Chenlin Huang

dblp:40/3697 · DBLP profile ↗
← Back
22ranked-venue papers
2as first author
13since 2021 · last 2026
0000-0002-6792-1651ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 1 first-author · 4 since 2021Security and privacy · 5 · 1 first-author · 4 since 2021Computer networks · 3 · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 EviGPU: An Evidence Collection Framework for GPU-TEEs
Yuncong Ma, Hongjing Song, Chenlin Huang
ICIC (11)4
2025 MetaCAN: Improving Generalizability of Few-shot Anomaly Detection with Meta-learning
abstract
Few-shot Anomaly Detection (AD) for images aims to detect anomalies with few-shot normal samples from the target dataset. It is a crucial task when only few samples can be obtained, and it is challenging since it needs to be generalized to different domains. Existing methods try to enhance the generalizability of AD by incorporating large vision-language models (LVLMs).However, how to transform category semantic information in LVLMs into anomaly information to improve the generalizability of AD remains a challenge facing existing methods.To address the challenge, we propose a few-shot AD method called MetaCAN, a novel category-to-anomaly network trained with AD meta-learning scheme based on an LVLM. Specifically, MetaCAN constructs the auxiliary training data and multiple tasks based on different categories to perform AD meta-learning, which ensures that the optimization toward the achievement of optimal anomaly detection across all categories. Moreover, MetaCAN introduces an image-image anomaly discriminator and an image-text anomaly detector to fully exploit the powerful multimodal semantic representations during auxiliary training. Once trained on auxiliary datasets, MetaCAN can be applied directly to other target datasets without retraining. Extensive experiments on six real-world datasets demonstrate that MetaCAN achieves state-of-the-art performance on cross-domain and cross-category anomaly detection tasks compared with existing methods.
Zhisheng Lv, Songlei Jian, Chenlin Huang, Guansong Pang, Zhong Liu 0003
CIKM4
2025 Heterogeneity-Aware Two-Tier GPU Resource Scheduling for Machine Learning Tasks
abstract
The widespread use of machine learning (ML) tasks has led to a rapid expansion of GPU clusters. Heterogeneous GPUs exhibit different performance characteristics across ML tasks, which leads to challenges for resource scheduling. As cluster scale expands, computational overhead for resource allocation grows while overall utilization remains low. Existing schedulers also lack adaptability and flexibility to different workloads and users requirements. In this work, we design a two-tier allocation framework, Gsched. We introduce an allocation metric, classify-put, to measure the relationship between tasks and GPUs. Based on classifyput, we propose a grouping mechanism, which breaks down ML tasks and GPU resource into smaller and parallel groups. In each group, we can use different scheduling policies and optimize parameters of ML tasks. Gsched can maintain high resource allocation efficiency while reducing computational overhead. Experimental results have shown that our framework achieves the best performance in most cases, reducing the average task completion time by up to 50% and tail latency by up to 15% compared with other advanced schedulers. The scheduling computational overhead can be reduced by several orders of magnitude.
Xilong Gu, Bao Li 0002, Chunbo Jia, Chenlin Huang
HPCC7
2025 Octopus: Decentralized Workflow-granular Scheduling for Serverless Workflow
abstract
With the continuous development of Serverless Computing, Serverless applications composed of multiple finegrained functions have been widely applied in various fields of real life. As a pre-defined logical abstraction of Serverless applications, Serverless Workflow describes the dependencies and data flow between functions, and is the mainstream paradigm of modern Serverless Computing. However, our investigation shows that traditional Master-Worker-based, function-granular Serverless Workflow Management Systems are no longer suitable for the multi-function composition and unpredictable high concurrency characteristics of current Serverless Workflow. The seemingly insignificant scheduling overhead of Serverless Workflows has become a non-trivial factor affecting the execution efficiency and scalability of Serverless Workflows. Therefore, we proposed a workflow-granular management paradigm and decentralized control to address these challenges. Following these methodologies, we implement Octopus to enable efficient workflow scheduling and execution across different levels of concurrency and cluster scales. Experiments indicate that, in high-concurrency environments, Octopus achieves up to a 90× reduction in scheduling overhead and can enhance execution efficiency by 7.5×. As the cluster size increases, Octopus shows acceptable overhead and high scalability.
