EDBT 2026 Demo / reviewers in the wild / expert
Chun-Jen Chung
dblp:85/326
· DBLP profile ↗
16ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0002-8873-2382ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-authorSystems, architecture and hardware · 2 · 1 since 2021Security and privacy · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Scalable High-Fidelity Cloud Network Validation via Hybrid ArchitectureabstractEnsuring reliable operation of cloud networks is critical for cloud service providers to guarantee quality of service for tenants. A promising solution is to design a high-fidelity cloud network validation platform that proactively validates the correctness of all operations before implementing changes to the production network. However, the tight coupling between physical and virtual networks in the cloud poses challenges to achieving high-fidelity cloud network validation. Existing network validation platforms focus primarily on traditional physical networks, while ignoring virtual network validation. Regrettably, neglecting the combined validation of physical and virtual networks will result in inaccurate evaluations. To bridge this gap, we present HifiCNet, a high-fidelity platform that concurrently validates both physical and virtual networks. HifiCNet designs an orchestrator to elegantly coordinate the interaction between physical and virtual networks in the cloud and innovatively adopts an emulator-simulator hybrid architecture to ensure high fidelity and scalability for cloud network validation. Through extensive evaluation based on real topologies and traffic traces, we show that HifiCNet enables high-fidelity validation of cloud network configurations, services, and exceptions. Notably, HifiCNet can leverage 38 servers to establish a physical network comprising 10k hosts, as well as a virtual network consisting of 200k virtual machines. Jiawei Liu 0007, Ji Qi 0005, Gongming Zhao, Hongli Xu 0001, Baoqing Wang, Chun-Jen Chung, Xuwei Yang |
IEEE Trans. Computers | 6 |
| 2024 | The Development of A Large-Scale Cloud EmulatorabstractBuilding a realistic and scalable cloud emulator is a significant and unaddressed challenge in the cloud industry. The hyper-scale nature of modern cloud environments, encompassing millions of servers and network devices, combined with the complexity of multiple layers of network virtualization in both underlay and overlay networks, and the heterogeneity of devices from various vendors and models, makes this a complex task. This study develops a large-scale cloud emulator that supports the automatic and flexible configuration of both cloud underlay and overlay networks at scale. The underlay networks emulate various data center topologies and heterogeneous hardware, while the overlay networks emulate virtualized networks and associated private resources, such as networking, storage, services, and virtualization. In the end-to-end performance test, this proposed cloud emulator can emulate both emulated physical machines (EPMs) and emulated virtual machines (EVMs) in the underlay and overlay network, where 100,000 EVMs are emulated with a high emulation density of 10,000 EVMs per EPM in 20 mins. This study also showcases the emulation of a cloud data center in a 200-node Kubernetes cluster in AWS EC2, deploying 10,000 EPMs in a Clos network topology with 500,000 EVMs. Chun-Jen Chung, Liguang Xie |
IC2E | 2 |
| 2024 | HifiCNet: High-Fidelity Cloud Network Validation Platform at Scale by Hybrid ArchitectureabstractEnsuring reliable operation of cloud networks is critical for cloud service providers to guarantee quality of service for tenants. A promising solution is to design a high-fidelity cloud network validation platform that proactively validates the correctness of all operations before implementing changes to the production network. However, the tight coupling between physical and virtual networks in the cloud poses challenges to achieving high-fidelity cloud network validation. Existing network validation platforms focus primarily on traditional physical networks, while ignoring virtual network validation. Regrettably, neglecting the combined validation of physical and virtual networks will result in inaccurate evaluations. To bridge this gap, we present HifiCNet, a high-fidelity platform that concurrently validates both physical and virtual networks. HifiCNet designs an orchestrator to elegantly coordinate the interaction between physical and virtual networks in the cloud and innovatively adopts an emulator-simulator hybrid architecture to ensure high fidelity and scalability for cloud network validation. Through extensive evaluation based on real topologies and traffic traces, we show that HifiCNet enables high-fidelity validation of cloud network configurations, services, and exceptions. Notably, HifiCNet can use 38 servers to establish a physical network comprising 10k hosts, and a virtual network consisting of 200 k virtual machines. Jiawei Liu 0007, Gongming Zhao, Hongli Xu 0001, Baoqing Wang, Peng Yang 0022, Chun-Jen Chung, Min Chen 0033, Xuwei Yang |
ICNP | 6 |
