VLDB 2026 Research / reviewers in the wild / expert
Linke Guo
dblp:00/10800
· DBLP profile ↗
69ranked-venue papers
10as first author
29since 2021 · last 2026
0000-0002-3658-7435ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 43 · 7 first-author · 16 since 2021Security and privacy · 10 · 1 first-author · 5 since 2021Systems, architecture and hardware · 7 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Resilient Percentile-Driven Spectrum Sharing for NTN-TN Coexistence
Shaoying Wang, Beatriz Lorenzo, Ming Li 0006, Linke Guo, Xiaonan Zhang 0001 |
INFOCOM | 4 |
| 2025 | What Lurks Within? Concept Auditing for Shared Diffusion Models at ScaleabstractDiffusion models (DMs) have revolutionized text-to-image generation, enabling the creation of highly realistic and customized images from text prompts. With the rise of parameter-efficient fine-tuning (PEFT) techniques like LoRA, users can now customize powerful pre-trained models using minimal computational resources. However, the widespread sharing of fine-tuned DMs on open platforms raises growing ethical and legal concerns, as these models may inadvertently or deliberately generate sensitive or unauthorized content, such as copyrighted material, private individuals, or harmful content. Despite increasing regulatory attention on generative AI, there are currently no practical tools for systematically auditing these models before deployment. In this paper, we address the problem of concept auditing: determining whether a fine-tuned DM has learned to generate a specific target concept. Existing approaches typically rely on prompt-based input crafting and output-based image classification but they suffer from critical limitations, including prompt uncertainty, concept drift, and poor scalability. To overcome these challenges, we introduce Prompt-Agnostic Image-Free Auditing (PAIA), a novel, model-centric concept auditing framework. By treating the DM as the object of inspection, PAIA enables direct analysis of internal model behavior, bypassing the need for optimized prompts or generated images. It integrates two key components: a prompt-agnostic strategy that mitigates prompt sensitivity by analyzing model behavior during late-stage denoising, and an image-free detection method based on conditional calibrated error, which compares the internal dynamics of a fine-tuned model against its base version. Our auditing setting assumes internal access to DMs, but does not require access to proprietary fine-tuning data or user prompts, an assumption aligned with how hosted platforms audit uploaded models. We evaluate PAIA on 320 controlled models trained with curated concept datasets and 771 real-world community models sourced from a public DM sharing platform, covering a wide range of concepts including celebrities, cartoon characters, videogame entities, and movie references. Evaluation results show that PAIA achieves over 90% detection accuracy while reducing auditing time by 18 - 40x compared to existing baselines, and remains robust under adaptive attacks. To our knowledge, PAIA is the first scalable and practical solution for pre-deployment concept auditing of diffusion models, providing a practical foundation for safer and more transparent diffusion model sharing. Xiaoyong Yuan, Linke Guo, Lan Zhang 0005 |
CCS | 3 |
| 2025 | Sculpting Memory: Multi-Concept Forgetting in Diffusion Models via Dynamic Mask and Concept-Aware Optimization
Gen Li 0012, Kaiyuan Deng, Bo Hui 0001, Linke Guo |
ICCV | 6 |
| 2025 | Achieving Robust Resource Orchestration for Highly Dense Heterogeneous IoT Systems
ChunChih Lin, Chenxu Jiang, Xiaonan Zhang 0001, Linke Guo |
INFOCOM | 4 |
| 2025 | Similarity-Guided Rapid Deployment of Federated Intelligence Over Heterogeneous Edge Computing
Hansong Zhou, Jingjing Fu, Yukun Yuan 0001, Linke Guo, Xiaonan Zhang 0001 |
INFOCOM | 4 |
| 2025 | Adversarial Robust ViT-Based Automatic Modulation Recognition in Practical Deep Learning-Based Wireless SystemsabstractAdvanced wireless communication systems adopt deep learning (DL) approaches to achieve automatic modulation recognition (AMR) for spectrum monitoring and management, especially in the spectrum bands supporting diverse co-existing wireless protocols. In practical wireless environments, wireless signals can easily get compromised by malicious noise, intentional interference, and adversarial attacks, reducing the effectiveness of AMR. By exploiting DL model vulnerabilities, an undetectable perturbation added to the wireless signal can cause misclassification, resutling in serious consequences including decoding errors, throughput degradation, and communication disruption. Facing the limitations of existing works on defending against wireless adversarial attacks, this work innovates the Transformer model to design an adversarial robust AMR driven by exploring temporal correlation in time-sequence wireless signals. Instead of directly applying the Vision Transformer (ViT), we first innovate a feature extraction module specifically for radio frequency (RF) signals from both the time and frequency domains, together with an adaptive positional embedding to the Transformer encoder for enhancing AMR accuracy. To mitigate the noise effect in practical wireless communication, we then propose a noise-adaptive adversarial training scheme on the developed Transformer-based model using adversarial examples crafted by white-box attackers. To show the scheme's efficiency, effectiveness, and robustness, our proposed design has been thoroughly evaluated via a self-collected real-world dataset consisting of over 30 million wireless signal data samples with 21 modulation schemes in both indoor and outdoor scenarios. Our results reach a maximum accuracy of 94.17% in AMR classification and 71.2 % under adversarial attacks. Besides, for the first time, we demonstrate the robustness of our design under a real wireless adversarial attack in real-time. Datasets and code available in https://github.com/coulsonlee/Robust-ViT-for-AMR-SP2025. Gen Li 0012, ChunChih Lin, Xiaonan Zhang 0001, Linke Guo |
SP | 5 |
| 2024 | NeurRev: Train Better Sparse Neural Network Practically via Neuron RevitalizationabstractDynamic Sparse Training (DST) employs a greedy search mechanism to identify an optimal sparse subnetwork by periodically pruning and growing network connections during training. To guarantee effectiveness, DST algorithms rely on high search frequency, which consequently, requires large learning rate and batch size to enforce stable neuron learning. Such settings demand extreme memory consumption, as well as generating significant system overheads that limit the wide deployment of deep learning-based applications on resource-constraint platforms. To reconcile such, we propose $\underline{Neur}$on $\underline{Rev}$italization framework for DST (NeurRev), based on an innovative finding that dormant neurons exist with the presence of weight sparsity, and cannot be revitalized (i.e., activated for learning) even with high sparse mask search frequency. These dormant neurons produce a large quantity of zeros during training, which contribute relatively little to the outputs of succeeding layers or to the final results. Different from most existing DST algorithms that spare no effort designing weight growing criteria, NeurRev focuses on optimizing the long-neglected pruning part, which awakes dormant neurons by pruning and incurs no additional computation costs. As such, NeurRev advances more effective neuron learning, which not only achieves outperforming accuracy in a variety of networks and datasets, but also promoting a low-cost dynamism at system-level. Systematical evaluations on training speed and system overhead are conducted on the mobile devices, where the proposed NeurRev framework consistently outperforms representative state-of-the-arts. Code will be released. Gen Li 0012, Lu Yin 0006, Wei Niu 0002, Minghai Qin, Bin Ren 0002, Linke Guo, Shiwei Liu 0003 |
ICLR | 7 |
| 2024 | Advancing Dynamic Sparse Training by Exploring Optimization OpportunitiesabstractDynamic Sparse Training (DST) is an effective approach for addressing the substantial training resource requirements posed by the ever-increasing size of the Deep Neural Networks (DNNs). Characterized by its dynamic "train-prune-grow” schedule during training, DST implicitly develops a bi-level structure for training the weights while discovering a subnetwork topology. However, such a structure is consistently overlooked by the current DST algorithms for further optimization opportunities, and these algorithms, on the other hand, solely optimize the weights while determining masks heuristically. In this paper, we extensively study DST algorithms and argue that the training scheme of DST naturally forms a bi-level problem in which the updating of weight and mask is interdependent. Based on this observation, we introduce a novel efficient training framework called BiDST, which for the first time, introduces bi-level optimization methodology into dynamic sparse training domain. Unlike traditional partial-heuristic DST schemes, which suffer from sub-optimal search efficiency for masks and miss the opportunity to fully explore the topological space of neural networks, BiDST excels at discovering excellent sparse patterns by optimizing mask and weight simultaneously, resulting in maximum 2.62% higher accuracy, 2.1$\times$ faster execution speed, and 25$\times$ reduced overhead. Code available at https://github.com/jjsrf/BiDST-ICML2024. Gen Li 0012, Lu Yin 0006, Minghai Qin, Geng Yuan, Linke Guo, Shiwei Liu 0003 |
ICML | 6 |
| 2024 | FreeEM: Uncovering Parallel Memory EMR Covert Communication in Volatile EnvironmentsabstractMemory Electromagnetic Radiation (EMR) allows attackers to manipulate the DRAM of infiltrated systems to leak sensitive secret information. Although most of the existing works have demonstrated its feasibility, practical concerns, such as the ideal electromagnetic environment and stationary attacking layout, make the covert channel attack less convincing, especially in vulnerable sites such as offices and data centers. This work removes the above impractical assumptions to uncover the potential of memory EMR by proposing the first parallel EMR covert communication protocol. Our design reshapes the current "1-to-1" covert communication mode to "n-to-1" mode via a novel pattern-based 2-dimensional symbol encoding scheme, allowing multiple victim computers to simultaneously perform data exfiltration to one attacker (the receiver) without mutual interference. Meanwhile, this novel scheme design also enables the very first mobile attacker, i.e., a smartphone connected to a software-defined radio (SDR) dongle, to capture parallel memory EMR signals in a volatile environment. Extensive experiments are conducted to verify the performance in a volatile environment with different parameter configurations, distances, motion modes, shielding materials, orientations, hardware configurations, and SDR platforms. Our experimental results demonstrate that FreeEM can support up to 4 parallel memory EMR transmissions to achieve an overall throughput of 625Kbps and a decoding accuracy of 96.88%. The maximum communication distance can reach up to 20 meters. Sihan Yu, Jingjing Fu, Chenxu Jiang, ChunChih Lin, Zhenkai Zhang 0002, Long Cheng 0005, Ming Li 0006, Xiaonan Zhang 0001, Linke Guo |
MobiSys | 9 |
| 2024 | A Single-Step, Sharpness-Aware Minimization is All You Need to Achieve Efficient and Accurate Sparse TrainingabstractSparse training stands as a landmark approach in addressing the considerable training resource demands imposed by the continuously expanding size of Deep Neural Networks (DNNs). However, the training of a sparse DNN encounters great challenges in achieving optimal generalization ability despite the efforts from the state-of-the-art sparse training methodologies. To unravel the mysterious reason behind the difficulty of sparse training, we connect the network sparsity with neural loss functions structure, and identify the cause of such difficulty lies in chaotic loss surface. In light of such revelation, we propose $S^{2} - SAM$, characterized by a **S**ingle-step **S**harpness_**A**ware **M**inimization that is tailored for **S**parse training. For the first time, $S^{2} - SAM$ innovates the traditional SAM-style optimization by approximating sharpness perturbation through prior gradient information, incurring *zero extra cost*. Therefore, $S^{2} - SAM$ not only exhibits the capacity to improve generalization but also aligns with the efficiency goal of sparse training. Additionally, we study the generalization result of $S^{2} - SAM$ and provide theoretical proof for convergence. Through extensive experiments, $S^{2} - SAM$ demonstrates its universally applicable plug-and-play functionality, enhancing accuracy across various sparse training methods. Code available at https://github.com/jjsrf/SSAM-NEURIPS2024. Gen Li 0012, Jingjing Fu, Fatemeh Afghah, Linke Guo, Xiaoyong Yuan |
