EDBT 2026 Demo / reviewers in the wild / expert
Huiran Yang
dblp:167/9197
· DBLP profile ↗
11ranked-venue papers
2as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AI Agent-Driven Client Selection and Pricing for Reliable D2D Computing Power Service in Wireless Computing Power Networks
Yueyue Dai, Huiran Yang, Yan Zhang 0002 |
ICC | 3 |
| 2025 | A Heterogeneous GNN Based Trust Evaluation Method for Remote Desktop AccessabstractThe remote desktop is widely used in enterprise environments. To improve its security, Zero Trust is generally introduced to replace the traditional perimeter-based model with dynamic trust evaluation and continuous verification. However, for the remote desktop system, where access chain topology can be abstracted as a graph consists of users, terminals, VMs and connections between them, classical dynamic trust evaluation approaches rely simply on users’ features collected from user-terminal interactions. They ignore features from remained parts of graph, such as terminal itself (as access medium) and status of virtual machines (as access target). Recent graph neural network (GNN) models are dedicated to fusing features from multiple sources in graph structure; however, they are often designed for low-heterogeneity domains and are thus not well suited to the heterogeneous interactions in remote desktop access. To address these challenges, we propose a heterogeneous graph neural network (HGNN) framework for trust evaluation in remote desktop systems. In particular, we model users, terminals, and virtual machines as distinct node types and represent their interactions as a heterogeneous graph, upon which we apply HGNN to aggregating multi-type relational information. This enables comprehensive and adaptive trust estimation tailored to the characteristics of remote desktop environments. Experiments on real-world datasets demonstrate that our method consistently outperforms baselines in terms of accuracy, precision, recall, and F1-score in the trust-level prediction task, confirming the effectiveness of heterogeneous graph modeling and neural-based aggregation in improving trust evaluation performance. Haishuo Zhang, Huiran Yang, Hongjia Li 0002, Yan Zhang 0014, Weiping Wang 0005, Ding Tang |
TrustCom | 2 |
| 2025 | Graph Learning-Based Multiuser Multitask Offloading in Wireless Computing Power NetworksabstractTo enhance service quality, wireless computing power networks (WCPNs) need to realize flexible scheduling and allocation of computation resources across heterogeneous computing servers. Due to large user scales and diverse computation tasks, it is difficult for the current WCPN to serve multiple users and handle multiple tasks concurrently. Graph learning is a promising approach that can learn the representations of nodes through graph structures, enabling the exploration of dependencies among multiple users and tasks, and thereby facilitating computation task offloading. In this paper, we propose a graph learning-based multi-user multi-task offloading scheme for WCPN. First, we propose a wireless computing power network with multi-user and multi-task in which users need to make full use of distributed computing resources through task offloading to ensure efficient task execution. We formulate a system energy consumption minimization problem to jointly optimize computation resources, transmission power, and task offloading. To address the problem, we utilize graph learning to transform the joint optimization problem into a graph regression problem and leverage line graph to explore the solution. Numerical results demonstrate that our proposed scheme can improve computation efficiency, enhance optimization performance, and maintain transferability compared with the benchmarks. Yueyue Dai, Xiaoyang Rao, Bruce Gu, Youyang Qu, Huiran Yang |
IEEE Internet Things J. | 5 |
| 2023 | Deep Reinforcement Learning for Resource Allocation in Blockchain-Based Federated LearningabstractWith the development of artificial intelligence, more and more applications rely on a large amount of high-quality data. Due to data island and security concerns, most of data is scattered on various devices and difficult to obtain. Federated learning (FL) is a promising paradigm to allow distributed devices cooperating to train a shared model without sharing raw data. However, the traditional FL is easy to be attacked because of single-point failure and it cannot avoid devices uploading fake or low-quality model updates. To this end, blockchain is integrated into FL to establish a secure model training ecosystem by maintaining an immutably distributed ledger. However, different data quality of raw data, diverse energy resources of devices, and different trust degree of devices make it challenging for blockchain-enabled FL efficient and reliable. Therefore, in this paper, we design a fine-grained resource allocation scheme for blockchain-enabled FL with considering the credit of devices, data quality, and energy resources. We first propose a credit-based blockchain-enabled FL to jointly execute FL training and blockchain establishment. Then we formulate the resource allocation problem with considering credit, data quality, precision, latency, and energy resources. A deep-reinforcement learning based algorithm is designed to solve the problem, and BlockSim is used to build the blockchain-enabled FL platform. Simulation results demonstrate the effectiveness of our proposed scheme on precision, latency and energy consumption, compared with traditional blockchain-enabled FL. Yueyue Dai, Huijiong Yang, Huiran Yang |
