Qingni Shen

dblp:11/325 · DBLP profile ↗
← Back
97ranked-venue papers
3as first author
58since 2021 · last 2026
0000-0002-0605-6043ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 2 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 19 · 19 since 2021Systems, architecture and hardware · 13 · 10 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 10 since 2021Artificial intelligence and machine learning · 8 · 8 since 2021Software engineering, systems software and programming languages · 8 · 6 since 2021Computer networks · 7 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021
YearPublicationVenuePosition
2026 Towards Practical Interrupt Side-Channel Attacks on macOS for Apple Silicon
Xin Zhang 0110, Qingni Shen, Zhi Zhang 0001, Trevor E. Carlson
ISCA5
2026 FedSRD: Sparsify-Reconstruct-Decompose for Communication-Efficient Federated Large Language Models Fine-Tuning
abstract
The current paradigm of training large language models (LLMs) on public available Web data is becoming unsustainable as high-quality data sources in specialized domains near exhaustion. Federated Learning (FL) emerges as a practical solution for the next generation of AI on a decentralized Web, enabling privacy-preserving collaborative fine-tuning on decentralized private data. While Low-Rank Adaptation (LoRA) is standard for efficient fine-tuning, its federated application faces a critical bottleneck: communication overhead under heterogeneous network conditions. Structural redundancy in LoRA parameters increases communication costs and causes aggregation conflicts. To address this, we propose FedSRD, a Sparsify-Reconstruct-Decompose framework for communication-efficient federated LLM fine-tuning. We introduce importance-aware sparsification to reduce the upload parameter count while preserving the structural integrity of LoRA updates. The server aggregates updates in full-rank space to mitigate conflicts, then decomposes the global update into a sparse low-rank format for broadcast, ensuring a symmetrically efficient cycle. We also propose an efficient variant, FedSRD-e, to reduce computational overhead. Experiments on 10 benchmarks show our framework significantly reduces communication costs by up to 90% while improving performance on heterogeneous client data.
Guochen Yan, Luyuan Xie, Qingni Shen, Yuejian Fang, Zhonghai Wu
WWW3
2026 MUXLeak: Exploiting Multiplexers as a Power Side Channel Against Multitenant FPGAs
abstract
FPGA cloud acceleration, or “FPGA as a Service” (FaaS), offered by AWS, Microsoft Azure, Alibaba Cloud, and Huawei Cloud, has become a promising solution for tackling complex, compute-intensive workloads. It targets applications such as genomics, image and video processing, electronic design automation, compression, and big data analytics. While multi-tenant FPGAs significantly enhances resource utilization efficiency, it faces security threats from power side channels, where attackers craft a malicious circuit to detect voltage fluctuations from victim circuits. Observing that all the crafted circuits exploit either Carry Chain or Look-up Table to sense voltage fluctuations, existing defenses have focused on detecting the malicious use of the two basic FPGA computing resources. However, it remains unclear whether such countermeasures are sufficient to address the growing threat of power side channels in multi-tenant FPGAs. In this paper, we reveal MUXLeak, a novel on-chip sensor that exploitsMultiplexer (MUX)to craft a stealthy power side channel, which bypasses existing countermeasures. Particularly, we perform a thorough analysis of basic resources within an FPGA unit and unveil thatMUX, another basic resource,has never been exploited before. More importantly, it can be directly initialized on Xilinx FPGAs and its incurred signal propagation delay demonstrates an inverse correlation with changes in voltage, making itself exploitable for a new power side channel leakage. In our evaluation, we test MUXLeak on three Xilinx FPGA products and use TDC [18] (i.e., the most sensitive on-chip sensor until now) to benchmark the sensitivity of MUXLeak. Our results show that MUXLeak has achieved the same level of sensitivity as TDC to voltage fluctuations. Further, we apply MUXLeak to mount two attacks, i.e., extracting AES keys within 2.54 hours and stealing DNN model architectures with an accuracy of over 90%.
Xin Zhang 0110, Zhi Zhang 0001, Qingni Shen, Yansong Gao 0001, Jinhua Cui 0002, Yusi Feng, Zhonghai Wu, Derek Abbott
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2025 FedVCK: Non-IID Robust and Communication-Efficient Federated Learning via Valuable Condensed Knowledge for Medical Image Analysis
abstract
Federated learning has become a promising solution for collaboration among medical institutions. However, data owned by each institution would be highly heterogeneous and the distribution is always non-independent and identical distribution (non-IID), resulting in client drift and unsatisfactory performance. Despite existing federated learning methods attempting to solve the non-IID problems, they still show marginal advantages but rely on frequent communication which would incur high costs and privacy concerns. In this paper, we propose a novel federated learning method: Federated learning via Valuable Condensed Knowledge (FedVCK). We enhance the quality of condensed knowledge and select the most necessary knowledge guided by models, to tackle the non-IID problem within limited communication budgets effectively. Specifically, on the client side, we condense the knowledge of each client into a small dataset and further enhance the condensation procedure with latent distribution constraints, facilitating the effective capture of high-quality knowledge. During each round, we specifically target and condense knowledge that has not been assimilated by the current model, thereby preventing unnecessary repetition of homogeneous knowledge and minimizing the frequency of communications required. On the server side, we propose relational supervised contrastive learning to provide more supervision signals to aid the global model updating. Comprehensive experiments across various medical tasks show that FedVCK can outperform state-of-the-art methods, demonstrating that it's non-IID robust and communication-efficient.
Guochen Yan, Luyuan Xie, Xinyi Gao 0001, Wentao Zhang 0001, Qingni Shen, Yuejian Fang, Zhonghai Wu
AAAI5
2025 HyperHammer: Breaking Free from KVM-Enforced Isolation
abstract
Hardware-assisted virtualization is a key enabler of the modern cloud. It decouples virtual machine execution from the hardware it runs on, allowing increased flexibility through services such as dynamic hardware provisioning and live migration. Underlying this flexibility is the security promise that guest virtual machines are isolated from each other. However, due to the level of sharing between VMs, hardware vulnerabilities present a serious threat to this usage. One such vulnerability is Rowhammer, which allows attackers to modify the contents of memory to which they have no access. While the attack has been known for over a decade, published applications against such environments are limited, compromising only co-resident VMs, but not the hypervisor. Moreover, due to security concerns, a key component enabling their attack has been disabled. Hence, this attack is no longer applicable in a contemporary virtualized environment.
Wei Chen 0006, Zhi Zhang 0001, Xin Zhang 0110, Qingni Shen, Yuval Yarom, Daniel Genkin, Zhe Wang 0017
ASPLOS (2)4
2025 Wildcarded Identity-Based Inner Product Encryption Based on SM9
Zinan Shen, Xinyu Feng 0002, Cong Li 0024, Qingni Shen
Inscrypt (1)5
2025 dFLMoE: Decentralized Federated Learning via Mixture of Experts for Medical Data Analysis
abstract
Federated learning has wide applications in the medical field. It enables knowledge sharing among different healthcare institutes while protecting patients’ privacy. However, existing federated learning systems are typically centralized, requiring clients to upload client-specific knowledge to a central server for aggregation. This centralized approach would integrate the knowledge from each client into a centralized server, and the knowledge would be already undermined during the centralized integration before it reaches back to each client. Besides, the centralized approach also creates a dependency on the central server, which may affect training stability if the server malfunctions or connections are unstable. To address these issues, we propose a decentralized federated learning framework named dFLMoE. In our framework, clients directly exchange lightweight head models with each other. After exchanging, each client treats both local and received head models as individual experts, and utilizes a client-specific Mixture of Experts (MoE) approach to make collective decisions. This design not only reduces the knowledge damage with client-specific aggregations but also removes the dependency on the central server to enhance the robustness of the framework. We validate our framework on multiple medical tasks, demonstrating that our method evidently outperforms state-of-the-art approaches under both model homogeneity and heterogeneity settings.
Luyuan Xie, Tianyu Luan, Wenyuan Cai, Guochen Yan, Nan Xi, Yuejian Fang, Qingni Shen, Zhonghai Wu, Junsong Yuan 0001
CVPR8
2025 ZK-Hammer: Leaking Secrets from Zero-Knowledge Proofs via Rowhammer
abstract
Zero-knowledge succinct non-interactive arguments of knowledge (zk-SNARK) schemes have been a promising technique in verified computation. Zk-SNARK schemes were designed to be mathematically secure against cryptographic attacks and it remains unclear whether they are vulnerable to fault injection attacks. In this work, we provide a positive answer by presenting ZK-Hammer, which leaks secrets from zk-SNARK schemes via Rowhammer. We incur faults in the exponentiate variables in the Quadratic Arithmetic Program (QAP) problem. Then we analyze the faulty proof using the bilinear pairing technique and manage to recover the secret. We employ a Rowhammer fault evaluation in libsnark and identify 3 CVEs.
Junkai Liang, Xin Zhang 0110, Daqi Hu, Qingni Shen, Yuejian Fang, Zhonghai Wu
DAC4
2025 AmpereBleed: Exploiting On-chip Current Sensors for Circuit-Free Attacks on ARM-FPGA SoCs
abstract
FPGAs offer superior energy efficiency and performance in parallel computing but are vulnerable to remote power side-channel attacks. Existing attacks rely on assumptions of coresident crafted circuits and shared power delivery networks, limiting their practicality in real-world scenarios. In this paper, we present AmpereBleed, a novel current-based side-channel attack that exploits widely available INA226 sensors in ARMFPGA SoCs, bypassing the aforementioned two assumptions. AmpereBleed achieves $261 \times$ greater variations to victim activities compared to the popular ring oscillator (RO) circuit, fingerprints DNN models on the Xilinx Deep Learning Processor Unit (DPU) with $\mathbf{9 9. 7 \%}$ accuracy, and distinguishes the Hamming weights of RSA-1024 keys.
Xin Zhang 0110, Qingni Shen, Zhi Zhang 0001, Yansong Gao 0001, Zhonghai Wu, Trevor E. Carlson
DAC4
2025 LeakyDSP: Exploiting Digital Signal Processing Blocks to Sense Voltage Fluctuations in FPGAs
abstract
In recent years, cloud providers are dedicated to enabling FPGA multi-tenancy to improve resource utilization, but this new sharing model introduces power side-channel threats, where attackers detect voltage fluctuations from colocated circuits. This paper proposes LeakyDSP, a novel onchip sensor that maliciously configures DSP blocks to sense fine-grained voltage fluctuations but is overlooked by existing studies. Our experimental results show that LeakyDSP achieves high sensitivity to voltage fluctuations and strong robustness to different placements. Besides, we apply LeakyDSP to extract full AES keys with $25 \mathrm{k}-78 \mathrm{k}$ traces and build covert channels with a high transmission rate of 247.94 bit/s.
