Li Yang 0005

dblp:09/3925-5 · DBLP profile ↗
← Back
46ranked-venue papers
13as first author
30since 2021 · last 2026
0000-0003-2750-7031ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 5 first-author · 10 since 2021Security and privacy · 15 · 4 first-author · 9 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ProvGuard: Logic-Aware Multi-View Contrastive Learning for Robust and Efficient Host Threat Detection
abstract
The security of web services increasingly relies on accurate detection of advanced, previously unseen attacks hidden within complex host activities. Provenance-based intrusion detection systems (PIDSes) offer a promising foundation for this task by capturing rich causal and structural relationships across processes, files, and network interactions. However, recent studies show that these graph-driven methods remain vulnerable to graph manipulation attacks, where adversaries subtly alter provenance graphs to evade detection, which limits their practical deployment.
Anyuan Sang, Li Yang 0005, Junbo Jia, Huipeng Yang
WWW2
2026 WebGeoInfer: Structure-Free Multi-Stage Framework for Geolocation Inference from Exposed Device Web Interfaces
abstract
While the web interfaces of remotely managed devices offer convenience, their unstructured content can inadvertently leak geographic locations, posing a significant security risk. We aim to assess the feasibility of automatically exploiting this leakage, serving as a clear warning to cybersecurity regulators. To this end, we propose WebGeoInfer, a framework that does not rely on page structure. It extracts clues through page clustering and differential analysis to overcome the challenge of information heterogeneity. It also leverages search engines and large language models to augment sparse clues and infer precise coordinates, addressing the challenge of information sparsity. In large-scale experiments, WebGeoInfer successfully located 5,435 devices across 94 countries and 2,056 cities, achieving accuracy rates as high as 96.96% at the country level, 88.05% at the city level, and 79.70% at the street level. These findings provide the first conclusive evidence of the reality and scale of this threat. Furthermore, our analysis offers new insights and mitigation strategies for affected devices, establishing a key benchmark for future security research.
Huipeng Yang, Li Yang 0005, Lichuan Ma, Junbo Jia, Anyuan Sang
WWW2
2026 CPFL: Lightweight Communication-Efficient and Privacy-Preserving Federated Learning
abstract
The combination of Deep Learning (DL) and Federated Learning (FL) makes it a popular paradigm to train powerful models securely on large-scale data in a distributed way. However, current solutions face challenges such as significant communication overheads for clients with limited resources, potential privacy risks arising from FL's distributed nature, and the inability to maintain model accuracy without loss under high compression ratios. To solve these issues, we propose a lightweight Communication-efficient and Privacy-preserving FL scheme CPFL by designing Cyclic Segmented Compressive Sensing (CSCS) and using efficient Symmetric Homomorphic Encryption (SHE), which greatly reduces the number of transmitted model weights without sacrificing model accuracy. Formal analysis shows the security of CPFL against known-plaintext attacks and ensures model convergence. Extensive experiments demonstrate that CPFL achieves remarkable model accuracy under more than 200× compression ratio, and even reduces the communication cost by 99.5% compared with previous solutions.
Li Yang 0005, Yinbin Miao, Rongpeng Xie, Xinghua Li 0001, Ju Wu, Guowen Xu, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.1
2025 Publicly Verifiable and Fault-Tolerant Privacy-Preserving Aggregation for Federated Learning
abstract
Publicly verifiable privacy-preserving aggregation is widely regarded as an effective approach to protect user privacy and ensure the integrity of the aggregated model published by the aggregator in Federated Learning (FL). State-of-the-art solutions either fail to guarantee unforgeability when the aggregator colludes with malicious users or require costly cryptographic operations during the online aggregation phase and lack fault tolerance. In this work, we propose eVTPA, the first online-efficient, publicly verifiable, and fault-tolerant privacy-preserving aggregation protocol considering malicious users and aggregators for FL. We introduce a novel collusion-resistant symmetric masking technique to conceal users' local gradients while ensuring the correctness of the aggregated model through a publicly verifiable aggregation signature algorithm. To improve the efficiency of online signature generation, we design a specialized precomputation-based acceleration method and leverage the randomness of masking to enable batch processing. Furthermore, eVTPA adopts a dynamic mask update mechanism that tolerates user dropouts without affecting the validation of the aggregated model. Security analysis shows that eVTPA meets FL's confidentiality, integrity, and authenticity requirements. Experimental results demonstrate that our scheme maintains model classification accuracy while achieving at least a 7.85× faster online aggregation than related solutions at the same security level.
