Teng Li 0003

dblp:09/6669-3 · DBLP profile ↗
← Back
46ranked-venue papers
19as first author
37since 2021 · last 2026
0000-0001-5147-8336ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 17 · 7 first-author · 14 since 2021Security and privacy · 16 · 5 first-author · 14 since 2021Systems, architecture and hardware · 5 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Knowledge Graph-Augmented Reasoning for Robust Multi-modal Document Attack Detection
Teng Li 0003, Shengkai Zhang, Yebo Feng, Zhuo Ma 0001, Jianfeng Ma 0001
ACISP (2)1
2026 Fake news detection with GAN-augmented contrastive learning and multimodal attention
abstract
Abstract The rapid proliferation of fake news in digital media has emerged as a major threat to information credibility and public trust. Although recent advances have explored multimodal learning for fake news detection, existing models often fail to effectively integrate heterogeneous data sources and remain vulnerable to adversarial manipulations. To address these challenges, we propose (Multimodal Adversarial Deep Semantic Learning), a robust multimodal fake news detection framework that unifies generative adversarial networks (GANs) with supervised contrastive learning. Specifically, employs a multi-layer joint attention mechanism to align and fuse textual and visual features, while adversarial training encourages the extraction of event-invariant representations, enhancing generalizability across unseen news events. Additionally, contrastive learning with adversarial perturbations further strengthens feature discrimination and robustness against attacks. Extensive experiments on benchmark Twitter and Weibo datasets demonstrate that achieves state-of-the-art accuracy (85.3%) and maintains stable performance with only a 1.1% drop under adversarial conditions, outperforming existing methods in both detection accuracy and resilience. These results underscore ’s effectiveness in advancing robust multimodal fake news detection and promoting digital information integrity.
Cong Wu 0003, Jing Chen 0003, Yebo Feng, Ju Jia, Zijian Zhang 0001, Jiahua Xu 0002, Teng Li 0003, Yang Liu 0003
Cybersecur.8
2026 AdaptiveShield: Dynamic Defense Against Decentralized Federated Learning Poisoning Attacks
abstract
Federated learning allows decentralized devices to collaboratively train a shared model while keeping data local, enhancing the privacy and security of the training process. However, it is vulnerable to poisoning attacks, where malicious participants inject false data to corrupt the global model. To address this, we propose AdaptiveShield, a dynamic hybrid defense approach designed to protect decentralized federated learning against such attacks. AdaptiveShield employs dynamic detection strategies that consider multiple risk factors to assess the maliciousness index and dynamically adjust the detection thresholds, which is able to adapt to various attack scenarios. In addition to attack detections, AdaptiveShield minimizes the negative impact on the global model from missed attackers by dynamically adjusting hyperparameters, thereby enhancing the robustness of the defense. It also dissociates user identities from their uploaded local models through a hierarchical shuffle mechanism, providing an extra layer of privacy protection for both the users and their local models. We evaluate AdaptiveShield across various experimental environments, attack settings, and datasets, demonstrating that it outperforms state-of-the-art approaches by achieving over 0.1 improvement in training accuracy while incurring negligible time overhead.
Yebo Feng, Baichuan Zheng, Teng Li 0003, Cong Wu 0003, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.3
2026 AeroGuard: Towards Real-Time UAV Fault Detection With Hybrid Models
abstract
Unmanned Aerial Vehicles (UAVs) are increasingly deployed in safety-critical applications, yet their operations in complex environments make them vulnerable to diverse faults. This paper presents AeroGuard, a lightweight hybrid frame work for real-time UAV fault detection. AeroGuard combines Long Short-Term Memory (LSTM) and AutoRegressive with eXogenous input (ARX) models, with residual-driven adaptive weighting to balance their strengths. Faults are identified through Z-score and Sequential Probability Ratio Test (SPRT) applied to prediction residuals, ensuring accurate and timely detection. Extensive experiments on public datasets, real UAV flight logs, and outdoor flights confirm AeroGuard's robustness, particularly in detecting drift and bias faults where existing methods degrade. AeroGuard achieves up to 95.8% precision, representing about 10% improvement over prior work, while maintaining sub-5ms latency on Raspberry Pi 4B with modest resource usage, and sub second detection on Pi Zero for low-speed UAVs. We also discuss current limitations, noting that evaluation on hardware-induced faults (e.g., motor seizure) will be pursued in future work.
Teng Li 0003, Zhili Wei, Yebo Feng, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001, Yang Liu 0003
IEEE Trans. Mob. Comput.1
2025 Slot: Provenance-Driven APT Detection through Graph Reinforcement Learning
abstract
Advanced Persistent Threats (APTs) represent sophisticated cyberattacks characterized by their ability to remain undetected within the victim system for extended periods, aiming to exfiltrate sensitive data or disrupt operations. Existing detection approaches often struggle to effectively identify these complex threats, construct the attack chain for defense facilitation, or resist adversarial attacks. To overcome these challenges, we propose Slot, an advanced APT detection approach based on provenance graphs and graph reinforcement learning. Slot excels in uncovering multi-level hidden relationships, such as causal, contextual, and indirect connections, among system behaviors through provenance graph mining. Slot implements semi-supervised learning with limited labels through efficient label similarity computation, significantly enhancing both detection performance and model robustness. By pioneering the integration of graph reinforcement learning, Slot dynamically adapts to new user activities and evolving attack strategies, enhancing its resilience against adversarial attacks. Additionally, Slot automatically constructs the attack chain according to detected attacks with clustering algorithms, providing precise identification of attack paths and facilitating the development of defense strategies. Evaluations with real-world datasets demonstrate Slot's outstanding accuracy, efficiency, adaptability, and robustness in APT detection, with most metrics surpassing state-of-the-art methods. Additionally, case studies conducted to assess Slot's effectiveness in supporting APT defense further establish it as a practical and reliable tool for cybersecurity protection.