Xin Zhang 0110, Qingni Shen, Zhi Zhang 0001, Yansong Gao 0001, Zhonghai Wu, Trevor E. Carlson
DAC4
2025 SACK: Enabling Environmental Situation-Aware Access Control for Vehicles in Linux Kernel
abstract
Connected and autonomous vehicles (CAVs) operate in open and evolving environments, which require timely and adaptive permission restriction to address dynamic risks that arise from changes in environmental situations (hereinafter referred to as situations), such as emergency situations due to vehicle crashes. Enforcing situation-aware access control is an effective approach to support adaptive permission restriction. Current works mainly implement situation-aware access control in the permission framework and API monitoring in user space. They are vulnerable to being bypassed and are coarse-grained. Autonomous systems have widely adopted mandatory access control (MAC) to configure and enforce system-wide and fine-grained access control policies. However, the MA$C$supported by Linux security modules (LSM) relies on predefined security contexts (e.g., type) and relatively fixed permission transition conditions (e.g., exec syscall), which lacks consideration of environmental factors. To address these issues, we propose a Situation-aware Access Control framework in the Kernel (SACK), which enforces adaptive permission restriction based on environmental factors for CAVs. Incorporating environmental situations into the LSM framework is not straightforward. SACK introduces situation states as a new security context for abstracting environmental factors in the kernel. Subsequently, SACK utilizes a situation state machine to implement new adaptive permission transitions triggered by situation events. In addition, SACK provides a novel situation-aware policy language that links specific user space permissions to MAC rules while maintaining compatibility with other LSMs such as AppArmor. We develop two prototypes: an independent SACK with its own policies and a SACK-enhanced AppArmor that adaptively updates the corresponding policies of AppArmor. The experimental results demonstrate that SACK can efficiently enforce situation-adaptive permissions with negliaible runtime overhead.
Boyan Chen, Qingni Shen, Lei Xue 0001, Jiarui She, Xiapu Luo, Xin Zhang 0110, Wei Chen 0006, Zhonghai Wu
DATE2
2025 RPPFL: Robust and Privacy-Preserving Federated Learning via Trusted Execution Environments
abstract
Federated Learning (FL) is a distributed framework that enables multi-participant collaborative model training without the need for data sharing. Despite its advantages, FL is vulnerable to poisoning and inference attacks, which compromise model accuracy and data privacy. Trusted execution environments (TEEs) offer a potential solution by providing a secure and isolated execution space to address these security and privacy concerns in FL. However, existing TEE-based FL schemes often suffer from reduced training speed and compromised model accuracy. To mitigate these issues, we propose a robust and privacy-preserving framework for federated learning (RPPFL) that leverages TEE and pseudorandom masking. In our approach, a trusted local model is trained on a secure subset of local data within the client-side TEE, which is then used for anomaly detection to resist poisoning attacks. Additionally, we employ pseudorandom masking to obfuscate local updates and global parameters. Experimental results indicate that RPPFL effectively counters both poisoning and inference attacks, with only a minimal decrease in training speed and no adverse impact on model accuracy. Compared to full-TEE approaches, our method improved local training efficiency by 10× , with less than a 9% loss in model performance under poisoning attacks.
Guangpu Chen, Xinyu Feng 0002, Qingni Shen, Zhonghai Wu
ICASSP5
2025 Efficient Input-Level Backdoor Defense on Text-to-Image Synthesis via Neuron Activation Variation
abstract
In recent years, text-to-image (T2I) diffusion models have gained significant attention for their ability to generate high quality images reflecting text prompts. However, their growing popularity has also led to the emergence of backdoor threats, posing substantial risks. Currently, effective defense strategies against such threats are lacking due to the diversity of backdoor targets in T2I synthesis. In this paper, we propose NaviT2I, an efficient input-level backdoor defense framework against diverse T2I backdoors. Our approach is based on the new observation that trigger tokens tend to induce significant neuron activation variation in the early stage of the diffusion generation process, a phenomenon we term Early-step Activation Variation. Leveraging this insight, NaviT2I navigates T2I models to prevent malicious inputs by analyzing Neuron activation variations caused by input tokens. Extensive experiments show that NaviT2I significantly outperforms the baselines in both effectiveness and efficiency across diverse datasets, various T2I backdoors, and different model architectures including UNet and DiT. Furthermore, we show that our method remains effective under potential adaptive attacks.
Shengfang Zhai, Yue Liu 0008, Huanran Chen, Zhihua Tian, Wenjie Qu 0001, Qingni Shen, Ruoxi Jia 0001, Yinpeng Dong, Jiaheng Zhang
ICCV7
2025 MA-RAG: Automating Role Engineering for RESTful APIs with Multi-Head Attention and Retrieval-Augmented Generation
abstract
This paper addresses the role engineering problem for RESTful applications and proposes a role engineering method based on multi-head attention and Retrieval Augmented Generation called MA-RAG. The method first performs fine-grained control flow analysis on the system source code to extract permission information of API handlers. Then, using basic blocks as units, it employs pre-trained code models to convert the source code into semantic vectors, which are stored in the retrieval augmented generation model. On this basis, a call chain structure tree is constructed with permissions as the center, utilizing the multi-head attention mechanism to aggregate semantic information of different code granularities from bottom to top, with each attention head corresponding to a role engineering objective. Finally, the root vectors of each permission tree are subjected to self-supervised clustering to adaptively determine the number of roles and perform division. We evaluated MA-RAG on 284 real-world software systems, and the results show that compared with other methods, MA-RAG can significantly save time overhead, reduce the number of generated roles, lower the role permission overlap rate, and improve the interpretability score.
Qingni Shen, Zhonghai Wu
IJCAI2
2025 LPDetective: Dusting the LLM Chats for Prompt Template Abusers
abstract
The abuse of LLM Chatbot interfaces by web robots leads to a significant waste of GPU and server resources, posing a serious security challenge. To address this issue, we propose LPDetective, an unsupervised method for detecting robot prompt templates. This method is based on the assumption that robot-generated text repeatedly uses the same or highly similar phrases and sentence structures across multiple sessions, differing from human natural conversations. We design a multi-stage workflow, including message grouping, text similarity measurement, hierarchical clustering analysis, and regular expression extraction, to automatically extract potential robot behavior patterns from chat logs. LPDetective does not require predefined templates or rely on training data, enabling it to adaptively discover new, unknown patterns. We conduct systematic experiments on three large-scale real-world datasets: Bing Copilot, Wildchat, and ChatLog. The results show that LPDetective can efficiently and accurately detect robot prompt templates in various scenarios, achieving a 7.5% improvement in F1 score compared to the state-of-the-art XLNet method and reducing detection latency by 178 times on the Bing Copilot dataset.
Qingni Shen, Zhonghai Wu
IJCAI2
2025 BloP: A Trusted Computing Scheme Integrating Blockchain and Privacy-Preserving Computation
abstract
In today's era of rapid digitalization, industries with high data security demands increasingly rely on reliable systems. The requirements for data security and privacy protection in their operations have become more prominent. Although federated learning offers advantages in data privacy protection and collaborative modeling, it still faces privacy risks during model iteration and training interference. It has become an urgent challenge for industries with high data security requirements to build a sensitive information protection system to ensure security and efficiency of data processing. To address these challenges, we propose BloP, a trusted computing scheme that integrates blockchain with privacy-preserving computation. The scheme combines blockchain algorithms with various privacy-preserving computation technologies. BloP relies on trusted computing and measurement modules to maintain a set of trusted nodes, monitor trusted anomaly events, and establish a tamper-proof mechanism. In addition, BloP employs the PBFT consensus algorithm to accelerate the blockchain algorithm. BloP has been implemented and tested on 10 industry systems with high data security demands. During 17 months, the system detected 32,220 trusted anomaly events and 479 tamper-proof events. Furthermore, more than 90 % of these trusted anomaly events were caused by operational errors, while the rest were malicious attacks or unknown incidents.
Zhonghao Pan, Yang Feng 0003, Qingni Shen
QRS4
2025 Achilles: A Formal Framework of Leaking Secrets from Signature Schemes via Rowhammer
Junkai Liang, Zhi Zhang 0001, Xin Zhang 0110, Qingni Shen, Yansong Gao 0001, Xingliang Yuan, Haiyang Xue, Pengfei Wu 0003, Zhonghai Wu
USENIX Security Symposium4
2025 SoK: Understanding zk-SNARKs: The Gap Between Research and Practice
Junkai Liang, Daqi Hu, Pengfei Wu 0003, Yunbo Yang, Qingni Shen, Zhonghai Wu
USENIX Security Symposium5
2025 A lattice-based privacy-preserving decentralized multi-party payment scheme
Jisheng Dong, Qingni Shen, Junkai Liang, Cong Li 0024, Xinyu Feng 0002, Yuejian Fang
Comput. Networks2
2025 Privacy-Enhanced Federated Feature Alignment Method Based on Secure Multi-Party Computation
abstract
Federated learning enables collaborative modeling across institutions while preserving data privacy. However, achieving accurate and efficient feature alignment remains a significant challenge, particularly in scenarios with nonoverlapping feature distributions. To address this issue, we propose P-FedAlign, a privacy-enhanced federated feature alignment method based on secure multi-party computation (SMPC). Our approach leverages cryptographic protocols to perform feature matching among participants without exposing raw data, effectively mitigating potential privacy leakage risks. Furthermore, an efficient acceleration mechanism is integrated to reduce protocol overhead and enhance alignment efficiency. Experimental results demonstrate that P-FedAlign outperforms existing methods in terms of alignment accuracy, privacy protection, and computational performance, making it suitable for various federated learning applications.
