EDBT 2026 Demo / reviewers in the wild / expert
Daguo Cheng
dblp:344/6903
· DBLP profile ↗
16ranked-venue papers
3as first author
16since 2021 · last 2026
0000-0001-7731-9050ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 3 first-author · 14 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Understanding the IPv6 Address Usage Strategies of Top Internet Services
Lin He 0004, Zedong Jia, Daguo Cheng, Jinlong E, Yuhan Du, Guanglei Song, Ying Liu 0024, Xingang Shi, Shenglin Zhang, Jiahai Yang 0001, Mingwei Xu 0001 |
ICC | 3 |
| 2026 | Divide, Predict, Conquer: Adaptive Internet-wide Service Discovery with Limited Seeds
Daguo Cheng, Zedong Jia, Ying Liu 0024, Lin He 0004, Le Gai, Jiuzhou Zhang, Chentian Wei, Zhaoan Wang, Jinlong E |
INFOCOM | 1 |
| 2026 | SpecNet-Agent: Network-Aware Speculation Control for QoS in Agentic Generative AI Services
Le Gai, Lin He 0004, Chentian Wei, Zedong Jia, Daguo Cheng, Ying Liu 0024 |
IWQoS | 5 |
| 2026 | AddrProbe: An Internet-Wide Active IPv6 Address Probing System With Limited SeedsabstractWith the large-scale deployment of IPv6, it is becoming more and more important to probe active IPv6 addresses on the global Internet. However, the vast address space and the random distribution of active addresses make the probing process full of challenges, especially for the probing of IPv6 prefixes without seed addresses. Furthermore, the widespread existence of IPv6 aliased prefixes also causes significant trouble for probing. In this paper, we presentAddrProbe, an active IPv6 address probing system, which dynamically probes all global routing prefixes based on learned fine-grained address patterns from limited seed addresses and quickly detects aliased prefixes during probing. The evaluation results show thatAddrProbeachieves a hit rate of 23%-45% with all routing prefixes announced by the BGP system, which is 6.6-13× that of current state-of-the-art approaches (no more than 4%). Moreover, we find 1.2×1033aliased addresses characterized by the detected aliased prefixes, covering 6,412 routing prefixes, which is a 107× and 5.9× improvement over existing methods, respectively. Finally, an IPv6 Hitlist is constructed based on the long-term probing results, which contains 562M addresses covering 190K routing prefixes and 29K ASes. These widely distributed addresses are meaningful for analyzing IPv6 address assignments and some other IPv6 measurement activities. Daguo Cheng, Lin He 0004, Qilei Yin, Guangxing Han, Boran Jin, Ying Liu 0024, Guanglei Song, Jinlong E, Tiankai Yang 0001, Jiahai Yang 0001 |
IEEE Trans. Netw. | 1 |
| 2026 | Do Not Fall Into the Trap: Efficiently Discovering IPv6 Fully Responsive Prefixes in the Wild
Lin He 0004, Chentian Wei, Daguo Cheng, Qilei Yin, Boran Jin, Zhaoan Wang, Xiaoteng Pan, Sixu Zhou, Ying Liu 0024, Shenglin Zhang, Fuchao Tan, Wenmao Liu |
IEEE Trans. Netw. | 3 |
| 2025 | TopoMiner: Efficient IPv6 Topology DiscoveryabstractTopology discovery can be used to obtain the connectivity and operational status of network devices by discovered interfaces. By performing topology discovery on networks, administrators can better understand and manage networks and improve network reliability and security. However, the large IPv6 address space, sparse address distribution, and unknown address assignment policies make it infeasible to simply and roughly probe the IPv6 network topology. To this end, we design an efficient IPv6 interface-level topology discovery method called TopoMiner. It performs multiple rounds of probing the IPv6 topology with the given set of IPv6 prefixes and locates the high-density interface regions based on the results of each round of topology discovery. TopoMiner then performs prefix expansion and address generation for the high-density interface address regions. At the same time, TopoMiner also uses some of the prefixes that have been probed to regenerate the target addresses. In this way, TopoMiner can dynamically adjust the breadth and depth of topology discovery and thus complete multiple rounds of topology discovery within the packetsending budget. In real-word probing, TopoMiner achieves a$3 \sim 7 \times$enhancement in probing efficiency compared to state-of-the-art topology discovery methods. Hongwei Li 0021, Lin He 0004, Guanglei Song, Daguo Cheng, Jiahai Yang 0001, Ying Liu 0024 |
ICC | 6 |