ICC | 3 |
| 2023 | CACluster: A Clustering Approach for IoT Attack Activities Based on Contextual AnalysisabstractAttacks against IoT have shown a rapid increase in both quantity and complexity. Analysts must handle massive alerts and determine the type of attack manually. In addition, the same attack activity may present polymorphism alert sequences due to overlapping attacks, adaptive attack strategy, error alerts, etc, which poses a severe challenge for human analysis. This manual-dependent and scenario-by-scenario security model is seriously overwhelming security analysts. This paper proposes a contextual-analysis-based clustering approach, CACluster, to aggregate similar attack activities end-to-end. It embeds alert context into vector space and uses an unsupervised clustering method to find similar attack activities based on domain matching and vector distance. Experimental results demonstrate that the CACluster could accurately aggregate similar attack activities, with 0.888 purity, reducing the number of attack activities by 84.8%. It will significantly cut down analysts’ workload. Huiran Yang, Yan Zhang 0014, Yueyue Dai, Jiyan Sun, Huajun Cui, Can Ma, Weiping Wang 0005 |
ICPADS | 1 |
| 2023 | LActDet: An Automatic Network Attack Activity Detection Framework for Multi-step AttacksabstractWith the evolution of attack tactics, cyber-attacks are presenting a sophisticated trend. The multi-step attack has become the mainstream attack form, where adversaries implement multiple attack steps to achieve their goals, which poses server challenges to attack detection. Traditional research mainly concentrates on how a particular attack step is exploited but fails to identify the whole attack activity automatically. Manual analysis is required to correlate multiple steps and determine the fine-grained type of attack activities, which is a heavy workload. In addition, the high error rate of alerts results in a negative impact on attack-activity detection performance.To address these challenges, we propose a framework, LActDet, to automatically identify attack activities from the raw alerts end-to-end. Firstly, it utilizes a document-embedding method to vectorize attack-event descriptions. Second, a seq2seq model is implemented to embed the attack-event sequence into the attack-phase sequence to represent the framework of attack activity, aiming at improving the fault tolerance for error alerts. In the end, we propose a temporal-sequence-based classifier to identify attack activities. Our experimental results demonstrate that LActDet achieves higher detection accuracy, lower artificial dependence, and less system overhead. Huiran Yang, Jiaqi Kang, Yueyue Dai, Jiyan Sun, Yan Zhang 0014, Huajun Cui, Can Ma |
TrustCom | 1 |
| 2023 | Coda: Runtime Detection of Application-Layer CPU-Exhaustion DoS Attacks in ContainersabstractDenial of service (DoS) attacks have increasingly exploited vulnerabilities in algorithms or implementation methods in application-layer programs. In this type of attack, called CPU-exhaustion DoS attack, a few well-crafted requests may consume a lot of server resources, which is essentially different from traditional volumetric DoS attacks. Due to the lack of recognizable patterns, the traditional network-layer defense mechanism is usually unable to detect such sophisticated DoS attacks. In this paper, we proposeCoda, a framework for detecting application-layer CPU-exhaustion DoS attacks in containers.Codamonitors the CPU time consumed by each connection and uses statistical methods to detect attacks. It traces system calls and other related information from the container based on Linux eBPF at the host level. Some specific system calls are used to indicate the establishment and closure of the connection, which in turn indicate the start/end of the request processing. After triggering these specific system calls,Codastarts/ends monitoring the CPU time consumed by a connection. An attack can be detected when the CPU time consumed by an attack connection is statistically different from that consumed by a legitimate connection.Codahas the following key advantages. First, it works with programs built in different programming languages. Second, it remains agnostic to the source code of protected programs. Third, it supports monitoring the container and is