Yao-Tung Tsou

dblp:129/1053 · DBLP profile ↗
← Back
16ranked-venue papers
8as first author
4since 2021 · last 2023
0000-0002-7324-5135ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 5 first-author · 1 since 2021Security and privacy · 5 · 1 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 User-Driven Synthetic Dataset Generation With Quantifiable Differential Privacy
abstract
Recently, releasing data to a third party for secondary analysis has become a trend of service computing. However, data owners are concerned that such a move may expose individuals’ records, which is in violation of regulations such as the European Union's General Data Protection Regulation. Differential privacy has been proposed as a possible solution to the aforementioned problem. The privacy budget$\varepsilon$in differential privacy is for theoretical interpretation, but in practice, its application in measuring the risk of data disclosure has not been well studied, especially with sampling-based synthetic datasets. Moreover, datasets released by data owners with quantifiable privacy levels and the explicit utility for these datasets have yet to be well developed. In this paper, we present an intuitive approach for defining the privacy level (i.e., data hit rate and$k$-level) and utility level (i.e., basic statistics and a series of data mining models), and the privacy budget$\varepsilon$is quantified for evaluating the risk and utility of private data. In addition, we propose two user-driven synthetic dataset hunting methods to generate a synthetic dataset with the specified privacy objective, enabling the data owner (e.g., the government and financial companies) to understand the possible privacy risk and thereby release datasets with confirmed privacy level. To the best of our knowledge, this is the first method that allows data providers to automatically generate synthetic datasets with a quantifiable privacy level for the service of open data.
Bo-Chen Tai, Yao-Tung Tsou, Szu-Chuang Li, Yennun Huang, Pei-Yuan Tsai, Yu-Cheng Tsai
IEEE Trans. Serv. Comput.2
2022 COVID-LPS: Location-Protected Services for COVID-19 Prevention
abstract
The COVID-19 pandemic has caused not only worldwide health problems but also economic damage. Numerous researchers and intuitions have attempted to visualize confirmed COVID-19 cases with maps to provide timely information to users (e.g., warnings upon entry of crowded areas) and prevent the spread of COVID-19. However, such systems are limited by their poor protection of private information because they must collect sensitive information, such as the locations of individuals. We propose a practical method of obtaining a distribution of users while anonymizing their location data that can be used in location-based services for the prevention of the spread of COVID-19. Generalization and local differential privacy are used to guarantee user and data anonymity while maintaining high data utility and accuracy. To our knowledge, COVID-LPS is not only the first COVID-19 tracing system in Taiwan but also the first system to visualize user distributions for location-based services while protecting user privacy through generalization and local differential privacy.
Yao-Tung Tsou, Jen-Yu Huang
GLOBECOM1
2021 (k, ε , δ)-Anonymization: privacy-preserving data release based on k-anonymity and differential privacy
Yao-Tung Tsou, Mansour Naser Alraja, Li-Sheng Chen, Yu-Hsiang Chang, Yung-Li Hu, Yennun Huang, Chia-Mu Yu, Pei-Yuan Tsai
Serv. Oriented Comput. Appl.1
2021 RoD: Evaluating the Risk of Data Disclosure Using Noise Estimation for Differential Privacy
abstract
Differential privacy is a paradigm of big data privacy protection that offers protection even when an attacker has arbitrary background knowledge in advance. Consequently, it is viewed as a reliable protection mechanism for sensitive information. Differential privacy introduces noise, such as Laplace noise, to obfuscate the true values in a data set while preserving its statistical properties. However, a large amount of Laplace noise added into a data set is typically defined by the discursive scale parameter of Laplace distribution. The privacy budget$\varepsilon$in differential privacy has been theoretically interpreted, but the implication on the risk of data disclosure (RoD) in practice has not yet been well studied. Moreover, choosing an appropriate value for$\varepsilon$is not straightforward because it considerably affects the level of privacy in a data set. In this paper, we define and evaluateRoDin a data set with either numerical or binary attributes for numerical or counting queries with multiple attributes based on noise estimation. Through confidence probability of noise estimation, we provide a simple method to select the privacy budget$\varepsilon$for differential privacy and associate differential privacy with$k$-anonymization. Finally, we show the relationship between theRoDand$\varepsilon$as well as between$\varepsilon$and$k$in our experimental results. To the best of our knowledge, this is the first study using the quantity of noise as a bridge to evaluateRoDfor multiple attributes (either numerical or binary data) and determine the relationship between differential privacy and$k$-anonymization.
