Zhihao Wang 0001

dblp:52/253-1 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0003-1989-3067ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 EAGLE: Erroneous Traffic Analysis Framework using Graph Representation Learning
abstract
Erroneous traffic – packets that fail to establish valid bidirectional communication – provides useful signals of misconfigurations, failures, and attacks, but is noisy and rapidly evolving, making systematic analysis challenging. We present EAGLE, an Erroneous traffic Analysis framework using Graph representation LEarning. EAGLE models erroneous traffic as dynamic bipartite graphs between external senders and internal destination ports. EAGLE combines a self-supervised inductive GraphSAGE encoder with a GRU-based temporal model and learns sender representations via graph reconstruction, requiring no labelled data. We evaluate EAGLE on seven days of traffic collected from a /16 university campus network, which contains 155 K external senders and 3 B packets. Across anomaly detection, supervised classification, and clustering, EAGLE consistently outperforms baselines, achieving up to 16.2% ROC AUC and 17.2% macro F1-score improvements. Case studies further demonstrate its ability to uncover coordinated behaviours, highlighting temporal graph representation learning as an effective approach for erroneous traffic modelling.
Xiaoxiong Yang, Zhihao Wang 0001, Dingde Jiang
APNet2
2025 Poster: The Potential of Erroneous Outbound Traffic Analysis to Unveil Silent Internal Anomalies
abstract
Network administrators have long relied on passive measurement to detect malicious activity, diagnose misconfigurations, and ensure network health. Under the assumption that threats and issues originate externally, prior studies [1] have predominantly focused on the analysis of inbound traffic — i.e., traffic initiated by external hosts and targeting internal destinations. Conversely, outbound traffic — i.e., originating from internal hosts toward external destinations — has received comparatively less attention, despite carrying strong indicators of security-relevant anomalies [2].
Andrea Sordello, Zhihao Wang 0001, Alessandro Cornacchia, Marco Mellia
IMC2
2025 Toward Synthetic Network Traffic Generating in NTN-Enabled IoT: A Generative AI Approach
abstract
Nonterrestrial networks (NTNs) enabled Internet of Things (IoT) extends connectivity to remote and underserved areas, enhances network reliability and coverage, and supports diverse IoT applications in challenging environments, such as rural, maritime, and disaster-stricken regions. As an emerging and fast-evolving IoT scheme, NTN-enabled IoT requires extensive evaluation to ensure effective deployment in real-world scenarios, such as connectivity, performance, and security evaluation. Since conducting testing in remote and diverse environments is logistically challenging and costly, we propose a generative artificial intelligence (GAI)-based synthetic traffic generation framework that facilitates comprehensive traffic analysis and performance evaluation. The proposed framework employs a GAI model to learn the traffic pattern and generate synthetic traffic from historical data. Our approach includes an embedding-based model for representing network flow attributes and a conditional generative adversarial network (CGAN) for generating traffic flows. Considering both source-destination information and statistical features achieves more comprehensive characterization of traffic flows. Finally, the simulation results demonstrate that the proposed approach can generate high quality traffic that conforms to real data distribution and shows obvious difference between multiple applications.
Dingde Jiang, Zhihao Wang 0001, Ruyun Zhang 0001, Lizhuang Tan, Peiying Zhang 0001
IEEE Internet Things J.2
2025 Network-Wide Data Collection Based on In-Band Network Telemetry for Digital Twin Networks
abstract
The Digital Twin Network (DTN) establishes a real-time virtual mirror of physical networks. Data collection plays an essential role in DTN, which collects the status data of physical network for building highly consistent digital twins. In this paper, we present a network-wide data collection scheme based on In-band Network Telemetry (INT). To build a lifelike mirror of the physical network, the probing path set is required to cover all links so that network topology, traffic load, and port-level device information is captured. We present a Latency-aware High-degree Replicated First (LHRF) vertex-cut graph partitioning algorithm to partition the network into several balanced subgraphs while trying to replicate the high-degree vertexes among partitions first. LHRF aims to balance the length and accumulated latency of the probing paths. With shorter and stabler probing latencies, the information received by digital twin can reflect the latest and consistent network-wide status. To prevent the packets from being fragmented due to overlong paths, a deep limited search (DLS) based path planning algorithm is employed to generate non-overlapped probing paths covering all edges in the separated subgraphs. Simulation results demonstrate that the proposed scheme generates more balanced INT paths with constrained path length and shorter, stabler probing delay.