Wei Qiao 0005, Yebo Feng, Teng Li 0003, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001, Yang Liu 0003
CCS3
2025 SafeLead: Detecting and Excluding Random STS Attack in UWB Ranging System
Zhuo Ma 0001, Jiayu Jin, Yang Liu 0118, Yilong Yang 0004, Xinjing Liu, Teng Li 0003, Junwei Zhang 0001, Jianfeng Ma 0001
INFOCOM6
2025 LBFT-DAG: A Swift, Leader-Driven, DAG-Based Consortium Blockchain with Byzantine Fault-Tolerance
Xuewen Dong, Teng Li 0003, Youliang Tian, Yulong Shen 0001, Xiaojiang Du
INFOCOM3
2025 L-HAWK: A Controllable Physical Adversarial Patch Against a Long-Distance Target
Taifeng Liu, Yang Liu 0118, Zhuo Ma 0001, Tong Yang 0003, Xinjing Liu, Teng Li 0003, Jianfeng Ma 0001
NDSS6
2025 STGraph: Spatio-Temporal Graph Mining for Anomaly Detection in Distributed System Logs
abstract
System logs are crucial sources of information for engineers to analyze and resolve anomalies and faults in large-scale software systems. However, logs on a distributed system are often fragmented, making it challenging to achieve unified processing and comprehension. Traditional methods for log-based anomaly detection often employ machine learning algorithms with a focus on log event counts or log sequences. However, traditional methods fall short of fully leveraging the temporal and spatial structures inherent in distributed system logs, leading to issues of false positives and unstable performance in anomaly detection. In this paper, we propose a novel log anomaly detection method based on the construction of distributed system workflow graphs. This method extracts spatio-temporal information from distributed system logs and constructs event workflow graphs. These graphs accurately reflect the execution of the system and provide more comprehensive support for anomaly detection based on distributed system logs. The experimental results demonstrated that STGraph achieved F1 scores of 0.959,0.979, and 0.959 on HDFS, BGL, and OpenStack datasets respectively, outperforming LogRobust, PLELog, and NeuralLog by 1.2%-18.6% across precision/recall metrics. Notably, it attained 0.985 recall on BGL and maintained >0.935 F1 scores under 30% noise interference, 21.8% higher than LogRobust.
Teng Li 0003, Shengkai Zhang, Yebo Feng, Jiahua Xu 0002, Zexu Dang, Yang Liu 0003, Jianfeng Ma 0001
RAID1
2025 HeteroSample: Meta-Path Guided Sampling for Heterogeneous Graph Representation Learning
abstract
The rapid expansion of Internet of Things (IoT) has resulted in vast, heterogeneous graphs that capture complex interactions among devices, sensors, and systems. Efficient analysis of these graphs is critical for deriving insights in IoT scenarios, such as smart cities, industrial IoT, and intelligent transportation systems. However, the scale and diversity of IoT-generated data present significant challenges, and existing methods often struggle with preserving the structural integrity and semantic richness of these complex graphs. Many current approaches fail to maintain the balance between computational efficiency and the quality of the insights generated, leading to potential loss of critical information necessary for accurate decision-making in IoT applications. We introduce HeteroSample, a novel sampling method designed to address these challenges by preserving the structural integrity, node and edge type distributions, and semantic patterns of IoT-related graphs. HeteroSample works by incorporating the novel top-leader selection, balanced neighborhood expansion, and meta-path guided sampling strategies. The key idea is to leverage the inherent heterogeneous structure and semantic relationships encoded by meta-paths to guide the sampling process. This approach ensures that the resulting subgraphs are representative of the original data while significantly reducing computational overhead. Extensive experiments demonstrate that HeteroSample outperforms state-of-the-art methods, achieving up to 15% higher F1 scores in tasks, such as link prediction and node classification, while reducing runtime by 20%. These advantages make HeteroSample a transformative tool for scalable and accurate IoT applications, enabling more effective and efficient analysis of complex IoT systems, ultimately driving advancements in smart cities, industrial IoT, and beyond.
Jing Chen 0003, Ruiying Du, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001
IEEE Internet Things J.6
2025 DynaShard: Secure and Adaptive Blockchain Sharding Protocol With Hybrid Consensus and Dynamic Shard Management
abstract
Blockchain sharding has emerged as a promising solution to the scalability challenges in traditional blockchain systems by partitioning the network into smaller, manageable subsets called shards. Despite its potential, existing sharding solutions face significant limitations in handling dynamic workloads, ensuring secure cross-shard transactions, and maintaining system integrity. To address these gaps, we propose DynaShard, a dynamic and secure cross-shard transaction processing mechanism designed to enhance blockchain sharding efficiency and security. DynaShard combines adaptive shard management, a hybrid consensus approach, plus an efficient state synchronization and dispute resolution protocol. Our performance evaluation, conducted using a robust experimental setup with real-world network conditions and transaction workloads, demonstrates DynaShard's superior throughput, reduced latency, and improved shard utilization compared to the fast transaction scheduling in blockchain sharding (FTSBS) method. Specifically, DynaShard achieves up to a 42.6% reduction in latency and a 78.77% improvement in shard utilization under high transaction volumes and varying cross-shard transaction ratios. These results highlight DynaShard's ability to outperform state-of-the-art sharding methods, ensuring scalable and resilient blockchain systems. We believe that DynaShard's innovative approach will significantly impact future developments in blockchain technology, paving the way for more efficient and secure distributed systems.