Guohao Li 0004, Qi Jiang 0001, Li Yang 0005
CIKM4
2025 LLM-Pot: A High-Interaction Honeypot System Driven by Large Language Model
abstract
Honeypots are commonly used tools in network security protection. However, low-interaction honeypots cannot obtain in-depth attack information, while the deployment of high-interaction honeypots is costly. This paper presents LLM-Pot, a novel high-interaction honeypot architecture powered by the Large Language Model (LLM), which explores the direction of intelligent honeypots and addresses the limitations of conventional honeypot solutions. LLM-Pot utilizes LLM to generate dynamic, context-aware responses that accurately simulate the behaviors of real operating systems. To demonstrate the effectiveness of LLM-Pot, this work used offline and online evaluations. The offline evaluation compared LLM-Pot and Cowrie by analyzing their responses to selected commands, and the results demonstrated LLM-Pot’s superior ability in handling complex operations. Online evaluation deployed honeypots in the cloud and captured extensive attack data over two weeks. The evaluation results demonstrate that our LLM-driven approach outperforms traditional honeypots across multiple key metrics, validating LLM-Pot’s superior deception capabilities.
Xuan Lyu, Pengbin Feng, Ning Xi 0002, XinDi Ma, Li Yang 0005, Di Lu 0001, Jianfeng Ma 0001
GLOBECOM5
2025 Embedding More Knowledge: Strategic Graph Masking Based Advanced Persistent Threats Detection
abstract
Advanced Persistent Threats (APTs) have become increasingly frequent, presenting substantial challenges to the management of network services. Using provenance graphs for log analysis has become a common approach in APT detection. However, existing research has two shortcomings: it does not fully utilize richer contextual semantic information and fails to effectively respond to unknown attacks. This paper presents SGAM, an accurate and fast APT detection framework. SGAM enhances accuracy through a training process driven by a masking strategy. The masking strategy includes the selection of masked nodes and a more robust training approach. SGAM incorporates the importance of provenance graph nodes into the masking strategy, gradually increasing the significance of the masked information during training, allowing the model to learn more critical node features. This enables the model to extract deeper contextual semantic information. In anomaly detection, SGAM employs an unsupervised method to ensure effective detection of unknown attacks while improving detection efficiency. We evaluated SGAM on three widely used datasets, and the results indicate that SGAM demonstrates outstanding detection performance across all scenarios, outperforming existing methods. Additionally, experiments show that SGAM can mitigate the impact of concept drift to some extent.
Junbo Jia, Li Yang 0005, Anyuan Sang, Huipeng Yang
IWQoS2
2025 Remote Management Device Identification Based on Multimodal Feature Fusion
abstract
To achieve high-performance identification for remote management device, this paper proposes MME4RMD, a novel BERT-ResNet-based multi-modal embedding model that integrates visual, textual, and HTML structural features to generate distinctive device embedding. By employing triplet network training, our method significantly enhances feature discrimination and generalization capability for cluster-based identification. Comprehensive evaluations on manually curated real-world datasets containing 25 known and 20 unknown device classes demonstrate superior performance, achieving 98% and 93% F1-scores for known and unknown device identification respectively, substantially outperforming conventional approaches.
Huipeng Yang, Li Yang 0005, Junbo Jia, Anyuan Sang, Wenjie Sha
IWQoS2
2025 Content-Independent Avatar Ownership Detection for Preventing Sockpuppet-Enabled Violations in the Social Metaverse
Jiangyu Wang, Guohao Li 0004, Li Yang 0005, Haixin Ye
UIST4
2025 STGAN: Detecting Host Threats via Fusion of Spatial-Temporal Features in Host Provenance Graphs
abstract
As the complexity and frequency of cyberattacks, such as Advanced Persistent Threats (APTs) and ransomware, continue to escalate, traditional anomaly detection methods have proven inadequate in addressing these sophisticated, multi-faceted threats. Recently, Host Provenance Graphs (HPGs) have played a crucial role in analyzing system-level interactions, detecting anomalous behaviors, and tracing attack chains. However, existing provenance-based detection methods primarily rely on single-dimensional feature analysis, which fails to capture the dynamic and multi-dimensional patterns of modern APT attacks, resulting in insufficient detection performance. To overcome this limitation, we introduce STGAN, a model that integrates spatial-temporal graphs into host provenance graph modeling. STGAN applies temporal and spatial encoding to dynamic provenance graphs to extract temporal, spatial, and semantic features, constructing a comprehensive feature representation. This representation is further fused and enhanced using a multi-head self-attention mechanism, followed by anomaly detection. Through extensive evaluations on three widely-used provenance graph datasets, we demonstrate that our approach consistently outperforms current state-of-the-art techniques in terms of detection performance. Additionally, we contribute to the research community by releasing our datasets and code, facilitating further exploration and validation.
