Linan Huang

dblp:172/2771 · DBLP profile ↗
← Back
9ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0003-1591-8749ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 STARDIS: Strategic Scheduling and Deceptive Signaling for Satellite Intrusion Detection System Deployment
abstract
Satellite communication networks operate under stringent computational constraints and are susceptible to sophisticated cyberattacks. This paper introduces a novel defense framework that decouples security optimization into ground-based analysis and onboard real-time execution. In the long-term loop, the ground segment processes historical data to estimate key statistical parameters of the task environment. Additionally, we incorporate the time-varying characteristics of satellite wireless links to account for the dynamic communication context. In the short-term loop, the satellite employs a receding horizon optimization that models dynamic task arrivals and maximizes a utility function considering detection rates and resource costs. To counter intelligent adversaries interception, we introduce a deception mechanism using Bayesian persuasion theory. By strategically manipulating the short-term action sequences in the telemetry downlink, we mislead an external attacker’s beliefs. We mathematically model the attacker’s optimal response under channel uncertainty and demonstrate that our framework significantly reduces attacker utility. The approach’s effectiveness is formally proven using Lyapunov theory.
Yuzhou Xiao, Linan Huang, Peilong Liu, Chunxiao Jiang, Linling Kuang
IEEE J. Sel. Areas Commun.2
2025 A Consolidated Game Framework for Cooperative Defense Against Cross-Domain Cyber Attacks in Satellite-Enabled Internet of Things
abstract
As the adoption of satellite-enabled Internet of Things (IoT) continues to rise, its intricate multi-domain architecture becomes increasingly susceptible to cross-domain cyber threats. Attackers can exploit compromised IoT devices, inject malicious packets into data streams aggregated at the IoT gateway for satellite backhaul, and potentially endanger the satellite network during transmission by exploiting the hardware, software, and protocol vulnerabilities. Compared to single-domain defenses, cooperative defense at the IoT devices, IoT access network, and satellite transmission network provides fine-granularity defense against cross-domain intelligent attacks. However, quantifying cross-domain impacts and tilting incentive misalignment among different participants remain significant challenges, making systematic cooperative defense development a complex task. To address this, we develop a tripartite security game framework to characterize the impacts of attacks and defense methods across both the terrestrial and satellite domains. Leveraging this game model, we devise flow pricing to optimally motivate the IoT Network Operator (IoT-NO) to prevent malicious packet infiltration into the satellite domain. Subsequently, we propose efficient learning algorithms enabling both the IoT-NO to ascertain their ideal flow sampling strategies and the Satellite Service Provider (SAT-SP) to determine optimal flow pricing. The simulation results corroborate the effectiveness of the consolidated game in counteracting cross-domain cyber attacks and facilitating cooperative defense between the IoT-NO and the SAT-SP with non-aligned incentives.
Linan Huang, Peilong Liu, Xu Chen 0004, Chunxiao Jiang, Linling Kuang, Jianhua Lu
IEEE Internet Things J.1
2024 ZETAR: Modeling and Computational Design of Strategic and Adaptive Compliance Policies
abstract
Compliance management plays an important role in mitigating insider threats. Incentive design is a proactive and noninvasive approach to achieving compliance by aligning an insider’s incentive with the defender’s security objective, which motivates (rather than commands) an insider to act in the organization’s interests. Controlling insiders’ incentives for population-level compliance is challenging because they are neither precisely known nor directly controllable. To this end, we develop ZEro-Trust Audit with strategic Recommendation (ZETAR), a zero-trust audit and recommendation framework, to provide a quantitative approach to model insiders’ incentives and design customized recommendation policies to improve their compliance. We formulate primal and dual convex programs to compute the optimal bespoke recommendation policies. We create the theoretical underpinning for understanding trust, compliance, and satisfaction, which leads to scoring mechanisms of how compliant and persuadable an insider is. After classifying insiders as malicious, self-interested, or amenable based on their incentive misalignment levels with the defender, we establish bespoke information disclosure principles for these insiders of different incentive categories. We identify the policy separability principle and the set convexity, which enable finite-step algorithms to efficiently learn the completely trustworthy (CT) policy set when insiders’ incentives are unknown. Finally, we present a case study to corroborate the design. Our results show that ZETAR can well adapt to insiders with different risk and compliance attitudes and significantly improve compliance. Moreover, trustworthy recommendations can provably promote cyber hygiene and insiders’ satisfaction.