| 2025 | Gungnir: Autoregressive Model for Unified Generation of IPv6 Fully Responsive PrefixesabstractWith the widespread adoption of IPv6, its vast address space presents significant challenges for network asset discovery. Traditional exhaustive scanning approaches are no longer practical, while strategies based on target generation algorithms are increasingly undermined by the existence of Fully Responsive Prefixes (FRPs)—prefixes in which all addresses appear responsive to probing. FRPs distort scanning results, introducing bias and inefficiency. Existing FRP probing techniques suffer from limited scalability, poor accuracy, and restricted applicability in large-scale IPv6 environments.To this end, we propose Gungnir, a multi-protocol unified FRP probing algorithm based on autoregressive semantic modeling. Gungnir captures the intricate relationships between FRP patterns and their influencing factors through a deep semantic learning architecture. It leverages prefix inference and a granularity correction mechanism to accurately predict and validate FRPs, while mitigating errors from incorrect prefix-length estimation. Extensive experiments demonstrate that Gungnir outperforms state-of-the-art techniques, achieving up to 27× higher efficiency, 4.2× wider address space coverage, and broader coverage of both autonomous systems and routing prefixes under the same probing budget. Beyond performance, we further analyze the service and port distributions of the discovered FRPs, uncovering operational patterns and potential security implications. These insights offer valuable guidance for IPv6 measurement, address discovery, and network defense. Chentian Wei, Ying Liu 0024, Lin He 0004, Daguo Cheng |
ICNP | 4 |
| 2025 | Lightning in the Dark: Uncovering Global IPv6 Router Interfaces and Their Security ImplicationsabstractThe IPv6 routing infrastructure is an important part of the modern Internet, and the collection of its interface addresses is greatly significant in network security, performance optimization, and measurement analysis. However, existing methods suffer from two major problems: the lack of flexibility in budget allocation across probing rounds and the absence of a dynamic hop limit adjustment mechanism based on feedback. These problems lead to the low hit rate and inefficiency of existing methods for discovering router interfaces, which seriously hinders the comprehensive knowledge of IPv6 routing infrastructure.To this end, we propose Helixir, a feedback-based, high hit-rate, and efficient IPv6 router interface discovery system. Helixir’s core design includes a dynamic budget allocation mechanism across probing rounds, an inter-prefix budget allocation strategy that adequately trades off exploration and exploitation, and a hop limit selection method based on Thompson sampling. Real-world experiments show that with a 100M budget, Helixir achieves a hit rate 3.64× that of state-of-the-art methods on the BGP prefixes dataset, and Helixir successfully discovers over 31 million IPv6 router interface addresses in total within half an hour. In addition, a systematic security analysis of the discovered router interfaces shows that many devices open sensitive ports and expose hundreds of potential CVE vulnerabilities, highlighting the security risks in the IPv6 network. Ying Liu 0024, Lin He 0004, Xiaoyi Shi, Yifan Yang 0009, Chentian Wei, Daguo Cheng, Jiahai Yang 0001 |
ICNP | 7 |
| 2025 | SubRecon: Efficient Internet-Wide IPv6 Subnet Discovery and Its ApplicationsabstractThe vastness of the IPv6 address space has led to the common practice of allocating prefixes to end users rather than individual addresses. Users can assign these prefixes as a single subnet or divide them into multiple subnets for different purposes. Allocation strategies vary significantly in terms of prefix granularity, and identifying the actual granularity of subnet assignments is crucial for improving measurement efficiency, accuracy, and for better IPv6 network management. However, no existing method can discover IPv6 subnets at an Internet-Wide scale.To this end, we propose SubRecon, an Internet-Wide IPv6 subnet discovery system. SubRecon consists of two key phases: subnet delimitation and target expansion. In the subnet delimitation phase, we perform a systematic scan across the entire IPv6 address space without relying on any existing seed dataset. This phase adopts a top-down approach, probing prefixes from the shortest to the longest in a hierarchical manner. At each level, we recursively refine prefixes and discard sub-prefixes that do not meet the convergence condition. This pruning strategy eliminates redundant probes in unallocated regions, significantly reducing the search space and improving probing efficiency. To further improve coverage, the target expansion phase leverages the active address dataset as an auxiliary input. It identifies active addresses not covered by previously discovered subnets, expands them into new candidate target prefixes, and performs another round of subnet delimitation. This helps enhance the completeness and coverage of the final discovered subnet set. Experimental results show that SubRecon discovers 8,381,974 IPv6 subnets across 14,147 autonomous systems, and the resulting subnet list can serve as high-quality input for topology discovery. Additionally, during the subnet discovery process, SubRecon identifies a large number of last-hop router interfaces, discovering approximately 10 million more than the current state-of-the-art methods. Ying Liu 0024, Lin He 0004, Yifan Yang 0009, Xiaoyi Shi, Daguo Cheng, Chentian Wei, Yun Fan, Guanglei Song |