Anyuan Sang, Xuezheng Fan, Li Yang 0005, Junbo Jia, Huipeng Yang
WWW3
2025 Hyper attack graph: Constructing a hypergraph for cyber threat intelligence analysis
abstract
Cybersecurity experts are actively exploring and implementing automated technologies to extract and present attack information from Cyber Threat Intelligence . However, there are multiple relations among security entities within Cyber Threat Intelligence, a feature that existing technologies often overlook. Additionally, integrating external security knowledge into cyber threat intelligence intuitively during analysis and presentation poses challenges. We propose the Hyper Attack Graph (HAG) framework, the first work to apply hypergraph data structures in the analysis of cyber threat intelligence. Our approach uses a joint extraction model that incorporates a multi-head selection mechanism, effectively addressing the extraction of multiple relations among security entities. We use hypergraph to display tactics and techniques in cyber threat intelligence. Our evaluation of the HAG framework on 685 real-world cyber threat intelligence reports shows an increase in the F1 score for security entity extraction by 11.12% and for relation extraction by 6.71% over existing efforts. Furthermore, HAG’s ability to visually represent external security knowledge on hypergraphs demonstrates its potential as a valuable tool in cybersecurity analysis.
Junbo Jia, Li Yang 0005, Anyuan Sang
Comput. Secur.2
2025 Efficient and Secure Content-Based Image Retrieval in Cloud-Assisted Internet of Things
abstract
With the rapid growth of encrypted image data outsourced to cloud servers, achieving data confidentiality and searchability in cloud-assisted Internet of Things (IoT) environments has become increasingly feasible. However, achieving high efficiency and strong security simultaneously over large-scale encrypted image datasets remains a challenge. To address this, we propose a novel efficient and secure content-based image retrieval scheme in cloud-assisted IoT. Specifically, our scheme leverages lattice-based fully homomorphic encryption and homomorphic comparison techniques, utilizing Cheon-Kim–Kim-Song’s batch processing and single-instruction-multiple-data capabilities. This approach significantly reduces the overhead of fully homomorphic computations, making the query process computational complexity independent of dataset size under certain conditions. Moreover, by integrating private information retrieval technology, the scheme enhances privacy by hiding access patterns of image data. Formal security analysis demonstrates that our scheme achieves indistinguishability against chosen-plaintext attack (IND-CPA), and extensive experiments based on real datasets confirm that our scheme is both practical and efficient for real-world applications.
Lin Chen 0033, Yiwei Yang 0003, Li Yang 0005, Yinbin Miao, Zhiquan Liu 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Chao Hong
IEEE Internet Things J.3
2025 Efficient Sharing of Energy Consumption Data: A Privacy-Preserving Threshold Aggregation Approach
abstract
Energy consumption data collected by smart meters (SMs) is increasingly used by various subscribers in the smart grid for load management, energy monitoring, and policy planning. To protect user privacy, edge-assisted privacy-preserving data aggregation (PPDA) techniques are commonly employed. However, existing methods face several challenges: 1) limited scalability, 2) strict trust requirements, and 3) the risk of revealing unique consumption patterns to data collectors. To address these challenges, we propose a privacy-preserving threshold aggregation method that is easily scalable and facilitates efficient energy data sharing under limited trust assumptions. Specifically, we design VFP-NTRU, a quantum-resistant homomorphic proxy re-encryption scheme with fault tolerance and re-encryption verification. In VFP-NTRU, SMs can encrypt data with a public key without the need for prior negotiation of decryption keys with multiple subscribers. Additionally, we develop a privacy threshold collection protocol that uses a verifiable oblivious pseudorandom function to provide privacy guarantees similar to k-anonymity for SM data collection. We further introduce an energy consumption model to determine optimal collection strategies, improving system responsiveness. We provide correctness analysis and prove the security of our scheme. Experimental results demonstrate that our approach outperforms existing PPDA methods, making it particularly suitable for resource-constrained SMs and central servers managing large-scale energy data.
Guohao Li 0004, Jiale Lian, Siyi Liu 0005, Li Yang 0005, Yantao Zhong, Qiang Li 0008
IEEE Internet Things J.5
2025 Secure and Efficient Cross-Modal Retrieval Over Encrypted Multimodal Data
abstract
With the popularity of social media, mobile devices and the Internet, a large amount of multimodal data (e.g, text, image, audio, video, etc.) is increasingly being outsourced to cloud to save local computing and storage costs. To search through encrypted multimodal data in the cloud, privacy-preserving cross-modal retrieval (PPCMR) techniques have attracted extensive attention. However, most of the existing PPCMR schemes lack the ability to resist quantum attacks and have low search efficiency on large-scale datasets. To solve above problems, we first propose a basic PPCMR scheme FECMR using the enhanced Single-key Function-hiding Inner Product Functional Encryption for Binary strings (SFB-IPFE) and cross-modal hashing technology, which achieves the measurement of similarity over encrypted multimodal data while resisting quantum attacks. Then, we design an efficient index KM-tree utilizing the K-modes clustering algorithm. On this basis, we propose an improved scheme FECMR+, which achieves sub-linear search complexity. Finally, formal security analysis proves that our schemes are secure against quantum attacks, and extensive experiments prove that our schemes are efficient and feasible for practical application.
