EDBT 2026 Demo / reviewers in the wild / expert
Guanglin Duan
dblp:322/9737
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2025
0009-0005-4917-9536ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
6 papers |
Software-defined and programmable networks · 100% | |
| Network and information security
3 papers |
Network security · 100% | |
| Databases, data mining, and information retrieval
1 paper |
Data stream processing · 100% | |
| Artificial intelligence
2 papers |
Efficient and distributed learning · 100% |
Topics — the 6 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software-defined and programmable networks
programmable data plane |
4.4 | 6 | 2025 | DNSGuard: In-Network Defense Against DNS Attacks · IEEE Trans. Dependable Secur. Comput. 2025 Learning-Enhanced High-Throughput Pattern Matching Based on Programmable Data Plane · USENIX ATC 2025 Empowering In-Network Classification in Programmable Switches by Binary Decision Tree and Knowledge Distillation · IEEE/ACM Trans. Netw. 2024 |
Network security › intrusion detection and prevention
intrusion detection |
1.2 | 3 | 2025 | Metis: Understanding and Enhancing In-Network Regular Expressions · NeurIPS 2023 DNSGuard: In-Network Defense Against DNS Attacks · IEEE Trans. Dependable Secur. Comput. 2025 Learning-Enhanced High-Throughput Pattern Matching Based on Programmable Data Plane · USENIX ATC 2025 |
Software-defined and programmable networks › programmable data plane
in-network defense |
0.9 | 1 | 2025 | DNSGuard: In-Network Defense Against DNS Attacks · IEEE Trans. Dependable Secur. Comput. 2025 |
Software-defined and programmable networks › programmable data plane › in-network computation
in-network classification |
0.8 | 1 | 2024 | Empowering In-Network Classification in Programmable Switches by Binary Decision Tree and Knowledge Distillation · IEEE/ACM Trans. Netw. 2024 |
Software-defined and programmable networks › programmable data plane › in-network computation
in-network intelligence |
0.6 | 1 | 2022 | Mousika: Enable General In-Network Intelligence in Programmable Switches by Knowledge Distillation · INFOCOM 2022 |
Machine learning › Efficient and distributed learning › model compression
knowledge distillation |
0.4 | 2 | 2024 | Empowering In-Network Classification in Programmable Switches by Binary Decision Tree and Knowledge Distillation · IEEE/ACM Trans. Netw. 2024 Mousika: Enable General In-Network Intelligence in Programmable Switches by Knowledge Distillation · INFOCOM 2022 |
Methods — techniques the papers use, named apart from their topics
knowledge distillation · 4.0binary decision tree · 2.7tree-based ensemble models · 1.7recursive incremental parsing · 1.7machine learning · 1.7hybrid model architecture · 1.7p4 programming · 1.5recurrent neural network · 1.3random forest · 1.3hash collision resolution · 1.3multi-stage tracking · 0.7decision tree · 0.6
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Learning-Enhanced High-Throughput Pattern Matching Based on Programmable Data Plane
Guanglin Duan, Qing Li 0006, Dan Zhao 0003, Zili Meng, Dirk Kutscher, Ruoyu Li 0003, Yong Jiang 0001, Mingwei Xu 0001 |
USENIX ATC | 1 |
| 2025 | DNSGuard: In-Network Defense Against DNS AttacksabstractThe Domain Name System (DNS) is a growing center of cyber attacks, including both volumetric and non-volumetric attacks. Programmable switches provide a new opportunity for more efficient defense against DNS attacks since they can offer better cost, performance, and flexibility trade-offs compared to traditional defense systems. However, programmable switches have strict limitations on the operations and storage space supported to ensure line-speed packet processing. In this paper, we propose DNSGuard, an intelligent in-network defense framework that can handle volumetric and non-volumetric DNS attacks on programmable switches. We propose a recursive incremental parsing algorithm that can effectively extract variable-length domain names. To achieve real-time and accurate detection against two types of DNS attacks, we design a switch-optimized and resource-efficient algorithm to extract both independent features of each packet and domain-based cumulative features. Then, we propose a multi-phase hybrid model architecture to perform dynamic packet analysis at different time phases of a domain. Further, we design efficient model representation mechanisms to deploy tree-based ensemble models in the data plane. Experimental