EDBT 2026 Demo / reviewers in the wild / expert
Dongjie Liu
dblp:75/9482
· DBLP profile ↗
15ranked-venue papers
3as first author
15since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 4 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DMFI: A Dual-Modality Log Analysis Framework for Insider Threat Detection with LoRA-Tuned Language ModelsabstractInsider threat detection (ITD) poses a persistent and high-impact challenge in cybersecurity due to the subtle, long-term, and context-dependent nature of malicious insider behaviors. Traditional models often struggle to capture semantic intent and complex behavior dynamics, while existing LLMbased solutions face limitations in prompt adaptability and modality coverage. To bridge this gap, we propose DMFI, a dual-modality framework that integrates semantic inference with behavior-aware fine-tuning. DMFI converts raw logs into two structured views: (1) a semantic view that processes content-rich artifacts (e.g., emails, https) using instruction-formatted prompts; and (2) a behavioral abstraction, constructed via a 4 W -guided (When-Where-What-Which) transformation to encode contextual action sequences. Two LoRA-enhanced LLMs are fine-tuned independently, and their outputs are fused via a lightweight MLP-based decision module. We further introduce DMFI-B, a discriminative adaptation strategy that separates normal and abnormal behavior representations, improving robustness under severe class imbalance. Experiments on CERT r4.2 and r5.2 datasets demonstrate that DMFI outperforms state-of-the-art methods in detection accuracy. Our approach combines the semantic reasoning power of LLMs with structured behavior modeling, offering a scalable and effective solution for real-world insider threat detection. Kaichuan Kong, Dongjie Liu, Xiao-Bo Jin, Guanggang Geng, Zhiying Li 0003, Jian Weng 0001 |
ICDM | 2 |
| 2025 | Log2Sig: Frequency-Aware Insider Threat Detection via Multivariate Behavioral Signal DecompositionabstractInsider threat detection presents a significant challenge due to the deceptive nature of malicious behaviors, which often resemble legitimate user operations. However, existing approaches typically model system logs as flat event sequences, thereby failing to capture the inherent frequency dynamics and multiscale disturbance patterns embedded in user behavior. To address these limitations, we propose Log2Sig, a robust anomaly detection framework that transforms user logs into multivariate behavioral frequency signals, introducing a novel representation of user behavior. Log2Sig employs Multivariate Variational Mode Decomposition (MVMD) to extract IMFs, which reveal behavioral fluctuations across multiple temporal scales. Based on this, the model further performs joint modeling of behavioral sequences and frequency-decomposed signals: the daily behavior sequences are encoded using a Mamba-Based temporal encoder to capture long-term dependencies, while the corresponding frequency components are linearly projected to match the encoder’s output dimension. These dual-view representations are then fused to construct a comprehensive user behavior profile, which is fed into a multilayer perceptron for precise anomaly detection. Experimental results on the CERT r4.2 and r5.2 datasets demonstrate that Log2Sig significantly outperforms state-of-the-art baselines in both accuracy and F1 score. Kaichuan Kong, Dongjie Liu, Xiao-Bo Jin, Zhiying Li 0003, Guanggang Geng |
TrustCom | 2 |
| 2025 | Context-aware inverse reinforcement learning for modeling individuals' daily activity schedules
Dongjie Liu |
Eng. Appl. Artif. Intell. | 1 |
| 2025 | DPI-ITD: A Dual-Perspective Information-Driven Framework for Insider Threat Detection in IoT SystemsabstractIn Internet of Things (IoT) environments, insider threat detection has advanced with the integration of deep learning techniques, which can effectively model complex behaviors and heterogeneous data. However, the fragmented nature of IoT logs, behavioral redundancy, and the sparsity of insider actions increase detection complexity. While fine-grained behavior classification can improve accuracy, it also raises computational overhead, limiting applicability in resource-constrained scenarios. To address these challenges, we propose dual-perspective information-driven framework for insider threat detection (DPI-ITD), which combines user-centric and behavior-centric analyses to enhance detection efficiency and accuracy. DPI-ITD introduces a symbolic tagging strategy guided by tagging scores (TS), derived from user action diversity and behavioral context, to filter redundant fragments and focus on high-impact behaviors. It further incorporates an adaptive embedding mechanism based on GloVe, which dynamically adjusts the context window for rare but critical actions. Experiments on multiple closed and open behavioral datasets demonstrate DPI-ITD’s superior detection performance, scalability, and efficiency, confirming its suitability for lightweight deployment in real-world IoT security systems. Kai-Chuan Kong, Xiao-Bo Jin, Dongjie Liu, Zhiquan Liu 0001, Guanggang Geng |
IEEE Internet Things J. | 3 |