ICNP | 6 |
| 2025 | Poster: TopoHunter: Enabling Efficient and High-Coverage Active IPv6 Topology DiscoveryabstractWe introduce TopoHunter, an efficient IPv6 Internet topology discovery system. The central concept of TopoHunter is to allocate more probing resources to target prefix spaces that yield greater topological benefits, as well as to their surrounding areas. To achieve this, we design a feedback-based target generation module comprised of a Target Prefix Probing Value Forest that maintains the estimated probing values of hierarchical target prefix spaces. Our system has successfully discovered the most extensive and complete IPv6 topology map to date, comprising over 144 million router interfaces and 251 million edges, covering 72.83% of autonomous systems and 43.36% of routing prefixes announced by the BGP system. Lin He 0004, Hongwei Li 0021, Guanglei Song, Wentong Wang, Daguo Cheng, Enhuan Dong, Chenglong Li 0006, Hui Zhang 0141, Jinlong E, Ying Liu 0024, Jiahai Yang 0001 |
IMC | 6 |
| 2025 | 6Map: Enabling Fast Active IPv6 Address Discovery with Programmable Switches
Lin He 0004, Yifan Yang 0009, Xiaoyi Shi, Daguo Cheng, Jinlong E, Ying Liu 0024, Dong Zhang 0010 |
INFOCOM | 5 |
| 2025 | Bringing New Life to Old Tools: Measuring Source Address Validation Deployment with 6in4 TunnelsabstractSource Address Validation (SAV) is a security mechanism deployed at network boundaries to prevent packets with illegal source addresses from crossing these boundaries. While SAV plays an important role in mitigating source address spoofing, its deployment across the global Internet remains limited. Measuring SAV deployment is essential for enhancing the understanding of the security landscape of networks. In this study, we propose a novel method for measuring SAV deployment based on 6 in 4 tunnels, complementing existing measurement work. Using this method, we measure inbound SAV for IPv4 and outbound SAV for IPv6, obtaining results from 12,417 and 2,104 Autonomous Systems (ASes), respectively. Based on our measurements, we analyze factors that may influence SAV deployment, including network address space size, AS type, and geographical location. Additionally, we provide a global heatmap of spoofable rates for networks in different countries and regions. Note that the measuring method using bin4 tunnels we introduce is not only applicable to SAV measurements but also holds potential for other measurement tasks, such as connectivity testing and transmission path discovery. This method offers a new way for large-scale measurement tasks across different networks, which may benefit future research. Jiaxing Guo, Lin He 0004, Daguo Cheng, Xingang Shi, Ying Liu 0024 |
IWQoS | 3 |
| 2025 | APCC: Enabling Reliable IPv6 Covert Communication with Aliased PrefixesabstractCovert communication ensures undetectable information exchange between parties while posing risks when exploited for malicious purposes. Existing network covert channels face challenges in reliability, throughput, and stealthiness due to packet loss, limited capacity, and detectable anomalies. This paper proposes APCC, a reliable covert communication system that leverages IPv6 aliased prefixes for the first time, where secret data is embedded in the Interface Identifier field of IPv6 addresses. APCC enhances stealthiness through encryption and camouflage strategies (e.g., traffic blending and rate control). Additionally, it employs a reliable transmission mechanism incorporating sequence numbering, acknowledgment, and retransmission to mitigate packet loss and reordering. It ensures deployment flexibility across ICMPv6, UDP, or TCP protocols. Evaluations in real-world and simulated environments demonstrate that APCC achieves 100% accuracy under high latency ($\mathbf{8 0 0 ~ m s ~ R T T}$) and packet loss (10%), with throughput up to 34.7 Kbps. Detection tests show APCC evades major intrusion detection systems (Snort, Zeek) except for Suricata's TCP alerts. We also propose mitigation measures to reduce APCC's potential negative impact. This work highlights critical vulnerabilities in IPv6 infrastructure while advancing robust covert communication methodologies for high-stakes scenarios. Zhaoan Wang, Lin He 0004, Daguo Cheng, Ying Liu 0024 |
