EDBT 2026 Demo / reviewers in the wild / expert
Guangxing Zhang
dblp:87/4248
· DBLP profile ↗
38ranked-venue papers
3as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 27 · 14 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Not All Pretrained Representation has The Sweet Danger of Sugar: Robust and Trustworthy Representation Learning for Encrypted Malicious Traffic IdentificationabstractIdentifying encrypted malicious traffic is a key challenge in network security. Although pre-training techniques based on self-supervised learning are a trend towards reducing dependence on labeled data, existing mainstream methods that directly apply the architecture of natural language processing and masked language modeling tasks have been shown to be "high sugar" by recent research. They may rely on specific "shortcuts" rather than robust traffic behavioral representations to achieve inflated performance. How to extract more robust and generalizable features from covert and sparse encrypted malicious traffic is a major challenge. Therefore, we propose SUGARLESS, a robust representation learning for encrypted malicious traffic identification. To depart from the BERT-based paradigm, we first propose a spatial-temporal contrastive learning as the pre-training task that aligns temporal and spatial modal features without using NLP-style objectives, encouraging the model to learn cross-modal traffic correlations between modalities. We also propose a traffic-specific prompt-tuning mechanism to bridge the gap between pre-training and downstream tasks. Meanwhile, we develop a spatial-temporal feature fusion module to maintain this alignment during fine-tuning. Experiments on two public malware traffic datasets show that SUGARLESS achieves the best precision, recall, and F1-score with competitive accuracy, improves the average F1-score by 9.26% over YaTC, and is more robust under packet loss and reordering. Mingyu Qiao, Zulong Diao, Guangxing Zhang, Wanhua Li, Haiyang Jiang 0001, Zhenyu Li 0001, Gaogang Xie |
APNet | 3 |
| 2026 | Not All Flows are Worth N Packets: Robust Encrypted Traffic Classification via Dynamic Patch-level Feature LearningabstractNetwork traffic classification is significant for modern network security. The widespread use of encryption protocols, such as TLS, has resulted in fewer identifiable features of traffic, rendering encrypted traffic classification a challenging task. However, existing flow-level classification methods typically rely on the features of the first N packets. This fixed-length paradigm, truncating long flows and padding short flows with invalid data, is difficult to adapt to the dynamic distribution of traffic length, which limits robustness in interference environments such as packet loss. Considering this limitation, we propose DART, a robust encrypted traffic classification method via dynamic patch-level feature learning. We first design a robust feature representation method to improve robustness against interference, which divides a flow into multiple sub-flows named patches to extract patch-level features, replacing the interference-prone packet-by-packet sequence and significantly reducing the length of the feature sequence. We also propose a sample-adaptive dynamic inference mechanism in response to traffic heterogeneity. The input scale is adaptively selected based on traffic complexity, and simple samples are allowed to exit early in shallow layers, achieving a balance between accuracy and efficiency. The experimental results on two public malware traffic datasets demonstrate that DART exhibits excellent anti-interference robustness and improves classification accuracy by 6.59%-30.51%, while maintaining high classification efficiency compared to existing mainstream methods. Mingyu Qiao, Zulong Diao, Guangxing Zhang, Haiyang Jiang 0001, Zhenyu Li 0001, Gaogang Xie |
APNet | 3 |
| 2026 | Task-Aware Network Traffic Label Reuse With Schema-Gated EvidenceabstractNetwork traffic labels are built from heterogeneous evidence: capture metadata, port rules, service names, model predictions, and expert decisions. These sources are not interchangeable across tasks: HTTP can support an application label but cannot prove attack behavior. We propose TaskLabel, a schema-gated framework that makes traffic-label reuse traceable and reviewable. TaskLabel stores each label as a schema-bound artifact with traffic unit, target schema, confidence, provenance, evidence requirement, and reuse boundary. Its compatibility gate admits weak-source votes only when source semantics match the target dataset schema; otherwise, the cue remains provenance and is routed for review. In a retrospective pilot on 1652 held-out RT-IoT2022 flows, non-model cues reach 64.6% of flows, but direct reuse disagrees with held-out target labels on 32.5% of reached flows. Schema-agnostic weak fusion falls to 58.5% macro-F1, whereas TaskLabel blocks incompatible votes and preserves the feature-only target predictor at 93.3% macro-F1 while routing a 16.4% queue that captures an oracle-estimated 86.8% of target-label errors. Ming You, Guangxing Zhang, Mingyu Qiao, Haiyang Jiang 0001, Jinsheng Zhao |
APNet | 3 |
| 2026 | Tracking the Stray Sheep: Understanding DNS Response Manipulation in the WildabstractThe Domain Name System (DNS) plays a crucial role in modern web applications; however, manipulations such as hijacking, tampering, and censorship can disrupt domain resolution, posing significant privacy and security risks. While such manipulations are prevalent across global DNS infrastructures, their scope and mechanisms remain poorly understood. Existing studies focus on country-level censorship or rely on authoritative data and passive traffic from selected domains, which prevents a comprehensive understanding. Moreover, the dynamic nature of modern DNS resolution, in which a single domain may resolve to thousands of edge servers, further complicates the detection of manipulated responses. Zhaohua Wang, Qinxin Li, Yiming Xia, Chuan Gao, Guangxing Zhang, Zhenyu Li 0001 |
WWW | 7 |
| 2026 | Not All Data are What You Need: A Data-Efficient Training Method Using Heterogeneous Hardware
