EDBT 2026 Demo / reviewers in the wild / expert
Yi Xie 0002
dblp:51/4462-2
· DBLP profile ↗
35ranked-venue papers
11as first author
14since 2021 · last 2026
0000-0002-8899-4032ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 4 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-authorSystems, architecture and hardware · 4 · 4 first-authorSecurity and privacy · 4 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Identifying Fraudulent Users in E-commerce Applications through Spatiotemporal Fusion and Selective AggregationabstractThe swift growth of e-commerce has led to an increase in fraudulent activities, which results in significant financial losses for both suppliers and consumers. Current research on detecting fraudulent activities within e-commerce platforms primarily focuses on analyzing individual user behavioral patterns over time or examining the spatial relationships among users. However, considering temporal or spatial contexts alone is not sufficient for fraud detection since they may not exist in real scenarios. Additionally, the issue caused by the imbalance of the data to be classified has not been solved in the field of fraud identification. To address these challenges, a novel scheme is proposed for fraudulent user detection in this work. The main contribution lies in the spatiotemporal fusion of user behavior and the layer-by-layer selective aggregation of graph models. Specifically, we utilize a long short-term memory model and a multi-layer perceptron model to extract the discriminant features from time-dependent and time-independent user behavior, respectively. This approach enhances the model’s ability to detect fraudulent users with different behavioral characteristics, including time-correlated and/or time-independent fraud behavior. Furthermore, a shared classifier is added to general graph neural network, it reclassifies the output of each layer of the graph model and reconstructs the spatial neighbor relationship. This little trick makes minority class samples select similar samples with a greater probability to build their spatial neighbor relationships, which can alleviate the issue of data imbalance. In the numerical experiments, three real datasets are used to validate the proposed scheme. Experiment results, including performance evaluation, comparison with existing benchmark approaches and ablation analysis, are presented and discussed. Rujia Chen, Yi Xie 0002, Minglang Liao, Jiankun Hu, Xingcheng Liu |
ACM Trans. Priv. Secur. | 2 |
| 2025 | Social-Assisted Two-Stage Cooperative Offloading and Resource Allocation for Mobile Edge Computing Networks: A Stackelberg Game and Hybrid Actor-Critic-Based ApproachabstractMobile Edge Computing (MEC) is a promising technology for future 6G communication systems. However, the dynamic network environment and the selfish nature of devices pose challenges to task offloading. Therefore, it is very critical to design an effective cooperative offloading scheme in dynamic environments. In this paper, a social-assisted two-stage cooperative task offloading and resource allocation algorithm based on Stackelberg game and DRL (SAC-SDRL) is proposed to maximize the system utility. The problem is formulated as a mixed integer non-linear programming (MINLP) problem that jointly determined the edge server selection, and offloading rate, resource price, and resource allocation. To address this problem, two stage-solutions are introduced. In the first stage, given a fixed resource price and offloading rate, the edge server selection and resource allocation scheme based on hybrid actor-critic algorithm is designed to solve the problem of hybrid action space. In order to avoid invalid decision space, a clustering method based on social relationship and spectral clustering is developed. In the second stage, based on the obtained edge server selection and resource allocation decision, a dynamic pricing and offloading incentive scheme based on the Stackelberg game is proposed, in which the optimal resource price and optimal offloading rate can be determined with the proposed gradient-based iterative search method. Moreover, it is proved that the game can achieve the Stackelberg equilibrium. Finally, simulation results show that the proposed SAC-SDRL algorithm can achieve higher system utility compared with other concerned algorithms. Zhiwei Wei, Xingcheng Liu, Yi Xie 0002, Guangjie Han |
IEEE Internet Things J. | 5 |