Zhihao Zhang 0004, Qingni Shen
Int. J. Pattern Recognit. Artif. Intell.2
2025 Redactable Blockchain From Decentralized Chameleon Hash Functions, Revisited
abstract
Recently, redactable blockchains have attracted attention owing to enabling the contents of blocks to be re-written. The existing redactable blockchain solutions can be classified as two categories, the centralized one and decentralized one. In centralized solutions, a single blockchain node possessing the trapdoor conducts redaction operations. However, they suffer from the issue of single point of failure. In decentralized solutions, redaction operations are performed by numerous blockchain nodes cooperatively. But there also exists the issue of inefficiency or requiring a trusted party in these solutions. Subsequently, Jia et al. proposed a redactable blockchain solution from a decentralized chameleon hash function (DCH) they designed, which supports the threshold redaction, traceability and consistency check. Nevertheless, after carefully analyzing their solution, we find that it fails to achieve the security they claimed by presenting a concrete attack. To resolve this security issue, we propose a novel chameleon hash function scheme that achieves strong collision-resistant security while maintaining simple and efficient as the building block. Based on it, we then present an improved DCH scheme with sufficient security, so that the redactable blockchain from it can resist the presented attack. Theoretical and experimental analyses demonstrate that improved DCH achieves efficiency comparable to DCH.
Cong Li 0024, Qingni Shen, Zhonghai Wu
IEEE Trans. Computers2
2025 Identity-Based Chameleon Hashes in the Standard Model for Mobile Devices
abstract
Online/offline identity-based signature (OO-IBS) is a versatile cryptographic tool to provide the message authentication and integrity in mobile devices, since it lightens the computational burden after the signer receiving the message and eliminates the overhead of certificate management. It has several valuable applications, for instance, wireless sensor networks. Identity-based chameleon hash (IB-CH), as an alternative building block to construct OO-IBS, has been explored in numerous literatures. Nevertheless, there still exist two major issues. 1) Nearly all of the previous IB-CH schemes with weak collision-resistance (W-CollRes) are with random oracles, which may lead to security risks in practicality. The only IB-CH scheme in the standard model suffers from the large size of public parameters and inefficient setup process. 2) The only IB-CH scheme without key exposure also relies on random oracles. In this paper, we propose two novel IB-CH schemes in the standard model. The first scheme is adaptive identity, W-CollRes secure and efficient, significantly reducing the computation costs of all algorithms and the size of public parameters compared with the existing scheme in the standard model. The second scheme is the first IB-CH achieving key exposure freeness without random oracles. Both theoretical and experimental analyses demonstrate the good performance of our proposed schemes. Furthermore, we apply our schemes to optimizing the existing generic OO-IBS construction. The optimized generic constructions reduce computational overhead by 50.0% in the online phase and enable the hash value/signature tuple generated in the offline phase to be reusable, respectively.
Cong Li 0024, Xiaoyu Jiao, Xinyu Feng 0002, Anyang Hu, Qingni Shen, Zhonghai Wu
IEEE Trans. Inf. Forensics Secur.5
2025 PERM: Streamlining Cloud Authorization With Flexible and Scalable Policy Enforcement
abstract
Authorization is a key component of cloud security. However, the differences in access control mechanisms in heterogeneous cloud environments bring many challenges to cloud users, such as the need to learn multiple policy languages and the difficulty in implementing unified access control across clouds. To address these issues, this paper proposes a new access control policy language called PERM, which achieves flexible support for various fine-grained access control models by separating authorization logic from specific policy rules, and significantly reduces the complexity of policy definition. In addition, we also design a distributed PERM enforcement framework named List-Leafed Decision Tree (L2DT), which leverages a list-tree structure and distributed key-value storage to achieve efficient policy storage and execution. We implement prototypes of PERM and L2DT based on Java and Python, and conduct comprehensive evaluations using OpenStack and XACML datasets. Experimental results show that L2DT can achieve scalable policy execution with small latency overhead (an average of 8.63% in the OpenStack scenario and 5.45% in the XACML scenario). The research in this paper provides new ideas for building flexible, efficient, and scalable access control mechanisms in cloud environments.
Qingni Shen, Zhonghai Wu
IEEE Trans. Inf. Forensics Secur.2
2025 Fantastic Interrupts and Where to Find Them: Exploiting Non-Movable Interrupts on x86
abstract
While interrupts play a critical role in modern OSes, they have been exploited as a wide range of side channel attacks to break system confidentiality, such as keystroke interrupts, graphic interrupts and network interrupts. However, as previous attacks mainly focus on the exploitation of movable interrupts, they are required to determine which core is handling the target interrupts before their attack, which is non-trivial. The exploitability of non-movable interrupts, which cannot be reassigned by privileged softwares at will, remains unclear. In this paper, we conduct an empirical study on exploitable non-movable interrupts and their contribution to interrupt-based side-channel leakages in x86-based systems. We propose a dynamic analysis technique to investigate how various types of non-movable interrupts are influenced by different workloads. We then conduct a model fingerprinting attack as the benchmark to show that 7 types of non-movable interrupts are exploitable. To demonstrate the viability of these non-movable interrupts, we have created two concrete side channels, called ThermalScope and TimerScope. Specifically, ThermalScope exploits the thermal event interrupts that are triggered only when the CPU temperature exceeds a pre-determined threshold, and TimerScope exploits timer interrupts that are activated regularly to enable the process schedule. Both techniques are adaptable to different attack scenarios, functioning regardless of whether the attacker and victim share the same core or reside on separate cores. Last, we successfully apply them to mount realistic case studies, ranging from constructing cross-core covert channels to breaking kernel address space layout randomization. We also demonstrate successful DNN model fingerprinting attacks under browser scenarios when the frequency scaling is disabled and attacker core is isolated from movable interrupts, where previous HertzBleed, ThermalBleed, and movable interrupt-based attacks are ineffective.
Xin Zhang 0110, Qingni Shen, Zhi Zhang 0001, Yansong Gao 0001, Zhonghai Wu
IEEE Trans. Inf. Forensics Secur.2
2024 ThermalScope: A Practical Interrupt Side Channel Attack Based on Thermal Event Interrupts
abstract
While interrupts play a critical role in modern OSes, they have been exploited as a wide range of side channel attacks to break system confidentiality, such as keystroke interrupts, graphic interrupts and network interrupts. In this paper, we propose ThermalScope, a new side channel that exploits thermal event interrupts, which is adaptable for both native and browser scenarios and incorporates two heat amplifying techniques. The thermal event interrupts are activated only when the CPU package temperature reaches a fixed threshold that is determined by manufacturers. Our key observation is that workloads running on CPUs inevitably generates their distinct heat, which can be correlated with the thermal event interrupts. To demonstrate the viability of ThermalScope, we conduct a comprehensive evaluation on multiple Ubuntu OSes with different Intel-based CPUs. First, we show that the activation of thermal event interrupts correlates with the level of CPU temperature. We then apply ThermalScope to mount different side channel attacks, i.e., building covert channels with a transmission rate of 0.1 b/s, fingerprinting DNN model architectures with an accuracy of over 90% and breaking KASLR within 8.2 hours.
Xin Zhang 0110, Zhi Zhang 0001, Qingni Shen, Wenhao Wang 0001, Yansong Gao 0001, Zhuoxi Yang, Zhonghai Wu
DAC3
2024 SegScope: Probing Fine-grained Interrupts via Architectural Footprints
abstract
Interrupts are critical hardware resources for OS kernels to schedule processes. As they are related to system activities, interrupts can be used to mount various side-channel attacks (i.e., monitoring keystrokes, inferring website visits, detecting GPU activities, and fingerprinting processes). Given that all these attacks rely on system file interfaces or architectural timers to probe interrupts, various countermeasures have been proposed to either remove the unprivileged access to the file interfaces or detect/cripple architectural timers. In this work, we propose SegScope, a new technique that abuses segment protection to provision fine-grained interrupt observations without any timer. As segment protection is widely used on x86, SegScope works across a wide range of Intel-and AMD-based CPUs. Particularly, we observe that while segment protection preserves the confidentiality of high privileged domain, it leaves a footprint via the data segment registers values when an interrupt occurs. With this key observation, SegScope is crafted by capturing the footprints. To show its security implications, we evaluate it in four case studies. First, SegScope has inferred website visits with a respective success rate of 92.4% on Chrome and 87.4% on Tor Browser in default system settings. Second, SegScope successfully extracts the keys from Cloudflare's Interoperable Reusable Cryptographic Library (CIRCL) vl.l. Third, SegScope steals DNN model architectures with an accuracy of over 80%. Last, SegScope effectively reduces the noise of interrupts to improve the performance of other side channels. As an example, SegScope reduces the error rate of Spectral side channel by 56×. Compared with existing timer-based interrupt-probing techniques, SegScope is fine-grained without introducing false-positives. Further, we leverage SegScope to craft a fine-grained timer, as regular timer interrupts as clock edges contain timestamps. Our evaluation shows that it achieves the same level of timing granularity as the high-resolution timer, i.e., rdtsc and rdpru. We then leverage the timer to break KASLR in about 10 seconds and mount a Flush+Reload based Spectre attack.
Xin Zhang 0110, Zhi Zhang 0001, Qingni Shen, Wenhao Wang 0001, Yansong Gao 0001, Zhuoxi Yang, Jiliang Zhang 0002
HPCA3
2024 Privacy Preserving Federated Learning from Multi-Input Functional Proxy Re-Encryption
abstract
Federated learning (FL) allows different participants to collaborate on model training without transmitting raw data, thereby protecting user data privacy. However, FL faces a series of security and privacy issues (e.g. the leakage of raw data from publicly shared parameters). Several privacy protection technologies, such as homomorphic encryption, differential privacy and functional encryption, are introduced for privacy enhancement in FL. Among them, the FL frameworks based on functional encryption better balance security and performance, thus receiving increasing attention. The previous FL frameworks based on functional encryption suffer from several security issues, including attacks by combining multiple rounds of ciphertexts and keys, and leakage of global parameters to the central server. To tackle these issues, we propose a novel multi-input functional proxy re-encryption (MI-FPRE) scheme and further design a new FL framework with better privacy based on MI-FPRE. Our framework allows a semi-trusted central server to aggregate the parameters without knowing the intermediate parameters and the result of aggregation, thus achieves better privacy in FL training. The experimental results indicate that our framework achieves less communication overhead and higher computational efficiency without losing accuracy.