Li Yang 0005, Wei Zhang 0308, Yinbin Miao, Yanrong Liang, Xinghua Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Computers1
2025 Practical and Collusion-Resistant Privacy-Preserving Aggregation for Edge Intelligence
abstract
Privacy-preserving data aggregation (PDA) enables an edge server to securely perform aggregation tasks on data generated by terminal devices in edge intelligence (EI) systems, revealing only the result without exposing individual inputs. However, most existing solutions, such as homomorphic encryption and federated learning, support only basic functions (e.g., SUM or AVG). They often fail to achieve privacy protection, fault tolerance, and lightweight terminal-side operations when the server colludes with compromised devices. In this work, we propose PrivEI, a practical PDA scheme for EI systems. It uses a proposed collusion-resistant symmetric masking scheme that enables an untrusted edge server to collect and decode masked inputs from$n$terminal devices while supporting arbitrary computations. The scheme allows the server to collude with$k \leq n - 2$terminal devices and has a lightweight mechanism to tolerate device dropouts during aggregation. PrivEI further leverages the Chinese Remainder Theorem to avoid frequent mask updates when aggregating multi-dimensional data, and ensures data integrity using a signer-efficient multiple-time elliptic curve signature algorithm. We formally prove that PrivEI ensures input privacy and achieves$(n-k)$-source anonymity. Both theoretical analysis and experimental results confirm that it offers superior functionality with performance comparable to existing approaches. We have open-sourced the implementation.
Guohao Li 0004, Li Yang 0005, Hongbin Huang, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Resist Dependency Explosion in Attack Investigation With Splittable Tag Propagation and Aggregation
abstract
Advanced Persistent Threats (APTs) pose significant security risks to the community. Researchers thereby propose techniques to capture the complex and stealthy scenarios of APT attacks through the use of provenance graphs to model system entities and their dependencies. Particularly, to mitigate the dependency explosion problem in attack investigation using provenance graphs, tag-based and priority-based provenance graphs are frequently utilized for analyzing attacks. These methods use threat tag propagation and threat prioritization to reduce the size of the provenance graph for faster analysis. Unfortunately, these methods can allow more complex and potential attacks to evade detection. To overcome these difficulties, we propose an APT attack investigation system,ProTaging, for APT detection and forensic analysis. By using Tactics, Techniques, and Procedures (TTPs) rules to assign and update the node's threat tag, splittable tag propagation to control the scope of threat information, and threat weight aggregation and prioritized backward analysis during the forensic analysis phase, ProTaging effectively reconstructs attack paths in seconds without dependency explosion. Experimental results on both the simulation dataset, DARPA TC E3, E5 dataset, and DARPA OpTC dataset demonstrate that ProTaging generates smaller dependency graphs (2.5 times smaller) and has fewer false positives (6.7 times fewer) compared to state-of-the-art solutions. Additionally, ProTaging significantly reduces manual investigation effort by approximately 99.9%.
Anyuan Sang, Junbo Jia, Li Yang 0005, Pengbin Feng, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.4
2025 Enhanced Model Poisoning Attack and Multi-Strategy Defense in Federated Learning
abstract
As a new paradigm of distributed learning, Federated Learning (FL) has been applied in industrial fields, such as intelligent retail, finance and autonomous driving. However, several schemes that aim to attack robust aggregation rules and reducing the model accuracy have been proposed recently. These schemes do not maintain the sign statistics of gradients unchanged during attacks. Therefore, the sign statistics-based scheme SignGuard can resist most existing attacks. To defeat SignGuard and most existing cosine or distance-based aggregation schemes, we propose an enhanced model poisoning attack, ScaleSign. Specifically, ScaleSign uses a scaling attack and a sign modification component to obtain malicious gradients with higher cosine similarity and modify the sign statistics of malicious gradients, respectively. In addition, these two components have the least impact on the magnitudes of gradients. Then, we propose MSGuard, a Multi-Strategy Byzantine-robust scheme based on cosine mechanisms, symbol statistics, and spectral methods. Formal analysis proves that malicious gradients generated by ScaleSign have a closer cosine similarity than honest gradients. Extensive experiments demonstrate that ScaleSign can attack most of the existing Byzantine-robust rules, especially achieving a success rate of up to 98.23% for attacks on SignGuard. MSGuard can defend against most existing attacks including ScaleSign. Specifically, in the face of ScaleSign attack, the accuracy of MSGuard improves by up to 41.78% compared to SignGuard.
