EDBT 2026 Demo / reviewers in the wild / expert
Zan Zhou 0001
dblp:203/3329
· DBLP profile ↗
25ranked-venue papers
7as first author
17since 2021 · last 2026
0000-0003-2388-2280ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 5 first-author · 10 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dynamic Differential Strategy-Based Multi-proxy MTD for Low-Rate DDoS Attack Detection
Penghui Xiao, Lin Yan 0006, Zan Zhou 0001, Changqiao Xu |
ICC | 5 |
| 2026 | Multi-Tiered Shuffling with User Stratification for QoS-Stable DDoS Defense in Online Services
Yongfeng Yu, Lin Yan 0006, Zan Zhou 0001, Changqiao Xu |
ICC | 5 |
| 2025 | KeBugFix: Automated Program Repair Framework Based on Code Retrieval Enhancement and LLM Agent
Chaopeng Wang, Yi Sun 0006, Chao Wang 0061, Zan Zhou 0001, Yujiao Yuan, Xu Xiang, Fei Xiao 0005 |
IEEE Big Data | 6 |
| 2025 | RecZTA: A Reputation-Based Architecture with Dual-Layer PEPs for Zero Trust AccessabstractTraditional bounded-based security models are difficult to cope with the challenges brought by dynamic cloud, microservices, and remote working environments. Although Zero Trust Architecture (ZTA) emphasizes "never trust, always verify", existing Policy Enforcement Point (PEP) deployments usually lack defense in depth and real-time health status assessment. To overcome these shortcomings, we propose RecZTA, a reputation-driven dual-layer PEP architecture under a unified control plane. The first layer is the service proxy, which is responsible for filtering and forwarding the initial traffic. The second layer is the resource access gateway, which is responsible for secondary security verification and service access authorization. RecZTA uses a multi-dimensional reputation model to realize real-time monitoring of service agents and rapid intrusion perception. Simulation results show that RecZTA can detect agent intrusion earlier than the existing zero trust models (device gateway model, resource portal model and enclave model), while maintaining low latency and low resource consumption, which verifies the feasibility and robustness of RecZTA in complex environments. Lin Yan 0006, Zan Zhou 0001, Yongfeng Yu, Penghui Xiao |
TrustCom | 3 |
| 2025 | PLAA: Packet-level Adversarial Attacks in Network Traffic DetectionabstractDeep neural networks (DNNs) are widely applied in Network-based Intrusion Detection System (NIDS) due to their high accuracy. However, DNNs are highly susceptible to adversarial attacks, which generate malicious traffic to evade NIDS detection. Existing approaches often adapt adversarial attacks from computer vision (CV) tasks to the NIDS domain, overlooking the fundamental differences between CV and NIDS. This results in two major issues: 1) The generated network traffic may become invalid, 2) The generated traffic may lose its original attack semantics. To address these issues, this paper proposes an adversarial attack specifically designed for NIDS. Instead of directly generating flow-level features, our approach incrementally generates packet-level features to construct adversarial traffic. During the generation process, the semantic integrity of the traffic is monitored at each stage, effectively avoiding the issues of invalid traffic and semantic loss observed in existing methods. We evaluate our attack algorithm against current NIDS models using the CIC-UNSW-NB15, CIC-DDoS2019, and CIC-IDS-2017 datasets. The proposed method achieves an average evasion success rate of 92.78%, while ensuring that the generated adversarial traffic remains semantically consistent with the original malicious traffic. Jinhao You, Zan Zhou 0001, Yi Sun 0006, Lei Zhang 0157, Changqiao Xu |
TrustCom | 2 |
| 2025 | A Fairness-aware Incentive Framework for Heterogeneous Federated Learning with Bifurcated Reverse Auction DesignabstractFederated Learning (FL) is an emerging distributed learning framework designed to address isolated data island and protect privacy. Besides, Clustered Federated Learning (CFL) is introduced as an efficient multitask scheme to solve heterogeneous problems in FL where clients' data is distributed in non-i.i.d. (non-independent and identically distributed) scenarios. However, due to bandwidth limitation and latency tolerance, the server can only select a subset of clients to participate. Average selection and only selecting low heterogeneous client groups lead to severe results. How to fairly select clients and improve efficient model performance in heterogeneous scenarios with limited communication has become a key issue. We propose a fairness-aware clustered federated learning (FACFL) incentive framework which balances collective and individual fairness. Specifically, our framework models CFL as a bifurcated reverse auction that consists of a first-layer cluster auction and a second-layer client auction. Our framework can dynamically adjust the par-ticipation of clusters and clients according to the communication capabilities. The experimental results on the CIFAR-10 dataset demonstrate that FACFL improves the model performance in severely heterogeneous and communication limited scenarios. Additionally, FACFL can maintain a high level of the training fairness with different numbers of clients. Sizhe Huang, Zan Zhou 0001, Xiping Li, Yi Sun 0006, Changqiao Xu |
