Semi-supervised learning in intrusion detection systems (IDSs) faces three major challenges: the scarcity of labeled samples, class imbalance, and distribution divergence between labeled and unlabeled data. Moreover, the third challenge may lead to an extreme situation where labeled data fail to cover all categories. To address these issues, we develop a heuristic factor-based semi-supervised model named HF-IDS. In particular, we employ symbolic regression, a novel feature engineering technique, to generate class-indicating factors. These factors guide a multilevel clustering for pseudo-label addition to some unlabeled data. For classification, we construct an ensemble of graph neural networks (E-GNNs). Different from common ensemble learning methods, each of the GNN classifiers is equipped with a unique graph filter constructed by the factors. Through these filters, we topologically reweight different classes to enhance the model's effectiveness in handling the class-imbalance problem. The model is evaluated in both multiclass and binary classification settings, with the binary case simulating the extreme missing-category scenario. Experiments on NSL-KDD and CICIDS-2017 datasets show that HF-IDS consistently outperforms state-of-the-art baselines in accuracy, precision, recall, and F1 _score.
We propose an optimal power allocation strategy at the transmitter and maximal ratio combining (MRC) at the receiver for reconfigurable intelligent surface (RIS)-assisted free-space optical (FSO) communication systems. Numerical results demonstrate that the proposed design improves signal-to-noise ratio (SNR) and performs better than the conventional design.
Adaptive biased optical orthogonal time frequency space (ABO-OTFS) faces challenges in achieving optimal spectral efficiency due to the presence of unused Doppler bins within the system. To address this, we propose two novel hybrid ABO-OTFS (HABO-OTFS) technologies for reconfigurable intelligent surface (RIS)-assisted optical wireless communication (OWe) systems. HABO 1 -OTFS integrates ABO-OTFS with pulse amplitude modulated discrete multitone (PAM-DMT), offering a straightforward implementation that enables the receiver to directly extract data without the need for complex demodulators. On the other hand, HABO 2 -OTFS combines ABO-OTFS with various hybrid schemes in a layered approach, providing enhanced flexibility and more efficient utilization of spectral resources. Numerical results demonstrate that both HABO 1 -OTFS and HABO 2 -OTFS significantly outperform the existing ABO-OTFS in terms of peak-to-average power ratio (PAPR), spectral efficiency, and power efficiency, underscoring their potential for superior performance in RIS-assisted OWC systems.
Artificial Intelligence of Things (AIoT) applications have advanced rapidly. However, most of them are inherently vulnerable to security threats and may be the source of spoofing attacks, and meanwhile, in AIoT systems, the transfer of real-time data from terminals and the cloud strains network bandwidth. To defend against attacks, save network forwarding resources, and relieve authentication pressure on the receiver end, it is essential to verify the source identity of AIoT terminals on the forwarding path. In this article, we propose PDIV, a probabilistic and distributed identity validation solution for AIoT applications. In the framework of PDIV, honest forwarders can verify the authenticity of the source identity of packets with a certain probability and filter spoofed packets to prevent them from spreading, reduce end-to-end network latency, and increase throughput as much as possible. Additionally, PDIV, a blockchain-based system that uses Merkle Patricia Trie (MPT) on the blockchain, makes it practical and efficient to realize distributed storage and verification of identity information. Moreover, we theorize about the tradeoff between PDIV network performance and detection effectiveness, as well as how PDIV enables defenses against different attacks, such as spoofing and Distributed Denial-of-Service attacks. Furthermore, we implement PDIV on network simulator version 3 (NS3) and evaluate its performance. The simulation results demonstrate that PDIV can prevent the spread of spoofed packets effectively and PDIV works better than currently available blockchain-based public-key infrastructure (PKI) approaches in terms of network latency.