Jing Chen 0003, Kun He 0008, Ruiying Du, Jiahua Xu 0002, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001
IEEE Internet Things J.8
2025 Log2Evt: Constructing high-level events for IoT Systems through log-code execution path correlation
Teng Li 0003, Baichuan Zheng, Yebo Feng, Xiaowen Quan, Jiahua Xu 0002, Yang Liu 0003, Jianfeng Ma 0001
J. Syst. Archit.1
2025 SauronEyes: Disentangling Voluminous Logs to Unveil Camouflaged Attack Intentions
Wei Qiao 0005, Weiheng Wu, Yebo Feng, Teng Li 0003, Bo Jiang 0013, Zhigang Lu 0002, Baoxu Liu
IEEE Trans. Inf. Forensics Secur.7
2025 CryptIF: Toward Cloud-Based IoT Anomaly Detection Over Encrypted Feature Streams
Teng Li 0003, Zejian Lin, Yebo Feng, Chong Wang 0013, Zhuo Ma 0001, Bin Xiao 0002, Jianfeng Ma 0001, Yang Liu 0003
IEEE Trans. Knowl. Data Eng.1
2024 Heuristic-based Parsing System for Big Data Log
abstract
Logs play a crucial role in recording valuable system runtime information, extensively utilized by service providers and users for effective service management. A typical approach in service management, based on log analysis, involves parsing the original log messages initially presented in an unstructured format. Subsequently, a data mining model is employed to extract critical system behavior information, aiding in service management. As the volume of logs rapidly increases, training models using current log resolution methods post-log collection becomes excessively time-consuming, leading to decreased accuracy. Manual analysis of extensive logs is both time-intensive and inefficient. This article introduces Aclog, an automated log parsing tool tailored for large-scale log analysis, storage, and management. Aclog operates by storing and managing logs in a structured and unified format, thereby offering a cohesive database for comprehensive log auditing of computing systems. Key components of Aclog encompass the log updater, log parser, log storage, and log querier. In this paper, we utilize a realworld, large-scale public log dataset to showcase the capabilities of Aclog. We evaluate the log files generated by ten popular systems.
Teng Li 0003, Shengkai Zhang, Yebo Feng, Jiahua Xu 0002, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001
GLOBECOM1
2024 An Efficient Key Agreement and Update Scheme in Cloud-Network-End Collaborative Security for Wireless Networks
abstract
With the commercial launch of 5G technology, the development of the Internet of Things, and the proliferation of edge computing, wireless networks are having a profound impact on society. However, ensuring data security in the wireless network remains a challenging issue. The proposed cloud-network-end collaborative security architecture provides an effective approach to address this challenge. This paper presents a non-interactive key agreement and update scheme based on cloud-network-end architecture. Non-interactive secure association is achieved by using Chameleon Hash and Diffie-Hellman key exchange technology. Furthermore, a Key Derivation Function is introduced to implement a one-time padding update mechanism. Security analysis in Protocol Composition Logic shows that the proposed scheme satisfies authentication, key confidentiality and forward security for session keys. Finally, experiments confirm that our solution incurs minimal communication overhead on the user side and achieves efficient secure association and key update.
Junwei Zhang 0008, Weihui Li, Jianfeng Ma 0001, Zhuo Ma 0001, Teng Li 0003, Chuang Tian 0001, Xinghua Li 0001
GLOBECOM5
2024 Need for Speed: Taming Backdoor Attacks with Speed and Precision
abstract
Modern deep neural network models (DNNs) require extensive data for optimal performance, prompting reliance on multiple entities for the acquisition of training datasets. One prominent security threat is backdoor attacks where the adversary party poisons a small subset of training datasets to implant a backdoor into the model, leading to misclassifications during runtime for triggered samples. To mitigate the attack, many defense methods have been proposed, such as detecting and removing poisoned samples or rectifying trojaned model weights in victim DNNs. However, existing approaches suffer from notable inefficiency as they are faced with large-scale training datasets, consequently rendering these defenses impractical in the real world. In this paper, we propose a lightweight backdoor identification and removal scheme, called ReBack. In this scheme, ReBack first extracts a subset of suspicious and benign samples, and then, proceeds with a "averaging and differencing" based method to identify target label(s). Next, leveraging the identification results, ReBack invokes a novel reverse engineering method to recover the exact trigger using only basic arithmetic atoms. Our experiments demonstrate that, for ImageNet with 750 labels, ReBack can defend against backdoor attacks in around 2 hours, showcasing a speed improvement of 18.5× to 214× compared to existing methods. For backdoor removal, the attack success rate can be decreased to 0.05% owing to 99% cosine similarity of the reversed triggers. The code is online available.
Zhuo Ma 0001, Yilong Yang 0004, Yang Liu 0118, Tong Yang 0003, Xinjing Liu, Teng Li 0003, Zhan Qin
SP6
2024 CoDetect: cooperative anomaly detection with privacy protection towards UAV swarm
Teng Li 0003, Weiguo Lin, Zhuo Ma 0001, Yulong Shen 0001, Jianfeng Ma 0001
Sci. China Inf. Sci.1
2024 DawnGNN: Documentation augmented windows malware detection using graph neural network
Pengbin Feng, Le Gai, Li Yang 0005, Qin Wang 0008, Teng Li 0003, Ning Xi 0002, Jianfeng Ma 0001
Comput. Secur.5
2024 T-Trace: Constructing the APTs Provenance Graphs Through Multiple Syslogs Correlation
abstract
Advanced Persistent Threats (APTs) employ sophisticated and covert tactics to infiltrate target systems, leading to increased vulnerability and an elevated risk of exposure. Consequently, it is essential for us to proactively create an extensive and clearly outlined attack chain for APTs in order to effectively combat these threats. Unlike traditional malware or application threats, APTs can sidestep cyber security efforts and cause severe damage to organizations or even state security. Nonetheless, earlier methods struggle to accurately track APTs and may face a dependency explosion issue, as identifying the intricate and complex unknown malicious activities within APTs proves to be challenging. In this paper, we propose and build an approach, T-trace, which constructs the events provenance graphs by analyzing the correlations among logs. The approach precisely finds the log communities with tensor decomposition and calculates significance scores to extract the events. The APTs can be inferred by discovering the event communities and constructing the provenance graph with log correlation. In the experiment, we used DARPA data sets and launched four current practical APTs. Compared with current approaches, the results show that T-trace can efficiently reduce time cost by 90% and achieve a 92% accuracy rate in constructing the provenance graph, which can be practically applied in APTs provenance.
