EDBT 2026 Demo / reviewers in the wild / expert
Jiyan Sun
dblp:167/9205
· DBLP profile ↗
40ranked-venue papers
4as first author
34since 2021 · last 2026
0000-0002-8479-333XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 3 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 6 since 2021Human-computer interaction and ubiquitous computing · 6 · 6 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Uni-Fi: Unifying Wi-Fi Human Activity Recognition Across Bandwidths via Contrastive LearningabstractChannel State Information (CSI)-based Human Activity Recognition (HAR) has emerged as a promising Wi-Fi sensing technology. Particularly in the power grids, ubiquitous sensing is crucial for monitoring personnel safety and terminal states. However, given the heterogeneous nature of communication protocol in real‑world infrastructure (e.g., power grids), the real‑world applicability of CSI‑based HAR is severely hampered by a fundamental limitation: mainstream deep learning methods are rigidly coupled to specific channel bandwidth and its corresponding subcarrier layouts. This lack of downward compatibility prevents models trained on 160 MHz Wi-Fi protocols from being deployed in environments using legacy 20 MHz protocols, despite the latter’s subcarriers being fully contained within the former. In this paper, we address this by learning bandwidth-invariant representations from CSI. Our key insight is that CSI measurements from disparate bandwidths are not disparate signals but rather complementary views of the same underlying activity-induced channel frequency response. We introduce Uni-Fi, a contrastive learning framework that pulls these views together in an embedding space, driving the model to learn shared frequency-domain activity features while being robust to specific bandwidth configuration. Extensive evaluations demonstrate that our framework empowers existing CSI-based HAR models with exceptional cross-bandwidth generalization: a model trained solely on 160 MHz CSI maintains high accuracy in a 20 MHz setting, where standard methods fail completely. Peizhe Xin, Zhaozheng Zhou, Yinlong Liu, Jiyan Sun |
ICIC | 7 |
| 2026 | SAT4RIDS: Self-Supervised Learning Adversarial Training Framework for Robust Network Intrusion Detection System
Xuhong Zuo, Jiang Fang, Jiyan Sun, Zhaozheng Zhou, Huilai Wan |
ICIC (11) | 4 |
| 2026 | A review of malicious traffic detection for satellite-terrestrial integrated networks
Mengke Wan, Zhicheng Zhang 0002, Liru Geng, Jiyan Sun, Yinlong Liu |
Comput. Secur. | 4 |
| 2026 | Toward Efficient Distributed Network Security: A Lightweight Multitask Traffic Analysis FrameworkabstractWith the rapid development of cloud computing, network architectures are moving towards distributed computing, which performs data processing at edge nodes to reduce latency, enabling more efficient and scalable network services. Nevertheless, this shift introduces significant security challenges due to the heterogeneity of communications protocols and the vulnerabilities of edge devices. To effectively secure these distributed networks, it is essential to perform multiple traffic analysis tasks, e.g. Network Intrusion Detection, Encrypted Traffic Classification, and Application Traffic Classification. However, existing methods have limited generic feature extraction and require the deployment of multiple models to solve multiple tasks, which exceeds the resource capacity of edge nodes. To address these challenges, we introduce a Lightweight Multitask Traffic Analysis Framework LiMTa, which novelly proposes a traffic pre-training method, FreqRec, and a lightweight multi-task model fine-tune method, MT-Adapter. FreqRec enables high-level semantic feature extraction by reconstructing the frequency features of traffic samples, and MT-Adapter efficiently performs multiple tasks by computing the pre-trained model only once. Experimental results demonstrate that our approach achieves state-of-the-art (SOTA) performance on six traffic analysis tasks. Moreover, the MT-Adapter module only fine-tunes a small number of parameters, accounting for only 6.37% of the pre-trained model’s parameters, and achieves the same result as the full fine-tuning. Compared to full fine-tuning, LiMTa reduces the time cost by 50.9% and the space cost by 57.4% in six edge traffic analysis tasks. Jiadong Fu, Jiang Fang, Jiyan Sun, Shangyuan Zhuang, Yinlong Liu, Zhiqiang Lv |
IEEE Trans. Netw. | 3 |
| 2025 | 3SAT: A Simple Self-Supervised Adversarial Training FrameworkabstractThe combination of self-supervised learning and adversarial training (AT) can significantly improve the adversarial robustness of self-supervised models. However, the robustness of self-supervised adversarial training (self-AT) still lags behind that of state-of-the-art (SOTA) supervised AT (sup-AT), even though the performance of current self-supervised learning models has already matched or even surpassed that of SOTA supervised learning models. This issue raises concerns about the secure application of self-supervised learning models. The inclusion of adversarial training turns self-AT into a challenging joint optimization problem, and recent studies have shown that the data augmentation methods necessary for constructing positive pairs in self-supervised learning negatively impact the robustness improvement in self-AT. Inspired by this, we propose 3SAT, a simple self-supervised adversarial training framework. 3SAT conducts adversarial training on original, unaugmented samples, reducing the difficulty of optimizing the adversarial training subproblem and fundamentally eliminating the negative impact of data augmentation on robustness improvement. Additionally, 3SAT introduces a dynamic training objective scheduling strategy to address the issue of model training collapse during the joint optimization process when using original samples directly. 3SAT is not only structurally simple and computationally efficient, reducing self-AT training time by half, but it also improves the SOTA self-AT robustness accuracy by 16.19\% and standard accuracy by 11.41\% under Auto-Attack on the CIFAR-10 dataset. Even more impressively, 3SAT surpasses the SOTA sup-AT method in robust accuracy by a significant margin of 11.25\%. This marks the first time that self-AT has outperformed SOTA sup-AT in robustness, indicating that self-AT is a superior method for improving model robustness. Jiang Fang, Jiyan Sun, Jiadong Fu, Zhaorui Guo, Yinlong Liu |
AAAI | 3 |