Keming Wang, Liaoliao Feng, Ligang He, Chenlin Huang, Tao Xie 0012
ICDCS4
2025 LASEFlow: A Label-Aware Security Enhancement Framework for Serverless Workflows
abstract
Serverless computing has gained widespread popularity among developers due to its low cost, fine-grained deployment, and management-free operation. However, when deploying serverless applications in practice, a single function is often insufficient to fulfill complete application requirements. This has led to the emergence of serverless workflows, which orchestrate a series of related serverless functions according to predefined logic. Through our investigation of existing serverless workflow platforms, we identify two major security limitations. First, current serverless workflows cannot guarantee execution integrity—they are unable to detect changes in the function execution order and lack mechanisms to defend against workflow-targeted denial-of-service (DoS) attacks. Second, identity management is typically coarse-grained, often resulting in over-privileged access and lacking support for function-level access control.To address these issues, we propose and implement the LASEFlow, a label-aware security enhancement framework for serverless workflows. A sequential function execution chain is designed based on the Platform Configuration Register (PCR) technique to guarantee the integrity of the execution of workflow in LASEFlow. In addition, a fine-grained function-level access control mechanism is designed to prevent privilege abuse in work-flows. The evaluation demonstrates the effectiveness of LASEFlow against workflow attacks, with an overhead of less than 4% in performance.
Keming Wang, Chenlin Huang, Renyu Yang, Mantun Chen
TrustCom3
2024 X-EDF: An Efficient Defensive Deception Framework against Reconnaissance Attacks
abstract
Deception techniques are increasingly recognized as trans-formative in the realm of cyber defense. With the advent of sophisticated, large-scale scanning technologies such as ZMap, attackers can swiftly pinpoint active and vulnerable ports on edge nodes. Given the diversity of these nodes, a versatile security tool adaptable to various deployment environments is essential. Moreover, edge nodes often encounter performance constraints, necessitating a defense strategy that balances cost-effectiveness for defenders. In response to these challenges, we introduce the X-EDF: an eXpress Data Path (XDP)-based Efficient Defensive De-ception Framework. This framework facilitates an efficient and lightweight deceptive defense leveraging XDP technology. The X-EDF can efficiently respond to attackers' scanning requests with deceptive messages before these requests enter the protocol stack, thus achieving deception defense at a minimal cost. We have validated the effectiveness of our defense strategy through game-theoretic proofs and real-world network deployments.
Zhihang Zhang, Chenlin Huang, Yan Ding 0004, Jinzhu Kong, Qing Liao 0001, Pan Dong, Haifang Zhou
MSN2
2023 LogRep: Log-based Anomaly Detection by Representing both Semantic and Numeric Information in Raw Messages
abstract
Log-based anomaly detection plays an essential role in various system reliability-related fields including software reliability, network reliability, and so on. System log data is a kind of semi-structured heterogeneous data that contains both semantic parts and numeric variables which both reflect the abnormal behavior of the system. However, existing log-based anomaly detection methods fail to capture the numeric information in raw data which makes them degrade a lot when only limited labeled data is available. To comprehensively capture the semantic and numeric information to enhance anomaly detection, we propose LogRep, a novel representation-based log anomaly detection method that captures both semantic and numeric information in the learned representations. The newly proposed position-aware numeric representation learning module and the attention-based representation fusion module in LogRep solve the heterogeneity problem well in log data. Due to the high quality of learned log representation, LogRep can achieve a comparable anomaly detection performance with SOTA methods while the training data used in LogRep is two orders of magnitude less than that used in SOTA methods. When reducing the training data scale, the performance of SOTA methods drops a lot, while LogRep keeps a stable good performance on two public HDFS dataset, BGL dataset, and one self-collected dataset. Specifically, LogRep achieves the 10.6% and 5.8% improvements over the second-best method in terms of F1 score on the BGL and HDFS datasets when only 1% training data are available respectively.