| 2024 | An Attention Mechanism Neural Network for Spatiotemporal Network Traffic Data CompletionabstractDue to the high cost of network monitoring equipment and uncontrollable factors, network measurement data often contains missing values. These missing values can severely hinder the progress of many downstream tasks, such as anomaly detection and resource scheduling. Utilizing known network measurement traffic data to infer network-wide network traffic data represents a crucial approach to alleviate this issue. Recently, spatiotemporal completion methods have received much attention because they can use spatiotemporal information to improve the accuracy of the completion compared to traditional unilateral methods. However, these methods typically only focus on completing missing values in static network topologies and struggle to filter out negative spatiotemporal information. To address these limitations, we propose a new approach for spatiotemporal data completion of network traffic under dynamic network topology conditions. The proposed method utilizes a neural network with an attention mechanism to capture the spatiotemporal correlation of network traffic data while effectively filtering out irrelevant spatiotemporal information. The model first uses external attention to capture the dependency of missing values of nodes in the time dimension, then adaptively aggregates the spatial information of nodes via graph attention, and finally decodes the spatiotemporal features of each node to predict the true values through a fully connected layer. The model can be trained by randomly sampling subgraphs from the training set. It can make immediate inferences even in the presence of changes in network topology during testing, without requiring retraining. The experimental results suggest that our proposed method outperforms existing benchmark methods in both real network traffic spatiotemporal datasets and various missing scenarios. Weikang Xiao, Yi Xie 0002 |
IJCNN | 2 |
| 2024 | Optimizing Multi-Cell Selection Handover in Cellular Networks: A Deep Reinforcement Learning ApproachabstractHandover (HO) is a critical component of mobility management in the 5th generation (5G) of communication networks, which ensures seamless connectivity and optimal communication performance for user equipment (UE) in motion across different cells. In previous studies, the deep reinforcement learning (DRL) techniques were employed to solve the HO problem. However, for most of these methods, the growing complexity in action space was not considered as the number of UEs increases, leading to inefficient model convergence and HO failures. To address this issue, this paper proposes a novel PPO-MH (Proximal Policy Optimization with Masking for Handover) model for multi-cell selection handover problem. This model calculates the action mask for each UE before each handover using the UE's measurement report, providing prior information for the decision-making process. By dynamically masking base stations (BSs) that do not meet the handover conditions, the model avoids invalid hand overs and improves sampling efficiency. Experimental results demonstrate that the PPO- MH outperforms the traditional PPO across various scenarios, ensuring Quality of Service (QoS) for UEs and reducing the handover frequency. Additionally, PPO- MH converges significantly faster than PPO, which validates the effectiveness of the action mask strategy. Benefiting from these advantages, our methods have broad potential applications, especially in scenarios requiring efficient resource management and low-latency handovers. Renwei Ou, Yi Xie 0002, Xingcheng Liu, Peiran Wu, Tie Qiu 0001, Guangjie Han |
MSN | 3 |
| 2024 | Estimating the composition ratios of network services carried in mixed traffic
Zihui Wu, Yi Xie 0002, Shensheng Tang, Xingcheng Liu |
Comput. Commun. | 2 |
| 2023 | Mobile-Aware Online Task Offloading Based on Deep Reinforcement Learning in Mobile Edge Computing NetworksabstractMobile Edge Computing (MEC) is one of the key enabling technologies for future 6G wireless networks that can provide lower latency service and more efficient resource utilization for future intelligent applications and the Internet of Things (IoT), while also reducing the energy consumption of end devices. In the intricate dynamic edge environment, the task offloading problem is entangled with several factors, such as the uncertainty of online tasks, the heterogeneity of edge servers, and the mobility of devices. In this paper, considering the randomness of online task arrivals, time-varying channels, and mobility of devices, a deep reinforcement learning-based online task offloading (DRL-OTO) algorithm is designed to minimize the energy consumption of all mobile devices. Specifically, by portraying the system model consisting of the communication model, energy consumption model, and node mobility model, the task offloading optimization problem is modeled as a mixed integer nonlinear programming (MINLP) problem. By decomposing this problem, each mobile device first determines the edge server to be offloaded, and then the DRL-OTO algorithm is designed by utilizing the DDPG method, in which each mobile device is able to determine the offloading rate. Simulation results show that the proposed DRL-OTO algorithm can achieve fast convergence and is able to reduce energy consumption, thus increasing the utility of all devices in the dynamic edge environment. Xingcheng Liu, Qiang Tu, Yi Xie 0002 |
PIMRC | 5 |