The forthcoming wireless networks must integrate to a high density of end-user devices while ensuring a superior quality of service. It is imperative to devise solutions that reduce the density of wireless access points and associated costs, while simultaneously ensuring security and privacy throughout propagation. Herein, a novel dual-band photodetector with high selective responsivities in distinct visible and near-infrared (NIR) band is developed as an optical signal receiver. The receiver has an unprecedented fast switch speed > 500 kHz between different operation modes. Leveraging this fast switch speed, a high-speed Multiple-Input-Single-Output (MISO) system is developed, fusing spectrum resources from visible to infrared bands. The system achieves a data rate of 600 Kbps in the visible channel and 500 Kbps in the NIR channel, with a sum rate of 1.1 Mbps. This is the highest single-channel data rate and sum rate among reported dual-band photodetectors. Additionally, two previously overlooked mechanisms, the Subtraction and Addition modes, are studied in detail. The four operation modes are developed to establish a novel physical encryption method in terms of arithmetic relation. The dual-channel coupled link can support a data rate of 200 Kbps, significantly enhancing communication security.
Fully Homomorphic Encryption is a cryptographic scheme to prevent the privacy leakage of sensitive data. However, one challenge with FHE is the ciphertext comparison widely used in clustering, an important scheme used for data mining and analysis. In this paper, we create a series of ciphertext comparison functions by rewriting the comparison in HE-friendly operations and the Heaviside step function approximated by Chebyshev Polynomials. Furthermore, we solve the challenging ciphertext division through constructing a function whose root is the reciprocal of the divisor and applying Newton's method to ap-proximate the root. Then, we propose a fully privacy-preserving, effective and efficient clustering scheme based on our ciphertext comparison and division. Tests on various datasets show that our algorithm maintains nearly the same classification accuracy as vanilla k-means and significantly outperforms the baseline in terms of accuracy. We then optimize our scheme by batching over multiple records and multithreading, and the results show that our approach has a significant efficiency advantage. Compared with the state-of-the-art FHE-based privacy-preserving clustering scheme (SAC 2018), our algorithm is four orders of magnitude faster than theirs.
Wireless networks are vulnerable to many attacks due to its dynamic environments. Unrestricted forwarding of packets from untrusted sources in wireless networks has caused many serious security threats and a great waste of network resources. This paper presents RepuFilter, a probabilistic packet filtering scheme based on trust evaluation, which enables a shared data plane to provide security services for wireless networks. RepuFilter proposes a dynamic trust evaluation model based on the transitivity of trust evaluation between network users, and applies the model to packet filtering. In the framework of RepuFilter, forwarders verify packets with a certain probability, and discard packets from untrusted sources, to prevent the packets from being spread, and reduce inspection expenses as much as possible. We implement RepuFilter and evaluate its performance based on Network Simulator Version 3 (NS3). Simulation results prove that RepuFilter can resist the spread of untrusted packets more effectively than the classic and latest trust models and RepuFilter can meet current network performance requirements,
Internet of Things (IoT) devices have achieved rapid development but most of them are vulnerable to spoofing attacks and spoofing-related attacks. It is crucial to verify source identity at the near-source end to defend against attacks, save network forwarding resources, and relieve the authentication pressure on the receiver end. In this paper, we propose Smart-PKI, a blockchain-based distributed identity validation scheme for IoT Devices. In the architecture of Smart-PKI, near-source forwarders can verify the authenticity of the source identity of packets and can filter spoofed packets. Besides, we apply Merkle Patricia Trie (MPT) to the Smart-PKI blockchain to enable lightweight blockchain copy storage and efficient retrieval and verification of identity information on forwarders. Meanwhile, Smart-PKI proposes an identity restoration mechanism and enables solutions for the attacks caused by public and private key compromise. Furthermore, we implement Smart-PKI on Network Simulator Version 3 (NS3) and evaluate its performance against reflection denial-of-service (DDoS) attacks. The simulation results demonstrate the effectiveness and efficiency of Smart-PKI and it outperforms existing blockchain-based PKI solutions for IoT devices in terms of network latency for verifying certificates.
As the basic structure of all-optical computing basic logic unit, the research progress of all-optical switch affects the development of all-optical computing and even the development of integrated optical field. An ultrafast all-optical switch with silicon-based silica structure is designed. The extinction ratio and the switch response time of the optically controlled optical switch are measured through two-color pump-probe experiment. The design of ultrafast all-optical switch with the switch intensity ratio of 7:1 and the switching time of 500 fs is realized.
