EDBT 2026 Demo / reviewers in the wild / expert
Wendi Feng
dblp:222/5921
· DBLP profile ↗
32ranked-venue papers
11as first author
23since 2021 · last 2026
0000-0002-2540-8120ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 25 · 9 first-author · 19 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MiniQ: Minimizing Tail Latency for Cloud SFCs with Queuing-aware Execution Planning
Weijia Yu, Guoyuan Li, Wendi Feng, Jianjun Chang |
IWQoS | 4 |
| 2026 | LinkSketch: Hash offloading accelerated network measurement with linked arrays
Wendi Feng, Chuanchang Liu |
Comput. Networks | 1 |
| 2025 | ALSHIRA: Minimizing Latency for Large-scale AI Tasks over the Heterogeneous Intelligent Computing Network
Mingxu Gong, Wendi Feng |
APNet | 3 |
| 2025 | Quarantine: Decoupling Overlapping Flows Defined in State Table of NFV with BDD and ddNF
Ao Jin, Wendi Feng |
APNet | 2 |
| 2025 | Charlotte: Interleaved Scheduling for Pipelined Network Tasks on SmartNICs
Guoyuan Li, Wendi Feng |
APNet | 2 |
| 2025 | HTS: Accelerating Mixed-partitionable Encryption Tasks on Heterogeneous Computing Platforms
Wendi Feng, Mingxu Gong |
APNet | 2 |
| 2025 | Cosite: Raising SFC Performance with VNF Ordering
Weijia Yu, Wendi Feng |
APNet | 3 |
| 2025 | RD-KNN: Detecting Malicious Encrypted Traffic as Processing Natural Language
Yuyao Zhou, Wendi Feng |
APNet | 3 |
| 2025 | HITOM: Optimizing Throughput for Mixed-Mode Encryption Tasks on Heterogeneous Computing PlatformsabstractCloud providers build dedicated crypto-cloud, which leverage various heterogeneous computing engines to speedup the encryption performance for the applications. Partitionable and unpartitionable tasks are the two main types of encryption tasks on the crypto-cloud. The challenge is that unpartitionable tasks cannot be placed on multiple engines to be processed simultaneously and may be too large to overload a particular computing engine, while merely placing one partitionable task on a single engine may underuse other engines in the cryptocloud, incurring impaired throughput performance. Hence, this paper introduces the Optimal Cryptographic Task Scheduling Problem (OCTSP), which seeks to optimize the throughput of mixed-partitionable encryption tasks on heterogeneous platforms by considering task characteristics, engine proficiency, and migration costs. To efficiently solve the problem, we propose a novel scheduling algorithm, HITOM, which enhances encryption task throughput through the synergistic integration of hierarchical scheduling, engine scoring, and migration-allocation optimization mechanisms. Simulation results manifest that HITOM successfully increases system throughput on heterogeneous platforms. HITOM achieves 75.08% and 52.81% throughput improvement compared to Random Scheduling and CBC-First Scheduling, respectively. Furthermore, it demonstrates an average throughput improvement of 17.6% over Utilization-First Scheduling, which optimizes cryptographic engine utilization. Wendi Feng, Mingxu Gong |
HPCC | 2 |
| 2025 | Hashmvt: Accelerating Parallel Networking Services With Hardware Offloaded Hash-Based Match-Value TablesabstractModern network infrastructures rely heavily on stateful networking services (NSes), such as firewall and network address translation (NAT). These services utilize state variables (a.k.a., states) to process network flows. However, existing state management mechanisms face significant performance bottlenecks in attaining high-throughput performance, primarily due to the substantial overhead incurred by frequent state matching and the inability to partition states across instances. To address these challenges, we propose HASHMVT, a novel abstraction optimized for state management in NSes. HashMVT employs a MatchValue Table (MVT) that associates network flows with their corresponding states and incorporates built-in partitioning operations that cope with the distribution of states across instances running in parallel. Additionally, it integrates a carefully designed hash-based flow matching mechanism, with hash calculations offloaded to general-purpose platforms using widely available hash instructions. This architecture achieves$O(1)$time complexity for state lookup operations while supporting concurrent state access via built-in atomic operations, which is particularly crucial for parallel NS deployments. We validate HASHMVT using a representative use case-network address translation. Experimental evaluations demonstrate that HASHMVT exhibits superior scalability compared to existing solutions, delivering over a 60 % improvement in throughput compare to the state-of-the-art implementation. Furthermore, comprehensive analyses on adapting HASHMVT to various real-world NSes confirm its generalizability through a systematic examination of state management requirements across different NS categories. Wendi Feng |
