EDBT 2026 Demo / reviewers in the wild / expert
Xiaofan Yang 0001
dblp:74/2319-1
· DBLP profile ↗
28ranked-venue papers
10as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 12 · 7 first-author · 1 since 2021Security and privacy · 9 · 5 since 2021Theory of computation · 8 · 5 first-authorHuman-computer interaction and ubiquitous computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating Insider-Facilitated Advanced Persistent Threat: A Three-Player Differential Game ApproachabstractAdvanced Persistent Threat (APT) presents a significant challenge to the cybersecurity of contemporary organizations. This challenge is further exacerbated when APT actors collaborate with malicious insiders. The involvement of the insider transforms a bilateral adversarial scenario into a triadic strategic interaction, introducing additional layers of complexity in modeling and defense planning. Effective defense against insider-facilitated APT necessitates a comprehensive treatment of two critical aspects: (i) the dynamic strategic interactions among the three players—the defender, the insider, and the APT actor—and (ii) the impact of these interactions on the evolving state of the intranet. However, both dimensions are insufficiently addressed in existing research. To bridge this gap, we first develop an expected state evolution model that captures the real-time influence of the dynamic strategies of the players on the expected compromise state of the intranet. Building upon this, we formulate a three-player differential game model that explicitly incorporates the dynamic interactions of all participants. The associated optimality system is derived and numerically solved using a proposed iterative algorithm. The proposed algorithm achieves a 27.5% improvement in the organization’s expected payoff compared to baseline permissible strategies. Subsequently, we analyze key properties of the proposed framework and empirically evaluate the cost-effectiveness of the resulting defense strategy. To the best of our knowledge, this work represents the first application of three-player differential game theory in the domain of cybersecurity, offering a novel approach to defending against insider-facilitated APT. Lu-Xing Yang, Xiaofan Yang 0001, Gang Li 0009, Robin Doss |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Malware containment with immediate response in IoT networks: An optimal control approach
Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009, Qingyi Zhu, Chenquan Gan, Xiaofan Yang 0001 |
Comput. Commun. | 6 |
| 2024 | Modeling and study of defense outsourcing against advanced persistent threat through impulsive differential game approach
Xiaofan Yang 0001, Lu-Xing Yang, Kaifan Huang |
Comput. Secur. | 2 |
| 2024 | Game-theoretic modeling and analysis of cyberbullying spreading on OSNs
Qi Chu 0007, Lu-Xing Yang, Xiaofan Yang 0001 |
Inf. Sci. | 4 |
| 2024 | Cost-Effective Hybrid Control Strategies for Dynamical Propaganda War GameabstractCyber propaganda wars significantly impact users on Online Social Networks (OSNs), potentially altering their psychological/ideological attitudes and behaviors. Understanding these behavioral dynamics necessitates models that can effectively capture the propagation of dual competitive information, encompassing both propaganda and counter-propaganda campaigns by both conflicting parties. However, current models do not adequately account for competitive information spreading in dual setting and it lacks efficient strategies for managing both propaganda and counter-propaganda investments. To bridge these gaps, our study presents an innovative netwORked dIfferENTial gAme wiTh hybrId cONtrol (ORIENTATION) framework that integrates differential game with 1) a degree-based network model characterizing the spreading dynamics of dual competitive information for both parties; and 2) a dual hybrid control mechanism consisting of investment rates by continuous-time propaganda and discrete-time counter-propaganda. Using this framework, we formulate the Hybrid-contrOlled Differential GamE (HODGE) problem. We theoretically derive the necessary conditions for Nash equilibrium, and develop an iterative algorithm, termed theHODGEalgorithm, to numerically approximate the Nash equilibrium. Our experiments, performed on different groups of OSNs, reveal that the resulting strategy profiles consistently outperform several alternative profiles in terms of cost-effectiveness. Scalability assessment for theHODGEalgorithm is then carried out on OSNs with different scales, demonstrating its strong performance in terms of computational efficiency, scalability and practicability. Additional experimental results suggest that a decrease in the lower bounds of the investment rates in both propaganda and counter-propaganda campaigns and an early implementation of counter-propaganda strategies can significantly enhance cost-effectiveness, offering strategic insights for those engaged in cyber propaganda war. Xiaojuan Cheng, Lu-Xing Yang, Qingyi Zhu, Chenquan Gan, Xiaofan Yang 0001, Gang Li 0009 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Cost-Effective Company Response Policy for Product Co-Creation in Company-Sponsored Online CommunityabstractProduct co-creation based on company-sponsored online community has come to be a paradigm of developing new products collaboratively with customers. In such a product