Zulong Diao, Mingyu Qiao, Xin Wang 0001, Guangxing Zhang, Wei Liang 0005, Jianguo Chen 0001, Changhua Pei, Yanbiao Li 0001, Zhenyu Li 0001, Gaogang Xie |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2026 | AFFS: Adaptive Fast Frequency Selection Algorithm for Deep Learning Feature ExtractionabstractAs deep learning (DL) continues to advance, effective feature extraction from large-scale data remains crucial for enhancing model performance. To leverage the advantages of the frequency domain, such as concentrated signal energy, prominent data features, and rich detailed characteristics, this paper proposes a novel frequency-domain feature extraction method. However, existing frequency component selection algorithms often struggle to adapt to diverse tasks, tend to yield only locally optimal solutions, and require prolonged processing times. To overcome these limitations, we introduce the Adaptive Fast Frequency Selection (AFFS) algorithm, which seamlessly integrates a frequency component selection factor layer into DL models to identify globally optimal frequency combinations suited to various downstream tasks. We further analyze the relationship between selected frequency components and model performance, providing theoretical guarantees regarding optimality, robustness, and generalization error bounds. Moreover, a fast selection procedure is developed to exploit the empirically observed rapid convergence of the selection-factor ranking, significantly accelerating the selection process. Extensive experiments on five datasets, ten DL models, and two subsequent tasks demonstrate that AFFS achieves superior performance: even when the input data size is reduced to only 10% of the original frequency features, model classification accuracy improves by approximately 1%, while the early stopping mechanism shortens the selection process by about 80%. Xiaocan Li, Kun Xie 0001, Jigang Wen, Jiannong Cao 0001, Guangxing Zhang, Gaogang Xie, Wei Liang 0005 |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2026 | Matrix Reshaping for Reduced Sensing Cost and Improved Data Inference in Sparse Mobile Sensing EnvironmentsabstractMobile crowd sensing (MCS) has emerged as a promising sensing paradigm with the widespread adoption of smartphones. However, one of the key bottlenecks in MCS lies in the high sensing cost imposed on mobile users. To alleviate this burden, sparse sensing strategies are often employed, where data is collected from a limited number of locations and the remaining data is inferred by exploiting spatio-temporal correlations. Compared with vector-based inference approaches, matrix completion techniques can better capture two-dimensional correlations in the sensing data, thereby achieving higher recovery accuracy. Nevertheless, their performance degrades significantly when the actual sensing rate is low. In this paper, we propose a novel matrix-reshaping strategy that is applied prior to matrix completion to enhance recovery performance under sparse observations. We provide a theoretical analysis demonstrating that the reshaping process reduces the number of measurements required for successful matrix recovery. To validate our approach, we conduct extensive experiments using traditional matrix completion algorithms, deep learning models, and tensor completion methods on six real-world datasets. The results show that, to achieve the same level of recovery accuracy, our reshaped matrices consistently reduce the measurement overhead compared to their original ones. Jiazheng Tian, Kun Xie 0001, Jigang Wen, Da-Fang Zhang 0001, Guangxing Zhang, Gaogang Xie |
IEEE Trans. Mob. Comput. | 5 |
| 2026 | ModelFreeUP: Attacking Sparse Network Monitoring via Model-Free Universal Adversarial PerturbationabstractSparse network monitoring, a breakthrough technology for cost-effective network-wide monitoring, has garnered significant attention from researchers and network equipment providers. By measuring only a subset of paths and nodes, it leverages the network’s low-rank property to obtain comprehensive monitoring data. However, a previously unnoticed vulnerability called the"global diffusion vulnerability"poses a significant threat to sparse network monitoring. This vulnerability suggests that if a few measurement samples are tainted, the entire network monitoring data can become inaccurate, leading to potential network failures and adverse effects on routing and bandwidth allocation. This paper presents the first exploration of the"global diffusion vulnerability"to launch effective attacks on sparse network monitoring. Sparse monitoring often employs various imputation models to estimate unmeasured data and collects multiple perspectives of network-wide data over extended periods. The challenges in attacking sparse monitoring lie in designing perturbations that can impact all views of network-wide data over time, regardless of the specific imputation models, while remaining unobtrusive. To tackle these challenges, we propose ModelFreeUP, the first perturbation generation algorithm designed for sparse network monitoring. ModelFreeUP creates imputation model-free, universal, and unobtrusive perturbations that exert a significant influence on multiple perspectives of network-wide data over time. Our experiments demonstrate that ModelFreeUP effectively disrupts the sparse monitoring process, causing substantial deviations in the network-wide monitoring data at a relatively low attack cost. Furthermore, when the manipulated monitoring data is used for downstream routing tasks, it triggers 100% Maximum Link Utilization in the Abilene network, indicating network congestion or failure. By shedding light on these critical mismeasurement issues, our work emphasizes the need for robust countermeasures against adversarial attacks in the network monitoring domain. Ruotian Xie, Kun Xie 0001, Jiazheng Tian, Jing Wang 0066, Jigang Wen, Yang Xu 0013, Guangxing Zhang, Wei Liang 0005, Gaogang Xie |
IEEE Trans. Netw. | 7 |
