VLDB 2026 Research / reviewers in the wild / expert
Longfei Wu
dblp:126/7646
· DBLP profile ↗
39ranked-venue papers
5as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 5 first-author · 7 since 2021Systems, architecture and hardware · 3 · 1 since 2021Security and privacy · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An epoch-weighted privacy budget allocation framework for fine-tuning large language models
Peisheng Zhang, Naiyu Wang, Longfei Wu, Liehuang Zhu, Zhitao Guan |
Sci. China Inf. Sci. | 3 |
| 2025 | Balancing Differential Privacy and Utility: A Relevance-Based Adaptive Private Fine-Tuning Framework for Language ModelsabstractDifferential privacy (DP) has been proven to be an effective universal solution for privacy protection in language models. Nevertheless, the introduction of DP incurs significant computational overhead. One promising approach to this challenge is to integrate Parameter Efficient Fine-Tuning (PEFT) with DP, leveraging the memory-efficient characteristics of PEFT to reduce the substantial memory consumption of DP. Given that fine-tuning aims to quickly adapt pretrained models to downstream tasks, it is crucial to balance privacy protection with model utility to avoid excessive performance compromise. In this paper, we propose a Relevance-based Adaptive Private Fine-Tuning (Rap-FT) framework, the first approach designed to mitigate model utility loss caused by DP perturbations in the PEFT context, and to achieve a balance between differential privacy and model utility. Specifically, we introduce an enhanced layer-wise relevance propagation process to analyze the relevance of trainable parameters, which can be adapted to the three major categories of PEFT methods. Based on the relevance map generated, we partition the parameter space dimensionally, and develop an adaptive gradient perturbation strategy that adjusts the noise addition to mitigate the adverse impacts of perturbations. Extensive experimental evaluations are conducted to demonstrate that our Rap-FT framework can improve the utility of the fine-tuned model compared to the baseline differentially private fine-tuning methods, while maintaining a comparable level of privacy protection. Naiyu Wang, Shen Wang 0012, Meng Li 0006, Longfei Wu, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | MulDoor: A Multi-target Backdoor Attack Against Federated Learning SystemabstractIn recent years, with the development of wireless communication networks, federated learning (FL) has been widely deployed in distributed scenarios as a privacy-preserving machine learning paradigm. Due to its inherent features, FL shows vulnerability to backdoor attacks. In a backdoor attack, an adversary manipulates the global model’s output by compromising the model of one or multiple participants. Existing backdoor attacks are constrained to outputting a single specified target label during the inference phase, limiting the adversary’s flexibility to alter the model’s output when different target labels are required. In this paper, we study the multi-target attack scenario within the federated learning context, where the adversary aims to manipulate the global model to output various specified labels by inserting different types of triggers. To effectively insert multiple backdoors simultaneously without reducing the attack’s effectiveness, we propose MulDoor, a novel multi-target backdoor attack scheme. MulDoor incorporates the concept of supervised contrastive learning to learn the discrepancies among different types of triggers and mitigate interference between them. The experimental results demonstrate that MulDoor achieves better attack effectiveness compared to existing backdoor attacks in a multi-target backdoor attack setting. Xuan Li 0007, Longfei Wu, Zhitao Guan, Xiaojiang Du, Nadjib Aitsaadi, Mohsen Guizani |
GLOBECOM | 2 |
| 2024 | From Informal Ed to the University - Hands-on Use of the BBC Micro: bit in CS1 Courses Post-COVIDabstractBBC micro:bits have long been used in informal and pre-college educational environments. With a wealth of sensors and a rich ecosystem of add-ons, it provides an engaging platform for teaching basic computer science. The use of block programming separates the learning of Computational Thinking and coding from the challenges students face with language syntax. In addition, the physicality of the device increases student engagement as they see code interact with the real world. Albert Chan, Tieming Geng, Joseph Kabbes, Mingxian Jin, Longfei Wu |
SIGCSE (2) | 5 |
| 2024 | GradDiff: Gradient-based membership inference attacks against federated distillation with differential comparison
Xiaodong Wang 0025, Longfei Wu, Zhitao Guan |
Inf. Sci. | 2 |
| 2024 | Research on person re-identification based on multi-level attention model
