Zhiquan Liu 0001

dblp:139/4288 · DBLP profile ↗
← Back
221ranked-venue papers
5as first author
206since 2021 · last 2026
0000-0002-3934-2177ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 105 · 3 first-author · 99 since 2021Security and privacy · 47 · 46 since 2021Applied, interdisciplinary, general and emerging computing · 24 · 2 first-author · 21 since 2021Artificial intelligence and machine learning · 17 · 17 since 2021Databases, data management, data science and information retrieval · 12 · 11 since 2021Systems, architecture and hardware · 9 · 8 since 2021Software engineering, systems software and programming languages · 5 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Grasp: Refining Semantic Graphs into Purified Knowledge for Cross-Modal Communication
abstract
The explosive growth of multimodal web data demands communication that transmits meaning rather than raw bits. Existing semantic-communication systems often fail under noise, missing modalities, and distribution shifts because they optimize surface features instead of modality-invariant knowledge. We present Grasp, a knowledge-centric framework for cross-modal communication. Grasp segments streams into semantic blocks and builds a graph over them; a lightweight Graph Neural Networks (GNN) produces schedulable, importance-weighted representations. At its core is knowledge purification : we minimize a conditional mutual information upper bound to perform a three-way disentanglement—strongly related, weakly related, and task-irrelevant components—so that only essential semantics are transmitted while non-essential factors are suppressed. To maintain synchrony, we introduce one-to-two temporal contrastive learning to achieve triple alignment of video, audio, and text despite sampling asynchrony. For efficient transmission, Grasp uses a cross-modal shared vector-quantization codebook—a discrete knowledge codebook —updated by multimodal attention. At the receiver, a soft-recovery mechanism leverages this shared knowledge to robustly reconstruct semantics under low signal-to-noise ratio (SNR) or missing modalities, yielding graceful degradation. Across web tasks—including cross-modal retrieval and missing-modality inference—Grasp improves knowledge consistency, semantic fidelity, and downstream performance over strong baselines while maintaining low latency. These results show that communication structured around purified knowledge is key to building robust, semantic-aware systems for the modern web.
Liang Chen 0044, Xiaoding Wang 0001, Limei Lin, Dajin Wang, Zhiquan Liu 0001, Jie Wu 0001
WWW5
2026 MSDLO: Joint General Lotto games and explainable DRL with multi-head attention for agentic task offloading in IIoT systems
Xinmin Cheng, Chengquan Yu, Shigen Shen, Zhiquan Liu 0001, Tian Wang 0001, Ruidong Li 0001
Adv. Eng. Informatics5
2026 Interpretable intrusion detection for IoT security: A SHAP-enhanced NGBoost model
Jingnan Dong, Haolei Chen, Shigen Shen, Huibin Xu, Zhiquan Liu 0001
Comput. Networks5
2026 BVPM: A blockchain-based scheme for secure and efficient vehicle platoon management
Piaoxiong Huang, Zhiquan Liu 0001, Feixiang Ye, Jianfeng Ma 0001
Comput. Networks3
2026 DRL-BM: Intelligent buffer management in data center network
Waixi Liu 0001, Xin-Jian Zhong, Zhen-xin Zhang, Jun Cai 0002, Zhiquan Liu 0001, Chao-Xuan Zheng, Zhen-zheng Guo
Comput. Networks7
2026 CLlog: A collaborative learning-based anomalous log detection model
Zhiquan Liu 0001, Xiaolei Liu 0001
Comput. Networks3
2026 A fully distributed algorithm for constructing underwater three-dimensional full coverage using mobile sensors
Weiqiang Shen, Zhiquan Liu 0001, Jinglun Shi
Comput. Networks2
2026 A verifiable and efficient chained federated learning scheme for privacy protection
Xiaoming Wang 0004, Zhiquan Liu 0001, Mingzhen Dai, Jiaming Gong, Weichuan Ni
Comput. Networks2
2026 STAR-RIS-Assisted Computation offloading and resource allocation optimization for mobile IoV with NOMA-MEC
Linbo Zhai, Zhiquan Liu 0001, Linfeng Wei, Xiaochuan Li 0001, Jie Liu 0040
Comput. Networks3
2026 Access selection and service placement in mobile edge computing networks
Linbo Zhai, Zhiquan Liu 0001, Linfeng Wei, Xiaochuan Li 0001, Jie Liu 0040
Comput. Networks3
2026 E2E-PP: End-to-End Privacy Protection via compressive sensing and personalized differential privacy for mobile crowdsensing
Xingyu Zheng, Kaimin Wei, Zhiquan Liu 0001, Jinpeng Chen 0001, Chengkun Jia, Jilian Zhang
Comput. Secur.3
2026 An enriched Transformer powered by knowledge graph for multi-task Ethereum fraud detection
Ye Tian 0027, Liguo Zhang 0002, Zhiquan Liu 0001
Eng. Appl. Artif. Intell.6
2026 Animal identity recognition based on gait features
Xin Chen 0021, Yubin Lan, Zhiquan Liu 0001, Qi Tian 0001
Expert Syst. Appl.4
2026 Shoot the arrow at the target: Personalized adversarial defense driven by dynamic rewards
Zhihai Yang, Ruping Zou, Zhiquan Liu 0001
Expert Syst. Appl.6
2026 Federated learning with dynamics-aware loss for label noise
Chengtian Ouyang, Jihong Mao, Zhiquan Liu 0001, Donglin Zhu, Changjun Zhou, Gangqiang Hu, Taiyong Li
Expert Syst. Appl.3
2026 TG-MG: Task grouping based on MDP graph for multi-task reinforcement learning
Quan Yuan 0004, Guiyang Luo, Xiaoyuan Fu, Zhiquan Liu 0001
Expert Syst. Appl.5
2026 Anti-APhish: A robust and adaptive detection approach against evolving AI-powered phishing URLs
Ning Lu 0005, Zhiquan Liu 0001
Expert Syst. Appl.5
2026 HALO: A scalable framework for hotness-aware coding and transformation-efficient placement
Junmei Chen, Ne Wang, Zongpeng Li, Zhiquan Liu 0001, Dan Xiang
Future Gener. Comput. Syst.4
2026 Backdoor defense framework with sparse training and detection in federated learning
Yingna Li, Yongde Wang, Haoheng Yuan, Pengfei Zhang 0016, Wei Huang 0037, Zhiquan Liu 0001
Neurocomputing6
2026 An Entropy-Based Privacy-Preserving Federated Deep Reinforcement Learning Framework for Task Offloading in Vehicular Edge Computing Networks
abstract
With the rapid evolution of 5G and the ongoing development of 6G technologies, the Internet of Vehicles (IoV) is expected to play a critical role in next-generation intelligent transportation systems. Applications such as autonomous driving, augmented reality, and smart mobility not only require ultra-low latency and high computational efficiency, but also demand enhanced trustworthiness and privacy assurance. To address these demands, Vehicular Edge Computing (VEC) has emerged as a foundational paradigm for 6G-IoT, enabling intelligent services by offloading tasks from vehicles to edge nodes. However, task offloading in IoV-VEC systems still faces critical challenges, including the need for responsible AI decision-making under dynamic network conditions and the protection of sensitive vehicular data. This paper proposes FedVTO, a privacy-preserving federated vehicle task offloading framework that integrates Federated Learning (FL) and Deep Reinforcement Learning (DRL) to optimize task offloading decisions and resource allocation strategies in VEC networks. By incorporating information entropy models and dynamically adjusting weighting parameters using an entropy-based method within a three-tier architecture (vehicles, roadside units, and cloud server), FedVTO minimizes latency, energy consumption, and privacy leakage. Experimental results show that FedVTO significantly improves task offloading efficiency and mitigates privacy risks compared to traditional methods in dynamic VEC environments.