WCNC | 3 |
| 2025 | Automatic Toxicity Evaluation for Human-LLM Conversations in Flexible Manufacturing System With Duplex Fine-Tuned LLMsabstractFlexible manufacturing systems (FMS), empowered by the Industrial Internet of Things (IIoT), have become a cornerstone of Industry 6.0 by enabling dynamic production adaptation, real-time equipment monitoring, and intelligent scheduling. As these systems increasingly incorporate large language models (LLMs) to support functions such as knowledge querying, decision assistance, and predictive maintenance, ensuring the safety and reliability of human-LLM conversations has become a pressing concern. Specifically, LLMs may generate toxic, biased, or privacy-violating outputs when interacting with sensitive IIoT data and production logic, potentially compromising operational safety. To address this challenge, we propose AugLLMSen, an automated toxicity evaluation framework tailored to the IIoT-driven FMS context. AugLLMSen integrates a question automatic expansion mechanism (Q-Judge) and an output toxicity evaluation model (O-Judge) into a closed-loop pipeline, enabling large-scale assessment of LLM safety across diverse industrial scenarios. Experimental results on open- and closed-source LLMs demonstrate the effectiveness and accuracy of our approach in identifying toxic responses and guiding safe deployment of LLMs in flexible manufacturing environments. Chao Wang 0061, Zan Zhou 0001, Yi Sun 0006, Yuning Cui 0002, Yasser D. Al-Otaibi, Ali Kashif Bashir, Changqiao Xu |
IEEE Internet Things J. | 3 |
| 2025 | SecFFT: Safeguarding Federated Fine-Tuning for Large Vision Language Models Against Covert Backdoor Attacks in IoRT NetworksabstractAs the large vision language models (LVLMs) and embodied intelligent robotic networks continue to advance at a remarkable pace, particularly in applications spanning smart cities, power grids, factories, and transportation, visual perception and understanding have emerged as foundational elements to overcoming performance limitations in such intelligent systems. However, since general pretrained models are not well-suited to specific tasks, federated fine-tuning (FFT) has gained attention as a promising technique for enhancing the performance of vision-based perception models by leveraging data and computational power distributed across nodes. The rise of advanced persistent threats has revealed significant vulnerabilities in existing defense mechanisms, which struggle to mitigate sophisticated backdoor attacks toward FFT for LVLMs. To address these challenges, this article proposes the SecFFT method, which tackles both the stealthiness and complexity of backdoor strategies. The approach incorporates instantaneous attack behavior detection based on frequency-domain distribution consistency and introduces a long-term secure aggregation mechanism aimed at identifying hidden attack intentions. These strategies effectively limit the feasibility of adversaries attempting to bypass defense measures by concealing their behaviors. Experiments conducted on public datasets demonstrate that SecFFT significantly improves defense success rates, model performance, and detection accuracy, particularly in response to highly covert, multiround backdoor attacks. Zan Zhou 0001, Changqiao Xu, Sizhe Huang, Su Yao |
IEEE Internet Things J. | 1 |
| 2025 | Community-Oriented Duplex Privacy Amplification and Active Poisoning Resistance for Heterogeneous Federated LearningabstractPrivacy protection and poisoning resilience are important concerns for federated learning (FL). During a relatively long period, the corresponding solutions are regarded as orthogonal and investigated separately. Unfortunately, due to the increasingly complex structure and ever-growing parameter dimensions of the models to be trained, the forthright coupling of existing differential privacy and Byzantine resilience techniques has been proved incompatible with FL. This emerging problem prompts us to give serious thought to jointly guaranteeing data privacy and model integrity. Besides, worse still, the multi-task characteristic and data imbalance of heterogeneous FL inevitably introduce huge variances, which make privacy-preserving under acceptable accuracy loss even more complicated, not to mention efficient and agile poisoning resistance. Against this bothersome situation, we propose a community-oriented secure heterogeneous FL (CoS-HFL) framework to provide guaranteed privacy protection and significant model robustness simultaneously. CoS-HFL includes two parts: community-oriented duplex privacy amplification and credit-based poisoning resistance. The former copes with potential leakage threats with both uplink and downlink obfuscations. The latter further