Danyang Liang, Longfei Wu, Suyun Luo |
Multim. Tools Appl. | 3 |
| 2024 | WEDA: Exploring Copyright Protection for Large Language Model Downstream AlignmentabstractLarge Language Models (LLMs) have shown incomparable representation and generalization capabilities, which have led to significant advancements in Natural Language Processing (NLP). Before deployment, the pre-trained LLMs often need to be tailored to specific downstream tasks for improved performance, which is commonly referred to as downstream alignment. This is a costly effort considering the needed manpower, training resources, and downstream-specific data. While much attention has been paid to protecting the copyright of the models themselves, the copyright protection of LLM alignment has been largely overlooked. In this paper, we present Watermark Embedding for Downstream Alignment (WEDA) scheme, which can provide effective copyright protection for two popular LLM alignment techniques parameter-efficient fine-tuning (PEFT) and in-context learning (ICL). For alignment through PEFT, we propose a Chain of Thought (CoT) based solution to embed watermarks into the PEFT weights. Furthermore, we extend this solution to safeguard alignment through ICL by utilizing the prefix-integrated CoT to watermark examples embedded within ICL prompts. We conduct an extensive experimental evaluation to demonstrate the effectiveness of our proposed scheme. Shen Wang 0012, Jialiang Dong, Longfei Wu, Zhitao Guan |
IEEE ACM Trans. Audio Speech Lang. Process. | 3 |
| 2023 | FeatureMix: A General Adversarial Defense Method for Pretrained Language ModelsabstractPretrained language models (PLMs) that are trained over large-scale data and then finetuned on downstream tasks have achieved great success. However, they are vulnerable to adversarial attacks. Adversarial training with both clean and adversarial data is a widely-used technique to improve model robustness. In this paper, we propose FeatureMix, a straightforward yet effective adversarial defense strategy for PLMs by finetuning on both discrete adversarial examples and online virtual examples. During finetuning, we augment clean data with discrete attacks first and generate virtual examples in each finetuning epoch by randomly mixing local latent features in the hidden layers of augmented data pairs. The virtual examples serve as additional training signals, regularizing the PLMs to favor mixing of latent features between discrete augmented examples and thus enhance adversarial robustness. The experimental evaluation results show that FeatureMix outperforms prevailing baseline methods in terms of robustness against adversarial attacks, without significantly reducing generalization performance. Huoyuan Dong, Longfei Wu, Zhitao Guan |
GLOBECOM | 2 |
| 2023 | GBMIA: Gradient-based Membership Inference Attack in Federated LearningabstractMembership inference attack (MIA) has been proved to pose a serious threat to federated learning (FL). However, most of the existing membership inference attacks against FL rely on the specific attack models built from the target model behaviors, which make the attacks costly and complicated. In addition, directly adopting the inference attacks that are originally designed for machine learning models into the federated scenarios can lead to poor performance. We propose GBMIA, an attack model-free membership inference method based on gradient. We take full advantage of the federated learning process by observing the target model's behaviors after gradient ascent tuning. And we combine prediction correctness and the gradient norm-based metric for membership inference. The proposed GBMIA can be conducted by both global and local attackers. We conduct experimental evaluations on three real-world datasets to demonstrate that GBMIA can achieve a high attack accuracy. We further apply the arbitration mechanism to increase the effectiveness of GBMIA which can lead to an attack accuracy close to 1 on all three datasets. We also conduct experiments to substantiate that clients going offline and the overlap of clients' training sets have great effect on the membership leakage in FL. Xiaodong Wang 0025, Naiyu Wang, Longfei Wu, Zhitao Guan, Xiaojiang Du, Mohsen Guizani |
ICC | 3 |
