Xue Leng

dblp:204/7938 · DBLP profile ↗
← Back
13ranked-venue papers
7as first author
9since 2021 · last 2026
0000-0003-1333-5988ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 4 first-author · 2 since 2021Security and privacy · 5 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FaaSGuard: An Adaptive Framework for Obfuscating Function Activity States in Serverless Applications
Xue Leng, Fengming Zhu, Xing Li 0001, Tiantian Zhu 0001
INFOCOM1
2026 PROPHET: Efficient and Intelligent Orchestrator for Microservices Scheduling and Scaling
abstract
Microservices are popular and widely used in the cloud. However, realizing cost-effective and high-performance microservice orchestration is challenging for Cloud Service Providers (CSPs). Current orchestration mechanisms have limited flexibility and resource efficiency in scheduling and would cause sluggishness in scaling, which brings unnecessary costs to CSP. This paper presents PROPHET, a microservice orchestrator for optimizing service scheduling and scaling. To improve scheduling flexibility and resource utilization, we propose aranking-based p-batch scheduling mechanism, which adopts a pairwise ranker to obtain resource-efficient scheduling plans for large-scale microservice applications rapidly. To advance the scaling agility, we design aproactive prediction-based scaling mechanism, which performs scaling in advance based on resource usage prediction. Our evaluations are conducted on a real-world cluster with the public Alibaba cluster dataset and datasets collected from the cluster. The results indicate that PROPHET can significantly reduce the number of nodes running in the cluster and improve scaling. This shows great potential in achieving cost-effective and high-performance microservice orchestration.
Xue Leng, Chengxuan Zhu, Fengming Zhu, Kaiwen Shen, Tiantian Zhu 0001, Yan Chen 0004
IEEE Trans. Netw.1
2025 Poster: An Obfuscation Framework for Mitigating Topology Probing Attacks in Cloud-Native Systems
abstract
In cloud-native systems, microservices communicate with each other through remote calls. This communication side channel contains various information that can be leveraged to carry out topology probing attacks, DDoS attacks, etc. To defend against these attacks, researchers conducted work on critical path analysis and topology obfuscation. However, these works can not be applied to cloud-native scenarios because of limited flexibility and the long calculation time. In this paper, we propose MeshGuard, a novel obfuscation framework for mitigating topology probing attacks in cloud-native systems. Specifically, we construct a service-level dynamic labyrinth to achieve adaptive topology obfuscation. To avoid leaking traffic patterns when obfuscating topology, we disguise obfuscated traffic with tailored parameters. Finally, we design a tag-based obfuscation mechanism to avoid affecting normal microservices. The preliminary results show that MeshGuard can effectively protect the critical path and services with acceptable resource overhead.
Xue Leng, Kaiwen Shen, Chengxuan Zhu, Xing Li 0001
CCS1
2025 Poster: Obfuscating Function Activity States to Enhance Privacy in Serverless Applications
abstract
Serverless computing, also known as Function-as-a-Service (FaaS), is widely used in modern applications. Function instances share the underlying physical infrastructure, which makes co-location attacks possible and leads to the leakage of sensitive information such as function activity states. Existing work has respective limitations in serverless scenarios because of incomplete detection coverage, long training time, and intrusion into the function's runtime environment. In this paper, we propose FaaSGuard, an obfuscation framework to protect function activity states in network side-channels and enhance privacy in serverless applications. To be specific, we design an adaptive obfuscation strategy selection mechanism to make FaaSGuard flexible. We design a traffic camouflage method to make obfuscated traffic indistinguishable from normal traffic, making FaaSGuard invisible. In order not to affect normal traffic, we propose a tag-based obfuscation mechanism to identify obfuscated packets. The preliminary evaluation results show that FaaSGuard can conceal function activity states with negligible resource overhead.
Xue Leng, Fengming Zhu, Xing Li 0001, Ye Tian 0027, Yan Chen 0004
CCS1
2025 Poster: Leveraging Large Language Models to Effectively and Efficiently Identify Vulnerability Patches for WordPress Plugins
abstract
Vulnerability patches are essential for managing vulnerabilities in Open-source software (OSS). However, accurately identifying them remains difficult. Existing methods mainly rely on rule-based matching and are not well-suited to ecosystems like WordPress plugins, due to the lack of a unified development standard. In contrast, methods that combine vulnerability descriptions with code changes demonstrate greater potential. However, current prediction models lack deep semantic understanding and thus cannot fully understand the meaning behind the changes.
Xue Leng, Tiantian Zhu 0001
CCS1
2025 ThreatCog: An adaptive and lightweight mobile user authentication system with enhanced motion sensory signals
Tiantian Zhu 0001, Jian-Ping Mei, Xue Leng, Xiangyang Zheng, Zhengqiu Weng
J. Inf. Secur. Appl.7
2025 FaaSTracker: Efficient Cross-Layer Provenance Tracking of Serverless Applications With Multi-Source Correlation
abstract
Serverless computing, also known as Function-as-a-Service (FaaS), has gained popularity due to its flexibility, scala bility, and transparent development. However, attacks against serverless are also increasing. Unfortunately, complex multi-layer FaaS architecture and frequently launched lightweight functions help attackers conceal their tracks. Specifically, (i) fully tracking the behavior of a function requires crossing multiple layers of FaaS. (ii) Intrusive auditing components in functions affect function startup latency and performance. (iii) Accurately provenance cross-layer function invocations require integrating data from multiple sources. In this paper, we propose FAASTRACKER, a cross-layer, non-intrusive, efficient provenance framework for accurately tracking user function behaviors in FaaS. FAASTRACKER tracks function behaviors across layers using a non-intrusive agent without any modifications to the function. In addition, it correlates data from multiple sources to construct a provenance graph of function workflows to locate attackers. We implement FAASTRACKER on the OpenFaaS platform and evaluate its performance using real-world serverless applications. Compared with state-of-the-art serverless provenance systems, FAASTRACKER provides a more accurate and complete view of provenance graphs and reduces 54.0% CPU and 48.9% memory resources.