ICWS | 1 |
| 2025 | Compresso: Latency-Aware Transmission of Compressed IoT Measurement Data Over SDNabstractMeasurement data obtained from “things” in the Internet of Things (IoT) faces challenges in efficient transmission due to the low-bandwidth data transmission link. We observe that measurement data are fixed in size and format, and low-entropy in the time domain, indicating that compression can be benefited. Rather than employing a single compression algorithm as advocated in existing literature, we argue that optimal transmission can be achieved by jointly considering compression overheads and network status, where software-defined networking (SDN) is employed to enforce network statistics and packet forwarding. This article presents a new paradigm that achieves optimal transmission of SDN-empowered compressed measurement data. We formulate the problem as an optimization problem and prove its nonpolynomial hardness time complexity. Due to this complexity, we introduceCompresso, a heuristic algorithm that efficiently solves the problem. We conduct rigorous simulations, and the results demonstrate the efficiency of the new paradigm andCompresso, i.e., attaining comparable performance to the optimal solution with 50% time usage reduction. Wendi Feng, Xintan Dou, Amirhosein Taherkordi, Bo Cheng 0001 |
IEEE Internet Things J. | 1 |
| 2024 | GRAPE: GPU-accelerated Zero-copy IoT Measurement Data Compression TransmissionabstractNowadays, a large number of sensors are involved in the Internet of Things (IoT) systems, incurring significant amount of data that are required to be efficiently transmitted under the stringent latency and IoT network link capacity constraints. Compression is an efficient method to alleviate it. However, existing IoT gateways, especially those on the cloud, leverage the gateway Central Processing Unit (CPU) which incurs impaired performance due to data compression and transmission. To this end, we propose Grape, the Graphics Processing Unit (GPU)-based data compression solution for efficient IoT measurement data transmission. Under the hood, Grape consolidates multiple measurement data of the same kind as a video and compresses the video using hardware instructions provided by the GPU to significantly improve the data compression performance. Besides, Grape creates a direct data path between the Network Interface Card (NIC) and the host to avoid data copy between kernel space and user space. Our primary experimental results indicate that Grape is 5 × faster than the traditional approach. Xintan Dou, Wendi Feng, Jun Liu 0091 |
APNet | 2 |
| 2024 | Sketchlet: Partitioning Traffic for Sketch with Clustering on Multi-core Commodity ServersabstractNetwork traffic measurement using Sketch has become an efficient and reliable means of network management. However, limited by the structure of Sketch, achieving high throughput at 100 Gbps or above on commodity server platforms is challenging. The reason is that each counter in Sketch is associated with multiple flows, making it difficult to direct flows across multiple processor cores without sharing the same counter. To the end, we propose the Sketchlet abstraction. By analyzing the positions of counters associated with flows in memory, Sketchlet establishes clustering relationships between flows. Flows in the same cluster are directed to the same processing core, and the traffic is thus partitioned. Hence, each cluster’s flows to access only one sketch slice (i.e., a sketchlet) of the entire Sketch structure. We have implemented a prototype system for Sketchlet abstract and conducted rigorous experiments. The preliminary experimental results show that the packet processing throughput of Sketchlet is 2.4 × higher than Sketch with locking under both using four cores. Jun Liu 0091, Wendi Feng, Xintan Dou |
APNet | 2 |