| 2022 | A Blockchain-Based Dual-Side Privacy-Preserving Multiparty Computation Scheme for Edge-Enabled Smart GridabstractUnlike a traditional centralized and producer-controlled power grid, the smart grid is a more complicated distributed power system consisted of many resources and applications. In smart grid, huge amounts of data generated by edge devices are collected by different parties. To achieve high operation efficiency, it is important to enable the data sharing and cooperative computation among different parties. How to protect the security and privacy of the utility data and the identities of their owners has become a major concern. There have been some studies on this issue. However, most of these works failed to consider the privacy protection in the dual sides of the data owner and receiver. In this article, we propose BPM4SG, a blockchain-based dual-side privacy-preserving multiparty computation (MPC) scheme for edge-enabled smart grid. In BPM4SG, the data segmentation method is adopted to ensure the security of MPC (e.g., summation) in edge nodes. The consortium blockchain and smart contract are used to further increase the system security and avoid the dependency on trusted third parties. Additionally, a data obfuscation method based on the ring signatures and a new one-time address scheme are proposed to protect the privacy of both the data owner and data receiver. The analysis shows that BPM4SG can meet the security and privacy requirements of smart grid. The experimental evaluation results demonstrate that our scheme has a better performance compared with other popular schemes. Zhitao Guan, Xiao Zhou 0025, Peng Liu 0027, Longfei Wu, Wenti Yang |
IEEE Internet Things J. | 4 |
| 2021 | Achieving adaptively secure data access control with privacy protection for lightweight IoT devices
Zhitao Guan, Wenti Yang, Liehuang Zhu, Longfei Wu, Ruimiao Wang |
Sci. China Inf. Sci. | 4 |
| 2021 | A sentence-level text adversarial attack algorithm against IIoT based smart grid
Jialiang Dong, Zhitao Guan, Longfei Wu, Xiaojiang Du, Mohsen Guizani |
Comput. Networks | 3 |
| 2021 | Secure Data Access Control With Fair Accountability in Smart Grid Data Sharing: An Edge Blockchain ApproachabstractNowadays, the advance of smart grid technology has fostered the development of microgrids, which can efficiently control and manage the distributed energy resources (DERs). In smart grid, IoT devices generate huge amounts of data, which are collected and shared among DERs, microgrids, and the main grid. To protect the shared data, it is necessary to implement the secure and efficient data access control. Ciphertext policy attribute-based encryption (CP-ABE) is a promising solution for the distributed system. However, lightweight IoT devices with limited computing capability cannot handle the computationally intensive ABE algorithms. To overcome this constraint, the decryption phase of CP-ABE is usually outsourced to the cloud, but this is inefficient and not safe enough in the distributed environment. In this article, we propose an edge blockchain empowered secure data access control scheme with fair accountability for the smart grid. The computation workloads of end user devices are outsourced to the edge nodes in a consortium blockchain system We adopt an on-chain/off-chain approach to ensure the flexible data sharing. Additionally, we adopt the threshold secret sharing scheme to establish a distributed authority. The security analysis and performance evaluation are conducted to prove the security and efficiency of our scheme. We use the Raspberry Pi to simulate lightweight IoT devices in the Hyperledger fabric platform to prove the usability of our scheme. Wenti Yang, Zhitao Guan, Longfei Wu, Xiaojiang Du, Mohsen Guizani |
IEEE Internet Things J. | 3 |
| 2021 | Achieving efficient and Privacy-preserving energy trading based on blockchain and ABE in smart grid
Zhitao Guan, Wenti Yang, Longfei Wu, Naiyu Wang, Zijian Zhang 0001 |
J. Parallel Distributed Comput. | 4 |
| 2021 | Achieving Secure Search over Encrypted Data for e-Commerce: A Blockchain ApproachabstractThe advances of Internet technology has resulted in the rapid and pervasive development of e-commerce, which has not only changed the production and operation mode of many enterprises, but also affected the economic development mode of the whole society. This trend has incurred a strong need to store and process large amounts of sensitive data. The traditional data storage and search solutions cannot meet such requirements. To tackle this problem, in this article, we proposed Consortium Blockchain-based Distributed Secure Search (CBDSS) Scheme over encrypted data in e-Commerce environment. By integrating the blockchain and searchable encryption model, sensitive data can be effectively protected. The consortium blockchain can ensure that only authorized nodes can join the system. To fairly assign nodes for the search tasks, we developed an endorsement strategy in which two agent roles are set up to divide and match the search tasks with the virtual resources according to the load capacity of each node. The security analysis and experiments are conducted to evaluate the performance of our proposed scheme. The evaluation results have proved the reliability and security of our scheme over existing methods. Zhitao Guan, Naiyu Wang, Xunfeng Fan, Xueyan Liu 0007, Longfei Wu, Shaohua Wan 0001 |