actively thwarts poisoning attacks based on credibility evaluation. Furthermore, we conduct experiments on benchmark datasets to highlight the performance of CoS-HFL in terms of privacy amplification, poisoning resistance, and learning accuracy under adversarial and heterogeneous environments. Zan Zhou 0001, Jun Zhao 0007, Hongjing Li, Tengchao Ma, Changqiao Xu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Device-Cloud Collaborative DDoS Resistance for QoS-Sensitive Mobile Applications: A Seamlessly Shuffle-based Moving Target Defense ApproachabstractDDoS attacks pose a fundamental security consideration for any application. With the rapid development of technology, highly QoS-sensitive and rich interaction mobile applications have occupied a great portion of current network traffic. However, owing to their inherent compatibility defects, current shuffle-based solutions fail to accommodate the urgent needs of QoS-sensitive applications, as the defenders require either nonnegligible service interruption or obligatory system modification. Therefore, we propose a feasible DDoS defense solution called RINP, which can be seamlessly integrated with existing applications through its innovative overlay-based wrap mechanism and isolated sidecar implementation. What’s more, we mathematically analyse the communication efficiency and false positive rate of RINP, which provides theoretical foundation for further adaptive defense strategy generation. Last but not least, to demonstrate the superiority of the RINP demo, we conduct a series of experiments in real-world WAN scenarios. The experimental results with Iperf3 (both TCP/UDP modes) show that our compatible defense solution can jointly provide great service continuity and maintain high-quality QoS. To the best of our knowledge, this is the first user-imperceptible and nonintrusive device-cloud collaborative defense solution for QoS-sensitive mobile applications. The source code can be found at https://github.com/bupt-narc/rinp. Lin Yan 0006, Zan Zhou 0001, Changqiao Xu |
GLOBECOM | 2 |
| 2024 | Deterrence of Adversarial Perturbations: Moving Target Defense for Automatic Modulation Classification in Wireless Communication SystemsabstractAutomatic modulation classification (AMC) plays an indispensable role in wireless communication systems. Deep learning-based AMC has become the mainstream solution due to its high accuracy and no need for manual feature engineering. However, every coin has two sides. DL-based AMC is susceptible to adversarial perturbations, which are carefully crafted to be superimposed on the transmitted signals in an iteratively try-and-error manner, resulting in incorrect classification. In this paper, we propose a model diversity-based moving target defense mechanism (MD-MTD), which employs multiple classifiers and switches periodically, preventing intelligent attackers from deducing universal adversarial perturbations (UAP). Besides, to jointly optimize the robustness and accuracy of different AMC models to be trained, we design a novel multi-agent reinforcement learning (MARL) module. It is worth mentioning that the proposed algorithm significantly mitigates the curse of dimensionality during the large-scale training process via integrating value-decomposition networks and illegal action masking, improving the feasibility of our solution in real-world wireless communication systems. Experimental results on the GNU radio dataset also exhibit the remarkable advantages of our method in terms of convergence and defense performance. Wei Dong 0007, Zan Zhou 0001, Xiping Li, Zhenhui Yuan, Changqiao Xu |
ICC | 2 |
| 2024 | EclipseFortify: Imperceptible Shuffle-Based Moving Target Defense for Budget-Friendly Web Service DDoS ProtectionabstractDistributed Denial of Service (DDoS) attacks continue to pose a significant threat to web services, making effective defense strategies crucial. However, traditional DDoS protection solutions are often expensive and may not be feasible for all organizations. To address this challenge, this paper presents EclipseFortify, a novel approach that combines the principles of Moving Target Defense (MTD) with cost-effective measures. EclipseFortify leverages the concept of reverse proxies as moving targets, employing proactive shuffling techniques to dynamically allocate valid proxies to users. By disrupting the correlation between users and reverse proxies, EclipseFortify effectively rejects attack traffic, significantly reducing the cost of defense. Furthermore, the method introduces a dynamically updated suspicious rating system to counter advanced attackers who adapt their strategies. To ensure uninterrupted service, EclipseFortify embeds scripts in reverse proxy forwarding, establishing a control link with user-side browsers. This enables seamless switching of reverse proxies without affecting users’ browsing experience. Experimental evaluations demonstrate the effectiveness of EclipseFortify in mitigating DDoS attacks while remaining imperceptible to legitimate users. A demo of EclipseFortify is available at https://hub.docker.com/r/frogsoftware/eclipse-fortify. Lin Yan 0006, Zan Zhou 0001, Changqiao Xu |
