EDBT 2026 Demo / reviewers in the wild / expert
ZengRi Zeng
dblp:193/9455
· DBLP profile ↗
13ranked-venue papers
10as first author
12since 2021 · last 2025
0000-0002-5329-0713ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 7 first-author · 8 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Causal Disentanglement for Stability in IoV Network Anomaly Detection
ZengRi Zeng, Aimei Kang, Yunlian Liu, Zhihong Zeng |
ICIC (18) | 1 |
| 2025 | Causal Gray Wolf Optimization: A Novel Approach to Robust Network Anomaly Detection Amidst Data RedundancyabstractThe rapid proliferation of IoT technologies intensifies network anomaly detection challenges because of high-dimensional and redundant data. To address this issue, we propose causal gray wolf optimization (CGWO), a framework that integrates the global search capabilities of gray wolf optimization (GWO) with causal inference to distinguish causal features from spurious correlations. CGWO employs a four-stage process: (1) data preprocessing with causal weight transformation, (2) causal analysis via potential outcome models (POMs), (3) feature subset optimization using a fitness function balancing accuracy and dimensionality, and (4) anomaly detection with an enhanced convolutional autoencoder (ECAE). By prioritizing causal relationships over statistical correlations, CGWO minimizes redundant features while increasing model interpretability. When evaluated with benchmark datasets (NSL-KDD and UNSW-NB15), CGWO achieves 99.8% accuracy (14 features) for 5-class classification with NSL-KDD and 94.2% accuracy (10 features) for 10-class classification with UNSW-NB15, outperforming conventional methods by more than 6%. The framework reduces feature dimensions by 65–80% without performance loss, demonstrating robustness, computational efficiency (120–150 s per dataset), and scalability for edge computing. These results validate the effectiveness of CGWO in balancing dimensionality reduction and interpretable model design for complex network environments. ZengRi Zeng, Xiaoheng Deng, Baokang Zhao |
IEEE Internet Things J. | 1 |
| 2025 | Toward Intelligent Attack Detection With Causal Transformer in Internet of ThingsabstractIt is difficult for existing Internet of Things (IoT) intrusion detection systems to simultaneously identify and classify network anomalies, especially when the classification of unknown attacks is required, which brings great risks to the use of IoT devices. This article applies transformers to decouple false associations by causal reasoning to obtain an intelligent interpretable IoT detection system that can classify known attacks and identify unknown attacks. To achieve these goals, a causal transformer-based intelligent detection system for IoT devices is proposed. The system is divided into three main modules. First, training is conducted based on known traffic types with prior knowledge, and then the detection samples containing unknown attack types are classified into known traffic types. Second, the causal feature distribution of known traffic types is learned based on causal attention, and the causal feature distribution differences between normal and abnormal traffic samples are amplified with the minimax strategy to distinguish their types. Then, all traffic samples different from the known types are integrated into unknown types for causal transformer classification until there is only one type. Validation is performed on three broad and representative IoT datasets, and the results show that the causal transformer detection system can not only correctly classify known attacks but also achieve a 100% success rate in identifying cyberattacks on IoT datasets. In addition, more than 99% of unknown attack types can be effectively identified and classified, providing timely and effective guidance for cybersecurity defense. ZengRi Zeng, Baokang Zhao, Xiaoheng Deng, Xuhui Liu, Jie Chen 0063 |
IEEE Internet Things J. | 1 |
| 2025 | Causal Interpretability Methods for IoT Anomaly Traffic DetectionabstractWith the continuous development of Internet of Things (IoT) technology, an increasing number of devices are connected to the internet, generating large amounts of highdimensional redundant information. Moreover, significant environmental and device heterogeneity leads to nonindependent and identically distributed (N-IID) samples. These challenges compromise the stability and causal interpretability of existing IoT detection methods, limiting their effectiveness in providing actionable insights for network security defense. To address these limitations, we propose a causal interpretabilitydriven IoT abnormal traffic detection approach. Central to this method is the adoption of structural causal models (SCMs), which are chosen for their ability to explicitly model direct causal linkages, suppress confounding effects, ensure robust cross-deployment detection, and enable counterfactual reasoning for precise attack attribution. The approach first eliminates spurious feature associations via Fourier transformation, then constructs and prunes SCMs using causal effect analysis, KNN, and counterfactual diagnosis to restore genuine causal relationships between anomalies and traffic features. Experiments on CI-CIDS2019, ToNIoT, and NSL-KDD datasets demonstrate effective noise reduction, redundancy elimination, and causal relationship recovery. Notably, detection accuracy improves by >19% on NSL-KDD data under polluted conditions, while maintaining stability and providing clear causal explanations for IoT network anomalies. ZengRi Zeng, Baokang Zhao, Xuhui Liu, Xiaoheng Deng |