ACM Trans. Internet Techn. | 5 |
| 2020 | Autonomous and Privacy-preserving Energy Trading Based on Redactable Blockchain in Smart GridabstractWith the development of information and communication technologies in smart grid, peer-to-peer (P2P) energy trading for distributed energy resources (DER) has achieved an efficient two-way flow of information and power. The adoption of blockchain technology makes the P2P energy trading more secure and transparent. Considering that users with extra energy may be reluctant to participate in the energy trading due to privacy concerns, many researchers have focused on potential privacy issues. However, most of the existing works are built on top of a semi-decentralized energy blockchain in which only a few certified third-party nodes are authorized to manage and verify transactions - once these authorized nodes are attacked, the system will be threatened. In this paper, we use the Ciphertext Policy Attribute-Based Encryption (CP-ABE) scheme to establish a blockchain based P2P energy trading approach with privacy preservation, which allows peer nodes, including sellers and purchasers, to manage and verify transactions autonomously without needing any additional third-party nodes. In addition, we introduce the redactable blockchain technology into our scheme to ensure users can modify their sensitive information uploaded to the blockchain. Furthermore, we improve the CP-ABE scheme to provide low latency in the system. The experimental evaluations show that our scheme is efficient and practical. Wenti Yang, Zhitao Guan, Longfei Wu, Xiaojiang Du, Zefang Lv, Mohsen Guizani |
GLOBECOM | 3 |
| 2020 | A Lightweight Attribute Based Encryption Scheme with Constant Size Ciphertext for Internet of ThingsabstractThe Internet of Things technology has been used in a wide range of fields, ranging from industrial applications to individual lives. As a result, a massive amount of sensitive data is generated and transmitted by IoT devices. Those data may be accessed by a large number of complex users. Therefore, it is necessary to adopt an encryption scheme with access control to achieve more flexible and secure access to sensitive data. The Ciphertext Policy Attribute-Based Encryption (CP-ABE) can achieve access control while encrypting data can match the requirements mentioned above. However, the long ciphertext and the slow decryption operation makes it difficult to be used in most IoT devices which have limited memory size and computing capability. This paper proposes a modified CP-ABE scheme, which can implement the full security (adaptive security) under the access structure of AND gate. Moreover, the decryption overhead and the length of ciphertext are constant. Finally, the analysis and experiments prove the feasibility of our scheme. Wenti Yang, Ruimiao Wang, Zhitao Guan, Longfei Wu, Xiaojiang Du, Mohsen Guizani |
ICC | 4 |
| 2020 | A Differentially Private Classification Algorithm With High Utility for Wireless Body Area NetworksabstractThe advancement of the wireless body area networks (WBAN) and sensor technologies allows us to collect a variety of physiological and behavioral data from human body. And appropriate application of machine learning methods can greatly promote the development of e-health. Nevertheless, the collected data contains personal privacy information. When using the machine learning methods to analyze the collected data, some information of the training data will be stored in the learning models unconsciously. To handle such information disclosure problem, we propose a differentially private classification algorithm based on ensemble decision tree with high utility for wireless body area networks. In order to improve the accuracy and stableness of classification, the bagging framework of ensemble learning is used in our algorithm. We aggregate the results of multiple private decision trees as the final classification in a weight-based voting way. For each private decision tree trained on the bootstrap samples, we offer a novel privacy budget allocation strategy that allows the nodes in larger depth to get more privacy budget, which can mitigate the problem of excessive noise introduced to leaf nodes to some extent. The better classification accuracy and stableness of this new algorithm, especially on small dataset, are demonstrated by simulation experiments. Xianwen Sun, Lingyun Shi, Longfei Wu, Zhitao Guan, Xiaojiang Du, Mohsen Guizani |
WCNC | 3 |
| 2020 | A differentially private greedy decision forest classification algorithm with high utility
Zhitao Guan, Xianwen Sun, Lingyun Shi, Longfei Wu, Xiaojiang Du |
Comput. Secur. | 4 |
| 2020 | Cross-lingual multi-keyword rank search with semantic extension over encrypted data