Zhihao Wang 0001, Dingde Jiang, Shahid Mumtaz
IEEE Trans. Mob. Comput.1
2024 A Blockchain-Reinforced Federated Intrusion Detection Architecture for IIoT
abstract
Federated learning (FL) in Industrial IoT (IIoT) facilitates collaborative model training across distributed edge devices, ensuring data privacy and localized insights without centralized data aggregation. However, the networked parameter sharing mechanism in FL renders it vulnerable to exploitation by man-in-the-middle (MITM) attackers, potentially disrupting the model training process. To mitigate this threat, this article presents a novel blockchain-reinforced FL architecture aimed at enabling cooperative intrusion detection. Initially, FL is leveraged to aggregate all learned information from edge servers, thereby disseminating extracted attack characteristics to all participants through gradient sharing. Subsequently, a blockchain-based parameter verification scheme is introduced to safeguard against tampered local parameters affecting the global model. Clients record model parameters in smart contracts deployed on a private chain, and parameter servers verify parameter confidentiality before aggregation, ensuring only valid parameters are considered. Finally, extensive experiments are conducted using an edge IIoT cybersecurity data set comprising 61 features spanning ten protocol layers and five attacks targeting IIoT connectivity protocols. Simulation results demonstrate that the proposed scheme significantly enhances intrusion detection accuracy, achieving a threefold improvement when two-thirds of federated nodes are subjected to MITM attacks.
Dingde Jiang, Zhihao Wang 0001, Lizhuang Tan, Jian Wang 0010, Peiying Zhang 0001
IEEE Internet Things J.2
2023 Seamless Handover in LEO Based Non-Terrestrial Networks: Service Continuity and Optimization
abstract
Developing non-terrestrial networks (NTN) in future wireless networks has been widely recognized to bring advanced communication services to remote and unserved areas. The Low-Earth-Orbit (LEO) constellation has emerged as a promising component for NTN to provide seamless and fast global connectivity. However, since natural dynamic features, the mobility management, in particular the handover (HO) between satellites, plays an important role in ensuring a stable and continuous data service for NTN. Motivated by this fact, this paper proposes a HO optimization strategy based on conditional handover (CHO) mechanism to enhance service continuity in LEO-based NTN. A reward function, related to link service time and service capability, is firstly designed to modify the monitoring conditions of target satellite candidates. The optimal target selection algorithm is proposed to obtain the maximum reward for each CHO. Then, a service continuity performance graph (SCG) model is constructed to predict different potential CHO combinations in service duration. On the basis of SCG, the HO sequence supporting a high-quality and stable data service is predictively calculated for each accessing user. Simulation results demonstrate that the proposed HO optimization scheme can obviously reduce handover rate under different NTN conditions and can better enhance NTN service continuity.
Feng Wang 0049, Dingde Jiang, Zhihao Wang 0001, Jianguang Chen, Tony Q. S. Quek
IEEE Trans. Commun.3
2023 AI-Assisted Trustworthy Architecture for Industrial IoT Based on Dynamic Heterogeneous Redundancy
abstract
Current cyberspace is confronted with unprecedented security risks, whereas traditional passive protection techniques are ill-equipped for attacks or defects with unknown features. Dynamic heterogeneous redundancy (DHR), a built-in active defense approach, deploys uncertain, random, dynamic systems to change the asymmetry of attack and defense, where arbitration is one of the key mechanisms. In this article, an AI-assisted trustworthy architecture based on DHR and deep reinforcement learning-based intelligent arbitration (DRLIA) algorithm is presented to enhance security for industrial Internet of things (IIoT). A double deep Q network (DDQN) is introduced, which is capable to distinguish the reliable and credible IIoT message from executors through interaction with the DHR environment. Finally, the DRLIA is implemented to conduct arbitration tasks in an IIoT critical message transmission scenario, where several comparison experiments between DRLIA and other traditional algorithms are designed. The result on the testbed empirically demonstrates the effectiveness of the proposed architecture and the security enhancement.