Xinyu Feng 0002, Qingni Shen, Cong Li 0024, Yuejian Fang, Zhonghai Wu
ICASSP2
2024 DROPFL: Client Dropout Attacks Against Federated Learning Under Communication Constraints
abstract
Federated learning (FL) has emerged as a promising paradigm for decentralized machine learning while preserving data privacy. However, under communication constraints, the standard FL protocol faces the risk of client dropout. Although some research has focused on the risk from the perspectives of communication optimization and privacy protection, it is still challenging to deal with the client dropout issue in dynamic networks, where clients may join or drop the training process at any time. In this paper, we systematically investigate and measure the impact of client dropout on FL by considering the offline duration, frequency, and pattern. Our work allows researchers to gain valuable insights into potential vulnerabilities. First, we assume an attacker can control a limited subset of clients and manipulate these clients to persistent dropout (PD) or random dropout (RD) in some iterative round during the training process. Then, we simulate a Shapley value-based dropout (SVD) attack to preferentially drop the local model of these controlled clients with highly valuable data per iterative round. Extensive experiments show that our SVD attack causes the model accuracy degradation by up to 10.2%, and the PD attack lengthens the training time by up to 4.1×.
Wenjun Qian, Qingni Shen, Zhonghai Wu
ICASSP2
2024 Security Equivalence Assessment between Cloud Standards by Mapping of Control Items
abstract
The rise of new industries, such as the Internet of Things and Smart Healthcare, has brought many cross-cloud business opportunities for cloud computing and posed new challenges to the cloud security. Traditionally, security can be assessed by compliance checking when selecting cloud services. However, when facing cross-cloud security requirements, even if passing the compliance checking, it cannot prove that different clouds have the same security level since they pass different standards. Therefore, security equivalence assessment of different security standards is a fundamental issue. In order to solve the issue automatically, we first transform it into the problem of mapping between control items with respect to different standards. Then, we define three tasks to work out the mapping problem: a task for mapping searching and two for new mapping establishing. Next, we collect, organize, and expand a dataset of mappings between control items containing 21 standards and more than 100,000 pieces of mapping data. Subsequently, we experiment with four well-known models for each task to test their performance on the dataset of mappings: TF-IDF, Word2vec, BERT, and GPT-Neo. Experimental results indicate that the current models can perform very well on the first two tasks but need to be better on the last task.
Yuchen Wong, Shengfang Zhai, Cong Li 0024, Qingni Shen
ICASSP5
2024 TRLS: A Time Series Representation Learning Framework Via Spectrogram for Medical Signal Processing
abstract
Representation learning frameworks in unlabeled time series have been proposed for medical signal processing. Despite the numerous excellent progresses have been made in previous works, we observe the representation extracted for the time series still does not generalize well. In this paper, we present a Time series (medical signal) Representation Learning framework via Spectrogram (TRLS) to get more informative representations. We transform the input time-domain medical signals into spectrograms and design a time-frequency encoder named Time Frequency RNN (TFRNN) to capture more robust multi-scale representations from the augmented spectrograms. Our TRLS takes spectrogram as input with two types of different data augmentations and maximizes the similarity between positive ones, which effectively circumvents the problem of designing negative samples. Our evaluation of four real-world medical signal datasets focusing on medical signal classification shows that TRLS is superior to the existing frameworks. We will open-source our code when the paper is accepted.
Luyuan Xie, Cong Li 0024, Xin Zhang 0110, Shengfang Zhai, Yuejian Fang, Qingni Shen, Zhonghai Wu
ICASSP6
2024 HyPRE: Hybrid Proxy Re-Encryption for Secure Multimedia Data Sharing on Mobile Devices
abstract
Due to the rapid growth of mobile internet, massive multimedia data (e.g., movies, photos, notes, etc.) on mobile devices is synchronized and shared through the cloud. During this process, public key encryption plays an important role in ensuring the confidentiality of data. However, due to the bottleneck of computing and storage resources in mobile devices, it is difficult to execute complex cryptographic algorithms on them. In this paper, we present a novel Hybrid Proxy Reencryption (HyPRE) scheme for the sharing of multimedia data on mobile devices, which empowers a semi-trusted proxy to convert a ciphertext under an identity to a new one under an expressive policy without revealing the underlying plaintext. Our scheme allows mobile devices with limited resources to encrypt data efficiently, and then to share the encrypted data to multiple entities securely. We define the HRA security for our HyPRE scheme to improve the incompleteness of the security under chosen plaintext attacks (CPA) in traditional proxy re-encryption schemes and prove it selectively secure under HRA. Experimental analysis indicates that HyPRE achieves 2× to 3× improvement in terms of re-encryption performance compared with the state-of-the-art ones.
Xinyu Feng 0002, Cong Li 0024, Qingni Shen, Jisheng Dong, Wenjun Qian, Yuejian Fang, Zhonghai Wu
ICME3
2024 MH-pFLID: Model Heterogeneous personalized Federated Learning via Injection and Distillation for Medical Data Analysis
abstract
Federated learning is widely used in medical applications for training global models without needing local data access, but varying computational capabilities and network architectures (system heterogeneity) across clients pose significant challenges in effectively aggregating information from non-independently and identically distributed (non-IID) data (statistic heterogeneity). Current federated learning methods using knowledge distillation require public datasets, raising privacy and data collection issues. Additionally, these datasets require additional local computing and storage resources, which is a burden for medical institutions with limited hardware conditions. In this paper, we introduce a novel federated learning paradigm, named Model Heterogeneous personalized Federated Learning via Injection and Distillation (MH-pFLID). Our framework leverages a lightweight messenger model, eliminating the need for public datasets and reducing the training cost for each client. We also develops receiver and transmitter modules for each client to separate local biases from generalizable information, reducing biased data collection and mitigating client drift. Our experiments on various medical tasks including image classification, image segmentation, and time-series classification, show MH-pFLID outperforms state-of-the-art methods in all these areas and has good generalizability.
Luyuan Xie, Manqing Lin, Tianyu Luan, Cong Li 0024, Yuejian Fang, Qingni Shen, Zhonghai Wu
ICML6
2024 pFLFE: Cross-silo Personalized Federated Learning via Feature Enhancement on Medical Image Segmentation
Luyuan Xie, Manqing Lin, ChenMing Xu, Tianyu Luan, Cong Li 0024, Yuejian Fang, Qingni Shen, Zhonghai Wu
MICCAI (10)8
2024 MH-pFLGB: Model Heterogeneous Personalized Federated Learning via Global Bypass for Medical Image Analysis
Luyuan Xie, Manqing Lin, ChenMing Xu, Tianyu Luan, Zhipeng Zeng, Wenjun Qian, Cong Li 0024, Yuejian Fang, Qingni Shen, Zhonghai Wu
MICCAI (10)9
2024 Membership Inference on Text-to-Image Diffusion Models via Conditional Likelihood Discrepancy
abstract
Text-to-image diffusion models have achieved tremendous success in the field of controllable image generation, while also coming along with issues of privacy leakage and data copyrights. Membership inference arises in these contexts as a potential auditing method for detecting unauthorized data usage. While some efforts have been made on diffusion models, they are not applicable to text-to-image diffusion models due to the high computation overhead and enhanced generalization capabilities. In this paper, we first identify a conditional overfitting phenomenon in text-to-image diffusion models, indicating that these models tend to overfit the conditional distribution of images given the corresponding text rather than the marginal distribution of images only. Based on this observation, we derive an analytical indicator, namely Conditional Likelihood Discrepancy (CLiD), to perform membership inference, which reduces the stochasticity in estimating memorization of individual samples. Experimental results demonstrate that our method significantly outperforms previous methods across various data distributions and dataset scales. Additionally, our method shows superior resistance to overfitting mitigation strategies, such as early stopping and data augmentation.
Shengfang Zhai, Huanran Chen, Yinpeng Dong, Qingni Shen, Yansong Gao 0001, Hang Su 0006, Yang Liu 0003
NeurIPS5
2024 FDP-FL: differentially private federated learning with flexible privacy budget allocation
abstract
Abstract Federated learning (FL) as a privacy-preserving technology enables multiple clients to collaboratively train models on decentralized data. However, transmitting model parameters between local clients and the central server can potentially result in information leakage. Differentially private federated learning (DPFL) has emerged as a promising solution to enhance privacy. Nevertheless, existing DPFL schemes suffer from two issues: (i) most schemes that aim to achieve desired model accuracy may incur a high privacy budget. (ii) several schemes that consider the trade-off between privacy and accuracy by utilizing linear clipping bound may distort numerous model parameters. In this paper, we first propose FDP-FL, a flexible differential privacy approach for FL. FDP-FL introduces a novel series sum privacy budget allocation instead of uniform allocation and enables adaptive and nonlinear noise scale decay. In this way, a tight bound for cumulative privacy loss can be achieved while optimizing model accuracy. Then in order to mitigate gradient leakages caused by honest-but-curious clients and server, we further design client-level FDP-FL and record-level FDP-FL, respectively. Experimental results demonstrate that our FDP-FL improves model accuracy by $\sim $13.3% compared with the basic DP-FL under a fixed privacy budget and outperforms existing trade-off schemes with the same hyperparameter setting.
Wenjun Qian, Qingni Shen, Cong Li 0024, Yuejian Fang, Zhonghai Wu
Comput. J.2
2024 IPOD2: an irrecoverable and verifiable deletion scheme for outsourced data
abstract
Abstract To alleviate the burden of data storage and management, there is a growing trend of outsourcing data to the cloud that enables users to remotely manage their data flexibly. However, this shift also raises concerns regarding outsourced data deletion, as users lose physical control over their outsourced data and are unable to verify its proper eradication. To address this issue, cloud service providers are required to provide a scheme that guarantees the effective deletion of outsourced data. Existing schemes, including key management-based and overwriting-based schemes, fail to ensure both the irrecoverability of deleted data and the verifiability of the deletion process. In this paper, we propose IPOD2, an irrecoverable and verifiable deletion scheme for outsourced data. Specifically, IPOD2 utilizes the overwriting-based deletion method to implement outsourced data deletion and extends the Integrity Measurement Architecture to measure the operations in the deletion process. The measurement results are protected by the Trusted Platform Module and verifiable for users. To demonstrate the viability of IPOD2, we implement a prototype of IPOD2 on the Linux kernel 5.4.120. Experimental results show that, compared with the three existing schemes, IPOD2 has the minimum overhead in both deletion and verification processes.
