Yuwei Xu 0001

dblp:05/9079-1 · DBLP profile ↗
← Back
35ranked-venue papers
23as first author
34since 2021 · last 2026
0000-0002-1611-9167ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 12 first-author · 17 since 2021Systems, architecture and hardware · 10 · 6 first-author · 10 since 2021Computer networks · 7 · 5 first-author · 7 since 2021
YearPublicationVenuePosition
2026 ByteDance: Let bytes perform brilliantly in multi-view encrypted traffic classification
Yuwei Xu 0001, Zhiyuan Liang, Xiaotian Fang, Kehui Song, Qiao Xiang, Guang Cheng 0001
Comput. Networks1
2026 PacketPatch: Practical generation and deployment of adversarial packets for byte-feature-based encrypted traffic classification
Yuwei Xu 0001, Yunpeng Bai, Kehui Song, Jie Cao 0009, Qiao Xiang, Guang Cheng 0001
Comput. Secur.1
2025 Rebel: A Cross-Chain Data Audit Scheme Based on Reputation Model to Defend Against Malicious Nodes
Hailang Cai, Yuwei Xu 0001, Qiao Xiang, Jingdong Xu, Guang Cheng 0001
ICA3PP (7)2
2025 PacketMorph: Generation of Recoverable Adversarial Packets Against Encrypted Traffic Classification via Class-Wise Universal Perturbation
Yuwei Xu 0001, Yunpeng Bai, Jie Cao 0009, Kehui Song, Guang Cheng 0001
ICA3PP (4)2
2025 CoDA: Cross-Domain Few-Shot Website Fingerprinting via Contrastive Prototype Alignment
abstract
Tor is widely used to facilitate anonymous web communication, but it remains vulnerable to Website Fingerprinting (WF) attacks. Although deep learning-based WF attacks have shown promising results, they typically rely on large-scale labeled data and assume consistent conditions between training and deployment. These assumptions limit their practical applicability in real-world scenarios, where data scarcity and domain shifts are common. To address these challenges, recent research has focused on Cross-Domain Few-Shot Website Fingerprinting (CDFSWF), a more realistic yet challenging setting. Existing efforts mainly leverage data augmentation or feature alignment techniques. While data augmentation can mitigate sample scarcity, it often fails to capture true distributional variability. In contrast, many feature alignment WF methods overlook the semantic structure of class relationships, reducing their effectiveness in the target domain. In this paper, we propose CoDA, a novel method designed to improve cross-domain robustness in CDFSWF. CoDA integrates supervised contrastive pre-training, hierarchical flow attention, and prototype-based classification to effectively model semantic traffic structures under domain shifts. Furthermore, a Dual Confidence Alignment (DCA) strategy is introduced during fine-tuning to adaptively align semantic structures. Extensive experiments across various cross-domain scenarios show that CoDA consistently outperforms state-of-the-art baselines in both closed-world and open-world settings.
Yuwei Xu 0001, Xinhe Fan, Yujie Hou, Yali Yuan, Qiao Xiang, Guang Cheng 0001
TrustCom2
2025 FastDCV: An efficient cross-chain data consistency verification scheme supporting batch processing
Yuwei Xu 0001, Junyu Zeng, Shengjiang Dai, Qiao Xiang, Jun Tao 0003, Guang Cheng 0001
Peer Peer Netw. Appl.1
2024 BlockWhisper: A Blockchain-Based Hybrid Covert Communication Scheme with Strong Ability to Evade Detection
Zehui Wu, Yuwei Xu 0001, Ranfeng Huang, Xinhe Fan, Jingdong Xu, Guang Cheng 0001
ICA3PP (1)2
2024 ZKCross: An Efficient and Reliable Cross-Chain Authentication Scheme Based on Lightweight Attribute-Based Zero-Knowledge Proof
Yuwei Xu 0001, Hailang Cai, Qiao Xiang, Jingdong Xu, Guang Cheng 0001
ICA3PP (6)1
2024 ChainSafari: A General and Efficient Blockchain Verifiable Query Scheme with Real-Time Synchronization
Yuwei Xu 0001, Shengjiang Dai, Junyu Zeng, Jie Cao 0009, Ran He 0003, Qiao Xiang
ICA3PP (3)1
2024 DataJudge: Cross-Chain Data Consistency Verification Based on Extended Merkle Hash Tree