Zhitao Guan, Xueyan Liu 0007, Longfei Wu, Jun Wu 0001, Ruzhi Xu, Jinhu Zhang, Yuanzhang Li 0001 |
Inf. Sci. | 3 |
| 2019 | An Efficient and Privacy-Preserving Energy Trading Scheme Based on BlockchainabstractDistributed transaction model has gradually replaced the traditional centralized transaction model and has become the leading direction of development in energy trading. As the underlying support, blockchain technology is attracting more and more attention due to its advantages, i.e., integrity and non-repudiation. However, most blockchain-based trading models face the problem of privacy protection. In this paper, to solve this problem, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is introduced as the core algorithm to reconstruct the transaction model. Specifically, we build a general model for distributed transaction called PP-BCTS (Privacy- Preserving Blockchain Trading Scheme). It can achieve fine-grained access control through transaction arbitration in ciphertext form. This design can maximize the protection of private information and can greatly improve the security and reliability of the transaction model. Additionally, a credibility-based equity proof consensus mechanism is proposed in PP-BCTS, which can greatly improve the operational efficiency. Security analysis and experimental evaluations are conducted to prove the validity and practicability of our proposed scheme. Zhitao Guan, Xiao Zhou 0025, Longfei Wu, Xiaojiang Du, Mohsen Guizani |
GLOBECOM | 4 |
| 2019 | Achieving Secure and Efficient Cloud Search Services: Cross-Lingual Multi-Keyword Rank Search Over Encrypted Cloud DataabstractMulti-user multi-keyword ranked search scheme in arbitrary language is a novel multi-keyword rank searchable encryption (MRSE) framework based on Paillier Cryptosystem with Threshold Decryption (PCTD). Compared to previous MRSE schemes constructed based on the k-nearest neighbor searchable encryption (KNN-SE) algorithm, it can mitigate some drawbacks and achieve better performance in terms of functionality and efficiency. Additionally, it does not require a predefined keyword set and support keywords in arbitrary languages. However, due to the pattern of exact matching of keywords in the new MRSE scheme, multilingual search is limited to each language and cannot be searched across languages. In this paper, we propose a cross-lingual multi-keyword rank search (CLRSE) scheme which eliminates the barrier of languages and achieves semantic extension with using the Open Multilingual Wordnet. Our CLRSE scheme also realizes intelligent and personalized search through flexible keyword and language preference settings. We evaluate the performance of our scheme in terms of security, functionality, precision and efficiency, via extensive experiments. Xueyan Liu 0007, Zhitao Guan, Xiaojiang Du, Longfei Wu, Zain Ul Abedin, Mohsen Guizani |
ICC | 4 |
| 2019 | POKs Based Secure and Energy-Efficient Access Control for Implantable Medical Devices
Chenglong Fu 0002, Xiaojiang Du, Longfei Wu, Qiang Zeng 0001, Amr Mohamed 0001, Mohsen Guizani |
SecureComm (1) | 3 |
| 2019 | EFFECT: an efficient flexible privacy-preserving data aggregation scheme with authentication in smart grid
Zhitao Guan, Yue Zhang 0027, Liehuang Zhu, Longfei Wu, Shui Yu 0001 |
Sci. China Inf. Sci. | 4 |
| 2019 | Achieving differential privacy against non-intrusive load monitoring in smart grid: A fog computing approachabstractSummary Fog computing, a non‐trivial extension of cloud computing to the edge of the network, has great advantage in providing services with a lower latency. In smart grid, the application of fog computing can greatly facilitate the collection of consumer's fine‐grained energy consumption data, which can then be used to draw the load curve and develop a plan or model for power generation. However, such data may also reveal customer's daily activities. Non‐intrusive load monitoring (NILM) can monitor an electrical circuit that powers a number of appliances switching on and off independently. If an adversary analyzes the meter readings together with the data measured by an NILM device, the customer's privacy will be disclosed. In this paper, we propose an effective privacy‐preserving scheme for electric load monitoring, which can guarantee differential privacy of data disclosure in smart grid. In the proposed scheme, an energy consumption behavior model based on Factorial Hidden Markov Model (FHMM) is established. In addition, noise is added to the behavior parameter, which is different from the traditional methods that usually add noise to the energy consumption data. The analysis shows that the proposed scheme can get a better trade‐off between utility and privacy compared with other popular methods. Longfei Wu, Zhitao Guan, Xiaojiang Du |