ICWS | 2 |
| 2024 | ClusterX: Adaptive Collaborative Scheduling of Layered User-Proxy Mapping to Enhance DDoS Defense in Distributed ClustersabstractIn the contemporary digital landscape, Distributed Denial of Service (DDoS) attacks pose a significant threat to the availability and integrity of online services. As cloud services and network infrastructures increasingly adopt distributed architectures, the challenge of defending against these attacks has become more complex. This paper introduces ClusterX, a novel two-tiered scheduling framework designed to enhance DDoS defense and service quality in distributed clusters. ClusterX incorporates Moving Target Defense (MTD) principles with a hierarchical, collaborative approach, featuring Program Chairs and Area Chairs that dynamically manage user-proxy mappings to counteract the fluid nature of DDoS attacks. The architecture of ClusterX is underpinned by a proactive transfer mechanism, which leverages user-service activity profiles to intelligently redistribute user traffic across clusters. This mechanism ensures that no single cluster becomes a bottleneck, maintaining low latency and high service quality even under high traffic conditions. Program Chairs oversee the global traffic distribution, while Area Chairs execute localized scheduling decisions, working in tandem to prevent traffic congestion and enhance the resilience of the network. Through extensive simulations and real-world experiments, we demonstrate the effectiveness of ClusterX in detecting and mitigating DDoS attacks, while maintaining high service availability. The results highlight the superiority of our approach in adapting to the dynamic nature of modern cyber threats and the benefits of a coordinated defense strategy in distributed cloud environments. ClusterX represents a significant advancement in the field of network security, offering a robust and adaptive solution to one of the most pressing challenges in cybersecurity today. Jianbo Lin, Lin Yan 0006, Zan Zhou 0001 |
TrustCom | 4 |
| 2024 | MR-FFL: A Stratified Community-Based Mutual Reliability Framework for Fairness-Aware Federated Learning in Heterogeneous UAV NetworksabstractFairness-aware federated learning (FFL) plays a crucial role in mitigating bias against specific demographic groups (e.g., gender, race, occupation) during collaborative training. Along with the ever-emerging new attack paradigms like gradient leakage and model poisoning, the reliability of FFL also obtains lots of research attention. Either UAV nodes or FFL aggregators could be untrusted adversaries. Although multiple security mechanisms involving encryption, obfuscation, Byzantine-robustness, and detection have been proposed, concrete to UAV networks, the majority of existing solutions are unfeasible due to high heterogeneity and limited resources among participants. Hence, in this paper, we propose mutually reliable FFL (MR-FFL), a stratified community-based framework to facilitate privacy protection (FFL aggregator’s reliability) and poisoning elimination (client nodes’ reliability) jointly for FFL in heterogeneous UAV networks. We first divide UAV nodes into both peer communities (PC) and colleague communities (CC) according to cross-participant similarity and task-oriented fitness, respectively. Thus, the arbitrarily settled learning tasks following fair principles can be efficiently completed by fine-tuned colleague communities, even in the presence of a large degree of heterogeneity among peer communities. Then, we integrate community-specific differential privacy into the MR-FFL process, to achieve privacy amplification as well as efficient and personal collaborative training at the same time. More importantly, we proposed a community-based credit evaluation to resist poisoning attacks in heterogeneous environments. The results on several standard datasets also highlight the performance of MR-Fed in terms of fairness, accuracy, and integrity jointly. Zan Zhou 0001, Yirong Zhuang, Hongjing Li, Sizhe Huang, Lujie Zhong, Zhenhui Yuan, Changqiao Xu |
IEEE Internet Things J. | 1 |
| 2023 | A Multi-Shuffler Framework to Establish Mutual Confidence for Secure Federated LearningabstractAlbeit the popularity of federated learning (FL), recently emerging model-inversion and poisoning attacks arouse extensive concerns towards privacy or model integrity, which catalyzes the developments of secure federated learning (SFL) methods. Nonetheless, the collisions between its privacy and integrity, two equally crucial elements in collaborative learning scenarios, are relatively underexplored. Individuals’ wish to “hide in the crowd” for privacy frequently clashes with aggregators’ need to resist abnormal participants for integrity (i.e., the incompatibility between Byzantine robustness and differential privacy). The dilemma prompts researchers to reflect on how