Teng Li 0003, Ximeng Liu, Wei Qiao 0005, Xiongjie Zhu, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Provably and Physically Secure UAV-Assisted Authentication Protocol for IoT Devices in Unattended Settings
abstract
As the core subject of IoT applications, IoT devices have faced numerous security challenges. Especially for IoT devices deployed in remote or harsh environments, they are often unattended for long periods, making it difficult to share the sensing data and susceptible to potential physical attacks. While aerial assistance methods represented by unmanned aerial vehicles (UAVs) can solve the problem of data sharing at a low cost, it is necessary to establish a secure channel between ground control stations, UAVs, and IoT devices due to the sensitivity of the sensing data. Recently, Physical Unclonable Function (PUF) has been proven to provide unique identity identification for devices using its tamper-proof feature. In this paper, we propose a lightweight UAV-assisted authentication and key agreement protocol for unattended IoT devices, ensuring secure communication and physical tamper-proof requirements. However, our work does not stop there. We noticed that some existing PUF-based authentication schemes misunderstand the ability of PUF, which leads to these schemes cannot actually provide physical protection. We analyzed the security vulnerabilities of these schemes and proposed rules that should be followed when designing authentication protocols using PUF. In addition, for the first time, we put forward the formal definitions and proof methods for PUF in the formal proof of the security protocol, which avoided the unreasonable initial assumptions adopted in the proof of the existing schemes. We extended Mao-Boyd (MB) logic and comprehensively analyzed the proposed protocol. We also evaluate the performance of the proposed scheme, and the results show that the proposed scheme has certain advantages in communication and computation overhead compared with existing schemes.
Chuang Tian 0001, Jianfeng Ma 0001, Teng Li 0003, Junwei Zhang 0008, Chengyan Ma 0001, Ning Xi 0002
IEEE Trans. Inf. Forensics Secur.3
2024 Location-Aware and Privacy-Preserving Data Cleaning for Intelligent Transportation
abstract
The widespread use of machine learning in location-related scenarios is propelling the rapid development of intelligent transportation. To assist users in making more informed travel plans, the demand for improving prediction accuracy is growing. Prior to model training, data cleaning is a common method used to eliminate redundant, erroneous and outlier samples. However, in intelligent transportation, there are serious issues with location awareness and privacy protection of existing data cleaning schemes. Therefore, we propose a location-aware and privacy-preserving data cleaning framework (PriSPA) which provides a cleaned dataset consisting of the samples from adopted data suppliers at qualified locations while ensuring the privacy of locations, spatial constraints and sensitive samples. We combine boolean secret sharing with XOR operations to make sure that it is possible to figure out whether a location complies with spatial constraints without leakage. More specifically, we ensure privacy using key agreement, secret sharing, authenticated encryption and random permutation. We seriously analyze the security of PriSPA and conduct comprehensive experiments to prove its security, effectiveness and efficiency. Based on the comparisons with the raw traffic forecasting framework, we observe that PriSPA improves the precision of the model with 17.6% - 32.7% error reduction.
Junwei Zhang 0008, Zhuo Ma 0001, Ning Lu 0005, Teng Li 0003, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.5
2024 Multi-Party Private Edge Computing for Collaborative Quantitative Exposure Detection of Endemic Diseases
abstract
Facing the global threat of endemic diseases, utilizing edge computing for exposure detection enables efficient monitoring of the dynamic distribution of infected patient groups across regions, enhancing the management and control of these diseases. Employing the quantitative exposure detection of endemic diseases, regions seek to reconcile patient information collected through mobile devices, aiming to obtain statistical and analytical results based on the intersection of patient lists. In this paper, we propose a privacy-preserving scheme for the collaborative quantitative exposure detection of endemic diseases, which ensures each region to only learn the statistical results, without any information about other regions' datasets. Our scheme is fundamentally achieved through Circuit-based Private Set Intersection (Circuit-PSI) that can compute functions over the set intersection without disclosing the intersection itself. However, the state-of-the-art solution involves a laborious process in which one party iteratively compares its elements with those of others, which leads to a significantly high communication complexity. Therefore, we introduce a novel multi-party protocol that can diminish the communication overhead of circuit-PSI through a skillful decoupling of the comparison complexity from the number of parties. To achieve this, we design a multiparty oblivious encoding scheme, which can prevent any party from inferring any private info through the encoded data. By filtering out the repeated elements, the comparison complexity is independent of the number of parties. Furthermore, to address scenarios involving patient information with additional attributes, we extend our protocol to include payloads by developing a lightweight multiparty data mapping algorithm. Our extensive experiments show that compared to prior works, our protocol achieves a substantial reduction in communication overhead by 6.4×, and runs 1.2× faster in the LAN setting and 3.1× in the WAN setting.