co-creation campaign, the sponsoring company needs to interact intensively with active community members about the design scheme of the product. We call the collection of the rates of the company’s response to active community members at all time in the co-creation campaign as a company response policy (CRP). This article addresses the problem of finding a cost-effective CRP (the CRP problem). First, we introduce a novel community state evolutionary model and, thereby, establish an optimal control model for the CRP problem (the CRP model). Second, based on the optimality system for the CRP model, we present an iterative algorithm for solving the CRP model (the CRP algorithm). Third, through extensive numerical experiments, we conclude that the CRP algorithm converges and the resulting CRP exhibits excellent cost benefit. Consequently, we recommend the resulting CRP to companies that embrace product co-creation. Next, we discuss how to implement the resulting CRP. Finally, we investigate the effect of some factors on the cost benefit of the resulting CRP. To our knowledge, this work is the first attempt to study value co-creation through optimal control theoretic approach. Lu-Xing Yang, Xiaofan Yang 0001, Kaifan Huang, Gang Li 0009, Yong Xiang 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2023 | Impulsive Artificial Defense Against Advanced Persistent ThreatabstractAdvanced persistent threat (APT) as a new type of cyber espionage poses a severe threat to modern organizations. Artificial APT defense, in which an organization engages experienced cybersecurity experts to artificially check if there exist rootkits implanted by APT actors within the organizational internet and, if so, artificially remove the discovered rootkits, is recognized as an indispensable part of APT defense. There are two different ways of artificial APT defenses: continuous artificial defense (CAD), where the defense work is conducted at all time points, and impulsive artificial defense (IAD), where the defense work is conducted at a scheduled sequence of time points. IAD is superior to CAD in terms of the overall service cost. In the context of IAD, we refer to each sequence of service costs as an IAD policy. This paper addresses the problem of developing a cost-effective IAD policy (the IAD problem). First, by introducing an impulsive state evolutionary model for the organizational intranet, the IAD problem is reduced to an optimal impulsive control model (the IAD model). Second, by deriving the optimality system for the IAD model, an iterative algorithm for solving the IAD model (the IAD algorithm) is presented. Next, the convergence and effectiveness of the IAD algorithm are validated through numerical experiments. Finally, the effect of some factors is inspected. To our knowledge, this is the first time IAD is inspected from the perspective of optimal impulsive control theory. Xiaofan Yang 0001, Lu-Xing Yang, Kaifan Huang, Gang Li 0009 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Containing Misinformation Spread: A Collaborative Resource Allocation Strategy for Knowledge Popularization and Expert EducationabstractWith the prevalence of online social networks, the potential threat of misinformation has greatly enhanced. Therefore, it is significant to study how to effectively control the spread of misinformation. Publishing the truth to the public is the most effective approach to controlling the spread of misinformation. Knowledge popularization and expert education are two complementary ways to achieve that. It has been proven that if these two ways can be combined to speed up the release of the truth, the impact caused by the spread of misinformation will be dramatically reduced. However, how to reasonably allocate resources to these two ways so as to achieve a better result at a lower cost is still an open challenge. This paper provides a theoretical guidance for designing an effective collaborative resource allocation strategy. First, a novel individual-level misinformation spread model is proposed. It well characterizes the collaborative effect of the two truth-publishing ways on the containment of misinformation spread. On this basis, the expected cost of an arbitrary collaborative strategy is evaluated. Second, an optimal control problem is formulated to find effective strategies, with the expected cost as the performance index function and with the misinformation spread model as the constraint. Third, in order to solve the optimal control problem, an optimality system that specifies the necessary conditions of an optimal solution is derived. By solving the optimality system, a candidate optimal solution can be obtained. Finally, the effectiveness of the obtained candidate optimal solution is verified by a series of numerical experiments. Linhong Li, Kaifan Huang, Xiaofan Yang 0001 |
Secur. Commun. Networks | 3 |
