EDBT 2026 Demo / reviewers in the wild / expert
Yali Yuan
dblp:188/9655
· DBLP profile ↗
39ranked-venue papers
17as first author
35since 2021 · last 2026
0000-0002-9258-9929ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 12 first-author · 13 since 2021Security and privacy · 14 · 5 first-author · 14 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PAGPL: Privacy-Aware Graph Prompt Learning Scheme via Adaptive Perturbation-Estimated Topology RecoveryabstractGraph prompt learning (GPL) serves as a crucial framework for mitigating the knowledge transfer by reconciling the substantial mismatch between pre-training models and downstream tasks. However, prevalent GPL paradigm fail to accommodate graph data affected by privacy-induced noise. Specifically, 1) GPL typically relies on the stability of original graph structures for the design of effective prompt templates; 2) the construction of prompts lacks explicit guidance to suppress noise introduced by privacy perturbations; 3) prompt optimization on single disturbed graphs can easily lead to overfitting to noise patterns. To address these issues, we propose a novel privacy-aware graph prompt learning (PAGPL) scheme, which alleviates spurious clues caused by privacy noise injection. Initially, an adaptive structure-wise Bayesian estimation is applied to reconstruct the privacy-perturbed graphs. Subsequently, to suppress the impact of residual perturbation, a noise-resilient prompt generation is employed to filter unreliable structural and signals. Ultimately, we incorporate a multi-view-based progressive privacy consistency to promote the robustness of prompts against the semantic misalignment while improving the task-specific consistency. The experimental results reveal that our scheme outperforms state-of-the-art (SOTA) GPL approaches with a 10%–60% improvement in accuracy under various real-world privacy-perturbed scenarios. Ju Jia, Jiansen Song, Jingxuan Yu, Jiabao Guo, Xiaoshuang Jia, Di Wu 0050, Yali Yuan, Guang Cheng 0001 |
AAAI | 7 |
| 2026 | MPAS: Breaking Sequential Constraints of Multi-Agent Communication Topologies via Individual-Epistemic Message PropagationabstractLarge language model (LLM)-driven agents are designed to handle a wide range of tasks autonomously. As tasks become increasingly composite, the integration of multiple agents into a graph-structured system offers a promising solution. Recent advances mainly architect the communication order among agents into a specified directed acyclic graph, from which a one-by-one execution can be determined by topological sort. However, sequential architectures restrict the diversity of the information flow, hinder parallel computation, and exhibit vulnerabilities to potential backdoor threats. To overcome underlying shortcomings of sequential structures, we propose a node-wise multi-agent scheme, named message passing agent system (MPAS). Specifically, to parallelize the communication across agents, we extend the message propagation mechanism in graph representation learning to multi-agent scenarios and introduce our individual-epistemic message propagation. To further enhance expressiveness and robustness, we investigate three self-driven message aggregators. To achieve desired working flows, collaborative connections can be optimized without constraints. The experimental results reveal that compared to state-of-the-art sequential designs, MPAS could architect more advanced algorithms in 93.8% of the evaluations, reduce the average communication time from 84.6 seconds to 14.2 seconds per round on AQuA, and improve resilience against backdoor misinformation injection in 94.4% tests. Jingxuan Yu, Ju Jia, Simeng Qin, Xiaojun Jia, Siqi Ma 0001, Yihao Huang 0001, Yali Yuan, Guang Cheng 0001 |
AAAI | 7 |
| 2026 | Beyond flat identification: Exploiting site-page structure for hierarchical webpage fingerprinting
Yali Yuan, Xingjian Zeng, Guang Cheng 0001 |
Comput. Networks | 1 |
| 2026 | Optimizing multi-objective strategies for enhanced Tor De-anonymizationabstractAbstract Tor employs multi-layer encryption and three-hop circuits to provide low-latency anonymity. While indispensable for privacy, these same properties can also be misused to conceal illicit activity. This dual-use nature makes effective de‑anonymization essential under appropriate, policy-bounded oversight, so that harmful behavior can be uncovered without undermining legitimate use. Yet de‑anonymization is not free: taking nodes offline and deploying honeypots consumes significant resources, increases exposure, and risks degrading network availability. Prior work faces two limitations: (i) it decouples the choice of which node to target from which method to apply, overlooking their strong coupling; and (ii) it often evaluates effectiveness with narrow, single-effect proxies, neglecting collateral network impact and operational cost. To support better de‑anonymization, we model joint node–technique selection as a tri-objective problem balancing attack gain ( AP ), attack impact ( AI ), and attack cost( AC ). For each feasible node–method pair we compute these three metrics, extract the Pareto set, prune with $$\epsilon$$ ϵ -constraints, and select a preference-aware compromise with VIKOR. In a Docker-orchestrated testbed, this Pareto-first pipeline achieves about $$+50\%$$ + 50 % higher attack gain and roughly $$-29\%$$ - 29 % lower attack Impact and attack cost compared with random selection. Yali Yuan, Ruolin Ma, Liangyi Gong, Guang Cheng 0001 |