| 2024 | Seraph: Towards secure and efficient multi-controller authentication with (t,n)-threshold signature in multi-domain SDWAN
Wendi Feng, Bo Cheng 0001 |
J. Netw. Comput. Appl. | 1 |
| 2023 | MobiPCR: Efficient, accurate, and strict ML-based mobile malware detectionabstractMobile devices have been and will be continuously prevalent as rich applications are provided for various demands. However, the mobile operating system lacks efficient malware detection tools, which puts personal data at risk. This paper presents MobiPCR, a trict, accurate, efficient mobile-oriented malware detection system. MobiPCR basically integrates a (n) (edge) cloud-based architecture, a powerful yet efficient machine learning-based detection model, and a neat detection process. We implemented the MobiPCR prototype system and conducted rigorous experiments to evaluate its performance from different perspectives. We implemented the MobiPCR prototype system on the Android platform (Installer Hooker part) considering that Android is an open-source platform that (i) can be easily modified and (ii) provides rich documentation. We used LineageOS 13 (a widespread Android distribution) to provide the necessary drivers to support communication and the camera for casual usage. Experimental results prove that MobiPCR can strictly and accurately detect malwares and outperform existing similar applications without extra operations. Chuanchang Liu, Jianyun Lu, Wendi Feng, Enbo Du, Luyang Di |
Future Gener. Comput. Syst. | 3 |
| 2023 | Causal embedding of user interest and conformity for long-tail session-based recommendations
Wendi Feng, Fayadh Alenezi, Prayag Tiwari |
Inf. Sci. | 3 |
| 2023 | An End-Host-Importance-Aware Secure Service-Enabled Hybrid SDN DeploymentabstractSecurity is critical to networks, but TCP/IP-basedlegacynetworks are difficult to advance new security functions due to the use of costly inflexible hardware devices and error-prone network configurations. Recent literature explores the paradigm of consolidating security services with the forwarding functionality using Software-defined Networking (SDN). Existingfull SDNdeployment, replacing all legacy network devices with SDN devices, is cost-prohibitive. Whereas thehybrid SDNthat only upgrades partial legacy devices to SDN switches is considered practical. However, the challenge is to minimize threats and deployment expenses simultaneously under heterogeneous end-host businesses that have various importance. In this paper, we study the challenge and propose theEnd-host-importance-Aware secure service-enabled hybrid Sdn deplOymeNt (EASON)problem. We mathematically formulate the EASON problem as an integer programming problem, prove its non-polynomial time complexity, and propose a heuristic algorithm called BonSèc. We conduct rigorous simulations on real-world topologies and traces. Experimental results show that BonSèc achieves comparable security and cost performances to the optimal solution on small topologies. Meanwhile, it is scalable on larger topologies. Wendi Feng, Chuanchang Liu, Bo Cheng 0001, Junliang Chen 0001, Zhiguo Wan |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2022 | MEMOCO: Memory-Efficient 100 Gbps Traffic Replay with Sequence Guarantee on Multi-core ServersabstractNetwork has become the most important infrastructure in today’s information society, in which traffic generation is essential in aiding network system development and testings. However, high-performance traffic replay, say 100 Gbps, is challenging. To this end, we present MEMOCO, a software-based 100 Gbps traffic generator to generate sequence guaranteed packets and replay real-world traces using fixed memory footage. At the heart of MEMOCO is a judiciously designed inter-core scheduler and a machine learning-based traffic pattern recognizer. We present the key design of MEMOCO to call for broad comments to the system. Ranzheng Cao, Wendi Feng |
APNet | 2 |
