EDBT 2026 Demo / reviewers in the wild / expert
Xinghai Wei
dblp:356/8791
· DBLP profile ↗
9ranked-venue papers
4as first author
9since 2021 · last 2026
0009-0002-8063-1103ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 3 first-author · 4 since 2021Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GZTrust: Topology-Aware Trust Management for IoT Networks Under Zero Trust PrinciplesabstractDue to the large-scale, dynamic topology and multi-hop communication characteristics of Internet of Things (IoT) systems, trust management has become a critical requirement for secure and reliable network operation. However, existing trust management schemes generally rely on endpoint-centric observations or centralized evidence aggregation, making them poorly suited to realistic IoT deployments with partial observability. In particular, performance degradations caused by compromised intermediate nodes or unstable links are often misattributed to benign devices, leading to distorted trust evaluation and inefficient trust-based control. To address these challenges, this study proposes a topology-aware trust management framework (GZTrust) for multi-hop IoT networks designed in accordance with Zero Trust principles. The GZTrust framework introduces a structured separation between trust evidence generation, trust reasoning, and trust-driven control. In the data plane, a TrustTrace mechanism is employed to incrementally collect hop-level trust evidence along forwarding paths with verifiable integrity and privacy-preserving pseudonyms. In the trust plane, dynamically selected policy enforcement points (PEPs) aggregate localized evidence in a topology-aware manner to avoid flat centralized processing. To accurately evaluate trust, this study designs an attribution-aware trust computation model that decomposes hop-level anomalies into node-centric and link-centric responsibility components. Extensive simulation results demonstrate that GZTrust consistently outperforms state-of-the-art trust management schemes, improving the F1-score by approximately 6–13% across varying malicious node ratios (5%–50%). These results indicate that GZTrust provides a practical and scalable trust management framework for dynamic multi-hop IoT environments, with a lightweight overhead profile that is well aligned with resource-constrained deployment settings. Xingwu Wang, Jie Yuan 0001, Xinghai Wei, Keji Miao |
IEEE Internet Things J. | 4 |
| 2026 | Enhancing Learning to Communicate With Reward-Shaped Curriculum and Network Awareness
Xinghai Wei, Jie Yuan 0001, Tingting Yuan 0001, Xiang Liu 0004, Xiaoming Fu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2026 | PanQoSR: Leveraging Path-Aware Network for Fine-Grained QoS RoutingabstractQuality of Service (QoS) routing is a critical technique for delivering differentiated services under limited network resources to meet the specific requirements of endpoint applications. Despite the development of various routing algorithms and management architectures, achieving fine-grained QoS optimization within existing networks remains challenging due to the lack of endpoint control over routing decisions. This paper introduces PanQoSR, the first application of path-aware networks (PAN) in QoS routing. PanQoSR leverages the inherent capabilities of PAN by offloading path computation and selection to the endpoint, enabling flow-level fine-grained QoS optimization. PanQoSR addresses several key challenges in applying PAN to QoS routing. First, by leveraging existing network technologies and protocols, PanQoSR remains fully compatible with legacy networks without requiring significant modifications. Second, by introducing an ε−Constraint Pathfinding (ε−CP) algorithm for intra-AS path computation and a Nonlinear Cost Pathfinding (NCP) algorithm for inter-AS path computation, PanQoSR achieves both high QoS guarantees and computational efficiency. Experimental results show that PanQoSR reduces QoS violation rates by up to 70.8% compared to baselines, while also decreasing inter-AS path computation time by 22.4% to 65.6%. Xinghai Wei, Jie Yuan 0001, Tingting Yuan 0001, Xiang Liu 0004, Keji Miao |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | 1BIT: Persistent Path Validation with Customized Noise Signal CharacteristicsabstractPath-aware networks have garnered significant attention as an emerging research area. It allows network senders to actively select or influence transmission paths to meet specific requirements, which necessitates the support of path validation mechanisms. Supported by the path-aware networking research group under the Internet Engineering Task Force (IETF), path validation plays a crucial role in enhancing end hosts' control over packet forwarding. However, existing methods face trade-offs among security, protocol header overhead, and computational cost, forming a ''trilemma.'' Drawing inspiration from persistent validation in zero-trust architecture, we propose the 1BIT protocol. This protocol reduces protocol header overhead by more than 57% while providing robust data flow security. The packet demand for path fault detection is reduced by more than 72%, and fault locations can be precisely identified. By employing hash algorithms and few binary operations, the 1BIT protocol achieves high throughput and supports routers capable of adapting to high-speed, multi-interface environments. On a 16-core CPU, the 1BIT protocol can handle throughput exceeding 100 Gbps. This lightweight and efficient solution introduces anomaly signal detection techniques into the field of path validation. Benefiting from in-depth research on anomaly signal detection, this technology offers a richer set of solutions for path validation and lays the foundation for future research and implementation in areas such as multi-path validation and path privacy protection. Keji Miao, Jie Yuan 0001, Xinghai Wei, Xingwu Wang, Runshan Hu, Xiaoyong Li 0003, Zitong Jin |
CCS | 3 |
