of ensemble learning and introduces an Explainable Intrusion Detection System (X-IDS), EI-XIDS. This system integrates a variety of advanced Explainable Artificial Intelligence (XAI) methods and adaptively selects them according to different scenarios through reinforcement learning. Comparative experiments demonstrate that EI-XIDS outperforms the current state-of-the-art explanation methods, achieving label flip rates of 97% and 96% on the NSL-KDD and UNSW-NB15 datasets, respectively. These results underscore EI-XIDS’s superior interpretability accuracy, robustness, and sparsity, showcasing its significant potential in the field of network security. Chen Li 0066, Kun Zhang 0016, Haojun Xia, Bibo Tu |
CSCWD | 2 |
| 2024 | CloudFusion: Multi-Source Intrusion Detection in Cloud EnvironmentsabstractAddressing the multifaceted security challenges inherent in cloud environments, our study delineates a robust, real-time threat detection framework. This methodology integrates three cardinal technologies: a memory access mechanism rooted in Virtual Machine Monitor (VMM) analytics, offering profound insights into the operational dynamics of virtual machines; a semantic reconstruction method, informed by software architectural tenets, adept at discerning intricate adversarial activities; and a log-oriented decoding and rule alignment mechanism tailored for sophisticated handling of cloud-based log data. In unison, these technologies forge a proficient, instantaneous threat detection paradigm. Applied and authenticated on a cloud platform, the proposed framework buttressed by judiciously crafted security protocols enables the contemporaneous surveillance of malicious incursions affecting virtual machines, host systems, and network data streams. Both functionality and efficiency assessments attest to the system’s adeptness in precise threat identification while ensuring minimal performance disruption for host and client systems. Kun Zhang 0016, Haojun Xia, Bibo Tu, Chen Li 0066 |
CSCWD | 5 |
| 2024 | Using KVM Events to Detect VM Memory-Sharing Lateral Movement Attacks in a Virtualized EnvironmentabstractVirtual machine (VM) memory-sharing lateral movement attacks are becoming more advanced, while detection methods against them are still perceived as non-practical. Especially the current detection methods can't detect the VM escape attack. In this paper, we introduce a novel monitoring approach to detect VM memory-sharing lateral movement attacks operations inside a virtualization environment. We utilize the Kernel Virtual Machine (KVM) event sequence data in the kernel and process this data using a machine learning technique to identify any VM memory-sharing lateral movement attacks operations in the guest VM. Experimental results demonstrate that our method successfully separates the VM memory-sharing lateral movement attacks datasets on VMs from the non attacks datasets on VMs, on both trained and nontrained data scenarios. Besides, we also explain the classification results by extracting the set of most important features that separate both classes using their Fisher scores and variance and show that our detecting approach can work to detect VM memory-sharing lateral movement attacks in general. Finally, we evaluate the overhead impact of our VM memory-sharing lateral movement attacks detecting method and show that it has a negligible computation overhead on the host and the guest VM. Kun Zhang 0016, Chen Li 0066 |
ISPA | 3 |
| 2023 | Who Gets in the Way of Parallelism? Analysis and Optimization of the Parallel Processing Bottleneck of SDN Flow Rules in ONOSabstractSoftware-Defined Networking (SDN) decouples the data plane from the control plane, enabling centralized control and open programmability of the network. OpenFlow flow rules are the key carrier for the SDN application to configure and manage the data plane through the control plane, and the processing efficiency of flow rules of the SDN controller in the control plane is critical as it will directly impact the instantaneity of configuring and managing the data plane. Currently, the controller increases the processing efficiency of flow rules by means of multi-threaded parallel processing. However, in the experiments of the widely used SDN controller ONOS, we found a new bottleneck in the parallel processing of flow rules that causes the performance gains from parallelism to be offset. Therefore, in this paper, we locate the bottleneck and analyze its causes through source code analysis and timestamp tests, propose a parallel event queue to resolve the bottleneck, and implement it in ONOS. Experiments show that our improved ONOS effectively resolves the bottleneck problem and achieves an average 3.57x improvement in the processing efficiency of flow rules compared to the original ONOS. Zixuan Ma, Ruibang You, Chen Li 0066 |
CSCWD | 4 |