Xin Zhang 0110, Qingni Shen, Zhonghai Wu
Comput. J.4
2024 ReenRepair: Automatic and semantic equivalent repair of reentrancy in smart contracts
Ruiyao Huang, Qingni Shen, Yiqi Wu, Zhonghai Wu, Xiapu Luo, Anbang Ruan
J. Syst. Softw.2
2024 On the Security of Secure Keyword Search and Data Sharing Mechanism for Cloud Computing
abstract
Nearly all of the previous attribute-based proxy re-encryption (ABPRE) schemes cannot support keyword search and keyword updating without the aid of private key generator (PKG) simultaneously. To resolve this problem, recently in IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2020.2963978), Ge et al. proposed a ciphertext-policy ABPRE scheme with keyword search, dubbed CPAB-KSDS, which supports keyword updating without communicating with PKG. It also achieves indistinguishability against chosen-ciphertext attack (IND-CCA) security and indistinguishability against chosen-keyword attack (INDCKA) security in the random oracle model. In this paper, we carefully analyze the security of Ge et al.’s CPAB-KSDS scheme and find that they did not give a correct reduction from IND-CKA security of theirs to the underlying cryptographic assumption. Furthermore, we also give a concrete attack on IND-CKA security of the CPAB-KSDS scheme. Therefore, it fails to achieve IND-CKA security they claimed, which is an essential security requirement for the encryption scheme with keyword search.
Cong Li 0024, Xinyu Feng 0002, Qingni Shen, Zhonghai Wu
IEEE Trans. Dependable Secur. Comput.3
2023 A Privacy Preserving Computer-aided Medical Diagnosis Framework with Outsourced Model
abstract
Computer-aided diagnosis plays an increasingly important role in modern medical activities, relying largely on the deployment of medical machine learning models. Protecting the security of model parameters is crucial for model providers. However, the current schemes for protecting model parameters are mostly interactive. This interactive nature makes it difficult to support offline deployment of models and flexible authorization of prediction results, thus hindering the widespread application of computer-aided diagnosis. To address these limitations, we propose a new computer-aided medical diagnosis framework by designing a new identity-based inner product functional proxy re-encryption (IB-IPFPRE) scheme. Our framework supports private deployment of medical diagnostic models without compromising model parameters. It also enables access control of prediction results based on user identity. Compared to existing privacy-preserving prediction techniques, our framework significantly reduces communication overhead and does not require the model owner to be online in real-time. Furthermore, our scheme enables flexible delegation of prediction results, allowing users to authorize the sharing of prediction results with other entities as needed. We conducted extensive experiments for logistic regression on three medical datasets. The experiments demonstrate that our scheme achieved 40% to 7× performance improvement in LAN environment and 13× to 15× improvement in WAN environment, and did not require any communication overhead during the privacy preserving prediction phase.
Xinyu Feng 0002, Qingni Shen, Cong Li 0024, Niantao Xie, Luyuan Xie, Yuejian Fang, Zhonghai Wu
BIBM2
2023 Detecting Malicious Migration on Edge to Prevent Running Data Leakage
abstract
With the popularity of the Internet of Things (IoT) applications, for instance, smart homes and smart medical, edge servers have become increasingly critical infrastructures. Nevertheless, the loose management puts the edge server under the threat of malicious administrators, which causes the leaking risks of the user’s data security. We first give a Data Sniffing Attack that malicious administrators can use live migration to complete without being discovered. To resist the attack, the transparency of live migration to users is the most severe difficulty, where there has not been an effective solution yet. In this paper, we propose a live migration detection model to simulate the migration process, namely observing the indicator values that can obtain without high authorities and calculating the possibility of state transition. Then through many migration experiments, we present the immediate indicators represented by the OS interrupts and the persistent indicators represented by the IO speed, and sort these indicator values into datasets. Next, we train ten frequently-used classifiers and show their accuracy. Eventually, we analyze the advantages and disadvantages of different algorithms in predicting migration and provide the weight recommendation if applied in the detection model.
Yuchen Wong, Qingni Shen, Cong Li 0024, Cunzhan Liu, Tianxiang Ai
ICASSP2
2023 A Role Engineering Approach Based on Spectral Clustering Analysis for Restful Permissions in Cloud
abstract
With the widely application of cloud, a series of privacy challenges arise. Generally, encryption methods are used to ensure privacy, which may result in high computation and communication overheads. Access control is another fundamental and important measure to protect resources. Usually cloud computing systems are managed through RESTful web services and users can conduct access control measures like role-based access control (RBAC) to manage the permissions to RESTful resources. By running integration test, test cases and the corresponding RESTful permissions can be parsed out automatically. We are the first to define the role engineering problem based on integration test and summarize three metrics for role engineering. Then we propose a novel role engineering method based on spectral clustering analysis which supporting more feature set such as permission weight, role hierarchy and customized number of roles. Finally, we conduct experiments using real integration test on three cloud computing systems to demonstrate the effectiveness and performance, outperforming prior works.
Yutang Xia, Wu Luo, Qingni Shen, Yahui Yang, Zhonghai Wu
ICASSP4
2023 NCL: Textual Backdoor Defense Using Noise-Augmented Contrastive Learning
abstract
At present, backdoor attacks attract attention as they do great harm to deep learning models. By poisoning the training data, the adversary makes the model trained based on this dataset being injected with a backdoor. In the field of text, however, existing works do not provide sufficient defense against backdoor attacks. In this paper, we propose a Noise-augmented Contrastive Learning (NCL) framework to defend against textual backdoor attacks when training models with untrustworthy data. With the aim of mitigating the mapping between triggers and the target label, we add appropriate noise perturbing possible backdoor triggers, augment the training dataset, and then pull homology samples in the feature space utilizing contrastive learning objective. Experiments demonstrate the effectiveness of our method in defending three types of textual backdoor attacks, outperforming the prior works.
Shengfang Zhai, Qingni Shen, Cong Li 0024, Yuejian Fang, Zhonghai Wu
ICASSP2
2023 CL-BOSIC: A Distributed Agent-Oriented Scheme for Remote Data Integrity Check and Forensics in Public Cloud
Huilin Zheng, Qingni Shen, Zhonghai Wu
ICIC (1)3
2023 SHISRCNet: Super-Resolution and Classification Network for Low-Resolution Breast Cancer Histopathology Image
Luyuan Xie, Cong Li 0024, Xin Zhang 0110, Boyan Chen, Qingni Shen, Zhonghai Wu
MICCAI (5)6
2023 Text-to-Image Diffusion Models can be Easily Backdoored through Multimodal Data Poisoning
abstract
With the help of conditioning mechanisms, the state-of-the-art diffusion models have achieved tremendous success in guided image generation, particularly in text-to-image synthesis. To gain a better understanding of the training process and potential risks of text-to-image synthesis, we perform a systematic investigation of backdoor attack on text-to-image diffusion models and propose BadT2I, a general multimodal backdoor attack framework that tampers with image synthesis in diverse semantic levels. Specifically, we perform backdoor attacks on three levels of the vision semantics: Pixel-Backdoor, Object-Backdoor and Style-Backdoor. By utilizing a regularization loss, our methods efficiently inject backdoors into a large-scale text-to-image diffusion model while preserving its utility with benign inputs. We conduct empirical experiments on Stable Diffusion, the widely-used text-to-image diffusion model, demonstrating that the large-scale diffusion model can be easily backdoored within a few fine-tuning steps. We conduct additional experiments to explore the impact of different types of textual triggers, as well as the backdoor persistence during further training, providing insights for the development of backdoor defense methods. Besides, our investigation may contribute to the copyright protection of text-to-image models in the future. Our Code: https://github.com/sf-zhai/BadT2I.
Shengfang Zhai, Yinpeng Dong, Qingni Shen, Shi Pu 0002, Yuejian Fang, Hang Su 0006
ACM Multimedia3
2023 T-Counter: Trustworthy and Efficient CPU Resource Measurement Using SGX in the Cloud
abstract
As cloud services have become popular, and their adoption is growing, consumers are becoming more concerned about the cost of cloud services. Cloud Service Providers (CSPs) generally use a pay-per-use billing scheme in the cloud services model: consumers use resources as they needed and are billed for their resource usage. However, CSPs are untrusted and privileged; they have full control of the entire operating system (OS) and may tamper with bills to cheat consumers. So, how to provide a trusted solution that can keep track of and verify the consumers’ resource usage has been a challenging problem. In this article, we propose a T-Counter framework based on Intel SGX. The T-Counter allows applications to construct a trusted solution to measure its CPU usage by itself in cloud computing. These constructed applications are instrumented with counters in basic blocks and added three components in trusted parts to count instructions and defend against malicious CSPs’ manipulations. We propose two algorithms which selectively instrument counters in the CFG. T-Counter is implemented as an extension of the LLVM framework and integrated with the SGX SDK. Theoretical analyses and evaluations show that T-Counter can effectively measure CPU usage and defend against malicious CSPs’ manipulations.
Chuntao Dong, Qingni Shen, Xuhua Ding, Daoqing Yu, Wu Luo, Pengfei Wu 0003, Zhonghai Wu
IEEE Trans. Dependable Secur. Comput.2
2022 Automated Extraction of ABAC Policies from Natural-Language Documents in Healthcare Systems
abstract
The healthcare system is a distributed collaborative system and the sensitivity of the medical data is one of the most important requirements. Preventing unauthorized access to healthcare information and data sharing security in the healthcare environment are critical processes that affect the credibility of the system. To achieve this goal and to meet the requirements of the healthcare system, access control is an important measure to realize the safe sharing of resources. The attribute-based access control (ABAC) model meets the complex security requirements of large and complex systems and provides a dynamic, flexible and scalable solution. The main obstacle to deploying ABAC is the precise development of ABAC policies. Manually developing access control policies is tedious, time-consuming and error prone. Most systems have high-level requirement specifications, which are written in natural language. These natural language (NL) documents have the intended access control policies for the systems. In this paper, we propose a new approach towards extracting policies from natural language documents. By fully taking advantage of Bidirectional Encoder Representations from Transformers (BERT) and Semantic role labeling (SRL), we are able to correctly identify access control policy (ACP) sentences with an average F1 score of 85% and correctly extract rules with an average F1 score of 72%, which outperforms the state-of-the-art and leads to a performance improvement of 7% and 2% respectively over the previously reported results.