IWQoS | 3 |
| 2024 | Luori: Active Probing and Evaluation of Internet-Wide IPv6 Fully Responsive PrefixesabstractWith the large-scale deployment and application of IPv6, IPv6 network measurements will become increasingly important. However, a special type of IPv6 prefix called Fully Responsive Prefix (FRP) is having a significant impact on IPv6 measurement campaigns, which is defined as all addresses under a prefix responding to scans. Obviously, there cannot be a real responder behind each of these addresses. To reveal the current status and impact of Internet-wide IPv6 FRPs, we propose for the first time an active probing method for Internet-wide IPv6 FRPs, Luori, which transforms the active probing process under IPv6 huge prefix space (potential range of prefix presence) into a dynamic search process in a tree based on reinforcement learning, achieving efficient probing of arbitrary routing prefixes. The evaluation results show that Luori found 31.7K largest FRPs in a single Internet-wide probing with 11 M budget, covering$1.5 \times 10^{30}$address space, which is$10^{6} \times$that of existing methods. More importantly, after six months of Internet-wide probing, we have found 516 K largest FRPs, which covers$1.3 \times 10^{33}$address space and 795 ASes, making it the largest publicly known FRP list. Based on this list, we screen out$20 \%$of the addresses covered by FRPs from a well-known IPv6 active address dataset. Furthermore, we further analyze and find that the distribution of these FRPs is extensive and their implementation methods are diverse, which can provide beneficial references for the practical application of FRPs. We also make this list publicly available and maintain it long-term for use and study by relevant researchers. Daguo Cheng, Lin He 0004, Chentian Wei, Qilei Yin, Boran Jin, Zhaoan Wang, Xiaoteng Pan, Sixu Zhou, Ying Liu 0024, Shenglin Zhang, Fuchao Tan, Wenmao Liu |
ICNP | 1 |
| 2023 | Efficient and Robust KPI Outlier Detection for Large-Scale DatacentersabstractTo ensure the performance of large-scale datacenters, operators need to monitor up to tens of millions of various-type KPIs, e.g., CPU utilization, memory utilization. For each KPI, it is crucial but challenging to detect outliers that deviate from its historical patterns or the patterns of other KPIs in the same period. In this work, we proposeOutSpot, an unsupervised outlier detection framework that integrates hierarchical agglomerative clustering (HAC) with conditional variational autoencoder (CVAE), which significantly improves computational efficiency and comprehensively learns the above two patterns. Additionally, two simple yet effective techniques, soft threshold and median filter, are applied to precisely determine outlier KPIs. Using two real-world datasets collected from the datacenters owned by a top-tier global short video service provider and a top-tier domestic operator,respectively. It demonstrates thatOutSpotachieves the best F1 score of 0.95 and 0.91, AUC of 0.99 and 0.99 on the two datasets, significantly outperforming seven baseline outlier detection methods. Yongqian Sun, Daguo Cheng, Tiankai Yang 0001, Yuhe Ji, Shenglin Zhang, Man Zhu, Xiao Xiong, Qiliang Fan, Minghan Liang, Dan Pei, Tianchi Ma |
IEEE Trans. Computers | 2 |
| 2023 | Robust Anomaly Clue Localization of Multi-Dimensional Derived Measure for Online Video ServicesabstractAnomaly clue localization of multi-dimensional derived measure is vitally important for the reliability of online video services. In this paper, we propose RobustSpot, an end-to-end framework for localizing the clues to anomalous multi-dimensional derived measures. RobustSpot integrates two novel indicators, i.e., “Anomaly Degree” and “Contribution Ability”, with a simple yet effective method, weighted association rule mining (WARM), to automatically mine the hidden relationships across data dimensions for localizing the most likely clues to the root cause. Using 135 real-world cases collected from a top-tier global online video service provider$H$with 170+ million monthly active users, we demonstrate that RobustSpot achieves high accuracy (Top-5 accuracy of 98%), significantly outperforming state-of-the-art methods. The average localization time of RobustSpot is 1.83s, which is satisfying in our scenario. We have open-sourced the implementation of RobustSpot as well as the data used in the evaluation experiments. Yongqian Sun, Daguo Cheng, Pengxiang Jin, Quan Ding, Shenglin Zhang, Xu Chen 0054, Minghan Liang, Dan Pei, Jianyan Zheng, Sen Luo |
IEEE Trans. Serv. Comput. | 2 |