| 2026 | Traffic-Aware Design for Multi-Dimensional Lookup and Forwarding: From IP Routing to Packet ClassificationabstractPacket processing in modern routers and switches relies on rule matching, primarily performed by two core modules: IP prefix lookup for next-hop determination and packet classification for multi-field policy enforcement. However, most existing algorithms are rule-centric and assume uniform rule access, overlooking the highly skewed nature of real-world network traffic. Such mismatch between static rule organization and dynamic traffic behavior leads to inefficiency in both lookup and classification. To address this limitation, we propose a Traffic-aware Lookup and Forwarding (TLF) framework that leverages traffic measurement with lookup operations, enabling online adaptation to dynamic traffic patterns and frequent rule updates. Experimental results demonstrate that TLF provides 1.04×–3.37× speedups for lookup and forwarding over state-of-the-art algorithms, while substantially reducing both memory overhead and construction time. Furthermore, integrating TLF into Vector Packet Processor (VPP) and Open vSwitch (OVS) results in throughput improvements of 2.61× and 4.88×, respectively. Xinyi Zhang 0004, Qianrui Qiu, Peng He 0003, Guangxing Zhang, Luyiyun Li, Jianer Zhou, Kavé Salamatian, Gaogang Xie |
IEEE Trans. Netw. | 5 |
| 2026 | Adaptive Semantic Communication System for High-Quality Remote Sensing Image Transmission in Unstable Wireless EnvironmentsabstractHigh-quality remote sensing imagery plays a vital role in environmental monitoring and disaster management. However, transmitting these images is challenging due to the unstable signal-to-noise ratio (SNR) and bandwidth limitations encountered in remote communications. Semantic communication, particularly deep learning-based methods, offers a promising solution by jointly optimizing source and channel coding to achieve data compression and noise resilience. Nevertheless, existing methods struggle to cope with varying channel noise and bandwidth, leading to unsatisfactory image reconstruction quality. To address these challenges, we propose a satellite-ground compression and transmission system called Adaptive Residual Joint Source-Channel Coding (ARJSCC), which is based on Deep Joint Source-Channel Coding (DeepJSCC). The ARJSCC system compresses remote sensing images into semantic information and residuals to achieve low overhead transmission and high-quality reconstruction. ARJSCC utilizes an attention module to adjust the semantic preference of the model for different SNRs, and deploys a variance-based position mask module to flexibly vary the semantic length and further compress it. These designs enable ARJSCC to automatically adapt to varying noise and bandwidth conditions. Moreover, for the residual, we apply BPG to compress it to reduce the transmission cost and design the corresponding enhancement module to recover its details from the noise-affected compressed residual. We experimentally compare our ARJSCC with the recent DeepJSCC-based wireless image transmission models in low-resolution dataset and high-resolution remote dataset under multiple wireless channel environments. The experimental results show that ARJSCC can achieve high reconstruction quality exceeding 44dB, and outperform the competitors by 4-6db even under low SNR and bandwidth environments. Zhangyayu Tan, Caiping Liu, Kun Xie 0001, Yudian Ouyang, Jigang Wen, Guangxing Zhang, Dong Chen 0013, Gaogang Xie, Kenli Li 0001 |
IEEE Trans. Wirel. Commun. | 6 |
| 2025 | Joint Neural Matrix Completion for Multi-Attribute Mobile Crowd Sensing
Xiaocan Li, Kun Xie 0001, Jigang Wen, Guangxing Zhang, Wei Liang 0005, Gaogang Xie, Kenli Li 0001 |
INFOCOM | 4 |
| 2025 | Lemon: Network-Wide DDoS Detection with Routing-Oblivious Per-Flow Measurement
Zhenyu Li 0001, Xilai Liu, Zhaohua Wang, Guangxing Zhang, Gaogang Xie |
USENIX Security Symposium | 6 |
| 2025 | Towards Enhancing Inter-Domain Routing Security With Visualization and Visual AnalyticsabstractIn the complex landscape of the Internet, inter-domain routing systems are essential for ensuring seamless connectivity and reachability across autonomous systems. However, the lack of dependable security validation mechanisms in these systems poses persistent challenges. Vulnerabilities such as prefix hijacking, path forgery, and route leakage not only compromise network operators and users, but also threaten the stability and accessibility of the Internet’s core infrastructure. To address this, visualization and visual analytics techniques are adept at identifying and detecting security threats, offering network administrators effective methods to monitor and maintain network operations. This paper presents a comprehensive survey of the state-of-the-art research in visualization and visual analytics for inter-domain routing security. We delineate four scenarios for tasks analysis in network visualization: monitoring, detection, verification, and discovery. Each category is explored in detail, focusing on the employed data sources and visualization techniques. Several key findings are presented at the end of each category, aimed at providing researchers and practitioners with research inspiration. Furthermore, we examine the trends of academic interest observed in recent decades and propose potential directions for future research in visual analytics pertaining to Internet infrastructure security. Jingwei Tang, Guodao Sun, Gefei Zhang 0002, Yanbiao Li 0001, Guangxing Zhang, Jian Liu 0053, Haixia Wang 0002, Ronghua Liang |
IEEE Trans. Big Data | 7 |