results show that DNSGuard can defend against diverse DNS attacks at the line rate. In addition, DNSGuard introduces a minimal nanosecond latency to normal traffic in heavily loaded networks. Guanglin Duan, Qing Li 0006, Dan Zhao 0003, Guorui Xie, Yuan Yang 0001, Zhenhui Yuan, Yong Jiang 0001, Mingwei Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Empowering In-Network Classification in Programmable Switches by Binary Decision Tree and Knowledge DistillationabstractGiven the high packet processing efficiency of programmable switches (e.g., P4 switches of Tbps), several works are proposed to offload the decision tree (DT) to P4 switches for in-network classification. Although the DT is suitable for the match-action paradigm in P4 switches, the range match rules used in the DT may not be supported across devices of different P4 standards. Additionally, emerging models including neural networks (NNs) and ensemble models, have shown their superior performance in networking tasks. But their sophisticated operations pose new challenges to the deployment of these models in switches. In this paper, we propose Mousikav2 to address these drawbacks successfully. First, we design a new tree model, i.e., the binary decision tree (BDT). Unlike the DT, our BDT consists of classification rules in the form of bits, which is a good fit for the standard ternary match supported by different hardware/software switches. Second, we introduce a teacher-student knowledge distillation architecture in Mousikav2, which enables the general transfer from other sophisticated models to the BDT. Through this transfer, sophisticated models are indirectly deployed in switches to avoid switch constraints. Finally, a lightweight P4 program is developed to perform classification tasks in switches with the BDT after knowledge distillation. Experiments on three networking tasks and three commodity switches show that Mousikav2 not only improves the classification accuracy by 3.27%, but also reduces the switch stage and memory usage by$2.00\times $and 28.67%, respectively. Code is available athttps://github.com/xgr19/Mousika. Guorui Xie, Qing Li 0006, Guanglin Duan, Jiaye Lin, Yutao Dong, Yong Jiang 0001, Dan Zhao 0003, Yuan Yang 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2023 | Efficient Flow Recording with InheritSketch on Programmable SwitchesabstractSeveral studies have been proposed to deploy the flow recording (i.e., flow size counting and sketching algorithms) on programmable switches for high-speed processing, helping network management tasks like scheduling. Although programmable switches provide a remarkable packet processing speed, they are of compact resources and follow a restrictive pipeline programming. To fit these limitations, current algorithms either sacrifice the recording accuracy or harm the switch throughput. In this paper, we propose InheritSketch for further improvement. InheritSketch utilizes a separation counting fashion, which is memory-efficient for compact switches. It accurately records the more valuable heavy hitters in the large key-value counters (i.e., the primary table), while only sketching non-heavy flows in the small sentinel table. With the recording ongoing, InheritSketch intelligently summarizes the historical recording experience as the basis for flow inheritance. That is, flows with the same IDs as the previous heavy hitters are regarded as new heavy hitters, being recorded in the primary table. To correct some incorrect inheritance, we also propose the flow rebellion, which promotes flows of large sizes but wrongly stored in the sentinel table to the primary table. InheritSketch is also helpful in applications like differentiated scheduling. We compare InheritSketch with six previous recording algorithms on three public traffic datasets, and prototype InheritSketch on a commodity P4 switch. The results demonstrate that InheritSketch reduces the recording errors by at most ∼7×, and that InheritSketch only consumes 10% of hardware resources on the switch. Guorui Xie, Qing Li 0006, Guanglin Duan, Yong Jiang 0001, Zhuyun Qi, Qiaoling Wang |
ICDCS | 3 |