Yao-Tung Tsou, Hung-Li Chen, Jia-Yang Chen
IEEE Trans. Big Data1
2020 SPARR: Spintronics-based private aggregatable randomized response for crowdsourced data collection and analysis
Yao-Tung Tsou, Hao Zhen, Sy-Yen Kuo, Ching-Ray Chang, Akio Fukushima, Bor-Doou Rong
Comput. Commun.1
2018 PPDCA: Privacy-preserving crowdsensing data collection and analysis with randomized response
abstract
Randomized response mechanisms for guaranteeing crowdsensing data privacy have attracted scholarly attention; aggregators can ensure privacy by collecting only randomized data and individuals have plausible deniability regarding their responses. The analysts employed by organizations can still make predictions and conduct analyses using the randomized data. Existing randomized response-based data collection solutions have severely restricted functionality and usability, resulting in impractical and inefficient systems. Hence, we propose a randomized response-based privacy-preserving crowdsensing data collection and analysis (PPDCA) method, in which a complementary randomized response (C-RR) approach is designed to guarantee data privacy and to preserve features for data analysis. Moreover, we transform encoded data into binary vectors and generate a learning network using a deep learning framework. Through C-RR and our learning model, PPDCA can perform exceptionally in terms of high-utility analysis for the collected client-side strings, compared with state-of-the-art methods.
Bo-Cheng Lin, Shang-Hong Wu, Yao-Tung Tsou, Yennun Huang
WCNC3
2017 Data-Driven Approach for Evaluating Risk of Disclosure and Utility in Differentially Private Data Release
abstract
Differential privacy (DP) is a popular technique for protecting individual privacy and at the same for releasing data for public use. However, very few research efforts are devoted to the balance between the corresponding risk of data disclosure (RoD) and data utility. In this paper, we propose data-driven approaches for differentially private data release to evaluate RoD, and offer algorithms to evaluate whether the differentially private synthetic dataset has sufficient privacy. In addition to the privacy, the utility of the synthetic dataset is an important metric for differentially private data release. Thus, we also propose the data-driven algorithm via curve fitting to measure and predict the error of the statistical result incurred by random noise added to the original dataset. Finally, we present an algorithm for choosing appropriate privacy budget ∈ with the balance between the privacy and utility.
Kang-Cheng Chen, Chia-Mu Yu, Bo-Chen Tai, Szu-Chuang Li, Yao-Tung Tsou, Yennun Huang, Chia-Ming Lin
AINA5
2017 Evaluating the Risk of Data Disclosure Using Noise Estimation for Differential Privacy
abstract
Differential privacy is a recent notion of data privacy protection, which does not matter even when an attacker has arbitrary background knowledge in advance. Consequently, it is viewed as a reliable protection mechanism for sensitive information. Differential privacy introduces Laplace noise to hide the true value in a dataset while preserving statistic properties. However, the large amount of Laplace noise added into a dataset is typically defined by the discursive scale parameter of the Laplace distribution. The privacy parameter ε in differential privacy is with theoretical interpretation, but the implication on the risk of data disclosure (called RoD for short) in practice has not yet been studied. Moreover, choosing appropriate value for ε is not an easy task since it impacts the level of privacy in a dataset significantly. In this paper, we define and evaluate the RoD in a dataset with either numerical or binary attributes for numerical or counting queries with multiple attributes based on the noise estimation. Through confidence probability of noise estimation, we give a simple way to choose the privacy parameter ε. Finally, we show the relation of the RoD and privacy parameter ε in experimental results. To the best of our knowledge, this is the first research work in using noise estimation to practically evaluate the RoD for multiple attributes (both numerical and binary data).