| 2022 | Effective Multiplatform Advertising PolicyabstractMultiplatform advertising (MPA) is recognized as an effective means of enhancing marketing revenue. In the context, we refer to the scheme of dynamically allocating the advertising expenditure among the selected media platforms as an MPA policy, and we refer to the problem of developing an MPA policy with maximum benefit as the MPA problem. This article is devoted to the solution of the MPA problem. An evolutionary model for the expected market state, in which the influence of both advertising and word-of-mouth (WOM) propagation is accounted for, is established. On this basis, the expected benefit of an MPA policy is calculated. Thereby, the MPA problem is reduced to an optimal control problem we refer to as the MPA model, where the objective functional stands for the expected benefit of an MPA strategy. The optimality system for the MPA model is derived. We refer to the MPA policy obtained by solving the optimality system as the promising MPA policy. The structure of the promising MPA policy is inspected. Through extensive comparative experiments, it is concluded that the promising MPA policy is superior to the majority of MPA policies in terms of expected benefit. Finally, how the expected benefit of the promising MPA policy is influenced by some factors is investigated. Kaifan Huang, Lu-Xing Yang, Xiaofan Yang 0001, Yuan Yan Tang |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2021 | Effective Quarantine and Recovery Scheme Against Advanced Persistent ThreatabstractAdvanced persistent threat (APT) for cyber espionage poses a great threat to modern organizations. In order to mitigate the impact of APT on an organization, all the compromised systems in the organization must be quarantined and recovered in a timely and effective way. This article focuses on the problem of customizing a dynamic quarantine and recovery (QAR) scheme for an organization so that the APT impact is minimized. Based on a novel node-level epidemic model characterizing the effect of the QAR scheme on the expected state of the underlying network, we estimate the expected impact of APT under a QAR scheme. On this basis, we model the original problem as an optimal control problem. By use of optimal control theory, we derive the optimality system for the optimal control problem and thereby introduce the concept of normal potential optimal (NPO) control. Next, through comparative experiments, we find that the NPO control outperforms a set of heuristic controls. Hence, the QAR scheme associated with the NPO control is satisfactory in terms of the effectiveness of defending against APT. Finally, we examine the effect of some factors on the expected APT impact under the NPO control. This article would be helpful to the defense against APT for cyber espionage. Lu-Xing Yang, Pengdeng Li, Xiaofan Yang 0001, Yong Xiang 0001, Frank Jiang 0001, Wanlei Zhou 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2020 | A Risk Management Approach to Defending Against the Advanced Persistent ThreatabstractThe advanced persistent threat (APT) as a new kind of cyber attack has posed a severe threat to modern organizations. When the APT has been detected, the organization has to deal with the APT response problem, i.e., to allocate the available response resources to fix her insecure hosts so as to mitigate her potential loss. This paper addresses the APT response problem by using the risk management approach. First, we introduce a model characterizing the evolution of the organization's expected state. By analyzing this model, we find the organization's expected state approaches a common limit expected state. Then, we use the organization's expected loss per unit time to measure her potential loss, and we find this measure is determined by the organization's limit expected state. On this basis, we model the APT response problem as a game-theoretic problem (the APT response game) in which the organization seeks a Nash equilibrium. We present a greedy algorithm for solving the game. Comparative experiments show that the algorithm is effective. Therefore, we recommend the response strategy generated by performing the algorithm. These findings contribute to defending against the APT. To our knowledge, this is the first time the APT response problem is addressed. Lu-Xing Yang, Pengdeng Li, Xiaofan Yang 0001, Yuan Yan Tang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | Seeking Best-Balanced Patch-Injecting Strategies through Optimal Control ApproachabstractTo restrain escalating computer viruses, new virus patches must be constantly injected into networks. In this scenario, the patch-developing cost should be balanced against the negative impact of virus. This article focuses on seeking best-balanced patch-injecting strategies. First, based on a novel virus-patch interactive model, the original problem is reduced to an optimal control problem, in which (a) each admissible control stands for a feasible patch-injecting strategy and (b) the objective functional measures the balance of a feasible patch-injecting strategy. Second, the solvability of the optimal control problem is proved, and the optimality system for solving the problem is derived. Next, a few best-balanced patch-injecting strategies are presented by solving the corresponding optimality systems. Finally, the effects of some factors on the best balance of a patch-injecting strategy are examined. Our results will be helpful in defending against virus attacks in a cost-effective way. Kaifan Huang, Pengdeng Li, Lu-Xing Yang, Xiaofan Yang 0001, Yuan Yan Tang |
Secur. Commun. Networks | 4 |