| 2025 | PetTC: Pairwise Joint Embedding Based Contrastive Tensor Completion for Network Traffic Monitoring ServicesabstractNetwork traffic matrices often suffer from incompleteness and sparsity due to various factors, including network device policies and system limitations. The incompleteness can undermine the reliability and accuracy of network traffic monitoring services, negatively impacting downstream tasks such as network planning and fault diagnosis. Our focus is on network traffic data recovery, intending to infer missing traffic data from partial measurements accurately. Although tensor completion algorithms are quite effective in recovering traffic data, existing models often overlook cross-domain traffic relationships and fail to account for the order and distribution of traffic, leading to reduced recovery accuracy. To overcome these limitations, we propose a new contrastive tensor completion model that utilizes pairwise joint embedding. This model employs innovative techniques, including a cross-domain embedding module to avoid information homogeneity and enhance model expressiveness, a contrastive module to preserve the order and distribution of traffic volumes, and an injective interaction module to map entry embeddings into the numerical space, ensuring convergence and retaining the original numerical distribution. Experiments on three real-world network traffic datasets show that our model significantly reduces the error in missing traffic data recovery compared to other existing models while maintaining traffic order and distribution. Kun Xie 0001, Jigang Wen, Guangxing Zhang, Wei Liang 0005, Gaogang Xie, Kenli Li 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2025 | High Quality Compression and Transmission of Remote Sensing Images Based on Semantic CommunicationabstractRemote sensing imagery plays a crucial role in areas such as environmental monitoring and urban planning. However, due to fragile communication links, limited bandwidth and harsh wireless environments, transmitting data from remote locations to ground applications faces the dilemma of high bit-error rates, which have a poor impact on downstream missions. Semantic communication is a feasible solution that transmits only the semantic features of the raw data extracted using neural networks. Although effective, existing semantic communication methods cannot cope with high compression rate requirements and complex communication environments. Therefore, in this paper, an effective image compression and transmission framework ASE-JSCC is proposed. To minimize the transmitted data, we design a semantic extraction module and an important feature selection module to efficiently extract, select, and compress critical semantic features required for downstream tasks. To improve the communication robustness of the model in complex environments affected by variable channels, we optimize the source-channel joint coding technique by randomly adding noise with different types and sizes. Finally, we deploy ASE-JSCC to the scene classification task of remote sensing images and conduct extensive experiments on four real datasets, achieving classification accuracy of 84.29%--88.62% under 384 times compression ratio, verifying the excellent performance of the proposed framework. Kun Xie 0001, Yudian Ouyang, Jigang Wen, Guangxing Zhang, Wei Liang 0005, Quan Feng |
IEEE Trans. Sustain. Comput. | 5 |
| 2024 | DMSTG: Dynamic Multiview Spatio-Temporal Networks for Traffic ForecastingabstractTraffic sensor networks are widely applied in smart cities to monitor traffic in real-time and record huge volumes of traffic data. Exploiting such data to forecast future traffic conditions have the potential to enhance the decision-making capabilities of intelligent transportation systems, which attracts widespread attention from both industries and academia. Among them, network-wide prediction based on graph convolutional neural networks(GCN) has become mainstream. It models the spatial dependencies of sensors in a graph with a pre-defined Laplacian matrix based on the distances among sensors. However, understanding spatio-temporal traffic patterns is quite challenging as there is a huge difference in terms of traffic patterns during different periods or in different regions. In addition, the actual data collected can be polluted due to unavoidable data loss from severe communication conditions or sensor failures. Considering these issues, we propose a novel dynamic multiview spatial-temporal prediction framework which takes into consideration various factors, including local/global, short/long term spatio-temporal dependencies and their dynamic changes. To comprehensively track the dynamic spatio-temporal dependencies among traffic data, we creatively design two different modules to perceive the changes in traffic patterns. We first propose a dynamic Laplacian matrix learning module based on our theoretical derivation to estimate the Laplacian matrix of the graph for GCN timely. We creatively incorporate tensor decomposition into this module, where real-time traffic data are decomposed into a global component that is stable and depends on long-term temporal-spatial traffic relationships and a local component that captures the traffic fluctuations. We also design a self-attention based module to dynamically assign a weight to each part in traffic data. The spatio-temporal features from multiple views are deeply fused by a feature fusion module. The forecasting performance is evaluated with 5 real-time traffic datasets. Experiment results demonstrate that our framework can consistently outperform the state-of-the-art baselines and be more robust under noisy environments. Zulong Diao, Xin Wang 0001, Da-Fang Zhang 0001, Gaogang Xie, Jianguo Chen 0001, Changhua Pei, Xuying Meng, Kun Xie 0001, Guangxing Zhang |
IEEE Trans. Mob. Comput. | 9 |
| 2023 | EC-GCN: A encrypted traffic classification framework based on multi-scale graph convolution networks
Zulong Diao, Gaogang Xie, Xin Wang 0001, Xuying Meng, Guangxing Zhang, Kun Xie 0001, Mingyu Qiao |
Comput. Networks | 6 |
| 2023 | Estimation on the Hourly Distribution of Near-Surface Temperature Lapse Rate Under Winter Clear-Sky ConditionsabstractThe near-surface (2 m) temperature lapse rate (TLR) is a key parameter in various environmental studies. However, high spatial and temporal resolution TLRs are not usually available on regional scales, especially in mountainous regions. The purpose of this study is to model spatio-temporal continuous TLR in a mountain area using observed air temperature, MODIS LST products, land cover maps, and the ASTER Digital Elevation Model (DEM). To address this issue, the sliding window method was employed in this study to model TLR from MODIS LST, and the diurnal temperature cycle (DTC) model was utilized to fit the diurnal variation of TLR. The results of this study indicated that MODIS LST can be used to calculate the near-surface TLR of grid point. The sliding window method can effectively calculate the spatially continuous TLR, and the sliding window size of 15×15 is suitable for this study area. The simulated TLR can be effectively corrected using the relationship between measured air temperature and LST by considering a correction coefficient. The Root Mean Square Error (RMSE) after correction was decreasing by 0.36 °C km-1. The daily amplitude of TLR ranges from 22.25 °C km-1to -13.07 °C km-1, with a standard deviation of 7.50 °C km-1. The near-surface TLRs vary in both space and time and are more variable than a constant of -6.5 °C km-1. The mean absolute error (MAE) and RMSE between simulated hourly TLR values and measured TLR values are 2.85 and 3.32 °C km-1, respectively, which means the diurnal variation of TLR can be effectively fitted using the DTC model. The research proposed method can effectively utilize MODIS LST under clear sky conditions to calculate spatio-temporal continuous TLR. Guangxing Zhang, Guixin Zhang, Shanyou Zhu |
