I am looking for Joint Ph.D. or Visitng Ph.D. Student opportunities ~ (CV)
I am currently a first-year Ph.D. student at the Cyberspace Institute of Advanced Technology (CIAT), Guangzhou University (ranked 3rd in China for Cybersecurity), led by Academician Binxing Fang(方滨兴院士班). I am fortunate to continue my Ph.D. studies under the supervision of Prof. Yuan Liu in the Blockchain and Reputation Group (B&R Group), where I also received my Master’s degree. (Updated in 2026.09.20)
My research interest includes:
- Game Theory and Mechanism Design
- Reputation Systems
- Multi Agent Reinforcement Learning
- Network Security
Education Background
- 2026.09 - present, Ph.D Cyberspace Institute of Advanced Technology (CIAT), Guangzhou University, Guangzhou, China.
- 2023.09 - 2026.06, M.Sc Cyberspace Institute of Advanced Technology (CIAT), Guangzhou University, Guangzhou, China.
- 2020.09 - 2022.06, B.Sc School of Computer Science, Jiaying University, Meizhou, China.
Awards
- 2025.10 China National Scholarship, By Ministry of Education of China.
- 2024.10 The First Prize Scholarship in Guangzhou University.
- 2025.01 TianRongXing Fang’s Class Scholarship
Publications
No Answer Puzzle: A Curiosity-Driven Attacker Model and Motivation Inference for APT in Cybersecurity of Major Events
Chenlu Zhuansun$^†$, Yiji Lin$^†$(Co-First author), Yuan Liu$^*$, Binxing Fang, Zhihong Tian$^*$.
Abstract: Major events such as the Olympic Games pose unique cybersecurity challenges due to their high visibility, short duration, and complex system environments, making them prime targets for nation-state–level Advanced Persistent Threats (APTs). With sufficient preparation time, attackers often conduct early reconnaissance, among which large-scale password guessing against event-related systems is a recurrent preparatory behavior frequently observed before and during major events. Traditional defense mechanisms such as firewalls and honeypots can capture direct intrusion attempts but often overlook these pre-attack behaviors, missing valuable opportunities for early detection. To address this gap, we propose a No-Answer Puzzle scheme, a lightweight and non-loginable password-interaction system tailored for major-event scenarios to capture pre-attack preparations from attackers. Based on motivational psychology, the persistent and covert behaviors of APT attacks are all driven by a strong curiosity towards the target systems. Therefore, by the captured interaction data, we define an attacker curiosity metric, design a computational update mechanism, and develop a fuzzy-logic–based model for inferring attacker motivation. The system was successfully deployed during the cybersecurity missions of the 2025 9th Asian Winter Games (Harbin) and the 137th China Import and Export Fair (Canton Fair), and real-world results demonstrate that it effectively captures and identifies potential attackers at an early stage without affecting normal system operations, thereby contributing substantially to achieving zero-incident security for major events.
HoneyCenter: An Intelligent Honeypoint IP Mutation Strategy Optimization Based on Multiagent Reinforcement Learning
Pengdeng Li$^†$, Yiji Lin$^†$(Co-First author), Chenlu Zhuansun, Binxing Fang, Yuan Liu$^*$, Zhihong Tian$^*$.
Abstract: APTs (Advanced Persistent Threats) on critical infrastructure such as smart grids and industrial control systems are growing increasingly severe. Although honeypoints, such as honeypots and honeybaits, have been widely adopted in cybersecurity, they still struggle to counter APTs as they can intelligently adjust strategies based on the current state of the system. Mutating the IP addresses of honeypoints has been recognized as an effective method for defending against various cyber attacks. However, in critical infrastructure, mutating the IP addresses requires careful design since improper strategy could lead to system instability or high costs such as service delay or interruption. Consequently, the defender needs to design a cost-effective honeypoint IP mutation strategy under the consideration of rational and smart APT attackers who can also adjust their attack strategies adaptively. To this end, first, we propose a dynamic two-player zero-sum game model HoneyCenter to characterize the strategic interaction between the defender and the attacker, where, in each state, the defender determines which host the honeypoint IP address should transition to, while the attacker selects one of the hosts to attack. Then, we leverage the Minimax Q-learning algorithm to derive the optimal mutation strategy to maximize the defender’s utility in capturing the attacker. Finally, through extensive experiments, we demonstrate that the proposed game model and the derived IP mutation strategy can significantly enhance the security of the critical infrastructure in a cost-effective manner.
When Reputation Meets Auction: A Dual Incentive Mechanism for Mitigating Clean Label Attack in Data Trading Markets
Qingyuan Li$^†$, Chenlu Zhuansun$^†$,Yiji Lin, Qingling Yang, Pengdeng Li, Yuan Liu$^*$, Zhihong Tian.