Yishan Chen 0001, Wenshuo Dai, Junxiao Han, Miaojiang Chen, Zhiquan Liu 0001, Ahmed Farouk
IEEE Internet Things J.6
2026 Category-Guided Vision-Language Model for IoMT-Enabled Medical Report Generation Under Heterogeneous Imaging Data
abstract
The traditional manual report writing model relies on radiologists to complete reports independently, lacking reference standards and potentially leading to diagnostic omissions or descriptive biases. Existing methods often treat medical report generation as an image captioning task with an encoder-decoder framework. However, purely data-driven approaches show weak correlations between disease features and text descriptions, and the model lacks knowledge of relevant rare diseases. To tackle these challenges, we propose a category-guided structured diagnostic decision framework in the Internet of Medical Things (IoMT). Through collecting medical data from various real-world scenarios, the proposed IoMT platform could generate accurate medical reports and reduce the workload of clinical doctors. During report generation process, the proposed framework introduces a Dual-Guided Prompting Strategy in which local lesion-aware prompts are embedded in the encoder, while global semantic prompts derived from disease classification results guide the decoder. This design enables cross-modal alignment at both local and global levels and enhances category-guided structured report generation. To further improve the diagnosis of long-tail diseases, we introduce a Cross-Modal Knowledge Enhancement module that utilizes positive classification results to retrieve similar sentences from a preconstructed knowledge base, infusing external clinical knowledge into the generation process. Numerous experiments on two benchmark datasets demonstrate that the Dual-Guided Prompting Strategy and the Cross-Modal Knowledge Enhancement module enhance natural language metrics. Specifically, compared to the baseline BLEU-4 score of 0.157, the Dual-Guided Prompting Strategy and the Cross-Modal Knowledge Enhancement module improve the scores to 0.178 and 0.164, respectively, with the final model achieving an overall score of 0.192.
Qiang Jin, Zhiquan Liu 0001
IEEE Internet Things J.6
2026 Secure and Robust Federated Learning Under Dual-Server Architecture in Internet of Things
abstract
The proliferation of Internet of Things (IoT) devices has led to the generation of vast amounts of sensitive and decentralized data. Federated Learning (FL) offers a promising solution by enabling collaborative model training without centralizing raw data. However, existing methods still face challenges such as reduced model accuracy, low robustness, and potential data privacy leakage. To address these issues, we propose a Secure and Robust Federated Learning framework (SRFL) under a dual-server architecture. Specifically, we use two servers to separate the functions of model aggregation and verification, minimizing the threat of single points of failure. We further construct verification models based on perturbed or encrypted client updates to filter malicious updates and defend against poisoning attacks. Meanwhile, we integrate the Cheon-Kim-Kim-Song (CKKS) scheme with random perturbation and ciphertext transformation mechanisms, ensuring that servers cannot access plaintext client updates throughout the training process. Formal security analysis and extensive experiments demonstrate that our scheme consistently achieves high accuracy and robustness under adversarial conditions while preserving data privacy.
Shuying Liu, Ru Meng, Xinru Yan, Yinbin Miao, Zhiquan Liu 0001, Yanfei Zou, Zheben Wang, Kim-Kwang Raymond Choo
IEEE Internet Things J.6
2026 Robustness-Enhanced and Explainable Federated Learning in Internet of Things
abstract
In the Internet of Things (IoT) environment, a large number of edge devices collaboratively generate and process data, making Federated Learning (FL) an appealing solution for privacy-preserving model training without sharing raw data. However, traditional FL frameworks suffer from performance degradation due to model poisoning attacks under Non-Independent and Identically Distributed (Non-IID) settings, as well as lack decision-making explainability. To address these challenges, we propose the Robustness-enhanced and explainable Federated Learning (ReFed) framework by combining Local Interpretable Model-agnostic Explanations (LIME) with similarity-based aggregation. Specifically, by fitting a local linear regression model to approximate the decision processes of both the global and local models for improved transparency, and dynamically computing client aggregation weights based on inter-model prediction similarity for enhanced robustness. Experiments demonstrate that ReFed achieves 99.76% accuracy on MNIST and 87.65% accuracy on CIFAR-10, outperforming typical FL methods in adversarial settings.