Zhihao Wang 0001, Dingde Jiang, Zhihan Lyu
IEEE Trans. Ind. Informatics1
2021 Time-Extended Pathfinding Optimization in Mobile LEO Satellite Communication Networks
abstract
The mobile satellite communication networks (MSCN) enable network expansion and supplement in remote areas. Users in these regions can obtain specific network services with low latency and high transmission rates utilizing the low-earth-orbit (LEO) satellite constellation. However, due to the frequent switching of MSCN topology, the challenge is how to ensure the quality and continuity of data transmission paths in a certain time period. In this paper, we build a user satisfaction (US) indicator to measure the performance of pathfinding. The MSCN pathfinding optimization problem for the maximum US is first formulated. To simplify the complex calculation, we utilize the special-temporal division to solve the problem in two stages. In each time slot, the modified heuristic algorithm is utilized to find paths for the maximum US. Then, an active time slot division scheme is proposed. The divided time slot sequences are disconnected and reorganized to seek the time-extended optimal solution. Simulation results show that the proposed scheme achieves superior performance in improving the total US and guarantees reliable service continuity for MSCN.
Feng Wang 0049, Dingde Jiang, Zhihao Wang 0001, Haibin Lv, Zhihan Lyu
VTC Fall3
2021 A Performance Measurement and Analysis Method for Software-Defined Networking of IoV
abstract
Internet of Vehicles (IoV), which plays a significantly important role in smart future cities, has become current hot research topics. However, the high heterogeneous nature of IoV has brought many new challenges such as low network performance and difficult network management for IoV. Software-defined networking enables the efficient solution of these problem. This article studies the measurement and analysis technology for software-defined networking of IoV. A new software-defined networking-based IoV heterogeneous networking measurement framework is proposed to build software-defined networking of IoV. We propose a performance measurement and analysis method to measure and characterize its performance. The performance indexes and measure methods about the delay, loss, throughput, delay jitter is in detail derived. The switch selection mechanism is proposed to establish optimal measurement points of advantage. The packet sampling process is presented to quickly obtain the needed measurement information from massive traffic flows. To validate our measurement method and fairly characterize its measurement performance for different controllers, we conduct massive simulation experiments to systematically analyze and compare current famous controllers. In such a case, we provide more comprehensive, systematic measurement analysis for application in software-defined networking of IoV. Experiments results show that our measurement approach is feasible and effective.
Dingde Jiang, Zhihao Wang 0001, Liuwei Huo, Shaowei Xie
IEEE Trans. Intell. Transp. Syst.2
2020 Research on Design and Application of Mobile Edge Computing Model Based on SDN
abstract
With the rapid development of the mobile Internet and the Internet of Things (IoT), the conventional centralized cloud computing environment is facing severe challenges, such as high latency, and low bandwidth which significantly reduces the user experience for the applications of Virtual Reality (VR), HD Video, etc. Mobile Edge Computing (MEC) architecture can shift several tasks to devices on the edge of the mobile network, decreasing the service time and relieving the flow pressure of the core network. Combining Software Defined Networking (SDN) and MEC, this paper proposes a MEC network model based on SDN and builds test models on physical devices. A set of network testing experiments is carried out to evaluate the performance of the topology. Meanwhile, motivated by the demand for quick processing of surveillance video, an intelligent video processing acceleration application is deployed on the testing platform and cloud computing platform. Under the control of a Floodlight controller, it shows that the MEC scheme proposed in this paper has better performance when carrying latency-sensitive services.
Shaohua Cao, Zhihao Wang 0001, Yizhi Chen, Dingde Jiang
ICCCN2