Yutang Xia, Shengfang Zhai, Qinting Wang, Huiting Hou, Zhonghai Wu, Qingni Shen
BIBM6
2022 Kallima: A Clean-Label Framework for Textual Backdoor Attacks
Yinpeng Dong, Zeyu Sun 0005, Shengfang Zhai, Qingni Shen, Zhonghai Wu
ESORICS (1)5
2022 Efficient Identity-Based Chameleon Hash for Mobile Devices
abstract
Online/offline identity-based signature (OO-IBS) is an adequate cryptographic tool to provide the message authentication and integrity in mobile devices, since it lightens the computational burden after the signer receives the message and eliminates the overhead of certificate management. It has several valuable applications, such as wireless sensor networks and automatic dependent surveillance-broadcast systems. Identity-based chameleon hash (IB-CH), as an alternative building block to construct OO-IBS, has been explored in several literatures. Nevertheless, almost all of the prior IB-CH schemes are in the random oracle model, which may lead to security risks in practicality. The only IB-CH scheme in the standard model proposed by Xie et al. (ICC’21) suffers from the large size of public parameters and inefficient setup process. In this paper, we propose an efficient IB-CH scheme in the standard model, significantly reducing the computational costs of all the algorithms and the size of public parameters compared with Xie’s scheme. The security and experimental analyses demonstrate the security and good performance of our scheme. Furthermore, we applied our scheme to optimize the existing generic OO-IBS construction. Our optimized construction reduces computational overhead by 50.0% in the online phase compared with the original construction.
Cong Li 0024, Qingni Shen, Zhikang Xie, Jisheng Dong, Yuejian Fang, Zhonghai Wu
ICASSP2
2022 RuleCache: Accelerating Web Application Firewalls by On-line Learning Traffic Patterns
abstract
Web Application Firewall (WAF) is widely deployed in cloud to protect web applications, whose performance becomes one of the major bottlenecks for web services. In this paper, we comprehensively analyze several root causes that downgrade WAF’s efficiency. Inspired by that, we build a caching system RuleCache to devise optimization strategies for improving WAF’s performance. Among, Rule Ordering Cache is online learning an optimal order of the ruleset for a better performance of blocking. Rule Result Cache reuses rule results of targets, saving large repetitive computations. Additionally, Rule Prepruning Cache aims to cut extra overhead by processing the static rules in the offline stage. Our evaluation demonstrates that the prototype can improve the performance by up to 3.85x, 1.57x, and 2.4x respectively with the above modules, and up to 5.5x in total.
Qingni Shen, Peng Cheng 0005, Yongqiang Xiong, Zhonghai Wu
ICWS2
2022 ScriptChecker: To Tame Third-party Script Execution With Task Capabilities
Wu Luo, Xuhua Ding, Pengfei Wu 0003, Qingni Shen, Zhonghai Wu
NDSS5
2022 Personalized User Profiles-based Insider Threat Detection for Distributed File System
abstract
In recent years, data security incidents caused by insider threats in distributed file systems have attracted the attention of academia and industry. The most common way to detect insider threats is based on user profiles. Through analysis, we realize that based on existing user profiles are not efficient enough, and there are many false positives when a stable user profile has not yet been formed. In this work, we propose personalized user profiles and design an insider threat detection framework, which can intelligently detect insider threats for securing distributed file systems in real-time. To generate personalized user profiles, we come up with a time window-based clustering algorithm and a weighted kernel density estimation algorithm. Compared with non-personalized user profiles, both the Recall and Precision of insider threat detection based on personalized user profiles have been improved, resulting in their harmonic mean F1 increased to 96.52%. Meanwhile, to reduce the false positives of insider threat detection, we put forward operation recommendations based on user similarity to predict new operations that users will produce in the future, which can reduce the false positive rate (FPR). The FPR is reduced to 1.54% and the false positive identification rate (FPIR) is as high as 92.62%. Furthermore, to mitigate the risks caused by inaccurate authorization for users, we present user tags based on operation content and permission. The experimental results show that our proposed framework can detect insider threats more effectively and precisely, with lower FPR and high FPIR.
Qingni Shen, Yutang Xia, Zhonghai Wu, Zhenghao Lin
TrustCom2
2022 Hierarchical and non-monotonic key-policy attribute-based encryption and its application
Cong Li 0024, Qingni Shen, Zhikang Xie, Jisheng Dong, Xinyu Feng 0002, Yuejian Fang, Zhonghai Wu
Inf. Sci.2
2021 BadNL: Backdoor Attacks against NLP Models with Semantic-preserving Improvements
abstract
Deep neural networks (DNNs) have progressed rapidly during the past decade and have been deployed in various real-world applications. Meanwhile, DNN models have been shown to be vulnerable to security and privacy attacks. One such attack that has attracted a great deal of attention recently is the backdoor attack. Specifically, the adversary poisons the target model’s training set to mislead any input with an added secret trigger to a target class.
Ahmed Salem 0001, Dingfan Chen, Michael Backes 0001, Shiqing Ma, Qingni Shen, Zhonghai Wu, Yang Zhang 0016
ACSAC6
2021 Identity-Based Chameleon Hash without Random Oracles and Application in the Mobile Internet
abstract
The rapid development of the mobile Internet makes it necessary to adopt efficient cryptographic primitives for the portable devices with limited computing resources. Online/offline identity-based signatures are suitable because of short response time of signature generation and being free from the cumbersome operations caused by public key infrastructures. In this paper, we propose the first identity-based chameleon hash which can be proved secure without the random oracle and show how to use it to translate any identity-based signature to an online/offline one.
Zhikang Xie, Qingni Shen, Cong Li 0024, Jisheng Dong, Yuejian Fang
ICC2
2021 Large Universe CCA2 CP-ABE With Equality and Validity Test in the Standard Model
abstract
Abstract Attribute-based encryption with equality test (ABEET) simultaneously supports fine-grained access control on the encrypted data and plaintext message equality comparison without decrypting the ciphertexts. Recently, there have been several literatures about ABEET proposed. Nevertheless, most of them explore the ABEET schemes in the random oracle model, which has been pointed out to have many defects in practicality. The only existing ABEET scheme in the standard model, proposed by Wang et al., merely achieves the indistinguishable against chosen-plaintext attack security. Considering the aforementioned problems, in this paper, we propose the first direct adaptive chosen-ciphertext security ciphertext-policy ABEET scheme in the standard model. Our method only adopts a chameleon hash function and adds one dummy attribute to the access structure. Compared with the previous works, our scheme achieves the security improvement, ciphertext validity check and large universe. Besides, we further optimize our scheme to support the outsourced decryption. Finally, we first give the detailed theoretical analysis of our constructions in computation and storage costs, then we implement our constructions and carry out a series of experiments. Both results indicate that our constructions are more efficient in Setup and Trapdoor and have the shorter public parameters than the existing ABEET ones do.
Cong Li 0024, Qingni Shen, Zhikang Xie, Xinyu Feng 0002, Yuejian Fang, Zhonghai Wu
Comput. J.2
2021 ObliComm: Towards Building an Efficient Oblivious Communication System
abstract
Anonymous Communication (AC) hides traffic patterns and protects message metadata from being leaked during message transmission. Many practical AC systems have been proposed aiming to reduce communication latency and support a large number of users. However, how to design AC systems which possess strong security property and at the same time achieve optimal performance (i.e., the lowest latency or highest horizontal scalability) has been a challenging problem. In this paper, we propose an ObliComm framework, which consists of six modular AC subroutines. We also present a strong security definition for AC, named oblivious communication, encompassing confidentiality, unobservability, and a new requirement sending-and-receiving operation hiding. The AC subroutines in ObliComm allow for modular construction of oblivious communication systems in different network topologies. All constructed systems satisfy oblivious communication definition and can be provably secure in the universal composability (UC) framework. Additionally, we model the relationship between the network topology and communication measurements by queuing theory, which enables the system's efficiency can be optimized and estimated by quantitative analysis and calculation. Through theoretical analyses and empirical experiments, we demonstrate the efficiency of our scheme and soundness of the queuing model.
Pengfei Wu 0003, Robert H. Deng, Qingni Shen, Ximeng Liu, Qi Li 0002, Zhonghai Wu
IEEE Trans. Dependable Secur. Comput.3
2020 RSDS: Getting System Call Whitelist for Container Through Dynamic and Static Analysis
abstract
Container technology has been used for running multiple isolated operating system distros on a host or deploying large scale microservice-based applications. In most cases, containers share the same kernel with the host and other containers on the same host, and the application in the container can make system calls of the host kernel like a normal process on the host. Seccomp is a security mechanism for the Linux kernel, through which we can prohibit certain system calls from being executed by the program. Docker began to support the seccomp mechanism from version 1.10 and disables around 44 system calls out of 300+ by default. However, for a particular container, there are still many system calls that are unnecessary for running it allowed to be executed, and the abuse of system calls by a compromised container can trigger the security vulnerabilities of a host kernel. Unfortunately, Docker does not provide a way to get the necessary system calls for a particular container. In this paper, we propose RSDS, a method combining dynamic analysis and static analysis to get the necessary system calls for a particular container. Our experiments show that our solution can reduce system calls by 69.27%-85.89% compared to the default configuration on an x86-64 PC with Ubuntu 16.04 host OS and does not affect the functionalities of these containers.
Xuhao Wang, Qingni Shen, Wu Luo, Pengfei Wu 0003
CLOUD2
2019 ObliDC: An SGX-based Oblivious Distributed Computing Framework with Formal Proof
abstract
Data privacy is becoming one of the most critical concerns in cloud computing. Several proposals based on Intel SGX such as VC3 [1] and M2R [2] have been introduced in the literature to protect data privacy during job execution in the cloud. However, a comprehensive formal proof of their security guarantees is still lacking. In this paper, we propose ObliDC, a general UC-secure SGX-based oblivious distributed computing framework. First, we model the life-cycle of a distributed computing job as data-flow graphs. Under the assumption of malicious, adaptive adversaries in the cloud, we then formally define data privacy of a distributed computing job by introducing a notion named ODC-privacy, which encompasses both semantic security (to protect data confidentiality during computation and transmission) and oblivious traffic (to prevent data leakage from traffic analysis). ObliDC is composed of four two-party protocols -- job deployment, job initialization, job execution, and results return, which allow for modular construction of concrete privacy-preserving job protocols in different distributed computing frameworks. Finally, inspired by a formal abstraction for trusted processors proposed by R. Pass et al. [3], we formally prove the security of ObliDC under the universal composability (UC) framework.