Yuwei Xu 0001, Junyu Zeng, Jie Cao 0009, Shengjiang Dai, Qiao Xiang, Guang Cheng 0001
ICA3PP (3)1
2024 TorHunter: A Lightweight Method for Efficient Identification of Obfuscated Tor Traffic Through Unsupervised Pre-training
Yuwei Xu 0001, Zhengxin Xu, Jie Cao 0009, Yali Yuan, Guang Cheng 0001
ICICS (2)1
2024 NuanceTracker: A Website Fingerprinting Attack against Tor Hidden Services through Burst patterns
abstract
Hidden services (HS) allow users to experience anonymity, but they also provide shelter for criminal activities. The widespread attention towards deanonymizing HS has brought website fingerprinting attack (WFA) into the spotlight, which is considered highly promising. However, most HS websites are designed simply and have high similarity in resource structures, making it difficult to represent the HS access traffic well, and existing work often directly applies traffic representation methods in the field of web research, resulting in poor effects of the model. Besides, features of HS access traffic are closely related to the resource access sequence of websites. Current studies build models based on convolutional neural network (CNN), ignoring the global correlation of HS access traffic parts. To address the short-comings, we have proposed an efficient WFA to deanonymize HS, and named it NuanceTracker. The contribution of our work lies in three points. Firstly, a burst-based HS fingerprint generation algorithm is proposed to describe the sequence of HS access traffic. Secondly, we propose NuanceTracker, which is designed by introducing multi-scale global attention (MGA) into a basic CNN model for global information extraction. Finally, comparison experiments are conducted in closed-world and open-world scenarios. Our NuanceTracker has proven to outperform three state-of-the-art WFA methods.
Yuwei Xu 0001, Yujie Hou, Kehui Song, Guang Cheng 0001
ISCC1
2024 Dual-view Traffic Identification for Open Source Proxy Software through Early Flows
abstract
Open Source Proxy Software (OSPS) provides privacy protection for users accessing the Internet by constructing a private anonymizing network. However, there is a growing concern about whether OSPS can actually prevent privacy leaks as it claims. Researchers have attempted to use AI-based techniques to identify OSPS, but there are two shortcomings in the current studies. First, there is no complete public dataset to support the identification tasks for different requirements. The existing datasets do not cover the most commonly used OSPS tools and their typical configurations. Second, with the introduction of deep learning techniques, the models continue to become complex, resulting in significant computational overhead. Using early flows for identification may make the model lighter, but result in weaker representations and lower classification performance. To address the above shortcomings, we have carried out pioneering work on OSPS traffic identification through early flows. First, we collect the access traffic of three OSPS tools and create a dataset with 8 protocol configurations. Second, we present an innovative Dual-View Identification (DVI) method for OSPS traffic. By considering both static and dynamic views, DVI effectively characterizes early flows and achieves accurate classification through feature fusion. In the static view, spatial distribution features are extracted by representing the early flows as a grayscale picture. In the dynamic view, spatial features and temporal correlations are represented using a flow with multiple packets, similar to a video with multiple frames. Comparative experiments show that DVI achieves over 90% accuracy and F1 scores in all three tasks, which greatly improves its ability to identify different protocol configurations and access sites. Besides, DVI outperforms 5 state-of-the-art methods and achieves low parameters and FLOPS through early flows.