Xiaoda Xie, Songlei Jian, Chenlin Huang, Yunjia Deng
ISSRE3
2023 Robust unsupervised network intrusion detection with self-supervised masked context reconstruction
Wei Wang 0130, Songlei Jian, Yusong Tan, Qingbo Wu 0003, Chenlin Huang
Comput. Secur.5
2022 SEED: Semantic Graph Based Deep Detection for Type-4 Clone
Zhipeng Xue 0002, Zhijie Jiang, Chenlin Huang, Rulin Xu, Xiangbing Huang, Liumin Hu
ICSR3
2022 An Optimized Isomorphic Design for the SM4 Block Cipher Over the Tower Field
abstract
The SM4 block cipher is Chinese domestic cryptography widely used to secure data confidentiality. Its performance is a key indicator in measuring the efficiency of encryption and decryption in large-scale data scenarios. In traditional tower field optimization, the paired forward and backward linear filed transformations are sandwiched between S-boxes and L-boxes for every round of the encryption operation, which introduces heavily burdensome computation times and complexity. In this paper, we propose a novel isomorphic design for the SM4 round function, where all operations are remaining in the tower filed through multiple rounds, and the paired forward and backward field transformations in each round can be omitted. Based on the isomorphic design, we introduce a more flexible fine-grained bitsliced scheme for the SM4 block cipher with the SIMD instructions, requiring only 32 independent data blocks to be processed in parallel. The experiments show that the proposed isomorphic design for the round function is superior to the traditional design, and the fine-grained bitsliced SM4 implementation on the server device and terminal device achieved 6.4 and 17.2 cycles per byte respectively, showing a performance increase of 284.3% and 54.4% compared to OpenSSL implementation(24.7 and 26.6 cycles per byte respectively).
Chenlin Huang, Liantao Song
TrustCom3
2022 Representation learning-based network intrusion detection system by capturing explicit and implicit feature interactions
Wei Wang 0130, Songlei Jian, Yusong Tan, Qingbo Wu 0003, Chenlin Huang
Comput. Secur.5
2021 DRAM Failure Prediction in Large-Scale Data Centers
abstract
Cloud computing is developing rapidly. Data centers are important infrastructures of cloud service and JointCloud structure. DRAM failure is one of the main causes which can lead to node outage in data centers. This paper proposes a decision-tree-based DRAM failure prediction method for large-scale data centers of cloud service. We utilize the first public-available DRAM failure prediction dataset released in PAKDD 2021 AIOps competition. We construct a suite of handcrafted features based on the system kernel log data and MCA log data. Feature engineering is detailedly introduced in this paper, which can inspire and foster future research in this field. Harnessing the power of a state-of-the-art classifier (i.e., XGBoost), our method can effectively and timely predict DRAM failures. Our solution has good performance on the PAKDD 2021 dataset, it can generally achieve more than 60% precision in the validation phase. Extensive experiments investigate the performance of variants of our method to validate the significance of different strategies in the proposed solution.
Hongzuo Xu, Songlei Jian, Chenlin Huang, Yijie Wang 0001, Zhiyue Wu
JCC4
2021 Toward security as a service: A trusted cloud service architecture with policy customization
Chenlin Huang, Wei Chen 0009, Songlei Jian, Yusong Tan, Dan Chen 0001
J. Parallel Distributed Comput.1
2020 SLR-SELinux: Enhancing the Security Footstone of SEAndroid with Security Label Randomization
abstract
The root privilege escalation attack is extremely destructive to the security of the Android system. SEAndroid implements mandatory access control to the system through the SELinux security policy at the kernel mode, making the general root privilege escalation attacks unenforceable. However, malicious attackers can exploit the Linux kernel vulnerability of privilege escalation to modify the SELinux security labels of the process arbitrarily to obtain the desired permissions and undermine system security. Therefore, investigating the protection method of the security labels in the SELinux kernel is urgent. And the impact on the existing security configuration of the system must also be reduced. This paper proposes an optimization scheme of the SELinux mechanism based on security label randomization to solve the aforementioned problem. At the system runtime, the system randomizes the mapping of the security labels inside and outside the kernel to protect the privileged security labels of the system from illegal obtainment and tampering by attackers. This method is transparent to users; therefore, users do not need to modify the existing system security configuration. A tamper-proof detection method of SELinux security label is also proposed to further improve the security of the method. It detects and corrects the malicious tampering behaviors of the security label in the critical process of the system timely. The above methods are implemented in the Linux system, and the effectiveness of security defense is proven through theoretical analysis and experimental verification. Numerous experiments show that the effect of this method on system performance is less than 1%, and the success probability of root privilege escalation attack is less than 10−9.