Concurr. Comput. Pract. Exp. | 3 |
| 2019 | Achieving data utility-privacy tradeoff in Internet of Medical Things: A machine learning approach
Zhitao Guan, Zefang Lv, Xiaojiang Du, Longfei Wu, Mohsen Guizani |
Future Gener. Comput. Syst. | 4 |
| 2019 | APPA: An anonymous and privacy preserving data aggregation scheme for fog-enhanced IoT
Zhitao Guan, Yue Zhang 0027, Longfei Wu, Jun Wu 0001, Jing Li 0006, Yinglong Ma 0001 |
J. Netw. Comput. Appl. | 3 |
| 2018 | Enabling Fair Spectrum Sharing between Wi-Fi and LTE-UnlicensedabstractDue to the fast increase of mobile traffic, most mobile network operators face the congestion issue in licensed spectrum bands. Several telecommunication vendors and operators propose to expand LTE service to the unlicensed spectrum bands to relieve the traffic congestion. However, LTE in unlicensed spectrum may interfere with Wi-Fi communications in the same bands and cause significant decrease in the quality of service of Wi-Fi. In this paper, we propose a novel mechanism that enables negotiations between two different wireless technologies (Wi-Fi and LTE), which ensures fair spectrum sharing between Wi-Fi and LTE-Unlicensed (LTE-U) in the same bands. We formulate the co-existence of Wi-Fi and LTE-U as a constrained optimization problem, and we solve the problem. We evaluate the performance of the proposed scheme via NS-3 simulations. The simulation results show that our approach can effectively improve the overall channel utilization and reduce the interference between Wi-Fi and LTE-U. Longfei Wu, Xiaojiang Du, Guisheng Yin, Jie Wu 0001, Bo Ji 0001, Xiali Hei 0001 |
ICC | 2 |
| 2017 | A Novel Traceroute-Based Detection Scheme for Wi-Fi Evil Twin AttacksabstractWi-Fi has been widely used in our work, home, and many other places, such as hotels and airports. However, the data may be leaked if the access through Wi-Fi is not well-guarded. Wi-Fi hotspots are deployed in an unprecedented speed to facilitate people's lives. The open access nature makes them vulnerable to an evil twin access point (AP), which has the same service set id (SSID) as the legitimate AP and larger signal strength. Current Wi-Fi capable devices are not able to detect the evil twin attack, and will automatically switch to the bogus AP. In this paper, we devise a novel detection scheme based on the commonly used network diagnostic tool traceroute. A remote detection server is set up so that the client-to-server and server-to-client traceroute results are compared. If the evil twin AP is present, it will attempt to conceal the legitimate AP. The inconsistency among the two traceroute results will reveal the evil twin attack. We first present the attack model, then describe the detection scheme in detail. In our implementation, a Nexus 4 smartphone serves as the client, a desktop PC with a USB wireless adapter is set up as the evil twin AP, and the detection service is running on an Amazon EC2 Server. The experimental result demonstrates that our scheme can effectively detect an evil twin attack. Alex Burns, Longfei Wu, Xiaojiang Du, Liehuang Zhu |
GLOBECOM | 2 |
| 2017 | EPDA: Enhancing Privacy-Preserving Data Authentication for Mobile Crowd SensingabstractAs a popular application, mobile crowd sensing systems aim at providing more convenient service via the swarm intelligence. With the popularity of sensor-embedded smart phones and intelligent wearable devices, mobile crowd sensing is becoming an efficient way to obtain various types of sensing data from individuals, which will make people's life more convenient. However, mobile crowd sensing systems today are facing a critical challenge, namely the privacy leakage of the sensitive information and valuable data, which can raise grave concerns among the participants. To address this issue, we propose an enhanced secure certificateless privacy-preserving verifiable data authentication scheme for mobile crowd sensing, named EPDA. The proposed scheme provides unconditional anonymous data authentication service for mobile crowd sensing, by deploying an improved certificateless ring signature as the cryptogram essential, in which the big sensing data should be signed by one of legitimate members in a specific group and could be verified without exposing the actual identity of the participant. The formal security proof demonstrates that EPDA is secure against existential forgery under adaptive chosen message and identity attacks in random oracle model. Finally, extensive simulations are conducted. The results show that the proposed EPDA efficiently decreases computational cost and time consumption in the sensing data authentication process. Fanghui Cai, Longfei Wu, Liehuang Zhu, Xiaojiang Du |
GLOBECOM | 3 |