| 2025 | Implementation of a Cell-Free RAN System With Distributed Cooperative Transceivers Under ORAN ArchitectureabstractAs a key technology for the evolution to the sixth generation (6G) systems, cell-free massive multiple-input multiple-output (CF-mMIMO) can effectively improve the spectrum efficiency, peak rate, and reliability of wireless communication systems. Starting from the scalable implementation of CF-mMIMO, we study a cell-free RAN (CF-RAN) with distributed cooperative transceivers under the open RAN (ORAN) architecture. Through theoretical analysis and numerical simulation, we investigate the uplink and downlink spectral efficiencies of CF-mMIMO with the distributed transceivers. We then discuss the implementation issues of CF-RAN under ORAN architecture, including time-frequency synchronization and over-the-air reciprocity calibration, low layer splitting, deployment of ORAN radio units (O-RU), and artificial intelligent-based user associations. Finally, we present some representative experimental results for the uplink distributed reception and downlink coherent joint transmission of CF-RAN with commercial off-the-shelf O-RUs. Xinjiang Xia, Pengzhe Xin, Dongjie Liu, Mengting Lou, Jing Jin 0007, Qixing Wang, Dongming Wang 0002, Yongming Huang 0001, Xiaohu You 0001, Jiangzhou Wang |
IEEE J. Sel. Areas Commun. | 5 |
| 2024 | Cross-Domain AI Towards 6G: Requirements, Solution, and ValidationabstractWith the continuous enrichment of intelligent applications, it is anticipated that 6G will evolve into a ubiquitous intelligent network. In order to achieve the vision of full-scenarios intelligent services, how to collaborate AI capabilities in different domains is an urgent issue. After analyzing potential use cases and technological requirements, this paper proposes an endto-end (E2E) cross-domain artificial intelligence (AI) collaboration framework for next-generation mobile communication systems. Two potential technical solutions, namely cross-domain AI management and orchestration and RAN-CN convergence, are presented to facilitate intelligent collaboration in both E2E scenarios and the edge network. Furthermore, we have validated the performance of a cross-domain federated learning algorithm in a simulated environment for the prediction of received signal power. While ensuring the security and privacy of terminal data, we have analyzed the communication overhead caused by cross-domain training. Dongjie Liu |
IWCMC | 4 |
| 2024 | STFT-TCAN: A TCN-attention based multivariate time series anomaly detection architecture with time-frequency analysis for cyber-industrial systemsabstractNetworks and industrial systems play a pivotal role in modern society, and their security has garnered increasing attention. Anomalies within industrial equipment may propagate through fault transmission, leading to a cascade of failures. Additionally, cyberattacks on equipment can result in significant losses. Therefore, in the realm of industrial and cyberspace domains, an effective multivariate time series anomaly detection system for monitoring equipment is instrumental in ensuring the healthy operation of the machinery. Nevertheless, detecting anomalies in numerous time series remains challenging, stemming from the absence of anomaly labels and the complexity of the data patterns. Existing algorithms predominantly concentrate on modeling within the time domain, falling short in fully leveraging the informative features present in frequency domain data, resulting in diminished detection performance. This paper introduces STFT-TCAN, a model for anomaly detection in time series that seamlessly integrates information from both time and frequency domains for extracting data features. Sliding windows and the Short Time Fourier Transform (STFT) are utilized to construct a frequency matrix, effectively amalgamating the characteristics of both time and frequency domains within the time series. Furthermore, the model employs Temporal Convolutional Networks (TCN) and Transformer attention mechanisms (which combined to form the TCAN module) to capture the features of multivariate time series, thereby resulting in heightened detection accuracy. The proposed model undergoes validation on six publicly available datasets, showcasing the superior performance of the STFT-TCAN model in comparison to current baseline methods. It adeptly extracts features from both frequency and time domains in sequential data, thereby achieving state-of-the-art performance in tasks related to anomaly detection in multivariate time series. Fei-Fan Tu, Dongjie Liu, Zhiwei Yan, Xiao-Bo Jin, Guanggang Geng |
Comput. Secur. | 2 |