| 2023 | Range-Free Localization Using Extreme Learning Machine and Ring-Shaped Salp Swarm Algorithm in Anisotropic NetworksabstractNode localization is one of the basic requirements in various Internet of Things applications. Among a wide range of localization schemes, the range-free localization algorithm is promising as a cost-effective technique. However, the localization accuracy of this technique is susceptible to various anisotropy factors, such as the existence of holes, nonuniform node distribution, and dynamic radio propagation pattern. To this end, an accurate range-free localization model using extreme learning machine (ELM) and ring-shaped salp swarm algorithm (SSA) is proposed for anisotropic wireless sensor networks. First, the integer hop count between two adjacent nodes is quantized as a real number according to the Jaccard coefficient of their shared neighbor nodes. Second, exploiting the strong generalization and fast learning speed of ELM, a distance mapping model based on the modified real hop count is developed for solving anisotropic signal attenuation. Third, the coordinate calculation of normal nodes is formulated as a minimum problem by taking into account the weighted squared error of estimated distance, and the bounding box method is utilized to initialize the possible location boundary area of normal nodes. Finally, the SSA based on the ring-shaped topology is designed to compute the coordinates of normal nodes. Extensive simulations on several network topologies are conducted with the effect of multiple anisotropic factors. Experimental results show that the proposed algorithm is superior to other developed ones not only in localization accuracy but also in robustness against network anisotropy. Qiang Tu, Xingcheng Liu, Yi Xie 0002, Guangjie Han |
IEEE Internet Things J. | 3 |
| 2023 | Network Traffic Content Identification Based on Time-Scale Signal ModelingabstractIdentifying the nature of data flows can help improve network service and security. Most existing solutions usually simplify the traffic classification to protocol and application identification based on some uniqueness assumptions. However, in the real world these assumptions aren’t always reasonable due to the abuse of multiplexing techniques. In this work, a new scheme is proposed from a different perspective that aims to directly identify the content inside a data flow without considering the external protocols and applications. We use wavelet to obtain the time-scale signals of each data flow and develop a new hidden Markov tree (HMT) with an embedding deep neural network (DNN) to model these signals. Each hidden state of the HMT represents a specific signal generation pattern. Transition of hidden states describes the time-scale context of the signal patterns. DNN is used to describe the probabilistic relationship between the implicit patterns and the observed time-scale signals. We derive new algorithms for the model and create an instance for each type of traffic, which projects the data flows into a multi-dimensional decision space and achieves their content identification through a classifier. Numerical experiments using real datasets are presented to validate the proposed scheme. Performance-related issues and comparisons with related works are discussed. Yi Xie 0002, Shensheng Tang, Shunzheng Yu, Xingcheng Liu, Jiankun Hu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Application Identification under Multi-Service Integration PlatformabstractMulti-service integration platform (MIP) is becoming a new way for mobile applications to provide services, such as the ChatBot of Facebook and the applet of WeChat. However, currently there are no special means and filtering strategies to supervise the services running on various MIPs. Existing solutions for program detection and traffic analysis are not suitable for MIP scenarios, which creates favorable conditions for the dissemination of illegal content through MIP. To address this issue, in this work we propose a new approach to identify mobile applications running on MIP platforms. The proposed approach uses IP flow to reconstruct data units of both transport and ap-plication layers respectively. By this way, we can capture the data transmission behavior of multi-protocol layers and obtain richer semantic features for application identification. Then, multi-kernel convolutional neural networks (CNN s) and long short term memory (LSTM) neural networks are employed to extract and aggregate the multi-scale features from the perspective of both protocol layer and time series. Finally, the fused features generated by the models are used to identify the category of the pending applications by a classifier composed of a fully connected neural network. We validate the proposed approach by three real datasets. The experimental results show that the proposed approach outperforms most existing benchmark methods in performance. Ziyang Wu, Yi Xie 0002 |
MSN | 2 |