NeurIPS | 5 |
| 2024 | Behaviors Speak More: Achieving User Authentication Leveraging Facial Activities via mmWave SensingabstractHuman faces have been widely adopted in many applications and systems requiring a high-security standard. Although face authentication is deemed to be mature nowadays, many existing works have demonstrated not only the privacy leakage of facial information but also the success of spoofing attacks on face biometrics. The critical reason behind this is the failure of liveness detection in biometrics. This work advances most biometric-based user authentication schemes by exploring dynamic biometrics (human facial activities) rather than traditional static biometrics (human faces). Inspired by observations from psychology, we propose the mmFaceID to leverage humans' dynamic facial activities when performing word reading for achieving robust, highly accurate, and effective user authentication via mmWave sensing. By addressing a series of technical challenges of capturing micro-level facial muscle movements using a mmWave sensor, we build a neural network to reconstruct facial activities via estimated expression parameters. Then, unique features can be extracted to enable robust user authentication regardless of relative distances and orientations. We conduct comprehensive experiments on 23 participants to evaluate mmFaceID in terms of distances/orientations, length of word lists, occlusion, and language backgrounds, demonstrating an authentication accuracy of 94.7%. We also extend our evaluation in a real IoT scenario. By speaking real IoT commends, the average authentication accuracy can reach up to 92.28%. Chenxu Jiang, Sihan Yu, Jingjing Fu, ChunChih Lin, Huadi Zhu, Ming Li 0006, Linke Guo |
SenSys | 8 |
| 2024 | Cross-Technology Federated Matching for Age of Information Minimization in Heterogeneous IoTabstractHeterogeneous Internet of Things (IoT) networks, which operate using various protocols and spectrum bands like WiFi, Bluetooth, Zigbee, and LoRa, bring many opportunities to collaborate and achieve timely data collection. However, several challenges must be addressed due to heterogeneous data patterns, coverage, spectrum bands, and mobility. This paper introduces a cross-technology IoT network architecture design that facilitates collaboration between service providers (SPs) to share their spectrum bands and offload computing tasks from heterogeneous IoT devices using multi-protocol mobile gateways (M-MGs). The objective is to minimize the age of information (AoI) and energy consumption by jointly optimizing collaboration between M-MGs and SPs for bandwidth allocation, relaying, and cross-technology data scheduling. A pricing mechanism is presented to incentivize different levels of collaboration and matching between M-MGs and SPs. Given the uncertainty due to mobility and task requests, we design a cross-technology federated matching algorithm (CT-Fed-Match) based on a multi-agent actor-critic approach in which M-MGs and SPs learn their strategies in a distributed manner. Furthermore, we incorporate federated learning to enhance the convergence of the learning process. The numerical results demonstrate that our CT-Fed-Match-RC algorithm with cross-technology and relaying collaboration reduces the AoI by 30 times and collects 8 times more packets than existing approaches. Haitham H. Esmat, Xiaohao Xia, Yinxuan Wu, Beatriz Lorenzo, Linke Guo |
IEEE/ACM Trans. Netw. | 5 |
| 2023 | SkillScanner: Detecting Policy-Violating Voice Applications Through Static Analysis at the Development PhaseabstractThe Amazon Alexa marketplace is the largest Voice Personal Assistant (VPA) platform with over 100,000 voice applications (i.e., skills) published to the skills store. In an effort to maintain the quality and trustworthiness of voice-apps, Amazon Alexa has implemented a set of policy requirements to be adhered to by third-party skill developers. However, recent works reveal the prevalence of policy-violating skills in the current skills store. To understand the causes of policy violations in skills, we first conduct a user study with 34 third-party skill developers focusing on whether they are aware of the various policy requirements defined by the Amazon Alexa platform. Our user study results show that there is a notable gap between VPA's policy requirements and skill developers' practices. As a result, it is inevitable that policy-violating skills will be published. Song Liao, Long Cheng 0005, Haipeng Cai, Linke Guo, Hongxin Hu |
CCS | 4 |
| 2023 | Towards High-Quality and Efficient Video Super-Resolution via Spatial-Temporal Data OverfittingabstractAs deep convolutional neural networks (DNNs) are widely used in various fields of computer vision, leveraging the overfitting ability of the DNN to achieve video resolution upscaling has become a new trend in the modern video delivery system. By dividing videos into chunks and over-fitting each chunk with a super-resolution model, the server encodes videos before transmitting them to the clients, thus achieving better video quality and transmission efficiency. However, a large number of chunks are expected to ensure good overfitting quality, which substantially increases the storage and consumes more bandwidth resources for data transmission. On the other hand, decreasing the number of chunks through training optimization techniques usually requires high model capacity, which significantly slows down execution speed. To reconcile such, we propose a novel method for high-quality and efficient video resolution upscaling tasks, which leverages the spatial-temporal information to accurately divide video into chunks, thus keeping the number of chunks as well as the model size to minimum. Additionally, we advance our method into a single overfitting model by a data-aware joint training technique. which further reduces the storage requirement with negligible quality drop. We deploy our models on an off-the-shelf mobile phone, and experimental results show that our method achieves real-time video super-resolution with high video quality. Compared with the state-of-the-art, our method achieves 28 fps streaming speed with 41.6 PSNR, which is 14 × faster and 2.29 dB better in the live video resolution upscaling tasks. Code available in https://github.com/coulsonlee/STDO-CVPR2023.git. Gen Li 0012, Minghai Qin, Wei Niu 0002, Bin Ren 0002, Fatemeh Afghah, Linke Guo |
CVPR | 7 |
| 2023 | A Meta-learning based Generalizable Indoor Localization Model using Channel State InformationabstractIndoor localization has gained significant attention in recent years due to its various applications in smart homes, industrial automation, and healthcare, especially since more people rely on their wireless devices for location-based services. Deep learning-based solutions have shown promising results in accurately estimating the position of wireless devices in indoor environments using wireless parameters such as Channel State Information (CSI) and Received Signal Strength Indicator (RSSI). However, despite the success of deep learning-based approaches in achieving high localization accuracy, these models suffer from a lack of generalizability and can not be readily-deployed to new environments or operate in dynamic environments without retraining. In this paper, we propose meta-learning-based localization models to address the lack of generalizability that persists in conventionally trained DL-based localization models. Furthermore, since meta-learning algorithms require diverse datasets from several different scenarios, which can be hard to collect in the context of localization, we design and propose a new meta-learning algorithm, TB-MAML (Task Biased Model Agnostic Meta Learning), intended to further improve generalizability when the dataset is limited. Lastly, we evaluate the performance of TB-MAML-based localization against conventionally trained localization models and localization done using other meta-learnina algorithms. Ali Owfi, ChunChih Lin, Linke Guo, Fatemeh Afghah, Jonathan D. Ashdown, Kurt A. Turck |
GLOBECOM | 3 |
| 2023 | Waste Not, Want Not: Service Migration-Assisted Federated Intelligence for Multi-Modality Mobile Edge ComputingabstractFuture mobile edge computing (MEC) is envisioned to provide federated intelligence to delay-sensitive learning tasks with multimodal data. Conventional horizontal federated learning (FL) suffers from high resource demand in response to complicated multi-modal models. Multi-modal FL (MFL), on the other hand, offers a more efficient approach for learning from multi-modal data. In MFL, the entire multi-modal model is split into several sub-models with each tailored to a specific data modality and trained on a designated edge. As sub-models are considerably smaller than the multi-modal model, MFL requires fewer computation resources and reduces communication time. Nevertheless, deploying MFL over MEC faces the challenges of device mobility and edge heterogeneity, which, if not addressed, could negatively impact MFL performance. In this paper, we investigate an Service Migration-assisted Mobile Multi-modal Federated Learning (SM3FL) framework, where the service migration for sub-models between edges is enabled. To effectively utilize both communication and computation resources without extravagance in SM3FL, we develop the optimal strategies of service migration and data sample collection to minimize the wall-clock time, defined as the required training time to reach the learning target. Our experiment results show that the proposed SM3FL framework demonstrates remarkable performance, surpassing other state-of-art FL frameworks via substantially reducing the computing demand by 17.5% and dramatically decreasing the wall-clock time by 25.3%. Hansong Zhou, Shaoying Wang, Chutian Jiang, Xiaonan Zhang 0001, Linke Guo, Yukun Yuan 0001 |
MobiHoc | 5 |
| 2023 | Cross-Domain Federated Computation Offloading for Age of Information Minimization in Satellite-Airborne-Terrestrial NetworksabstractSatellite-Airborne-Terrestrial Networks (SATNs) are expected to provide communication and edge-computing services for a plethora of IoT applications. However, preserving the freshness of information is challenging since it requires timely data collection, bandwidth, and offloading decisions across different administrative domains. In this paper, we aim to optimize the age of information (AoI) and energy consumption tradeoff when serving multiple traffic classes in SATNs. A cross-domain federated computation offloading algorithm (Fed-SATEC-Off) is presented in which different service providers (SPs) collaborate to allocate the bandwidth while unmanned aerial vehicles (UAVs) and satellites make decisions to collect, relay, and offload the computing tasks. Given the requirements of each traffic class, the optimum collaborative strategies between SPs, UAVs, and satellites are obtained together with the computation offloading topology. Our algorithm is based on multi-agent actor-critic and incorporates federated learning to improve the convergence of the learning process. The numerical results show that Fed-SATEC-Off reduces the AoI by factor 4 and achieves faster convergence than existing approaches. Xiaohao Xia, Haitham H. Esmat, K. Dyer, Beatriz Lorenzo, Linke Guo |
PIMRC | 5 |