Pengfei Wu 0003, Qingni Shen, Robert H. Deng, Ximeng Liu, Yinghui Zhang 0002, Zhonghai Wu
AsiaCCS2
2019 CloudCoT: A Blockchain-Based Cloud Service Dependency Attestation Framework
Qingni Shen, Wu Luo, Anbang Ruan
ICICS2
2019 PTAD: Provable and Traceable Assured Deletion in Cloud Storage
abstract
As an efficient deletion method, unlinking is widely used in cloud storage. While unlinking is a kind of incomplete deletion, `deleted data' remains on cloud and can be recovered. To make `deleted data' unrecoverable, overwriting is an effective method on cloud. Users lose control over their data on cloud once deleted, so it is difficult for them to confirm overwriting. In face of such a crucial problem, we propose a Provable and Traceable Assured Deletion (PTAD) scheme in cloud storage based on blockchain. PTAD scheme relies on overwriting to achieve assured deletion. We reference the idea of data integrity checking and design algorithms to verify if cloud overwrites original blocks properly as specific patterns. We utilize technique of smart contract in blockchain to automatically execute verification and keep transaction in ledger for tracking. The whole scheme can be divided into three stages-unlinking, overwriting and verification-and we design one specific algorithm for each stage. For evaluation, we implement PTAD scheme on cloud and construct a consortium chain with Hyperledger Fabric. The performance shows that PTAD scheme is effective and feasible.
Hecan Zhang, Yahui Yang, Qingni Shen
ISCC4
2019 Container-IMA: A privacy-preserving Integrity Measurement Architecture for Containers
Wu Luo, Qingni Shen, Yutang Xia, Zhonghai Wu
RAID2
2018 Invader Job: A Kind of Malicious Failure Job on Hadoop YARN
abstract
In distributed computing platform, it's possible to occur unexpected job failure. Normally, the system performance will not be affected obviously. But, in Hadoop YARN, we find Invader Job, a kind of inappropriate user-definable parameter caused malicious failure job, may cut down the system performance greatly. In this paper, we find in Hadoop YARN, there are two vulnerabilities that can be used to construct invader job. First, it's easy to cause job failure by modifying the user-definable parameters inappropriately. Second, YARN doesn't check on the job before execution, and also doesn't check the failure reason before re-attempt. So that, invader job could fail as much as possible to occupy the scheduling resource over and over again. Thus, we propose a detection framework called InTect which employs SVM to predict invader jobs. Finally, we verify our findings using the cluster of our lab and Amazon EMR respectively. As a result, the cluster performance degrades 4 times than normal case. Moreover, the recall rate of our detection framework is more than 90%, which means the SVM model has a good discrimination for invader jobs.
Lijing Cheng, Qingni Shen, Chuntao Dong
ICC2
2018 Towards Real-Time Privacy Preservation: A Streaming Location Anonymous Method Based on Distributed Framework
abstract
In order to better serve users, several location-based services rely on the real-time spatio-temporal information. Existing location privacy- preserving methods traverse the whole dataset to anonymize k locations together, and do not utilize parallel computing technology. The anonymization for big volume of location data may result in huge computing cost. We propose a new method called Never Wait for Long (NW4L), which protects the privacy of big-volume location data in parallel and real-time. Instead of linear structure, a k-d tree structure is adopted for the nearest location search to speed up computation. To further improve efficiency, locations are pre- classified in several groups, so that each group can be anonymized in parallel with support from the distributed stream computation framework. In this paper, we implemented NW4L based on Spark and used real-world dataset for performance evaluation. Experimental results show that 100,000 location samples can be processed in 2 minutes, which is feasible for real-time computation.
Tong Hui, Yahui Yang, Qingni Shen, Zhonghai Wu
ICC3
2018 Non-Authentication Based Checkpoint Fault-tolerant Vulnerability in Spark Streaming
abstract
Apache Spark uses Resilient Distributed Datasets (RDDs) as primitives for data sharing. The in-memory feature of RDD makes Spark faster but it also brings a volatile problem where a failure or a missing RDD causes Spark to recompute all the missing RDD in the lineage. A checkpoint cuts off the lineage by saving the data which is required in the coming computing, thus becoming an essential fault-tolerance mechanism. In this paper, we find that as for Spark Streaming jobs with checkpoint, user authentication is not performed while doing checkpoint during job execution. We present two typical attack scenarios where attackers exploit this vulnerability to interfere with normal users job, causing data loss or even incorrect results. And we put forward a solution which focuses on the administration of checkpoint directory permissions. The experimental results show that our scheme can effectively monitor and resist this attack.
Yazhen Tian, Qingni Shen, Ziyao Zhu, Yahui Yang, Zhonghai Wu
ISCC2
2018 KASR: A Reliable and Practical Approach to Attack Surface Reduction of Commodity OS Kernels
Zhi Zhang 0001, Yueqiang Cheng, Surya Nepal, Dongxi Liu, Qingni Shen, Fethi A. Rabhi
RAID5
2017 Making least privilege the low-hanging fruit in clouds
abstract
Failing to promote the least privilege principle in administration can lead to substantial vulnerabilities in cloud computing. A malicious insider like a compromised cloud administrator can affect security of data and workloads belonging to cloud customers. Enforcing the least privilege principle in cloud administration can fairly restrict the permissions of administrators and reduce the attack surface. However, writing a least privilege policy can be hard and error prone for cloud service providers. In this paper, we propose a framework called Least Privilege for Cloud (LPCloud) to address these concerns. LPCloud automatically produces policies for minimization of administrators' privileges at the granularity of representational state transfer (REST) application program interfaces (API), and enforces the policies without affecting current systems. Specifically, we introduce a novel algorithm to partition privileges based on dependencies between API calls. This paper presents design of LPCloud, including a service called Policy Generator which produces partitioned policies and a component named Policy Enforcer to enforce the policies. We implement a prototype of our framework in OpenStack Mitaka. Experiments indicate that LPCloud can produce proper policies to enforce the least privilege principle. Meantime, the average performance overhead is 10.1% which is in acceptable level.
Tian Puyang, Qingni Shen, Wu Luo, Zhonghai Wu
ICC2
2017 SeEagle: Semantic-Enhanced Anomaly Detection for Securing Eagle
Qingni Shen, Yahui Yang, Zhonghai Wu
ICDF2C2
2017 Practical Large Universe Attribute-Set Based Encryption in the Standard Model
Xinyu Feng 0002, Cancan Jin, Cong Li 0024, Yuejian Fang, Qingni Shen, Zhonghai Wu
ICICS5
2017 Fully Secure Hidden Ciphertext-Policy Attribute-Based Proxy Re-encryption
Xinyu Feng 0002, Cong Li 0024, Yuejian Fang, Qingni Shen
ICICS5
2017 Statically Defend Network Consumption Against Acker Failure Vulnerability in Storm
Wenjun Qian, Qingni Shen, Yizhe Yang, Yahui Yang, Zhonghai Wu
ICICS2
2017 MCS: Memory Constraint Strategy for Unified Memory Manager in Spark
abstract
Apache Spark is an increasingly popular distributed computation framework based on in-memory computations, which enables iterative or interactive applications to run faster. In Spark, memory management is the key to performance enhancement to avoid memory bloat problems. Compared with previous static memory manager, in Spark 1.6 and later versions, unified memory manager is implemented as the default memory management model, targeting to achieve optimal memory utilization by borrowing between storage and execution memory. However, the storage memory borrowed from execution memory may frequently be evicted when memory pressure arises. It is because of frequently re- computation during cache evicted and frequent garbage collection during shuffle in iterative applications. This situation will produce runtime overhead caused by garbage collection including cache eviction and cache re-computation. We propose a memory constraint strategy for unified memory manager in Spark to reduce runtime overhead caused by garbage collection by reducing the cache eviction size. We implement the strategy in Spark 1.6.1 using SparkPageRank, WordCount and GroupByTest to compare three different memory managers. Experimental results reveal that compared unified memory manager, memory constraint strategy can achieve better performance improvement with lower job runtime and garbage collection time when the dataset sizes or the iterations are increasing.
Ziyao Zhu, Qingni Shen, Yahui Yang, Zhonghai Wu
ICPADS2
2017 RestSep: Towards a Test-Oriented Privilege Partitioning Approach for RESTful APIs
abstract
At present, a growing number of web applications especially cloud computing systems employ representational state transfer (REST) API as the interface to expose their services for simplicity and clarity. For security purposes, service providers prefer to control the access to the provided interface based on the principle of least privilege. However, how to divide the administrative privileges remains a difficulty in practice. In this work, we simplify the privilege partitioning problem into a classification problem of RESTful functions, so the permission to call a category of functions can be granted to a specific administrator. We propose a RESTful API classification approach called RestSep based on genetic algorithm. A classification is represented as a 2-dimensional matrix, which is used as the chromosome. Customized operators of selection, mutation and crossover are designed. The fitness function is designed to balance parameters such as number of categories, test case coverage, function overlapping, etc. Experiments on popular clouds like OpenStack and Kubernetes indicate RestSep can generate a self-explanatory classification result, which can serve as a guideline for privilege partitioning. The overhead of test generation is at most 13.1% and the overhead of genetic algorithm is at most 183.29s, which are acceptable for practical use.
Tian Puyang, Xiaoning Sun, Qingni Shen, Yahui Yang, Anbang Ruan, Zhonghai Wu
ICWS4
2017 A practical construction for large universe hierarchical attribute-based encryption
abstract
Summary We present a practical large universe hierarchical attribute‐based encryption (LU‐HABE) scheme, which supports monotone access structures. In our system, key generation centers (KGCs), any one in which is labeled by a unique identity, are organized as a hierarchical structure. Thus, all secret keys issued by the KGC contain 2 parts: the identity‐related one and the attribute‐related one. Once the data owner wants to encrypt his/her data, he/she needs to specify certain numbers of pairs according to his/her demand. The pair consists of an identity of a KGC and a policy of attributes managed by the corresponding KGC, eg, IDi and (Mi, ρi). If and only if an identity associated with user's secret key is equal to or is an ancestor of one of the identities appearing in ciphertext, and simultaneously a set of attributes belonging to the user satisfies the policy, the user can decrypt it successfully. Our scheme is proved to be selectively secure in the standard model under the modified “q‐type” assumption similar to the ones used in former works and is extended to support online/offline encryption. To show the efficiency of our construction, we implement our original scheme and the extended one in Charm. Analyses show that both of them are very practical.