Shuying Liu, Jiameng Tian, Ru Meng, Yinbin Miao, Zhiquan Liu 0001, Yanfei Zou, Zheben Wang, Kim-Kwang Raymond Choo
IEEE Internet Things J.6
2026 Hidden Facial Verification Scheme in IoT Cloud Environment Based on Homomorphic Privacy Information Retrieval
abstract
With the popularization of face recognition technology in IoT-Cloud, the problem of privacy leakage caused by it is becoming more and more serious. Although traditional privacy protection schemes can improve security to a certain extent, there is still a risk of data leakage when facing semi-trusted cloud servers. To this end, this paper proposes an anonymized face verification scheme for IoT convergence scenarios, which achieves real-time retrieval and secure matching of dense face features in virtual device copies by combining homomorphic encryption (CKKS) and privacy information retrieval (PIR) for anonymized face verification. The scheme ensures that the semi-trusted cloud server cannot obtain user-specific index information and matching results. Experiments show that the scheme’s verification accuracy in the ciphertext state on the LFW dataset is consistent with the plaintext, up to 97.06%, and can complete a privacy-protected anonymized facial verification process within seconds. The scheme is feasible in security demanding scenarios.
Xu An Wang 0014, Wei Zhao 0054, Weiwei Jiang 0003, Lingling Wu, Haibo Lei, Zhiquan Liu 0001, Dianhua Tang
IEEE Internet Things J.7
2026 Dependency-Aware Dynamic Priority Scheduling for Online Multi-DAG Task Offloading in Mobile Edge Computing
abstract
The Internet of Things (IoT) revolution has led to unprecedented data generation, necessitating a shift from traditional centralized computing to more decentralized approaches. To address the challenges of data processing closer to the source, the paradigm of Mobile Edge Computing (MEC) has emerged. It facilitates task offloading to nearby edge servers, thereby reducing delay and enhancing privacy. However, limited computation resources at the edge necessitate intelligent resource allocation through effective scheduling to maintain Quality of Service (QoS). Typically, a task comprises multiple subtasks with inherent dependencies, some of which are locally dependent and unsuitable for offloading. In subtask scheduling, one must account for both inter-subtask and local dependencies, deploying different subtask types to near-optimal computing devices, whether edge servers or User Equipment (UEs). This requirement presents significant challenges to scheduling strategies. Furthermore, since task offloading requests are inherently online, without prior task information before their arrival, improper scheduling can result in resource wastage and increased delays. To tackle these challenges, we formulate the Online Multi-DAG task Scheduling with Dependency awareness (OMSD) problem within a DAG-MEC framework. This problem is modeled as an Integer Linear Programming (ILP) problem and proven to be NP-hard. We propose a Dynamic Priority List Scheduling (DPLS) algorithm to address this problem effectively. Our algorithm strategically determines subtask execution order by evaluating upward and downward ranks, task volume, and contention levels. Simulation results demonstrate that DPLS significantly outperforms existing benchmark algorithms regarding mean task completion time, server load balance, and maximum task completion time, offering a robust solution to the OMSD challenge in MEC environments.
Haolin Liu 0001, Guizhong Zheng, Zhiquan Liu 0001, Shujuan Tian, Yanchun Li
IEEE Internet Things J.3
2026 PAMA: Provable-Secure Anonymous Multifactor Authentication With Postquantum Security for IoT-Enabled E-Healthcare Systems
abstract
The booming technologies of the Internet of Things (IoT) enable various applications and develop well. E-healthcare system is one of the successful examples, where people manage their healthcare information, diagnosis data, physical examination results, and so on. These types of sensitive information cause crucial security risks, posing threats to the security of the lives and property of the people. Given this concern, safeguard measures, such as authentication and encryption, are necessary. However, due to the openness of the wireless networks, authentication protocols for IoT-enabled e-healthcare systems are usually vulnerable to serious attacks. Furthermore, the quantum era is around the corner, urging authentication protocols to possess post-quantum security properties. In this paper, we propose a multi-factor password authentication scheme, named PAMA, with post-quantum security for the e-healthcare system. The lattice cryptography is adopted for post-quantum security. We formally prove the proposed PAMA scheme to be secure, and also informally verify the security against common attacks. Furthermore, we compare the performance of the communication efficiency of the PAMA scheme with other related works from both theoretical and experimental aspects. The efficiency comparison results demonstrate that our PAMA scheme approximately reduces the computation cost by 37.59% and the energy consumption by 37.5%, compared to the related post-quantum schemes. In summary, the PAMA scheme has a great advantage in secure authentication and agreement on a session key in the e-healthcare system.
Yuqian Ma, Yongliu Ma, Zhiquan Liu 0001, Qi Jiang 0001, Qingfeng Cheng
IEEE Internet Things J.3
2026 QSDA: Quality-Aware Secure Multidimensional Data Aggregation With Location Privacy for HIoT
abstract
Data aggregation, as a data processing technique, facilitates accurate diagnosis in the Healthcare Internet of Things (HIoT) by integrating multi-source heterogeneous health data. However, achieving efficient and secure aggregation of multi-dimensional medical data remains challenging, particularly when simultaneously preserving location privacy and providing fair, quality-driven incentives. To address these issues, this paper proposes a Quality-Aware Secure Multi-Dimensional Data Aggregation scheme with Location Privacy for HIoT (QSDA). First, the scheme employs inner product encryption to support aggregation task matching without revealing users’ actual coordinates, and further integrates symmetric homomorphic encryption with super-increasing sequences to enable one-stop compressed aggregation of multi-dimensional data, thereby effectively supporting common statistical operations such as mean and variance. Second, it introduces a data quality incentive mechanism based on offset metrics, while leveraging blockchain auditing to ensure the traceability of the aggregation process and the verifiability of the aggregation results. Finally, security analysis and performance evaluation demonstrate the scheme’s effectiveness and efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Internet Things J.6
2026 Joint Task Offloading and Resource Allocation in RIS-Assisted NOMA-VEC Intent-Based Networking
abstract
In Intent-based Vehicular Edge Computing (VEC) networking, escalating demands for computational offloading and resource management in dynamic urban environments necessitate innovative solutions. This paper proposes a novel RIS-assisted NOMA-VEC framework that empowers vehicle users (VUs) to offload arbitrary task portions to multiple edge servers via any available subcarrier. This approach overcomes limitations posed by heterogeneous local computing capabilities and stringent latency constraints. By leveraging Reconfigurable Intelligent Surfaces (RIS) to enhance channel conditions through both direct and reflected links, our framework significantly improves communication reliability and offloading efficiency. To minimize the average weighted energy consumption of VUs under time-varying channels and traffic dynamics, we formulate a joint optimization problem integrating offloading decisions, power allocation, and transmission time scheduling. Addressing the problem’s inherent complexity, characterized by multi-variable coupling and non-convex constraints, we develop a two-stage decomposition strategy: Offloading decisions are dynamically adapted to environmental fluctuations using a Proximal Policy Optimization (PPO)-based algorithm, while resource allocation is resolved through a hybrid Genetic Algorithm (GA) and Sequential Least Squares Programming(SLSQP) approach, efficiently navigating combinatorial and non-convex landscapes. Extensive simulations demonstrate that our framework reduces VU energy consumption by 11.12% compared to baseline methods, validating its superior efficiency in RIS-enhanced VEC systems.
