EDBT 2026 Demo / reviewers in the wild / expert
Ruyun Zhang 0001
dblp:28/875-1
· DBLP profile ↗
11ranked-venue papers
0as first author
11since 2021 · last 2026
0000-0002-2969-817XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 6 since 2021Security and privacy · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Normality in Anomaly: Rethinking Traffic Labels
Chao Zha, Dakun Shen, Ruyun Zhang 0001, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | FlowXpert: Context-Aware Flow Embedding for Enhanced Traffic Detection in IoT NetworkabstractIn the Internet of Things (IoT) environment, continuous interaction among a large number of devices generates complex and dynamic network traffic, which poses significant challenges to rule-based detection approaches. Machine learning (ML)-based traffic detection technology, capable of identifying anomalous patterns and potential threats within this traffic, serves as a critical component in ensuring network security. This study first identifies a significant issue with widely adopted feature extraction tools (e.g., CICFlowMeter): the extensive use of time- and length-related features leads to high sparsity, which adversely affects model convergence. Furthermore, existing traffic detection methods generally lack an embedding mechanism capable of efficiently and comprehensively capturing the semantic characteristics of network traffic. To address these challenges, we propose a novel feature extraction tool that eliminates traditional time and length features in favor of context-aware semantic features related to the source host, thus improving the generalizability of the model. In addition, we design an embedding training framework that integrates the unsupervised DBSCAN clustering algorithm with a contrastive learning strategy to effectively capture fine-grained semantic representations of traffic. Extensive empirical evaluations are conducted on the real-world dataset (Mawi) and two simulated datasets (CICIDS-2017 and UNSW-NB15) to validate the proposed method in terms of detection accuracy, robustness, and generalization. Comparative experiments against several state-of-the-art (SOTA) models demonstrate the superior performance of our approach. Furthermore, we confirm its applicability and deployability in real-time scenarios. Chao Zha, Haolin Pan, Ruyun Zhang 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | Toward Synthetic Network Traffic Generating in NTN-Enabled IoT: A Generative AI ApproachabstractNonterrestrial networks (NTNs) enabled Internet of Things (IoT) extends connectivity to remote and underserved areas, enhances network reliability and coverage, and supports diverse IoT applications in challenging environments, such as rural, maritime, and disaster-stricken regions. As an emerging and fast-evolving IoT scheme, NTN-enabled IoT requires extensive evaluation to ensure effective deployment in real-world scenarios, such as connectivity, performance, and security evaluation. Since conducting testing in remote and diverse environments is logistically challenging and costly, we propose a generative artificial intelligence (GAI)-based synthetic traffic generation framework that facilitates comprehensive traffic analysis and performance evaluation. The proposed framework employs a GAI model to learn the traffic pattern and generate synthetic traffic from historical data. Our approach includes an embedding-based model for representing network flow attributes and a conditional generative adversarial network (CGAN) for generating traffic flows. Considering both source-destination information and statistical features achieves more comprehensive characterization of traffic flows. Finally, the simulation results demonstrate that the proposed approach can generate high quality traffic that conforms to real data distribution and shows obvious difference between multiple applications. Dingde Jiang, Zhihao Wang 0001, Ruyun Zhang 0001, Lizhuang Tan, Peiying Zhang 0001 |
IEEE Internet Things J. | 6 |
| 2025 | Intelligent Intrusion Detection System With Autonomous Optimal Traffic Steering for Aerial-Aided Edge ComputingabstractAerial-aided Edge Computing (AEC) promises to provide low-latency computing services as a critical component for future low-altitude intelligent transportation systems. However, the complex edge network environment poses security challenges, as traditional Intrusion Detection Systems (IDS) struggle to handle AEC’s large traffic volume and resource constraints. To address this, we propose a collaborative detection mechanism called Switch IDS. First, Switch IDS adopts a packet-level detection solution to meet real-time detection requirements. Next, Switch IDS is designed for resource-constrained nodes. By introducing the Mixture of Experts (MoE) structure into the traditional Deep Learning (DL) model, it enables seamless and scalable multi-node deployment. Switch IDS establishes a resource status-based capability for each Expert and incorporates steering loss in the loss function to enable autonomous near-optimal traffic steering, ultimately maximizing system processing capacity. Finally, the Switch IDS utilizes parallelized Service Function Chaining (SFC) for practical multi-node deployment. To the best of our knowledge, this is the first realization of multi-node deployment and autonomous traffic steering for DL-based IDS. Experiments on public datasets show that Switch IDS and its multi-node deployment scheme notably boost processing capacity while maintaining high detection performance. Huachun Zhou, Ruyun Zhang 0001, Keping Long |