| 2022 | NFlow and MVT Abstractions for NFV ScalingabstractThe ability to dynamically scale in/out network functions (NFs) on multiple cores/servers to meet traffic demands is a key benefit of network function virtualization (NFV). The stateful NF operations make NFV scaling a challenging task: if care is not taken, NFV scaling can lead to incorrect operations and poor performance. We advocate two general abstractions, NFlow and Match-Value Table (MVT), for NFV packet processing pipelines. We present formal definitions of the abstractions and discuss how they can facilitate NFV scaling by minimizing or eliminating shared states. Using NFs implemented with the proposed abstractions, we conduct extensive experiments and demonstrate their efficacy in terms of correctness and performance of NFV scaling. Ziyan Wu 0002, Yang Zhang 0074, Wendi Feng, Zhi-Li Zhang |
INFOCOM | 3 |
| 2022 | BatchSketch: a "network-server" aligned solution for efficient mobile edge network sketchingabstractHeavy flow identification is essential for discovering potential adversarial activities in mobile edge networks. However, state-of-the-art falls short in accuracy with approximation algorithms and unbounded memory usages with precise measurement. To this end, we introduce BatchSketch, a "network - server" aligned solution to achieve both high accuracy and low memory usage. The intelligence behind is that BatchSketch first conducts coarse-grained filtering from the switch with bounded memory and computation resources, and it then sends the filtered flows to the RDMA-link attached server with plenty of memory for accurate measurement. Our primary experimental results indicate that the filter on the switch can filter 99% of non-heavy flows, remarkably reducing the memory usage for the measurement. Wendi Feng, Chuanchang Liu, Junliang Chen 0001 |
MobiCom | 1 |
| 2022 | Maintaining Control Resiliency and Flow Programmability in Software-Defined WANs During Controller FailuresabstractProviding resilient network control is a critical concern for deploying Software-Defined Networking (SDN) into Wide-Area Networks (WANs). For performance reasons, a Software-Defined WAN is divided into multiple domains controlled by multiple controllers with a logically centralized view. Under controller failures, we need to remap the control of offline switches from failed controllers to other active controllers. Existing solutions have three limitations: (1) the least flow programmability (e.g., the ability to change paths of flows) cannot be maintained; (2) active controllers could be overloaded, interrupting their normal operations; (3) network performance could be degraded because of the increasing controller-switch communication overhead. In this paper, we propose RetroFlow+ to recover the flow programmability and achieve low communication overhead during controller failures. By intelligently configuring a set of selected offline switches working under the legacy routing mode and several active controllers releasing a few control resources, RetroFlow+ enables active controllers to use the minimum control resource to sustain the flow programmability. RetroFlow+ also smartly transfers the control of offline switches with the SDN routing mode to active controllers to minimize the communication overhead from these offline switches to the active controllers. Simulation results show that RetroFlow+ realizes low communication overhead, recovers all offline flows under one and two controller failures, and improves the flow recovery percentage up to 70% under three controller failures, compared with the state-of-the-art solution. Zehua Guo 0001, Songshi Dou, Sen Liu 0002, Wendi Feng, Wenchao Jiang, Yang Xu 0010, Zhi-Li Zhang |
IEEE/ACM Trans. Netw. | 4 |
| 2021 | Secure and cost-effective controller deployment in multi-domain SDN with Baguette
Wendi Feng, Chuanchang Liu, Bo Cheng 0001, Junliang Chen 0001 |
J. Netw. Comput. Appl. | 1 |
| 2021 | HybridFlow: Achieving Load Balancing in Software-Defined WANs With Scalable RoutingabstractThe scalability issue hinders the deployment of Software-Defined Networking (SDN) in the Wide Area Networks (WANs). Existing solutions have two issues: (1) network performance relies on complicated controller synchronization, which increases the complexity of network control; (2) fine-grained flow processing enables flexible flow control at the cost of high processing load on the controllers and high flow table occupancy on switches. In this paper, we propose a scalable routing solution named HybridFlow, which achieves a good load balancing performance using a single controller with low control overhead (i.e., flow routing and rerouting overhead). HybridFlow mainly employs two techniques: hybrid routing and crucial flow rerouting. Hybrid