Cybersecur. | 1 |
| 2026 | Network intrusion detection with edge-directed graph Multi-Head Attention Networks
Xiang Li 0167, Haiyang Diao, Yali Yuan, Jing Zhang 0015 |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | AHE: Adaptive hybrid-sampling ensemble for large-scale highly imbalanced data classification
Xingjian Zeng, Yali Yuan, Hantao Mei, Guang Cheng 0001 |
Knowl. Based Syst. | 2 |
| 2026 | Heterogeneous graph contrastive learning with spectral augmentation and dual aggregation
Jing Zhang 0015, Xiaoqian Jiang, Yingjie Xie, Yali Yuan, Shunmei Meng, Cangqi Zhou |
Pattern Recognit. | 5 |
| 2026 | Robust and Invisible Flow Watermarking With Invertible Neural Network for Traffic TrackingabstractThis paper introduces an innovative blind flow watermarking framework on the basis of Invertible Neural Network (INN) called IFW, which aims to solve the problem of suboptimal encoder-decoder coupling in existing end-to-end watermarking architectures. The framework tightly couples the encoder and decoder to achieve highly consistent feature mapping using the same parameters, thus effectively avoiding redundant feature embedding. In addition, this paper adopts the INN to implement watermarking, which supports forward encoding and backward decoding, and the watermark extraction is completely dependent on the embedding algorithm without the need for the original network flow. This feature enables both the embedding and the blind extraction of watermarks simultaneously. Extensive experiments demonstrate that the proposed IFW method achieves a watermark extraction accuracy exceeding 96.6% and maintains a stable K-S test p-value above 0.85 in both simulated and real-world Tor traffic environments. These results indicate a clear advantage over mainstream baselines, highlighting the methods ability to jointly ensure robustness and invisibility, as well as its strong potential for real-world deployment. Yali Yuan, Ruolin Ma, Jian Ge 0004, Guang Cheng 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2026 | Early-MFC: Enhanced Flow Correlation Attacks on Tor via Multi-View Triplet Networks With Early Network TrafficabstractFlow correlation attacks is an efficient network attacks, aiming to expose those who use anonymous network services, such as Tor. Conducting such attacks during the early stages of network communication is particularly critical for scenarios demanding rapid decision-making, such as cybercrime detection or financial fraud prevention. Although recent studies have made progress in flow correlation attacks techniques, research specifically addressing flow correlation with early network traffic flow remains limited. Moreover, due to factors such as model complexity, training costs, and real-time requirements, existing technologies cannot be directly applied to flow correlation with early network traffic flow. In this paper, we propose flow correlation attack with early network traffic, named Early-MFC, based on multi-view triplet networks. The proposed approach extracts multi-view traffic features from the payload at the transport layer and the Inter-Packet Delay. It then integrates multi-view flow information, converting the extracted features into shared embeddings. By leveraging techniques such as metric learning and contrastive learning, the method optimizes the embeddings space by ensuring that similar flows are mapped closer together while dissimilar flows are positioned farther apart. Finally, Bayesian decision theory is applied to determine flow correlation, enabling high-accuracy flow correlation with early network traffic flow. Furthermore, we investigate flow correlation attacks under extra-early network traffic flow conditions. To address this challenge, we propose Early-MFC+, which utilizes payload data to construct embedded feature representations, ensuring robust performance even with minimal packet availability. Yali Yuan, Qianqi Niu, Yachao Yuan |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | CoDA: Cross-Domain Few-Shot Website Fingerprinting via Contrastive Prototype AlignmentabstractTor is widely used to facilitate anonymous web communication, but it remains vulnerable to Website Fingerprinting (WF) attacks. Although deep learning-based WF attacks have shown promising results, they typically rely on large-scale labeled data and assume consistent conditions between training and deployment. These assumptions limit their practical applicability in real-world scenarios, where data scarcity and domain shifts are common. To address these challenges, recent research has focused on Cross-Domain Few-Shot Website Fingerprinting (CDFSWF), a more realistic yet challenging setting. Existing efforts mainly leverage data augmentation or feature alignment techniques. While data augmentation can mitigate sample scarcity, it often fails to capture true distributional variability. In contrast, many feature alignment WF methods overlook the semantic structure of class relationships, reducing their effectiveness in the target domain. In this paper, we propose CoDA, a novel method designed to improve cross-domain robustness in CDFSWF. CoDA integrates supervised contrastive pre-training, hierarchical flow attention, and prototype-based classification to effectively model semantic traffic structures under domain shifts. Furthermore, a Dual Confidence Alignment (DCA) strategy is introduced during fine-tuning to adaptively align semantic structures. Extensive experiments across various cross-domain scenarios show that CoDA consistently outperforms state-of-the-art baselines in both closed-world and open-world settings. Yuwei Xu 0001, Xinhe Fan, Yujie Hou, Yali Yuan, Qiao Xiang, Guang Cheng 0001 |