IEEE Internet Things J. | 1 |
| 2024 | Toward Intelligent Attack Detection with a Causal Explainable Method for Encrypting TrafficabstractTo address the cybersecurity problems caused by encrypted traffic, current attack detection systems (ADSs) focus on non-decryption-based detection. However, non-decryption systems face problems including large training sample imbalances, which seriously affect ADS performance. To address these problems, we propose a structural causal model (SCM) for cyberattacks and define detection tasks such as eliminating noise features and providing interpretability. First, the influence of causal features on the results is enhanced by weighting the causal features, and low-weight noise features are removed to improve the causal interpretability of the detection results. Furthermore, samples are generated through a Wasserstein generative adversarial network (WGAN) that learns the causal feature distribution to balance the training samples. Finally, the detection performance is evaluated through the F1 score and interpretability indices. Our method achieves F1 score improvements on all datasets, and the causal relationships between cyberattacks and feature anomalies are explained through causal effects. ZengRi Zeng, Wei Peng 0005, Baokang Zhao |
ICC | 1 |
| 2024 | Toward Unknown/Known Cyberattack Detection with a Causal Transformer
Aimei Kang, ZengRi Zeng, Jiayi Peng, Wenjian Luo, Genghui Li |
ICIC (2) | 3 |
| 2024 | Improving the Stability of Networks Anomaly Detection in Internet of ThingsabstractNetworks Anomaly Detection is very critical to ensure the security in IoT. However, the noise in training and detection samples varies due to differences in scenarios and devices, and this different noise information corresponds to distinct false correlation relationships. This leads to a lack of stability in existing detection models based on correlation reasoning. To address these issues, in this paper, we propose a novel causal diffusion approach to detect anomalies in IoT. The model first generates independent features by adding noise to remove false correlations and subsequently addresses the problems of Not Independent and Identically Distributed (N-IID) sample distributions by calculating the causal effect relationships between the labels and features to remove noise. Finally, through the validation of one broad and representative network intrusion detection dataset, the experimental results show that method can achieve a maximum detection rate of >99% in the actual different network environments in CICIDS2019. Baokang Zhao, ZengRi Zeng, Xiaoheng Deng |
MSN | 2 |
| 2024 | Toward identifying malicious encrypted traffic with a causality detection system
ZengRi Zeng, Peng Xun, Wei Peng 0005, Baokang Zhao |
J. Inf. Secur. Appl. | 1 |
| 2024 | Causal Genetic Network Anomaly Detection Method for Imbalanced Data and Information RedundancyabstractThe proliferation of Internet-connected devices and the complexity of modern network environments have led to the collection of massive and high-dimensional datasets, resulting in substantial information redundancy and sample imbalance issues. These challenges not only hinder the computational efficiency and generalizability of anomaly detection systems but also compromise their ability to detect rare attack types, posing significant security threats. To address these pressing issues, we propose a novel causal genetic network-based anomaly detection method, the CNSGA, which integrates causal inference and the nondominated sorting genetic algorithm-III (NSGA-III). The CNSGA leverages causal reasoning to exclude irrelevant information, focusing solely on the features that are causally related to the outcome labels. Simultaneously, NSGA-III iteratively eliminates redundant information and prioritizes minority samples, thereby enhancing detection performance. To quantitatively assess the improvements achieved, we introduce two indices: a detection balance index and an optimal feature subset index. These indices, along with the causal effect weights, serve as fitness metrics for iterative optimization. The optimized individuals are then selected for subsequent population generation on the basis of nondominated