Meng Yi, Miaojiang Chen, Zhiquan Liu 0001, Athanasios V. Vasilakos, Houbing Song, Ahmed Farouk
IEEE Internet Things J.4
2026 SEBA: A Secure and Efficient Blockchain-Based Cross-Domain Authentication Scheme for Vehicular Networks
abstract
With the rapid growth of connected vehicles and the increasing demand for low-latency and reliable communication, traditional vehicular networks face severe security challenges. Existing cross-domain authentication schemes often suffer from complex certificate management, key leakage, and inefficient trust coordination. In this paper, we propose a Secure and Efficient Blockchain-based Cross-Domain Authentication (SEBA) scheme for vehicular networks that integrates blockchain with physical unclonable functions (PUFs) to establish a robust trust management framework. The proposed scheme adopts a hybrid on-chain/off-chain architecture, where blockchain-based smart contracts provide tamper-resistant credential storage, while time-critical authentication operations are executed off-chain to improve system throughput and response latency. By incorporating PUF technology, SEBA enables reliable binding between physical devices and cryptographic identities, effectively resisting impersonation and cloning attacks. In addition, lightweight cryptographic primitives are employed to further reduce computation and communication overhead. The security of the proposed scheme is formally verified using ProVerif and further analyzed through theoretical security analysis. Performance evaluation is conducted using a simulation framework that models vehicular communication latency, cryptographic operation costs, and blockchain transaction confirmation delays. Experimental results under varying vehicle loads demonstrate that SEBA significantly outperforms existing schemes, achieving up to 83% higher throughput and 38% lower authentication latency. Overall, SEBA provides a privacy-preserving and low-latency authentication framework suitable for large-scale and highly dynamic vehicular networks.
Wenming Wang 0001, Deyang Liu, Zhiquan Liu 0001, Haiping Huang
IEEE Internet Things J.4
2026 Practical Certificateless Aggregate Signcryption With Public Verification for IoMT
abstract
In the Internet of Medical Things (IoMT), ensuring the confidentiality, integrity, and authenticity of sensitive medical data poses a significant challenge. Signcryption, merging digital signature and public-key encryption into one logical step, offers a promising solution for such resource-constrained networks. Most existing signcryption schemes inherently lack public verification, which prevents third parties (such as routers) from early identifying illegal messages without decryption. In this paper, we propose a practical certificateless aggregate signcryption scheme with public verification for IoMT. Our design uses elliptic curves and follows the certificateless cryptosystem framework. Thus, it not only avoids time-consuming pairing operations but also addresses the issues of certificate management and key escrow. Meanwhile, individual signcryptions can be compressed into a single aggregate signcryption, optimizing computational and communication overheads. Furthermore, both the pre-aggregated and aggregated signcryptions support public verification, effectively enabling the early elimination of illegal messages. We further present formal security proofs for our construction and reduce its security to the hardness of the one-sided gap Diffie-Hellman (OGDH) and the elliptic curve discrete logarithm (ECDL) problems. Performance analysis reveals that, compared with prior studies, this scheme preemptively blocks illegal message spread, reduces receiving-end load, and better suits resource-constrained IoMT.
Wenjie Yang 0001, Tao Li 0043, Futai Zhang, Zhiquan Liu 0001
IEEE Internet Things J.5
2026 Spatio-Temporal Propagation-Aware Graph Neural Network for Traffic Flow Prediction
abstract
Traffic flow prediction is fundamental to intelligent transportation systems, requiring accurate modeling of complex spatio-temporal dependencies. Existing methods typically assume instantaneous propagation of traffic conditions, ignoring inherent time delays in real-world systems. We propose STPAGNN (Spatio-Temporal Propagation-Aware Graph Neural Network), which explicitly models propagation delays in traffic networks. Our approach introduces three innovations: (1) Delay-Aware Temporal Identity Embedding (DATIE) incorporating propagation delays into temporal patterns, (2) Propagation-Aware Dynamic Graph Learning (PADGL) updating graph structures with transmission delays, and (3) Multi-Delay Multi-Scale Interaction Module (MDMIM) capturing interactions across delay horizons. Experiments on four real-world datasets demonstrate state-of-the-art performance with 8.2% MAE and 7.5% RMSE improvements over existing methods. The model provides interpretable insights into traffic propagation patterns for transportation management applications.
