EDBT 2026 Demo / reviewers in the wild / expert
Jun'e Li
dblp:41/7676 · also June Li
· DBLP profile ↗
8ranked-venue papers
0as first author
8since 2021 · last 2025
0000-0003-1967-7743ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 4 since 2021Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | HARS:A Dynamic Scheduling Algorithm for Redundant Executors Based on Weighted Hypergraph HeterogeneityabstractExisting scheduling methods for redundant executors in mimic defense systems often lack dynamism and typically only consider second-order heterogeneity. This limitation makes systems vulnerable to attacks that exploit common-mode vulnerabilities. Furthermore, these methods fail to differentiate the varying threat levels posed by common-mode vulnerabilities of different orders, consequently overestimating low-order risks while underestimating high-order ones. To address these issues, this paper proposes an efficient dynamic scheduling algorithm based on weighted hypergraph heterogeneity, named HARS(Hypergraph-based Amplified Risk Scheduling). For the first time, we accurately model the executor-vulnerability relationships in a Dynamic Heterogeneous Redundancy (DHR) system as a weighted hypergraph, where hyperedges intuitively represent common-mode vulnerabilities. By introducing a risk weight function, our model achieves differentiated and amplified measurement of high-order security risks. The scheduling decision is then transformed into a graph-theoretic optimization problem that can be approximately solved in polynomial time. We further develop an efficient heuristic greedy algorithm, fundamentally resolving the exponential complexity bottleneck associated with high-order heterogeneity computation. Simulation results demonstrate that the proposed HARS algorithm not only inherits the negative feedback mechanism but also achieves a superior trade-off between security and system performance through more precise and efficient high-order heterogeneity calculations. Xinjian Zhao, Zesheng Xi, Jun'e Li, Xu Zhong |
TrustCom | 4 |
| 2025 | IRMAOC: an interpretable role mining algorithm based on overlapping clusteringabstractAbstract The Industrial Internet motivates the research and development of Zero-Trust Architecture (ZTA). Role-Based Access Control (RBAC) as one of the key technologies for ZTA has become a hot topic. Role mining algorithms are crucial for RBAC and interpretable role mining receives wide attention due to its virtue of mining meaningful roles. However, the roles generated by existing algorithms have low interpretability and high time complexity, limiting their application in practice. This paper proposes an Interpretable Role Mining Algorithm Based on Overlapping Clustering (IRMAOC). It evaluates the interpretability of a role based on user similarity calculated on the permission and attribute of the role, and employs policy interpretability as the metric of a role set. IRMAOC creates a user association graph and clusters to generate candidate roles based on the graph. Then it remains the roles whose interpretability is higher than the preset threshold and re-clusters the users belonging to the other roles until the interpretability of all roles are higher than the threshold. Experimental results show that our algorithm significantly improves the interpretability of roles, reduces the Weighted Structure Complexity (WSC), and decreases time complexity compared to previous works. Yaqi Yang, Jun'e Li, Guirong Huang, Zhuo Lv |
Cybersecur. | 2 |
| 2025 | Research on improving the robustness of spatially embedded interdependent networks by adding local additional dependency links
Zhengcheng Dong, Jun'e Li |
Expert Syst. Appl. | 4 |
| 2025 | Cyber-Physical-Social Security of High-DER-Penetrated Smart Grids: Threats, Countermeasures, and ChallengesabstractWith the trend of large‐scale renewable distributed energy sources (DERs) penetrating into the smart grids (SGs), the SGs entail heavy reliance on information and communication technologies (ICT) and increasing impact of social behaviors on system operation and management. The SGs can be viewed as cyber–physical–social systems (CPSSs). However, the deep coupling of cyber, physical, and social spaces leads the SGs to be more complex and openness, and thus, a higher risk of exposure to various threats. To study the threats, countermeasures, and challenges of the high‐DER‐penetrated SGs from a cyber–physical–social perspective, the key features of the SGs on devices, networks, and applications are first analyzed. On this basis, the threats faced by the SGs due to the widespread deployment of terminal devices, open network environments, and the increasing importance of social behaviors are analyzed. Subsequently, the limitations of the deployed security measures in current power systems are discussed, and an overview of the state‐of‐art countermeasures for the SGs security faced by the threats is organized in three stages: prevention, detection, and mitigation. Finally, the research challenges, key gaps, and future directions for security enhancement of the SGs are also discussed. Qiuyu Lu, Jun'e Li |
IET Inf. Secur. | 2 |
| 2024 | Detecting the cyber-physical-social cooperated APTs in high-DER-penetrated smart grids: Threats, current work and challenges
Qiuyu Lu, Jun'e Li, Jianbo Luo |
Comput. Networks | 2 |