Yuwei Xu 0001, Yunpeng Bai, Yuquan Zhang, Yige Song, Qiao Xiang, Guang Cheng 0001
ISPA1
2024 Tarnhelm: Using Adversarial Samples to Protect User Privacy Against Traffic Identification
Yuwei Xu 0001, Yunpeng Bai, Jie Cao 0009, Liang He 0002, Guang Cheng 0001
SecureComm (3)1
2024 FullView: Using Bidirectional Group Sequences to Achieve Accurate Encrypted Traffic Classification
Yuwei Xu 0001, Zhiyuan Liang, Zhengxin Xu, Kehui Song, Qiao Xiang, Guang Cheng 0001
SecureComm (2)1
2024 OnionPeeler: A Novel Input-Enriched Website Fingerprinting Attack on Tor Onion Services
Zhengxin Xu, Jie Cao 0009, Yujie Hou, Yuwei Xu 0001, Guang Cheng 0001
SecureComm (3)4
2024 M-ETC: Improving Multi-Task Encrypted Traffic Classification by Reducing Inter-Task Interference
abstract
With the rapid evolution of deep learning (DL), its integration in encrypted traffic classification (ETC) can automatically extract key features from raw traffic data, enhancing classification performance. So far, researchers have proposed many DL-based models for ETC. However, the complexity and dynamism of network applications lead to the diversification of ETC tasks. Current models, mostly tailored for single tasks, overlook real-world multi-tasking needs of network devices. Deploying task-specific complex models concurrently on resource-limited devices is impractical. In response to the increasing number of tasks, researchers have introduced multi-task learning frameworks for ETC, demonstrating its potential as a promising technical approach. However, current research overlooks the interference between tasks, resulting in flawed models when it comes to sharing parameters, setting learning rates, and determining loss values. Aiming at these deficiencies, we propose $\mathcal{M}$-ETC, a multi-task ETC method reducing inter-task interference. The innovation of $\mathcal{M}$-ETC lies in two aspects. Firstly, we design a hierarchical multi-task learning model (HMLM) to provide effective features for each task and prevent the impact of invalid features. Secondly, we propose a learning rate balancing strategy (LRB) for modules and a dynamic weight average strategy (DWA) for tasks’ loss values. During model training, LRB prevents overfitting and underfitting of tasks, while DWA prevents bias towards tasks with large loss values. To validate $\mathcal{M}$-ETC, we carry out comparative experiments using four encrypted traffic datasets. The experimental results show that the classification performance of $\mathcal{M}$-ETC on multiple tasks exceeds those of five state-of-the-art methods.
Yuwei Xu 0001, Xiaotian Fang, Zhengxin Xu, Kehui Song, Yali Yuan, Guang Cheng 0001
TrustCom1
2024 TriViewNet: Achieve Accurate Tor Hidden Service Classification by Multi-View Feature Extraction and Fusion
abstract
Tor has provided hidden services (HS) and protected the anonymity of the Web server with hidden service directory servers. Some criminals use hidden services to engage in illegal activities, such as anonymous transactions, pirated distribution, hacking, etc. In order to protect the security of cyberspace, hidden service traffic needs to be deanonymized. Artificial intelligence-based methods have become the most promising, but there are still two shortcomings in current research work. First, some of them mainly uses the size and direction sequence of the data packet as the input to complete the recognition, without mining the features of network traffic from many views. Second, they extract information from different view, but just concatenate them together instead of fuse them densely. Therefore, in this paper we propose a Tor hidden service traffic identification method with multi views named TriViewNet. TriViewNet extracts information from three different views, local flow, TLS layer, and TCP layer for identification ad fuses them with Tri-attention module. By comparing with state-of-the-art models, the results show that our TriViewNet outperforms in the recognition of Tor HS traffic.
Yuwei Xu 0001, Yujie Hou, Xinxu Huang, Yali Yuan, Guang Cheng 0001
TrustCom1
2024 A High-Accuracy Unknown Traffic Identification Method Based on Multi-View Contrastive Learning
abstract
The technology for AI-based encrypted traffic classification (ETC) is advancing rapidly. However, many current studies are conducted in closed network environments where traffic is classified into pre-determined classes. In the actual network environment, new traffic is constantly emerging, making anomaly detection of unknown traffic a pressing issue. The current research attempts different approaches for unknown traffic identification (UTI) from the perspective of model construction, including UTI based on n-classification, UTI based on multiple 2-classifiction, and UTI baed on (n+1)-classification. The above three approaches mentioned are prone to misclassification and have low accuracy due to issues with threshold setting, poor generalization of binary classifiers, and low credibility of generated samples. Researchers have used contrastive learning (CL) for UTI because of its strengths in feature representation. However, there are two shortcomings in the current studies. First, the feature representation of a single view cannot fully capture different classes of traffic features. Second, the existing CL schemes distinguish whether they belong to the same category by constructing pairs of positive and negative samples, but they are still unable to distinguish between known classes and unknown classes in the feature space, resulting in low accuracy. To address the above shortcomings, we propose UTI-MCL, an unknown traffic identification method using multi-view contrastive learning. Firstly, in terms of feature expression, we extract the packet length sequence and the packet byte sequence respectively to learn a more comprehensive feature representation. Secondly, in terms of model construction, we introduce an anchor and compare the distance with both positive and negative samples to help the model better separate different classes in the feature space, enhancing feature distinction. Furthermore, the distance between samples is optimized through the adaptive weights triplet loss function to balance samples from different classes. A series of experiments have proved the effectiveness of UTI-MCL. Even with unknown traffic accounting for 60%, the Fβ-Score can still exceed 94%.