| 2022 | Stacked Autoencoders-Based Localization Without Ranging Over Internet of ThingsabstractLocation information plays an important role in many applications of the Internet of Things (IoT). The low cost and ease of scalability of range-free localization algorithms have attracted the attention of many researchers, but the performance of many localization algorithms available in the literature varies greatly in different networks. Specifically, algorithms designed for anisotropic networks may not perform well in isotropic networks, and vice versa. To improve localization accuracy in both isotropic and anisotropic networks, a novel range-free localization algorithm named LSAE is proposed in this article, oriented to the network positioning without ranging over the IoT. The proposed algorithm utilizes the known information in the network, namely, the hop counts and distances between anchor nodes, to train the stacked autoencoders (SAE) model. In this way, it achieves accurate prediction of the distances between unknown nodes and anchor nodes. To further improve the localization accuracy, the disadvantage of the least square method is analyzed, and a novel coordinate estimation method based on the statistical results of distance estimation errors is proposed. We conducted a huge number of numerical simulations with and without the impact of multiple anisotropic factors in three different types of networks. The results indicate that the proposed algorithm outperforms other state-of-the-art algorithms treating the impact of multiple anisotropic factors, and demonstrates the high accuracy and robustness. Zhengqiang Yan, Xingcheng Liu, Wenjie Ji, Guangjie Han, Yi Xie 0002 |
IEEE Internet Things J. | 6 |
| 2022 | Threat-Event Detection for Distributed Networks Based on Spatiotemporal Markov Random FieldabstractDistributed threat-events are one of the main challenges faced in computer networks. Although a lot of research has been conducted for these issues, the situation has not been significantly improved. Different from existing victim-centric approaches, in this article we propose a new network-centric approach for the detection of distributed threat-events. The distributed network is treated as a holistic system that consists of spatially interconnected network elements. Network events are detected by the dynamic behavior analysis of the distributed networks. We develop a model consisting of two-layer random fields to describe the time-varying traffic forwarding behavior of the distributed networks. The bottom layer describes the interaction and influence of the network elements under the action of network events. Markovianity is adopted to characterize the spatiotemporal context of each network element’s behavior patterns. The top layer describes each network element’s traffic features driven by the underlying behavior patterns. A Gaussian mixture model is used to capture the statistical features of the network traffic for each behavior pattern. We derive algorithms for parameter estimation and event detection. Numerical experiments using real datasets and different network scenarios are presented to validate the proposed approach. Performance-related issues and comparison with related works are discussed. Haishou Ma, Yi Xie 0002, Shensheng Tang, Jiankun Hu, Xingcheng Liu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | A Light-Weight Scheme for Detecting Component Structure of Network Traffic
Zihui Wu, Yi Xie 0002, Ziyang Wu |
PDCAT | 2 |
| 2021 | Range-free localization using Reliable Anchor Pair Selection and Quantum-behaved Salp Swarm Algorithm for anisotropic Wireless Sensor Networks
Qiang Tu, Xingcheng Liu, Yi Xie 0002 |
Ad Hoc Networks | 5 |
| 2021 | Identifying click-requests for the network-side through traffic behaviorabstractWith the rapid development of web-based applications, clicking on hyperlinks has become a general means for accessing various network services. Understanding the visiting behavior of web users not only helps improve the personalized service quality and user experience, but also plays an important role in network management and early threat detection. Click-stream identification is a fundamental issue for user behavior analysis. However, most existing approaches are designed for non-encrypted HTTP requests and only focus on server-side scenarios, which makes them inapplicable to the increasingly popular HTTPS and network-side management. In this work, we propose an encryption-independent scheme from a network-side perspective that adopts the web traffic collected at the network boundary to identify the HTTP(S) requests generated by the click actions of web users. The proposed scheme employs hidden Markov models (HMMs) to describe the time-varying behavior of click and non-click web traffic. A deep neural network (DNN) is integrated into the HMMs to capture the context of web traffic, which eliminates the limitations caused by the independence hypothesis of the traditional HMMs. Finally, a DNN-based rear classifier is proposed to determine the type of HTTP(S) requests according to the fitting degree between the HTTP(S) requests and the HMM-based behavior models. We derive the algorithms for model learning and click identification. Experiments are conducted to validate the proposed approach. Performance-related issues and comparisons are discussed. Results show that both the average precision and recall rate of the proposed approach exceed 92%, which is better than most existing benchmark methods in terms of performance and stability. Xingrui Fei, Yi Xie 0002, Shensheng Tang, Jiankun Hu |