| 2025 | Root Cause Analysis of Faults in Power Grids 5G Network Based on RRC Signalling MessagesabstractThe growing flexibility of 5G network architectures increases the risk of network faults. Such network fault types are diverse and variability, as 5G networks have been integrated in various vertical industries, e.g., power grids, resulting in these faults being widespread and challenging to diagnose. To reduce the costs associated with fault identification and remediation, we introduce Rsm-RCA as a novel framework for automated root cause analysis (RCA) in 5G networks. By training on massive amounts of data, Rsm-RCA is capable of identifying fault types from the fault signalling messages collected. Specifically, this framework efficiently collects and processes radio resource control (RRC) fault signalling messages from commercial networks to extract multidimensional attributes and KPI parameters. The processed signalling messages are then fed into a decision tree model, which enables accurate fault classification with minimal time expenditure after training. For power utilities private 5G networks, fast and accurate RCA is highly beneficial. Experimental results demonstrate that Rsm-RCacan classify faults in an extremely short time, achieving an average accuracy of 99 %. Zhaorui Guo, Peizhe Xin, Zhaozheng Zhou, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu |
CSCWD | 6 |
| 2025 | Root Cause Analysis of Power Grid 5G Network Faults Based on Large Language ModelabstractThe growing complexity and diversity of 5G network architecture (e.g., power grid 5G network) have made security risk assessment and root cause analysis increasingly challenging. Recent advances in large language models (LLMs) have the potential to transform this landscape. However, existing LLMs-based solutions primarily focus on understanding the language of 5G telecommunications, while overlooking potential security vulnerabilities in the data flows. To facilitate LLMs' in-depth application, this paper presents RCA-LLM, a novel fault root cause analysis framework for 5G networks developed from tailored LLMs-based solutions. In explicit terms, RCA-LLM is trained by inputting processed and organized fault information for fine-tuning, and combined with retrieval-augmented generation (RAG) technology to significantly improve the accuracy of 5G fault analysis. Our experimental results indicate that RCA-LLM performs well in fault analysis, effectively supporting users in diagnosing and resolving fault issues. Model evaluation results further demonstrate that the model significantly improves fault analysis accuracy and has high practical value. In addition, RCA-LLM provides important reference value for efficient operation and maintenance management of 5G and future power grid networks, while also offering new ideas for advancing intelligent fault analysis. Zhaorui Guo, Peizhe Xin, Xiongfei Zhao, Tian Hu, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu |
CSCWD | 7 |
| 2025 | DASSL: Domain Agnostic Self-Supervised Learning with Multiple Missing Information Reconstruction BranchesabstractSelf-supervised learning (SSL) is a technique used to learn feature representations from unlabeled data. However, existing SSL frameworks either rely too heavily on domain knowledge due to their design based on feature invariance, leading to a lack of domain transferability, or they are based on autoencoder designs, which generate features with redundant low-level semantics, resulting in suboptimal model representations. In this work, we introduce a novel Domain Agnostic Self-Supervised Learning framework called DASSL, which learns superior high-level feature representations of samples by reconstructing the samples’ missing information in the representation space. DASSL does not require additional domain priors, and compared to successful SSL methods, DASSL achieves competitive representation quality. Moreover, when DASSL incorporates domain-related data augmentation techniques, it outperforms successful methods across multiple datasets and evaluation protocols. Jiang Fang, Jiyan Sun, Zhaorui Guo, Mohan Su, Yinlong Liu |
ICASSP | 4 |
| 2025 | A Novel LLM Approach of Cybersecurity Threat Analysis and ResponseabstractSatellite-based cloud computing cybersecurity threats have long posed significant challenges, particularly for cloud infrastructure operators.While prior research has partially addressed these issues by mitigating threats and enhancing human response efficiency, this paper proposes a novel AI-Driven Threat Analysis and Response (TAR) framework.The study progresses in three main phases: (1) redefining urgent threats through a novel formula; (2) implementing a triage and analysis framework using augmented Large Language Models (LLMs); and (3) automating incident response via a Security Orchestration, Automation, and Response (SOAR) platform.Our prototype, tested in a simulated public cloud environments using real production threats, demonstrated a 17% improvement in handling low-and medium-urgency threats.Experimental results show our approach achieves 97.8% coverage in automatic threat classification, significantly outperforming traditional manual methods, which achieve 77.8% coverage.With high recall and precision in managing low-and medium-urgency threats, our method enhances manual efficiency through SOAR-enabled automation.Furthermore, * Corresponding Author.our augmented method surpasses the state-of-the-art GPT-4 Turbo model in addressing security threats containing Chinese characters. Tian Hu, Shangyuan Zhuang, Zhaorui Guo, Jiyan Sun, Yinlong Liu, Lingfeng Zhao |
Internetware | 4 |
| 2025 | Hot-Swap MarkBoard: An Efficient Black-box Watermarking Approach for Large-scale Model DistributionabstractRecently, Deep Learning (DL) models have been increasingly deployed on end-user devices as On-Device AI, offering improved efficiency and privacy. However, this deployment trend poses more serious Intellectual Property (IP) risks, as models are distributed on numerous local devices, making them vulnerable to theft and redistribution. Most existing ownership protection solutions (e.g., backdoor-based watermarking) are designed for cloud-based AI-as-a-Service (AIaaS) and are not directly applicable to large-scale distribution scenarios, where each user-specific model instance must carry a unique watermark. These methods typically embed a fixed watermark, and modifying the embedded watermark requires retraining the model. To address these challenges, we propose Hot-Swap MarkBoard, an efficient watermarking method. It encodes user-specific n-bit binary signatures by independently embedding multiple watermarks into a multi-branch Low-Rank Adaptation (LoRA) module, enabling efficient watermark customization without retraining through branch swapping. A parameter obfuscation mechanism further entangles the watermark weights with those of the base model, preventing removal without degrading model performance. The method supports black-box verification and is compatible with various model architectures and DL tasks, including classification, image generation, and text generation. Extensive experiments across three types of tasks and six backbone models demonstrate our method's superior efficiency and adaptability compared to existing approaches, achieving 100% verification accuracy. Zhicheng Zhang 0002, Peizhuo Lv, Mengke Wan, Jiang Fang, Diandian Guo, Yezeng Chen, Yinlong Liu, Jiyan Sun, Liru Geng |