routing enabled by commercial SDN switches gives us opportunities to reduce the processing load of the controller by routing flows with the hybrid OpenFlow/OSPF mode. Thus, the majority of flows can be routed by OSPF without involving the controller. Crucial flow rerouting realizes load balancing by dynamically identifying crucial flows based on a new metric called Variation Slope and rerouting these flows with the hybrid OpenFlow/OSPF mode. The simulation based on the real traffic traces and network typologies shows that compared with the optimal solution, HybridFlow can achieve 87% of the optimal load balancing performance by rerouting 36% less flows on average. Zehua Guo 0001, Songshi Dou, Yi Wang 0004, Sen Liu 0002, Wendi Feng, Yang Xu 0010 |
IEEE Trans. Commun. | 5 |
| 2020 | BAGUETTE: Towards a Secure and Cost-effective Switch Upgrade in Hybrid Software-Defined NetworksabstractSoftware-Defined Networking (SDN), providing flexible controlling and monitoring mechanisms that simplifies network management, is becoming prevalent in recent years. However, replacing all legacy network devices with SDN-capable devices is cost-prohibitive. One practical approach for the SDN deployment is to incrementally upgrade a few legacy devices to SDN devices. The network, which consists of legacy and SDN devices, is called a hybrid SDN. Existing hybrid SDN deployment schemes do not consider the security impact of device deployment. They use the same type of devices to upgrade, and upgraded devices could be compromised if an attacker controls one SDN device by leveraging its vulnerabilities.In this paper, we consider this security issue in the hybrid SDN deployment and present the Secure and Cost-effective Switch Upgrade (SCESU) problem. The SCESU problem aims to upgrade a few network devices to satisfy the security requirement by using multiple SDN switch types with a minimal upgrade cost. The complexity of the SCESU problem comes from common vulnerabilities shared among different types of SDN devices and attack propagations among network nodes. To efficiently solve the problem, we propose the BAGUETTE algorithm to judiciously choose and upgrade critical legacy switches with selected SDN devices. Simulation results show that BAGUETTE achieves up to about 92.1% security enhancement compared with legacy network and reduces to 11.1% cost of the securest deployment. Wendi Feng, Zehua Guo 0001, Chuanchang Liu, Yueming Zheng, Meng Wang 0018, Bo Cheng 0001, Junliang Chen 0001 |
ICC | 1 |
| 2020 | NFV Performance Profiling on Multi-core Servers
Wendi Feng, Arvind Narayanan, Zhi-Li Zhang |
Networking | 2 |
| 2020 | MobiGyges: A mobile hidden volume for preventing data loss, improving storage utilization, and avoiding device reboot
Wendi Feng, Chuanchang Liu, Zehua Guo 0001, Thar Baker, Gang Wang 0014, Meng Wang 0018, Bo Cheng 0001, Junliang Chen 0001 |
Future Gener. Comput. Syst. | 1 |
| 2020 | Exploring the role of paths for dynamic switch assignment in software-defined networks
Zehua Guo 0001, Shaojun Zhang, Wendi Feng, Weichao Wu, Julong Lan |
Future Gener. Comput. Syst. | 3 |
| 2019 | An Efficient Service Function Chain Placement Algorithm in a MEC-NFV EnvironmentabstractMobile Edge Computing (MEC) is a promising network architecture that pushes network control and mobile computing to the network edge. Recent studies propose to deploy MEC applications in the Network Function Virtualization (NFV) environment. The mobile network service in NFV is deployed as a Service Function Chains (SFC). In this paper, we solve the SFC placement problem in a MEC-NFV environment. We formulate the SFC placement problem as a weighted graph matching problem, including two sub-problems: a graph matching problem and a SFC mapping problem. To efficiently solve the graph matching problem, we propose a linear programming-based approach to calculate the similarity between physical nodes and VNFs. Based on the similarity, we design a Hungarian-based placement algorithm to solve the SFC mapping problem. Evaluation results show that our proposed solutions outperform the greedy algorithm in terms of execution time and resource utilization. Meng Wang 0018, Bo Cheng 0001, Wendi Feng, Junliang Chen 0001 |
GLOBECOM | 3 |