| 2023 | Signal Emulation Attack and Defense for Smart Home IoTabstractInternet of Things (IoT) is transforming every corner of our daily life and plays important roles in the smart home. Depending on different requirements on wireless transmission, dedicated wireless protocols have been adopted on various types of IoT devices. Recent advances in Cross-Technology Communication (CTC) enable direct communication across those wireless protocols, which will greatly improve the spectrum utilization efficiency. However, it incurs serious security concerns on heterogeneous IoT devices. In this paper, we identify a new physical-layer attack, cross-technology signal emulation attack, where a WiFi device eavesdrops a ZigBee packet on the fly, and further manipulates the ZigBee device by emulating a ZigBee signal. To defend against this attack, we propose two defense strategies with the help of a commonly found WiFi router. Particularly, the passive defense strategy focuses on misleading the ZigBee signal eavesdropping, while the proactive approach develops a real-time detection mechanism on distinguishing between a common ZigBee signal and an emulated signal. We implement the complete attacking process and defense strategies with TI CC26x2R LaunchPad, USRP-N210 platform, and a self-designed prototype. Extensive experiments have demonstrated the existence of the attack, and the feasibility, effectiveness, and accuracy of the proposed defense strategies. Xiaonan Zhang 0001, Sihan Yu, Hansong Zhou, Pei Huang 0005, Linke Guo, Ming Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Revealing Smart Selective Jamming Attacks in WirelessHART NetworksabstractAs a leading industrial wireless standard, WirelessHART has been widely implemented to build wireless sensor-actuator networks (WSANs) in industrial facilities, such as oil refineries, chemical plants, and factories. For instance, 54,835 WSANs that implement the WirelessHART standard have been deployed globally by Emerson process management, a WirelessHART network supplier, to support process automation. While the existing research to improve industrial WSANs focuses mainly on enhancing network performance, the security aspects have not been given enough attention. We have identified a new threat to WirelessHART networks, namely smart selective jamming attacks, where the attacker first cracks the channel usage, routes, and parameter configuration of the victim network and then jams the transmissions of interest on their specific communication channels in their specific time slots, which makes the attacks energy efficient and hardly detectable. In this paper, we present this severe, stealthy threat by demonstrating the step-by-step attack process on a 50-node network that runs a publicly accessible WirelessHART implementation. Experimental results show that the smart selective jamming attacks significantly reduce the network reliability without triggering network updates. Xia Cheng, Junyang Shi, Mo Sha 0001, Linke Guo |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | Multi-protocol Aware Federated Matching for Architecture Design in Heterogeneous IoTabstractEnabling timely data collection in heterogeneous IoT networks under different protocols and spectrum bands (e.g., WiFi, Bluetooth, Zigbee, LoR$a$) is crucial to implementing large-scale IoT systems. This paper presents a federated matching framework for heterogeneous IoT networks in which an intermediate layer of multi-protocol mobile gateways (M-MGs) is deployed by different service providers (SPs) to collect and relay data from IoT objects and perform computing tasks. The aim is to develop collaborative strategies between M-MGs and SPs to minimize the average weighted sum of the age-of-information and energy consumption. A novel collaborative framework based on a 2-level multi-protocol multi-agent actor-critic (MP-MAAC) is presented, where M-MGs and SPs can learn the interactive strategies through their own observations. The M-MGs strategies include the selection of IoT objects for data collection, execution, and offloading t o S Ps' a ccess points while SPs decide on the spectrum allocation. Moreover, we incorporate federated matching (Fed-Match) into the multi-agent collaborative framework to improve the convergence of the learning process. The numerical results show that our Fed-Match algorithm reduces the Aol by factor 4, collects twice more packets than existing approaches and establishes design principles for the stability of the training process. Haitham H. Esmat, Xiaohao Xia, Beatriz Lorenzo, Linke Guo |
GLOBECOM | 4 |
| 2022 | Defending against Cross-Technology Jamming in Heterogeneous IoT SystemsabstractThe wide deployment of IoT devices has resulted in a critical shortage of spectrum resources. Many IoT devices coexist on the same spectrum band, where the network performance is always degraded. As a promising solution, the Cross-Technology Communication (CTC) enables the direct communication among heterogeneous IoT devices. Unfortunately, the emerging cross-technology attacks have demonstrated their high success rates in terms of spoofing the end IoT devices or jamming the communication channels. In this paper, we investigate a novel cross-technology jamming issue for a distributed heterogeneous IoT system. Compared with traditional jamming methods, the cross-technology jammer has a much higher jamming power, wider jamming bandwidth, and stronger stealthiness, all of which deserve a complete re-thinking of defensive mechanisms. Therefore, we propose a hybrid anti-jamming scheme that jointly considers frequency hopping and power control techniques. Specifically, we model the anti-jamming process as a Markov Decision Process (MDP) and adopt Deep Q-Network (DQN) to find the optimal strategy. Extensive real-world experiments show that the goodput (payload data) of our anti-jamming scheme can achieve up to 2X and 1.39X than the passive and random anti-jamming approaches, respectively. In particular, our anti-jamming scheme provides 78% of goodput with the presence of a cross-technology jammer, outperforming existing passive and random anti-jamming scheme designs at 37.6% and 54.1%. Sihan Yu, ChunChih Lin, Xiaonan Zhang 0001, Linke Guo |
ICDCS | 4 |
| 2022 | Physical-Level Parallel Inclusive Communication for Heterogeneous IoT DevicesabstractThe proliferation of Internet of Things (IoT) has transformed the way people interact with the world. Various kinds of wireless protocols have been developed to support diverse types of IoT communications. Unfortunately, the lack of spectrum resources puts a hard limit on managing the large-scale heterogeneous IoT system. Although previous works alleviate this strain by coordinating transmission power, time slots, and sub-channels, they may not be feasible in future IoT applications with dense deployments. In this paper, we explore a physical-level parallel inclusive communication paradigm for the coexistence of Wi-Fi and ZigBee, which leverages novel bits embedding approaches on the OQPSK protocol to enable both Wi-Fi and ZigBee IoT devices to decode the same inclusive signals at the same time but with each one’s different data. By carefully crafting the inclusive signals using legacy Wi-Fi protocol, the overlapping spectrum can be simultaneously re-used by both protocols, expecting a maximum data rate (250kbps) for ZigBee devices and up to 3.75Mbps for a Wi-Fi pair over only a 2MHz bandwidth. The achieved spectrum efficiency outperforms a majority of CTC schemes and parallel communication designs. Compared with existing works on parallel communication, our proposed system is the first one that achieves an entire software-level design, which can be readily implemented on Commercial Off-The-Shelf (COTS) devices without any hardware modification. Based on extensive real-world experiments on both USRP and COTS device platforms, we demonstrate the feasibility, generality, and efficiency of the proposed new paradigm. Sihan Yu, Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo |
INFOCOM | 4 |
| 2022 | Wearable-User Authentication via Cross-Technology Interference in Heterogeneous EnvironmentsabstractThe increasing deployment of wireless sensors enables a broad spectrum of health-related wearable applications. Due to the sensitivity of collected personal health information, these wearables should be authenticated together with their users as “wearable-user pairs” to ensure that they are attached to legitimate users. However, various devices are equipped with dedicated sensing abilities and wireless protocols corresponding to data characteristics in practice. Traditional authentication methodologies may not work in this heterogeneous environment because of protocol incompatibility. For example, how to verify a new ZigBee-enabled monitor when the existing trusted device is Wi-Fi-enabled? Therefore, to achieve authentication across protocols, in this article, we leverage the unique cross-technology interference (CTI), triggered by heterogeneous wireless transmissions, along with human physiological activity measurements (e.g., respiration patterns) to design an authentication scheme between wearables and users. Specifically, the authentication from an unknown ZigBee wearable to a trusted Wi-Fi device is achieved by monitoring the channel state information (CSI) changes according to human respiration. Our approach not only successfully recognizes a legitimate wearable-user pair but also blocks illegal access from adversaries. Extensive experiments have been conducted to demonstrate both the security and feasibility of the proposed scheme. The designed mechanism can achieve over 92% authentication accuracy with human subjects. Pei Huang 0005, Xiaonan Zhang 0001, Sihan Yu, Linke Guo, Ming Li 0006 |
IEEE Internet Things J. | 4 |
| 2022 | IS-WARS: Intelligent and Stealthy Adversarial Attack to Wi-Fi-Based Human Activity Recognition SystemsabstractThe non-intrusive human activity recognition has been envisioned as a key enabler for many emerging applications requiring interactions between humans and computing systems. To accurately recognize different human behaviors, ubiquitous wireless signals are widely adopted, e.g., Wi-Fi signals, whose Channel State Information (CSI) can precisely reflect human movements. Unfortunately, nearly all Wi-Fi-based recognition systems assume a clean wireless environment, i.e., no interference will compromise the developed algorithms, which, apparently, is not feasible in practice. Even worse, for systems using Wi-Fi 2.4GHz signals, the widely existing interference from coexisting protocols, such as ZigBee, Bluetooth, and LTE-Unlicensed, can easily compromise the recognition process, posing a hard limit on further enhancing the accuracy. Therefore, this work uncovers a new signal adversarial attack against Wi-Fi-based human activity recognition systems, by intentionally injecting interference using coexisting protocol signals. The contaminated Wi-Fi signal will distort CSI estimation and finally output a false recognition result. Different from traditional jamming attacks, this new adversarial attack is intelligent and stealthy in terms of avoiding being detected from traffic analysis. Along with both theoretical analysis and extensive real-world experiments, we have shown this newly-identified attack can easily compromise many existing Wi-Fi-based human recognition systems while still bypassing existing schemes for malicious signal detection. Pei Huang 0005, Xiaonan Zhang 0001, Sihan Yu, Linke Guo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | ULPT: A User-Centric Location Privacy Trading Framework for Mobile Crowd SensingabstractMobile crowd sensing (MCS) arises as a promising data collection paradigm that leverages the power of ubiquitous mobile devices to acquire rich information regarding their surrounding environment. In many location-based sensing tasks, workers are required to associate their sensing reports with corresponding geographic coordinates. Such information leaves a trail of worker's historical location record which thus poses a severe threat to their location privacy. On the other hand, individual workers may perceive location privacy differently. Instead of following conventional solutions that aim to perfectly hide user privacy, this paper adopts a novel alternative approach. Auser-centriclocationprivacytrading framework, called ULPT, is constructed to facilitate location privacy trading between workers and the platform. Each worker can decide how much location privacy to disclose to the platform in an MCS task based on its own location privacy leakage budget$\xi$. The higher$\xi$is, the more privacy its reported location discloses. Accordingly, it receives higher payment from the platform as compensation. Besides, ULPT enables the platform to select a suitable set of winning workers to achieve desirable MCS service accuracy while taking into account of its budget limit and worker privacy requirements. For this purpose, a heuristic algorithm is devised with a bounded optimality gap. As formally proved in this manuscript, ULPT guarantees a series of nice properties, including$\xi$-privacy,$(\alpha, \beta)$-accuracy,budget feasibility. Moreover, both rigorous theoretical analysis and extensive simulations are conducted to evaluate tradeoffs among these three. Wenqiang Jin, Mingyan Xiao, Linke Guo, Lei Yang 0001, Ming Li 0006 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Launching Smart Selective Jamming Attacks in WirelessHART NetworksabstractAs a leading industrial wireless standard, WirelessHART has been widely implemented to build wireless sensor-actuator networks (WSANs) in industrial facilities, such as oil refineries, chemical plants, and factories. For instance, 54,835 WSANs that implement the WirelessHART standard have been deployed globally by Emerson process management, a WirelessHART network supplier, to support process automation. While the existing research to improve industrial WSANs focuses mainly on enhancing network performance, the security aspects have not been given enough attention. We have identified a new threat to WirelessHART networks, namely smart selective jamming attacks, where the attacker first cracks the channel usage, routes, and parameter configuration of the victim network and then jams the transmissions of interest on their specific communication channels in their specific time slots, which makes the attacks energy efficient and hardly detectable. In this paper, we present this severe, stealthy threat by demonstrating the step-by-step attack process on a 50-node network that runs a publicly accessible WirelessHART implementation. Experimental results show that the smart selective jamming attacks significantly reduce the network reliability without triggering network updates. Xia Cheng, Junyang Shi, Mo Sha 0001, Linke Guo |