Yuwei Xu 0001, Zizhi Zhu, Chufan Zhang, Kehui Song, Guang Cheng 0001
TrustCom1
2024 Perturbing Vulnerable Bytes in Packets to Generate Adversarial Samples Resisting DNN-Based Traffic Monitoring
abstract
Leveraging the advanced capabilities of Deep Neural Networks (DNNs), attackers can precisely detect users' online activities through traffic monitoring, nullifying the efficacy of current encrypted communication tools/protocols and progressively resulting in privacy leakage. Several defensive methods against DNN-based traffic monitoring (DTM) have been proposed; however, these methods often rely excessively on prior knowledge and incur inevitable additional bandwidth overhead (BWO). Moreover, they frequently generate invalid packets that violate network transmission constraints. To address these drawbacks, in this paper, we propose BYTEFLIPPING, a byte-space grey-box defensive method, which perturbs vulnerable bytes in the transport layer payload to generate adversarial sample packets. We design a Payload Byte Vulnerability Ranking algorithm to pinpoint the most vulnerable bytes and based on this generate adversarial packets to defend DTM. Extensive experiments reveal that ByteFLIPPING performs well in protecting against three DTM methods across two benchmark datasets, significantly decreasing the accuracy of the state-of-the-art ET-BERT by 94%. Compared to baseline defensive methods, BYTEFLIPPING incurs no extra BWO, offers more dependable packet validity, and boasts greater feasibility.
Jie Cao 0009, Zhengxin Xu, Yunpeng Bai, Yuwei Xu 0001, Qiao Xiang, Guang Cheng 0001
TrustCom4
2024 WCDGA: BERT-Based and Character-Transforming Adversarial DGA with High Anti-Detection Ability
abstract
Domain Generation Algorithms (DGAs) are essential for creating numerous domain names automatically, commonly used to make malicious domains more stealthy and persistent online. To counteract DGAs, deep learning-based detection methods have been proposed, significantly reducing the effectiveness of traditional DGAs. However, due to inherent vulnerabilities in deep learning models, these detection methods are susceptible to adversarial attacks. Existing adversarial DGAs focus on character-based detection methods but overlook word-based structures, leading to weak performance against advanced word-based detection methods like graph neural networks. In this paper, we propose an innovative adversarial method and name it Word-Character DGA (WCDGA). The main idea is to create domain names by combining high-frequency words with common prefixes and suffixes found in reputable domains. This process utilizes a bidirectional encoder (BERT) and implements character transformations based on edit distance. We evaluate WCDGA against established character-based DGA detection methods (LSTM.MI, MIT, NYU) and the latest word-based method DGGCN. The results demonstrate that WCDGA out-performs existing adversarial DGAs in its evasion capabilities, successfully bypassing multiple detection methods simultaneously. Index Terms—Domain generation algorithm, Anti-detection, Dictionary generation, Character transformation
Zhujie Guan, Mengmeng Tian, Yuwei Xu 0001, Kehui Song, Guang Cheng 0001
TrustCom3
2024 GateKeeper: An UltraLite malicious traffic identification method with dual-aspect optimization strategies on IoT gateways
Jie Cao 0009, Yuwei Xu 0001, Enze Yu, Qiao Xiang, Kehui Song, Liang He 0002, Guang Cheng 0001
Comput. Networks2
2023 $\mathcal{L}{-}$ ETC: A Lightweight Model Based on Key Bytes Selection for Encrypted Traffic Classification
abstract
To protect the confidentiality of communication data, internet users often use encryption protocols (e.g., TLS/SSL) or tools (e.g., VPN, Tor) for network access. Therefore, as a pivotal network management method, encrypted traffic classification technology is vital for guaranteeing the quality of service, the quality of experience, and network security. Researchers have already developed some end-to-end deep learning-based methods to realize encrypted traffic classification. However, given the constrained computational resources available in real-world network measurement scenarios, the existing approaches with high complexity and computation overhead are not appropriate. In this paper, we propose a lightweight model to tackle this issue. Firstly, we propose a base model based on the self-attention mechanism to obtain the key bytes in packets contributing to the classification. Secondly, we leverage these key bytes to reconstruct the input and then streamline the base model, carrying out a lightweight model, i.e.,$\mathcal{L}{-}$ETC. Finally, we implement experiments on three benchmark datasets.$\mathcal{L}-\mathbf{ETC}^{\prime}\mathrm{s}$macro Fl score of the three tasks exceeds 0.92 with only 0.076M (Million) parameters, and the throughput reaches 917 pps, which is also superior to state-of-the-art methods.