TrustCom | 5 |
| 2025 | DeMarking: A defense for network flow watermarking in real-time
Yali Yuan, Jian Ge 0004, Guang Cheng 0001 |
Comput. Secur. | 1 |
| 2025 | Attack smarter: Attention-driven fine-grained webpage fingerprinting attacks
Yali Yuan, Weiyi Zou, Guang Cheng 0001 |
Comput. Secur. | 1 |
| 2025 | A network flow fingerprinting method with adaptive embedding strengthabstractAbstract Network flow fingerprinting technology extends the number of embedded bits based on watermarking, thereby conveying additional information about the marked traffic, such as the traffic origin or the identity of the marking entity. However, existing fingerprinting/watermarking techniques follow the same embedding pattern under various levels of network noise, which hinders adaptation to high-noise environments and increases the risk of information loss. Therefore, this paper introduces the concept of embedding strength and proposes a network flow fingerprinting method with adaptive embedding strength. The embedding strength is adaptive for different network flows and can be freely adjusted. To achieve this, we design a two-stage training framework to generate fingerprint delays. In the first stage, we use an autoencoder architecture to obtain the optimal embedding for the fingerprint. In the second stage, we introduce a new component-the Adaptor-to produce a minimized embedding strength that eliminates redundant embeddings from the previous stage, thus balancing robustness and invisibility. Experimental results show that, after two stages of training, our scheme achieves an extraction rate of 98.33% and a bit error rate of 0.83%. Furthermore, in high-noise environments, our scheme can adjust the embedding strength to improve the extraction rate from 60.83 to over 90%. Yali Yuan, Jian Ge 0004, Guang Cheng 0001 |
Cybersecur. | 1 |
| 2025 | FDGAT-WTA: A dynamic detection model for web tracking and advertising based on improved graph attention networks
Yali Yuan, Runke Li, Guang Cheng 0001 |
J. Netw. Comput. Appl. | 1 |
| 2025 | MW3F: Improved multi-tab website fingerprinting attacks with Transformer-based feature fusion
Yali Yuan, Weiyi Zou, Guang Cheng 0001 |
J. Netw. Comput. Appl. | 1 |
| 2025 | Class Incremental Website Fingerprinting Attack Based on Dynamic Expansion ArchitectureabstractEncrypted traffic on anonymizing networks is still at risk of being exposed to the Website Fingerprinting (WF) attack. This attack can seriously threaten the online privacy of users of anonymity networks such as Tor. While deep-learning-based WF attacks achieve high accuracy in controlled experimental settings, they cannot continuously learn after deployment. In real-world environments, new websites are constantly emerging, requiring attackers to expand their monitoring scope continuously. This necessitates attack models capable of continuous learning and expanding classification capabilities. In this paper, we explore how attackers can leverage incremental class learning techniques to continuously learn new classes while retaining the ability to distinguish old ones. This approach mitigates the catastrophic forgetting problem in dynamic, open-world scenarios. We introduce a new WF attack, Class Incremental Fingerprinting (CIF), which employs a scalable architecture enabling Class Incremental Learning (CIL) with limited resources. We evaluate this attack in various scenarios, such as learning 100, 200, and 500 monitored website classes across 5 and 10 incremental tasks, achieving an average accuracy of 97.8% and above. Additionally, we assess the CIF attack’s effectiveness in open-world multi-classification scenarios and test it in few-shot settings using the proposed data augmentation method, Mixtam, achieving an average task accuracy of 87.6% and above with only 30 samples per class. Yali Yuan, Yangyang Du, Guang Cheng 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | High Precision and Efficient Anonymous Traffic Classification in the Real-WorldabstractVarious Traffic Classification (TC) technologies have been developed to de-anonymize anonymous tools, such as Tor, the most popular communication anonymous system. Although current TC methods boast high performance in closed-world scenarios, they frequently encounter challenges when dealing with the low base rate of anonymous traffic in the real open world, a phenomenon referred to as the base rate fallacy. In this paper, we introduce HPETC, an anonymous traffic classification system tailored for real-world scenarios, with a focus on achieving high precision, even in the presence of extremely low rates of anonymous traffic within expansive network environments. HPETC comprises an online classifier that efficiently filters anonymous traffic with minimal resource requirements, alongside an offline classifier responsible for extracting detailed information to support fine-grained classification. In response to the base rate fallacy, we introduce three Enhanced Techniques to enhance the performance of the classifiers within HPETC. Experimental findings illustrate that HPETC markedly diminishes resource consumption and greatly enhances the actual precision in comparison to state-of-the-art methods. Remarkably, in scenarios characterized by an extremely low rate of anonymous traffic (non-Tor/Tor$=$1000), our HPETC demonstrates an actual precision improvement that exceeds eightfold when benchmarked against commonly utilized models, specifically the Random Forest (RF) and Convolutional Neural Network (CNN) models. Hantao Mei, Guang Cheng 0001, Yali Yuan |