| 2025 | IB-SC: Simplify Key Management to Enable Quick Start for Short-session Path ValidationabstractIn the current Internet architecture, path validation protocols enable the source host to accurately trace the forwarding path of packets, thereby preventing degradation in the quality and security of network services. However, these protocols typically rely on Public Key Infrastructure (PKI), which can theoretically result in a storage overhead of at least 64 PB. To address this issue, we propose an Identity-Based Path Validation Protocol (IB-SC). This protocol leverages a trusted third party equipped with a public-private key pair to distribute identity keys to network nodes. The identities of these nodes, along with the public key of the third party, are used to validate packet signatures. Furthermore, we designed a Source Commitment (SC) mechanism that commits to parameters of future packets to further enhance the performance of the IB-SC protocol. Evaluation results demonstrate that the IB-SC protocol eliminates the overhead associated with PKI and session key management. Compared to the Atomos protocol, which provides similar security levels, IB-SC reduces the signature space overhead by 73.4%, the packet construction and processing delay by 8.4% and 62.1%. Keji Miao, Xinghai Wei, Jie Yuan 0001, Tieyan Li |
ICDCS | 2 |
| 2025 | ReSCOM: Reward-Shaped Curriculum for Efficient Multi-Agent Communication Learning
Xinghai Wei, Tingting Yuan 0001, Jie Yuan 0001, Xiaoming Fu 0001 |
AAMAS | 1 |
| 2025 | Rlaph: a lightweight and dynamic proactive defense method in cloud-edge collaborationabstractAbstract In cloud-edge collaboration scenarios, attackers pose significant security risks by compromising computational nodes and using them to infiltrate other nodes and networks. Ensuring the security of cloud-edge collaboration is crucial for protecting sensitive data, preventing disruptions to critical services, and safeguarding infrastructure in increasingly interconnected and digitized societies. Traditional passive defense mechanisms are often inadequate in dealing with the complex and dynamic nature of modern network threats. In recent years, Moving Target Defense (MTD) has become an important research direction, disrupting adversaries’ reconnaissance and exploitation phases by dynamically shuffling the attack surface. However, existing MTD strategies have some shortcomings, such as single-dimensional movement strategies, poor flexibility and a lack of historical information analysis. To overcome these challenges, we propose a reinforcement learning-based approach for host address and port hopping (RLAPH). First, the approach strengthens system security through coordinated decision-making across IP address and port, leveraging both historical data and current information to make accurate and adaptive decisions. Second, a reward function is carefully designed to balance the trade-off between system overhead and security. Finally, validation experiments conducted in a simulated environment show that the proposed method effectively enhances defense performance while minimizing system overhead, highlighting its robustness and applicability. Yingbo Li, Jie Yuan 0001, Faqun Jiang, Xiang Liu 0004, Xinghai Wei, Xiaoyong Li 0003 |
Cybersecur. | 6 |
| 2025 | BiTrust: Hybrid Trust Management for Secure Data Transmission in LEO Satellite NetworksabstractDue to characteristics such as the openness and exposure of inter-satellite links, Low-Earth Orbit (LEO) satellite networks are subject to heightened vulnerability to malicious attacks compared to ground-based networks. Given various security risks, implementing trust management in LEO satellite networks becomes imperative. However, existing trust management schemes tailored for this scenario are vulnerable to a spectrum of attacks, resulting in low detection rates and poor network performance. To address the above issues, we propose BiTrust, a hybrid trust management scheme for secure data transmission in LEO satellite networks. BiTrust introduces two distinct types of trust: state trust and behavior trust. State trust leverages remote attestation technology to verify the authenticity of node identities and the integrity of their functions, ensuring that nodes consistently disseminate reliable behavior trust announcements to safeguard the trust plane. Behavior trust, on the other hand, utilizes a trust model to quantify the real-time data forwarding behavior characteristics of nodes, thereby maintaining the reliability of the data plane. To precisely quantify behavior trust, we design a trust model based on multi-path trust propagation. By integrating an unstable penalty term, the proposed trust model can effectively defend against dynamic dropping misbehavior. Besides, to facilitate the deployment of BiTrust in a distributed manner, we introduce a two-hop rely message mechanism and a query-answer mechanism to support the construction of behavior trust. Experimental results confirm the efficacy of BiTrust, demonstrating a significant improvement of up to 64.3% in data transmission rate under highly untrusted environments while maintaining affordable overhead. Xinghai Wei, Jie Yuan 0001, Runshan Hu, Xiang Liu 0004, Xingwu Wang |
IEEE Internet Things J. | 1 |
| 2024 | TVRAVNF: an efficient low-cost TEE-based virtual remote attestation scheme for virtual network functionsabstractAbstract With the continuous advancement of virtualization technology and the widespread adoption of 5G networks, the application of the Network Function Virtualization (NFV) architecture has become increasingly popular and prevalent. While the NFV architecture brings a lot of advantages, it also introduces security challenges, including the effective and efficient verification of the integrity of deployed Virtual Network Functions (VNFs) and ensuring the secure operation of VNFs. To address the challenge of efficiently conducting virtual remote attestation for VNFs and establishing trust in virtualized environments like NFV architecture, we propose TVRAVNF, which is a highly efficient and low-cost TEE-based virtual remote attestation scheme for VNFs. The scheme we proposed ensures the security and effectiveness of the virtual remote attestation process by leveraging TEE. Furthermore, we introduces a novel local attestation mechanism, which not only reduces the overall overhead of the virtual remote attestation process but also shortens the attestation interval to mitigate Time-Of-Check-Time-Of-Use attacks, thereby enhancing overall security. We conduct experiments to validate the overhead of the TVRAVNF scheme and compare its performance with that of a typical remote attestation process within a maximum unattested time interval. The experimental results demonstrate that, by employing the local attestation mechanism, our solution achieves nearly an 80% significant performance improvement with a relatively small time overhead for small to medium-sized files. This further substantiates the significant advantages of our approach in both security and efficiency. Jie Yuan 0001, Xinghai Wei, Keji Miao |
Cybersecur. | 3 |