Linan Huang, Quanyan Zhu
IEEE Trans. Comput. Soc. Syst.1
2022 RADAMS: Resilient and adaptive alert and attention management strategy against Informational Denial-of-Service (IDoS) attacks
Linan Huang, Quanyan Zhu
Comput. Secur.1
2022 A Dynamic Game Framework for Rational and Persistent Robot Deception With an Application to Deceptive Pursuit-Evasion
abstract
This article studies rational and persistent deception among intelligent robots to enhance security and operational efficiency. We present an$N$-player$K$-stage game with an asymmetric information structure where each robot’s private information is modeled as a random variable or its type. The deception is persistent as each robot’s private type remains unknown to other robots for all stages. The deception is rational as robots aim to achieve their deception goals at minimum cost. Each robot forms a dynamic belief of others’ types based on intrinsic or extrinsic information. Perfect Bayesian Nash equilibrium (PBNE) is a natural solution concept for dynamic games of incomplete information. Due to its requirements of sequential rationality and belief consistency, PBNE provides a reliable prediction of players’ actions, beliefs, and expected cumulative costs over the entire$K$stages. The contribution of this work is fourfold. First, we identify the PBNE computation as a nonlinear stochastic control problem and characterize the structures of players’ actions and costs under PBNE. We further derive a set of extended Riccati equations with cognitive coupling under the linear-quadratic (LQ) setting and extrinsic belief dynamics. Second, we develop a receding-horizon algorithm with low temporal and spatial complexity to compute PBNE under intrinsic belief dynamics. Third, we investigate a deceptive pursuit-evasion game as a case study and use numerical experiments to corroborate the results. Finally, we propose metrics, such as deceivability, reachability, and the price of deception (PoD), to evaluate the strategy design and the system performance under deception. Note to Practitioners—Recent advances in automation and adaptive control in multi-agent systems enable robots to use deception to accomplish their objectives. Deception involves intentional information hiding to compromise the security and operational efficiency of the robotic systems. This work proposes a dynamic game framework to quantify the impact of deception, understand the robots’ behaviors and intentions, and design cost-efficient strategies under the deception that persists over stages. Existing research studies on robot deception have relied on experiments while this work aims to lay a theoretical foundation of deception with quantitative metrics, such as deceivability and the PoD. The proposed model has wide applications, including cooperative robots, pursuit and evasion, and human–robot teaming. The pursuit-evasion games are used as case studies to show how the deceiver can amplify the deception by belief manipulation and how the deceived robots can reduce the negative impact of deception by enhanced maneuverability and Bayesian learning. The future work would focus on designing cooperative deception among swarm robotics and robotic systems that are robust to or further benefit from the deception.
Linan Huang, Quanyan Zhu
IEEE Trans Autom. Sci. Eng.1
2022 ADVERT: An Adaptive and Data-Driven Attention Enhancement Mechanism for Phishing Prevention
abstract
Attacks exploiting theinnateand theacquiredvulnerabilities of human users have posed severe threats to cybersecurity. This work proposes ADVERT, ahuman-technical solutionthat generates adaptive visual aids in real-time to prevent users from inadvertence and reduce their susceptibility to phishing attacks. Based on the eye-tracking data, we extractvisual statesandattention statesas system-level sufficient statistics to characterize the user’s visual behaviors and attention status. By adopting a data-driven approach and two learning feedback of different time scales, this work lays out a theoretical foundation toanalyze,evaluate, and particularlymodifyhumans’ attention processes while they vet and recognize phishing emails. We corroborate theeffectiveness,efficiency, androbustnessof ADVERT through a case study based on the data set collected from human subject experiments conducted at New York University. The results show that the visual aids can statistically increase the attention level and improve the accuracy of phishing recognition from 74.6% to a minimum of 86%. The meta-adaptation can further improve the accuracy to 91.5% (resp. 93.7%) in less than 3 (resp. 50) tuning stages.
Linan Huang, Shumeng Jia, Emily Balcetis, Quanyan Zhu
IEEE Trans. Inf. Forensics Secur.1
2021 Duplicity Games for Deception Design With an Application to Insider Threat Mitigation
abstract
Recent incidents such as the Colonial Pipeline ransomware attack and the SolarWinds hack have shown that traditional defense techniques are becoming insufficient to deter adversaries of growing sophistication. Proactive and deceptive defenses are an emerging class of methods to defend against zero-day and advanced attacks. This work develops a new game-theoretic framework called the duplicity game to design deception mechanisms that consist of a generator, an incentive modulator, and a trust manipulator, referred to as the GMM mechanism. We formulate a mathematical programming problem to compute the optimal GMM mechanism, quantify the upper limit of enforceable security policies, and characterize conditions on user's identifiability and manageability for cyber attribution and user management. We develop a separation principle that decouples the design of the modulator from the GMM mechanism and an equivalence principle that turns the joint design of the generator and the manipulator into the single design of the manipulator. A case study of dynamic honeypot configurations is presented to mitigate insider threats. The numerical experiments corroborate the results that the optimal GMM mechanism can elicit desirable actions from both selfish and adversarial insiders and consequently improve the security posture of the insider network. In particular, a proper modulator can reduce the \textcolor{black}{incentive misalignment} between the players and achieve win-win situations for the selfish insider and the defender. Meanwhile, we observe that the defender always benefits from faking the percentage of honeypots when the optimal generator is presented.
Linan Huang, Quanyan Zhu
IEEE Trans. Inf. Forensics Secur.1
2020 A dynamic games approach to proactive defense strategies against Advanced Persistent Threats in cyber-physical systems
Linan Huang, Quanyan Zhu
Comput. Secur.1
2016 A comprehensive reconfigurable computing approach to memory wall problem of large graph computation
Xu Wang 0010, Yongxin Zhu 0001, Linan Huang
J. Syst. Archit.3