ACM Multimedia | 9 |
| 2025 | Quantum Contextual Bandits: Integrating Bandit Exploration into Quantum Neural NetworkabstractSupervised quantum learning methods face notable limitations in dynamic, real-world environments due to their reliance on static labels and limited adaptability. To address these challenges, we propose a novel online learning framework — Quantum Contextual Bandit (QCB) — that integrates quantum neural networks (QNNs) with contextual bandit (CB) algorithms. The QCB framework enables adaptive decision-making by incorporating bandit-based exploration into QNN training, making it particularly suitable for applications such as recommender systems. To mitigate the adverse effects of quantum noise—including depolarizing, Pauli, and shot noise, the framework leverages a gradient-free optimization approach, enhancing robustness and convergence stability. Experimental results on various datasets demonstrate that QCB consistently outperforms traditional QNN training methods with identical circuit architectures. Notably, the model achieves over 99% accuracy under ideal conditions and sustains high performance under noisy quantum environments. These results underscore the potential of QCB as a scalable, noise-resilient solution for adaptive learning in quantum machine learning systems. Shiva Raj Pokhrel, Jiang Fang, Yinlong Liu, Jiyan Sun, Liru Geng, Gang Li 0009 |
SMC | 5 |
| 2025 | A Fine-grained Troubleshooting method in 6G NTN systems Based on Signaling MessagesabstractThe signaling collected in mobile communication networks can intuitively display the operational status of the system, which can use to locate faults. This paper proposes a novel signaling-based end-to-end fine-grained troubleshooting (simFGT) method for 6G NTN networks. First, the signaling collected from the core network is analyzed to extract multidimensional KPIs and attribute information. Second, a root cause localization algorithm is employed for fine-grained fault localization. Third, a lightweight data-driven ensemble learning method is adopted, with the abnormal KPI of the localized root cause node as inputs, and precise fault classification is achieved through data-driven weight optimization. Experiments results show that the proposed lightweight SimFGT method achieves best balance between precision and recall, resulting in highest F1 score, outperforming current state-of-the-art solutions. Liru Geng, Zhaorui Guo, Jiyan Sun, Jiadong Fu, Jiang Fang, Yinlong Liu |
SMC | 3 |
| 2025 | A Novel Automation Method of Cybersecurity Alerts Analysis and Response in Satellite Cloud Systems
Liru Geng, Tian Hu, Jiang Fang, Jiyan Sun, Yinlong Liu |
SMC | 4 |
| 2025 | Explainable and Transferable Adversarial Attack for ML-Based Network Intrusion DetectorsabstractDespite being widely used in network intrusion detection systems (NIDSs), machine learning (ML) has proven to be vulnerable to adversarial attacks. White-box and black-box adversarial ML attacks of NIDS have been explored in several studies. However, white-box attacks unrealistically assume that the attackers have full knowledge of the target NIDSs. Meanwhile, existing black-box attacks can not achieve high attack success rate due to the weak adversarial transferability between models (e.g., neural networks and tree models). Additionally, neither of them explains why adversarial examples exist and why they can transfer across models. To address these challenges, this paper introduces ETA, anExplainableTransfer-based Black-Box AdversarialAttack framework. ETA aims to achieve two primary objectives: 1) create transferable adversarial examples applicable to various ML detectors and 2) provide insights into the existence of adversarial examples and their transferability within NIDSs. Specifically, we first provide a general transfer-based adversarial attack method applicable across the entire ML space. Following that, we exploit a unique insight based on cooperative game theory and perturbation interpretations to explain adversarial examples and adversarial transferability. On this basis, we propose an Important-Sensitive Feature Selection (ISFS) method to guide the search for adversarial examples, achieving stronger transferability and ensuring traffic-space constraints. Finally, the experimental results on three NIDSs datasets show that our method performs significantly effectively against several classical and state-of-the-art ML classifiers, outperforming the latest baselines. We conduct three interpretation experiments and two cases to verify our interpretation method's correctness. Meanwhile, we uncover two major misconceptions about applying machine learning to NIDSs systems. Hangsheng Zhang, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu, Jiqiang Liu, Jin Song Dong 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Improve Model Robustness in Less Time Than It Takes to Drink A Cup of Coffee with Plug-and-Play Robustness Plugins
Jiang Fang, Jiyan Sun, Jiadong Fu, Yinlong Liu |
ACCV (1) | 3 |
| 2024 | Fast and Accurate Root Cause Analysis Based on Signalling Messages for 5G NetworksabstractThe ever-increasing complexity and scale of 5G communication networks pose huge challenges to network operations. Root cause analysis is considered as a promising method for fault detection. However, it still suffers challenges of severely uneven distribution of fault data, low accuracy in root cause detection, and long time consumption due to a large search space in 5G cellular networks. To address the above challenges, we introduce SimRCA to effectively analyze the faults’ root causes in 5G networks using signalling messages. By designing a novel confidence threshold value and pruning technique, SimRCA can significantly reduce the search space of signalling messages while maintaining the accuracy of root cause analysis. Moreover, SimRCA is proven to be able to handle unbalanced data distribution in 5G networks. We collected over 10GB of signalling data from Huawei 5G commercial network and conducted extensive experiments on this dataset. Experimental results demonstrate that SimRCA can complete root cause localization and fault classification within 11 seconds with an average F1-score over 0.93 which outperforms the current state-of-the-art solutions. Zhaorui Guo, Jiyan Sun, Jiadong Fu, Shangyuan Zhuang, Liru Geng, Yinlong Liu |