Wenbiao Yang, Zhiquan Liu 0001
IEEE Internet Things J.3
2026 Blockchain-Enabled Multi-Authority Secure Data Sharing With Traceability and Attribute Revocation for IoT
abstract
To address the demand for fine-grained access control in Internet of Things (IoT) data sharing, attribute-based encryption (ABE) has emerged as a critical solution. Nevertheless, the computational overhead inherent in ABE poses a major challenge for its direct deployment on resource-constrained IoT devices. Data storage and sharing through centralized cloud may be interrupted due to cloud server failures. Additionally, if user attributes cannot be revoked, some users who should have had their data access rights canceled will still be capable of accessing the data. To solve these problems, we propose a multi-authority attribute-based data sharing scheme that combines blockchain to construct a secure and trusted data sharing environment, while supporting efficient attribute revocation. We reduce the computational burden during the online encryption phase through online/offline encryption, while introducing outsourced decryption to lessen the computational overhead of user decryption. Our scheme supports the tracing of key abusers and attribute revocation for users. Furthermore, by interplanetary file system (IPFS), we reduce on-chain storage burden, and by interplanetary name system (IPNS), we address the difficulty of logically deleting old ciphertexts when updating ciphertexts. Security analysis shows that our scheme exhibits static security, and experimental results demonstrate that our data sharing scheme exhibits excellent efficiency and practicality.
Haojie Zhou, Zhaofeng Ma, Zhiquan Liu 0001, Tiezheng Wu, Jiyuan Song, Pengfei Duan 0002
IEEE Internet Things J.3
2026 DNA Sequence-Inspired Similarity-Driven Particle Swarm Optimization for UAV-BS Deployment
abstract
In response to sudden high-traffic signal demand caused by massive device access in urban Internet of Things environments, Unmanned Aerial Base Stations (UAV-BSs), as dynamic network nodes, can effectively enhance the coverage capacity and quality of communication network services. However, how to efficiently deploy UAV-BSs in complex urban environments while meeting the differentiated communication needs of common and special areas remains an urgent challenge. In this paper, we propose an Average Hamming Distance Modified Particle Swarm Optimization (AHDPSO) algorithm based on the similarity calculation of DNA sequences, which firstly matrices the position and velocity information, and then calculates the average Hamming distance between particles using DNA mapping sequences to identify ’outlier points’. Further, the search guidance coefficientc3is introduced to quantify the guiding effect of ’outlier points’ on the global search, and the values ofc1,c2, andc3are dynamically adjusted by combining with the chaotic mapping, so as to balance the exploratory and developmental capabilities of the algorithm. Compared with the original particle swarm optimization algorithm, matrix particle swarm optimization algorithm, and seven other improved particle swarm optimization algorithms, the experimental results show that AHDPSO can quickly converge to the optimal solution. Compared with the traditional PSO algorithm, the absolute improvement values in the coverage of the entire region and special regions are 7.82% and 7.29%, respectively. It also shows good stability in different scenarios, indicating that the proposed algorithm has significant advantages in convergence speed, coverage, and stability.
Donglin Zhu, Jialing Hu, Jiaying Shen, Zhaolong Ouyang, Gangqiang Hu, Changjun Zhou, Shi Cheng 0002, Zhiquan Liu 0001
IEEE Internet Things J.8
2026 FedDPKD: Federated learning with dual-phase knowledge distillation for label distribution skew
Fanfan Shen, Wenzhang Su, Zhiquan Liu 0001, Jun Feng 0007, Yanxiang He
Inf. Process. Manag.4
2026 Compact-key boolean searchable encryption for multi-category cloud data sharing
Jinlu Liu, Haining Yang, Jing Qin 0002, Zhiquan Liu 0001
Inf. Sci.5
2026 HeliFed: A dual-helix framework for noise-robust federated learning
Fanfan Shen, Zhiquan Liu 0001, Jun Feng 0007, Yanxiang He
Inf. Sci.4
2026 STA-MS: A many-to-many stable task allocation based on multi-round selection in mobile crowdsensing
Shiting Zhao, Kaimin Wei, Zhiquan Liu 0001, Jinpeng Chen 0001
J. Netw. Comput. Appl.3
2026 LETA: A Lattice-Based Efficient and Traceable Privacy-Preserving Batch Authentication Scheme for Vehicle Platoon in VANETs
abstract
Vehicle platoon (VP), as a typical form of traffic cooperation, can significantly enhance traffic efficiency and safety in Vehicular Ad hoc Networks (VANETs). However, malicious vehicles in VP poses a severe threat to the security of entire VP, requiring to be efficiently traced by identity authentication. In this paper, we propose a lattice-based efficient and traceable privacy-preserving batch authentication scheme for vehicle platoon in VANETs, named LETA. First, we design a dynamic VP identity structure VPD-Tree which is constructed based on hash tree and pseudonyms of vehicles to preserve privacy. Then, an aggregate signature is constructed based on VPD-tree and modular lattice for secure and efficient batch authentication of VP. Finally, Zero-Knowledge Proofs (ZKP) is applied on the VPD-Tree structure to anonymously and efficiently trace the malicious vehicles of VP. Security analysis shows that LETA achieves stronger security guarantees, thereby offering a more secure solution than existing approaches. Moreover, performance evaluations show that LETA achieves lower computation and communication overheads through the VPD-tree structure and efficient batch authentication scheme.
Yingjie Xia, Xuejiao Liu 0002, Zhiquan Liu 0001, Zhen Guo 0003, Zhe Liu 0001, Liming Fang 0001
IEEE J. Sel. Areas Commun.5
2026 PP-TDD: Privacy protection towards secure vehicle semantic trajectory data dissemination
Na Fan 0003, Wenjun Fan, Xing Liang, Zhiquan Liu 0001
Knowl. Based Syst.5
2026 PFedRobust: A personalized federated learning framework toward robustness against data poisoning attacks in IoT
Tao Li 0043, Andrea Bracciali, Daojing He, Zhiquan Liu 0001
Knowl. Based Syst.7
2026 Secure and efficient friend recommendation in online social network
abstract
Abstract Nowadays, more and more people are expanding their network through online social network services, such as friend recommendation. To improve user experience, the social network service provider wishes to outsource its services to a powerful cloud. Since the cloud is always untrusted, uploading query data and users’ information to it may cause serious privacy issues. Although some schemes have been proposed to address these privacy concerns, there are still some problems in privacy and efficiency. To deal with these problems, we propose a privacy-preserving friend recommendation scheme that is more secure and efficient than the state-of-the-art work. Specifically, based on three-party secret sharing ( TPSS ) scheme, we propose a secure threshold testing ( STT ) protocol to check whether an encrypted value is greater than the given threshold value. Second, we design a more secure and efficient friend recommendation scheme with the help of our proposed STT and the homomorphic properties of TPSS . Finally, the security of our scheme is proved in the semi-honest model, and the privacy of users is well preserved. Also, we evaluate the performance of the proposed scheme through extensive experiments. The results demonstrate that our proposed scheme outperforms the state-of-the-art.