IEEE Trans. Geosci. Remote. Sens. | 1 |
| 2022 | Lightweight Trilinear Pooling based Tensor Completion for Network Traffic MonitoringabstractNetwork traffic engineering and anomaly detection rely heavily on network traffic measurement. Due to the lack of infrastructure to measure all points of interest, the high measurement cost, and the unavoidable transmission loss, network monitoring systems suffer from the problem that the network traffic data are incomplete with only a subset of paths or time slots measured. Recent studies show that tensor completion can be applied to infer the missing traffic data from partial measurements. Although promising, the interaction model adopted in current tensor completion algorithms can only capture linear and simple correlations in the traffic data, which compromises the recovery performance. To solve the problem, we propose a new tensor completion scheme based on Lightweight Trilinear Pooling, which designs (1) a Trilinear Pooling, a new multi-modal fusion method to model the interaction function to capture the complex correlations, (2) a low-rank decomposition based neural network compression method to reduce the storage and computation complexity, (3) an attention enhanced LSTM to encode and incorporate the temporal patterns in the tensor completion scheme. The extensive experiments on three real-world network traffic datasets demonstrate that our scheme can significantly reduce the error in missing data recovery with fast speed using small storage. Yudian Ouyang, Kun Xie 0001, Xin Wang 0001, Jigang Wen, Guangxing Zhang |
INFOCOM | 5 |
| 2021 | Compact-index: an efficient index algorithm for network trafficabstractIn many network security systems, network packets will be archived with no loss for the purpose of forensic, troubleshooting and so on. In order to achieve fast retrieval for these stored packets, index is essential. However, with the rapid increase of network link bandwidth, indexing network traffic traces is facing the challenges of index construction speed, index storage overhead and retrieval efficiency. In this paper, we propose an efficient index scheme for packet index, named Compact-Index, that not only effectively reduces the storage cost of index, but also greatly improves index insertion rate and retrieval efficiency. Experimental results show that our scheme can achieve 7.14Mpps index insertion rate for IPv4 traffic and 6.11Mpps index insertion rate for IPv6 traffic, and supports millisecond scale response to most queries. In addition, the average space cost of index is only about 5% of the raw network traffic. All the experimental results above indicate that Compact-Index significantly outperforms the existing state-of-art index schemes. Guangxing Zhang, Haiyang Jiang 0001, Gaogang Xie |
CoNEXT | 2 |
| 2021 | Low Cost Sparse Network Monitoring Based on Block Matrix CompletionabstractDue to high network measurement cost, network-wide monitoring faces many challenges. For a network consisting of n nodes, the cost of one time network-wide monitoring will be O(n2). To reduce the monitoring cost, inspired by recent progress of matrix completion, a novel sparse network monitoring scheme is proposed to obtain network-wide monitoring data by sampling a few paths while inferring monitoring data of others. However, current sparse network monitoring schemes suffer from the problems of high measurement cost, high computation complexity in sampling scheduling, and long time to recover the un-sampled data. We propose a novel block matrix completion that can guarantee the quality of the un-sampled data inference by selecting as few as m = O(nr ln(r)) samples for a rank r N × T matrix with n = max{N,T}, which largely reduces the sampling complexity as compared to the existing algorithm for matrix completion. Based on block matrix completion, we further propose a light weight sampling scheduling algorithm to select measurement samples and a light weight data inference algorithm to quickly and accurately recover the un-sampled data. Extensive experiments on three real network monitoring data sets verify our theoretical claims and demonstrate the effectiveness of the proposed algorithms. Kun Xie 0001, Jiazheng Tian, Gaogang Xie, Guangxing Zhang, Da-Fang Zhang 0001 |
INFOCOM | 4 |
| 2021 | S2H: Hypervisor as a setter within Virtualized Network I/O for VM isolation on cloud platform
Haiyang Jiang 0001, Guangxing Zhang, Xin Wang 0001, Yilong Lv, Xing Li 0007, Serge Fdida, Gaogang Xie |
Comput. Networks | 3 |
| 2020 | Precise and Adaptable: Leveraging Deep Reinforcement Learning for GAP-based Multipath Scheduler
Binbin Liao, Guangxing Zhang, Zulong Diao, Gaogang Xie |
Networking | 2 |