| 2024 | Dynamic Recursive Logit Model for Vehicle Driving Route Choices and Path Inference With Incomplete Fixed Location Sensor DataabstractThis paper studies the estimation of dynamic route choice behavior of drivers with incomplete fixed location-based sensor data, such as radio frequency identification (RFID) data. Unlike global positioning system (GPS) data providing continuous vehicle trajectories, the location-based RFID sensors record vehicles only when they pass by but may not record all vehicles. These bring challenges for route choice modeling since empty sensor observations will also influence the likelihood of routes that do not cross these sensors. Also, it requires the essential integration of dynamic traffic conditions into the modeling process as observation paths may share the same sensor detection sequence but exhibit different travel times. To address these challenges, the paper proposes a dynamic recursive logit model to estimate vehicle route choices with RFID data, enabling the characterization of the likelihood function of sensor observation paths without the need for path enumeration between consecutive detections. Also, we develop a probabilistic dynamic link utilization estimation method to infer the actual path of each vehicle from the available sensor observations. It serves as a validation process to ensure that the route choice behavior can comprehensively reflect traffic flow dynamics. The proposed methods are evaluated using both a simulated dataset on the Sioux Falls network and a collection of real-world RFID data in Chongqing, China. The simulation results show that the proposed method can recover true choice parameters and perform significantly better compared with static models. The real-world experimental results highlight its efficacy in aggregated link flow prediction and individual trajectory reconstruction. Dawei Li 0013, Zhenliang Ma, Dongjie Liu, Chongqi He |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | Link Traffic-Delay Mapping Model Learning Based on Multi-Class Samples in Software-Defined NetworksabstractDelays are crucial factors in the service management of networks, especially software-defined networks. Unfortunately, it is very difficult to accurately model a traffic-delay mapping without any assumptions on an uncertain network. In this article, we present a machine learning-based solution to generate a mapping between link traffic and link delay in software-defined networks. The proposed solution only requires a small number of link delay samples from the production network. The small number of link delay samples is not sufficient for learning link traffic-delay mapping. To solve the above problem, we extend the link delay-related data via a sample transfer method and a distributed path delay data collection method without the assistance of the controller. We design a link traffic-delay mapping learning solution using the above three classes of data. This solution uses a traffic segment-based statistical mechanism to deduce the mean link delay effectively from the collected path delay information and implements effective sample transfer via a distance-based approximation. On the basis of specially designed deep learning structures and training procedures, the proposed learning solution effectively builds traffic-delay mapping models using the samples transferred from an experimental network and the samples of the production network. Xinchang Zhang 0001, Maoli Wang, Yuanjie Zheng, Dongjie Liu |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Full-spectrum cell-free RAN for 6G systems: system design and experimental results
Dongming Wang 0002, Xiaohu You 0001, Yongming Huang 0001, Wei Xu 0001, Jiamin Li 0001, Pengcheng Zhu 0001, Yanxiang Jiang, Xinjiang Xia, Qingji Jiang, Pan Wang 0006, Dongjie Liu, Mengting Lou, Jing Jin 0007, Qixing Wang, Jiangzhou Wang |
Sci. China Inf. Sci. | 13 |
| 2023 | Experimental Performance Evaluation of Cell-Free Massive MIMO Systems Using COTS RRU With OTA Reciprocity Calibration and Phase SynchronizationabstractDownlink coherent multiuser transmission is an essential technique for cell-free massive multiple-input multiple-output (MIMO) systems, and the availability of channel state information (CSI) at the transmitter is a basic requirement. To avoid CSI feedback in a time-division duplex system, the uplink channel parameters should be calibrated to obtain the downlink CSI due to the radio frequency circuit mismatch of the transceiver. In this paper, a design of a reference signal for over-the-air reciprocity calibration is proposed. The frequency domain generated reference signals can make full use of the flexible frame structure of the fifth-generation (5G) new radio, which can be completely transparent to commercial off-the-shelf (COTS) remote radio units (RRU) and commercial user equipments. To further obtain the calibration of multiple RRUs, an interleaved RRU grouping with a genetic algorithm is proposed, and an averaged Argos calibration algorithm is also presented. We develop a cell-free massive MIMO prototype system with COTS RRUs, demonstrate the statistical characteristics of the calibration error and the effectiveness of the calibration algorithm, and evaluate the impact of the calibration delay on the different cooperative transmission schemes. Pan Wang 0006, Xianghu Liang, Dongjie Liu, Mengting Lou, Jing Jin 0007, Qixing Wang, Dongming Wang 0002, Yongming Huang 0001, Xiaohu You 0001, Jiangzhou Wang |
IEEE J. Sel. Areas Commun. | 5 |