Pan Dong, Yusong Tan, Chenlin Huang, Lifeng Wei, Yudan Zuo
Wirel. Commun. Mob. Comput.5
2016 Developing the Cloud-integrated data replication framework in decentralized online social networks
Songling Fu, Ligang He, Xiangke Liao, Chenlin Huang
J. Comput. Syst. Sci.4
2015 Performance Optimization for Managing Massive Numbers of Small Files in Distributed File Systems
abstract
The processing of massive numbers of small files is a challenge in the design of distributed file systems. Currently, the combined-block-storage approach is prevalent. However, the approach employs the traditional file systems such as ExtFS and may cause inefficiency when accessing small files randomly located in the disk. This paper focuses on optimizing the performance of data servers in accessing massive numbers of small files. We present a Flat Lightweight File System (iFlatLFS) to manage small files, which is based on a simple metadata scheme and a flat storage architecture. iFlatLFS is designed to substitute the traditional file system on data servers and can be deployed underneath distributed file systems that store massive numbers of small files. iFlatLFS can greatly simplify the original data access procedure. The new metadata proposed in this paper occupies only a fraction of the metadata size based on traditional file systems. We have implemented iFlatLFS in CentOS 5.5 and integrated it into an open source Distributed File System (DFS), called Taobao FileSystem (TFS), which is developed by a top B2C service provider, Alibaba, in China and is managing over 28.6 billion small photos. We have conducted extensive experiments to verify the performance of iFlatLFS. The results show that when the file size ranges from 1 to 64 KB, iFlatLFS is faster than Ext4 by 48 and 54 percent on average for random read and write in the DFS environment, respectively. Moreover, after iFlatLFS is integrated into TFS, iFlatLFS-based TFS is faster than the existing Ext4-based TFS by 45 and 49 percent on average for random read access and hybrid access (the mix of read and write accesses), respectively.
Songling Fu, Ligang He, Chenlin Huang, Xiangke Liao, Kenli Li 0001
IEEE Trans. Parallel Distributed Syst.3
2014 Modelling and Predicting the Data Availability in Decentralized Online Social Networks
abstract
Maintaining data availability is one of the biggest challenges in Decentralized Online Social Networks (DOSN). In the existing work of improving data availability in DOSN, it is often assumed that the friends of a user are always capable of contributing sufficient storage capacity to store all the data published by the user. However, this assumption is not always true for today's Online Social Networks (OSNs) for the following reasons. On one hand, the increasingly more data are being generated on the OSNs nowadays. On the other hand, current users often use the smart mobile devices to access the OSNs. These two factors cause the shortage of the storage capacity in DOSN, where the published data are supposed to be stored within a friend circle. The limitation of the storage capacity may jeopardize the data availability. Therefore, it is desired to know the relation between the storage capacity contributed by the OSN users and the level of data availability that the OSN can achieve. This paper addresses this issue. In this paper, the data availability model over storage capacity is established. Further, a novel method is proposed to predict the data availability on the fly. Extensive simulation experiments have been conducted to evaluate the effectiveness of the data availability model and the on-the-fly prediction. The data availability model can be used by the OSN designers to determine the storage capacity for the published data in order to achieve the desired data availability. The on-the-fly prediction method can help the data replication and storage policies make judicious decisions at runtime.