Abstract: The data trading markets are increasingly vulnerable to clean-label attacks, where attackers provide poisoned data through manipulating the feature space of a target object instead of directly altering the target object labels such that trained models make undesirable decisions about the target object. Existing defenses whether high-precision poisoning filters or adversarial-training pipelines are locked in the same asymmetric arms race: attackers can refine perturbations at near zero marginal cost, while defenders must continually retrain, revalidate, and redeploy. Finally, escalating resource burden erodes market trust and resulting in the failure of the whole data markets. To overcome the challenges, we propose a dual incentive mechanism that integrates reputation systems with multi-attribute reverse auctions to mitigate the clean-label attack, where the attackers are less likely to be selected and their data price is also discounted. Specifically, we construct the reputation of data providers based on their clean-attack verification history, which is designed in a hard-to-build but easy-to-crush manner to capture long-term attacking behavior. Then, we formulate the optimal auction problem based on reputation. Furthermore, we design a multi-attribute reverse auction mechanism to effectively incentivize and penalize, thereby preventing clean label attack behaviors. Finally, theoretical analyses and simulations quantitatively demonstrate that the proposed dual incentive mechanism can create a safer data trading markets.
A comprehensive quality assessment model for cyber threat intelligence
Zhipeng Lei, Yuan Zhou, Yiji Lin$^*$(Corresponding author), Yuan Liu$^*$.
A4DIoT: Multi-AI Agent Adversarial-Based Active Defense Framework for Securing Large-Scale IoT Network
Pengdeng Li, Siying Li, Yiji Lin, Chenlu Zhuansun, Qingling Yang, Yuan Liu, Zhihong Tian.
Chameleon: A Deception Defense Strategy Against LLM-assisted Attacker in New Power
Yitong Yao, Yiji Lin(Co-First author),Qingling Yang, Pengdeng Li, Yuan Liu$^*$, Zhihong Tian$^*$.
Fine-Grained Reputation Thresholds for Major Events: A KG-LLM Approach
Qiwei Liu, Yiji Lin(Co-First author), Chenlu Zhuansun$^*$, Yuan Liu$^*$.
An IP Reputation Model Based on Dual-Scale Analysis of Malicious Behaviors in Energy Internet (Translated from Chinese)
Kaifeng Meng, Yinsheng Wang, Bainian Wu, Yiji Lin, Yuan Liu.
Patents
-
Yuan Liu; Yitong Yao; Yiji Lin et al. 一种面向电力网络攻击机器人的变色龙服务构建及优化部署方法, 已受理.
-
Yuan Liu; Xinkai Yi; Pengdeng Li; Yiji Lin et al. A Malicious Traffic Data Augmentation Method Based on Multi-Startpoint Diffusion Strategy, CN121864468A, 2026-04-14.
- Qingling Yang; Yuan Liu; Yitong Yao; Yiji Lin et al. Intelligent target deployment method and system for power scene APT attack, CN121603304B, 2026-04-10.
-
Yuan Liu; Yiji Lin et al. 一种IP灰度信誉柔性评估方法,No.CN122027347A, 2026-5-12.
-
Zhihong Tian, Yuan Liu; Yiji Lin et al. Fraud defense strategy optimization method based on offline reinforcement learning, No.CN120956480A, 2025-11-14.
-
Yuan Liu; Yiji Lin et al. A malicious entity identification method based on subjective logical reputation, No. CN120602213A, 2025-09-05.
-
Yuan Liu; Yiji Lin et al. Pre-early warning method for security attack of important active network, No.CN120785661A, 2025-10-14.
-
Yuan Liu; Qingyuan Li; Yiji Lin et al. A data trading market incentive method integrating reputation and auction strategies, No.CN120410697A, 2025-08-01.
-
Zhihong Tian; Yuan Liu; Yiji Lin et al.Honey spot address mutation decision method, system and readable storage medium, No.CN120090879A, 2025-06-03.
-
Yuan Liu; Zhihong Tian; Yiji lin; Qingyuan Li et al.Network defense method, system and readable storage medium based on game model, No.CN119011243A, 2024-11-22.
- Zhihong Tian; Binxing Fang; Yuan Liu; Longyu sun; Yiji Lin et al. A network security protection method based on signaling game, No.CN118764267A, 2024-10-11.
Project
-
Reputation System in DunLiFang (Core Developer)
Designed and implemented the Reputation System in DunLiFang. DunLiFang led by Academician Binxing Fang, has been deployed in critical events (such as Canton Fair, Asian Games, Winter Asian Games, etc.) and leading enterprises(such as China Southern Power Grid, etc.)
Software Copyright
- Guangzhou University, DunLiFang-Reputation System 2.0(Translated from Chinese), 2025SR1695922, Authorized.
Research Funding Supports
- National Key R&D Program of Smart Grid, Grant No.2025ZD0805904.
- Guangdong Basic and Applied Basic Research Foundation, Grant No.2025B1515020022.
- National Natural Science Foundation of China, Grant No. T252200258.
- National Key R&D Program of China, Grant No. 2022YFB3102700.
- National Natural Science Foundation of China, Grant No.62172085.
- National Natural Science Foundation of China, Grant No.U20B2046.
- Strategic Research and Consultation Project of the Chinese Academy of Engineering, Grant No.2024-XZ-07.