Hung-Li Chen, Jia-Yang Chen, Yao-Tung Tsou, Chia-Mu Yu, Bo-Chen Tai, Szu-Chuang Li, Yennun Huang, Chia-Ming Lin
PRDC3
2017 Compressive Sensing-Based Adaptive Top-k Query over Compression Domain in Wireless Sensor Networks
abstract
Data query and energy saving in wireless sensor networks (WSNs) are crucial and have been widely studied. The compressive sensing (CS) technique is a candidate for reserving energy in communications and prolonging the lifetime of WSNs. However, the decompression of CS makes sensor nodes computationally inefficient. An intuitive approach to resolving this problem is to preserve sensing data in the compression domain, but this would limit the utility of stored data, such as data queries in WSNs. In this paper, we introduce the CS theory on sensing nodes to compress sensing data and store compressed data on storage nodes so that the communication and space overhead can be significantly reduced. More importantly, we allow querists to launch Top-k queries to the storage nodes, which can apply adaptive compressed data reduction (ACDR) to derive required data from the compression domain in accordance with the k ranks and return query results to the querists. ACDR enables storage nodes to dynamically change the size of compressed data according to the k ranks launched by querists so that the communication overhead is lower than that of other methods in literature.
Yu-Shun Chen, Yao-Tung Tsou
WCNC2
2017 SER: Secure and efficient retrieval for anonymous range query in wireless sensor networks
Yao-Tung Tsou, Chun-Shien Lu, Sy-Yen Kuo
Comput. Commun.1
2014 PCTopk: Privacy-and Correctness-Preserving Functional Top-k Query on Un-trusted Data Storage in Two-Tiered Sensor Networks
abstract
This paper proposes an efficient mechanism, called PCTopk, for functional top-k query with a combination of multiple conditions/dimensions in two-tiered sensor networks to simultaneously preserve data privacy and correctness (i.e., authenticity and integrity). PCTopk constructs a layered authentication tree, cooperated with an order-preserving symmetric encryption technique, for only permitting storage nodes to systematically process inquired data over encryption domain and enabling querists to efficiently verify the authentic and complete query results. To the best of our knowledge, this is the first research work on the issue of secure functional top-k query with a combination of multiple conditions in two-tiered sensor networks. The performance evaluation results show that PCTopk takes significantly less energy consumption and storage space than prior arts while preserving data privacy and correctness.
Yao-Tung Tsou, Yung-Li Hu, Yennun Huang, Sy-Yen Kuo
SRDS1
2013 Localized Algorithms for Detection of Node Replication Attacks in Mobile Sensor Networks
abstract
We deal with the challenging problem of node replication detection. Although defending against node replication attacks demands immediate attention, compared to the extensive exploration on the defense against node replication attacks in static networks, only a few solutions in mobile networks have been presented. Moreover, while most of the existing schemes in static networks rely on the witness-finding strategy, which cannot be applied to mobile networks, the velocity-exceeding strategy used in existing schemes in mobile networks incurs efficiency and security problems. Therefore, based on our devised challenge-and-response and encounter-number approaches, localized algorithms are proposed to resist node replication attacks in mobile sensor networks. The advantages of our proposed algorithms include 1) localized detection; 2) efficiency and effectiveness; 3) network-wide synchronization avoidance; and 4) network-wide revocation avoidance. Performance comparisons with known methods are provided to demonstrate the efficiency of our proposed algorithms. Prototype implementation on TelosB mote demonstrates the practicality of our proposed methods.
Chia-Mu Yu, Yao-Tung Tsou, Chun-Shien Lu, Sy-Yen Kuo
IEEE Trans. Inf. Forensics Secur.2
2013 MoteSec-Aware: A Practical Secure Mechanism for Wireless Sensor Networks
abstract
Ensuring the security of communication and access control in Wireless Sensor Networks (WSNs) is of paramount importance. In this paper, we present a security mechanism, MoteSec-Aware, built on the network layer for WSNs with focus on secure network protocol and data access control. In the secure network protocol of MoteSec-Aware, a Virtual Counter Manager (VCM) with a synchronized incremental counter is presented to detect the replay and jamming attacks based on the symmetric key cryptography using AES in OCB mode. For access control, we investigate the Key-Lock Matching (KLM) method to prevent unauthorized access. We implement MoteSec-Aware for the TelosB prototype sensor platform running TinyOS 1.1.15, and conduct field experiments and TOSSIM-based simulations to evaluate the performance of MoteSec-Aware. The results demonstrate that MoteSec-Aware consumes much less energy, yet achieves higher security than several state-of-the-art methods.