INFOCOM | 4 |
| 2021 | A Privacy-Preserving Distributed Contextual Federated Online Learning Framework with Big Data Support in Social Recommender SystemsabstractNowadays, the booming demand of big data analytics and the constraints of computational ability and network bandwidth have made it difficult for a stand-alone agent/service provider to provide suitable information for every user from the large volume online data within the limited time. To handle this challenge, a recommender system (RS) can call in a group of agents to collaborate to learn users' preference and taste, which is known as a distributed recommender system (DRS). DRSs can improve the accuracy of a traditional RS by requesting agents to share information with each other. However, it is challenging for DRSs to make personalized recommendations for each user due to the large amount of candidates. In addition, information sharing among agents raises a privacy concern. Thus, we propose a privacy-preserving DRS in this paper, and then model each service provider as a distributed online learner with context-awareness. Service providers collaborate to make personalized recommendations by learning users' preferences according to the user context and users' history behaviors. We adopt the federated learning framework to help train a high quality privacy- preserving centralized model over a large number of distributed agents which is probably unreliable with relatively slow network connections. To handle big data scenario, we build an item-cluster tree to deal with online and increasing datasets from top to the bottom. We further consider the structure of social network and present an efficient algorithm to avoid more performance loss adaptively. Theoretical proofs show that our proposed algorithm can achieve sublinear regret and differential privacy protection simultaneously for service providers and users. Numerical results confirm that our novel framework can handle increasing big datasets and strike a trade-off between privacy-preserving level and the prediction accuracy. Pan Zhou 0001, Kehao Wang 0001, Linke Guo, Shimin Gong, Bolong Zheng |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2021 | Incentivizing Crowdsensing-Based Noise Monitoring with Differentially-Private LocationsabstractMobile crowd sensing is a technique where a crowd sensing server outsources sensing tasks to the crowd for mobile data collection. In mobile crowd sensing, some tasks require location information to achieve their objectives, such as road monitoring, indoor floor plan reconstruction, and smart transportation. This required information incurs severe concerns on location privacy leakage and threatens workers' properties as well as public safety. In some cases, even sensing data itself can be used as auxiliary information resulting in location privacy breaches. Many existing works apply differential privacy mechanisms for location privacy preservation to tackle this problem, but they cannot efficiently fulfill privacy goals because each worker only considers his own privacy. As a consequence, the accumulated privacy budget will lower down the composed privacy level of all the workers' locations. In addition, deploying differential privacy is costly for workers and it will degrade the quality of data required in crowd sensing tasks. How to balance the cost and provide accurate aggregated data while fulfilling privacy objectives becomes a challenging issue. In this paper, we propose a group-differentially-private game-theoretical solution, which addresses these limitations in a privacy-preserving and efficient way. Our scheme enables the indistinguishability of workers' locations and sensing data without the help of a trusted entity while meeting the accuracy demands of crowd sensing tasks. The effectiveness and efficiency of our scheme are thoroughly evaluated based on real-world datasets. Pei Huang 0005, Xiaonan Zhang 0001, Linke Guo, Ming Li 0006 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Autonomous Robustness Control for Fog Reinforcement in Dynamic Wireless NetworksabstractThe sixth-generation (6G) of wireless communications systems will significantly rely on fog/edge network architectures for service provisioning. To realize this vision, AI-based fog/edge enabled reinforcement solutions are needed to serve highly stringent applications using dynamically varying resources. In this paper, we propose a cognitive dynamic fog/edge network where primary nodes (PNs) temporarily share their resources and act as fog nodes (FNs) for secondary nodes (SNs). Under this architecture, that unleashes multiple access opportunities, we design distributed fog probing schemes for SNs to search for available connections to access neighbouring FNs. Since the availability of these connections varies in time, we develop strategies to enhance the robustness to the uncertain availability of channels and fog nodes, and reinforce the connections with the FNs. A robustness control optimization is formulated with the aim to maximize the expected total long-term reliability of SNs’ transmissions. The problem is solved by an online robustness control (ORC) algorithm that involves online fog probing and an index-based connectivity activation policy derived from restless multi-armed bandits (RMABs) model. Simulation results show that our ORC scheme significantly improves the network robustness, the connectivity reliability and the number of completed transmissions. In addition, by activating the connections with higher indexes, the total long-term reliability optimization problem is solved with low complexity. Beatriz Lorenzo, Francisco Javier González-Castaño, Linke Guo, Felipe J. Gil-Castiñeira, Yuguang Fang |
IEEE/ACM Trans. Netw. | 3 |
| 2020 | Harnessing the Ambient Radio Frequency Noise for Wearable Device PairingabstractWearable devices that capture user's rich information regarding their health conditions and daily activities have unmet pairing needs. Today's solutions, which primarily rely on human involvement, are cumbersome, error-prone, and do not scale well. Despite some prior efforts trying to fill this gap, they either rely on some sophisticated sensors, such as electromyogram (EMG) or electrocardiogram (ECG) pads that may not universally exist, or non-trivial design of communication transceivers that cannot be found easily on current commercial devices. Therefore, a pairing scheme for wearable devices that is secure, practical, and convenient is in dire need. In this paper, we propose a novel approach that leverages ambient radio frequency (RF) noise. Our design is based on a key observation that received RF noise power measured in the logarithmic scale at different parts of a human body surface experience the same variation trend, whereas those from different human bodies or off the body are distinct. Wearables make use of the observed noise as the entropy source for the proposed pairing protocol. Extensive experiments show that our scheme has an equal error rate (EER) as low as 1.4% for pairing. Its key generation rate reaches 138 bits/sec, which beats so-far existing pairing schemes. Besides, our scheme can be efficiently executed within 0.97 s. Its incurred energy consumption is as low as 0.27 J for the entire pairing procedure. Wenqiang Jin, Ming Li 0006, Srinivasan Murali, Linke Guo |
CCS | 4 |
| 2020 | AuthCTC: Defending Against Waveform Emulation Attack in Heterogeneous IoT EnvironmentsabstractWidely deployed IoT devices have raised serious concerns for the spectrum shortage and the cost of multi-protocol gateway deployment. Recent emerging Cross-Technology Communication (CTC) technique can alleviate this issue by enabling direct communication among heterogeneous wireless devices, such as WiFi, Bluetooth, and ZigBee on 2.4 GHz. However, this new paradigm also brings security risks, where an attacker can use CTC to launch wireless attacks against IoT devices. Due to limited computational capability and different wireless protocols being used, many IoT devices are unable to use computationally-intensive cryptographic approaches for security enhancement. Therefore, without proper detection methods, IoT devices cannot distinguish signal sources before executing command signals. In this paper, we first demonstrate a new defined physical layer attack in the CTC scenario, named as waveform emulation attack, where a WiFi device can overhear and emulate the ZigBee waveform to attack ZigBee IoT devices. Then, to defend against this new attack, we propose a physical layer defensive mechanism, named as AuthCTC, to verify the legitimacy of CTC signals. Specifically, at the sender side, an authorization code is embedded into the packet preamble by leveraging the dynamically changed cyclic prefix. A WiFi-based detector is used to verify the authorization code at the receiver side. Extensive simulations and experiments using off-the-shelf devices are conducted to demonstrate both the feasibility of the attack and the effectiveness of our defensive mechanism. Sihan Yu, Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Long Cheng 0005, Kuang-Ching Wang |
AsiaCCS | 4 |
| 2019 | Hide and Seek: Waveform Emulation Attack and Defense in Cross-Technology CommunicationabstractThe exponentially increasing number of heterogeneous Internet of Things (IoT) devices result in severe spectrum shortage and interference in the already crowded ISM band. Cross-Technology Communication (CTC) is dedicated to achieving direct communication among wireless devices with different radios and modulation schemes, which serves as an effective approach to address the above challenges. Nevertheless, CTC also provides opportunities for adversaries to manipulate IoT devices. In this paper, we identify a new attack. Built on CTC, WiFi devices are able to hide the pre-intercepted ZigBee message into their transmitted waveforms, achieving the objective of directly controlling ZigBee devices. To defend against the attack, we analyze possible strategies and consider constellation higher-order statistic analysis as the countermeasure. Extensive simulations and experiments with commodity devices (CC26x2R1) and USRP-based prototypes show the existence of the newly identified attack, and further, validate the effectiveness of the proposed defensive approach. Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Yuguang Fang |
ICDCS | 3 |
| 2019 | If You Do Not Care About It, Sell It: Trading Location Privacy in Mobile Crowd SensingabstractMobile crowd sensing (MCS) is a technique where sensing tasks are outsourced to a crowd of mobile users. Since most of sensing tasks are location-dependent, workers are required to embed their locations into sensing reports, which incurs location privacy vulnerabilities. Realizing that workers perceive their location privacy differently, in this work we construct an auction-based trading market, facilitating location privacy trading between workers and the platform. Each worker can decide how much location privacy to disclose to the platform based on its own location privacy leakage budget $\xi$. The higher $\xi$ is, the less secrecy its reported location preserves. As a result, it receives higher payment from the platform as a compensation to its privacy loss. Besides, our mechanism enables the platform to select a suitable set of winning workers to achieve desirable service accuracy. For this purpose, a heuristic algorithm is devised, with polynomial-time complexity and bounded optimality gap. As formally proved in this manuscript, our proposed mechanism guarantees a series of nice properties, including $\xi$-privacy, $(\alpha,\beta)$accuracy, and budget feasibility. Wenqiang Jin, Mingyan Xiao, Ming Li 0006, Linke Guo |
INFOCOM | 4 |
| 2019 | Incentivizing Relay Participation for Securing IoT CommunicationabstractInternet of Things (IoT) has emerged as a new computing paradigm that promises to offer a fully connected “smart” world. However, due to the open nature of wireless medium, the information sensed, collected, and transmitted by IoT devices can be easily intercepted by adversaries, which becomes a serious concern in most IoT applications requiring sensitive data. In practice, cooperative communication approaches can effectively improve the security level for wireless communication under the presence of eavesdroppers with unbounded computational ability. In this paper, we apply the amplify-and-forward (AF) cooperative communication to increase the secrecy capacity of IoT systems by incentivizing relay IoT devices. Specifically, a Stackelberg game is designed to motivate the participation of the relay IoT devices for security enhancement. Extensive experimental results have demonstrated the feasibility and security of the proposed mechanism under both unknown and known channel state information (CSI) models. Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Mo Sha 0001 |