IEEE Internet Things J. | 4 |
| 2025 | A-NIDS: Adaptive Network Intrusion Detection System Based on Clustering and Stacked CTGANabstractIntrusion detection systems (IDS) are crucial tools for detecting anomalous network traffic in cybersecurity. In recent years, significant progress has been made in applying artificial intelligence to IDS. However, existing research often assumes that training and testing data are static and identically distributed, whereas in reality, data drift is inevitable. Moreover, to enhance model versatility and detection performance, models have become increasingly complex, posing challenges to real-time deployment. To address these challenges, we propose an adaptive network intrusion detection system named A-NIDS, consisting of a main task and two bypass tasks. The main task is to develop a fully connected and shallow network with strong detection performance and real-time capability. The first bypass task is a clustering model that helps the main task detect data drift in an unsupervised manner. The second bypass task is a generation model to generate old data to address catastrophic forgetting in new model iterations and the storage cost issue caused by accumulating old data. We conduct extensive experiments on the CICIDS-2017 and CSE-CICIDS-2018 datasets, demonstrating the superior performance of A-NIDS on new and old data. Furthermore, our detection module achieves a detection latency of 5 microseconds, highlighting its suitability for real-time applications. All the related code is publicly available at:https://github.com/ids-sec-hub/A-NIDS. Chao Zha, Yinjie Zhang, Sainan Shi, Ruyun Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | DM-IDS - A Network Intrusion Detection Method Based on Dual-Modal FusionabstractThe machine learning-based approach to network intrusion detection presents a groundbreaking research paradigm, positioned to replace traditional rule-based and signature-based methods. However, prior research methodologies have predominantly focused on flow-based approaches, which may not be effective in detecting all types of attacks at a granular level. In this study, we introduce DM-IDS, an attention-convolution architecture model for bimodal network intrusion detection in both flow and payload modalities, using bilinear fusion. Notably, we present a novel method for constructing binary-form feature vectors under the payload modality, with the goal of extracting additional security semantic features. To facilitate this, we independently develop a feature generation tool named Beeman. Finally, we conduct a series of comparative and ablation experiments on two publicly available datasets, CICIDS-2017 and CICIoT-2023, achieving state-of-the-art model performance. Chao Zha, Yinjie Zhang, Sainan Shi, Ruyun Zhang 0001 |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2025 | Architectural Exploration for Waferscale Switching SystemabstractWith the end of Moore’s law and Dennard scaling, waferscale systems or processors that integrate multiple pre-tested known good dies (KGDs) on a waferscale-interposer are new approaches to further improve the chiplet-based system’s performance. This article explores the network on wafer (NoW) architecture of waferscale switching system under several physical constraints. A software-based approach is proposed to redefine the topological property. A five-level butterfly fat-tree (BFT)-like logical topology with 8.96-Tb/s (896 ports$\times 10$Gb/s/port) switching bandwidth is achieved based on 2-D-mesh-like physical topology. We show that the proposed BFT-like topology with breadth-first-search (BFS) based traffic balanced routing algorithm reduces 55.6% hops, 41.4% transmission delay, and improves 24.2% throughput compared to 2-D-mesh-like topology under different traffic distributions. This BFT-like waferscale switching system is suitable for high-performance computing and data centers. In addition, the numerical analysis shows that the waferscale package can provide significant power efficiency and latency advantages compared to the typical single-chip package, which mainly benefits from the short-reach IO requirements. Note that the proposed waferscale switching system is compatible with high-switch-capacity dies with advanced process technology, which can further improve system performance. Finally, we present the physical implementations for the waferscale system with heterogeneous dies. Zhiquan Wan, Zhipeng Cao 0001, Shunbin Li, Peijie Li, Qingwen Deng, Kun Zhang 0037, Guandong Liu, Ruyun Zhang 0001, Qinrang Liu |
IEEE Trans. Very Large Scale Integr. Syst. | 9 |
| 2024 | SKT-IDS: Unknown attack detection method based on Sigmoid Kernel Transformation and encoder-decoder architecture