| 2017 | VDAS: Verifiable data aggregation scheme for Internet of ThingsabstractAlong with the miniaturization of various types of sensors, a mass of intelligent terminals are gaining stronger sensing capability, which raises a deeper perception and better prospect of Internet of Things (IoT). With big sensing data, IoT provides lots of convenient services for the monitoring and management of smart cities and people's daily lives. However, there are still many security challenges influencing the further development of IoT, one of which is how to quickly verify the big data obtained from IoT terminals. Aggregate signature is an efficient approach to perform big data authentication. It can effectively reduce the computation and communication overheads. In this paper, utilizing these features, we construct a verifiable data aggregation scheme for Internet of Things, named VDAS, based on an improved certificateless aggregate signature algorithm. In VDAS, the length of the aggregated authentication message is independent of the number of IoT terminals. Then, we prove that VDAS is existentially unforgeable under adaptive chosen message attacks assuming that the computational Diffie-Hellman problem is hard. Additionally, the proposed VDAS achieves a better trade-off on the computation overheads between the resource-constrained IoT terminals and the data center. Jinping Han, Longfei Wu, Xiaojiang Du |
ICC | 3 |
| 2017 | Achieving Fair Spectrum Allocation for Co-Existing Heterogeneous Secondary User NetworksabstractThe rapid growth of mobile network traffic has posed a serious challenge to the limited spectrum. The United States Federal Communications Commission (FCC) allowed the utilization of unused TV White Space (TVWS) by unlicensed secondary users (SUs). Particularly, the IEEE 802.19.1 standard is proposed to regulate the coexistence of dissimilar or independently operated SU networks and devices on the TV band. In this paper, we propose a fair spectrum allocation scheme for co-existing SU networks under the IEEE 802.19.1 system architecture. The entire heterogeneous wireless system is divided into two levels, and the spectrum allocation is formulated into a four-stage problem. Unlike previous allocation schemes that maximize the aggregated throughput, the aim of our scheme is to maximize the end user satisfactions within each SU network while maintaining fairness among and within the SU networks. Extensive simulations demonstrate the effectiveness of our spectrum allocation scheme. Longfei Wu, Xiaojiang Du, Jie Wu 0001, Bin Song 0001 |
ICCCN | 1 |
| 2017 | Achieving Efficient and Secure Data Acquisition for Cloud-Supported Internet of Things in Smart GridabstractCloud-supported Internet of Things (Cloud-IoT) has been broadly deployed in smart grid systems. The IoT front-ends are responsible for data acquisition and status supervision, while the substantial amount of data is stored and managed in the cloud server. Achieving data security and system efficiency in the data acquisition and transmission process are of great significance and challenging, because the power grid-related data is sensitive and in huge amount. In this paper, we present an efficient and secure data acquisition scheme based on ciphertext policy attribute-based encryption. Data acquired from the terminals will be partitioned into blocks and encrypted with its corresponding access subtree in sequence, thereby the data encryption and data transmission can be processed in parallel. Furthermore, we protect the information about the access tree with threshold secret sharing method, which can preserve the data privacy and integrity from users with the unauthorized sets of attributes. The formal analysis demonstrates that the proposed scheme can fulfill the security requirements of the Cloud-IoT in smart grid. The numerical analysis and experimental results indicate that our scheme can effectively reduce the time cost compared with other popular approaches. Zhitao Guan, Jing Li 0006, Longfei Wu, Yue Zhang 0027, Jun Wu 0001, Xiaojiang Du |
IEEE Internet Things J. | 3 |
| 2017 | Access Control Schemes for Implantable Medical Devices: A SurveyabstractImplantable medical devices (IMDs) are electronic devices implanted within human body for diagnostic, monitoring, and therapeutic purposes. It is imperative to guarantee that IMDs are completely secured since the patient's life is closely bound to the robustness and effectiveness of IMDs. Intuitively, we have to ensure that only the authorized medical personnel and IMD programmer can access the IMD. However, in recent years, several attacks have been reported which can successfully compromise a number of IMD products, e.g., stealing the sensitive health data and issuing fake commands. Up to now, there is no commonly agreed and well-recognized security standards and the protection of IMD is still an open problem. In this paper, we present a comprehensive survey of the existing literature on IMD security, with a focus on the access control schemes to prevent unauthorized access. Specifically, we first reviewed the security incidents, IMD threat model and the development of regulations for IMD security. Next, we classified existing IMD access control schemes based on architecture, type of keys used, access control channel, and logic. We also analyzed how different access control models can be adopted to secure IMD. Besides, we particularly discussed the viability of online authentication and low/zero power authentication in the IMD context. Longfei Wu, Xiaojiang Du, Mohsen Guizani, Amr Mohamed 0001 |