to build mutual confidence between individuals and aggregators. Against the backdrop, this paper proposes a multi-shuffler secure federated learning (MSFL) framework, based on which we further propound three modules (hierarchical shuffling mechanism, malice evaluation module, and composite defense strategy) to jointly guarantee strong privacy protection, efficient poisoning resistance, and agile adversary elimination. Extensive experiments on standard datasets exhibited the method's effectiveness in thwarting different FL poisoning attack paradigms with a minimal cost of privacy breaches. Zan Zhou 0001, Changqiao Xu, Ming-Ze Wang, Xiaohui Kuang, Yirong Zhuang, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Augmented Dual-Shuffle-based Moving Target Defense to Ensure CIA-triad in Federated LearningabstractIn today's “Internet of Everything (IoE)” era, the collaboration from massive participants significantly boosts the performance and efficiency of model training. This trend also un-avoidably stirs up considerable concerns about multi-dimensional security problems. Under the circumstances, federated learning (FL) is enthusiastically adopted, as it protects privacy to a certain extent by only processing personal data locally. Nevertheless, FL's characteristics of concealment also pave the way for sev-eral emerging attacks during the training process, i.e., model inversion, poisoning, and backdoor. Currently, although partially mitigating attack effects, existing countermeasures against those threats are studied separately and orthogonal. This separation makes those defense methods mutually exclusive and restrictive in real-world application scenarios, far from satisfying. In this paper, we extensively model different attack paradigms into three types based on CIA-triad, the well-known information security primitive, and propose a novel dual-shuffle method to thwart aforementioned threats jointly. Concretely speaking, our primary model shuffling mechanism provides the confidentiality guarantee based on the information-theoretic notion of identifiability; then, an augmented client shuffling mechanism purges the user group of adversaries proactively without any compromise of anonymous constraints. By conducting a series of experiments on bench-mark datasets, we demonstrate that our method could achieve significant security and convergence performance against three state-of-the-art attacks. Zan Zhou 0001, Changqiao Xu, Ming-Ze Wang, Tengchao Ma, Shui Yu 0001 |
GLOBECOM | 1 |
| 2021 | Context-Aware Adaptive Route Mutation Scheme: A Reinforcement Learning ApproachabstractMoving target defense (MTD) is an emerging proactive defense technology, which can reduce the risk of vulnerabilities exploited by attacker. As a crucial component of MTD, route mutation (RM) faces a few fundamental problems defending against sophisticated Distributed-Denial of Service (DDoS) attacks: 1) it is unable to make optimal mutation selection due to insufficient learning in attack behaviors and 2) because network situation is time varying, RM also lacks self-adaptation in mutation parameters. In this article, we propose a context-aware Q-learning algorithm for RM (CQ-RM) that can learn attack strategies to optimize the selection of mutated routes. We first integrate four representative attack strategies into a unified mathematical model and formalize multiple network constraints. Then, taking above network constraints into considerations, we model RM process as a Markov decision process (MDP). To look for the optimal policy of MDP, we develop a context estimation mechanism and further propose the CQ-RM scheme, which can adjust learning rate and mutation period adaptively. Correspondingly, the optimal convergence of CQ-RM is proved theoretically. Finally, extensive experimental results highlight the effectiveness of our method compared to representative solutions. Changqiao Xu, Tao Zhang 0063, Xiaohui Kuang, Zan Zhou 0001, Shui Yu 0001 |
IEEE Internet Things J. | 4 |
| 2020 | Intelligent-driven Adapting Defense Against the Client-side DNS Cache Poisoning in the CloudabstractA new Domain Name System (DNS) cache poisoning attack aiming at clients has emerged recently. It induced cloud users to visit fake web sites and thus reveal information such as account passwords. However, the design of current DNS defense architecture does not formally consider the protection of clients. Although the DNS traffic encryption technology can alleviate this new attack, its deployment is as slow as the new DNS architecture. Thus we propose a lightweight adaptive intelligent defense strategy, which only needs to be deployed on the client without any configuration support of DNS. Firstly, we model the attack and defense process as a static stochastic game with incomplete information under bounded rationality conditions. Secondly, to solve the problem caused by uncertain attack strategies and large quantities of game states, we adopt a deep reinforcement learning (DRL) with guaranteed monotonic improvement. Finally, through the prototype system experiment in Alibaba Cloud, the effectiveness of our method is proved against multiple attack modes with a success rate of 97.5% approximately. Tengchao Ma, Changqiao Xu, Zan Zhou 0001, Xiaohui Kuang, Lujie Zhong, Luigi Alfredo Grieco |