Zhuo Ma 0001, Yang Liu 0118, Teng Li 0003, Zuobin Ying, Bingsheng Zhang
IEEE Trans. Mob. Comput.4
2023 Outsourced Privacy-Preserving Data Alignment on Vertically Partitioned Database
abstract
In the context of real-world secure outsourced computations, private data alignment has been always the essential preprocessing step. However, current private data alignment schemes, mainly circuit-based, suffer from high communication overhead and often need to transfer potentially gigabytes of data. In this paper, we propose a lightweight private data alignment protocol (called SC-PSI) that can overcome the bottleneck of communication. Specifically, SC-PSI involves four phases of computations, including data preprocessing, data outsourcing, private set member (PSM) evaluation and circuit computation (CC). Like prior works, the major overhead of SC-PSI mainly lies in the latter two phases. The improvement is SC-PSI utilizes the function secret sharing technique to develop the PSM protocol, which avoids the multiple rounds of communication to compute intersection set members. Moreover, benefited from our specially designed PSM protocol, SC-PSI does not to execute complex secure comparison circuits in the CC phase. Experimentally, we validate that compared to prior works, SC-PSI can save around 61.39% running time and 89.61% communication overhead.
Cui Hu, Bin Xiao 0002, Yang Liu 0118, Teng Li 0003, Zhuo Ma 0001, Jianfeng Ma 0001
IEEE Trans. Big Data5
2023 Joint Controller Placement and Control-Service Connection in Hybrid-Band Control
abstract
By separating the forwarding and control planes, Software-Defined Networking (SDN) facilitates flexible traffic routing and network management for a service network. Because of the impact of controller deployment on message transmission distances and network latency, controller placement problems have drawn many researchers’ attention. However, assumptions in most existing research that all control packets are either transmitted in the service network (i.e., in-band control) or through predetermined control-service connection (i.e., out-of-band control) are not reasonable due to bandwidth resources occupation on the service network or high construction costs. In this paper, we are the first to jointly discuss the controller placement and control-service connection problem for latency minimization in the hybrid-band control mode, which is essentially a bi-level programming optimization problem. Specifically, we introduce auxiliary variables to simplify the above NP-hard problem. Next, Generalized Benders decomposition is used to obtain an optimal solution in theory. In addition, we propose a time-efficient fireworks algorithm with a little latency increment for large-scale networks. Extensive evaluations show that the two proposed algorithms accomplish the desired objectives and respectively achieve up to 35% and 25% latency decrement than greedy algorithms.
Xuewen Dong, Lingtao Xue, Zhiwei Zhang 0004, Yushu Zhang 0001, Teng Li 0003, Zhichao You, Yulong Shen 0001
IEEE Trans. Cloud Comput.5
2023 Trust-Based Secure Multi-Cloud Collaboration Framework in Cloud-Fog-Assisted IoT
abstract
Cloud-Fog-Assisted Internet-of-Things (IoT) is a convincing paradigm to provide users with on-demand and low-latency services through Fog nodes in the edge of multiple clouds (Multi-Cloud). Multi-Cloud is a scalable multi-domain service-oriented net-centric system and can respond to complicated user requirements leveraging Multi-Cloud Service Composition (MCSC). However, in MCSC, user security can be easily compromised by untrusted and curious cloud service providers that may collect and violate the privacy and other essential assets of cloud users. Although many trust-based MCSC solutions have been proposed to seek a trustworthy composite service with highest trust level, most of them are vulnerable to malicious users intending to break through the clouds and inflict serious data leakage or asset damage. Considering these security concerns on both malicious users and untrusted service providers, in this article, we present a trust-based secure multi-cloud collaboration framework for Cloud-Fog-Assisted IoT systems. Specifically, to guarantee the security of users, we develop a role-based trust evaluation method to enhance the trustworthiness of MCSC. To preserve the security of services, we design an efficient user authentication scheme and a secure collaboration scheme to provide collaborative user authentication and access control mechanism for MCSC. We develop a proof of concept implementation for our framework and demonstrate its practicability by performance evaluation with extensive experiments.
Jiawei Zhang 0011, Teng Li 0003, Zuobin Ying, Jianfeng Ma 0001
IEEE Trans. Cloud Comput.2
2023 DeepAG: Attack Graph Construction and Threats Prediction With Bi-Directional Deep Learning
abstract
The complicated multi-step attacks, such as Advanced Persistent Threats (APTs), have brought considerable threats to cybersecurity because they are naturally varied and complex. Therefore, studying the strategies of adversaries and making predictions are still significant challenges for attack prevention. To address these problems, we proposeDeepAG, a framework utilizing system logs to detect threats and predict the attack paths.DeepAGleverages transformer models to novelly detect APT attack sequences by modeling semantic information of system logs. On the other hand,DeepAGutilizes Long Short-Term Memory (LSTM) network to propose bi-directional prediction for attack paths, which achieves higher performance than traditional BiLSTM. In addition, with previously detected attack sequences and predicted paths,DeepAGconstructs the attack graphs that attackers may follow to compromise the network. Furthermore,DeepAGoffers the mechanisms of Out-Of-Vocabulary (OOV) word processor and online update respectively to adapt new attack patterns that show up during detection and prediction stages. The experiments on open-source data sets show that more than 99% of over 15000 sequences can be detected accurately byDeepAG. Moreover,DeepAGcan improve the baseline by 11.166% of accuracy in terms of prediction.
Teng Li 0003, Ya Jiang, Chi Lin 0001, Mohammad S. Obaidat, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.1
2023 Reveal Your Images: Gradient Leakage Attack Against Unbiased Sampling-Based Secure Aggregation
abstract
Recently, some Unbiased Gradient Sampling-based (UGS) methods have been proposed to enhance the security and efficiency of federated learning through crafted unbiased random transformation and sampling, such as MinMax Sampling in SIGMOD ’22. In this paper, we propose a novel attack, GLAUS, to show that UGS is not as secure as claimed in these works and is still vulnerable to the gradient leakage attack (GLA). Specifically, we demonstrate an idea to approximately infer the gradient for GLA in the context of the UGS scenario where the real gradient is not available. Once the gradient is approximately obtained, the security of the UGS frameworks is downgraded to that of the original federated learning. The approximate gradient is refined by the following steps: 1)narrow the gradient searching rangeto the finite set; 2)obtain the magnitudeof each gradient value approximately; 3)revise the gradient signs. Versus the failure of existing attacks, extensive experiments on six datasets show that our attack is effective in reconstructing private datapoints with pixel-wise accuracy on four network sizes and three image resolutions. Finally, we show how to defend against GLAUS while maintaining the high efficiency of UGS and only introducing an additional step to hide the sampled gradient indices.