IEEE Trans. Netw. | 3 |
| 2024 | ProfistMAC: A Protocol Finite State Machine Classifier via Graph Representation
Yali Yuan, Guang Cheng 0001 |
ACISP (2) | 1 |
| 2024 | Improve Deep Forest with Learnable Layerwise Augmentation Policy SchedulesabstractAs a modern ensemble technique, Deep Forest (DF) employs a cascading structure to construct deep models, providing stronger representational power compared to traditional decision forests. However, its greedy multi-layer learning procedure is prone to overfitting, limiting model effectiveness and generalizability. This paper presents AugDF, an optimized Deep Forest featuring learnable, layerwise data augmentation policy schedules. Specifically, We introduce the Cut Mix for Tabular data (CMT) augmentation technique to mitigate overfitting and develop a population-based search algorithm to tailor augmentation intensity for each layer. Additionally, we propose to incorporate outputs from intermediate layers into a checkpoint ensemble for more stable performance. Experimental results show that AugDF sets new state-of-the-art (SOTA) benchmarks in various tabular classification tasks, outperforming shallow tree ensembles, deep forests, deep neural network, and AutoML competitors. The learned policies also transfer effectively to Deep Forest variants, underscoring its potential for enhancing non-differentiable deep learning modules in tabular signal processing. Hongyu Zhu 0004, Sichu Liang, Fangqi Li 0001, Yali Yuan, Shi-Lin Wang, Guang Cheng 0001 |
ICASSP | 5 |
| 2024 | TorHunter: A Lightweight Method for Efficient Identification of Obfuscated Tor Traffic Through Unsupervised Pre-training
Yuwei Xu 0001, Zhengxin Xu, Jie Cao 0009, Yali Yuan, Guang Cheng 0001 |
ICICS (2) | 5 |
| 2024 | M-ETC: Improving Multi-Task Encrypted Traffic Classification by Reducing Inter-Task InterferenceabstractWith the rapid evolution of deep learning (DL), its integration in encrypted traffic classification (ETC) can automatically extract key features from raw traffic data, enhancing classification performance. So far, researchers have proposed many DL-based models for ETC. However, the complexity and dynamism of network applications lead to the diversification of ETC tasks. Current models, mostly tailored for single tasks, overlook real-world multi-tasking needs of network devices. Deploying task-specific complex models concurrently on resource-limited devices is impractical. In response to the increasing number of tasks, researchers have introduced multi-task learning frameworks for ETC, demonstrating its potential as a promising technical approach. However, current research overlooks the interference between tasks, resulting in flawed models when it comes to sharing parameters, setting learning rates, and determining loss values. Aiming at these deficiencies, we propose $\mathcal{M}$-ETC, a multi-task ETC method reducing inter-task interference. The innovation of $\mathcal{M}$-ETC lies in two aspects. Firstly, we design a hierarchical multi-task learning model (HMLM) to provide effective features for each task and prevent the impact of invalid features. Secondly, we propose a learning rate balancing strategy (LRB) for modules and a dynamic weight average strategy (DWA) for tasks’ loss values. During model training, LRB prevents overfitting and underfitting of tasks, while DWA prevents bias towards tasks with large loss values. To validate $\mathcal{M}$-ETC, we carry out comparative experiments using four encrypted traffic datasets. The experimental results show that the classification performance of $\mathcal{M}$-ETC on multiple tasks exceeds those of five state-of-the-art methods. Yuwei Xu 0001, Xiaotian Fang, Zhengxin Xu, Kehui Song, Yali Yuan, Guang Cheng 0001 |
TrustCom | 5 |
| 2024 | TriViewNet: Achieve Accurate Tor Hidden Service Classification by Multi-View Feature Extraction and FusionabstractTor has provided hidden services (HS) and protected the anonymity of the Web server with hidden service directory servers. Some criminals use hidden services to engage in illegal activities, such as anonymous transactions, pirated distribution, hacking, etc. In order to protect the security of cyberspace, hidden service traffic needs to be deanonymized. Artificial intelligence-based methods have become the most promising, but there are still two shortcomings in current research work. First, some of them mainly uses the size and direction sequence of the data packet as the input to complete the recognition, without mining the features of network traffic from many views. Second, they extract information from different view, but just concatenate them together instead of fuse them densely. Therefore, in this paper we propose a Tor hidden service traffic identification method with multi views named TriViewNet. TriViewNet extracts information from three different views, local flow, TLS layer, and TCP layer for identification ad fuses them with Tri-attention module. By comparing with state-of-the-art models, the results show that our TriViewNet outperforms in the recognition of Tor HS traffic. Yuwei Xu 0001, Yujie Hou, Xinxu Huang, Yali Yuan, Guang Cheng 0001 |