Cong Li 0024, Yuejian Fang, Xing Zhang 0002, Cancan Jin, Qingni Shen, Zhonghai Wu
Concurr. Comput. Pract. Exp.5
2016 OpenStack Security Modules: A Least-Invasive Access Control Framework for the Cloud
abstract
The access control mechanisms of existing cloud systems, mainly OpenStack, fail to provide two key factors: i) centralized access mediation and ii) flexible policy customization. This situation prevents cloud administrators and end customers from enhancing their security. Furthermore, a variety of clouds have implemented their access control systems and policies in separated ways. This might confuse the customers whose businesses are built on multiple clouds, as they have to take efforts to accommodate their policies for different platforms. The OpenStack Security Modules (OSM) project has developed a least-invasive access control framework for OpenStack to enable different access control models to be implemented as loadable modules. This framework can be a good replacement of the existing permission checks in OpenStack and other platforms. We also propose an integration mechanism for multiple policies to form a single decision. This paper presents the design and implementation of OSM, including a new service called patron and an attachment module called access endpoint middleware (AEM). Experiments on the tempest benchmark indicate that OSM has improved the flexibility and security of policy management without affecting other services. Meantime, the average performance overhead remains as low as 7.3%, which is acceptable for practical use.
Wu Luo, Tian Puyang, Qingni Shen, Anbang Ruan, Zhonghai Wu
CLOUD4
2016 SECapacity: A Secure Capacity Scheduler in YARN
Chuntao Dong, Qingni Shen, Lijing Cheng, Yahui Yang, Zhonghai Wu
ICICS2
2016 MultiPol: Towards a Multi-policy Authorization Framework for RESTful Interfaces in the Cloud
Tian Puyang, Wu Luo, Qingni Shen, Anbang Ruan, Zhonghai Wu
ICICS4
2016 Sift - An Efficient Method for Co-residency Detection on Amazon EC2
Qingni Shen, Cong Li 0024, Yahui Yang, Zhonghai Wu
ICISSP2
2016 Whispers in the Cloud - A Covert Channel using the Result of Creating a Virtual Machine
Cong Li 0024, Qingni Shen, Yahui Yang, Zhonghai Wu
ICISSP2
2016 DDHCS: Distributed Denial-of-service Threat to YARN Clusters based on Health Check Service
Wenting Li 0002, Qingni Shen, Chuntao Dong, Yahui Yang, Zhonghai Wu
ICISSP2
2016 RestPL: Towards a Request-Oriented Policy Language for Arbitrary RESTful APIs
abstract
Recently an increasing number of web applications especially cloud computing systems utilize representational state transfer (REST) API to deploy their services for simplicity and clarity. Users can employ the same interface to invoke various applications from the Internet. For security purposes, service providers would control the access to the provided interface through policy enforcement. Yet the access control of REST interfaces lacks a uniform standard regarding the policy language and corresponding enforcement implementation, which brings two limitations: i) Users have to deal with totally different types of policies to accommodate certain systems. ii) Service providers have to design their own platform-specific authorization policy language and the related enforcement mechanisms. In this paper, we propose a REST Policy Language (RestPL) to express the authorization policies especially for REST APIs. RestPL is ensured to be request-oriented, based on our definition of the standard request form. This indicates that a RestPL policy can be automatically generated from an actual request, which helps mitigate a user's pressure during policy designing. Furthermore, we also provide a reference implementation for the enforcement code of RestPL based on regular expressions and deploy it on OpenStack Liberty to demonstrate its feasibility. The experimental results indicate the enforcement overhead of RestPL can be reduced to 80.6% compared with the original policy. In addition, we show that an end-user can also benefit from RestPL for reducing the learning effort by at least 41.6%.
Hongbo Zhou 0010, Qingni Shen, Anbang Ruan, Zhonghai Wu
ICWS3
2015 Eavesdropper: A Framework for Detecting the Location of the Processed Result in Hadoop
Chuntao Dong, Qingni Shen, Wenting Li 0002, Yahui Yang, Zhonghai Wu
ICICS2
2015 MB-DDIVR: A Map-Based Dynamic Data Integrity Verification and Recovery Scheme in Cloud Storage
Zizhou Sun, Yahui Yang, Qingni Shen, Zhonghai Wu
ICICS3
2015 SuperCall: A Secure Interface for Isolated Execution Environment to Dynamically Use External Services
Yueqiang Cheng, Xuhua Ding, Qingni Shen
SecureComm5
2015 POSTER: Ciphertext-Policy Attribute-Based Encryption Method with Secure Decryption Key Generation and Outsourcing Decryption of ABE Ciphertexts
Yuejian Fang, Zilong Wen, Qingni Shen, Yahui Yang, Zhonghai Wu
SecureComm3
2015 Ciphertext-Policy Attribute-Based Encryption with User and Authority Accountability
Xing Zhang 0002, Cancan Jin, Cong Li 0024, Zilong Wen, Qingni Shen, Yuejian Fang, Zhonghai Wu
SecureComm5
2013 A Covert Channel Using Event Channel State on Xen Hypervisor
Qingni Shen, Mian Wan, Zhi Zhang 0001, Sihan Qing, Zhonghai Wu
ICICS1
2011 Need for Symmetry: Addressing Privacy Risks in Online Social Networks
abstract
Private attributes of Online Social Network (OSN) users can be inferred from other information (which is usually from users' friends and group information). To address this, social networking sites allow users to hide their friend lists and group lists, so that general public cannot see them. However, if a user doesn't make his friend list public, but his friends have public friend list where we can find him, we can do reverse lookup to extend the friend lists of the user. Furthermore, many social networks allow non-group members to list the members of public groups (e.g., Face book). These are strong violations of OSN users' privacy, and can be considered as privacy risks caused by the asymmetric configuration of settings in OSNs. In this paper we present the privacy risks due to the lack of symmetric configurations, which exist in most of the OSNs. To make our idea more clear, we propose a inference attack and show that it can be used to infer users' private information, even users already made their friend list private. We theoretically analyze the risk of proposed privacy issues, and evaluate the risk using experiments based on real-world OSN data. We show that it is not sufficient to only disable friend list and group list to guarantee privacy, and propose methods to mitigate these privacy issues.
Cong Tang, Hu Xiong, Tao Yang 0015, Jian-bin Hu, Qingni Shen, Zhong Chen 0001
AINA6
2011 Towards Data Isolation & Collaboration in Storage Cloud
abstract
Cloud Storage has been turned into a common platform shared among varied organizations, even market competitors, thus has raised many security concerns. Most of the current researches focus on data encryption and decryption, in this paper, however, we take an alternative perspective-access control, to design and implement a secure solution for cloud storage, aiming to solve both the data isolation problem, which ensures that data in storage cloud owned by one company wouldn't be crossly accessed by other ones, and data collaboration problem, which makes data sharing between different organizations through storage cloud possible while still under the restriction of company data isolation. Besides, we have presented a pretty flexible security policy which could be easily customized to fit the variant security requirements in different cooperation. Finally, a prototype has been implemented based on HDFS by this policy, and the time cost is given and evaluated.
Qingni Shen, Yahui Yang, Zhonghai Wu
APSCC1
2011 SecGuard: Secure and Practical Integrity Protection Model for Operating Systems
Ennan Zhai, Qingni Shen, Tao Yang 0015, Liping Ding, Sihan Qing
APWeb2
2011 Poster: LBMS: load balancing based on multilateral security in cloud
Qingni Shen, Zhonghai Wu, Cong Zhang 0001, Anbang Ruan, Liang Gu
CCS2
2011 SecDM: Securing Data Migration between Cloud Storage Systems
abstract
With the development of cloud computing, cloud security issues have recently gained traction in the research community. Although much of the efforts are focused on securing the operation system and virtual machine, or securing data storage inside a cloud system, this paper takes an alternative perspective to cloud security-the security of data migration between different clouds. First, we describe some threats when we are doing data migration. Second, we propose a security mechanism to deal with the security issues on data migration from one cloud to another. Third, we design a prototype to give the mechanism a brief implementation based on HDFS (Hadoop Distributed File System) and we do a series of tests to evaluate our prototype. Here, the solutions to securing data migration between clouds mainly involve in SSL negotiation, migration ticket design and block encryption in distributed file system and cluster parallel computing.
Qingni Shen, Lizhe Zhang, Yahui Yang, Zhonghai Wu
DASC1
2011 A Variant of Boyen-Waters Anonymous IBE Scheme
Qingni Shen, Yongming Jin, Yu Chen 0003, Zhong Chen 0001, Sihan Qing
ICICS2
2011 A Way of Key Management in Cloud Storage Based on Trusted Computing
Qingni Shen, Yahui Yang, Sihan Qing
NPC2
2010 SCOBA: source code based attestation on custom software
abstract
Most existing attestation schemes deal with binaries and typically require an exhaustive list of known-good measurements beforehand in order to perform verification. However, many programs nowadays are custom-built: the end user is allowed to tailor, compile and build the source code into various versions, or even build everything from scratch. As a result, it is very difficult, if not impossible, for existing schemes to attest the custom-built software with theoretically unlimited number of valid binaries available. This paper introduce SCOBA, a new Source COde Based Attestation framework, to specifically deal with the attestation on custom software. Instead of trying to obtain a know-good measurement list, SCOBA focuses on the source code and provides a trusted building process to attest the resulting binaries based on the source files and building configuration. SCOBA introduces a trusted verifier to certify the binary code of custom-build program according to its source code and building configuration. For custom-built software based on open-source distributions, we implemented a fully automatic trusted building system prototype for SCOBA based on GCC and TPM. As a case study, we also applied SCOBA to Gentoo and its Portage, which is a source code based package management system. Experimental results show that remote attestation, one of the key TCG features, can be made practically available to the free software community.
Liang Gu, Yao Guo 0001, Anbang Ruan, Qingni Shen, Hong Mei 0001
ACSAC4
2009 Trusted Isolation Environment: An Attestation Architecture with Usage Control Model
Anbang Ruan, Qingni Shen, Liang Gu, Yahui Yang, Zhong Chen 0001
ICICS2