J. Netw. Comput. Appl. | 2 |
| 2020 | Serially concatenated scheme of polar codes and the improved belief propagation decoding algorithmabstractIn this study, a serially concatenated scheme of polar codes with convolutional codes is proposed to improve the error correction performance. The novel belief propagation (BP) decoding algorithm addresses two issues that are present in the currently available BP decoding algorithms. The first issue is the poor performance of the BP decoding algorithms, in particular the introduction of an error floor. The second is the component codes can only use systematic codes in the traditional concatenated scheme of polar codes with convolutional codes, which inhibits the effective update of the prior information of the redundant check bits. The proposed BP decoding algorithm is based on right‐directed message processing, which effectively improves the decoding performance. In addition, the proposed concatenated scheme extends the selection of component codes from the systematic polar codes to the non‐systematic polar codes. Hence, the areas of applications and the prior information of information bits for polar codes are expanded and more effectively updated, respectively. The simulation results show that the proposed scheme is much better than the traditional concatenated scheme, and the error floor is no longer introduced in terms of the block error rate, while the storage and computational complexities have not increased obviously. Yinyou Mao, Xingcheng Liu, Yi Xie 0002 |
IET Commun. | 4 |
| 2020 | A Novel Range-Free Localization Scheme Based on Anchor Pairs Condition Decision in Wireless Sensor NetworksabstractIt is essential to acquire the location of sensor nodes in the wireless sensor networks (WSNs), since the data collected with nodes would become meaningless without their location. In the existing studies, range-free localization schemes have been proved suitable to large-scaled WSNs due to the low cost in hardware implementation. However, the defect of those schemes is their poor accuracy in anisotropic networks with coverage holes. To tackle this problem, we propose a range-free localization scheme that combines the advantages of geometric constraint and hop progress-based methods. The geometric information provided by the combination of anchor pairs and unknown nodes is used to design the discrimination conditions, and each node divides the anchor pairs into one of three proposed categories. For different categories of anchor pairs, corresponding methods are proposed to estimate the distancse between sensor nodes. In this way, the trade-off between distance estimation accuracy and anchor utilization can be achieved. Simulation results indicate that the proposed scheme outperforms other schemes in terms of localization accuracy and proportion of outliers with acceptable computational and time complexity, where the localization accuracy and proportion of outliers in the proposed scheme are improved by up to 47% and 61% compared to DV-maxHop. Xingcheng Liu, Wenjie Ji, Yi Xie 0002 |
IEEE Trans. Commun. | 5 |
| 2019 | Recognizing the content types of network traffic based on a hybrid DNN-HMM model
Xincheng Tan, Yi Xie 0002, Haishou Ma, Shunzheng Yu, Jiankun Hu |
J. Netw. Comput. Appl. | 2 |
| 2019 | Corrigendum to "Recognizing the content types of network traffic based on a hybrid DNN-HMM model" [J. Netw. Comput. Appl. 142 (2019) 51-62]
Xincheng Tan, Yi Xie 0002, Haishou Ma, Shunzheng Yu, Jiankun Hu |
J. Netw. Comput. Appl. | 2 |
| 2019 | Detecting Anomalous Behavior in Cloud Servers by Nested-Arc Hidden SEMI-Markov Model with State SummarizationabstractAnomaly detection for cloud servers is important for detecting zero-day attacks. However, it is very challenging due to the large amount of accumulated data. In this paper, a new mathematical model for modeling dynamic usage behavior and detecting anomalies is proposed. It is constructed using state summarization and a novel nested-arc hidden semi-Markov model (NAHSMM). State summarization is designed to extract usage behavior reflective states from a raw sequence. The NAHSMM is comprised of exterior and interior hidden Markov chains. The exterior controls the propagation of raw sequences of system calls and, conditional on it, the interior one controls the summarized observation process from the transition less usage behavior reflective states. An anomaly detection algorithm is derived by integrating state summarization and NAHSMM. During training the algorithm is assisted by a forensic module to tune the behavioral threshold. Experimental data is collected using IXIA Perfect Storm in conjunction with the commercial security-test hardware platform cyber range. To evaluate the reliability of the proposed model, first, its accuracy and training costs are compared with those of existing machine-learning models and then its scalability and resistance capabilities are tested. The results indicate that this model could be used as a method for detecting anomalies in cloud servers. Waqas Haider, Jiankun Hu, Yi Xie 0002, Xinghuo Yu 0001, Qianhong Wu |