ICASSP | 2 |
| 2024 | Manticore: An Unsupervised Intrusion Detection System Based on Contrastive Learning in 5G NetworksabstractThe increasing complexity and openness of 5G networks naturally enlarge the attack surface and introduce new vulnerabilities, thereby posing challenges to the performance of existing intrusion detection systems (IDSs). Current IDSs solely rely on statistical features, which may suffer from low accuracy due to the complex traffic patterns in 5G networks. Additionally, recent IDSs apply contrastive learning to improve detection capabilities, but the reliance on costly manual labeling hinders the adaptability to complex attacks in 5G networks.In this paper, we present Manticore, an unsupervised intrusion detection system based on contrastive learning for 5G networks. Specifically, Manticore leverages both statistical features and original features of packets to capture the holistic information of traffic in 5G networks. Moreover, it automatically establishes positive and negative pairs without manual labeling. We further explore the combination patterns between reconstruction loss and contrastive loss to attain a more precise model. Our experimental evaluation of two datasets demonstrates the proposed Manticore outperforms the relevant state-of-the-art methods. Jiyan Sun, Shangyuan Zhuang, Yinlong Liu, Liru Geng, Peizhe Xin, Weiqing Huang |
ICASSP | 2 |
| 2024 | CoSen-IDS: A Novel Cost-Sensitive Intrusion Detection System on Imbalanced Data in 5G Networks
Jiyan Sun, Shangyuan Zhuang, Yinlong Liu, Liru Geng |
ICIC (8) | 2 |
| 2024 | LoFT: LoRA-Based Efficient and Robust Fine-Tuning Framework for Adversarial TrainingabstractRecently, Self-Supervised Learning (SSL) has achieved great success in various famous applications e.g., BERT and ChatGPT. However, when applying SSL to safety-critical downstream tasks, such as self-driving cars, potential adversarial attacks can completely change the final decisions and thus lead to serious security issues. To overcome this issue, existing methods combine adversarial training with pre-training to improve the adversarial robustness of SSL. However, combining these two computationally complex processes may largely amplify the computation cost. Moreover, whether performing adversarial training in pre-training or fine-tuning, current methods may degrade the accuracy due to the famous catastrophic forgetting problem. The computation cost of current adversarial training methods based on full parameter updating is still high even in the fine-tuning stage.To address the above challenges, we propose an effective robust fine-tuning framework for SSL based on Low-Rank Adaptation (LoRA), named LoFT. First, LoFT performs adversarial training in the fine-tuning stage rather than in the pre-training stage. Second, LoFT innovatively and elaborately integrates LoRA into adversarial training to avoid the catastrophic forgetting problem. Third, LoFT exploits a low-rank matrix in LoRA which enables efficient fine-tuning by updating only a small set of parameters, which contains only 1%-5% of the parameters of the pre-trained model. The whole pre-training and fine-tuning stages take only 9.44 hours, which reduces training time by 3× over the current SOTA method. Furthermore, compared with existing SOTA robust pre-training methods for SSL, LoFT improves accuracy by 5.97% (77.41%⇒83.38%) and robustness by 13% (45.04%⇒58.44%) on the CIFAR-10 dataset. Jiadong Fu, Jiang Fang, Jiyan Sun, Shangyuan Zhuang, Liru Geng, Yinlong Liu |
IJCNN | 3 |
| 2024 | LightGuard: A Lightweight Malicious Traffic Detection Method for Internet of ThingsabstractThe rapid growth of Internet of Things (IoT) devices has expanded the cyber attack surface, posing a challenge to IoT security. Some deep learning-based detection methods have been designed to detect malicious attacks in the IoT by analyzing network traffic. However, the algorithm computational complexity of existing methods is usually high due to having a large number of parameters and iterative training inference, making them difficult to implement on IoT gateways which have limited computational and storage resources. To this end, this paper proposes a lightweight malicious traffic detection model for IoT based on lightweight residual block (LRB) modules, named LightGuard. Specifically, LRB module designs a unique residual structure based on the construction idea of ShuffleNetV2, which enables LightGuard to achieve high detection performance while reducing the parameters, computations and inference time of the model. In addition, LRB module replaces the traditional convolution with a lightweight convolutional module called ghost module to generate feature maps at low cost while without compromising detection performance. We evaluate the effectiveness of LightGuard by comparing it with seven advanced baseline models on four generic datasets. The experimental results show that LightGuard achieves more than 99.6% accuracy on all four datasets, while exhibits significant advantages with low computational complexity. Yuehua Huo, Junhan Chen, Shangyuan Zhuang, Jiyan Sun |
IEEE Internet Things J. | 5 |
| 2023 | Implementation of a Cost-Effective Privacy Leakage Detection System for Hosted ProgramsabstractPosting programs to code hosting platforms such as GitHub is common for developers, but it will lead to privacy leakage issues in hosted programs. Though there are some detection methods for privacy leakage, they are difficult to be applied in practice. First, existing works mainly focus on detection algorithms, while ignoring the complete detection system from a holistic perspective. Second, the system will be blocked when acquiring programs because code hosting platforms usually have protection mechanism. Third, high-performance privacy detection algorithms need hardware devices in practice, and their effectiveness in real scenarios has not been verified since there is no public real hosted program privacy dataset.To address the above problems, we implement and commercialize a user-friendly privacy information leakage detection system for actual hosted programs. Firstly, we provide a system frame-work that can automatically complete "program acquisition-privacy detection-alert", allowing subscribers receive alerts if there is a privacy information leakage. Secondly, we propose a novel multi-random crawler scheme that can flexibly cope with the limitations of GitHub when acquiring hosted programs. Thirdly, we skillfully apply a cost-effective detection approach based on fuzzy matching, which can detect the subscriber customized privacy information with high performance. Based on this, we further provide a high-quality dataset obtained in real scenarios. Finally, we conduct comprehensive experiments to evaluate our system. Experimental results demonstrate the effectiveness of our crawler scheme and detection approach in providing a user-friendly system. Tian Hu, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu |
CSCWD | 3 |
| 2023 | CACluster: A Clustering Approach for IoT Attack Activities Based on Contextual AnalysisabstractAttacks against IoT have shown a rapid increase in both quantity and complexity. Analysts must handle massive alerts and determine the type of attack manually. In addition, the same attack activity may present polymorphism alert sequences due to overlapping attacks, adaptive attack strategy, error alerts, etc, which poses a severe challenge for human analysis. This manual-dependent and scenario-by-scenario security model is seriously overwhelming security analysts. This paper proposes a contextual-analysis-based clustering approach, CACluster, to aggregate similar attack activities end-to-end. It embeds alert context into vector space and uses an unsupervised clustering method to find similar attack activities based on domain matching and vector distance. Experimental results demonstrate that the CACluster could accurately aggregate similar attack activities, with 0.888 purity, reducing the number of attack activities by 84.8%. It will significantly cut down analysts’ workload. Huiran Yang, Yan Zhang 0014, Yueyue Dai, Jiyan Sun, Huajun Cui, Can Ma, Weiping Wang 0005 |
ICPADS | 4 |
| 2023 | A Cost-effective Automation Method of Massive Vulnerabilities Analysis and Remediation Based on Cloud NativeabstractWith the rapid development of the cutting edge cloud computing technology, millions of vulnerabilities have been identified, there is a growing concern that organizations should devote plenty of time and lots of resources to secure. The overarching objective of remediation is to prioritize the vulnerabilities. Hence, define the severity and the urgency of the vulnerabilities and remediate them automatically is very important. Although the recognized Common Vulnerability Scoring System (CVSS) 4.0 method addresses this issues partly, they are difficult to be implemented in practices on the cloud because of the complication and lack of risk based factors.To this end, we propose a Cost-effective Massive Automation Method of Vulnerability Analysis and Remediation Based on Cloud Native Framework. Specifically, considering that the current CVSS is more like a severity of vulnerabilities, we design a novel formula to define the urgency of vulnerabilities. The formula takes the advantaged of the capabilities of modern cloud-based infrastructure and simplifies the CVSS. Besides, we propose an algorithm of risk reduction by leveraging the cloud native security capabilities, which cut down unnecessary patching time and workload. Particularly, in order to remediation the risk on the cloud, we implement an automatic scheme to harden the vulnerabilities by invoking the cloud native APIs based on the Security Orchestration, Automation and Response (SOAR) platform. Finally, we conduct comprehensive experiments to evaluate our system. Experimental results demonstrate the effectiveness of ours approach has a high ratio of urgency risk recognition of 99.24%. Meanwhile, ours approach shows a maximum risk reduction by downgrade the fixable vulnerability with a average of 79% risk reduction rate in application level and 99% of risk reduction rate in operating system level respectively. As a result, our approach lightens the workload of patching greatly in the real cloud computing environment. Tian Hu, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu |
TrustCom | 3 |
| 2023 | LActDet: An Automatic Network Attack Activity Detection Framework for Multi-step AttacksabstractWith the evolution of attack tactics, cyber-attacks are presenting a sophisticated trend. The multi-step attack has become the mainstream attack form, where adversaries implement multiple attack steps to achieve their goals, which poses server challenges to attack detection. Traditional research mainly concentrates on how a particular attack step is exploited but fails to identify the whole attack activity automatically. Manual analysis is required to correlate multiple steps and determine the fine-grained type of attack activities, which is a heavy workload. In addition, the high error rate of alerts results in a negative impact on attack-activity detection performance.To address these challenges, we propose a framework, LActDet, to automatically identify attack activities from the raw alerts end-to-end. Firstly, it utilizes a document-embedding method to vectorize attack-event descriptions. Second, a seq2seq model is implemented to embed the attack-event sequence into the attack-phase sequence to represent the framework of attack activity, aiming at improving the fault tolerance for error alerts. In the end, we propose a temporal-sequence-based classifier to identify attack activities. Our experimental results demonstrate that LActDet achieves higher detection accuracy, lower artificial dependence, and less system overhead. Huiran Yang, Jiaqi Kang, Yueyue Dai, Jiyan Sun, Yan Zhang 0014, Huajun Cui, Can Ma |
TrustCom | 4 |
| 2023 | ESMO: Joint Frame Scheduling and Model Caching for Edge Video AnalyticsabstractWith the advancements in Machine Learning (ML) and edge computing, increasing efforts have been devoted toedge video analytics. However, most of the existing works fail to consider the cooperation of edge nodes for ML model caching and video frame scheduling, thus less efficient in practical scenarios with diverse requirements. In this article, we propose a novel approach named ESMO (joint framEScheduling andMOdel caching) to jointly optimize Frame Scheduling and Model Caching (FSMC), aiming at enhancing the performance of edge video analytics. In detail, we decompose the FSMC as three sub-problems, where the first two sub-problems (i.e., user's transmit power and edge computing resources allocation problems) are proven to be quasi-convex and strictly convex, respectively; while the third main sub-problem (i.e., trade-off among the video analytics (VA) accuracy, service delay and energy consumption) is NP-hard. Therefore, an efficient Two-layers Genetic Algorithm based algorithm (i.e., TGA-FSMC) is designed to find the close-to-optimal frame scheduling and the model caching decisions in an iterative manner. Finally, we deploy a target recognition prototype to comprehensively evaluate