"互联网+党建"工作模式是信息时代下推动高校党建工作科学化的重要手段之一.结合清华大学研究生党建实践,提出"互联网+党建"工作模式的基本架构,并以研究生网上民主评议制度为例,阐释了该模式的优越性、先进性和科学性,以及该模式的基本原则和方案要点.
学术软环境建设是高层次创新人才培养的重要途径.界定了学术软环境的概念范畴,围绕创新人才培养的需求,从机制、文化、精神三个层面,归纳了学术软环境建设的途径与特点.结合清华大学的探索与实践,阐述了学术软环境建设的具体措施与成效,分析了其对于创新人才培养的作用机制.
In order to improve the performance of suspicious traffic detection algorithm in software defined network , this paper proposes a method for detecting suspicious traffic of k nearest neighbor based on undirected graph process .OpenFlow module is used to create data stream ,and the intrusion rules are constructed .Then ,based on the map nodes/edges represent with the Markov chain ,the undirected graph was used to represent the attack characteristics ,it realized the incremental implementation of new attacks ,which could reduce the computational complexity of constructing undirected graph ,and the k nearest neighbor algorithm was used to classify the malicious attack traffic characteristics of undirected graph to achieve effective detection of attacks .Finally ,the performance of the proposed algorithm is verified by the SDN test platform .
Named data networking (NDN) is a new Internet architecture that replaces today’s focus on where – addresses and hosts with what – the content that users and applications care about. One of NDN’s prominent advantages is scalable and efficient content distribution due to its native support of caching and multicast in the network. However, at the last hop to wireless users, often the WiFi link, current NDN implementation still treats the communication as multiple unicast sessions, which will cause duplicate packets and waste of bandwidth when multiple users request for the same popular content. WiFi’s built-in broadcast mechanism can alleviate this problem, but it suffers from packet loss since there is no MAC-layer acknowledgement as in unicast. In this paper, we develop a new NDN-based cross-layer approach called NLB for efficient and scalable live video streaming over wireless LAN. The core ideas are: using WiFi’s broadcast channel to deliver content from the access point to the users, a leader-based mechanism to suppress duplicate requests from users, and receiver-driven rate control and loss recovery. The design is implemented and evaluated in a physical testbed comprised of one software AP and 20 Raspberry Pi-based WiFi clients. While NDN with multiple unicast sessions or plain broadcast can support no more than ten concurrent viewers of a 1Mbps streaming video, NDN plus NLB supports all 20 viewers, and Received December 29, 2015; accepted April 28, 2016 E-mail: zhxp@tsinghua.edu.cn can likely support much more when present.
As the instance system of information center networking (ICN),the named data networking (NDN) attracts more and more attention in academia.NDN changes the network service from "destination to destination" to "retrieving data of given names".NDN is more convenient for consumers to share data and it gets a substantial increase in the rate of repeated utilization of data.We focus on the forwarding of NDN routing nodes and propose a forwarding strategy based on historical access records called HRF,which can find out whether there is target data stored by the neighbor nodes in the local network,and then access the target data in the local network efficiently and rapidly.Through a series of typical scenarios,we validate the feasibility and effectiveness of the HRF.
移动互联网技术的兴起,深刻地改变着现有的教育教学模式.介绍了清华大学在研究生学术交流工作中,结合社交媒体,探索基于移动互联网的“020”学术交流新模式——微沙龙,实现了对传统学术交流模式的有益补充,使随时随地开展学术交流成为可能.实践证明:这一模式能有效培育学生学术交流习惯,促进跨学科学术交流,激发创新潜力,建设更为自主、活跃的高校学术交流环境.
802.11 (WiFi) networks have become increasingly important for our daily lives. However, previous work has shown that enterprise WiFi performance is often unsatisfactory and that over-utilization and interference from rogue APs are the two primary reasons. To address the above problem, this paper proposes to improve the capacity of WiFi infrastructures by increasing the enterprise AP deployment density, as well as disabling the wired Internet access in buildings to eliminate rogue APs and their interference. We deployed several WiFi networks with different AP density and vendors on Tsinghua campus. Based on the measurement results from our real-world deployments, we made three main observations: 1) in general, higher AP density improves WiFi performance; 2) over-dense deployment with unnecessarily high transmission power can worsen WiFi performance. 3) choice of AP vendors also has an impact on WiFi performance.