Lulu Han, Zhuolan Liu, Zhiquan Liu 0001, Yudan Cheng, Jiaquan Shen
Peer Peer Netw. Appl.4
2026 Co-Design of Bandwidth-Awareness Scheduling Protocol and Vehicular Platoon Control Subject to DoS Attacks Over VANETs
abstract
This paper deals with the dynamic event-triggered platoon control problem for automated vehicles subject to denial-of-service attacks over the resource-constrained vehicular adhoc networks. A unified framework is established where the longitudinal dynamics of linearized third-order vehicular platoon, the constant time headway strategy as well as the resource-constrained communication are simultaneously considered. For the resource-efficient purpose, a dynamic event-triggered mechanism is developed where the triggering thresholds are adaptively adjusted based on a bandwidth-awareness parameter α as well as the state variables to trade a balance between communication efficiency and control performance. Furthermore, a set of Bernoulli random variables are introduced to describe the nature of denial-of-service attacks. The main objective of this paper is to co-design a dynamic event-triggered mechanism and a platoon controller to ensure exponential mean-square stability andH∞ performance under resource-limited networks and denial-of-service attacks. With the aid of the established Lyapunov function, the sufficient condition of the desired platoon controller is designed, and then the corresponding parameters are derived by recurring to a set of linear matrix inequalities. Finally, a 6 vehicles platoon is employed to validate effectiveness of the developed co-design scheme.
Yinbo Gu, Dezong Zhao, Zhiquan Liu 0001
IEEE Trans Autom. Sci. Eng.4
2026 Maximizing Computation Efficiency and Fairness of Multi-UAV Assisted MEC System Supported by RIS
abstract
Recently, unmanned aerial vehicles (UAVs) have been widely used in mobile edge computing (MEC) systems to compute part of the computing tasks offloaded from ground equipments (GEs) due to their high mobility and flexibility. In addition, reconfigurable intelligent surfaces (RIS), as an emerging technology, can enhance the wireless propagation environment in wireless networks and improve the computation efficiency of the system. In this paper, we propose a multi-UAV-assisted MEC system supported by RIS, where GEs can partially offload tasks to UAVs for computation. A joint optimization problem is formulated to maximize the weighted computation efficiency and fairness by optimizing the user association state, offloading ratio, computing resource allocation, the trajectory of UAVs and the actual RIS phase shift design. To solve the problem, a Fuzzy C-Means-Multi-Agent Deep Deterministic Policy Gradient Alternating Iterative (FMAI) algorithm is designed. In this algorithm, we firstly design a GE-UAV Association and Variable Initialization Combine Fuzzy C-Means Clustering (GUAIFCM) algorithm to solve GE-UAV association strategy. Then we introduce the multi-agent deep deterministic policy gradient alternating iteration (MADDPGAI) algorithm to solve the computation resource allocation, the trajectory of UAVs, task allocation and RIS phase shift. The simulation results show that the proposed scheme can significantly improve the computation efficiency and fairness of RIS-assisted multi-UAV MEC system compared with the benchmark scheme.
Zekun Lu, Linbo Zhai, Yujuan Jia, Meiyu Jin, Jiande Sun 0001, Zhiquan Liu 0001
IEEE Trans. Commun.7
2026 A Base Station Sleeping Strategy for Large-Scale Scenarios With Multi-Time-Window Spatio-Temporal Graph Convolutional Network
abstract
The explosive growth of mobile data traffic has prompted operators to deploy a large number of base stations (BSs). However, due to the uneven traffic distribution, many BSs remain underutilized or idle during off-peak periods while still consuming substantial amounts of energy. To tackle this issue, we propose a Proactive Optimization-based (PO-based) BS sleeping strategy for large scale scenarios with hundreds of BSs. Specifically, by analyzing the Autocorrelation Function (ACF) of BS traffic in real-world scenarios, we identify multiple potential periods. Guided by this insight, we introduce multi-time-window mechanism and Graph Convolutional Network (GCN), designing Multi-Time-Window Spatio-Temporal Graph Convolutional Network (MTSGCN) to effectively capture the complex spatio-temporal dependencies present large-scale settings. The forecasted results acquired by MTSGCN serve as inputs to a multiple-BSs cooperative sleeping problem with the objective to minimize the total energy consumption. To tackle this huge problem efficiently, we first use K-means++ to divide the large region into several small cooperative clusters and then adopt the Integral Linear Programming (ILP) algorithm to solve each subproblem. Experimental results demonstrate that MTSGCN reduce the forecasting error by 10.9% compared with the state-of-the-art methods. Furthermore, the proposed MTSGCN-ILP algorithm achieves over 20% energy savings gains compared to the other typical strategies.
Mengke Yang, Daosen Zhai, Ruonan Zhang 0001, Lei Liu 0031, Zhiquan Liu 0001, Dusit Niyato
IEEE Trans. Commun.5
2026 Traceable and Revocable Multi-Authority Attribute-Based Encryption With Cloud and Fog Computing Feasible for IoV
abstract
With the wide application of cloud and fog computing, fog devices deployed in scenarios such as the Internet of Vehicles (IoV) are faced with the need to share massive amounts of data, which makes it crucial to implement fine-grained data access control. However, data transmission between fog devices and vehicles in the IoV is highly susceptible to eavesdropping, tampering, and other attacks by malicious vehicles. Most of the existing attribute-based encryption schemes rely on periodic key updates to enable malicious user tracking and attribute revocation, but they cannot meet the demand for real-time security response in the IoV. For this reason, we propose traceable and revocable multi-authority attribute-based encryption with cloud and fog computing (TR-MAABE-CFC). We elaborate on the system model, rigorously define the concepts, and build the security model for TR-MAABE-CFC. Subsequently, we construct a specific implementation scheme for TR-MAABE CFC. Our proposed solution provides fine-grained access control mechanisms, enables the identification of malicious entities, and supports precise attribute revocation. It can be effectively put into practice in cloud and fog computing scenarios. Experimental findings show that our scheme demonstrates superior decryption efficiency and is highly compatible with intelligent transportation system scenarios, making it a viable solution for the IoV.