TrustCom | 5 |
| 2024 | Joint Optimization of QoE and Fairness for Adaptive Video Streaming in Heterogeneous Mobile EnvironmentsabstractThe rapid growth of mobile video traffic and user demand poses a more stringent requirement for efficient bandwidth allocation in mobile networks where multiple users may share a bottleneck link. This provides content providers an opportunity to jointly optimize multiple users’ experiences but users often suffer short connection durations and frequent handoffs because of their high mobility. In this paper, we propose an end-to-end scheme, VSiM, for supporting mobile video streaming applications in heterogeneous wireless networks. The key idea is allocating bottleneck bandwidth among multiple users based on their mobility profiles and Quality of Experience (QoE)-related knowledge to achieve max-min QoE fairness. Besides, the QoE of buffer-sensitive clients is further improved by the novel server push strategy based on HTTP/3 protocol without affecting the existing bandwidth allocation approach or sacrificing other clients’ view quality. VSiM is lightweight and easy to deploy in the real world without touching the underlying network infrastructure. We evaluated VSiM experimentally in both simulations and a lab testbed on top of the HTTP/3 protocol. We find that the clients’ QoE fairness of VSiM achieves more than 40% improvement compared with state-of-the-art solutions, i.e., the viewing quality of clients in VSiM can be improved from 720p to 1080p in resolution. Meanwhile, VSiM provides about 20% improvement of average QoE. Yali Yuan, Weijun Wang 0001, Sripriya Srikant Adhatarao, Bangbang Ren, Kai Zheng 0003, Xiaoming Fu 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2023 | Zoomer: A Website Fingerprinting Attack Against Tor Hidden Services
Yuwei Xu 0001, Kehui Song, Yali Yuan |
ICICS | 5 |
| 2023 | PrSLoc: Sybil attack detection for localization with private observers using differential privacy
Yachao Yuan, Yali Yuan |
Comput. Secur. | 3 |
| 2023 | ReplaceDGA: BiLSTM-Based Adversarial DGA With High Anti-Detection AbilityabstractBotnets extensively leverage Domain Generation Algorithms (DGAs) to establish reliable communication channels between bots and Command and Control (C&C) servers. Numerous character-level DGA classifiers have been extensively studied to detect and classify domain names generated by DGAs. Meanwhile, a series of adversarial domain generation algorithms have been proposed to evade DGA classifiers. Although the existing domain name generation algorithms have progressed against DGA classifier, their anti-detection abilities are still weak. This paper proposes a Bidirectional Long Short-Term Memory (BiLSTM) network-based adversarial DGA with high anti-detection ability, referred to as ReplaceDGA. ReplaceDGA requires no knowledge of the targeted DGA classifiers. It first builds a prediction model for benign domain names using the BiLSTM network to model the semantic relationship hidden within benign domain names and then replaces two characters of each input benign domain name based on the prediction model to maximize the similarity between the benign and generated domain names. Our experimental results validate that ReplaceDGA successfully evades various character-level DGA classifiers even after they are retrained by domain names generated by ReplaceDGA and outperforms the state-of-the-art adversarial DGAs in anti-detection ability, repetition rate, and collision rate. Our study of ReplaceDGA promotes the urgent need for developing more comprehensive and robust DGA classifiers that consider other factors besides character-level information of domain names. Xiaoyan Hu 0007, Guang Cheng 0001, Ruidong Li 0001, Hua Wu 0004, Yali Yuan |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2022 | VSiM: Improving QoE Fairness for Video Streaming in Mobile EnvironmentsabstractThe rapid growth of mobile video traffic and user demand poses a more stringent requirement for efficient bandwidth allocation in mobile networks where multiple users may share a bottleneck link. This provides content providers an opportunity to optimize multiple users’ experiences jointly, but users often suffer short connection durations and frequent handoffs because of their high mobility. This paper proposes an end-to-end scheme, VSiM, to support mobile video streaming applications in heterogeneous wireless networks. The key idea is allocating bottleneck bandwidth among multiple users based on their mobility profiles and Quality of Experience (QoE)-related knowledge to achieve max-min QoE fairness. Besides, the QoE of buffer-sensitive clients is further improved by the novel server push strategy based on HTTP/3 protocol without affecting the existing bandwidth allocation approach or sacrificing other clients’ view quality. We evaluated VSiM experimentally in both simulations and a lab testbed on top of the HTTP/3 protocol. We find that the clients’ QoE fairness of VSiM achieves more than 40% improvement compared with state-of-the-art solutions, i.e., the viewing quality of clients in VSiM can be improved from 720p to 1080p in resolution. Meanwhile, VSiM provides about 20% improvement on average of the averaged QoE. Yali Yuan, Weijun Wang 0001, Sripriya Srikant Adhatarao, Bangbang Ren, Kai Zheng 0003, Xiaoming Fu 0001 |