| 2019 | Toward Generalized Neural Model for VMs Power Consumption Estimation in Data CentersabstractThe power consumption of IT equipment is always being a big challenge for data centers. The research communities are attempting to solve this problem, by employing various of energy-aware tasks scheduling or VMs consolidation policies. It is crucial for these policies to figure out the major parameters that affect power consumption and their correlation. In this paper, we first identify the major parameters using real cloud services' workload and power consumption data. An important observation is that the parameters are strongly interdependent and the importance of individual parameters varies in different cloud services. Nevertheless, existing power consumption models are unable to fully capture this feature and thus lack generalization. To address this gap, we propose Lapem that adopts a Long Short-term Memory network for power consumption estimation. Lapem further uses an attention mechanism to achieve stable performance and improve generalization. The experimental results demonstrate that Lapem estimates power consumption with a relative error of as low as 2%-5%. More importantly, in comparison with the state-of-the-art models, Lapem reduces the estimation error by more than 23% when generalizing to new cloud services. Guangxing Zhang, Zhenyu Li 0001, Wei Liangs, Gaogang Xie |
ICC | 2 |
| 2019 | Online Internet Anomaly Detection With High Accuracy: A Fast Tensor Factorization SolutionabstractTraffic anomaly detection is critical for advanced Internet management. Existing detection algorithms usually work off-line and cannot timely detect anomalies. They also suffer from high cost for storage and computation. Although online and accurate traffic anomaly detection is very important, it very difficult to achieve. We propose to utilize tensor model to well exploit the multi-dimensional information hidden in the traffic data for more accurate online Internet anomaly detection. We decouple the tensor recovery problem to iteratively solve two sub problems, a tensor factorization sub-problem and an anomaly detection sub-problem. To reduce the high cost for computation and storage involved in tensor factorization, we propose two lightweight techniques to effectively derive factor matrices of tensor in the current window and iteration, taking advantage of tensor decomposition results of the previous window and iteration. We have done extensive experiments using two real traffic traces to compare with three tensor based algorithms and three matrix based algorithms. The experiment results demonstrate that our online anomaly detection algorithm can achieve the same anomaly detection accuracy as that of the best offline tensor based algorithm, but at 6100 times faster speed and with very low storage cost. Xiaocan Li, Kun Xie 0001, Xin Wang 0001, Gaogang Xie, Jigang Wen, Guangxing Zhang, Zheng Qin 0001 |
INFOCOM | 6 |
| 2019 | A Data-Driven Approach to Client-Transparent Access Selection of Dual-Band WiFiabstractDual-band WiFi which supports both 2.4 GHz and 5 GHz has been widely deployed, aiming to expand wireless capacity, and eliminate serious interference in 2.4 GHz. As the proportion of dual-band APs and clients increase enormously, how to select which band to access to achieve considerable user experience is becoming essential in wireless network. Clients' native decisions that tend to prefer 5 GHz will consequently cause serious interference in 5 GHz and leave 2.4 GHz notably idle. Through analyzing a unique dataset in the wild, we quantitatively study the impact of various WiFi factors on the wireless delay. We propose a decision tree approach to intelligent access selection that decides which band to access dynamically according to prior learned schemes. A prototype of the access selection system named LazyAS, which only requires modification at AP side, is realized and deployed in a production WiFi network. Evaluation results demonstrate that LazyAS reduces the 90th percentile of wireless delay in the production WiFi network from 32 ms to 12 ms. Jun Zhang 0033, Guangxing Zhang, Qinghua Wu 0004, Binbin Liao, Gaogang Xie |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2018 | Accurate Recovery of Internet Traffic Data: A Sequential Tensor Completion Approach
Kun Xie 0001, Lele Wang 0003, Xin Wang 0001, Gaogang Xie, Jigang Wen, Guangxing Zhang, Jiannong Cao 0001, Da-Fang Zhang 0001 |
IEEE/ACM Trans. Netw. | 6 |
| 2017 | LazyAS: Client-Transparent Access Selection in Dual-Band WiFiabstractDual-band WiFi which supports both 2.4GHz and 5GHz has been widely deployed, aiming to expand wireless capacity and eliminate serious interference in 2.4GHz. Thus, how to select which band to access to achieve considerable user experience is becoming essential in wireless network. Clients' native decision that always prefers 5GHz will consequently cause serious interference in 5GHz and leave 2.4GHz notably idle. Through analyzing a unique dataset in the wild, we quantitatively study the impact of various WiFi factors on the wireless delay. We propose a decision tree approach for intelligent access selection that decides which band to access dynamically according to prior learned schemes. A prototype of the access selection system named LazyAS, which only requires modification at AP side, is realized and deployed in production WiFi network. Evaluation results demonstrate that our proposed LazyAS reduces the 90th percentile of wireless delay in the production WiFi network from 32ms to 12ms. Jun Zhang 0033, Guangxing Zhang, Qinghua Wu 0004, Gaogang Xie |
ICCCN | 2 |
| 2017 | Throughput Guaranteed Handoff for SDN-Based WLAN in Distinctive Signal CoverageabstractIn SDN-based WLAN, controller needs to collect the state info of Mobile Nodes (MNs) like received signal strength indicator (RSSI) for handoff. In such scenarios, high sampling rate facilitates handoff, but it also easily leads to system overhead thus limits access scale of MN. Besides, dynamical adjustment of transmit power of access point (AP) leads to the distinctive signal coverage. Existing handoff algorithms that directly use the uplink RSSI as handoff condition would result in significant throughput decay of MN. Also in indoor deployment RSSI may varies much, large variation of RSSI result in unstable handoff. To address the issues, we design a variable sampling rate mechanism, then filter sampling RSSI and propose a handoff algorithm for distinctive signal coverage scenarios. Our sampling mechanism uses a finite state machine (FSM) to adjust the sampling rate by MN on all nearby APs. Our handoff algorithm uses Kalman filter to achieve stable and trend-reflecting uplink RSSI estimation, then estimate downlink signal noise ratio (SNR) difference between potential and current AP. We implement our algorithm and deployed a test-bed for extensive experiments. Results show our sampling mechanism could achieve sampling quantity decrease by 60%; compared to mean filter based approach, our handoff algorithm improves throughput by 10-50% in distinctive signal coverage scenarios. Besides, handoff frequency decreased by about 60%, indicating a more stable handoff decision. Guangxing Zhang, Zhenyu Li 0001, Gaogang Xie |