| 2024 | SMART: Dual-channel Southbound Message Delivery in Clouds with Rate EstimationabstractDriving southbound messages from a cloud control plane down to the distributed data plane on every compute node is one of the critical challenges in public clouds. Existing message delivery solutions solely based on remote procedure call (RPC) or message queue (MQ) tend to overlook strict resource constraints, e.g., network bandwidth and CPU capacity. This often results in extensive overhead in the control plane or message redundancy in the data plane, especially when a cloud receives highly concurrent user requests or experiences a rapid expansion. To this end, we design a dual-channel southbound message delivery framework, namely SMART, which combines an RPC channel with an MQ channel, to maximize the resource utilization in the cloud network. In the control plane, we implement a message parsing mechanism and propose a delivery channel selection algorithm based on the deep reinforcement learning (DRL) approach to support efficient dual-channel delivery under resource constraints. In the data plane, we design a message agent on each compute node to ensure the order preservation and state consistency of southbound messages. Both experimental and large-scale simulation results show that SMART demonstrates a reduction in control plane overhead by 64% compared to RPC and redundant messages by 45% compared to MQ, respectively. Luyao Luo, Gongming Zhao, Hongli Xu 0001, Chun-Jen Chung, Liguang Xie |
IWQoS | 4 |
| 2023 | Southbound Message Delivery With Virtual Network Topology Awareness in CloudsabstractSouthbound message delivery from the control plane to the data plane is one of the essential issues in multi-tenant clouds. A natural method of southbound message delivery is that the control plane directly communicates with compute nodes in the data plane. However, due to the large number of compute nodes, this method may result in massive control overhead. The Message Queue (MQ) model can solve this challenge by aggregating and distributing messages to queues. Existing MQ-based solutions often perform message aggregation based on the physical network topology, which do not align with the fundamental requirements of southbound message delivery, leading to high message redundancy on compute nodes. To address this issue, we design and implement VITA, the first-of-its-kind work on virtual network topology-aware southbound message delivery. However, it is intractable to optimally deliver southbound messages according to the virtual attributes of messages. Thus, we design two algorithms, submodular-based approximation algorithm and simulated annealing-based algorithm, to solve different scenarios of the problem. Both experiment and simulation results show that VITA can reduce the total traffic amount of redundant messages by 45%-75% and reduce the control overhead by 33%-80% compared with state-of-the-art solutions. Gongming Zhao, Luyao Luo, Hongli Xu 0001, Chun-Jen Chung, Liguang Xie |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | LICALITY - Likelihood and Criticality: Vulnerability Risk Prioritization Through Logical Reasoning and Deep LearningabstractSecurity and risk assessment aims to prioritize detected vulnerabilities for remediation in a computer networking system. The widely used expert-based risk prioritization approach, e.g., Common Vulnerability Scoring System (CVSS), cannot realistically associate vulnerabilities to the likelihood of exploitation. The CVSS metrics are calculated from static formulas, and cannot easily integrate attackers’ motivations and capabilities w.r.t. the network environmental factors. To address this issue, this paper proposes LICALITY, a vulnerability risk prioritization system. LICALITY captures the attacker’s preference on exploiting vulnerabilities through a threat modeling method, and learns threat attributes that contribute to the exploitation of vulnerability. LICALITY creatively uses a neuro-symbolic model, with neural network (NN) and probabilistic logic programming (PLP) techniques, to learn such threat attributes. The risk of vulnerability is assessed from the criticality of exploitation and the likelihood of exploitation. LICALITY consolidates these two measurements by using a logic reasoning engine. In the evaluation, the historical threat and future threat are from real attack scenarios. The results reveal that LICALITY reduces the vulnerability remediation work of the future threat required by the CVSS by a factor of 2.89 in the first case study and by a factor of 1.85 in the second case study. Such future threats are identified as the top routinely exploited vulnerabilities and the APT attack chained vulnerabilities reported in the Cybersecurity and Infrastructure Security Agency (CISA) alerts. Zhun Yang, Dijiang Huang, Chun-Jen Chung |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2018 | Personalized Learning in a Virtual Hands-on Lab Platform for Computer Science EducationabstractThis Innovate Practice full paper presents a cloud-based personalized learning lab platform. Personalized learning is gaining popularity in online computer science education due to its characteristics of pacing the learning progress and adapting the instructional approach to each individual learner from a diverse background. Among various instructional methods in computer science education, hands-on labs have unique requirements of understanding learner's behavior and assessing learner's performance for personalization. However, it is rarely addressed in existing research. In this paper, we propose a personalized learning platform called ThoTh Lab specifically designed for computer science hands-on labs in a cloud environment. ThoTh Lab can identify the learning style from student activities and adapt learning material accordingly. With the awareness of student learning styles, instructors are able to use techniques more suitable for the specific student, and hence, improve the speed and quality of the