INFOCOM | 3 |
| 2019 | Practical Privacy-Preserving ECG-Based Authentication for IoT-Based HealthcareabstractIn current healthcare systems, patients use various types of medical Internet of Things devices for monitoring their health conditions. The collected information (personal health records) will be sent back to hospitals for diagnosis and quick responses. However, severe security and privacy leakages with regard to data privacy and identity authentication are incurred because the monitored health data contains sensitive information. Therefore, the data should be well protected from unauthorized entities. Unfortunately, traditional cryptographic approaches or password-based mechanisms cannot fulfill the privacy and security demands in health monitoring due to their low efficiency and knowledge-based property. Biometric authentication overcomes these deficiencies and successfully verifies the inherent characteristics of humans. Among all biometrics, the electrocardiogram (ECG) signal is the most suitable one due to its medical properties. However, the security and privacy objectives of ECG-based authentication usually fail in practice due to the noise interferences in the collected ECG data and the privacy breach of the ECG database. In this paper, we propose a practical scheme that can reliably authenticate patients with noisy ECG signals and provide differentially private protection simultaneously. The effectiveness and efficiency of our scheme are thoroughly analyzed and evaluated over online datasets. We also conduct a pilot study on human subjects experiencing different exercise levels to validate our scheme. Pei Huang 0005, Linke Guo, Ming Li 0006, Yuguang Fang |
IEEE Internet Things J. | 2 |
| 2019 | Publicly Verifiable Boolean Query Over Outsourced Encrypted DataabstractOutsourcing storage and computation to the cloud has become a common practice for businesses and individuals. As the cloud is semi-trusted or susceptible to attacks, many researches suggest that the outsourced data should be encrypted and then retrieved by using searchable symmetric encryption (SSE) schemes. Since the cloud is not fully trusted, we doubt whether it would always process queries correctly or not. Therefore, there is a need for users to verify their query results. Motivated by this, in this paper, we propose a publicly verifiable dynamic searchable symmetric encryption scheme based on the accumulation tree. We first construct an accumulation tree based on encrypted data and then outsource both of them to the cloud. Next, during the search operation, the cloud generates the corresponding proof according to the query result by mapping Boolean query operations to set operations, while keeping privacy preservation and achieving the verification requirements: freshness, authenticity, and completeness. Finally, we extend our scheme by dividing the accumulation tree into different small accumulation trees to make our scheme scalable. The security analysis and performance evaluation show that the proposed scheme is secure and practical. Shunrong Jiang, Xiaoyan Zhu 0005, Linke Guo, Jianqing Liu |
IEEE Trans. Cloud Comput. | 3 |
| 2019 | PersonaIA: A Lightweight Implicit Authentication System Based on Customized User Behavior SelectionabstractMotivated by the great potential of implicit and seamless user authentication, we attempt to build an implicit authentication (IA) system with adaptive sampling that automatically selects dynamic sets of activities for user behavior extraction. Various activities, such as user location, application usage, user motion, and battery usage have been popular choices to generate behaviors, the soft biometrics, for implicit authentication. Unlike password-based or hard biometric-based authentication, implicit authentication does not require explicit user action or expensive hardware. However, user behaviors can change unpredictably which renders it more challenging to develop systems that depend on them. In addition to dynamic behavior extraction, the proposed implicit authentication system differs from the existing systems in terms of energy efficiency for battery-powered mobile devices. Since implicit authentication systems including the proposed one rely on machine learning, the expensive training process needs be outsourced to the remote server. However, mobile devices may not always have reliable network connections to send real-time data to the server for training. We overcome this limitation by proposing a W-layer, an overlay that provides a practical and energy-efficient solution for implicit authentication on mobile devices. We implemented partially labeled Dirichlet allocation (PLDA) on the server side for more accurate feature extraction, and achieved 93.3 percent precision and 98.6 percent accuracy in the synthetic dataset. Furthermore, we tested the power consumption of the smartphones used for our experiments and found that our method consumed 14.5 percent of the devices' total battery usage. Yingyuan Yang, Jinyuan Sun, Linke Guo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2019 | Social-Aware Energy-Efficient Data Offloading With Strong StabilityabstractThe exploding popularity of mobile devices enables people to enjoy the benefits brought by various interesting mobile apps. The ever-increasing data traffic has exacerbated energy consumption on both cellular service providers and mobile users. It has become an urgent need to reducing the energy consumption in the cellular network while satisfying users' increasing traffic demands. Mobile data offloading is an effective energy-saving paradigm to tackle the above-mentioned problem. However, the current approaches cannot fully address the issue in terms of user demands and offloaded traffic. With the observation that duplicated data transmission often happens in the crowd with similar social interests, we deploy device-to-device (D2D) data offloading to achieve the energy efficiency at the user side while adapting their increasing traffic demands. Specifically, we investigate the stochastic optimization of the long-term time-averaged expected energy consumption while guaranteeing the strong stability of the network by utilizing the social-aware and energy-efficient D2D mobile offloading. By jointly considering interference among D2D users, social-aware caching, link scheduling, and routing, an offline finite-queue-aware energy minimization problem is formulated, which is a time-coupling stochastic mixed-integer non-linear programming (MINLP) problem. We propose an online finite-queue-aware energy algorithm by employing the Lyapunov drift-plus-penalty theory. Extensive analysis and simulations are conducted to validate the proposed scheme. Xiaonan Zhang 0001, Pei Huang 0005, Linke Guo, Yuguang Fang |
IEEE/ACM Trans. Netw. | 3 |
| 2018 | CREAM: Unauthorized Secondary User Detection in Fading EnvironmentsabstractDynamic Spectrum Access (DSA) has emerged as a major technology in the future wireless system to alleviate the worldwide spectrum scarcity issue. Authorized secondary users can take advantages of underutilized spectrum for communication. However, due to the open nature of the wireless medium, the DSA system suffers spectrum misuse by unauthorized secondary users, and thus fewer users would participate in DSA. Although many existing works have implemented misuse detection schemes into DSA, practical concerns, such as channel fading issues, are not well addressed. Therefore, how to ensure the reliable communication among authorized secondary users in a practical channel model becomes a challenging issue. In this paper, we propose CREAM, a physical-layer based misuse detection scheme specifically in the fading environment, which conceals the unforgeable spectrum permit into the message by superposition modulation for verification. Given the pre-shared secret information, the third-party verifier can perform efficient detection on unauthorized spectrum access. Detailed analysis and simulation results demonstrate the security, accuracy, efficiency, and low intrusion to message transmission in fading environments. Xiaonan Zhang 0001, Pei Huang 0005, Qi Jia 0002, Linke Guo |
MASS | 4 |
| 2018 | Motivating Human-Enabled Mobile Participation for Data OffloadingabstractThe exploding popularity of mobile devices enables people to enjoy benefits brought by various interesting mobile apps. However, the ever-increasing data traffic has exacerbated the congestion on current cellular networks, which results in users' dissatisfaction, especially in crowded areas. Hence, how to alleviate data traffic in cellular networks becomes a challenging problem. Traditional methods rely on mobile offloading techniques to deviate the data traffic originally targeted to cellular networks, such as the small cell, Wi-Fi, and opportunistic communication. Unfortunately, mobile users still experience severe congestion when a large number of users request for data. Facing these challenges, we introduce the concept of mobile participation to assist data offloading by leveraging the mobility of users and the social features among a group of users. A mobile caching user, who pre-caches a certain amount of contents, will roam around congested areas to participate in content dissemination in order to satisfy users' requests, which is expected to benefit both himself and users in the crowd simultaneously. To motivate such human-enabled mobile participation for data offloading, a Stackelberg game is deployed with joint considerations on social effect and delay effect. Based on detailed performance analysis, we demonstrate the feasibility and efficiency of the proposed approach. Xiaonan Zhang 0001, Linke Guo, Ming Li 0006, Yuguang Fang |
IEEE Trans. Mob. Comput. | 2 |
| 2018 | Preserving Model Privacy for Machine Learning in Distributed SystemsabstractMachine Learning based data classification is a widely used data mining technique. By learning massive data collected from the real world, data classification helps learners discover hidden data patterns. These hidden data patterns are represented by the learned model in different machine learning schemes. Based on such models, a user can classify whether the new incoming data belongs to an existing class; or, multiple entities may test the similarity of their datasets. However, due to data locality and privacy concerns, it is infeasible for large-scale distributed systems to share each individual's datasets for classifying or testing. On the one hand, the learned model is an entity's private asset and may leak private information, which should be well protected from all other non-collaborative entities. On the other hand, the new incoming data may contain sensitive information which cannot be disclosed directly for classification. To address the above privacy issues, we propose an approach to preserve the model privacy of the data classification and similarity evaluation for distributed systems. With our scheme, neither new data nor learned models are directly revealed during the classification and similarity evaluation procedures. Based on extensive real-world experiments, we have evaluated the privacy preservation, feasibility, and efficiency of the proposed scheme. Qi Jia 0002, Linke Guo, Zhanpeng Jin, Yuguang Fang |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2017 | Securing a UAV using individual characteristics from an EEG signalabstractUnmanned aerial vehicles (UAVs) have been applied for both civilian and military applications; scientific research involving UAVs has encompassed a wide range of scientific study. However, communication with unmanned vehicles are subject to attack and compromise. Such attacks have been reported as early as 2009, when a Predator UAV's video stream was compromised. Since UAVs extensively utilize autonomous behavior, it is important to develop an autopilot system that is robust to potential cyber-attack. In this work, we present a biometric system to encrypt communication between a UAV and a computerized base station. This is accomplished by generating a key derived from the Beta component of a user's EEG. When communication with a UAV is attacked, a safety mechanism directs the UAV to a safe ‘home’ location. This system has been validated on a commercial UAV under malicious attack conditions. Ashutosh Singandhupe, Hung Manh La, David Feil-Seifer, Pei Huang 0005, Linke Guo, Ming Li 0006 |
SMC | 5 |