Qingyang Zeng, Lianjie Wu, Kaiyu Hou, Xue Leng, Yan Chen 0004
IEEE Trans. Inf. Forensics Secur.4
2024 DirectFaaS: A Clean-Slate Network Architecture for Efficient Serverless Chain Communications
abstract
Serverless computing, also known as Function-as-a-Service (FaaS), triggers web applications in the form of function chains. It uses a central orchestrator to route all requests from end-users and internal functions. Such architecture simplifies application deployment for developers. However, the convenient centralized network architecture compromises the efficiency of function chain communications. Specifically, (i) a centralized API gateway assists in routing requests between functions. This indirect routing scheme raises invocation latency. (ii) The control flow for invoking functions and the data flow for passing function data packets are both forwarded by the API gateway. This results in the API gateway consuming a significant amount of resources. (iii) All data packets of internal function communications go through the same API gateway. This expands the additional attack surface in multi-tenant scenarios.
Qingyang Zeng, Kaiyu Hou, Xue Leng, Yan Chen 0004
WWW3
2024 A comprehensive performance evaluation, comparison, and integration of computational methods for detecting and estimating cross-contamination of human samples in cancer next-generation sequencing analysis
Huijuan Chen, Lili Cai, Yali Hu, Xue Leng, Dongjie Fan, Beifang Niu, Qiming Zhou
J. Biomed. Informatics7
2019 A lightweight policy enforcement system for resource protection and management in the SDN-based cloud
Xue Leng, Kaiyu Hou, Yan Chen 0004, Kai Bu, Libin Song, You Li 0008
Comput. Networks1
2018 SDNKeeper: Lightweight Resource Protection and Management System for SDN-Based Cloud
abstract
SDN-based cloud has the merit of allowing more flexibility in network management, however, the security of network accessing and the correctness of network configuration in SDN-based cloud have not been effectively addressed yet. In this paper, SDNKeeper, a generic and fine-grained policy enforcement system in SDN-based cloud is proposed, which can defend against unauthorized attacks and avoid network resource misconfiguration. With the usage of SDNKeeper, numerous flexible network management policies can be created by administrators, which give administrators the discretionary room on controlling the network resources. To be specific, SDNKeeper can reject any unauthorized network access request at Northbound Interface (NBI), which located between application plane and control plane. Moreover, compared with other traditional policy-based access control systems, SDNKeeper is totally application-transparent and lightweight, which is easy to implement, deploy and runtime configure. Based on the prototype implementation and evaluation, we conclude that SDNKeeper can perform access control accurately with negligible computation overhead whilst the throughput degradation is still within the acceptable range.
Xue Leng, Kaiyu Hou, Yan Chen 0004, Kai Bu, Libin Song
IWQoS1
2018 Calibration Method for Mapping Camera Based on a Precise Grouped Approach Method
abstract
This paper introduces a new calibration method for the mapping camera called Precise Grouped Approach Method (PGAM). The conventional calibration method for the mapping camera is the exact measuring angle method. The accuracy of this method can be reduced by theoretical uncertainties and the number and distribution of observation points. PGAM is able to overcome these disadvantages and improve the accuracy. Firstly, we reduce the theoretical uncertainties by means of a grouped approach method, which rectifies the high-precision rotation stage to zero position. Secondly, a weighted theory is applied to eliminate the effect of the number and distribution of observation points. Finally, the accuracy of PGAM is analyzed. The experiment result shows that the calibration accuracy is significantly improved when using the proposed PGAM algorithm, compared to the conventional one under the identical experimental condition.
Guoqin Yuan, Xue Leng, Yingfeng Wu
Int. J. Pattern Recognit. Artif. Intell.3
2017 RuleScope: Inspecting Forwarding Faults for Software-Defined Networking
abstract
Software-defined networking (SDN) promises unprecedentedly flexible network management but it is susceptible to forwarding faults. Such faults originate from data-plane rules with missing faults and priority faults. Yet existing fault detection ignores priority faults, because they are not discovered on commercial switches until recently. In this paper, we present RuleScope, a more comprehensive solution for inspecting SDN forwarding. RuleScope offers a series of accurate and efficient algorithms for detecting and troubleshooting rule faults. They inspect forwarding behavior using customized probe packets to exercise data-plane rules. The detection algorithm exposes not only missing faults but also priority faults and the troubleshooting algorithm uncover actual forwarding states of data-plane flow tables. Both of them help track real-time forwarding status and benefit reliable network monitoring. Furthermore, toward fast inspection of dynamic networks, we propose incremental algorithms for rapidly evolving network policies to amortize detection and troubleshooting overhead without sacrificing accuracy. Experiments with our prototype on the Ryu SDN controller and Pica8 P-3297 switch show that the RuleScope achieves accurate fault detection on 320-entry flow tables with a cost of 1500+ probe packets within 16 s.
Xitao Wen, Kai Bu, Yan Chen 0004, Li Erran Li, Xue Leng
IEEE/ACM Trans. Netw.8