WCNC | 2 |
| 2017 | Musubi: Improving Loss Resilience by Exploiting Multi-Radio Diversity for SDN-Based WLANabstractAs Wi-Fi networks are becoming insecurely denser, frame loss and the consequent throughput degradation are much more profound, due to severe interference in dense networks. Pre- vious works propose to exploit multi-radio diversity to improve loss resilience. However, they are far from practical because of their incompatibility with the Wi-Fi standard, high deployment cost and large processing delay. In this work, we propose Musubi, which is a practical and low cost solution for exploiting multi- radio diversity. Furthermore, Musubi does not require client-side modification, thus it is totally compatible with the legacy Wi-Fi standard. Musubi leverages flexibility and programmability of the growingly-popular Software- Defined-Network (SDN) based WLAN, and incorporates capture effect and redundancy packet elimination, so as to handle the specific challenges raised in loss resilience. Compared with a state- of-the-art solution, in theory analysis, Musubi achieve 15% jitter decrease with only 0.8% throughput decrease, when frame loss rate is 20%. We implemented deployed and evaluated Musubi. Experiment results show that Musubi reduces frame loss by 70% and achieves throughput gain up to 1.4amp;#x000D7; as well as packet delay decreasing by 34% compared with the legacy Wi-Fi. Guangxing Zhang, Anfu Zhou, Gaogang Xie |
WCNC | 2 |
| 2017 | Index-Trie: Efficient archival and retrieval of network traffic
Gaogang Xie, Jingxiu Su, Xin Wang 0001, Taihua He, Guangxing Zhang, Steve Uhlig, Kavé Salamatian |
Comput. Networks | 5 |
| 2016 | Accurate recovery of Internet traffic data: A tensor completion approachabstractThe inference of traffic volume of the whole network from partial traffic measurements becomes increasingly critical for various network engineering tasks, such as traffic prediction, network optimization, and anomaly detection. Previous studies indicate that the matrix completion is a possible solution for this problem. However, as a two-dimension matrix cannot sufficiently capture the spatial-temporal features of traffic data, these approaches fail to work when the data missing ratio is high. To fully exploit hidden spatial-temporal structures of the traffic data, this paper models the traffic data as a 3-way traffic tensor and formulates the traffic data recovery problem as a low-rank tensor completion problem. However, the high computation complexity incurred by the conventional tensor completion algorithms prevents its practical application for the traffic data recovery. To reduce the computation cost, we propose a novel Sequential Tensor Completion algorithm (STC) which can efficiently exploit the tensor decomposition result for the previous traffic data to deduce the tensor decomposition for the current data. To the best of our knowledge, we are the first to apply the tensor to model Internet traffic data to well exploit their hidden structures and propose a sequential tensor completion algorithm to significantly speed up the traffic data recovery process. We have done extensive simulations with the real traffic trace as the input. The simulation results demonstrate that our algorithm can achieve significantly better performance compared with the literature tensor and matrix completion algorithms even when the data missing ratio is high. Kun Xie 0001, Lele Wang 0003, Xin Wang 0001, Gaogang Xie, Jigang Wen, Guangxing Zhang |
INFOCOM | 6 |
| 2015 | Sequential and adaptive sampling for matrix completion in network monitoring systemsabstractEnd-to-end network monitoring is essential to ensure transmission quality for Internet applications. However, in large-scale networks, full-mesh measurement of network performance between all transmission pairs is infeasible. As a newly emerging sparsity representation technique, matrix completion allows the recovery of a low-rank matrix using only a small number of random samples. Existing schemes often fix the number of samples assuming the rank of the matrix is known, while the data features thus the matrix rank vary over time. In this paper, we propose to exploit the matrix completion techniques to derive the end-to-end network performance among all node pairs by only measuring a small subset of end-to-end paths. To address the challenge of rank change in the practical system, we propose a sequential and information-based adaptive sampling scheme, along with a novel sampling stopping condition. Our scheme is based only on the data observed without relying on the reconstruction method or the knowledge on the sparsity of unknown data. We have performed extensive simulations based on real-world trace data, and the results demonstrate that our scheme can significantly reduce the measurement cost while ensuring high accuracy in obtaining the whole network performance data. Kun Xie 0001, Lele Wang 0003, Xin Wang 0001, Gaogang Xie, Guangxing Zhang, Dongliang Xie, Jigang Wen |
INFOCOM | 5 |
| 2013 | Scalable high-performance parallel design for Network Intrusion Detection Systems on many-core processorsabstractNetwork Intrusion Detection Systems (NIDSes) face significant challenges coming from the relentless network link speed growth and increasing complexity of threats. Both hardware accelerated and parallel software-based NIDS solutions, based on commodity multi-core and GPU processors, have been proposed to overcome these challenges. This work explores new parallel opportunities afforded by many-core processors for high performance, scalable and inexpensive NIDS. We exploit the huge many-core computational power by adopting a hybrid parallel architecture combining data and pipeline parallelism. We also design a hybrid load balancing scheme, using both ruleset and flow space partitioning. Furthermore, the proposed design leverages particular features of the processor to break the bottlenecks. We have integrated the open source NIDS Suricata into our proposed design and evaluated its performance with synthetic traffic. The prototype exhibits almost linear speedup and can handle up to 7.2 Gbps traffic with 100-bytes packets. Haiyang Jiang 0001, Guangxing Zhang, Gaogang Xie, Kavé Salamatian, Laurent Mathy |