Li Yang 0005, Yinbin Miao, Zhiquan Liu 0001, Xinghua Li 0001, Da Kuang, Hongwei Li 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.1
2025 Generating Adversarial Malware Examples Against Multiple Machine Learning Detectors
abstract
Malware poses a significant threat to network and information system security, particularly in industrial Internet of Things (IIoT) environments, where embedded systems and edge devices often rely on general-purpose operating systems. Although machine learning (ML) techniques have advanced malware detection, they remain vulnerable to adversarial attacks. Current research primarily focuses on adversarial examples targeting single ML detectors, but the widespread use of ensemble learning necessitates generating adversarial examples that can simultaneously evade multiple detectors. To address this challenge, we propose GanGenetic, a novel framework that combines generative adversarial networks (GANs) with genetic algorithms (GAs) to generate adversarial malware examples targeting import address table features in portable executable files. GanGenetic generates examples with minimal perturbations while simultaneously evaluating the robustness of multiple ML detectors. The framework first generates initial examples using GANs, then optimizes them through a GA to maximize evasion and minimize noise. Experiments on the VirusShare and Ember datasets show that GanGenetic can evade detection by seven ML models (including AdaBoost, Gradient Boosting Decision Trees, logistic regression, multilayer perceptron, random forest, support vector machine, and MalConv) with an average attack success rate exceeding 96%. In addition, in real-world tests, the framework successfully evaded detection while preserving malware functionality.
Anyuan Sang, Li Yang 0005, Junbo Jia, Huipeng Yang
IEEE Trans. Ind. Informatics3
2024 Assessing Threats: Security Boundary and Side-Channel Attack Detection in the Metaverse
Ruiyuan Yang, Guohao Li 0004, Li Yang 0005, Jiangyu Wang, Anyuan Sang
ICDF2C (2)3
2024 Adaptive Oriented Adversarial Attacks on Visible and Infrared Image Fusion Models
abstract
Visible and infrared image fusion (VIF), combining thermal information with textural details for more informative output, has attracted widespread research interest. However, current studies in VIF primarily focus on enhancing the image quality of fusion results, while the robustness against adversarial attacks remains largely unexplored. The VIF system might be deceived to produce inferior output that affects the decision of subsequent high-level tasks, leading to potential security accidents. This work aims to bridge this gap. We focus on degrading the fusion quality by introducing an adversarial attack, which injects imperceptible perturbation into input images to deteriorate the fusion result. To this end, we design an adaptive target generation method to establish a benchmark that indicates the ideal attack effect, which is used to guide the generation of perturbations. Extensive experiments demonstrate that our attack effectively impairs the performance of VIF models, while concurrently exerting a notable impact on subsequent tasks.
Li Yang 0005, Jianfeng Ma 0001, Hui Li 0006
ICME3
2024 Obfuscating Provenance-Based Forensic Investigations with Mapping System Meta-Behavior
abstract
The provenance graph technique has gained popularity for attack analysis, such as Advanced Persistent Threat (APT) attacks, by creating entity interaction graphs from host audit logs. While this method has shown promising analysis results and interpretability, its robustness against mimic attacks carried out by potentially skilled attackers has yet to be fully proven. Recent research has showcased adversarial methodologies targeting provenance-based Machine Learning (ML) detectors, leading to evasion attacks through the addition of corresponding nodes and edges to the feature space. However, these approaches face several challenges, including the difficulty in translating feature alterations into practical attack scenarios and limited applicability to other provenance graph-based detection schemes.
Anyuan Sang, Li Yang 0005, Junbo Jia
RAID3
2024 DawnGNN: Documentation augmented windows malware detection using graph neural network
Pengbin Feng, Le Gai, Li Yang 0005, Qin Wang 0008, Teng Li 0003, Ning Xi 0002, Jianfeng Ma 0001
Comput. Secur.3
2024 ADDITION: Detecting Adversarial Examples With Image-Dependent Noise Reduction
abstract
Notwithstanding the tremendous success of deep neural networks in a range of realms, previous studies have shown that these learning models are exposed to an inherent hazard calledadversarial example— images to which an elaborate perturbation is maliciously added could deceive a network, which entails the study of countermeasures urgently. However, existing solutions suffer from some weaknesses, e.g. parameters are usually determined empirically in some processing-based detection methods might result in a sub-optimal effect, and the directly performed processing on images might affect the classification of benign samples, leading to increment of false positive. In this paper, we propose a novel imAge-DepenDent noIse reducTION (ADDITION) model based on deep learning for adversarial detection. The ADDITION model can adaptively convert the adversarial perturbation in each image to approximate Gaussian noise by injecting image-dependent additional noise, then perform noise reduction to eliminate the adversarial perturbation, and finally detect adversarial examples by examining the classification inconsistency between the input image and its denoised version. The ADDITION model is trained end-to-end on benign samples without any prior knowledge of adversarial attacks, and thus avoid time-consuming task of generating adversarial examples in practical use. We generate more than 220,000 adversarial examples based on six attack algorithms for evaluation and present state-of-the-art comparisons on three real-word datasets. Extensive experiments demonstrate that our proposed method achieves improved performance in both detection accuracy rate and false positive rate.