transparent to the container. Through evaluation of real-world attacks, we demonstrate thatCodacan accurately detect ongoing application-layer CPU-exhaustion DoS attacks with low additional overhead. Mengqi Zhan, Yang Li 0192, Huiran Yang, Guangxi Yu, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | ActDetector: A Sequence-based Framework for Network Attack Activity DetectionabstractThe cyber security situation is not optimistic in recent years due to the rapid growth of security threats. What's more worrying is that threats are tending to be more sophis-ticated, which poses challenges to attack activity analysis. It is quite important for analysts to understand attack activities from a holistic perspective, rather than just pay attention to alerts. Currently, the attack activity analysis generally relies on human resources, which is a heavy workload for manual analysis. Besides, it's difficult to achieve high detection accuracy due to the missing and false-positive alerts. In this paper, we propose a new framework, ActDetector, to detect attack activities automatically from the raw Network Intrusion Detection System (NIDS) alerts, which will greatly reduce the workload of security analysts. We extract attack phase descriptions from alerts and embed attack activity descriptions to obtain their numerical expression. Finally, we use a temporal-sequence-based model to detect potential attack activities. We evaluate ActDetector with three datasets. Experimental results demonstrate that ActDetector can detect attack activities from the raw NIDS alerts with an average of 94.8% Precision, 95.0% Recall, and 94.6% F1-score. Jiaqi Kang, Huiran Yang, Yan Zhang 0014, Yueyue Dai, Mengqi Zhan, Weiping Wang 0005 |
ISCC | 2 |
| 2019 | Towards Homograph-Confusable Domain Name Detection Using Dual-Channel CNN
Guangxi Yu, Xinghua Yang, Yan Zhang 0014, Huajun Cui, Huiran Yang, Yang Li 0192 |
ICICS | 5 |
| 2018 | Virtualized Security Function Placement for Security Service Chaining in CloudabstractSecurity Service Chaining (SSC) has recently shown great potential to address cloud security problems. A key point to implement SSC is Virtualized Security Functions (VSF) placement, which is a special kind of VNF placement. However, the existing solutions of VNF placement have not considered traffic reachability problem and policy conflict problem, which should be addressed for SSC. In this paper, we study the issue of VSF placement for SSC in cloud, and propose a solution named MCE (Map, Check reachability, and Eliminate conflict). In the framework of MCE, we first formulate an optimization model for VSF and VL mapping, which is NP-hard and can be solved by existing mapping algorithms. Next, we propose to use HSA method to find and delete some improper mapping results where traffic reachability can't be satisfied. Finally, we propose a scheme named BSIS-RC (Bit Sequence Intersection and Subtraction based Rule Computation), which is based on our work on the formula expression of security policies, the definition of policy spaces, bit sequence subtraction rule and the definition of policy relationships. BSIS-RC can check and eliminate policy conflicts quickly and effectively. We combine MCE with three existing mapping algorithms and compare the performance of six solutions through simulations. Results show that, compared with three solutions not considering the problems of traffic reachability and policy conflict, MCE can improve 38% of the SSC request success rate on average and reduce 15% of the total bandwidth consumption per SSC request on average. Moreover, among the three MCE solutions with three different mapping algorithms, MCE with Genetic algorithm has the best performance. Hongjing Wu, Yan Zhang 0014, Huiran Yang, Guangxi Yu, Jiuyue Cao |
ICPADS | 3 |
| 2015 | Adaptive purchase option for multi-tenant data centerabstractGenerally, data center's applications have different Quality of Service (QoS) requirements. Meanwhile, data center's tenants may give different priorities to performance and cost. Therefore, it is unsuitable to treat applications/tenants equally. In this paper, we adopt Dynamic Pricing (DP) to charge for the usage of bandwidth and provide tenants with capability to automatically response to the dynamic price. Further, for applications with tight delay requirements, we propose Dynamic Pricing with Bandwidth Reservation (DPBR), which can reserve bandwidth for specific applications. With the modelling of user satisfaction of cost and performance, we show that tenants with DP and DPBR can get better trade-offs between performance and cost. Comparing with Flat Pricing (FP), which is a representative of today's on-demand purchase option, we demonstrate that DPBR is a better option for tenants since it can maximize their satisfactions. The validity is demonstrated through numerical studies and simulations. Yong Zhan, Du Xu, Huiran Yang, Mi Tang, Shuping Peng 0001, Dimitra Simeonidou |
ICC | 3 |