IEEE Trans. Big Data | 3 |
| 2017 | Generating realistic intrusion detection system dataset based on fuzzy qualitative modelingabstractPrior to deploying any intrusion detection system, it is essential to obtain a realistic evaluation of its performance. However, the major problems currently faced by the research community is the lack of availability of any realistic evaluation dataset and systematic metric for assessing the quantified quality of realism of any intrusion detection system dataset. It is difficult to access and collect data from real-world enterprise networks due to business continuity and integrity issues. In response to this, in this paper, firstly, a metric using a fuzzy logic system based on the Sugeno fuzzy inference model for evaluating the quality of the realism of existing intrusion detection system datasets is proposed. Secondly, based on the proposed metric results, a synthetically realistic next generation intrusion detection systems dataset is designed and generated, and a preliminary analysis conducted to assist in the design of future intrusion detection systems. This generated dataset consists of both normal and abnormal reflections of current network activities occurring at critical cyber infrastructure levels in various enterprises. Finally, using the proposed metric, the generated dataset is analyzed to assess the quality of its realism, with its comparison with publicly available intrusion detection system datasets for verifying its superiority. Waqas Haider, Jiankun Hu, Jill Slay, Benjamin P. Turnbull, Yi Xie 0002 |
J. Netw. Comput. Appl. | 5 |
| 2016 | Comments and CorrectionsabstractPresents correcttions to the paper, “A performance evaluation of machine learning-based streaming spam tweets detection,” (Chen ], C.; et al) , IEEE Trans. Comput. Social Syst., vol. 2, no. 3, pp. 65–76, Sep. 2015. Chao Chen 0015, Jun Zhang 0010, Yi Xie 0002, Yang Xiang 0001, Wanlei Zhou 0001, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2016 | A General Collaborative Framework for Modeling and Perceiving Distributed Network BehaviorabstractCollaborative Anomaly Detection CAD is an emerging field of network security in both academia and industry. It has attracted a lot of attention, due to the limitations of traditional fortress-style defense modes. Even though a number of pioneer studies have been conducted in this area, few of them concern about the universality issue. This work focuses on two aspects of it. First, a unified collaborative detection framework is developed based on network virtualization technology. Its purpose is to provide a generic approach that can be applied to designing specific schemes for various application scenarios and objectives. Second, a general behavior perception model is proposed for the unified framework based on hidden Markov random field. Spatial Markovianity is introduced to model the spatial context of distributed network behavior and stochastic interaction among interconnected nodes. Algorithms are derived for parameter estimation, forward prediction, backward smooth, and the normality evaluation of both global network situation and local behavior. Numerical experiments using extensive simulations and several real datasets are presented to validate the proposed solution. Performance-related issues and comparison with related works are discussed. Yi Xie 0002, Yu Wang 0017, Haitao He, Yang Xiang 0001, Shunzheng Yu, Xincheng Liu |
IEEE/ACM Trans. Netw. | 1 |
| 2015 | Integer Data Zero-Watermark Assisted System Calls Abstraction and Normalization for Host Based Anomaly Detection SystemsabstractThe generation of representative computer system behavior profile from system calls in LINUX environments to establish reliable Host Based Anomaly Detection Systems (HADS) against Next Generation of Attacks (NGA) is a challenge due to two major reasons. Firstly, NGA causes a low footprint upon host activities and consequently, attack activities are difficult to detect from normal computer processes in terms of accuracy and processing time. Secondly, there is no effective method to extract the natural difference from the two different types of traces (e.g. normal or abnormal) of system calls. Following these reasons, a semi-supervised model is proposed, which is comprised of two parts. Firstly, to establish an unsupervised computer behavior classification, an integer data zero-watermarking algorithm is developed to extract abstract hidden representation