the practical performance in diverse edge nodes and CNN models. Extensive experiments demonstrate the empirical superiority of the ESMO over alternatives on real-world edge video analytics platforms, and it achieves 37.5%$\sim$87.2% performance improvement. Ting Li 0023, Jiyan Sun, Yinlong Liu, Xu Zhang 0006, Dali Zhu, Zhaorui Guo, Liru Geng |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2022 | LibHunter: An Unsupervised Approach for Third-party Library Detection without Prior KnowledgeabstractThird-party libraries (TPLs) are a significant component of mobile apps. They provide various functionalities, and developers employ them to facilitate app development. TPL detection is a fundamental task in security research, as it can impact other security studies. TPL can act as an assistant to malware detection, privacy leakage detection, etc. Because if a TPL carries malicious code, all apps that integrate the TPL can be considered risky. However, in some studies, TPLs can also act as noise, like app traffic fingerprinting. The TPL and app traffic are mixed during app runtime, making it difficult to fingerprint the app traffic accurately. Unfortunately, all existing TPL detection studies are working with prior knowledge of TPLs, as they need a whitelist or a train on known TPLs. However, new TPLs keep emerging, and it is not feasible for existing works to identify them-especially those who have network behaviors, as they may transfer inappropriate contents in the network. To this end, we propose LibHunter - an approach to identify TPLs without prior knowledge. LibHunter inspects the HTTP(S) traffic, logs the corresponding code execution traces, extracts features from the collected data, and performs a clustering algorithm to obtain TPLs. We apply LibHunter to 3000 apps. Results demonstrate that LibHunter can identify 79 TPLs, and about 60% of them are not detected by all existing works. We perform an analysis to show how important these TPLs are; we also present the visiting graph of these TPLs. Our findings bring light to the research community that existing tools are not accurate when encountering contemporary apps. Huajun Cui, Guozhu Meng, Yuejun Li, Yan Zhang 0014, Jiyan Sun, Dali Zhu, Weiping Wang 0005 |
ISCC | 6 |
| 2022 | Automated Privacy Network Traffic Detection via Self-labeling and LearningabstractWith the increasing popularity of mobile devices, privacy leakage has become more and more serious. The inappropriate behaviors of mobile APPs have brought substantial security risks to the public (e.g., location leakage). Existing solutions detect privacy leakage based on network traffic analysis. However, they can only detect unencrypted traffic, which leads to failures in the face of encrypted traffic. To solve this challenge, we designed an Automated Privacy Traffic Detection system (APTD). APTD can automatically generate self-labeling privacy traffic datasets, learn to identify the encrypted privacy traffic, and accurately assess the risk of privacy leakage. Due to its automation capability, APTD can directly support privacy leakage detection for newly-emerged applications without any system changes. To comprehensively evaluate APTD, we conducted an experiment on 2327 real-world mobile APPs. APTD automatically generated a labeled dataset containing 27343 real-world encrypted traffic traces. Based on the dataset, APTD identifies privacy traffic, and performs a privacy leakage risk assessment of APPs. The results show that APTD achieves 97% accuracy and 99% recall on our dataset and identifies 12 APPs that transmit high-risk privacy data. Yuejun Li, Huajun Cui, Jiyan Sun, Yan Zhang 0014, Guozhu Meng, Weiping Wang 0005 |
ISCC | 3 |
| 2022 | StinAttack: A Lightweight and Effective Adversarial Attack Simulation to Ensemble IDSs for Satellite- Terrestrial Integrated NetworkabstractEffective adversarial attacks simulation is essential for the deployment of ensemble Intrusion Detection Systems (en- semble IDSs) in Satellite-Terrestrial Integrated Network (STIN). This is because it can automatically generate a large amount of adversarial samples to evaluate the robustness of different classifiers. Based on the result, it can further guide the STIN engineers to select proper classifiers in ensemble IDSs. Moreover, it can help the IDSs improve detect performance by their self- learning property in the adversarial attack process. However, the existing adversarial attack approaches suffer from the problems of low success rate and high overhead of communication and calculation due to the limited computing resources and long communication links of STIN. This results in their inefficiency in STIN. To address the above problems, we provide StinAttack as a robustness evaluation scheme for STIN. First, StinAttack provides a comprehensive and automatic robustness evaluation framework for IDSs in STIN with only few times interactions between terrestrial and satellite nodes. Second, StinAttack proposes an effective adversarial attack simulation based on lightweight gradient evaluation for ensemble IDSs. Third, we conduct experiments on 11 typical IDSs, 4 baseline popular adversarial attacks and our StinAttack. Experimental results show that our approach can effectively attack ensemble IDSs and the evaluation results based on real STIN dataset are instructive for designing secure networks. Shangyuan Zhuang, Jiyan Sun, Hangsheng Zhang, Xiaohui Kuang, Ling Pang, Haitao Liu 0006, Yinlong Liu |
ISCC | 2 |
| 2022 | iSwift: Fast and Accurate Impact Identification for Large-scale CDNsabstractOne key challenge to maintain a large-scale Content Delivery Network (CDN) is to minimize the service downtime when severe system problems happen (e.g., hardware failures). In this case, a critical step is to quickly and accurately identify the range of users with performance degradation, termed impact identification. Successful impact identification not only helps identify impacted users but also provides meaningful information for troubleshooting. However, current practice of impact identification usually takes network engineers several hours to manually identify impacted users, which may lead to a huge business loss. The main challenges for automatic impact identification in large CDNs include the inaccuracy of underlying anomaly detection, huge search space of impact identification and severe long-tail distribution of user traffic. In this paper we propose iSwift, a system that is specifically designed for impact identification in large-scale CDNs in order to address aforementioned challenges. We evaluate the performance of iSwift on semi-synthetic datasets and the results show that iSwift can achieve a F1-score greater than 0.85 within ten seconds, which significantly outperforms state-of-the-art solutions. Furthermore, iSwift has been deployed in a production CDN around one year as a pilot project and demonstrated its online performance confirmed by the network operators. Jiyan Sun, Tao Lin 0001, Yinlong Liu, Xin Wang 0001, Bo Jiang 0003, Liru Geng, Pengkun Jing |