GLOBECOM | 3 |
| 2020 | Multi-vNIC Intelligent Mutation: A Moving Target Defense to thwart Client-side DNS Cache AttackabstractAs massive research efforts are poured into server-side DNS security enhancement in online cloud service platforms, sophisticated APTs tend to develop client-side DNS attacks, where defenders only have limited resources and abilities. The collaborative DNS attack is a representative newest client-side paradigm to stealthily undermine user cache by falsifying DNS responses. Different from existing static methods, in this paper, we propose a moving target defense solution named multi-vNIC intelligent mutation to free defenders from arduous work and thwart elusive client-side DNS attack in the meantime. Multiple virtual network interface cards are created and switched in a mutating manner. Thus attackers have to blindly guess the actual NIC with a high risk of exposure. Firstly, we construct a dynamic game-theoretic model to capture the main characteristics of both attacker and defender. Secondly, a reinforcement learning mechanism is developed to generate adaptive optimal defense strategy. Experiment results also highlight the security performance of our defense method compared to several state-of-the-art technologies. Zan Zhou 0001, Changqiao Xu, Tengchao Ma, Xiaohui Kuang |
ICC | 1 |
| 2020 | A Survey of Blockchain-based Cybersecurity for Vehicular NetworksabstractThe development of vehicular networks has greatly improved the efficiency and safety of intelligent traffic systems. However, it also introduces additional security threats into the system. The special characteristics of vehicular networks, such as dynamic topology, huge network scale and so on, make it difficult to adopt the traditional security solutions directly into this scenario. In addition, the single point failure problem of the centralized security mechanisms is also a big challenge. Recently, blockchain technology, which is a distributed database, is a potential approach to address these security issues. In this paper, a comprehensive review of the existing blockchain-based cybersecurity mechanisms is presented with the corresponding performance analysis. The purpose of this work is to provide a guideline for the further study in the application of blockchain in the vehicular network security area. Xifeng Wang, Changqiao Xu, Zan Zhou 0001, Limin Sun 0001 |
IWCMC | 3 |
| 2019 | An Intelligent Route Mutation Mechanism against Mixed Attack Based on Security AwarenessabstractStatic network defense technologies are always in a passive defense state because of their disadvantages in cost, time and information. So Network Moving Target Defense (NMTD) is proposed as a kind of proactive defense technology. As an important research direction of NMTD, route mutation techniques still have limitations that they can not learn attack strategies and be adaptive in dynamical security situation. In this paper, we propose a novel route mutation mechanism based on reinforcement learning. We firstly investigate four different attack strategies and introduce a mixed attack strategy with entropy constraints. Then we formulate the network requirements using Satisfiability Module Theory (SMT) logic to acquire the route mutation space. We further propose a security-awareness Q- learning algorithm to select routes from the mutation space iteratively and conduct security awareness to adjust learning rate adaptively. Meanwhile, the optimal convergence of our algorithm is proved theoretically. Finally, experimental results highlight the effectiveness as defense performance, network overhead and convergence speed of our method compared to the representative solution. Tao Zhang 0063, Xiaohui Kuang, Zan Zhou 0001, Hongquan Gao, Changqiao Xu |
GLOBECOM | 3 |
| 2019 | A Reputation Management Scheme for Identifying Malicious Nodes in VANETabstractIn vehicular ad-hoc network (VANET), vehicles exchange information on road conditions which guarantees safety. However, there exists malicious nodes which interfere the communication between vehicles. Thus, it is vital to identify malicious vehicles in VANET. Reputation-based schemes are one of the most promising schemes to identify malicious nodes in time. However, existing methods can only identify malicious nodes of a specific attack. Additionally, the efficiency and effectiveness of existing work in solving advanced attacks are unsatisfactory. In this paper, we propose a scheme to identify malicious nodes in VANET based on collaborative filtration. Distinguished from the existing solutions, we consider a variety of attacks in VANET, instead of a specific attack. In addition, our scheme updates the reputation of nodes in time according to the result of each communication, which brings better efficiency and effectiveness. The superiority of our proposed scheme has been demonstrated through simulation experiments. Changhui Gong, Changqiao Xu, Zan Zhou 0001, Tao Zhang 0063 |