| 2024 | Distributed cyber-physical intrusion detection using stacking learning for wide-area protection systemabstractWide-area protection systems (WAPSs) heavy depends on communication technologies to operate, which leaves space for cyberattacks. A well-designed stealthy and coordinated cyberattacks can disrupt the seamless operation of WAPS by compromising measurement signals, control signals, or both. In this paper, we present a distributed cyber-physical intrusion detection system (DCPIDS) that utilizes the bilateral data from both the cyber side and the physical side to accurately detect cyberattacks on both measurement and control signals in WAPSs. DCPIDS consists of multiple slave agents (SAs) scattered in every area of the power system for regional-area intrusion detection and a master agent (MA) embedded in the system protection center for system status awareness. For the SAs, a hybrid-based intrusion detection method is utilized to conduct regional-area intrusion detection. The proposed method receives the bilateral data to simultaneously detect data integrity attacks on measurement and control signals using three classification models and performs the identification of single and coordinated attacks using a rule-based approach. Further, to train the classification models in the proposed method, a NewStacking-based model training algorithm is adopted. The proposed algorithm combines different selected classifiers that operate on two different feature subsets, which improves the detection accuracy of the models and extends the generalization ability with better robustness. Experimental results reveal that the proposed algorithm has better performance than existing machine learning algorithms and state-of-art works, the proposed method can identify single and coordinated attacks with high accuracy, and our DCPIDS satisfies the real-time requirements for practical online application. Qiuyu Lu, Qize Gao, Jun'e Li, Xuanxuan Xie, Wenrui Guo |
Comput. Commun. | 3 |
| 2024 | Privacy-Preserving and Secure Industrial Big Data Analytics: A Survey and the Research FrameworkabstractThe development of the Industrial Internet will generate a large amount of valuable data, known as industrial big data (IBD). By mining and utilizing IBD, enterprises can improve production efficiency, reduce costs and risks, optimize management processes, and innovate services and business models. However, industrial big data comes from various institutions in all walks of life and has features such as multi-source, heterogeneity, and multi-modality. And data sharing and trading (DS&T) occur in the Industrial Internet environment without mutual trust. These characteristics pose new challenges to analytics methods and privacy and security protection technologies. Therefore, this paper aims to provide references for privacy-preserving and secure industrial big data analytics (IBDA) from three perspectives: research framework, platform architecture, and key technologies. Firstly, we review the current state of research on theories and technologies related to IBDA. Then, we reveal three challenges to secure and efficient IBDA. We take the analytics and utilization of IBD as systematic engineering, propose the research framework for privacy-preserving and secure IBDA, and point out the specific content to be studied. Further, we design the architecture of the IBDA platform with the idea of layering, including a function model, security architecture, and system architecture. Finally, detailed research proposals and potential technologies for IBD analytics and utilization are presented from three aspects: data fusion and analytics, data privacy and security protection, and blockchain. Linbin Liu, Jun'e Li, Jianming Lv, Juan Wang 0006, Qiuyu Lu |
IEEE Internet Things J. | 2 |
| 2023 | UDP-RT: A UDP-based reliable transmission scheme for power WAPSabstractIt is expected that TCP/IP networks take the place of point-to-point fiber channels for the communications of WAPS. In TCP/IP networks, TCP does not guarantee real-time while UDP does not guarantee reliability. An efficient method is demanded for WAPS to guarantee the real-time and reliability of messages transmitted in TCP/IP networks under congestion states. To address the challenge, we propose a UDP-based reliable transmission (UDP-RT) scheme, which achieves low latency by adopting UDP at the transport layer and high reliability by adding the mechanisms of error correction, error detection, resending and timeout retransmission at the application layer. The error correction mechanism employs TPCs, which has low complexity and good performance at high code rate, to correct errors in a message. A blocking rule for TPCs considering the features of communication channels and messages of WAPS is presented. The error detection mechanism is for detecting whether all errors in the message are corrected by the error correction mechanism. The resending mechanism and the timeout retransmission mechanism (optional) is for ensuring the reliability in the two cases of message loss and not all errors corrected. Additionally, algorithms for UDP-RT are presented, and their correctness are validated through experiment. Our analyses demonstrate that the proposed scheme can meet the real-time requirements of WAPS businesses when network congesting and has higher reliability than the TCP transmission scheme and other UDP transmission schemes. Qiuyu Lu, Jun'e Li, Kaipei Liu, Jianbo Luo |
Comput. Networks | 2 |