Chonghua Wang

dblp:171/1034 · DBLP profile ↗
← Back
18ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0001-9797-6736ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 1 first-author · 2 since 2021Security and privacy · 6 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Reverse K Nearest Neighbor Query in Large Road Networks: a Tree Decomposition Based Approach
Dian Ouyang, Jianye Yang 0001, Shiyu Yang 0002, Chonghua Wang, Xuemin Lin 0001
ICDE5
2026 Analysis on the Feasibility of D-FACTS Devices for Localizing FDI Attacks in Smart Grids
abstract
Proactive detection with distributed flexible AC transmission system (D-FACTS) devices has been extensively studied for identifying false data injection (FDI) attacks in smart grids, while their potential for localizing remains largely unexplored. To meet this gap, this paper systematically explores the feasibility of localizing FDI attacks with D-FACTS devices. Specifically, we first thoroughly study the rationale underlying FDI localization with D-FACTS devices. We prove that an activated D-FACTS device is capable of localizing FDI attacks targeted on its connected end buses once a bad data detection (BDD) alarm is triggered. In addition, we elaborately analyze the inherent localization limitations: (i) the unlocalizable adversary cases targeting one-degree buses or super-buses; (ii) the localization uncertainty introduced by the defender's blind spots, resulting in huge operational costs and insufficient precision. Following this, a data-prompting framework is designed to over-come the above limitations. This framework integrates a data driven injected error identifier for precise localization and cost reduction, followed by a perturbation strategy with D-FACTS devices that significantly lowers false positive rates. Extensive simulations validate our theoretical findings on the rationale and limitations, while also demonstrating the effectiveness of the proposed framework in addressing limitations and enhancing localization accuracy.
Qingyun Du, Mi Wen, Chonghua Wang, Beibei Li 0002, Yan Zhang 0002
IEEE Trans. Dependable Secur. Comput.3
2024 EM2FL: An Embedding Multimodal Fusion Federated Learning Approach to Optimize Privacy and Performance
abstract
Multimodal federated learning enhances model performance by integrating data from different modalities. However, this integration also introduces new privacy leakage risk associated with cross-modal correlation. Existing differential privacy methods are primarily designed for single-modal data, making them ineffective in multimodal scenarios, while noise addition often compromises data utility. In this paper, we propose an Embedding Multimodal Fusion Federated Learning Approach, called EM2FL. This approach leverages horizontal multimodal federated learning to collaboratively train global models across multiple data platforms without exposing raw private data. Instead of applying differential privacy to each modality-specific encoder separately, we implement it on the mixed embedding module that combines multiple modalities. We tested our approach on 3 distinct models and validated its effectiveness for the combination of image and user-item pair modalities. Experimental results show that our method improves performance by 10-20% compared to traditional differential privacy methods while maintaining a similar level of privacy protection. This demonstrates that EM2FL effectively balances privacy and performance through selective noise addition.
Zhe Sun 0005, Jiewei Wu, Chao Li 0027, Chonghua Wang, Yufu Zou, Shutong Yang, Yaowei Huang
HPCC4
2024 User Behavior Forensics on Encrypted Traffic in the Industrial Internet of Things
Zhishen Zhu, Gaopeng Gou, Chonghua Wang, Gang Xiong 0001
IFIP Int. Conf. Digital Forensics3
2024 Ada-LEval: Evaluating long-context LLMs with length-adaptable benchmarks
abstract
Chonghua Wang, Haodong Duan, Songyang Zhang, Dahua Lin, Kai Chen. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2024.
Chonghua Wang, Haodong Duan, Songyang Zhang 0001, Dahua Lin, Kai Chen 0026
NAACL-HLT1
2023 HubRouter: Learning Global Routing via Hub Generation and Pin-hub Connection
abstract
Global Routing (GR) is a core yet time-consuming task in VLSI systems. It recently attracted efforts from the machine learning community, especially generative models, but they suffer from the non-connectivity of generated routes. We argue that the inherent non-connectivity can harm the advantage of its one-shot generation and has to be post-processed by traditional approaches. Thus, we propose a novel definition, called hub, which represents the key point in the route. Equipped with hubs, global routing is transferred from a pin-pin connection problem to a hub-pin connection problem. Specifically, to generate definitely-connected routes, this paper proposes a two-phase learning scheme named HubRouter, which includes 1) hub-generation phase: A condition-guided hub generator using deep generative models; 2) pin-hub-connection phase: An RSMT construction module that connects the hubs and pins using an actor-critic model. In the first phase, we incorporate typical generative models into a multi-task learning framework to perform hub generation and address the impact of sensitive noise points with stripe mask learning. During the second phase, HubRouter employs an actor-critic model to finish the routing, which is efficient and has very slight errors. Experiments on simulated and real-world global routing benchmarks are performed to show our approach's efficiency, particularly HubRouter outperforms the state-of-the-art generative global routing methods in wirelength, overflow, and running time. Moreover, HubRouter also shows strength in other applications, such as RSMT construction and interactive path replanning.