HPSR | 3 |
| 2019 | An Efficient and Agile Spatio-Temporal Route Mutation Moving Target Defense MechanismabstractFor the reasons that defect remedy is an endless arduous work for static network defense technologies and cyberspace security remains unguaranteed, moving target defense (MTD) is proposed to stem the tide. Whereas, as an important branch of MTD, route mutation technologies still have limitations against some sophisticated adversaries like Advanced Persistent Threat (APT), multiple-step complex or combined attacks. In this paper, we propose a new spatio-temporal route mutation method based on MTD. We first take the maximization of resistibility towards not only multiple forms of attacks but also attackers' long-term background knowledge into consideration. We also formulate the problem into a stochastic optimization model and make it possible to agilely generate the satisfying mutation route meets the demands of various parties jointly by only solving one uniform problem. Thus, network Security is guaranteed from both flows(users) and nodes(infrastructure) perspectives. Experimental results highlight the security advantages as traffic dispersion, potential victim number and attack failure rates of our method compared to existing solutions. Zan Zhou 0001, Changqiao Xu, Xiaohui Kuang, Tao Zhang 0063, Limin Sun 0001 |
ICC | 1 |
| 2019 | SE-PSO: Resource Scheduling Strategy for Multimedia Cloud Platform Based on Security Enhanced Virtual MigrationabstractIn the multimedia cloud platform, the resource scheduling performance directly affects the energy consumption, resource utilization of the active physical machine (PM) and virtual machine (VM) security. Besides, service level agreement (SLA) violation rate also fluctuates with the strategy. Many optimization methods have been launched to cope with this scheduling task, while none of them accommodate all the above aspects in a uniform manner to our best knowledge. In this paper, aiming at optimizing the four sides performance, we propose a new resource scheduling strategy called Security Enhanced Particle Swarm Optimization (SE-PSO) based on VM migration which uses Particle Swarm Optimization (PSO) as a kernel part. Firstly, the inertia factor and the learning factor are dynamically adapted to improve the search performance of SE-PSO. Then, by periodically predicting physical hotspots with the exponential smoothing model, we reduce unnecessary migrations and thus minimize the VM migration security risk. Finally, roulette wheel idea is applied to achieve long-term optimization of the platform resources. The experiments conducted in CloudSim with real-world dataset also show that SE-PSO has a good overall performance in energy consumption, resource utilization, SLA violation rate and migration security compared with the mainstream PSO algorithm. Tengchao Ma, Changqiao Xu, Zan Zhou 0001, Xiaohui Kuang, Lujie Zhong |
IWCMC | 3 |
| 2017 | Mobility-aware multimedia data transfer using Multipath TCP in Vehicular NetworkabstractThis paper proposed a mobility-aware multimedia data transfer mechanism using Multipath TCP in Vehicular Network. Since high transmission rate and low latency are the two key factors for multimedia data transmission that could provide stable video streaming services, therefore, we first adopted Multipath Transport Control Protocol which can transfer data concurrently for improving transmission rate and designed Quality-aware Data Distribution to dynamically allocate the data to different subflows. Moreover, in Vehicular Network, the mobile terminal, which means the vehicle, can communicate with remote server through roadside unit (RSU). However, the communication link between terminals and remote server will disrupt while the vehicle exceeding the communication range of roadside unit; and there also exists the situation that the vehicle is in the communication range of several RSU. Accordingly, we exploited a mobility-aware distance measurement for checking whether the vehicle has moved out of the communication range of any RSU or it is in multi-RSU's communication range. Afterwards, we designed a handover mechanism which transfer data to connected path (4G) for stable transmission using MPTCP when the vehicle exceeded the communication range of RSU; while one mobile can communicate with more than one RSU, we exploited a mechanism which can trigger new path for multipath data transmission and non-corporation Nash Equilibria was employed for solving the problem of fairness in the same kind of network technology multipath transmission. Simulation results show how mobility-aware multimedia data transfer mechanism improve the performance of transmission comparison with state-of-art solution. Danyang Zhu, Changqiao Xu, Jiuren Qin, Zan Zhou 0001, Jianfeng Guan |
IWCMC | 4 |