Jie Cao 0009, Yuwei Xu 0001, Qiao Xiang
ICC2
2023 Zoomer: A Website Fingerprinting Attack Against Tor Hidden Services
Yuwei Xu 0001, Kehui Song, Yali Yuan
ICICS1
2023 SCOPE: A Cross-Chain Supervision Scheme for Consortium Blockchains
Yuwei Xu 0001, Junyu Zeng
ICICS1
2023 S-chain: A Shard-based Blockchain Scheme for Cross-chain Supervision
abstract
With the popularization of consortium blockchain, how to supervise numerous business chains has become a problem. Recently, some researchers have proposed the concept of ‘governing chain by chain’, which means that multiple organizations deploy a consortium blockchain to supervise many business chains in the industry. However, as the number of business chains increases, a performance bottleneck occurs on the supervision chain. Sharding is a promising direction to improve scalability, but existing studies focus on public chains. If transplanted to the supervision chain, these solutions will bring two challenges. Firstly, data from multiple business chains will cause storage conflicts and unbalanced sharding. Secondly, sharding makes it difficult for inter-shard transaction validation. Aiming at the challenges, we propose $\mathcal{S}$-chain, a shard-based supervision chain scheme. The contribution of our work lies in three points. Firstly, we design a unified label-based data sharding method that can evenly map data from different business chains to all shards without conflict. Secondly, we propose a mechanism to validate general smart-contract-based inter-shard transactions. At first, we design a smart contract splitting algorithm that splits one inter-shard smart contract into multiple sub-contracts and depicts their dependencies via a Directed Acyclic Graph(DAG). Then, we design an inter-shard transaction validation method by analyzing the dependencies of all sub-contracts. Finally, we implement a prototype system of $\mathcal{S}$-chain and test its performance. The results show that our $\mathcal{S}$-chain outperforms the scheme without sharding on throughput and storage overhead.
Yuwei Xu 0001, Yuxing Song, Junyu Zeng, Ran He 0003, Jingdong Xu
ICPADS1
2023 DarkTrans: A Blockchain-based Covert Communication Scheme with High Channel Capacity and Strong Concealment
abstract
Covert communication technology serves as a crucial tool for safeguarding not only the content of communication but also the identities of the parties involved. In this regard, blockchain emerges as a promising solution due to its decentralized nature, flood propagation of data, and inherent anonymity features. This makes blockchain an ideal candidate for covert communication channels, effectively addressing the weaknesses associated with traditional covert communication methods susceptible to detection, tracing, and interruption. However, the current efforts encounter obstacles like limited practicality, constrained channel capacity, and insufficient concealment capabilities, impeding their broad adoption in real-world scenarios. To address these issues, we propose DarkTrans, a blockchain-based covert communication scheme consisting of an address binary tree and a novel embedding mechanism. The address binary tree as a dynamic label method enables rapid recognition of specific transactions by the recipient, rendering detection by third parties challenging. The embedding mechanism encodes secret messages into transaction values for transmission to augment channel capacity, which can be practically realized within an Ethereum private blockchain. Our experiments with three aspects demonstrate that, compared with the existing scheme, DarkTrans achieves a low embedding time and a high channel capacity. Additionally, Kolmogorov-Smirnov test and sample entropy analysis are conducted to validate the robust concealment of this scheme.