learning process. With that in mind, ThoTh Lab also provides student performance prediction, which allows the instructors to change the learning progress and take other measurements to help the students timely. For example, instructors may provide more detailed instructions to help slow starters, while assigning more challenging labs to those quick learners in the same class. To evaluate ThoTh Lab, we conducted an experiment and collected data from an upper-division cybersecurity class for undergraduate students at Arizona State University in the US. The results show that ThoTh Lab can identify learning style with reasonable accuracy. By leveraging the personalized lab platform for a senior level cybersecurity course, our lab-use study also shows that the presented solution improves students engagement with better understanding of lab assignments, spending more effort on hands-on projects, and thus greatly enhancing learning outcomes. Yuli Deng, Duo Lu, Chun-Jen Chung, Dijiang Huang |
FIE | 3 |
| 2018 | Improving student learning performance in a virtual hands-on lab system in cybersecurity educationabstractThis Research Work in Progress paper presents a study on improving student learning performance in a virtual hands-on lab system in cybersecurity education. As the demand for cybersecurity-trained professionals rapidly increasing, virtual hands-on lab systems have been introduced into cybersecurity education as a tool to enhance students' learning. To improve learning in a virtual hands-on lab system, instructors need to understand: what learning activities are associated with students' learning performance in this system? What relationship exists between different learning activities? What instructors can do to improve learning outcomes in this system? However, few of these questions has been studied for using virtual hands-on lab in cybersecurity education. In this research, we present our recent findings by identifying that two learning activities are positively associated with students' learning performance. Notably, the learning activity of reading lab materials (p <; 0:01) plays a more significant role in hands-on learning than the learning activity of working on lab tasks (p <; 0:05) in cybersecurity education.In addition, a student, who spends longer time on reading lab materials, may work longer time on lab tasks (p <; 0:01). Yuli Deng, I-Han Hsiao, Dijiang Huang, Chun-Jen Chung |
FIE | 5 |
| 2018 | Conceptualizing Student Engagement in Virtual Hands-on Lab: Preliminary Findings from a Computer Network Security Course (Abstract Only)abstractEngaged students are more likely to spend longer time on study, and obtain a better academic performance. Previous studies investigated the role of student engagement in virtual learning environments (e.g., online course, online discussion forum, and intelligent tutoring systems). However, it is still challenging to engage students on a virtual hands-on lab system. Comparing to other virtual learning environment, students have a unique learning model -- learning by doing in virtual hands-on lab. To successfully engage students in a large hands-on lab in cybersecurity education, instructors need to understand how students engage in a lab session, and how their engagement affect lab learning outcome in this specific educational setting. In this paper, we developed a conceptual model, especially for virtual hands-on lab education, to describe student engagement during learning processes in working on virtual hands-on lab tasks. This model adopts two existing educational models on engagement behavior. Preliminary data was collected from 109 students' lab project in a computer network security course at Arizona State University in 2016 Fall semester. Pearson correlation coefficient analysis results reveal two statistically significant preliminary results: the longer time a student spends on reading lab instructional material, the more likely the student works longer time on lab tasks (p < 0.01); the longer time a student works on lab tasks, a better learning performance the student archives (p < 0.01). Yuli Deng, I-Han Hsiao, Dijiang Huang, Chun-Jen Chung |
SIGCSE | 5 |
| 2017 | ThoTh Lab: A Personalized Learning Framework for CS Hands-on Projects (Abstract Only)abstractPersonalized learning is often referred to a new learning approach by taking individual parameters such as learning preferences, abilities, skills and knowledge into account. In this poster, we present a personalized learning solution for computer networks, system, and cybersecurity focusing on hands-on projects. The personalized learning models are established in ThoTh Lab - a cloud-based hands-on virtual laboratory for Computer Science (CS) education. ThoTh Lab is a remote web-accessing virtual laboratory and it was originally designed to reduce lab management overhead for instructors and improve learning experience for CS students. By introducing new personalized learning capabilities, we can transfer ThoTh Lab from a traditional hands-on lab resource provisioning system to an active personalized e-learning platform for CS education. The system can track and assess students' hands-on projects' activities to monitor students' lab performance, and then provide intelligent suggestions or resources to improve students' learning experience and outcomes. Our personalized learning framework is distinguished from existing approaches by three salient features: (1) it is built into a hands-on and virtualized laboratory environment usually involving multiple virtual computers and their interconnections, (2) it has incorporated into a wide range of learners' characteristics such as individuals' learning style, prior knowledge and learning effectiveness, and it is designed to be able to include new and customizable features, (3) it uses machine learning approaches to model student characteristics during the learning process. Yuli Deng, Dijiang Huang, Chun-Jen Chung |