INFOCOM | 1 |
| 2022 | LbSP: Load-Balanced Secure and Private Autonomous Electric Vehicle Charging Framework With Online Price OptimizationabstractNowadays, autonomous electric vehicles (AEVs) are increasingly popular due to low resource consumption, low pollutant emission, and high efficiency. In practice, Vehicle-to-Grid (V2G) networks supply energy power to EVs to ensure the usage of EVs. However, there are still certain security and privacy concerns in V2G connections, such as identity impersonation and message manipulation. Additionally, the widespread usage of EVs brings significant pressure on the power grid, leading to undesirable effects like voltage deviations if EVs’ charging is not well coordinated. In this article, to tackle these issues, we design a novel load-balanced secure and private EV charging framework named load-balanced secure and private framework (LbSP) for secure, private, and efficient EV charging with a minimal negative effect on the existing power grid. It assures reliable and efficient charging services by a lightweighted encryption technique. Also, it balances the energy consumption of power grids via an online pricing strategy that minimizes load variance by optimizing energy prices in real time. Moreover, it preserves users’ privacy while not affecting online pricing using an advanced differential privacy technique. Furthermore, LbSP deploys on an edge-cloud structure for fast response and more precise pricing, where clouds balance overall load consumption by online price optimization while edges gather data for clouds and respond to charging requests from EVs. The evaluation results show that the proposed framework ensures secure and private EV charging, balances energy load consumption, and preserves users’ privacy. Yachao Yuan, Yali Yuan, Parisa Memarmoshrefi, Thar Baker, Dieter Hogrefe |
IEEE Internet Things J. | 2 |
| 2022 | Eurus: Towards an Efficient Searchable Symmetric Encryption With Size Pattern ProtectionabstractTo achieve efficiently search and update on outsourced encrypted data, dynamic searchable symmetric encryption (DSSE) was proposed by just leaking some well-defined leakages. Though small, many recent works show that an attacker can exploit these leakages to undermine the security of existing DSSE schemes. In particular, an attacker can exploit even seemingly harmless size pattern to perform severe attacks. Many exiting schemes resort to oblivious RAM (ORAM) to hide search/access pattern; however, even such powerful cryptographic primitive cannot protect size pattern leakage. In this article, we first show that size pattern can lead to more information leakages, which is not well studied or protected by existing schemes. We then extend the existing privacy notion for DSSE to capture the size pattern leakage, achieving a strong forward and backward privacy definition. Following the definition, we propose a new DSSE scheme Eurus. Eurus can eliminate search/access pattern by relying on a multi-server ORAM scheme, meanwhile reducing size pattern with reasonable efficiency. We show that Eurus can reduce leakage significantly with better efficiency, compared with state-of-the-art leakage reduction schemes. Zheli Liu, Yanyu Huang, Xiangfu Song, Bo Li 0062, Jin Li 0002, Yali Yuan, Changyu Dong |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | EncodeORE: Reducing Leakage and Preserving Practicality in Order-Revealing EncryptionabstractOrder-preserving encryption (OPE) is a cryptographic primitive that preserves the order of plaintexts. In the past few years, many OPE schemes were proposed to solve the problem of executing range queries in encrypted databases. However, OPE leaks some certain information (for example, the order of ciphertext), so it is vulnerable to many attacks. Subsequently, order-revealing encryption (ORE) was proposed by Bonehet al.(Eurocrypt 2015) as a generalization of order-preserving encryption. It breaks through the limitation of the numeric order of OPE plaintext. It implements ciphertext comparison for any specific form of plaintext through a publicly computable comparison function. In this article, we aim to design a new ORE scheme which reduces the leakages and preserves the practicality in terms of ciphertext length and encryption time. We first propose the hybrid model namedHybridORE. Then, we propose an improved scheme namedEncodeOREwhich achieves acceptable security and appropriate ciphertext length. They both explore the encode strategy of encoding plaintext into different parts and apply suitable ORE algorithms to each part according to its security characteristics to reduce leakages. Compared with the typical CLWW scheme (FSE 2016) and Lewi-Wu (CCS 2016) in large domain, they have fewer leakages. The experiment shows that the proposedEncodeOREis