Xingbo Du, Chonghua Wang, Ruizhe Zhong, Junchi Yan
NeurIPS2
2023 WaterPurifier: A scalable system to prevent the DNS water torture attack in 5G-enabled SIoT network
Lihua Yin, Muyijie Zhu, Chonghua Wang
Comput. Commun.5
2022 Anomaly Detection in Encrypted Identity Resolution Traffic based on Machine Learning
abstract
Identity resolution is an emerging network resource widely applied in Industrial Internet of Things. Although encryption improves the privacy of identity resolution, it also challenges DPI-based anomaly detection. Therefore, it is imperative to recognize and supplement the encrypted information of IDS. In this paper, we design a machine learning-based framework to automatically extract critical information of identity resolution system from network traffic. According to the characteristics of traffic, we use the hybrid feature of statistics and sequences to describe encrypted traffic. Besides, a supervised classification algorithm is applied to explore the effective classification of two communication processes, which are service attribution information for node addressing and operation behavior for data management. We tested this method based on the encrypted traffic collected from a realistic identity resolution system. The results indicate that our approach exhibits good performance, outperforms related works, and can be applied in resource-constrained industrial scenario. This is the first work analysing the identity resolution system from the perspective of traffic analysis.
Zhishen Zhu, Qingya Yang, Chonghua Wang, Zhen Li 0011
QRS4
2022 MCFM: Discover Sensitive Behavior from Encrypted Traffic in Industrial Control System
abstract
To tackle with advanced persistent threats against industrial control system, Siemens has developed S7CommPlus- TLS, a new version of the encrypted protocol challenging traditional DPI-based anomaly detection methods. However, the communication mode of industrial control system leads to the overlapping of periodic traffic and sensitive behavior traffic, and thus makes mainstream encrypted traffic classification methods exhibit a poor performance in S7CommPlus-TLS protocol. Therefore, we design a multiple clustering framework called MCFM, which can automatically extract sensitive behavior of S7CommPlus-TLS from network traffic. The first-clustering is used as a pre-processing model to separate and remove periodic traffic from overlapping flows according to the communication mode of industrial control system. Besides, we employ the second- clustering as a generator to extract the fingerprint of sensitive behaviors. Our comprehensive experiments on the simulation dataset covering six sensitive behaviors indicate that MCFM achieves an excellent performance, and outperforms present cutting-edge methods. To the best of our knowledge, this is the first work analyzing industrial control system from the perspective of encrypted traffic analysis.
Zhishen Zhu, Junzheng Shi, Chonghua Wang, Gang Xiong 0001, Zhiqiang Hao, Gaopeng Gou
TrustCom3
2022 Network traffic analysis over clustering-based collective anomaly detection
Chonghua Wang, Zhiqiang Hao, Shu Hu 0001, Bo Jiang 0013, Xuehong Chen
Comput. Networks1
2021 An efficient identity-based proxy signcryption using lattice
Chonghua Wang, Xiaochun Cheng
Future Gener. Comput. Syst.3
2020 pRnR: A Parallel Record-Replay Framework for Virtual Machines
abstract
The record and replay(RnR) technology of virtual machine(VM) provides the ability to reproduce the past execution of a VM deterministically. It has many promising applications in the cloud environment, including fault tolerance, security analysis, and failure diagnosis. Existing studies in this area pay more effort in optimizing the record method, such as reducing performance penalty and storage costs. However, considering that many practical applications follow the record once, replay many mode, the optimization for the replay is more critical, especially for efficiency. In this paper, we propose pRnR, a novel parallel RnR framework, to support efficient replay. By combining the native RnR framework with an improved continuous snapshots mechanism, pRnR divides the full execution into many independent and complete slices, each of which supports arbitrary replay. In addition, it supports two replay modes to improve replay efficiency, i.e., multi-slice parallel replay and multi-dimension parallel replay. Moreover, we apply our pRnR framework to syscall-based diagnosis to demonstrate its usability. The experimental results show that pRnR is more efficient than existing RnR frameworks.