| 2023 | Metis: Understanding and Enhancing In-Network Regular ExpressionsabstractRegular expressions (REs) offer one-shot solutions for many networking tasks, e.g., network intrusion detection. However, REs purely rely on expert knowledge and cannot utilize labeled data for better accuracy. Today, neural networks (NNs) have shown superior accuracy and flexibility, thanks to their ability to learn from rich labeled data. Nevertheless, NNs are often incompetent in cold-start scenarios and too complex for deployment on network devices. In this paper, we propose Metis, a general framework that converts REs to network device affordable models for superior accuracy and throughput by taking advantage of REs' expert knowledge and NNs' learning ability. In Metis, we convert REs to byte-level recurrent neural networks (BRNNs) without training. The BRNNs preserve expert knowledge from REs and offer adequate accuracy in cold-start scenarios. When rich labeled data is available, the performance of BRNNs can be improved by training. Furthermore, we design a semi-supervised knowledge distillation to transform the BRNNs into pooling soft random forests (PSRFs) that can be deployed on network devices. To the best of our knowledge, this is the first method to employ model inference as an alternative to RE matching in network scenarios. We collect network traffic data on our campus for three weeks and evaluate Metis on them. Experimental results show that Metis is more accurate than original REs and other baselines, achieving superior throughput when deployed on network devices. Guanglin Duan, Qing Li 0006, Dan Zhao 0003, Yong Jiang 0001, Lianbo Ma 0004, Xi Xiao 0001, Hengyang Xu |
NeurIPS | 3 |
| 2023 | Pontus: Finding Waves in Data StreamsabstractThe bumps and dips in data streams are valuable patterns for data mining and networking scenarios such as online advertising and botnet detection. In this paper, we define the wave, a data stream pattern with a serious deviation from the stable arrival rate for a period of time. We then propose Pontus, an efficient framework for wave detection and estimation. In Pontus, a lightweight data structure is utilized for the preliminary processing of incoming packets in the data plane to take advantage of its high processing speed; then, the powerful control plane carries out computationally intensive wave detection and estimation. In particular, we propose the Multi-Stage Progressive Tracking strategy which detects waves in stages and removes any disqualified items promptly to save memory. Hash collisions are addressed by a Stage Variance Maximization technique to reduce estimation error. Moreover, we prove the theoretical error bound and establish upper bounds of false positive and false negative. Experiment results show that the software version of Pontus can achieve around 97% F1-Score even under scarce memory when baselines fail. Furthermore, the implemented prototype of Pontus based on P4 achieves 842x higher throughput than the baseline strawman solution. Qing Li 0006, Guanglin Duan, Dan Zhao 0003, Jingyu Xiao, Guorui Xie, Yong Jiang 0001 |
Proc. ACM Manag. Data | 3 |
| 2022 | Mousika: Enable General In-Network Intelligence in Programmable Switches by Knowledge DistillationabstractGiven the power efficiency and Tbps throughput of packet processing, several works are proposed to offload the decision tree (DT) to programmable switches, i.e., in-network intelligence. Though the DT is suitable for the switches’ match-action paradigm, it has several limitations. E.g., its range match rules may not be supported well due to the hardware diversity; and its implementation also consumes lots of switch resources (e.g., stages and memory). Moreover, as learning algorithms (particularly deep learning) have shown their superior performance, some more complicated learning models are emerging for networking. However, their high computational complexity and large storage requirement are cause challenges in the deployment on switches. Therefore, we propose Mousika, an in-network intelligence framework that addresses these drawbacks successfully. First, we modify the DT to the Binary Decision Tree (BDT). Compared with the DT, our BDT supports faster training, generates fewer rules, and satisfies switch constraints better. Second, we introduce the teacher-student knowledge distillation in Mousika, which enables the general translation from other learning models to the BDT. Through the translation, we can not only utilize the super learning capabilities of complicated models, but also avoid the computation/memory constraints when deploying them on switches directly for line-speed processing. Guorui Xie, Qing Li 0006, Yutao Dong, Guanglin Duan, Yong Jiang 0001, Jingpu Duan |
INFOCOM | 4 |