Chao Zha, Yinjie Zhang, Sainan Shi, Ruyun Zhang 0001 |
Comput. Secur. | 8 |
| 2023 | Fast DDoS Traffic Throttling and Normal Traffic Permitting in SDN-IoT: A Deep Reinforcement Learning ApproachabstractRecent Internet of Things (IoT) security incidents indicate that current IoT defense methods are insufficient to defend against DDoS attacks due to a lack of timely and plausible mitigation mechanisms. These methods may make wrong decisions on traffic throttling when network traffic patterns dynamically change. To swiftly and properly defend against DDoS attacks in IoT, we propose a novel deep reinforcement learning (DRL) based DDoS defense approach. Our goals are to both safeguard normal traffic and discard malicious traffic. To achieve these goals, we establish a software defined networking (SDN) based IoT network by replacing traditional IoT gateways at certain locations with SDN switches. The proposed method consists of network monitoring, reward evaluation, and defense policy execution. The DRL agent is able to monitor the whole network by utilizing various traffic features from the SDN-enabled IoT network framework. We propose an adaptive punishment based reward function to accelerate the learning procedure. We also propose an available bandwidth allocation algorithm to refine defense policy so as to protect more normal traffic. The experimental results demonstrate that the proposed method could determine optimal defense policy faster by around 200 episodes and forward more normal traffic by around 22%. Congqi Shen, Wanxin Gao, Ruyun Zhang 0001 |
ICC | 6 |
| 2023 | Mangling Rules Generation With Density-Based Clustering for Password GuessingabstractRule-based password generation is one of the most effective and often employed techniques in the highly compute-intensive password recovery process. However, it is challenging to design and maintain a practical password mangling ruleset, which is a time-consuming task requiring specialized expertise. This paper therefore introduced MDBSCAN (Modified Density-Based Spatial Clustering of Applications with Noise), a novel density-based cluster approach in machine learning, to build an automatic password mangling rule generator. To evaluate the proposed method, cross-checks across 4 different real-world password datasets leaked from popular Internet services and applications are adopted. The results indicate that the proposed generator could produce high-quality mangling rules with a better hit rate and enhance current mangling rules by identifying hidden or omitted rules. The proposed approach also shows strong interpretability and computational efficiency. When examining the RockYou password dataset with the top 77 rules, the hit rate may rise by 11% to 104% proportionally to other well-known solutions. Furthermore, by combining the top 77 rules generated by MDBSCAN with those from other rulesets, 3–12.67% more real-world passwords can be retrieved. Shunbin Li, Ruyun Zhang 0001, Chunming Wu 0001, Hanguang Luo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | Multi-Agent and Cooperative Deep Reinforcement Learning for Scalable Network Automation in Multi-Domain SD-EONsabstractThe service provisioning in multi-domain software-defined elastic optical networks (SD-EONs) is an interesting but difficult problem to tackle, because the basic problem of lightpath provisioning, i.e., the routing and spectrum assignment (RSA), is$\mathcal {NP}$-hard, and each domain is owned and operated by a different carrier. Therefore, even though numerous RSA heuristics have been proposed, there does not exist a universal winner that can always achieve the lowest blocking probability in all the scenarios of a multi-domain SD-EON. This motivates us to revisit the inter-domain provisioning problem in this paper by leveraging deep reinforcement learning (DRL). Specifically, we propose DeepCoop, which is an inter-domain service framework that uses multiple cooperative DRL agents to achieve scalable network automation in a multi-domain SD-EON. DeepCoop employs a DRL agent in each domain to optimize intra-domain service provisioning, while a domain-level path computation element (PCE) is introduced to obtain the sequence of the domains to go through for each lightpath request. By sharing a restricted amount of information among each other, the DRL agents can make their decisions distributedly. To ensure scalability and universality, we design the action space of each DRL agent based on well-known RSA heuristics, and architect the agents based on the soft actor-critic (SAC) scenario. We run extensive simulations to evaluate DeepCoop, and the results show that DeepCoop can adapt to the dynamic environment in a multi-domain SD-EON to always select the best RSA heuristic for minimizing blocking probability, and it outperforms the existing algorithms on inter-domain provisioning in various scenarios. Moreover, we verify that the distributed training implemented in DeepCoop ensures its universality and scalability (i.e., its training and operation do not depend on the topology of the SD-EON). Ruyun Zhang 0001, Xiaojian Tian, Zuqing Zhu |
IEEE Trans. Netw. Serv. Manag. | 2 |