Wei Wang 0428, Lei Cui 0003, Zhiyu Hao, Haiqiang Fei, Chonghua Wang, Yaqiong Peng
ICCD5
2020 STIDM: A Spatial and Temporal Aware Intrusion Detection Model
abstract
Network intrusion detection plays a critical role in cyberspace security. Most existing conventional detection methods mostly rely on manually-designed features to detect intrusion behaviours from large-scale flow data. Recent studies show that deep learning-based methods are effective for network intrusion detection due to the ability to learn discriminative features from data automatically. However, these models ignore the problem of the irregular time intervals between packets in a flow, causing the degradation of detection performance. To this end, we propose a Spatial and Temporal Aware Intrusion Detection model (STIDM). The proposed STIDM model first uses a one-dimensional Convolutional Neural Network (1D-CNN) to extract spatial features based on the nature of flow and packet. Then we design a Time and Length sensitive LSTM (TL-LSTM) method to learn richer temporal features from the irregular flows. The two parts are trained simultaneously to achieve global optimum. Through extensive experiments on the ISCX2012 dataset and the CICIDS2017 dataset, we demonstrate that STIDM outperforms state-of-the-art models.
Xueying Han, Rongchao Yin, Zhigang Lu 0002, Bo Jiang 0013, Chonghua Wang
TrustCom7
2017 NOR: Towards Non-intrusive, Real-Time and OS-agnostic Introspection for Virtual Machines in Cloud Environment
Chonghua Wang, Zhiyu Hao, Xiao-chun Yun
Inscrypt1
2017 SA-PFRS: Semantics-Aware Page Frame Reclamation System in Virtualized Environments
abstract
Page reclamation is one compelling way to overcommit memory in modern operating systems. To achieve wise reclamation, the Linux kernels employ page frame reclamation algorithm (PFRA) to reclaim pages based on the page usage view. However, due to the semantic gap problem in virtualized environments, the native PFRA suffers three types of unwise evictions including false eviction, superficial eviction and omitted eviction. This will lead to high swapping I/O activity and consequently limits the ability to overcommit memory. We present SA-PFRS, a Semantics-Aware Page Frame Reclamation System, to address this problem. SA-PFRS separates the memory pages allocated for guests from reclaimable candidates in host, explores how the pages are being used by guest OS, and adjusts the reclamation order in the view of guest. Then, SA-PFRS re-arranges the reclamation sequence of guest pages and host pages, so as to reclaim the memory pages in a global semantics-aware manner. This enables SA-PFRS to eliminate a large number of swapping I/O operations when memory is overcommitted. We implement a prototype of SA-PFRS in Linux kernel, and show its effectiveness through a set of experiments.
Lei Cui 0003, Zhiyu Hao, Chonghua Wang
ICPADS4
2017 A Hypervisor Level Provenance System to Reconstruct Attack Story Caused by Kernel Malware
Chonghua Wang, Shiqing Ma, Xiangyu Zhang 0001, Junghwan Rhee, Xiao-chun Yun, Zhiyu Hao
SecureComm1
2016 Piccolo: A Fast and Efficient Rollback System for Virtual Machine Clusters
abstract
Rollback is an effective technique to resume the system execution from a recorded intermediate state upon failures. However, in virtualized environments, rollback of a virtual machine cluster (VMC) produces high network traffic and long service disruption, consequentially imposing significant overhead both on network and applications. In this paper, we propose Piccolo, a fast and efficient rollback system, to restore a VMC from snapshot files over datacenter network. We exploit the similarity among VMC snapshots and leverage multicast to deliver the identical pages across VMs placed on disperse hosts, thereby bypassing transmission of a large number of unnecessary pages. In addition to presenting Piccolo, we detail its implementation, and evaluate it by a set of experiments. The results show that Piccolo could achieve a significant reduction in terms of total sent data, network traffic and rollback latency compared to the existing generic rollback techniques.
Lei Cui 0003, Zhiyu Hao, Chonghua Wang, Haiqiang Fei, Zhenquan Ding
ICPP3
2015 Exploring Efficient and Robust Virtual Machine Introspection Techniques
Chonghua Wang, Xiao-chun Yun, Zhiyu Hao, Lei Cui 0003, Yandong Han, Qingxin Zou
ICA3PP (3)1