Li Yang 0005, Jianfeng Ma 0001, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.3
2023 BejaGNN: behavior-based Java malware detection via graph neural network
Pengbin Feng, Li Yang 0005, Di Lu 0001, Ning Xi 0002, Jianfeng Ma 0001
J. Supercomput.2
2023 IRGA: An Intelligent Implicit Real-time Gait Authentication System in Heterogeneous Complex Scenarios
abstract
Gait authentication as a technique that can continuously provide identity recognition on mobile devices for security has been investigated by academics in the community for decades. However, most of the existing work achieves insufficient generalization to complex real-world environments due to the complexity of the noisy real-world gait data. To address this limitation, we propose an intelligent Implicit Real-time Gait Authentication (IRGA) system based on Deep Neural Networks (DNNs) for enhancing the adaptability of gait authentication in practice. In the proposed system, the gait data (whether with complex interference signals) will first be processed sequentially by the imperceptible collection module and data preprocessing module for improving data quality. In order to illustrate and verify the suitability of our proposal, we provide analysis of the impact of individual gait changes on data feature distribution. Finally, a fusion neural network composed of a Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) is designed to perform feature extraction and user authentication. We evaluate the proposed IRGA system in heterogeneous complex scenarios and present start-of-the-art comparisons on three datasets. Extensive experiments demonstrate that the IRGA system achieves improved performance simultaneously in several different metrics.
Li Yang 0005, Xi Li 0003, Zhuoru Ma, Lu Li 0008, Naixue Xiong, Jianfeng Ma 0001
ACM Trans. Internet Techn.1
2022 SEMMI: Multi-party Security Decision-making Scheme Under the Internet of Medical Things
abstract
In the Internet of Medical Things, the intelligent auxiliary decision-making system uses machine learning algorithms to analyze medical data for disease diagnosis, auxiliary intervention, and analysis and early warning. However, in the process of medical data transmission, processing, and storage, a large amount of private information is also at risk of leakage. Therefore, this article proposes a smart classification and decision-making program in the Internet of Medical Things scenario-SEMMI, which can effectively deal with the risk of data leakage in the process of medical data processing. At the same time, it reduces the huge computing and storage pressure caused by encryption and decryption operations in medical institutions. In the scheme, data collection, processing, transmission, storage and calculation are completed by ciphertext. In addition, in view of the relatively weak computing and storage capabilities of sensor nodes, we use chaos theory to construct a stream cipher algorithm to ensure the security of transmission from sensor to user; the homomorphic encryption algorithm is used to ensure the computability of the ciphertext and the security of storage. Through security analysis, it can be concluded that this scheme can resist attacks from adversaries; at the same time, the experimental results show that the scheme has good performance in terms of calculation, storage overhead, accuracy, and so on.
Cheng Li 0030, Li Yang 0005, Shui Yu 0001, Wenjing Qin, Jianfeng Ma 0001
ICC2
2022 Vacuum: Efficient and Assured Deletion Scheme for User Sensitive Data on Mobile Devices
abstract
Embedded devices (e.g., mobile phones, smart watches, etc.) store a large amount of sensitive information. However, Android-based devices may leak a lot of user information if unsafe data deletion. Therefo re, research on secure data deletion for embedded devices has become a practical and urgent issue. In this article, we study the logic structure, operation characteristics, and data management mechanisms of flash memory. Then, we propose a novel method Vacuum that uses a user-space file system and can provide fine-grained file deletion guarantees. Our approach encrypts files on an insecure medium with a unique key that can later be discarded to cryptographically render the data irrecoverable. Additionally, we use TrustZone as a secure key vault, and a garbage collection mechanism is introduced to purge the memory. Finally, we carried out experiments on the Android system, and the results showed that the solution is efficient and can meet the needs of real applications.
Li Yang 0005, Cheng Li 0030, Teng Wei, Fengwei Zhang, Jianfeng Ma 0001, Naixue Xiong
IEEE Internet Things J.1
2022 SEMMI: Multi-party security decision-making scheme for linear functions in the internet of medical things
Cheng Li 0030, Li Yang 0005, Shui Yu 0001, Wenjing Qin, Jianfeng Ma 0001
Inf. Sci.2
2022 Achieving privacy-preserving sensitive attributes for large universe based on private set intersection
Li Yang 0005, Cheng Li 0030, Yuting Cheng 0002, Shui Yu 0001, Jianfeng Ma 0001
Inf. Sci.1
2021 FedGR: A Lossless-Obfuscation Approach for Secure Federated Learning
abstract
Federated learning is a promising new technology in the field of artificial intelligence. However, the unprotected model gradient parameters in federated learning may reveal sensitive participants information. To address this problem, we present a secure federated learning framework called FedGR. We use Paillier homomorphic encryption to design a new gradient security replacement algorithm, which eliminates the connections between gradient parameters and user sensitive data. In addition, we revisit the previous work by Aono and Hayashi(IEEE TIFS 2017) and show that, with their method, the user's local computing burden is too heavy. We then proved FedGR has the following characteristics to solve this problem: 1) The system does not leak any information to the server. 2) Compared with that of ordinary deep learning systems, the accuracy of federated training results yielded by our system remains unchanged. 3)The proposed approach greatly reduces the user's local computing overhead.