very practical. Zheli Liu, Siyi Lv, Jin Li 0002, Yanyu Huang, Liang Guo 0013, Yali Yuan, Changyu Dong |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | Adaptive Fuzzy Game-Based Energy-Efficient Localization in 3D Underwater Sensor NetworksabstractNumerous applications in 3D underwater sensor networks (UWSNs), such as pollution detection, disaster prevention, animal monitoring, navigation assistance, and submarines tracking, heavily rely on accurate localization techniques. However, due to the limited batteries of sensor nodes and the difficulty for energy harvesting in UWSNs, it is challenging to localize sensor nodes successfully within a short sensor node lifetime in an unspecified underwater environment. Therefore, we propose the Adaptive Energy-Efficient Localization Algorithm (Adaptive EELA) to enable energy-efficient node localization while adapting to the dynamic environment changes. Adaptive EELA takes a fuzzy game-theoretic approach, whereby the Stackelberg game is used to model the interactions among sensor and anchor nodes in UWSNs and employs the adaptive neuro-fuzzy method to set the appropriate utility functions. We prove that a socially optimal Stackelberg–Nash equilibrium is achieved in Adaptive EELA. Through extensive numerical simulations under various environmental scenarios, the evaluation results show that our proposed algorithm accomplishes a significant energy reduction, e.g., 66% lower compared to baselines, while achieving a desired performance level in terms of localization coverage, error, and delay. Yali Yuan, Chencheng Liang, Xu Chen 0004, Thar Baker, Xiaoming Fu 0001 |
ACM Trans. Internet Techn. | 1 |
| 2022 | Optimal Deployment of SRv6 to Enable Network Interconnection ServiceabstractMany organizations nowadays have multiple sites at different geographic locations. Typically, transmitting massive data among these sites relies on the interconnection service offered by ISPs. Segment Routing over IPv6 (SRv6) is a new simple and flexible source routing solution which could be leveraged to enhance interconnection services. Compared to traditional technologies, e.g., physical leased lines and MPLS-VPN, SRv6 can easily enable quick-launched interconnection services and significantly benefit from traffic engineering with SRv6-TE. To parse the SRv6 packet headers, however, hardware support and upgrade are needed for the conventional routers of ISP. In this paper, we study the problem of SRv6 incremental deployment to provide a more balanced interconnection service from a traffic engineering view. We formally formulate the problem as an SRID problem with integer programming. After transforming the SRID problem into a graph model, we propose two greedy methods considering short-term and long-term impacts with reinforcement learning, namely GSI and GLI. The experiment results using a public dataset demonstrate that both GSI and GLI can significantly reduce the maximum link utilization, where GLI achieves a saving of 59.1% against the default method. Bangbang Ren, Deke Guo, Yali Yuan, Guoming Tang, Weijun Wang 0001, Xiaoming Fu 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2021 | Cetus: an efficient symmetric searchable encryption against file-injection attack with SGX
Yanyu Huang, Siyi Lv, Zheli Liu, Xiangfu Song, Jin Li 0002, Yali Yuan, Changyu Dong |
Sci. China Inf. Sci. | 6 |
| 2021 | FedRD: Privacy-preserving adaptive Federated learning framework for intelligent hazardous Road Damage detection and warning
Yachao Yuan, Yali Yuan, Thar Baker, Lutz M. Kolbe, Dieter Hogrefe |
Future Gener. Comput. Syst. | 2 |
| 2021 | EcRD: Edge-Cloud Computing Framework for Smart Road Damage Detection and WarningabstractRoad damages have caused numerous fatalities, thus the study of road damage detection, especially hazardous road damage detection and warning is critical for traffic safety. Existing road damage detection systems mainly process data at cloud, which suffers from a high latency caused by long-distance. Meanwhile, supervised machine learning algorithms are usually used in these systems requiring large precisely labeled data sets to achieve a good performance. In this article, we propose EcRD: an edge-cloud-based road damage detection and warning framework, that leverages the fast-responding advantage of edge and the large storage and computation resources advantages of cloud. There are three main contributions in this article: we first propose a simple yet efficient road segmentation algorithm to enable fast and accurate road area detection. Then, a light-weighted road damage detector is developed based on gray level co-occurrence matrix features at edge for rapid hazardous road damage detection and warning. Furthermore, a multitypes road damage detection model is introduced for long-term road management at cloud, embedded with a novel image generator based on cycle-consistent adversarial networks which automatically generates images with labels to further improve road damage detection accuracy. By comparing with the state-of-the-art, we demonstrate that the proposed EcRD can accurately detect both hazardous road damages at edge and multitypes road damages at cloud. Besides, it is around 579 times faster than cloud-based approaches without affecting users' experience and requiring very low storage and labeling cost. Yachao Yuan, Md. Saiful Islam 0011, Yali Yuan, Shengjin Wang, Thar Baker, Lutz M. Kolbe |