Liqing Chen, Zhile Tai, Jian Weng 0001, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 Traceable and Revocable Dynamic Searchable Symmetric Encryption With Forward Privacy and Conjunctive Query for Internet of Vehicles
abstract
To achieve the sharing of traffic data with other vehicles, the related data of the Internet of Vehicles (IoV) normally have to be uploaded to the cloud server. Dynamic searchable symmetric encryption (DSSE) empowers users to perform retrieve operations on encrypted databases preserved on cloud servers and supports dynamic data updates at the same time. However, most of the DSSE solutions that support forward privacy and only supply single-keyword search, which places a limit on the practical implementations. When the data owner discloses data to shared users, licensed users might sell their private keys to achieve economic benefits. Based on the aforementioned issues, we put forward traceable and revocable dynamic searchable symmetric encryption with forward privacy and conjunctive query (TR-DSSE-FC), this scheme supports efficient conjunctive-query and the tracking and revocation of malicious users while ensuring forward privacy. This scheme realizes the conjunctive query function by integrating the inverted index with the forward index. The inverted index is deployed to extract the documents that align the least frequent items, while the forward index constructed based on t-puncturable pseudorandom functions (t-Pun-PRFs) is responsible for determining the final query results. To verify whether the search results generated by the cloud server have been modified, we design an accumulative verification label based on symmetric cryptography. Furthermore, we prove the security of TR-DSSE-FC through simulation experiments. According to the performance experiment analysis, compared with analogous approaches, TR-DSSE-FC has significant merits in conjunctive query and verification.
Liqing Chen, Yeting Wu, Jian Weng 0001, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 EPRU: Efficient and Privacy-Aware Reputation Update Scheme With a Dual-Threshold Mechanism for Vehicular Platoons
abstract
Vehicular platooning demands secure and trustworthy inter-vehicle communications to maintain platoon stability, traffic efficiency, and driving safety. Existing privacy-preserving authentication schemes protect message integrity over open channels but often overlook the credibility of message content, allowing authenticated yet misleading data. Reputation management frameworks address this by evaluating vehicle behavior, yet most employ periodic updates, delaying detection of sudden misbehavior. This paper proposes a reputation-based authentication mechanism (EPRU) that establishes trust between vehicles by evaluating vehicle behavior and historical records, thereby ensuring the reliability of message transmission between vehicles. Our EPRU incorporates a dynamic aggregation trigger mechanism that updates vehicle credit scores based on verified feedback collected in real time, thereby accurately reflecting behavioral changes. Furthermore, a combination of ElGamal encryption and homomorphic encryption is employed to safeguard vehicle identities and feedback data during transmission and processing. Formal security proofs and extensive analysis demonstrate resistance to forgery, replay, and modification attacks, ensuring the confidentiality, integrity, and authenticity of both messages and feedback data. Experimental results demonstrate that our EPRU reduces computation overhead by at least 3.05% and communicational cost by 37.5% compared with recent state-of-the-art schemes, highlighting its practicality and efficiency for real-time, privacy-aware vehicular platoon systems.
Hongyuan Cheng, Xiaosong Guan, Yi-Ning Liu 0002, Jiuru Wang, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 Dual-Verifiable Federated Learning With Vector Commitments Against Collusion Attacks
abstract
Collusion attacks, where the server and malicious clients collaborate to bypass gradient source confirmation or tamper with aggregation results, cause a fundamental damage to the training process in federated learning (FL). However, existing verifiable FL frameworks typically adopt a split-verification model-clients can independently validate the correctness of aggregation results, while the server is responsible for confirming the legitimacy of gradient sources. Thus, the collusion attack has emerged as a critical and intractable vulnerability, as it completely collapses this split-verification model, thereby invalidating such verification mechanisms. To tackle this fundamental issue, we propose an innovative dual-verifiable FL framework. Specifically, by leveraging vector commitments, our scheme first integrates both gradient source confirmation and aggregation result verification into a unified framework. Based on this unified design, our scheme implements two targeted strategies to defend against collusion attacks. To prevent collusion-enabled gradient source spoofing, our scheme introduces a semi-trusted verification cluster in place of unreliable server-side validation and embeds an anonymized identity-check strategy to collaboratively confirm gradient source legitimacy. To counter collusion-driven manipulation of gradient aggregation results, our scheme customizes auxiliary verification proofs with a computational one-wayness for client-uploaded gradients. This renders it infeasible for adversaries to tamper with the aggregation result through reverse engineering. Under experiments and security analyses, our scheme achieves reliable dual-verification and robust resistance to collusion attacks. Moreover, it reduces computation and communication overhead by at least 40.83% and 50.47%, respectively, compared to state-of-the-art verifiable FL schemes.