Yao-Tung Tsou, Chun-Shien Lu, Sy-Yen Kuo
IEEE Trans. Wirel. Commun.1
2012 Privacy- and integrity-preserving range query in wireless sensor networks
abstract
A large-scale wireless sensor network constructed in terms of two-tiered architecture, where cloud nodes take charge of storing sensed data and processing queries with respect to the sensing nodes and querists, incurs security breach. This is because the importance of cloud nodes makes them attractive to adversaries and raises concerns about data privacy and query result correctness. To address these problems, we propose an efficient approach, namely EQ (efficient query), which mainly prevents adversaries from gaining the information processed by or stored in cloud nodes, and detects the compromised cloud nodes when they misbehave. EQ can not only achieve the goals of data privacy and integrity preserving but also ensure the secure range query without incurring false positive. For data privacy preserving, EQ presents an order encryption mechanism by adopting stream cipher to encrypt/decrypt all sensed data such that a cloud node can only process issued queries over stored data in the encryption domain. For data integrity/completeness, we manipulate a data structure of XOR linked list (X2L), which allows a querist to verify the integrity of retrieved data via the socalled verification information, i.e., neighborhood difference in a storage-efficient manner. We demonstrate the feasibility and efficiency of EQ via experiments conducted on TelosB prototype sensor platform running TinyOS 1.1.15 and comparisons with state-of-the-arts.
Yao-Tung Tsou, Chun-Shien Lu, Sy-Yen Kuo
GLOBECOM1
2011 Practical and Secure Multidimensional Query Framework in Tiered Sensor Networks
abstract
The two-tier architecture consisting of a small number of resource-abundant storage nodes in the upper tier and a large number of sensors in the lower tier could be promising for large-scale sensor networks in terms of resource efficiency, network capacity, network management complexity, etc. In this architecture, each sensor having multiple sensing capabilities periodically forwards the multidimensional sensed data to the storage node, which responds to the queries, such as range query, top-kquery, and skyline query. Unfortunately, node compromises pose the great challenge of securing the data collection; the sensed data could be leaked to or could be manipulated by the compromised nodes. Furthermore, chunks of the sensed data could be dropped maliciously, resulting in an incomplete query result, which is the most difficult security breach. Here, we propose a simple yet effective hash tree-based framework, under which data confidentiality, query result authenticity, and query result completeness can be guaranteed simultaneously. In addition, the subtree sampling technique, which could be of independent interest to the other applications, is proposed to efficiently identify the compromised nodes. Last, analytical and extensive simulation studies are conducted to evaluate the performance and security of our methods. Prototype implementation on TelosB mote demonstrates the practicality of our proposed methods.
Chia-Mu Yu, Yao-Tung Tsou, Chun-Shien Lu, Sy-Yen Kuo
IEEE Trans. Inf. Forensics Secur.2
2011 Constrained Function-Based Message Authentication for Sensor Networks
abstract
Sensor networks are vulnerable to false data injection attack and path-based denial of service (PDoS) attack. While conventional authentication schemes are insufficient for solving these security conflicts, an en-route filtering scheme, enabling each forwarding node to check the authenticity of the received message, acts as a defense against these two attacks. To construct an efficient en-route filtering scheme, this paper first presents a Constrained Function-based message Authentication (CFA) scheme, which can be thought of as a hash function directly supporting the en-route filtering functionality. Obviously, the crux of the scheme lies on the design of guaranteeing each sensor to have en-route filtering capability. Together with the redundancy property of sensor networks, which means that an event can be simultaneously observed by multiple sensor nodes, the devised CFA scheme is used to construct a CFA-based en-route filtering (CFAEF) scheme. In addition to the resilience against false data injection and PDoS attacks, CFAEF is inherently resilient against false endorsement-based DoS attack. In contrast to most of the existing methods, which rely on complicated security associations among sensor nodes, our design, which directly exploits an en-route filtering hash function, appears to be novel. We examine the CFA and CFAEF schemes from both the theoretical and numerical aspects to demonstrate their efficiency and effectiveness. Moreover, prototype implementation on TelosB mote demonstrates the practicality of our proposed method.
Chia-Mu Yu, Yao-Tung Tsou, Chun-Shien Lu, Sy-Yen Kuo
IEEE Trans. Inf. Forensics Secur.2