| 2019 | Effective Repair Strategy Against Advanced Persistent Threat: A Differential Game ApproachabstractAdvanced persistent threat (APT) is a new kind of cyberattack that poses a serious threat to modern society. When an APT campaign on an organization has been identified, the available repair resources must be reasonably allocated to the potentially insecure hosts to mitigate the potential loss of the organization. We refer to the feasible repair resource allocation strategies as repair strategies. This paper focuses on the APT repair problem, i.e., the problem of developing effective repair strategies for organizations. First, for an organization with time-varying communication relationship, we establish an evolution model of the organization's expected state, in which the impact of lateral movement of APT is accommodated. On this basis, we model the APT repair problem as a differential Nash game problem (the APT repair game) in which the attacker attempts to maximize his potential benefit, and the organization manages to minimize its potential loss. Second, we derive a system (the potential system) for calculating a potential Nash equilibrium of an APT repair game, and we examine the structure of the potential attack and repair strategies in a potential Nash equilibrium. Next, we solve some potential systems to get the corresponding potential Nash equilibria. Finally, by comparison with a large number of randomly generated attack and repair strategies, we conclude that the potential Nash equilibrium of each APT repair game is a Nash equilibrium of the game. Therefore, we recommend to organizations their respective potential repair strategies. Our findings help to better understand and effectively defend against APT. Lu-Xing Yang, Pengdeng Li, Yushu Zhang 0001, Xiaofan Yang 0001, Yong Xiang 0001, Wanlei Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Defending against the Advanced Persistent Threat: An Optimal Control ApproachabstractThe new cyberattack pattern of advanced persistent threat (APT) has posed a serious threat to modern society. This paper addresses the APT defense problem, that is, the problem of how to effectively defend against an APT campaign. Based on a novel APT attack-defense model, the effectiveness of an APT defense strategy is quantified. Thereby, the APT defense problem is modeled as an optimal control problem, in which an optimal control stands for a most effective APT defense strategy. The existence of an optimal control is proved, and an optimality system is derived. Consequently, an optimal control can be figured out by solving the optimality system. Some examples of the optimal control are given. Finally, the influence of some factors on the effectiveness of an optimal control is examined through computer experiments. These findings help organizations to work out policies of defending against APTs. Pengdeng Li, Xiaofan Yang 0001, Qingyu Xiong, Junhao Wen 0001, Yuan Yan Tang |
Secur. Commun. Networks | 2 |
| 2014 | Exact formulas for fixation probabilities on a complete oriented star
Xiaofan Yang 0001, Jiming Liu 0001 |
Inf. Sci. | 1 |
| 2012 | Optimal broadcasting for locally twisted cubes
Xiaofan Yang 0001, Lu-Xing Yang |
Inf. Process. Lett. | 1 |
| 2012 | Routing and wavelength assignment for 3-ary n-cube in array-based optical network
Cui Yu, Xiaofan Yang 0001, Lu-Xing Yang |
Inf. Process. Lett. | 2 |
| 2010 | Embedding meshes/tori in faulty crossed cubes
Xiaofan Yang 0001, Qiang Dong, Yuan Yan Tang |
Inf. Process. Lett. | 1 |
| 2008 | Embedding a family of disjoint multi-dimensional meshes into a crossed cube
Qiang Dong, Xiaofan Yang 0001, Juan Zhao 0011 |
Inf. Process. Lett. | 2 |
| 2008 | Embedding a family of disjoint 3D meshes into a crossed cube
Qiang Dong, Xiaofan Yang 0001, Juan Zhao 0011, Yuan Yan Tang |
Inf. Sci. | 2 |
| 2007 | A (4n-9)/3 diagnosis algorithm on n-dimensional cube network
Xiaofan Yang 0001, Yuan Yan Tang |
Inf. Sci. | 1 |
| 2007 | Efficient Fault Identification of Diagnosable Systems under the Comparison ModelabstractDiagnosis-by-comparison is a realistic approach to the fault diagnosis of massive multicomputers. This paper addresses the fault identification of diagnosable multicomputer systems under the MM* comparison model. We find that the fault location task can be reduced to that under the classical PMC* model. On this basis, we present an Ο(n×Δ3×δ) time diagnosis algorithm for an n-node MM* diagnosable system, where Δ and δ denote the maximum and minimum degrees of a node, respectively. The proposed algorithm is much more effi-cient than the fastest known diagnosis algorithm (which consumes Ο(n5) time) because realistic massive multi-computers are sparsely interconnected and hence Δ, δ « n. Xiaofan Yang 0001, Yuan Yan Tang |
IEEE Trans. Computers | 1 |
| 2006 | Minimum neighborhood in a generalized cube
Xiaofan Yang 0001, Jianqiu Cao, Graham M. Megson |
Inf. Process. Lett. | 1 |
| 2006 | An oblivious shortest-path routing algorithm for fully connected cubic networks
Xiaofan Yang 0001, Graham M. Megson, David J. Evans 0001 |
J. Parallel Distributed Comput. | 1 |
| 2005 | Existence and Stability of Periodic Solution in a Class of Impulsive Neural Networks
Xiaofan Yang 0001, David J. Evans 0001, Yuan Yan Tang |
ISNN (1) | 1 |
| 2005 | Maximum induced subgraph of a recursive circulant
Xiaofan Yang 0001, David J. Evans 0001, Graham M. Megson |
Inf. Process. Lett. | 1 |
| 2004 | Generalized honeycomb torus is Hamiltonian
Xiaofan Yang 0001, David J. Evans 0001, Hong-Jian Lai, Graham M. Megson |
Inf. Process. Lett. | 1 |
| 1999 | Honeycomb tori are Hamiltonian
Graham M. Megson, Xiaofan Yang 0001 |
Inf. Process. Lett. | 2 |