Yilong Yang 0004, Zhuo Ma 0001, Bin Xiao 0002, Yang Liu 0118, Teng Li 0003, Junwei Zhang 0008
IEEE Trans. Knowl. Data Eng.5
2023 Near Optimal Charging Schedule for 3-D Wireless Rechargeable Sensor Networks
abstract
Wireless rechargeable sensor networks (WRSNs) have become a hot research issue owing to the breakthrough of wireless power transfer (WPT) technology. Previous theoretical schemes are mostly designed for 2-D networks, and few of them are tailored for 3-D scenarios, making them not suitable for wide adoptions in practical applications. In this paper, we address the issue of how to serve a 3-D WRSN with an unmanned aerial vehicle (UAV). Our main concern is to maximize the charged energy for sensors supplied by the UAV, which has energy constraints. We respectively develop a spatial discretization scheme to construct a finite feasible set of charging spots for the UAV in a 3-D environment and a temporal discretization scheme to determine the appropriate charging duration for each charging spot. Then, we reduce the problem into a submodular maximization problem with routing constraints and present a cost-efficient algorithm (CEA) with a provable approximation ratio to solve it. Finally, test-bed experiments are conducted to show the feasibility of our schemes in practical scenarios. Extensive simulations are taken to verify the superior performance of our algorithm in charged energy and robustness. The charged energy of our scheme outperforms other competing methods by at least$18.2\%$.
Chi Lin 0001, Wei Yang 0039, Haipeng Dai 0001, Teng Li 0003, Yi Wang 0037, Lei Wang 0005, Guowei Wu 0001, Qiang Zhang 0008
IEEE Trans. Mob. Comput.4
2023 Hierarchical and Multi-Group Data Sharing for Cloud-Assisted Industrial Internet of Things
abstract
With the development of Industrial Internet of Things (IIoT) and 5G, massive data are easily collected and transmitted in cloud. Therefore, it is critical to guarantee the security of data sharing. In IIoT applications, the users of a group are in hierarchical structure and they intend to access data by external groups, which requires fine-grained access control, data authenticity and data retrieval. However, existing approaches rarely provide such solutions to satisfy these requirements simultaneously. In this paper, we propose an efficient hierarchical and multi-group data sharing framework (HMGDSF) in cloud-assisted IIoT. Apart from fine-grained data access control for hierarchical users with key leakage resilience, HMGDSF achieves user anonymity with traceability and keyword-based data retrieval. Moreover, the approach supports data authenticity and integrity verification for multi-group data sharing by integrating group signature mechanism. We provide proof for the security of framework and demonstrate its efficiency and practicability by extensive evaluations.
Teng Li 0003, Jiawei Zhang 0011, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Serv. Comput.1
2022 I Can Still Observe You: Flow-level Behavior Fingerprinting for Online Social Network
abstract
The privacy of online social networks (OSNs) remains a major concern for today's Internet. Researchers have demonstrated that by analyzing inter-packet or packet-level network traffic, a third-party analyzer is able to fingerprint a user's OSN behavior information even when the traffic is encrypted. In this paper, we propose a learning-based approach that steps further to perform OSN behavior fingerprinting only through highly compressed, flow-level network traffic (e.g., NetFlow). By preprocessing flow records, segmenting traffic flows into bursts, and leveraging a long short-term memory network to classify the bursts, our approach can identify major OSN behaviors (e.g., Facebook post, Twitter Read, Weibo video, etc.) with nearly 90% accuracy. Compared with packet-level fingerprinting approaches, our approach significantly improves the fingerprinting efficiency in evaluations, making large-scale OSN usage monitoring feasible only with limited computing resources and coarse-grained network traffic. This work also reveals the huge risks facing privacy of OSN users on today's Internet today.
Yebo Feng, Jian-Zhen Luo, Chengyan Ma 0001, Teng Li 0003, Liang Hui
GLOBECOM4
2022 Reliable PUF-based mutual authentication protocol for UAVs towards multi-domain environment
Chuang Tian 0001, Qi Jiang 0001, Teng Li 0003, Junwei Zhang 0008, Ning Xi 0002, Jianfeng Ma 0001
Comput. Networks3
2022 Energy-Efficient and Secure Communication Toward UAV Networks
abstract
Wireless networks ensure the unmanned aerial vehicles (UAVs) communicate and cooperate with each other, which plays an indispensable role among UAVs. The two crucial challenges in UAV wireless networks are energy saving and security. The current lightweight communication approaches lead to insufficient robustness of the encrypted transmission that is insecure. To address this issue, we propose a secure transmission approach with energy efficiency toward UAVs networks. We design a lightweight symmetric encryption algorithm based on SM4 and the relevant key negotiation and update mechanism to protect the confidentiality of communication contents. Moreover, a modified aggregative BLS signature scheme, together with the Merkle Hash tree (MHT), is introduced to guarantee the integrity and authenticity of data packets in transmission. Furthermore, we propose an online/offline revocable identity-based group signature (OORIBGS) scheme and integrate it into our framework for UAV anonymity, traceability, as well as revocability with small key management cost and high efficiency. We give detailed security analysis and prove that our proposal has the properties of data confidentiality, integrity, and authenticity, as well as identity traceability and anonymity. Moreover, we apply our approach in the UAVs networks and evaluate the runtime and anti-attack performance. The experimental results show that the proposed method can be effectively used in UAVs secure communication.