Wenjing Qin, Li Yang 0005, Jianfeng Ma 0001
GLOBECOM2
2021 UserRBPM: User Retweet Behavior Prediction with Graph Representation Learning
abstract
Social and information networks such as Facebook, Twitter, and Weibo have become the main social platforms for the public to share and exchange information, where we can easily access friends’ activities and in turn be influenced by them. Consequently, the analysis and modeling of user retweet behavior prediction have an important application value, such as information dissemination, public opinion monitoring, and product recommendation. Most of the existing solutions for user retweeting behavior prediction are usually based on network topology maps of information dissemination or designing various handcrafted rules to extract user‐specific and network‐specific features. However, these methods are very complex or heavily dependent on the knowledge of domain experts. Inspired by the successful use of neural networks in representation learning, we design a framework, UserRBPM, to explore potential driving factors and predictable signals in user retweet behavior. We use the graph embedding technology to extract the structural attributes of the ego network, consider the drivers of social influence from the spatial and temporal levels, and use graph convolutional networks and the graph attention mechanism to learn its potential social representation and predictive signals. Experimental results show that our proposed UserRBPM framework can significantly improve prediction performance and express social influence better than traditional feature engineering‐based approaches.
Huihui Guo, Li Yang 0005, Zeyu Liu 0009
Wirel. Commun. Mob. Comput.2
2020 A Secure and Verifiable Outsourcing Scheme for Assisting Mobile Device Training Machine Learning Model
abstract
In smart applications such as smart medical equipment, more data needs to be processed and trained locally and near the local end to prevent privacy leaks. However, the storage and computing capabilities of smart devices are limited, so some computing tasks need to be outsourced; concurrently, the prevention of malicious nodes from accessing user data during outsourcing computing is required. Therefore, this paper proposes EVPP (efficient, verifiable, and privacy-preserving), which is a computing outsourcing scheme used in the training process of machine learning models. The edge nodes outsource the complex computing process to the edge service node. First, we conducted a certain amount of testing to confirm the parts that need to be outsourced. In this solution, the computationally intensive part of the model training process is outsourced. Meanwhile, a random encryption perturbation is performed on the outsourced training matrix, and verification factors are introduced to ensure the verifiability of the results. In addition, the system can generate verifiable evidence that can be generated to build a trust mechanism when a malicious service node is found. At the same time, this paper also discusses the application of the scheme in other algorithms in order to be better applied. Through the analysis of theoretical and experimental data, it can be shown that the scheme proposed in this paper can effectively use the computing power of the equipment.
Cheng Li 0030, Li Yang 0005, Jianfeng Ma 0001
Wirel. Commun. Mob. Comput.2
2019 MineAuth: Mining Behavioural Habits for Continuous Authentication on a Smartphone
Xiaojian Pang, Li Yang 0005, Maozhen Liu 0001, Jianfeng Ma 0001
ACISP2
2019 Achieving Efficient and Verifiable Assured Deletion for Outsourced Data Based on Access Right Revocation
Yuting Cheng 0002, Li Yang 0005, Shui Yu 0001, Jianfeng Ma 0001
CANS2
2019 A DNS Tunneling Detection Method Based on Deep Learning Models to Prevent Data Exfiltration
Li Yang 0005, Shui Yu 0001, Jianfeng Ma 0001
NSS2
2019 Inference attack in Android Activity based on program fingerprint
Li Yang 0005, Yifang Zhi, Teng Wei, Shui Yu 0001, Jianfeng Ma 0001
J. Netw. Comput. Appl.1
2019 Fingerprint Protected Password Authentication Protocol
abstract
With the rapid development of industrial Internet of things (IIOT), a variety of cloud services have been deployed to store and process the big data of IIOT. The traditional password only authentication is unable to meet the needs of security situation in IIOT. Therefore, a lot of mobile phone assisted password authentication schemes have been proposed. However, in existing schemes, the secret information is required to be stored in the user’s mobile phone. Once the phone is lost, the secret information may be obtained by the opponent, which will bring irreparable loss to the user. To address the above problems, we propose a fingerprint protected password authentication scheme which has no need to store the secret parameter in the mobile phone. When a user logs in, he uses his mobile phone to generate the private key which is used to decrypt the encrypted text generated during the registration phase. The process of generating the private key needs to enter the password and the fingerprint. When the computer interacts with the mobile phone, the user’s password will be blinded so that it can protect the user’s password from adversary’s attacks. Theoretical analysis and experimental results show that our scheme improves the security of the user’s secret. Meanwhile, our scheme can resist the opponent’s dictionary attacks, replay attacks, and phishing attack. Our scheme can reduce the storage pressure of the mobile phone and is easy to deploy.