| 2019 | Availability-Aware Service Chain Composition and Mapping in NFV-Enabled NetworksabstractNetwork Function Virtualization (NFV) is an emerging technology decouples network functions from hardware. Network service in NFV is deployed as a service chain, also known as Service Function Chain (SFC). SFC consists of an ordered set of Virtual Network Functions (VNFs). However, VNFs bring new challenges in providing network services with availability guarantee. In addition, in a customizable and dynamic NFV-enabled network, the composition and mapping of service chain are different from that of a traditional network. In this paper, we define an availability model that takes both hardware and VNF failures into consideration. Then we propose Joint Path-VNF backup model to combine path and VNF backup in a joint way. And a priority-based algorithm is designed for service chain composition and mapping. Simulation results show that our proposed solutions can reduce resource consumption while guaranteeing availability. Meng Wang 0018, Bo Cheng 0001, Shuai Zhao 0001, Biyi Li, Wendi Feng, Junliang Chen 0001 |
ICWS | 5 |
| 2019 | Data Loss Prevention and Storage Utilization Improvement of the Hidden Volume on Mobile DevicesabstractSensitive data protection is vital for mobile users. An effective way is to store sensitive data in the hidden volume of mobile devices with Plausibly Deniable Encryption (PDE) systems. Typically, PDE creates a hidden volume inside the outer volume. However, existing PDE systems could lose data, due to overriding the hidden volume, and significantly waste physical storage, because of the fixedly reserved area for the hidden volume. In this paper, we present MobiGyges to solve the above problems. MobiGyges leverages the Thin Pool to coordinate the storage allocation for both the outer volume and the hidden volume which avoids data override and prevents data loss. Moreover, it improves the storage efficiency by virtualizing the total physical storage into small storage blocks and utilizing the blocks for the outer volume and the hidden volume, which eliminates the reserved area. We implement MobiGyges prototype on Google Nexus 6P with LineageOS 13 operating system. Experimental results show that MobiGyges avoids data loss and improves storage utilization up to 31% compared with existing works. Wendi Feng, Chuanchang Liu, Zehua Guo 0001, Thar Baker, Bo Cheng 0001, Junliang Chen 0001 |
ISCC | 1 |
| 2019 | RetroFlow: maintaining control resiliency and flow programmability for software-defined WANsabstractProviding resilient network control is a critical concern for deploying Software-Defined Networking (SDN) into Wide-Area Networks (WANs). For performance reasons, a Software-Defined WAN is divided into multiple domains controlled by multiple controllers with a logically centralized view. Under controller failures, we need to remap the control of offline switches from failed controllers to other active controllers. Existing solutions could either overload active controllers to interrupt their normal operations or degrade network performance because of increasing the controller-switch communication overhead. In this paper, we propose RetroFlow to achieve low communication overhead without interrupting the normal processing of active controllers during controller failures. By intelligently configuring a set of selected offline switches working under the legacy routing mode, RetroFlow relieves the active controllers from controlling the selected offline switches while maintaining the flow programmability (e.g., the ability to change paths of flows) of SDN. RetroFlow also smartly transfers the control of offline switches with the SDN routing mode to active controllers to minimize the communication overhead from these offline switches to the active controllers. Simulation results show that compared with the baseline algorithm, RetroFlow can reduce the communication overhead up to 52.6% during a moderate controller failure by recovering 100% flows from offline switches and can reduce the communication overhead up to 61.2% during a serious controller failure by setting to recover 90% of flows from offline switches. Zehua Guo 0001, Wendi Feng, Sen Liu 0002, Wenchao Jiang, Yang Xu 0010, Zhi-Li Zhang |
IWQoS | 2 |
| 2018 | TrustGyges: A Hidden Volume Solution with Cloud Safe Storage and TEEabstractNo abstract available. Wendi Feng, Chuanchang Liu, Bingfei Ren, Bo Cheng 0001, Junliang Chen 0001 |
MobiSys | 1 |