Yuwei Xu 0001, Zehui Wu, Jie Cao 0009, Jingdong Xu, Guang Cheng 0001
ICPADS1
2023 Cerberus: Efficient OSPS Traffic Identification through Multi-Task Learning
abstract
The privacy protection capabilities of open source proxy software (OSPS) while browsing the Internet have sparked great interest from both industry and academia, bringing forth pressing security concerns. Currently, using artificial intelligence for traffic identification is the most promising direction. Due to the wide variety and rich configuration of OSPS, it is not feasible to train models for all tasks and deploy them on the same network device. It is a novel idea to improve efficiency by leveraging multi-task learning. However, the related studies still have three shortcomings. First, improving the performance of the main task through auxiliary tasks does not apply to equally important OSPS identification tasks. Second, the model’s ability to characterize traffic is weak, resulting in performance gaps between different tasks. Finally, the influence of task difficulty on convergence speed is ignored, which is easy to cause overfitting and underfitting. Aiming at the shortcomings, we propose Cerberus, an OSPS traffic identification scheme based on multi-task learning. The main contributions of our work can be summarized in three aspects. Firstly, a high-quality dataset is constructed through traffic collection, and three OSPS traffic identification tasks are defined on it. Secondly, an identification model is designed by optimizing the ability to characterize traffic and balancing the convergence speed of multiple tasks. Finally, Cerberus is verified through comparative experiments. Its classification performance is better than both single-task and multi-task solutions. Besides, Cerberus runs fast and consumes few resources, making it suitable for deployment on network devices.
Yuwei Xu 0001, Xiaotian Fang, Jie Cao 0009, Rou Yu, Kehui Song, Guang Cheng 0001
TrustCom1
2023 SharpEye: Identify mKCP Camouflage Traffic through Feature Optimization
abstract
As a new self-developed protocol of V2Ray, mKCP disguises users’ network access as communication of four network applications by forging application layer headers to evade traffic-based detection. The emergence of mKCP has received widespread attention. Whether mKCP can provide secure network access that protects user privacy is the focus. Traditional methods cannot identify mKCP camouflage traffic, but machine learning (ML)-based traffic identification is considered a promising direction. Unlike the previous network traffic classification, mKCP camouflage traffic identification introduces new challenges. First, existing work has neither published any dataset containing mKCP camouflage traffic nor designed specific traffic features. Second, no researchers have optimized the identification scheme for deployment on network devices. Aiming at the shortcomings, we propose SharpEye, an ML-based mKCP camouflage traffic identification scheme. The novelty of our work lies in three points. Firstly, a complete dataset containing mKCP camouflage traffic is constructed through long-term traffic collection. Secondly, by analyzing the communication patterns of mKCP traffic, a feature set mFS is designed to improve identification accuracy. Finally, a two-stage feature selection method mGBFS is proposed to improve the operation efficiency. The experimental results show that mFS can enhance the performance of classifiers in identifying mKCP camouflage traffic, and mGBFS reduces the running time and overhead while ensuring high accuracy. Therefore, SharpEye achieves accurate and efficient mKCP camouflage traffic identification.
Yuwei Xu 0001, Zizhi Zhu, Yunpeng Bai, Lilanyi Wu, Kehui Song, Guang Cheng 0001
TrustCom1
2023 ChainPass: A Privacy-preserving Complete Cross-chain Authentication for Consortium Blockchains
abstract
Consortium blockchains have been widely used in many industries such as medical care, finance, and so on. The business data on different blockchains are isolated from each other. In order to share the value data, it is necessary to achieve cross-chain access. Existing cross-chain technologies are mainly aimed at public blockchains, while consortium blockchain users hold identity credentials to participate in transactions, which has higher security requirements. In addition, most of the existing consortium blockchains use pluggable cryptography components. If all consortium blockchains participating in the cross-chain are required to be configured with the same cryptosystem, the cost will be too high. To solve the above privacy protection and compatibility issues, we propose a privacy-preserving complete cross-chain authentication scheme and name it ChainPass. Chain-Pass introduces paillier homomorphic encryption and pseudonym technologies, allowing users to use the original cryptosystem to generate public and private keys and participate in cross-chain transactions. At the same time, the user’s pseudonym is updated according to the user’s public key. ChainPass protects users’ privacy while ensuring complete compatibility. Security analysis and performance evaluation prove that ChainPass has better security and higher efficiency.