SIGCSE | 3 |
| 2015 | Efficient Attribute-Based Comparable Data Access ControlabstractWith the proliferation of mobile devices in recent years, there is a growing concern regarding secure data storage, secure computation, and fine-grained access control in data sharing for these resource-constrained devices in a cloud computing environment. In this work, we propose a new efficient framework named Constant-size Ciphertext Policy Comparative Attribute-Based Encryption (CCP-CABE) with the support of negative attributes and wildcards. It embeds the comparable attribute ranges of all the attributes into the user's key, and incorporates the attribute constraints of all the attributes into one piece of ciphertext during the encryption process to enforce flexible access control policies with various range relationships. Accordingly, CCP-CABE achieves the efficiency because it generates constant-size keys and ciphertext regardless of the number of involved attributes, and it also keeps the computation cost constant on lightweight mobile devices. We further discuss how to extend CCP-CABE to fit a scenario with multiple attribute domains, such that the decryption proceeds from the least privileged attribute domain to the most privileged one to help protect the privacy of the access policy. We provide security analysis and performance evaluation to demonstrate their efficiency at the end. Zhijie Wang 0002, Dijiang Huang, Yan Zhu 0010, Bing Li 0019, Chun-Jen Chung |
IEEE Trans. Computers | 5 |
| 2014 | SeRViTR: A framework, implementation, and a testbed for a trustworthy future Internet
Shingo Ata, Dijiang Huang, Xuan Liu 0002, Akira Wada, Tianyi Xing, Parikshit Juluri, Chun-Jen Chung, Yasuhiro Sato, Deep Medhi |
Comput. Networks | 7 |
| 2013 | Non-intrusive process-based monitoring system to mitigate and prevent VM vulnerability explorationsabstractCloud is gaining momentum but its true potential is hampered by the security concerns it has raised. Having vulnerable virtual machines in a virtualized environment is one such concern. Vulnerable virtual machines are an easy target and existence of such weak nodes in a network jeopardizes its enti Chun-Jen Chung, Jingsong Cui, Pankaj Khatkar, Dijiang Huang |
CollaborateCom | 1 |
| 2013 | NICE: Network Intrusion Detection and Countermeasure Selection in Virtual Network SystemsabstractCloud security is one of most important issues that has attracted a lot of research and development effort in past few years. Particularly, attackers can explore vulnerabilities of a cloud system and compromise virtual machines to deploy further large-scale Distributed Denial-of-Service (DDoS). DDoS attacks usually involve early stage actions such as multistep exploitation, low-frequency vulnerability scanning, and compromising identified vulnerable virtual machines as zombies, and finally DDoS attacks through the compromised zombies. Within the cloud system, especially the Infrastructure-as-a-Service (IaaS) clouds, the detection of zombie exploration attacks is extremely difficult. This is because cloud users may install vulnerable applications on their virtual machines. To prevent vulnerable virtual machines from being compromised in the cloud, we propose a multiphase distributed vulnerability detection, measurement, and countermeasure selection mechanism called NICE, which is built on attack graph-based analytical models and reconfigurable virtual network-based countermeasures. The proposed framework leverages OpenFlow network programming APIs to build a monitor and control plane over distributed programmable virtual switches to significantly improve attack detection and mitigate attack consequences. The system and security evaluations demonstrate the efficiency and effectiveness of the proposed solution. Chun-Jen Chung, Pankaj Khatkar, Tianyi Xing, Jeongkeun Lee, Dijiang Huang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2012 | Constructing a virtual networking environment in a Geo-distributed programmable layer-2 networking environment (G-PLaNE)abstractWith Cloud Computing technology occupying the majority of future Internet research and development work, research on deploying and extending existing capabilities onto a newly emerging infrastructure becomes more significant. For example, extending the virtual network provisioning capability onto a Geo-distributed programmable layer-2 networking environment (G-PLaNE) is a novel attempt and is different from in a single domain system. In this paper, we aim to illustrate how to construct the virtual networking environment upon our self-designed resource provisioning system consisting of multiple clusters through G-PLaNE. Experimenters and researchers are able to develop and explore their own mechanisms in our platform. Furthermore, a concrete example named Secure and Resilient Virtual Trust Routing (SeRViTR) is given to illustrate how this can be constructed over G-PLaNE. Tianyi Xing, Xuan Liu 0002, Chun-Jen Chung, Akira Wada, Shingo Ata, Dijiang Huang, Deep Medhi |
ICC | 3 |
| 2006 | A Two-Echelon Deteriorating Production-Inventory Newsboy Model with Imperfect Production Process
Hui-Ming Wee, Chun-Jen Chung |
ICCSA (3) | 2 |