| 2023 | Service Delay Minimization for Federated Learning Over Mobile DevicesabstractFederated learning (FL) over mobile devices has fostered numerous intriguing applications/services, many of which are delay-sensitive. In this paper, we propose a service delay efficient FL (SDEFL) scheme over mobile devices. Unlike traditional communication efficient FL, which regards wireless communications as the bottleneck, we find that under many situations, the local computing delay is comparable to the communication delay during the FL training process, given the development of high-speed wireless transmission techniques. Thus, the service delay in FL should be computing delay + communication delay over training rounds. To minimize the service delay of FL, simply reducing local computing/communication delay independently is not enough. The delay trade-off between local computing and wireless communications must be considered. Besides, we empirically study the impacts of local computing control and compression strategies (i.e., the number of local updates, weight quantization, and gradient quantization) on computing, communication and service delays. Based on those trade-off observation and empirical studies, we develop an optimization scheme to minimize the service delay of FL over heterogeneous devices. We establish testbeds and conduct extensive emulations/experiments to verify our theoretical analysis. The results show that SDEFL reduces notable service delay with a small accuracy drop compared to peer designs. Rui Chen 0026, Dian Shi, Xiaoqi Qin, Dongjie Liu, Miao Pan, Shuguang Cui |
IEEE J. Sel. Areas Commun. | 4 |
| 2022 | Multi-scale semantic deep fusion models for phishing website detectionabstractIn view of semantic counterfeiting characteristics of phishing websites and their multi-scale composition, this paper fully considers the semantic information of different scales, and proposes three semantic-based phishing detection models at different depths using various deep learning methods. The proposed three models are Multi-scale Data-layer Fusion (MDF) model, Multi-scale Feature-layer Fusion (MFF) model and Multi-scale In-depth Fusion(MIF) model. Experimental results on a constructed complex dataset show that the three models all have good recognition capabilities and the MIF model achieves the best performance on a complex dataset, with an F1-Measure of 0.9830, AUC value of 0.9993 and a false positive rate of 0.0047. Then with further comparison with both visual and text methods and an active discovery experiment lasting for 6 months with 3016 phishing websites detected in the real network environment, it is found that the proposed model is both competitive and practical for real detection scenarios. Dongjie Liu, Guanggang Geng, Xinchang Zhang 0001 |
Expert Syst. Appl. | 1 |
| 2022 | Seeing Traffic Paths: Encrypted Traffic Classification With Path Signature FeaturesabstractAlthough many network traffic protection methods have been developed to protect user privacy, encrypted traffic can still reveal sensitive user information with sophisticated analysis. In this paper, we propose ETC-PS, a novel encrypted traffic classification method with path signature. We first construct the traffic path with a session packet length sequence to represent the interactions between the client and the server. Then, path transformations are conducted to exhibit its structure and obtain different information. A multiscale path signature is finally computed as a kind of distinctive feature to train the traditional machine learning classifier, which achieves highly robust accuracy and low training overhead. Six publicly available datasets with different traffic types of HTTPS/1, HTTPS/2, QUIC, VPN, non-VPN, Tor, and non-Tor are used to conduct closed-world and open-world evaluations to verify the effectiveness of ETC-PS. The experimental results demonstrate that ETC-PS is superior to the state-of-the-art methods in terms of accuracy, f1 score, time complexity, and stability. Guanggang Geng, Xiao-Bo Jin, Dongjie Liu, Jian Weng 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | An efficient multistage phishing website detection model based on the CASE feature framework: Aiming at the real web environmentabstractPhishing has become a favorite method of hackers for committing data theft and continues to evolve. As long as phishing websites continue to operate, many more people and companies will suffer privacy leaks or financial losses. Therefore, the demand for fast and accurate phishing website detection grows stronger. However, the existing phishing detection methods do not fully analyze the features of phishing, and the performance and efficiency of the models only apply to certain limited datasets and need to be improved to be applied to the real web environment. This paper fully considers the social engineering principles of phishing, proposes a comprehensive and interpretable CASE feature framework and designs a multistage phishing detection model to effectively detect phishing sites, especially in the real web environment, where high efficiency and performance and extremely low false alarm rates are required. To fully verify the proposed method, two kinds of data experiments were carried out. One was the comparative experiments among different features and different detection models on CASE, which covers both classic machine learning and deep learning algorithms based on a constructed complex dataset. The other was a one-year phishing discovery experiment in the real web environment. The proposed method achieves better detection results under the premise of significantly shortening the execution time and works well in real phishing discovery, which proves its high practicability in reality. Dongjie Liu, Guanggang Geng, Xiao-Bo Jin, Wei Wang 0083 |
Comput. Secur. | 1 |