of system calls. This hidden representation constitutes the natural difference between attack and normal computer system behavior in real-time. Secondly, various supervised Machine Learning (ML) algorithms and normalizations are realized with proposed hidden representation of the system calls to evaluate the semi-supervised model in HADS. To evaluate the performance in terms of accuracy and processing time, the publicly available bench mark host based data sets: ADFA-LD and KDD 98 have been utilized. Each data set is the collection of traces of processes and each trace comprises of process's system calls. Experimental results shows that the suggested semi-supervised model outperforms existing methodologies in terms of accuracy and processing time for the detection of low and high foot print attacks. Waqas Haider, Jiankun Hu, Xinghuo Yu 0001, Yi Xie 0002 |
CSCloud | 4 |
| 2015 | A Performance Evaluation of Machine Learning-Based Streaming Spam Tweets DetectionabstractThe popularity of Twitter attracts more and more spammers. Spammers send unwanted tweets to Twitter users to promote websites or services, which are harmful to normal users. In order to stop spammers, researchers have proposed a number of mechanisms. The focus of recent works is on the application of machine learning techniques into Twitter spam detection. However, tweets are retrieved in a streaming way, and Twitter provides the Streaming API for developers and researchers to access public tweets in real time. There lacks a performance evaluation of existing machine learning-based streaming spam detection methods. In this paper, we bridged the gap by carrying out a performance evaluation, which was from three different aspects of data, feature, and model. A big ground-truth of over 600 million public tweets was created by using a commercial URL-based security tool. For real-time spam detection, we further extracted 12 lightweight features for tweet representation. Spam detection was then transformed to a binary classification problem in the feature space and can be solved by conventional machine learning algorithms. We evaluated the impact of different factors to the spam detection performance, which included spam to nonspam ratio, feature discretization, training data size, data sampling, time-related data, and machine learning algorithms. The results show the streaming spam tweet detection is still a big challenge and a robust detection technique should take into account the three aspects of data, feature, and model. Chao Chen 0015, Jun Zhang 0010, Yi Xie 0002, Yang Xiang 0001, Wanlei Zhou 0001, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi, Majed A. AlRubaian |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2013 | A Forward-Backward Algorithm for Nested Hidden semi-Markov Model and Application to Network TrafficabstractDoubly hidden Markov models (DHMMs) have been widely used to analyze a type of time process whose driving factors are hierarchical and hierarchically correlated. A common issue of these models is that they implicitly assume that the dwell time of any system state is constant or exponentially distributed. This property comes from the standard hidden Markov models and causes the DHMM to limitations in some actual application environment, where an application has latent temporal structure and does not follow the exponential distribution but has the period-like or variable-period feature. Such problems are frequently encountered in practice, e.g. network traffic. In this paper, we remove this limitation by a new structural discrete approach named nested hidden semi-Markov model. The proposed model includes a nested latent semi-Markov chain and one observable discrete stochastic process. The bottom latent semi-Markov chain is the core layer and controls the second-layer semi-Markov chain that generates the observable process. The state duration of both the semi-Markov chains can be variable or explicit. The model makes no assumptions on the distribution of the state-duration and the observable processes. An efficient forward and backward recursion procedure is developed for estimating the generator of the proposed model and inferring the underlying state processes for a given observation sequence. To evaluate the performance of the proposed model, we apply the model to the arrival process of network traffic and compare its simulation traffic and the real traffic. The performance evaluation in the experiments includes time dynamic process, auto-correlation, cross-correlation, statistical distribution and self-similarity. Yi Xie 0002, Jiankun Hu |
Comput. J. | 1 |