ANCS | 2 |
| 2010 | Mnemonic Lossy Counting: An efficient and accurate heavy-hitters identification algorithmabstractIdentifying heavy-hitter traffic flows efficiently and accurately is essential for Internet security, accounting and traffic engineering. However, finding all heavy-hitters might require large memory for storage of flows information that is incompatible with the usage of fast and small memory. Moreover, upcoming 100Gbps transmission rates make this recognition more challenging. How to improve the accuracy of heavy-hitters identification with limited memory space has become a critical issue. This paper presents a scalable algorithm named Mnemonic Lossy Counting (MLC) that improves the accuracy of heavy-hitters identification while having a reasonable time and space complexity. MLC algorithm holds potential candidate heavy-hitters in a historical information table. This table is used to obtain tighter error bounds on the estimated sizes of candidate heavy-hitters. We validate the MLC algorithm using real network traffic traces, and we compared its performance with two state-of-the-art algorithms, namely Lossy Counting (LC) and Probabilistic Lossy Counting (PLC). The results reveal that: 1) with same set of parameters and memory usage, MLC achieves between 31.5% and 6.67% fewer false positives than LC and PLC. 2) MLC and LC have a zero false negative ratio, whereas 38% of the cases PLC has a non-zero false negatives and PLC can miss up to 4.4% of heavy-hitters. 3) MLC has a slightly lower memory cost than LC during the first few windows and its memory usage decreases with time, when PLC memory usage declines sharply. 4) MLC has similar runtime than LC, and smaller time than PLC. Qiong Rong, Guangxing Zhang, Gaogang Xie, Kavé Salamatian |
IPCCC | 2 |
| 2008 | Accurate Online Traffic Classification with Multi-Phases Identification MethodologyabstractTraffic metrics at application level are critical for protocol research, abnormity detection, accounting and network operation. There are great challenges to identify packets at application level since dynamic protocol ports and packet encryption are deployed popularly. There are several different methods of traffic identification being proposed in recently research for corresponding applications. It is impossible to identify traffic with any one method alone. A methodology of online traffic identification at application level named multi-phases identification (MPI) based on packet and flow is proposed in this paper. There are two stages in the methodology. The traffic classification is based on packet characteristic in the first stage and based on flow feature in the second stage to correct the results in the first stage. There are several advantages in MPI: (1) these existing traffic identification methods can be easily integrated into MPI to improve the identification accuracy, (2) the corresponding new identification method for the new application can be inserted into MPI feasibly with scripts of the identification rule, and (3) efficiency of identification can be improved with the mechanism of adaptive justification for the sequence of methods and implemented on multi-CPUs platform. MPI has been implemented a general purpose CPU platform with OC-48 POS and 10 GE network interface. Experiment on an OC-48 POS backbone link shows MPI is accurate and effective for traffic identification. Guangxing Zhang, Gaogang Xie, Yinghua Min, Zhaomin Zhou, Xiaodong Duan |
CCNC | 1 |
| 2008 | Rogue access point detection using segmental TCP jitterabstractRogue Access Points (RAPs) pose serious security threats to local networks. An analytic model of prior probability distribution of Segmental TCP Jitter (STJ) is deduced from the mechanism of IEEE 802.11 MAC Distributed Coordinated Function (DCF) and used to differentiate the types of wire and WLAN connections which is the crucial step for RAPs detecting. STJ as the detecting metric can reflect more the characteristic of 802.11 MAC than ACK-Pair since it can eliminate the delay caused by packet transmission. The experiment on an operated network shows the average detection ratio of the algorithm with STJ is more than 92.8% and the average detection time is less than 1s with improvement of 20% and 60% over the detecting approach of ACK-Pair respectively. Farther more no WLAN training trace is needed in the detecting algorithm. Gaogang Xie, Guangxing Zhang |
WWW | 3 |
| 2007 | Self-Similar Characteristic of Traffic in Current Metro Area NetworkabstractComplexity and diversity of Internet traffic are constantly growing. Networking researchers become aware of the need to constantly monitor and reevaluate their assumptions in order to ensure that the conceptual models correctly represent reality. Using the dataset collected by NetTurbo from three different bidirectional OC-48 links in metro area networks at the two biggest ISPs of China, this paper carefully investigates the self-similar characteristics of traffic from different aspects. In contrast to the previous results which have been widely accepted, this paper shows that for the aggregated traffic and the TCP and UDP traffic whether the self-similarity exists is uncertain. Further, break down by the application category, only the traditional and uncategorized traffic are self-similar while the others are not. However, on the view of the individual application of each category, it seems that traffic of every application exhibits self-similarity. To the best of our knowledge, this paper firstly provides the experimental evidence showing that aggregating different groups of self-similar traffic series could generate a traffic series which is either self-similar or non-self-similar. Guangxing Zhang, Gaogang Xie, Dunxing Zhang, Da-Fang Zhang 0001 |
LANMAN | 1 |