Chao Yang 0016, Junwei Zhang 0001, Yu Zheng 0004, Li Yang 0005, Jianfeng Ma 0001
Secur. Commun. Networks5
2018 SADUS: Secure data deletion in user space for mobile devices
Li Yang 0005, Teng Wei, Fengwei Zhang, Jianfeng Ma 0001
Comput. Secur.1
2018 A remotely keyed file encryption scheme under mobile cloud computing
Li Yang 0005, Ziyi Han, Zhengan Huang, Jianfeng Ma 0001
J. Netw. Comput. Appl.1
2018 Online handwritten signature verification using feature weighting algorithm relief
Li Yang 0005, Yuting Cheng 0002, Xianmin Wang, Qiang Liu 0031
Soft Comput.1
2018 Identifying opinion leader nodes in online social networks with a new closeness evaluation algorithm
Li Yang 0005, Yafeng Qiao, Jianfeng Ma 0001, Xinghua Li 0001
Soft Comput.1
2018 Efficient Multifactor Two-Server Authenticated Scheme under Mobile Cloud Computing
abstract
Because the authentication method based on username‐password has the disadvantage of easy disclosure and low reliability and the excess password management degrades the user experience tremendously, the user is eager to get rid of the bond of the password in order to seek a new way of authentication. Therefore, the multifactor biometrics‐based user authentication wins the favor of people with advantages of simplicity, convenience, and high reliability. Now the biometrics‐based (especially the fingerprint information) authentication technology has been extremely mature, and it is universally applied in the scenario of the mobile payment. Unfortunately, in the existing scheme, biometric information is stored on the server side. As thus, once the server is hacked by attackers to cause the leakage of the fingerprint information, it will take a deadly threat to the user privacy. Aiming at the security problem due to the fingerprint information in the mobile payment environment, we propose a novel multifactor two‐server authenticated scheme under mobile cloud computing (MTSAS). In the MTSAS, it divides the authentication method and authentication means; in the meanwhile, the user’s biometric characteristics cannot leave the user device. Thus, MTSAS avoids the fingerprint information disclosure, protects user privacy, and improves the security of the user data. In the same time, considering user actual requirements, different authentication factors depending on the privacy level of authentication are chosen. Security analysis proves that MTSAS has achieved the authentication purpose and met security requirements by the BAN logic. In comparison with other schemes, the result shows that MTSAS not only has the reasonable computational efficiency, but also keeps the superior communication cost.
Ziyi Han, Li Yang 0005, Sen Mu, Qiang Liu 0031
Wirel. Commun. Mob. Comput.2
2017 Toward better data veracity in mobile cloud computing: A context-aware and incentive-based reputation mechanism
Hui Lin 0007, Jia Hu 0001, Youliang Tian, Li Yang 0005, Li Xu 0002
Inf. Sci.4
2015 Universally composable secure positioning in the bounded retrieval model
Junwei Zhang 0001, Jianfeng Ma 0001, Chao Yang 0016, Li Yang 0005
Sci. China Inf. Sci.4
2015 CRM: A New Dynamic Cross-Layer Reputation Computation Model in Wireless Networks
abstract
Multi-hop wireless networks (MWNs) have been widely accepted as an indispensable component of next-generation communication systems due to their broad applications and easy deployment without relying on any infrastructure. Although showing huge benefits, MWNs face many security problems, particularly the internal multi-layer security threats being one of the most challenging issues. Since most security mechanisms require the cooperation of nodes, characterizing and learning actions of neighboring nodes and the evolution of these actions over time is vital to constructing an efficient and robust solution for security-sensitive applications such as social networking, mobile banking and teleconferencing. In this paper, we propose a new dynamic Cross-layer Reputation computation Model (CRM) to dynamically characterize and quantify actions of nodes. CRM couples an uncertainty-based conventional layered reputation computation model (RCM) with cross-layer design and multi-level security technology to identify malicious nodes and preservation of security against internal multi-layer threats. Simulation results and performance analyses demonstrate that CRM can provide rapid and accurate malicious node identification and management, and implement the preservation of security against the internal multi-layer and bad-mouthing attacks more effectively and efficiently than existing models.
Hui Lin 0007, Jia Hu 0001, Jianfeng Ma 0001, Li Xu 0002, Li Yang 0005
Comput. J.5
2015 A delegation based cross trusted domain direct anonymous attestation scheme
Li Yang 0005, Jianfeng Ma 0001, Wenjing Lou, Qi Jiang 0001
Comput. Networks1
2014 Multi-domain Direct Anonymous Attestation Scheme from Pairings
Li Yang 0005, Jianfeng Ma 0001, Wei Wang 0105, Chunjie Cao
NSS1