Songling Fu, Ligang He, Xiangke Liao, Chenlin Huang, Kenli Li 0001, Bo Gao 0001
ICWS4
2013 iFlatLFS: Performance optimization for accessing massive small files
abstract
The processing of massive small files is a challenge in the design of distributed file systems. Currently, the combined-block-storage approach is prevalent. However, the approach employs traditional file systems like ExtFS and may cause inefficiency for random access to small files. This paper focuses on optimizing the performance of data servers in accessing massive small files. We present a Flat Lightweight File System (iFlatLFS) to manage small files, which is based on a simple metadata scheme and a flat storage architecture. iFlatLFS aims to substitute the traditional file system on data servers that are mainly used to store small files, and it can greatly simplify the original data access procedure. The new metadata proposed in this paper occupies only a fraction of the original metadata size based on traditional file systems. We have implemented iFlatLFS in CentOS 5.5 and integrated it into an open source Distributed File System (DFS), called Taobao FileSystem (TFS), which is developed by a top B2C service provider, Alibaba, in China and is managing over 28.6 billion small photos. We have conducted extensive experiments to verify the performance of iFlatLFS. The results show that when the file size ranges from 1KB to 64KB, iFlatLFS is faster than Ext4 by 48% and 54% on average for random read and write in the DFS environment, respectively. Moreover, after iFlatLFS is integrated into TFS, iFlatLFS-based TFS is faster than the existing Ext4-based TFS by 45% and 49% on average for random read access and hybrid access (the mix of read and write accesses), respectively.
Songling Fu, Chenlin Huang, Ligang He, Nadeem Chaudhary, Xiangke Liao, Shazhou Yang, Bao Li 0002
HiPC2
2012 Modeling and analyzing the impact of authorization on workflow executions
Ligang He, Chenlin Huang, Kewei Duan, Kenli Li 0001, Hao Chen 0002, Jianhua Sun 0002, Stephen A. Jarvis
Future Gener. Comput. Syst.2
2011 Modelling and analyzing the authorization and execution of video workflows
abstract
It is becoming common practice to migrate signal-based video workflows to IT-based Video workflows. Video workflows have some inherent features, including: 1) necessary human involvements in video workflows introduce security and authorization concerns; 2) the frequent change of video workflow contexts requires a flexible approach to acquiring performance data; 3) the content-centric nature of video workflows, which is in contrast to the business-centric of business workflows, requires the support of scheduled activities. This paper takes the above issues into account, proposing a novel mechanism for modeling video workflow executions in cluster-based resource pools under Role-Based Authorization Control (RBAC) schemes. The Color Timed Petri-Net (CTPN) formalism is applied to construct the models. Various types of authorization constraint are modeled in this paper, and scheduled activities are also supported in the model. There is a clear interface between workflow execution and workflow authorization modules. The constructed models are then simulated and analyzed to obtain performance data, including authorization overhead, system- and application-oriented performance. Based on the model analysis, this paper further proposes the methods to improve performance in the presence of authorization policies. This work can be used to plan system capacity subject to the authorization control, and can also be used to tune performance by changing the scheduling strategy and resource capacity when it is not possible to adjust the authorization policies.
Ligang He, Chenlin Huang, Kenli Li 0001, Hao Chen 0002, Jianhua Sun 0002, Bo Gao 0001, Kewei Duan, Stephen A. Jarvis
HiPC2
2010 Efficient and fine-grained sharing of encrypted files
abstract
In this work, we present an efficient fine-grained sharing approach of encrypted files. A concept named safe capsule (SC) is proposed as the organization unit for files. By using safe capsule, user can provide one of the fine-grained access permissions of their own data to others, such as read-only. Data are encrypted(decrypted) transparently when writing(reading) to keep its privacy.
Songling Fu, Xiangke Liao, Lianyue He, Chenlin Huang, Xiaodong Tang
IWQoS4
2006 A Dynamic Trust Model Based on Feedback Control Mechanism for P2P Applications
Chenlin Huang, Huaping Hu, Zhiying Wang 0003
ATC1