IWQoS | 1 |
| 2022 | Robust System Instance Clustering for Large-Scale Web ServicesabstractSystem instance clustering is crucial for large-scale Web services because it can significantly reduce the training overhead of anomaly detection methods. However, the vast number of system instances with massive time points, redundant metrics, and noise bring significant challenges. We propose OmniCluster to accurately and efficiently cluster system instances for large-scale Web services. It combines a one-dimensional convolutional autoencoder (1D-CAE), which extracts the main features of system instances, with a simple, novel, yet effective three-step feature selection strategy. We evaluated OmniCluster using real-world data collected from a top-tier content service provider providing services for one billion+ monthly active users (MAU), proving that OmniCluster achieves high accuracy (NMI=0.9160) and reduces the training overhead of five anomaly detection models by 95.01% on average. Shenglin Zhang, Dongwen Li, Zhenyu Zhong, Minghan Liang, Jiexi Luo, Yongqian Sun, Ya Su, Sibo Xia, Zhongyou Hu, Dan Pei, Jiyan Sun, Yinlong Liu |
WWW | 13 |
| 2022 | Efficient KPI Anomaly Detection Through Transfer Learning for Large-Scale Web ServicesabstractTimely anomaly detection of key performance indicators (KPIs),e.g., service response time, error rate, is of utmost importance to Web services. Over the years, many unsupervised deep learning-based anomaly detection approaches have been proposed. To achieve good performance, they require a long period of KPI data for model training, which is not easy to guarantee with frequent service changes. Additionally, the training overhead is too significant for the vast number of KPIs in large-scale Web services. To address the problems, we propose an unsupervised KPI anomaly detection approach, namedAnoTransfer, by combining a novel Variational Auto-Encoder (VAE)-based KPI clustering algorithm with an adaptive transfer learning strategy. Extensive evaluation experiments using real-world data collected from several large-scale Web service providers demonstrate thatAnoTransferreduces the average initialization time by 65.71% and improves the training efficiency by 50.62 times, without significantly degrading anomaly detection accuracy. Shenglin Zhang, Zhenyu Zhong, Dongwen Li, Qiliang Fan, Yongqian Sun, Man Zhu, Dan Pei, Jiyan Sun, Yinlong Liu, Yongqiang Zou |
IEEE J. Sel. Areas Commun. | 9 |
| 2021 | AutoRoot: A Novel Fault Localization Schema of Multi-dimensional Root CausesabstractThe key challenge for large scale software system maintenance is to minimize the troubleshooting time when severe system anomaly (e.g., server failure, link congestion, software bugs) happens. It often takes hours for operators to manually locate the fault and thus degrades the service performance in terms of user experience and economics. Previous root cause localization algorithms are usually time-consuming and error-prone. In this paper, we present AutoRoot, a fast and accurate multi-dimensional root cause localization algorithm. Specifically, AutoRoot uses an adaptive density clustering to improve the accuracy and an effective filtering mechanism to reduce the search time. Extensive experiments using multiple real data traces validate the performance of AutoRoot compared with existing algorithms. Pengkun Jing, Yanni Han, Jiyan Sun, Tao Lin 0001, Yanjie Hu |
WCNC | 3 |
| 2021 | Deep Reinforcement Learning-based Task Offloading in Satellite-Terrestrial Edge Computing NetworksabstractIn remote regions (e.g., mountain and desert), cellular networks are usually sparsely deployed or unavailable. With the appearance of new applications (e.g., industrial automation and environment monitoring) in remote regions, resource-constrained terminals become unable to meet the latency requirements. Meanwhile, offloading tasks to urban terrestrial cloud (TC) via satellite link will lead to high delay. To tackle above issues, Satellite Edge Computing architecture is proposed, i.e., users can offload computing tasks to visible satellites for executing. However, existing works are usually limited to offload tasks in pure satellite networks, and make offloading decisions based on the predefined models of users. Besides, the runtime consumption of existing algorithms is rather high. In this paper, we study the task offloading problem in satellite-terrestrial edge computing networks, where tasks can be executed by satellite or urban TC. The proposed Deep Reinforcement learning-based Task Offloading (DRTO) algorithm can accelerate learning process by adjusting the number of candidate locations. In addition, offloading location and bandwidth allocation only depend on the current channel states. Simulation results show that DRTO achieves near-optimal offloading cost performance with much less runtime consumption, which is more suitable for satellite-terrestrial network with fast fading channel. Dali Zhu, Haitao Liu 0006, Ting Li 0023, Jiyan Sun, Hangsheng Zhang, Liru Geng, Yinlong Liu |
WCNC | 4 |
| 2021 | Privacy-Aware Online Task Offloading for Mobile-Edge ComputingabstractMobile edge computing (MEC) has been envisaged as one of the most promising technologies in the fifth generation (5G) mobile networks. It allows mobile devices to offload their computation‐demanding and latency‐critical tasks to the resource‐rich MEC servers. Accordingly, MEC can significantly improve the latency performance and reduce energy consumption for mobile devices. Nonetheless, privacy leakage may occur during the task offloading process. Most existing works ignored these issues or just investigated the system‐level solution for MEC. Privacy‐aware and user‐level task offloading optimization problems receive much less attention. In order to tackle these challenges, a privacy‐preserving and device‐managed task offloading scheme is proposed in this paper for MEC. This scheme can achieve near‐optimal latency and energy performance while protecting the location privacy and usage pattern privacy of users. Firstly, we formulate the joint optimization problem of task offloading and privacy preservation as a semiparametric contextual multi‐armed bandit (MAB) problem, which has a relaxed reward model. Then, we propose a privacy‐aware online task offloading (PAOTO) algorithm based on the transformed Thompson sampling (TS) architecture, through which we can (1) receive the best possible delay and energy consumption performance, (2) achieve the goal of preserving privacy, and (3) obtain an online device‐managed task offloading policy without requiring any system‐level information. Simulation results demonstrate that the proposed scheme outperforms the existing methods in terms of minimizing the system cost and preserving the privacy of users. Dali Zhu, Ting Li 0023, Haitao Liu 0006, Jiyan Sun, Liru Geng, Yinlong Liu |