Yuwei Xu 0001, Jie Cao 0009
TrustCom1
2023 FastTraffic: A lightweight method for encrypted traffic fast classification
Yuwei Xu 0001, Jie Cao 0009, Kehui Song, Qiao Xiang, Guang Cheng 0001
Comput. Networks1
2023 Corrigendum to "FastTraffic: A lightweight method for encrypted traffic fast classification" [Computer Networks, Volume 235, November 2023, 109965]
Yuwei Xu 0001, Jie Cao 0009, Kehui Song, Qiao Xiang, Guang Cheng 0001
Comput. Networks1
2022 A Lightweight Authentication Scheme Based on Consortium Blockchain for Cross-Domain IoT
abstract
Internet of Things (IoT) has been ubiquitous in both industrial and living areas, but also known for its weak security. Being as the first defense line against various cyberattacks, authentication is even more critical to IoT applications. Moreover, there has been a growing demand for cross-domain collaboration, leading to an increasing need for cross-domain authentication. Recently, certificate-based authentication schemes have been extensively studied. However, many of these schemes are not efficient in computation, storage, and communication, which are highly required in IoT. In this paper, we propose a lightweight authentication scheme based on consortium blockchain and design a cryptocurrency-like digital token to build trust. Furthermore, trust lifecycle management is performed by manipulating the amount of tokens. The comprehensive analysis and evaluation demonstrate that the proposed scheme is resistant to various common attacks and more efficient than competitor schemes in terms of storage, communication, and authentication cost.
Yujian Zhang, Xing Chen 0021, Fei Tong 0001, Yuwei Xu 0001, Jun Tao 0003, Guang Cheng 0001
Secur. Commun. Networks5
2021 A variable neighborhood search algorithm for energy conscious task scheduling in heterogeneous computing systems
abstract
Summary Energy efficiency in heterogeneous computing systems has attracted increasing interests due to its economic and environmental impacts during recent decades. Based on power‐aware hardware techniques, such as dynamic voltage frequency scaling, efforts have been made through task scheduling to reduce the total energy consumption for executing a parallel application while maintaining its time efficiency. In this case, energy conscious task scheduling refers to a bi‐objective optimization that aims to minimize the overall completion time (makespan) and the total energy consumption, simultaneously. Existing energy conscious scheduling algorithms conduct energy optimization by means of slack reclamation or a trade‐off function. However, the performance of slack reclamation has been proved to be upper‐bounded and methods relying on trade‐off functions cannot guarantee bi‐objective optimization. In this article, an energy conscious task scheduling algorithm is proposed to tackle the above issues based on the framework of variable neighborhood search. Two neighborhood structures are designed to reduce makespan and the total energy consumption, respectively. Furthermore, a pruning technique is incorporated into the algorithm to accelerate the searching process. Extensive experimental results on both randomly generated and real‐world applications demonstrate that the proposed algorithm improves the time‐efficient schedules on average by 22.4% for the energy consumption and 1.2% for the makespan.
Yujian Zhang, Chuanyou Li, Fei Tong 0001, Yuwei Xu 0001
Concurr. Comput. Pract. Exp.4
2020 A Privacy-Preserving Authentication Scheme for VANETs based on Consortium Blockchain
abstract
The authentication protocol is commonly served as the first defense line against various attacks in vehicular ad hoc networks (VANETs). Conventional schemes usually employ public key infrastructure or cryptography-based algorithms, which suffer from high computational and storage cost. In this paper, we propose a privacy-preserving authentication scheme for VANETs based on consortium blockchain. The authenticity of a vehicle or a road-side unit is represented by its transaction capability on blockchain instead of a certificate or a cryptographic key. In support of that, we design a novel data structure based on the unspent transaction output (UTXO) combined with a set of online operations, including issue, transfer, query and revocation. Thus, the authentication between two entities is accomplished by on-chain verification and corresponding communications. We conduct a set of security and privacy analysis as well as implementing a prototype on the Hyperledger Fabric platform, to evaluate the effectiveness and the efficiency of the proposed scheme.
Yujian Zhang, Fei Tong 0001, Yuwei Xu 0001, Jun Tao 0003, Guang Cheng 0001
VTC Fall3