| 2017 | Privacy-Preserving Verifiable Set Operation in Big Data for Cloud-Assisted Mobile CrowdsourcingabstractThe ubiquity of smartphones makes the mobile crowdsourcing possible, where the requester (task owner) can crowdsource data from the workers (smartphone users) by using their sensor-rich mobile devices. However, data collection, data aggregation, and data analysis have become challenging problems for a resource constrained requester when data volume is extremely large, i.e., big data. In particular to data analysis, set operations, including intersection, union, and complementation, exist in most big data analysis for filtering redundant data and preprocessing raw data. Facing challenges in terms of limited computation and storage resources, cloud-assisted approaches may serve as a promising way to tackle the big data analysis issue. However, workers may not be willing to participate if the privacy of their sensing data and identity are not well preserved in the untrusted cloud. In this paper, we propose to the use cloud to compute a set operation for the requester, at the same time workers' data privacy and identities privacy are well preserved. Besides, the requester can verify the correctness of set operation results. We also extend our scheme to support data preprocessing, with which invalid data can be excluded before data analysis. By using batch verification and data update methods, the proposed scheme greatly reduces the computational cost. Extensive performance analysis and experiment based on real cloud system have shown both the feasibility and efficiency of our proposed scheme. Gaoqiang Zhuo, Qi Jia 0002, Linke Guo, Ming Li 0006, Pan Li 0001 |
IEEE Internet Things J. | 3 |
| 2017 | My Privacy My Decision: Control of Photo Sharing on Online Social NetworksabstractPhoto sharing is an attractive feature which popularizes online social networks (OSNs). Unfortunately, it may leak users' privacy if they are allowed to post, comment, and tag a photo freely. In this paper, we attempt to address this issue and study the scenario when a user shares a photo containing individuals other than himself/herself (termed co-photo for short). To prevent possible privacy leakage of a photo, we design a mechanism to enable each individual in a photo be aware of the posting activity and participate in the decision making on the photo posting. For this purpose, we need an efficient facial recognition (FR) system that can recognize everyone in the photo. However, more demanding privacy setting may limit the number of the photos publicly available to train the FR system. To deal with this dilemma, our mechanism attempts to utilize users' private photos to design a personalized FR system specifically trained to differentiate possible photo co-owners without leaking their privacy. We also develop a distributed consensus-based method to reduce the computational complexity and protect the private training set. We show that our system is superior to other possible approaches in terms of recognition ratio and efficiency. Our mechanism is implemented as a proof of concept Android application on Facebook's platform. Kaihe Xu, Yuanxiong Guo, Linke Guo, Yuguang Fang, Xiaolin Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2016 | A Robust and Reusable ECG-Based Authentication and Data Encryption Scheme for eHealth SystemsabstracteHealth systems generate from the integration of information and communication technologies with traditional healthcare systems. They have widely replaced paper-based systems due to their prominent features of convenience and accuracy. However, eHealth systems also face many challenges, such as the privacy and security concerns over patients' identities and their personal health records (PHRs). Traditional cryptographic approaches are only capable of verifying ``what you possess" or ``what you remember" with the help of trust authorities. As a result, they are not suitable for medical applications and cannot handle above concerns effectively. Using biometrics can verify ``who you are" due to permanence, distinctiveness, and undeniability properties of biometrics. It outstands conventional authentication and encryption approaches in eHealth systems. A promising one among all is the ECG (ElectroCardioGram) signal, which is easier to implement than other biometrics. Unfortunately, most of existing works do not take the nonuniformity of ECG signals into consideration. Besides, they do not protect ECG signals well despite their sensitivity. Hence, we propose a robust and reusable authentication and encryption scheme based on ECG signals for eHealth systems. Our scheme can authenticate patients' identities and protect their PHRs, enable the reuse of the same ECG signal, and preserve the privacy of ECG signals. Theoretical and empirical evaluations demonstrate the security, effectiveness, and efficiency of the proposed scheme. Pei Huang 0005, Borui Li 0002, Linke Guo, Zhanpeng Jin, Yu Chen 0002 |
GLOBECOM | 3 |
| 2016 | Privacy-Preserving Data Aggregation over Incomplete Data for CrowdsensingabstractCrowdsensing recently attracts great attention from both industry and academia. By fusing and analyzing multi- dimensional sensing data collected from crowdsensing users, it is possible to support health caring, environment mentoring, traffic mentoring and social behavior mentoring. Nonetheless, how to preserve users' data privacy during data fusing, e.g., data aggregation, has been rarely discussed for crowdsensing before. Besides, due to the dynamics of sensing environments and available resources at users, there will be missing elements from users' sensing results. In this paper we aim to achieve privacy-preserving data aggregation over incomplete data for crowdsensing. A novel scheme is developed based on linear transformation and homomorphic encryption scheme. It enables the server to obtain aggregation results over recovered sensing results without learning their individual details. Security analysis and performance evaluation are conducted showing the effectiveness and efficiency of our scheme. Iman Vakilinia, Jiajun Xin, Ming Li 0006, Linke Guo |
GLOBECOM | 4 |
| 2016 | Social-Enabled Data Offloading via Mobile Participation - A Game-Theoretical ApproachabstractThe exploding popularity of mobile devices enables people to enjoy benefits brought by various interesting mobile apps, such as social networking, mobile video services, and location-based services, etc. However, the ever-increasing data traffic has exacerbated congestions on current cellular networks, which results in users' dissatisfaction, especially in crowded areas. Hence, how to deal with the explosive data traffic in cellular networks becomes a challenging problem. Traditional methods rely on mobile offloading techniques to deviate the data traffic targeted to cellular networks, such as small cell, Wi-Fi, and opportunistic communication. Unfortunately, mobile users will still experience severe congestion when a large number of users request for data. Facing these challenges, we introduce the concept of mobile participation to assist data offloading by leveraging the mobility of mobile users and the social features among a group of users. A mobile caching user, who pre- caches certain amount of contents, can roam around congested areas to participate in data dissemination in order to satisfy users' requests, which can benefit both herself and users in the crowd simultaneously. Therefore, we propose a game theoretical approach to analyze the data offloading via mobile participation with joint considerations on network effects, congestion, social behaviors, and pricing strategy. Based on detailed performance analysis, we show the feasibility and efficiency of the proposed approach. Xiaonan Zhang 0001, Linke Guo, Ming Li 0006, Yuguang Fang |
GLOBECOM | 2 |
| 2016 | Privacy-Preserving Data Classification and Similarity Evaluation for Distributed SystemsabstractData classification is a widely used data mining technique for big data analysis. By training massive data collected from the real world, data classification helps learners discover hidden data patterns. In addition to data training, given a trained model from collected data, a user can classify whether a new incoming data belongs to an existing class, or, multiple distributed entities may collaborate to test the similarity of their trained results. However, due to data locality and privacy concerns, it is infeasible for large-scale distributed systems to share each individual's datasets with each other for data similarity check. On the one hand, the trained model is an entity's private asset and may leak private information, which should be well protected from all other non-collaborative entities. On the other hand, the new incoming data may contain sensitive information which cannot be disclosed directly for classification. To address the above privacy issues, we propose a privacy-preserving data classification and similarity evaluation scheme for distributed systems. With our scheme, neither new arriving data nor trained models are directly revealed during the classification and similarity evaluation procedures. The proposed scheme can be applied to many fields using data classification and evaluation. Based on extensive real-world experiments, we have also evaluated the privacy preservation, feasibility, and efficiency of the proposed scheme. Qi Jia 0002, Linke Guo, Zhanpeng Jin, Yuguang Fang |
ICDCS | 2 |
| 2016 | Privacy-preserving verifiable data aggregation and analysis for cloud-assisted mobile crowdsourcingabstractCrowdsourcing is a crowd-based outsourcing, where a requester (task owner) can outsource tasks to workers (public crowd). Recently, mobile crowdsourcing, which can leverage workers' data from smartphones for data aggregation and analysis, has attracted much attention. However, when the data volume is getting large, it becomes a difficult problem for a requester to aggregate and analyze the incoming data, especially when the requester is an ordinary smartphone user or a start-up company with limited storage and computation resources. Besides, workers are concerned about their identity and data privacy. To tackle these issues, we introduce a three-party architecture for mobile crowdsourcing, where the cloud is implemented between workers and requesters to ease the storage and computation burden of the resource-limited requester. Identity privacy and data privacy are also achieved. With our scheme, a requester is able to verify the correctness of computation results from the cloud. We also provide several aggregated statistics in our work, together with efficient data update methods. Extensive simulation shows both the feasibility and efficiency of our proposed solution. Gaoqiang Zhuo, Qi Jia 0002, Linke Guo, Ming Li 0006, Pan Li 0001 |
INFOCOM | 3 |
| 2015 | Publicly Verifiable Boolean Query over Outsourced Encrypted DataabstractOutsourcing storage and computation to the cloud has become a common practice for businesses and individuals. As the cloud is semi-trusted or susceptible to attacks, many researches suggest that the outsourced data should be encrypted and then retrieved by using searchable symmetric encryption (SSE) schemes. Since the cloud is not fully trusted, we doubt whether it would always process queries correctly or not. Therefore, there is a need for users to verify their query results. Motivated by this, in this paper, we propose a publicly verifiable dynamic searchable symmetric encryption scheme based on the accumulation tree. We first construct an accumulation tree based on encrypted data and then outsource both of them to the cloud. Next, during the search operation, the cloud generates the corresponding proof according to the query result by mapping Boolean query operations to set operations while keeping privacy-preservation and achieving the verification requirements: authenticity, freshness, and completeness. The security analysis and performance evaluation show that the proposed scheme is privacy-preserving and practical. Shunrong Jiang, Xiaoyan Zhu 0005, Linke Guo, Jianqing Liu |
GLOBECOM | 3 |
| 2015 | A Secure Collaborative Machine Learning Framework Based on Data LocalityabstractAdvancements in big data analysis offer cost-effective opportunities to improve decision-making in numerous areas such as health care, economic productivity, crime, and resource management. Nowadays, data holders are tending to sharing their data for better outcomes from their aggregated data. However, the current tools and technologies developed to manage big data are often not designed to incorporate adequate security or privacy measures during data sharing. In this paper, we consider a scenario where multiple data holders intend to find predictive models from their joint data without revealing their own data to each other. Data locality property is used as an alternative to multi-party computation (SMC) techniques. Specifically, we distribute the centralized learning task to each data holder as local learning tasks in a way that local learning is only related to local data. Along with that, we propose an efficient and secure protocol to reassemble local results to get the final result. Correctness of our scheme is proved theoretically and numerically. Security analysis is conducted from the aspect of information theory. Kaihe Xu, Haichuan Ding, Linke Guo, Yuguang Fang |