reference point ordering. The experimental results obtained with four real-world network attack datasets demonstrate that the CNSGA significantly outperforms existing methods in terms of overall precision, the imbalance index, and the optimal feature subset index, with maximum increases exceeding 10%, 0.5, and 50%, respectively. Notably, for the CICDDoS2019 dataset, the CNSGA requires only 16-dimensional features to effectively detect more than 70% of all sample types, including 6 more network attack sample types than the other methods detect. The significance and impact of this work encompass the ability to eliminate redundant information, increase detection rates, balance attack detection systems, and ensure stability and generalizability. The proposed CNSGA framework represents a significant step forward in developing efficient and accurate anomaly detection systems capable of defending against a wide range of cyber threats in complex network environments. ZengRi Zeng, Xuhui Liu, Xiaoheng Deng, Detian Zeng, Jie Chen 0063 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Towards Intelligent Attack Detection Using DNA ComputingabstractIn recent years, frequent network attacks have seriously threatened the interests and security of humankind. To address this threat, many detection methods have been studied, some of which have achieved good results. However, with the development of network interconnection technology, massive amounts of network data have been produced, and considerable redundant information has been generated. At the same time, the frequently changing types of cyberattacks result in great difficulty collecting samples, resulting in a serious imbalance in the sample size of each attack type in the dataset. These two problems seriously reduce the robustness of existing detection methods, and existing research methods do not provide a good solution. To address these two problems, we define an unbalanced index and an optimal feature index to directly reflect the performance of a detection method in terms of overall accuracy, feature subset optimization, and detection balance. Inspired by DNA computing, we propose intelligent attack detection based on DNA computing (ADDC). First, we design a set of regular encoding and decoding features based on DNA sequences and obtain a better subset of features through biochemical reactions. Second, nondominated ranking based on reference points is used to select individuals to form a new population to optimize the detection balance. Finally, a large number of experiments are carried out on four datasets to reflect real-world cyberattack situations. Experimental results show that compared with the most recent detection methods, our method can improve the overall accuracy of multiclass classification by up to 10%; the imbalance index decreased by 0.5, and 1.5 more attack types were detected on average; and the optimal index of the feature subset increased by 83.8%. ZengRi Zeng, Baokang Zhao, Han-Chieh Chao, Ilsun You, Kuo-Hui Yeh, Weizhi Meng 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2022 | Intrusion detection framework based on causal reasoning for DDoS
ZengRi Zeng, Wei Peng 0005, Detian Zeng, Chong Zeng 0002 |
J. Inf. Secur. Appl. | 1 |
| 2022 | Improving the Stability of Intrusion Detection With Causal Deep LearningabstractDue to factors such as differing distributions of training data and test data, false associations between features and weight associations lead to unstable detection performance and lack of generalization of network intrusion detection systems (NIDSs) based on machine learning (ML). To improve the stability and generalization of NIDSs, a detection system based on causal deep learning is proposed in this paper. First, causal weights were optimized by the propensity score through causal effects, the correlation between causal features and attack labels was increased, and the correlation between false correlation variables was weakened to improve the stability performance. Second, the approximate numerical optimization method of the Tammes problem was used to remove correlations between weights, maintain the independence of causal features, and improve the generalization of the detection system. Last, the feature distribution was disrupted by adding noise to four datasets to simulate different network environments. The results showed that our system can achieve good stability in various network environments where the training and testing datasets are not independently and identically distributed. In particular, after applying binary coding features and causal intervention (CIT) screening features, the average stability of the system improved by more than 10%. ZengRi Zeng, Wei Peng 0005, Detian Zeng |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2017 | An energy efficient hole repair node scheduling algorithm for WSN
ZengRi Zeng, Ou Ding |
Wirel. Networks | 2 |