As a novel Internet architecture, Named Data Networking (NDN) shifts the communication model from address-centric to content-centric. An NDN router caches the data in its content store, greatly reducing network traffic. NDN adopts the hierarchical naming schema, which allows the name aggregation and enables high scalability. However, in a richly connected topology, the nearest data replica are often not on the path dictated by NDN's tree-like data fetching model. This might result in a lower data delivery efficiency compared with the flat self-certifying naming schema in other Information-Centric Networking (ICN) architectures. To address the low efficiency problem, we propose a CDN-like enhancement to the NDN design, called Fetching the Nearest Replica (FNR). In FNR, when a consumer sends an interest for a popular data, the data is fetched from the nearest replica in the network, regardless of whether it is on the best path from the producer to the consumer. We present the design details and theoretical overhead analysis for FNR. Our evaluation results using ndnSIM simulator show that on average FNR reduces the total (inter-domain, intra-domain) traffic by 25.6% (53.0%, 18.2%) on average, compared to the default NDN approach. In addition, the average latency is reduced by 37% and the average cost is reduced by 51.4%. To the best of our knowledge, this paper is the first NDN enhancement in the literature to support nearest replica fetching in NDN.
Named Data Networking (NDN) is a new Internet architecture that replaces today's focus on where - addresses and hosts - with what - the content that users and applications care about. A unique advantage of NDN over IP is the adaptive forwarding plane, which, by observing the performance of Interest/Data exchange, can dynamically select the best performing forwarding path, detect and recover from failures, load-balance across multiple paths, and mitigate attacks such as prefix hijacking and DDoS. A key component of adaptive forwarding is interface ranking, namely when and how to update the interfaces' metrics and rank them.As we will point out in this paper, however, the existing interface ranking scheme suffers from the problem of outdated forwarding states. Using two concrete problems, SRTT slow-convergence and probing oscillation, we illustrate how outdated forwarding states can impact the forwarding performance. We propose new forwarding strategies with Adaptive SRTT Update (ASU) and Proactive Probing to achieve up-to-date forwarding states, and evaluate how these strategies are able to address the two problems. Both theoretical analysis and simulation results show that the new strategies can reduce SRTT convergence time by 37.9% and the loss rate by 75% to 94.75%, compared to the existing interface ranking strategies.
IEEE 802.11-based wireless LAN, commonly referred to as Wi-Fi, has become a universal solution for the last-hop network access. In large and public assembly places, people may use their mobile devices to view the video of the same popular events via the same wireless access points (APs). However, current 802.11 APs transmit the same video stream multiple times via separate unicast sessions due to the well-known poor reliability and low data rate of the legacy Wi-Fi multicast. Besides, in traditional single-layer-coded video streams, all clients have to settle with the lowest video bitrate limited by the client with the worst channel quality. To address these problems, we propose M3, a practical and reliable multi-layer video multicast solution over multi-rate Wi-Fi networks. The aims of our system are, in the premise of no change to APs, not only to ensure that all clients can smoothly watch the video at least with the lowest quality, but also to maximize the overall video quality received by all clients. To meet these design goals, the video server selects certain clients as unicast receivers to transmit different SVC video layers, and other clients listen for the packets in the promiscuous mode. It is challenging to select specific unicast receivers and allocate different SVC layers to fully utilize the available bandwidth because of dynamic network conditions. To overcome this challenge, we use a periodical feedback mechanism to collect necessary statistics from clients, and use them to derive an optimal SVC-layer allocation strategy to maximize the video quality. We implemented a prototype in a real Wi-Fi testbed consisting of one AP and one M3 server and 8 clients. Compared with the single-layer video multicast, our M3 system can improve the total received video rate by up to 200%
Yonggang Zhao (赵永刚)合作论文数Department of Physics, Tsinghua University28
Beichuan Zhang合作论文数Computer Science Department
The University of Arizona
Tucson, AZ 857216