| 2023 | Continuous User Trust Assessment Based on Emphasized Contextual Differentiation Behavior AnalysisabstractMasquerade attacks are one of the most dangerous threats in the cloud environment. Attackers masquerade as legitimate users obtaining access to illegally use cloud resources. If attackers masquerades as internal administrator with top-level privileges, they can change security policies or convey confidential information, causing irreparable damage to the system. Building trust on the user side is an important auxiliary to protect cloud resources. Most user trust evaluation research mainly extracts user behavior features to train basic machine learning models, which cannot accurately track abnormal user behavior in real time. In this paper, we propose a continuous user trust assessment scheme as an additional security layer to enhance secure access to cloud resources, which can effectively fuse behavior and contextual information to automatically detect user anomalies and serve as a criterion to assess user trust status. We test on an open-source Windows security log dataset. The experiments show that our approach continuously assesses user trust with good detection performance and alerts on time. Ri Wang, Chen Li 0066, Ruibang You |
CSCWD | 2 |
| 2022 | A Novel Discrete Bi-objective Optimization Method for Virtual Machine PlacementabstractAccording to the cloud computing paradigm, cloud providers can offer computing infrastructure as a service in virtual machines (VMs) running on physical machines (PMs). A data center relies on a VM placement (VMP) algorithm to allocate VMs to the appropriate PMs. As VMs are running on PMs, cloud services providers need to consider operating costs and minimize energy consumption to reduce costs. Meanwhile, multiple VMs running on fewer PMs will result in excellent resource contention, affecting the user experience. How to reduce energy consumption while maintaining VM performance remains a challenge. Although some existing VMPs study VM performance degradation, they do not consider the PM’s state, which will result in errors occurring when predicting VM performance. Moreover, many current VMP algorithms converge too slowly and easily fall into the local optimum solutions. So in this paper, first, we build the energy consumption model based on real data sets to obtain more accurate energy consumption values. Second, we investigate and model VM performance in CPU and memory. Third, we formulate the VMP as a discrete optimization problem based on the energy consumption model and VM performance model. We then propose a novel bi-objective discrete VMP (BDVMP) algorithm to solve it. Finally, we evaluate the BDVMP algorithm on both the CloudSim platform and the real Openstack platform. The results show the efficiency of our BDVMP algorithm. Yanchang Feng, Chen Li 0066, Bibo Tu |
ICPADS | 2 |
| 2021 | Log-based Anomaly Detection from Multi-view by Associating Anomaly Scores with User TrustabstractLogs, prevalent among nearly all computer systems, contain rich information that helps with troubleshooting or root cause analysis. Therefore, logs are excellent information sources for anomaly detection. Since logs are diverse and heterogeneous, to deal with all of them requires maintenance personnel to check detection results one by one, which is troublesome. This paper applies an ensemble method that combines the output of different results of log anomaly detection and generates a unified output to reduce the burden of maintenance personnel. Since logs are recorded according to user behavior, they often have non-fixed intervals. We apply a trust computational model to transform the unevenly distributed data into a regularly spaced time series. To our best knowledge, this is the first work to employ the trust in the data processing. Futhermore, there are some parameters introduced by the trust computational model. We take advantage of the parametric ensemble technique to address the issue of parameter choice and finally improve the accuracy of anomaly detection. In this way, our method allows one to track a user from multi-view by logs with ease. The experiment shows that our method could achieve a good performance in detecting anomalies of user behavior from multiple kinds of logs. Lin Wang 0042, Kun Zhang 0016, Chen Li 0066, Bibo Tu |
TrustCom | 3 |
| 2021 | TKCA: a timely keystroke-based continuous user authentication with short keystroke sequence in uncontrolled settingsabstractAbstract Keystroke-based behavioral biometrics have been proven effective for continuous user authentication. Current state-of-the-art algorithms have achieved outstanding results in long text or short text collected by doing some tasks. It remains a considerable challenge to authenticate users continuously and accurately with short keystroke inputs collected in uncontrolled settings. In this work, we propose a Timely Keystroke-based method for Continuous user Authentication, named TKCA. It integrates the key name and two kinds of timing features through an embedding mechanism. And it captures the relationship between context keystrokes by the Bidirectional Long Short-Term Memory (Bi-LSTM) network. We conduct a series of experiments to validate it on a public dataset - the Clarkson II dataset collected in a completely uncontrolled and natural setting. Experiment results show that the proposed TKCA achieves state-of-the-art performance with 8.28% of EER when using only 30 keystrokes and 2.78% of EER when using 190 keystrokes. Chen Li 0066, Ruibang You, Bibo Tu, Linghui Li 0001 |
Cybersecur. | 2 |