Wirel. Commun. Mob. Comput. | 4 |
| 2020 | A Feedback Mechanism for Prediction-based Anomaly Detection In Content Delivery NetworksabstractCDN (Content Delivery Network) has become an important infrastructure of the Internet. However, building an anomaly detection system to monitor and guarantee CDN service quality is non-trivial. Current anomaly detection system usually suffers from undesirable performance in terms of high rate of false positive and false negative, which consequently impacts on its practical deployment. Identifying the root cause of a false detection is critical for diagnosing and improving the performance of anomaly detection. In this paper, we propose a novel feedback mechanism for prediction-based anomaly detection in CDN . Specifically, we introduce a carefully-designed metric named Fittingscore to diagnose whether the prediction model can fit the data well. Further, a threshold adjustment mechanism is proposed to dynamically adjust the thresholds of residual errors. Extensive experiments employing a three-month real CDN dataset collected from a top ISP-operated CDN in China show our proposed method can significantly improve the performance of anomaly detection. Zhilei Liu, Tao Lin 0001, Jiyan Sun, Yanjie Hu, Yan Zhang 0014, Zhen Xu 0009 |
ISCC | 4 |
| 2017 | DC2-MTCP: Light-Weight Coding for Efficient Multi-Path Transmission in Data Center NetworkabstractMulti-path TCP has recently shown great potential to take advantage of the rich path diversity in data center networks (DCN) to increase transmission throughput. However, the small flows, which take a large fraction of data center traffic, will easily get a timeout when split onto multiple paths. Moreover, the dynamic congestions and node failures in DCN will exacerbate the reorder problem of parallel multi-path transmissions for large flows. In this paper, we propose DC2-MTCP (Data Center Coded Multi-path TCP), which employs a fast and light-weight coding method to address the above challenges while maintaining the benefit of parallel multi-path transmissions. To meet the high flow performance in DCN, we insert a very low ratio of coded packets with a careful selection of the packets to be coded. We further present a progressive decoding algorithm to decode the packets online with a low time complexity. Extensive ns2-based simulations show that with two orders of magnitude lower coding delay, DC2-MTCP can reduce on average 40% flow completion time for small flows and increase 30% flow throughput for large flows compared to the peer schemes in varying network conditions. Jiyan Sun, Yan Zhang 0014, Xin Wang 0001, Shihan Xiao, Zhen Xu 0009, Hongjing Wu, Xin Chen 0019, Yanni Han |
IPDPS | 1 |
| 2017 | VNF-FG design and VNF placement for 5G mobile networks
Jiuyue Cao, Yan Zhang 0014, Wei An 0002, Xin Chen 0019, Jiyan Sun, Yanni Han |
Sci. China Inf. Sci. | 5 |
| 2016 | VNF Placement in Hybrid NFV Environment: Modeling and Genetic AlgorithmsabstractIn this paper, we study the VNF placement problem in hybrid NFV environment, which is important during the transition from traditional networks to NFV networks. We first propose a new concept of hybrid NFV environment, which is more comprehensive and realistic than the former works. Then, we give out a novel model of VNF placement optimization to achieve lower bandwidth consumption and lower maximum link utilization simultaneously, with consideration of VNF combination. Next, to solve this problem, we propose four genetic algorithms, which are combinations of the frameworks of two existing algorithms (MOGA and NSGA-II) and our novel modifications. Simulation results show that, in our 4 algorithms Greedy-NSGA-II has the best performance. When compared with other two non-genetic algorithms (BM and Random), the average total bandwidth consumption of Greedy-NSGA-II is only 12.24% and 2.96% of theirs respectively, and the average maximum link utilization of Greedy-NSGA-II is only 25.04% and 13.81% of theirs respectively. Jiuyue Cao, Yan Zhang 0014, Wei An 0002, Xin Chen 0019, Yanni Han, Jiyan Sun |
ICPADS | 6 |
| 2015 | TCP-FNC: A novel TCP with network coding for wireless networksabstractIn this paper, we propose TCP-FNC (TCP with fast network coding), which is designed to reduce the decoding delay for TCP with network coding. TCP-FNC retains the framework of TCP/NC and includes two schemes to meet the demand of online network coding. First, we develop a feedback based scheme named FCWL, which can efficiently reduce the waiting delay and work well with both RTT-based and loss-based TCP variants. Second, we propose an optimized progressive decoding algorithm named EFU for Gaussian-Jordan elimination, which can further reduce the computation delay from O(n2) to O(n). Evaluation results indicate that our TCP-FNC can achieve shorter decoding delay than TCP/NC and VON without trading off its goodput performance. We verify that TCP-FNC can reduce the decoding delay by 33% on average. Jiyan Sun, Yan Zhang 0014, Ding Tang, Shuli Zhang, Zhijun Zhao, Song Ci |
ICC | 1 |
| 2015 | Improving TCP performance in data center networks with Adaptive Complementary CodingabstractTCP suffers from low throughput and high latency because of its expensive timeout based loss recovery mechanism in data center networks (DCNs). In this paper, we propose TCP with Adaptive Complementary Coding (TCP-ACC) to effectively address these problems. Without revising existing TCP congestion control, we first design a light-weight complementary coding scheme to avoid TCP timeout which will result in higher throughput and lower latency. In our scheme, the redundancy setting is adaptive to the real-time packet loss rate. Then we introduce Lyapunov optimization framework to find the optimal number of redundant coding packets for TCP-ACC, and we also prove that TCP-ACC can reduce the flow timeout probability close to that of the optimal complementary coding solution. Extensive NS2 simulations show that, compared with other three solutions for TCP's problems in DCNs, TCP-ACC can reduce the flow completion time by 45% and improve the flow throughput by 40% on average. Jiyan Sun, Yan Zhang 0014, Ding Tang, Shuli Zhang, Zhen Xu 0009, Jingguo Ge |
LCN | 1 |