IEEE Internet Things J. | 1 |
| 2017 | A Survey on Security and Privacy Issues in Internet-of-ThingsabstractInternet-of-Things (IoT) are everywhere in our daily life. They are used in our homes, in hospitals, deployed outside to control and report the changes in environment, prevent fires, and many more beneficial functionality. However, all those benefits can come of huge risks of privacy loss and security issues. To secure the IoT devices, many research works have been conducted to countermeasure those problems and find a better way to eliminate those risks, or at least minimize their effects on the user's privacy and security requirements. The survey consists of four segments. The first segment will explore the most relevant limitations of IoT devices and their solutions. The second one will present the classification of IoT attacks. The next segment will focus on the mechanisms and architectures for authentication and access control. The last segment will analyze the security issues in different layers. Longfei Wu, Guisheng Yin, Hongbin Zhao |
IEEE Internet Things J. | 2 |
| 2015 | Effective task scheduling in proximate mobile device based communication systemsabstractDespite the increasing capabilities, mobile devices still cannot satisfy the computation requirement of many applications. Intuitively, this can be solved by outsourcing tasks to external resources such as a remote server, cloud, or closely deployed cloudlet. However, all of them require extra infrastructures. In this paper, we consider a proximate-mobile-device based communication system in which all tasks and resources are under the control of a central scheduler. We propose a friendship-based task scheduling algorithm to address the contentions when resources are not sufficient. We also present two attack models including the denial-of-service (DoS) attack and the collusion attack. We evaluate the performance of the proposed algorithm along with another contribution-based task scheduling algorithm through extensive experiments. Longfei Wu, Xiaojiang Du, Hongli Zhang 0001, Wei Yu 0002, Chonggang Wang |
ICC | 1 |
| 2014 | Analyzing mobile phone vulnerabilities caused by cameraabstractNowadays mobile phones have been widely used, and Android is one of the most popular mobile operating system. The security issue of Android has caught great concerns among mobile users and researchers. In this paper, we study the vulnerabilities related of phone cameras. Specifically, we discover and present several camera-based attacks including the basic camera attack and advanced passcode inference attacks. We implement these attacks on real phones (with anti-virus software installed) and demonstrate the feasibility and effectiveness of the attacks. Furthermore, a lightweight defense scheme is proposed to secure phones against these attacks. Longfei Wu, Xiaojiang Du, Xinwen Fu, Ralph Oyini Mbouna, Seong G. Kong |
GLOBECOM | 1 |
| 2014 | MobiFish: A lightweight anti-phishing scheme for mobile phonesabstractRecent years have witnessed the increasing threat of phishing attacks on mobile platforms. In fact, mobile phishing is more dangerous due to the limitations of mobile phones and mobile user habits. Existing schemes designed for phishing attacks on computers/laptops cannot effectively address phishing attacks on mobile devices. This paper presents MobiFish, a novel automated lightweight anti-phishing scheme for mobile platforms. MobiFish verifies the validity of web pages and applications (Apps) by comparing the actual identity to the identity claimed by the web pages and Apps. MobiFish has been implemented on the Nexus 4 smartphone running the Android 4.2 operating system. We experimentally evaluate the performance of MobiFish with 100 phishing URLs and corresponding legitimate URLs, as well as fake Facebook Apps. The result shows that MobiFish is very effective in detecting phishing attacks on mobile phones. Longfei Wu, Xiaojiang Du, Jie Wu 0001 |
ICCCN | 1 |
| 2011 | Social Summarization via Automatically Discovered Social Context
Po Hu 0001, Cheng Sun 0002, Longfei Wu, Donghong Ji, Chong Teng |
IJCNLP | 3 |