GLOBECOM | 3 |
| 2015 | Privacy-Preserving Verifiable Proximity Test for Location-Based ServicesabstractThe prevalence of smartphones with geo-positioning functionalities gives rise to a variety of location-based services (LBSs). Proximity test, an important branch of location-based services, enables the LBS users to determine whether they are in a close proximity with their friends, which can be extended to numerous applications in location-based mobile social networks. Unfortunately, serious security and privacy issues may occur in the current solutions to proximity test. On the one hand, users' private location information is usually revealed to the LBS server and other users, which may lead to physical attacks to users. On the other hand, the correctness of proximity test computation results from LBS server cannot be verified in the existing schemes and thus the creditability of LBS is greatly reduced. Besides, privacy should be defined by user him/herself, not the LBS server. In this paper, we propose a privacy-preserving verifiable proximity test for location-based services. Our scheme enables LBS users to verify the correctness of proximity test results from LBS server without revealing their location information. We show the security, efficiency, and feasibility of our proposed scheme through detailed performance evaluation. Gaoqiang Zhuo, Qi Jia 0002, Linke Guo, Ming Li 0006, Yuguang Fang |
GLOBECOM | 3 |
| 2015 | Efficient private matching based on blind signature for proximity-based mobile social networksabstractProximity-based mobile social networks (PMSNs) are becoming increasingly popular due to the explosive growth of mobile devices in recent years, where a user can find a best matching friend within a nearby proximity through profile matching. However, the matching process calls for the exchange of users' personal information, which conflicts with their growing privacy concerns on revealing their profiles to strangers. Although a few methods have been proposed to achieve privacy-preserving friend discovery, most of them introduce tremendous communication overhead to the system so that they are not practical for resource-limited mobile devices. In this paper, we propose a private matching scheme based on blind signature for PMSNs, which can achieve a fine-grained matching and preferably protect users' privacy without relying on any Trusted Third Party (TTP). Moreover, our scheme can significantly reduce the communication overhead even when working as a group matching mode. Security analysis and detailed simulations show that the proposed scheme can achieve efficient privacy-preserving friend discovery. Shunrong Jiang, Xiaoyan Zhu 0005, Linke Guo, Ripei Hao |
ICC | 3 |
| 2015 | Privacy-Preserving Machine Learning Algorithms for Big Data SystemsabstractMachine learning has played an increasing important role in big data systems due to its capability of efficiently discovering valuable knowledge and hidden information. Often times big data such as healthcare systems or financial systems may involve with multiple organizations who may have different privacy policy, and may not explicitly share their data publicly while joint data processing may be a must. Thus, how to share big data among distributed data processing entities while mitigating privacy concerns becomes a challenging problem. Traditional methods rely on cryptographic tools and/or randomization to preserve privacy. Unfortunately, this alone may be inadequate for the emerging big data systems because they are mainly designed for traditional small-scale data sets. In this paper, we propose a novel framework to achieve privacy-preserving machine learning where the training data are distributed and each shared data portion is of large volume. Specifically, we utilize the data locality property of Apache Hadoop architecture and only a limited number of cryptographic operations at the Reduce() procedures to achieve privacy-preservation. We show that the proposed scheme is secure in the semi-honest model and use extensive simulations to demonstrate its scalability and correctness. Kaihe Xu, Hao Yue 0001, Linke Guo, Yuanxiong Guo, Yuguang Fang |
ICDCS | 3 |
| 2015 | PPER: Privacy-preserving economic-robust spectrum auction in wireless networksabstractMany truthful spectrum auction schemes have been recently proposed to to ensure that the dominant strategy for bidders is to bid truthfully and thus protect the auctioneer's benefits. However, most of them assume the auctioneer is trustful and do not protect bidders' interests. An auctioneer can manipulate the winner's charging price if it knows bidders' bids. Thus, it is critical to protect bids from the auctioneer. Towards this end, we develop a Privacy-Preserving Economic-Robust spectrum auction scheme, namely PPER. Not only does it well protect users' bid privacy, but also guarantees economic-robustness which is another important auction property. Besides, only transmitters but not receivers are considered in most previous spectrum auctions, resulting in many unexpected collisions during transmissions. In this work, we consider interference constraints from transmissions instead of transmitters in spectrum allocation. Extensive privacy analysis and simulation results show the effectiveness and efficiency of our scheme. Ming Li 0006, Pan Li 0001, Linke Guo, Xiaoxia Huang 0004 |
INFOCOM | 3 |
| 2015 | Verifiable privacy-preserving monitoring for cloud-assisted mHealth systemsabstractWidely deployed mHealth systems enable patients to efficiently collect, aggregate, and report their Personal Health Records (PHRs), and then lower the costs and shorten their response time. The increasing needs of PHR monitoring require the involvement of healthcare companies that provide monitoring programs for analyzing PHRs. Unfortunately, healthcare companies are lack of the computation, storage, and communication capability on supporting millions of patients. To tackle this problem, they seek for the help from the cloud. However, delegating monitoring programs to the cloud may incur serious security and privacy breaches because people have to provide their identity information and PHRs to the public domain. Even worse, the cloud may mistakenly return the incorrect computation results, which will put patients' life in jeopardy. In this paper, we propose a verifiable privacy-preserving monitoring scheme for cloud-assisted mHealth systems. Our scheme allows patients to verify the correctness of computation results from the cloud without revealing their PHRs and identity information. In addition, our advanced schemes offer efficient PHR updates and PHR computations on complex monitoring programs. By detailed performance evaluation, we have shown the security and efficiency of our proposed scheme. Linke Guo, Yuguang Fang, Ming Li 0006, Pan Li 0001 |
INFOCOM | 1 |
| 2015 | SEISA: Secure and efficient encrypted image search with access controlabstractImage search has been widely deployed in many applications for the rich content that images contain. In the era of big data, image search engines have to be hosted in data centers. As a viable solution, outsourcing the image search to public clouds is an economic choice for many small organizations. However, as many images contain sensitive information, e.g., healthcare information and personal faces/locations, directly outsourcing image search services to public clouds obviously raises privacy concerns. With this observation, several attempts are made towards secure image search over encrypted dataset, but they are limited by either search accuracy or search efficiency. In this paper, we propose a lightweight secure image search scheme over encrypted data, namely SEISA. Compared with image search techniques over plaintexts, SEISA only increases about 9% search cost and sacrifices about 3% on search accuracy. SEISA also efficiently supports search access control by employing a novel polynomial based design, which enables data owners to define who can search a specific image. Furthermore, we design a secure k-means outsourcing algorithm that significantly saves the data owner's cost. To demonstrate SEISA's performance, we implement a prototype of SEISA on Amazon EC2 cloud over a dataset with 10 million images. Shucheng Yu, Linke Guo |
INFOCOM | 3 |
| 2015 | A Privacy-Preserving Attribute-Based Reputation System in Online Social Networks
Linke Guo, Chi Zhang 0001, Yuguang Fang, Phone Lin |
J. Comput. Sci. Technol. | 1 |
| 2015 | A Trust-Based Privacy-Preserving Friend Recommendation Scheme for Online Social NetworksabstractOnline social networks (OSNs), which attract thousands of million people to use everyday, greatly extend OSN users' social circles by friend recommendations. OSN users' existing social relationship can be characterized as 1-hop trust relationship, and further establish a multi-hop trust chain during the recommendation process. As the same as what people usually experience in the daily life, the social relationship in cyberspaces are potentially formed by OSN users' shared attributes, e.g., colleagues, family members, or classmates, which indicates the attribute-based recommendation process would lead to more fine-grained social relationships between strangers. Unfortunately, privacy concerns raised in the recommendation process impede the expansion of OSN users' friend circle. Some OSN users refuse to disclose their identities and their friends' information to the public domain. In this paper, we propose a trust-based privacy-preserving friend recommendation scheme for OSNs, where OSN users apply their attributes to find matched friends, and establish social relationships with strangers via a multi-hop trust chain. Based on trace-driven experimental results and security analysis, we have shown the feasibility and privacy preservation of our proposed scheme. Linke Guo, Chi Zhang 0001, Yuguang Fang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2014 | Control of photo sharing over Online Social NetworksabstractPhoto sharing is an attractive feature which popularizes Online Social Networks (OSNs). Unfortunately, it may leak users' privacy if they are allowed to post, comment, and tag a photo freely. In this paper, we attempt to address this issue and study the scenario when a user shares a photo containing individuals other than himself/herself (termed co-photo for short). To prevent possible leakage of a photo privacy, we design a mechanism to enable each individual in a photo be aware of the posting activity and participate in the decision making on the photo posting. For this purpose, we need an efficient facial recognition (FR) system that can recognize everyone in the photo. However, more demanding privacy setting may limit the number of the photos publicly available to train the FR system. To deal with this dilemma, our mechanism attempts to utilize users' private photos to design a personalized FR system specifically trained to differentiate possible photo co-owners without leaking his/her privacy. We have also developed a distributed consensus-based method to not only reduce the computational complexity, but also preserve the privacy during the training. We show that our system is superior to other possible approaches in terms of recognition ratio and efficiency. Our mechanism is implemented as an Android application on Facebook's platform. Kaihe Xu, Yuanxiong Guo, Linke Guo, Yuguang Fang, Xiaolin Li 0001 |
GLOBECOM | 3 |
| 2014 | DataClouds: Enabling Community-Based Data-Centric Services Over the Internet of ThingsabstractThe Internet of Things (IoT) is emerging as one of the major trends for the next evolution of the Internet, where billions of physical objects or things (including but not limited to humans) will be connected over the Internet, and a vast amount of information data will be shared among them. However, the current Internet was built on a host-centric communication model, which was primarily designed for meeting the demand of pair-wise peer-to-peer communications and cannot well accommodate various advanced data-centric services boosted by the IoT in which users care about content and are oblivious to locations where the content is stored. In this paper, we propose a novel architecture for the future Internet based on information-centric networking (ICN), which is called DataClouds, to better accommodate data-centric services. Different from existing ICN-based architectures, we take the sharing nature of data-centric services under the IoT into consideration and introduce logically and physically formed communities as the basic building blocks to construct the network so that data could be more efficiently shared and disseminated among interested users. We also elaborate on several fundamental design challenges for the Internet under this new architecture and show that DataClouds could offer more efficient and flexible solutions than traditional ICN-based architectures. Hao Yue 0001, Linke Guo, Ruidong Li 0001, Hitoshi Asaeda, Yuguang Fang |