IEEE Internet Things J. | 3 |
| 2020 | ADA: Adaptive Deep Log Anomaly DetectorabstractLarge private and government networks are often subjected to attacks like data extrusion and service disruption. Existing anomaly detection systems use offline supervised learning and employ experts for labeling. Hence they cannot detect anomalies in real-time. Even though unsupervised algorithms are increasingly used nowadays, they cannot readily adapt to newer threats. Moreover, many such systems also suffer from high cost of storage and require extensive computational resources. In this paper, we propose ADA: Adaptive Deep Log Anomaly Detector, an unsupervised online deep neural network framework that leverages LSTM networks and regularly adapts to newer log patterns to ensure accurate anomaly detection. In ADA, an adaptive model selection strategy is designed to choose pareto-optimal configurations and thereby utilize resources efficiently. Further, a dynamic threshold algorithm is proposed to dictate the optimal threshold based on recently detected events to improve the detection accuracy. We also use the predictions to guide storage of abnormal data and effectively reduce the overall storage cost. We compare ADA with state-of-the-art approaches through leveraging the Los Alamos National Laboratory cyber security dataset and show that ADA accurately detects anomalies with high F1-score ~95% and it is 97 times faster than existing approaches and incurs very low storage cost. Yali Yuan, Sripriya Srikant Adhatarao, Mingkai Lin, Yachao Yuan, Zheli Liu, Xiaoming Fu 0001 |
INFOCOM | 1 |
| 2017 | Two Layers Multi-class Detection method for network Intrusion Detection SystemabstractIntrusion Detection Systems (IDSs) are powerful systems which monitor and analyze events in order to detect signs of security problems and take action to stop intrusions. In this paper, the Two Layers Multi-class Detection (TLMD) method used together with the C5.0 method and the Naive Bayes algorithm is proposed for adaptive network intrusion detection, which improves the detection rate as well as the false alarm rate. The proposed TLMD algorithm also addresses some difficulties in data mining situations such as handling imbalance datasets, dealing with continuous attributes, and reducing noise in training dataset. We compared the performance of the proposed TLMD method with that of existing algorithms, using the detection rate, accuracy as well as false alarm rate on the KDDcup99 benchmark intrusion detection dataset. The experimental results prove that the proposed TLMD method has a reduced false alarm rate and a good detection rate based on the imbalanced dataset. Yali Yuan, Liuwei Huo, Dieter Hogrefe |
ISCC | 1 |
| 2016 | Tri-MCL: Synergistic Localization for Mobile Ad-Hoc and Wireless Sensor NetworksabstractLocalization is a highly important topic in wireless sensor networks as well as in many Internet of Things applications. Many current localization algorithms are based on the Sequential Monte Carlo Localization method (MCL), the accuracy of which is bounded by the radio range. High computational complexity in the sampling step is another issue of these approaches. We present Tri-MCL which significantly improves on the accuracy of the Monte Carlo Localization algorithm. To do this, we leverage three different distance measurement algorithms based on range-free approaches. Using these, we estimate the distances between unknown nodes and anchor nodes to perform more fine-grained filtering of the particles as well as for weighting the particles in the final estimation step of the algorithm. Simulation results illustrate that the proposed algorithm achieves better accuracy than the MCL and SA-MCL algorithms. Furthermore, it also exhibits high efficiency in the sampling step. Arne Bochem, Yali Yuan, Dieter Hogrefe |
LCN | 2 |
| 2016 | A Novel Semi-Supervised Adaboost Technique for Network Anomaly DetectionabstractWith the developing of Internet, network intrusion has become more and more common. Quickly identifying and preventing network attacks is getting increasingly more important and difficult. Machine learning techniques have already proven to be robust methods in detecting malicious activities and network threats. Ensemble-based and semi-supervised learning methods are some of the areas that receive most attention in machine learning today. However relatively little attention has been given in combining these methods. To overcome such limitations, this paper proposes a novel network anomaly detection method by using a combination of a tri-training approach with Adaboost algorithms. The bootstrap samples of tri-training are replaced by three different Adaboost algorithms to create the diversity. We run 30 iteration for every simulation to obtain the average results. Simulations indicate that our proposed semi-supervised Adaboost algorithm is reproducible and consistent over a different number of runs. It outperforms other state-of-the-art learning algorithms, even with a small part of labeled data in the training phase. Specifically, it has a very short execution time and a good balance between the detection rate as well as the false-alarm rate. Yali Yuan, Georgios Kaklamanos, Dieter Hogrefe |
MSWiM | 1 |