Teng Li 0003, Jiawei Zhang 0011, Mohammad S. Obaidat, Chi Lin 0001, Yangxu Lin, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Internet Things J.1
2022 CoAvoid: Secure, Privacy-Preserved Tracing of Contacts for Infectious Diseases
abstract
To fight against infectious diseases (e.g., SARS, COVID-19, Ebola, etc.), government agencies, technology companies and health institutes have launched various contact tracing approaches to identify and notify the people exposed to infection sources. However, existing tracing approaches can lead to severe privacy and security concerns, thereby preventing their secure and widespread use among communities. To tackle these problems, this paper proposesCoAvoid, an edge-based, privacy-preserved contact tracing system that features good dependability and usability.CoAvoidleverages the Google/Apple Exposure Notification (GAEN) API to achieve decent device compatibility and operating efficiency. It utilizes Bluetooth Low Energy (BLE) to detect close contact with other people and leverages GPS with fine-grained matching algorithms to verify user information. In addition, to enhance privacy protection,CoAvoidapplies fuzzification and obfuscation measures to shelter sensitive data, making both servers and users agnostic to information of both low and high-risk populations. The evaluation demonstrates good efficacy and security of CoAvoid. Compared with four state-of-the-art contact tracing applications,CoAvoidcan reduce the size of upload data by at least 90% and reduce the verification time by 92%. More importantly,CoAvoidcan preserve user privacy and resist replay and wormhole attacks in all analysis scenarios.
Teng Li 0003, Siwei Yin, Yebo Feng, Lei Jiao 0002, Yulong Shen 0001, Jianfeng Ma 0001
IEEE J. Sel. Areas Commun.1
2021 Blockchain-Based Fine-Grained Data Sharing for Multiple Groups in Internet of Things
abstract
Cloud-based Internet of Things, which is considered as a promising paradigm these days, can provide various applications for our society. However, as massive sensitive and private data in IoT devices are collected and outsourced to cloud for data storage, processing, or sharing for cost saving, the data security has become a bottleneck for its further development. Moreover, in many large-scale IoT systems, multiple group data sharing is practical for users. Thus, how to ensure data security in multiple group data sharing remains an open problem, especially the fine-grained access control and data integrity verification with public auditing. Therefore, in this paper, we propose a blockchain-based fine-grained data sharing scheme for multiple groups in cloud-based IoT systems. In particular, we design a novel multiauthority large universe CP-ABE scheme to guarantee the fine-grained access control and data integrity across multiple groups by integrating group signature into our scheme. Moreover, to ease the need for a trusted third auditor in traditional data public auditing schemes, we introduce blockchain technique to enable a distributed data public auditing. In addition, with the group signature, our scheme also realizes anonymity and traitor tracing. The security analysis and performance evaluation show that our scheme is practical for large-scale IoT systems.
Teng Li 0003, Jiawei Zhang 0011, Yangxu Lin, Shengkai Zhang, Jianfeng Ma 0001
Secur. Commun. Networks1
2021 Efficient Hierarchical and Time-Sensitive Data Sharing with User Revocation in Mobile Crowdsensing
abstract
Recently, cloud-based mobile crowdsensing (MCS) has developed into a promising paradigm which can provide convenient data sensing, collection, storage, and sharing services for resource-constrained terminates. Nevertheless, it also inflicts many security concerns such as illegal access toward user secret and privacy. To protect shared data against unauthorized accesses, many studies on Ciphertext-Policy Attribute-Based Encryption (CP-ABE) have been proposed to achieve data sharing granularity. However, providing a scalable and time-sensitive data-sharing scheme across hierarchical users with compound attribute sets and revocability remains a big issue. In this paper, we investigate this challenge and propose a hierarchical and time-sensitive CP-ABE scheme, named HTR-DAC, which is characteristics of time-sensitive data access control with scalability, revocability, and high efficiency. Particularly, we propose a time-sensitive CP-ABE for hierarchical structured users with recursive attribute sets. Moreover, we design a robust revocable mechanism to achieve direct user revocation in our scheme. We also integrate verifiable outsourced decryption to improve efficiency and guarantee correctness in decryption procedure. Extensive security and performance analysis is presented to demonstrate the security requirement satisfaction and high efficiency for our data-sharing scheme in MCS.
Jiawei Zhang 0011, Jianfeng Ma 0001, Teng Li 0003, Qi Jiang 0001
Secur. Commun. Networks3
2021 Enabling Efficient Decentralized and Privacy Preserving Data Sharing in Mobile Cloud Computing
abstract
Mobile cloud computing (MCC) is embracing rapid development these days and able to provide data outsourcing and sharing services for cloud users with pervasively smart mobile devices. Although these services bring various conveniences, many security concerns such as illegally access and user privacy leakage are inflicted. Aiming to protect the security of cloud data sharing against unauthorized accesses, many studies have been conducted for fine‐grained access control using ciphertext‐policy attribute‐based encryption (CP‐ABE). However, a practical and secure data sharing scheme that simultaneously supports fine‐grained access control, large university, key escrow free, and privacy protection in MCC with expressive access policy, high efficiency, verifiability, and exculpability on resource‐limited mobile devices has not been fully explored yet. Therefore, we investigate the challenge and propose an Efficient and Multiauthority Large Universe Policy‐Hiding Data Sharing (EMA‐LUPHDS) scheme. In this scheme, we employ fully hidden policy to preserve the user privacy in access policy. To adapt to large scale and distributed MCC environment, we optimize multiauthority CP‐ABE to be compatible with large attribute universe. Meanwhile, for the efficiency purpose, online/offline and verifiable outsourced decryption techniques with exculpability are leveraged in our scheme. In the end, we demonstrate the flexibility and high efficiency of our proposal for data sharing in MCC by extensive performance evaluation.