IEEE Internet Things J. | 2 |
| 2014 | A Privacy-Preserving Attribute-Based Authentication System for Mobile Health NetworksabstractElectronic healthcare (eHealth) systems have replaced paper-based medical systems due to the attractive features such as universal accessibility, high accuracy, and low cost. As a major component of eHealth systems, mobile healthcare (mHealth) applies mobile devices, such as smartphones and tablets, to enable patient-to-physician and patient-to-patient communications for better healthcare and quality of life (QoL). Unfortunately, patients' concerns on potential leakage of personal health records (PHRs) is the biggest stumbling block. In current eHealth/mHealth networks, patients' medical records are usually associated with a set of attributes like existing symptoms and undergoing treatments based on the information collected from portable devices. To guarantee the authenticity of those attributes, PHRs should be verifiable. However, due to the linkability between identities and PHRs, existing mHealth systems fail to preserve patient identity privacy while providing medical services. To solve this problem, we propose a decentralized system that leverages users' verifiable attributes to authenticate each other while preserving attribute and identity privacy. Moreover, we design authentication strategies with progressive privacy requirements in different interactions among participating entities. Finally, we have thoroughly evaluated the security and computational overheads for our proposed schemes via extensive simulations and experiments. Linke Guo, Chi Zhang 0001, Jinyuan Sun, Yuguang Fang |
IEEE Trans. Mob. Comput. | 1 |
| 2014 | PSaD: A Privacy-Preserving Social-Assisted Content Dissemination Scheme in DTNsabstractContent dissemination is very useful for many mobile applications, like instant messaging, file sharing, and advertisement broadcast, etc. In real life, for various kinds of time-insensitive contents, such as family photos and video clips, the process of content dissemination forms a delay tolerant networks (DTNs). To improve the data forwarding performance in DTNs, several social-based approaches have been proposed, most of which leverage mobile users' social information, including contact history, moving trajectory, and personal profiles as metrics to design routing schemes. However, although the social-based approaches provide better performance, the revealing of mobile users' information apparently compromises their privacy. Moreover, users' contents may only be shared with a particular group of users rather everyone in the system. In this paper, we propose the PSaD: a Privacy-preserving Social-assisted content Dissemination scheme in DTNs. We apply users' verifiable attributes to establish their social relationships in terms of identical attributes in a privacy-preserving way. Besides, to provide the confidentiality of contents, our approach enables users to encrypt contents before the dissemination process, and only allows users who have particular attributes to decrypt them. By trace-driven simulations and experiments, we show the performance, privacy preservation, and efficiency of our proposed scheme. Linke Guo, Chi Zhang 0001, Hao Yue 0001, Yuguang Fang |
IEEE Trans. Mob. Comput. | 1 |
| 2013 | Privacy-preserving attribute-based friend search in geosocial networks with untrusted serversabstractLocation-based Services (LBSs) enable mobile users to request and obtain certain services based on their current locations, such as finding nearby gas station, looking for coffee shops, and using online GPS navigation, etc. As a major branch of LBSs, geosocial networking services, such as Foursquare, become popular due to the explosive growth of smartphone users. Geosocial networking services allow people to use their location information to find potential friends who have similar interests within close proximity and initiate communications with each other. However, most existing geosocial networking services ask for mobile users' current location information and store it on an untrusted server with less privacy concerns. To some extent, mobile users need to reveal their interests and physical location information to a service provider in order to realize the functionality of geosocial networking, which apparently deteriorates users' privacy on the aspects of their profiles and locations. In this paper, we propose a privacy-preserving friend search scheme in geosocial networks without relying on a trusted centralized server. Our scheme lets localization infrastructures, such as base stations, create encrypted searchable tables on an untrusted server and allow mobile users to search for their possible friends using their profiles without exposing their location information. Extensive trace-driven simulation results and analysis show both the efficiency and privacy preservation of our proposed scheme. Linke Guo, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang |
GLOBECOM | 1 |
| 2013 | A privacy-preserving social-assisted mobile content dissemination scheme in DTNsabstractMobile content dissemination is very useful for many mobile applications in delay tolerant networks (DTNs), like instant messaging, file sharing, and advertisement dissemination, etc. Recently, social-based approaches, which attempt to exploit social behaviors of DTN users to forward time-insensitive data, such as family photos and friends' sightseeing video clips, have attracted intensive attentions in designing routing schemes in DTNs. Most social-based schemes leverage users' contact history and social information (e.g., community and friendship) as metrics to improve the dissemination performance. In these schemes, users need to obtain others' social information to determine their dissemination strategy, which apparently compromises others users' privacy. Moreover, the owner of mobile contents may only want to disclose his/her data to a particular group of users rather than revealing it to the public. In this paper, we propose a privacy-preserving social-assisted mobile content dissemination scheme in DTNs. We apply users' verifiable attributes to establish their potential social relationships in terms of identical attributes in a privacy-preserving way. Besides, to provide the confidentiality of mobile contents, our approach enables users to encrypt contents before the dissemination process, and only allows users who have particular attributes to decrypt them. By trace-driven simulations and experiments, we show the security and efficiency of our proposed scheme. Linke Guo, Chi Zhang 0001, Hao Yue 0001, Yuguang Fang |
INFOCOM | 1 |
| 2013 | A game-theoretic approach for achieving k-anonymity in Location Based ServicesabstractLocation Based Service (LBS), although it greatly benefits the daily life of mobile device users, has introduced significant threats to privacy. In an LBS system, even under the protection of pseudonyms, users may become victims of inference attacks, where an adversary reveals a user's real identity and complete moving trajectory with the aid of side information, e.g., accidental identity disclosure through personal encounters. To enhance privacy protection for LBS users, a common approach is to include extra fake location information associated with different pseudonyms, known as dummy users, in normal location reports. Due to the high cost of dummy generation using resource constrained mobile devices, self-interested users may free-ride on others' efforts. The presence of such selfish behaviors may have an adverse effect on privacy protection. In this paper, we study the behaviors of self-interested users in the LBS system from a game-theoretic perspective. We model the distributed dummy user generation as Bayesian games in both static and timing-aware contexts, and analyze the existence and properties of the Bayesian Nash Equilibria for both models. Based on the analysis, we propose a strategy selection algorithm to help users achieve optimized payoffs. Leveraging a beta distribution generalized from real-world location privacy data traces, we perform simulations to assess the privacy protection effectiveness of our approach. The simulation results validate our theoretical analysis for the dummy user generation game models. Xinxin Liu 0006, Linke Guo, Xiaolin Li 0001, Yuguang Fang |
INFOCOM | 3 |
| 2012 | User-centric private matching for eHealth networks - A social perspectiveabstractThe widely deployed electronic health (eHealth) systems changed people's daily life due to the extraordinary benefits, such as more efficiency, higher accuracy and broader availability. Patients in the eHealth network use their personal health records (PHRs) to communicate with their physicians and obtain medical services. As a matter of fact, patients who share the same diseases or symptoms want to communicate with each other not only for treatment, but also for psychological therapy. However, without sufficient knowledge of the authenticity of other patients' PHRs, patients are reluctant to share their medical information. On the other hand, patients would accept the patient-to-patient interaction only if their privacy issues of PHR are also well preserved. In this paper, we design a privacy-preserving user-centric private matching scheme from a social perspective in eHealth networks, where patients use verified PHR to find other patients who share the same situations and derive different user-centric results based on each one's own policy. In our scheme, the matching process guarantees both the verifiability and the privacy of patients' PHRs. Based on security and efficiency analysis, we show that our work satisfies both the privacy preservation and practicality requirements. Linke Guo, Xinxin Liu 0006, Yuguang Fang, Xiaolin Li 0001 |
GLOBECOM | 1 |
| 2012 | PAAS: A Privacy-Preserving Attribute-Based Authentication System for eHealth NetworksabstractRecently, eHealth systems have replaced paper based medical system due to its prominent features of convenience and accuracy. Also, since the medical data can be stored on any kind of digital devices, people can easily obtain medical services at any time and any place. However, privacy concern over patient medical data draws an increasing attention. In the current eHealth networks, patients are assigned multiple attributes which directly reflect their symptoms, undergoing treatments, etc. Those life-threatened attributes need to be verified by an authorized medical facilities, such as hospitals and clinics. When there is a need for medical services, patients have to be authenticated by showing their identities and the corresponding attributes in order to take appropriate healthcare actions. However, directly disclosing those attributes for verification may expose real identities. Therefore, existing eHealth systems fail to preserve patients' private attribute information while maintaining original functionalities of medical services. To solve this dilemma, we propose a framework called PAAS which leverages users' verifiable attributes to authenticate users in eHealth systems while preserving their privacy issues. In our system, instead of letting centralized infrastructures take care of authentication, our scheme only involves two end users. We also offer authentication strategies with progressive privacy requirements among patients or between patients and physicians. Based on the security and efficiency analysis, we show our framework is better than existing eHealth systems in terms of privacy preservation and practicality. Linke Guo, Chi Zhang 0001, Jinyuan Sun, Yuguang Fang |
ICDCS | 1 |
| 2011 | A Multi-Hop Privacy-Preserving Reputation Scheme in Online Social NetworksabstractOnline Social Networks (OSNs) are becoming immensely popular nowadays, and they change the ways people think and live. In this paper, we propose a novel reputation system which allows users to find potential connections between unfamiliar people based on the most updated friend list of each user in OSNs. To some extent, our scheme provides a way to judge people in OSNs without real interactions, but based on the existing overall attitudes on particular people. Moreover, our scheme can protect the confidentially of the potential relationships in which no one is able to acquire the detailed connections between two end nodes. Contrary to those which publish each individual's reputation online, we treat the reputation value in our system as a private issue that has been carefully guaranteed. Linke Guo, Xiaoyan Zhu 0005, Chi Zhang 0001, Yuguang Fang |
GLOBECOM | 1 |