| 2013 | Modeling Oscillation Behavior of Network Traffic by Nested Hidden Markov Model with Variable State-DurationabstractNetwork traffic modeling is a fundamental problem in communication. A traffic model should be able to capture and reproduce various properties of a real trace. Despite the widespread success of most numerical models in various applications, few actually focus on the oscillation behavior proven to be one of the basic properties in network traffic. In this paper, a new mathematical method is proposed to model and synthesize stationary and nonstationary oscillatory processes of network traffic. The proposed model is based on the structure of the hierarchical hidden Markov model, which includes two nested hidden Markov chains and one observable process. The first-layer hidden Markov chain with variable state-duration controls the time-varying oscillatory process. Conditional on the first-layer Markov chain, the local fluctuation process is modeled by the second-layer hidden Markov chain. Algorithms are derived for inference of model parameters and traffic synthesis. The proposed approach is compared with four classical models for performance evaluation. The selected performance criterion includes time structure, statistical properties, self-similarity, queuing behavior and multiscale properties. The flexibility and accuracy of the proposed model results in a close fit to the real traces. Yi Xie 0002, Jiankun Hu, Yang Xiang 0001, Shui Yu 0001, Shensheng Tang, Yu Wang 0017 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2013 | Resisting Web Proxy-Based HTTP Attacks by Temporal and Spatial Locality BehaviorabstractA novel server-side defense scheme is proposed to resist the Web proxy-based distributed denial of service attack. The approach utilizes the temporal and spatial locality to extract the behavior features of the proxy-to-server traffic, which makes the scheme independent of the traffic intensity and frequently varying Web contents. A nonlinear mapping function is introduced to protect weak signals from the interference of infrequent large values. Then, a new hidden semi-Markov model parameterized by Gaussian-mixture and Gamma distributions is proposed to describe the time-varying traffic behavior of Web proxies. The new method reduces the number of parameters to be estimated, and can characterize the dynamic evolution of the proxy-to-server traffic rather than the static statistics. Two diagnosis approaches at different scales are introduced to meet the requirement of both fine-grained and coarse-grained detection. Soft control is a novel attack response method proposed in this work. It converts a suspicious traffic into a relatively normal one by behavior reshaping rather than rudely discarding. This measure can protect the quality of services of legitimate users. The experiments confirm the effectiveness of the proposed scheme. Yi Xie 0002, Shensheng Tang, Yang Xiang 0001, Jiankun Hu |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2012 | A Periodic Structural Model for Characterizing Network Traffic
Yi Xie 0002, Shensheng Tang, Xiangnong Huang |
ICIC (2) | 1 |
| 2012 | A structural approach for modelling the hierarchical dynamic process of Web workload in a large-scale campus network
Yi Xie 0002, Jiankun Hu |
J. Netw. Comput. Appl. | 1 |
| 2011 | Modeling and Analysis of Network Security Situation Prediction Based on Covariance Likelihood Neural
Chenghua Tang, Reixia Zhang, Yi Xie 0002 |
ICIC (3) | 4 |
| 2011 | A Two-Layer Hidden Markov Model for the Arrival Process of Web TrafficabstractA new two-layer hidden Markov model is proposed to describe the arrival rate process of Web traffic. The macro state process of the first underlying layer is used to describe the large-scale trends of network traffic. The sub-state process of the second underlying layer is used to describe the small-scale fluctuations that are happening during the duration of a given macro state. Experiments are implemented to validate the proposed model. Yi Xie 0002, Shunzheng Yu, Shensheng Tang, Xiangnong Huang |
MASCOTS | 1 |
| 2009 | Monitoring the application-layer DDoS attacks for popular websites
Yi Xie 0002, Shunzheng Yu |
IEEE/ACM Trans. Netw. | 1 |
| 2009 | A large-scale hidden semi-Markov model for anomaly detection on user browsing behaviors
Yi Xie 0002, Shunzheng Yu |
IEEE/ACM Trans. Netw. | 1 |
| 2008 | Measuring the Normality of Web Proxies' Behavior Based on Locality Principles
Yi Xie 0002, Shunzheng Yu |
NPC | 1 |
| 2006 | A Dynamic Anomaly Detection Model for Web User Behavior Based on HsMMabstractIt is difficult for the existing anomaly detection methods to distinguish the burst of normal traffic from the anomalous traffic in a large-scale Web site. This paper uses hidden semi-Markov model to describe the browsing behaviors of Web users. An efficient recursive algorithm for this model is presented for the online implementation of model update, which is used to track the Web users' browsing behaviors dynamically. An anomaly detection scheme is proposed for the application of this model. Likelihood of an observation sequence on a user browsing behaviors fitting to the model is used as a measure of normality of the user. Finally, an experiment is conducted to validate our model and algorithms, which is based on a real traffic data and an emulated distributed denial of service attack Yi Xie 0002, Shunzheng Yu |
CSCWD | 1 |