Jiawei Zhang 0011, Ning Lu 0005, Teng Li 0003, Jianfeng Ma 0001
Wirel. Commun. Mob. Comput.3
2020 A secured TPM integration scheme towards smart embedded system based collaboration network
Di Lu 0001, Ruidong Han, Yue Wang 0063, Yongzhi Wang 0001, Xuewen Dong, XinDi Ma, Teng Li 0003, Jianfeng Ma 0001
Comput. Secur.7
2019 AClog: Attack Chain Construction Based on Log Correlation
abstract
Before the final attack happens, clandestine attackers conduct sequenced stages for being stealthy and elusive. These attacks can leave clues in several different log files. Howeverexisting approaches can only detect the anomalies using single type of log and fail to reveal all of the attack steps through log integration and correlation. Such methods can hardly detect the relationships among events and prevent the attack in advance. Additionally, traditional machine learning or data mining in log analysis has a high overhead in computing which is impractically applied in a real product or system. To address these problems, we present AClog, a multiple log correlated analysis system to construct the attack chain. Inspired by penetration testing and social network analysis, we transfer the attack provenance as an event relationship discover problem. We use different logs to form the steps of the system and regard them as the event sequences before the attack. Then, we leverage Fast Linear SVM and Longest Common Subsequences to find out the regular steps before the attack. Finally, we spot the corresponding log sequences to identify the pre- attackk steps proactively. We apply our approach in the attack prediction of a cloud computing platform and a university network. The results show that the proposed method can effectively and precisely construct the attack steps and identify the corresponding syslogs.
Teng Li 0003, Jianfeng Ma 0001, Qingqi Pei, Yulong Shen 0001, Chi Lin 0001, Siqi Ma 0001, Mohammad S. Obaidat
GLOBECOM1
2019 Privacy-Preserving Verification and Root-Cause Tracing Towards UAV Social Networks
abstract
Unmanned Aerial Vehicles (UAV) have rapidly developed and been widely applied to military and civilian applications in recent years. Anomaly Detections and finding out the root causes are critically important for UAV social network security. In the UAV social networks, the drone can communicate with one another directly in a form of leading flights with followers during a far away mission. The ground controller cannot get their information directly. Besides, none of the works consider the privacy protection and anomaly root cause tracing during the distributed detection. This paper presents a self-verification approach among UAV flights which can check whether the flights have honestly obeyed the orders or suffered the anomalies. Besides, we do the verification without looking through the plaintext records or data of the drones. Finally, to instruct the drones to solve the problems, we trace the fundamental root causes leading to the anomalies by learning the fault tree. We apply our approach on raw UAV social network data and align our experiment with two former works as baselines for comparison. Our approach can reduce the time cost of verification from exponential growth to linear growth and improve the tracing accuracy rate around 4.3% higher than the former work.
Teng Li 0003, Jianfeng Ma 0001, Qingqi Pei, Chengyan Ma 0001, Dawei Wei, Cong Sun 0001
ICC1
2019 SRDPV: secure route discovery and privacy-preserving verification in MANETs
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001
Wirel. Networks1
2018 Dlog: diagnosing router events with syslogs for anomaly detection
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001
J. Supercomput.1
2017 Data-Oriented Instrumentation against Information Leakages of Android Applications
abstract
As one of the most prominent threat, information leakages usually take sensitive data from some private sources and improperly release the data through malicious or misused method invocations and intercommunications. As a countermeasure against this threat, a number of detection approaches have been developed based on static analysis, esp. taint analysis. But we still have not reached a satisfactory solution to the patching and mitigation against this threat. In this paper, we propose an approach to automatically instrument malicious Android applications with cryptographic primitives and data randomization. With the help of an off-the-shelf taint analyzer, we detect the parts of code that might leak private information. In order to mitigate these information leakages, the standard cipher transformations and randomization are used to enforce different security policies according to the positions of related information sinks and intermediate system calls along malicious flow paths. The evaluation on different benchmark suites and real-world applications demonstrates that our approach can avoid false positives and mitigate around 91% information leakages in real applications, with acceptable cost on analysis and instrumentations affordable by desktops.
Cong Sun 0001, Pengbin Feng, Teng Li 0003, Jianfeng Ma 0001
COMPSAC (2)3
2017 NetPro: detecting attacks in MANET routing with provenance and verification
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001
Sci. China Inf. Sci.1
2016 CDRep: Automatic Repair of Cryptographic Misuses in Android Applications
abstract
Cryptography is increasingly being used in mobile applications to provide various security services; from user authentication, data privacy, to secure communications. However, there are plenty of mistakes that developers could accidentally make when using cryptography in their mobile apps and such mistakes can lead to a false sense of security. Recent research efforts indeed show that a significant portion of mobile apps in both Android and iOS platforms misused cryptographic APIs. In this paper, we present CDRep, a tool for automatically repairing cryptographic misuse defects in Android apps. We classify such defects into seven types and manually assemble the corresponding fix patterns based on the best practices in cryptographic implementations. CDRep consists of two phases, a detection phase which identifies defect locations in a mobile app and a repair phase which repairs the vulnerable app automatically. In our validation, CDRep is able to successfully repair 94.5% of 1,262 vulnerable apps. Furthermore, CDRep is lightweight, the average runtime to generate a patch is merely 19.3 seconds and the size of a repaired app increases by only 0.667% on average.
Siqi Ma 0001, David Lo 0001, Teng Li 0003, Robert H. Deng
AsiaCCS3
2015 CRVad: Confidential Reasoning and Verification Towards Secure Routing in Ad Hoc Networks
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001
ICA3PP (3)1