Kaiping Cui, Xia Feng, Liangmin Wang 0001, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.4
2026 Is There a Bottom Line for Poisoning? Detecting High-Concealed Injection Attacks for Recommendation
abstract
Recommender systems (RSs) are widely adopted due to their effectiveness in modeling user preferences and generating personalized recommendations. However, data poisoning attacks (PAs) manipulate recommendation results by injecting fake user profiles, thereby affecting the quality and accuracy of RSs. Moreover, emerging high-concealed PAs (HCPAs) achieve greater evasion of detection by controlling the cost of the attack, simulating the behavior patterns of benign users, and carrying out the attack with less prior knowledge. The HCPAs bring challenges: (1) the very low cost of attacks not only leads to an imbalance in data distribution but also introduces a large amount of accidental co-occurrence noise; (2) the behavioral patterns similar to benign users make it difficult to describe the characteristics of HCPAs; and (3) the prior knowledge for detecting HCPAs in real scenarios is very limited. To address these challenges, we propose STOP, an orthogonal projection bi-hypersphere detection method built on multi-view relational disentanglement and information-consistent fusion. First, we model the distributional preferences of user ratings to eliminate rating and popularity bias, and construct a co-occurrence association graph to suppress accidental overlaps. To address data imbalance caused by HCPAs, second, we introduce a distributional-consensus importance screening method that filters out benign users weakly associated with potential attackers. To address the issues of noise and the difficulty in feature characterization, third, we propose a multi-view relational disentanglement and information-consistent fusion method, which can eliminate redundant relationships, separate key relations into sequence-varying and sequence-stable components over rating sequences, and retain task-related relationships. Finally, inspired by the “convergence theorem”, we design an orthogonal projection bi-hypersphere boundary learning detection method to reduce the high false alarm rate (FAR). We extensively evaluate STOP under various HCPA scenarios, demonstrating its superiority over existing methods with an average 12.34% improvement in detection rate and an average 2.75% reduction in FAR. Furthermore, forensic analysis on real-world unlabeled data reveals distinct attacker “fingerprints”, such as extreme ratings, contradictory review styles, and analysis of target items, validating STOP's reliability in practical applications.
Zhihai Yang, Jianhua He 0001, Jianxin Li 0001, Pinghui Wang, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.7
2026 A Deep Reinforcement Learning Approach to Time Delay Differential Game Deception Resource Deployment
abstract
Current methods for deploying cyber deception do not consider the impact of time delays on the effectiveness of actions by both attackers and defenders, nor can they make real-time decisions on the deployment of deception assets in complex network environments. To address these issues, this paper proposes a deception resource deployment method based on deep reinforcement learning with time-delay differential game theory. First, we constructed the security evolution process of nodes in complex network environments by analyzing the threat models of attackers and defense models of defenders, presenting time-delay differential state equations for nodes with varying degrees. Furthermore, we introduced a cyber deception time-delay differential game model, quantifying the gains for both sides. We then designed a deep reinforcement learning algorithm, employing proximal policy optimization (PPO) to determine the optimal deception deployment strategy, based on the analysis of the network deception time-delay differential game model. Finally, the effectiveness of the proposed method in determining the optimal deception deployment strategy was validated through the construction of a scale-free complex network. Experimental results show that the proposed model could effectively discern the evolutionary processes of nodes with different degrees and the strategies of both attackers and defenders. Compared with other methods, the proposed method showed distinct advantages in stability and effectiveness. The results indicate that the proposed method can be effectively deployed in cyber deception.
Weizhen He, Jinglei Tan, Zhiquan Liu 0001, Xiangyang Luo 0001, Hengwei Zhang
IEEE Trans. Dependable Secur. Comput.4
2026 Boosting the Stealthiness of Backdoor Attack Against Data-Free Detection
abstract
The proliferation of model-sharing platforms has intensified the need for data-free backdoor detection, as deployed models are often accessed without accompanying clean validation data. This constraint renders traditional, data-dependent detection methods ineffective. However, existing strategies to evade data-free detection are inadequate; they frequently fail to circumvent the multi-faceted discriminative criteria of modern detectors that analyze model output behavior, and they often compromise the backdoor model's primary task performance, thus failing to balance attack stealth with functionality. To evade these detections, this paper introduces a Stealthy Backdoor Attack (SBdA) based on label smoothing. Our method dynamically adjusts the training labels for backdoor samples by leveraging the feature similarity between each class and the attacker's target class. This optimization shapes the backdoored model's output distributions to closely mimic those of a benign model, thereby evading detection mechanisms that rely on outlier characterization and posterior distribution analysis. Extensive experiments demonstrate that SBdA maintains a high attack success rate (exceeding 91% under all tested conditions, with 75% of models surpassing 96%) while significantly reducing its detectability. On CIFAR-10, the average outlier score for our models was 0.554-merely 0.050 higher than benign models-compared to a 25.517 deviation for conventional attacks. On GTSRB, SBdA reduced the outlier score gap by 82.86% compared to the average-label technique. Furthermore, by carefully calibrating the posterior distribution, SBdA effectively avoids detection by posterior matrix-based methods across all four tested datasets.
Tao Jiang 0017, Zhiquan Liu 0001, Yinbin Miao, Peihan Qi, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2026 2PCLGA: Privacy-Preserving and Provable-Secure Certificateless Group Key Agreement Scheme for the Distributed Learning-Based MEC Networks
abstract
Machine learning is a rapidly evolving field with applications in all aspects of human life. Utilizing the decentralized computing architecture can alleviate the high training and computational burden of central servers and improve service accuracy. However, the inherent properties of decentralized networks pose great challenges to communication security. It is urgent to design novel and appropriate security schemes, as malicious adversaries are curious about user private information, sensing data, and service demands. Furthermore, end devices always cooperate to accomplish the service targets, which means that group security schemes are needed to protect transmissions among them. In this paper, a certificateless-based group authentication and key agreement (CL-GAKA) scheme is proposed, named 2PCLGA, for distributed learning-based mobile edge computing (DL-MEC) networks. The proposed scheme establishes a session key among the end device group with the group leader MEC server based on the elliptic curve cryptography. Besides, the 2PCLGA scheme adopts dynamic pseudonym identity technology to realize the anonymity. The provable security analysis under the random oracle model, the formal analysis tool, and the informal analysis are adopted. The performance of 2PCLGA is also evaluated with the benchmarks, and the results show that the 2PCLGA scheme is greatly applicable to the resource-constrained circumstance.
Yuqian Ma, Qingfeng Cheng, Zhiquan Liu 0001, Xiangyang Luo 0001, Xiaofeng Chen 0001
IEEE Trans. Dependable Secur. Comput.3
2026 An Outsourced Attribute-Based Encryption Scheme With Verifiable Policy Update and Dynamic Attributes for Digital Twins
abstract
Digital Twins (DTs) generate vast sensitive data, demanding secure, dynamic, and fine-grained access control. While Ciphertext-Policy Attribute-Based Encryption (CP-ABE) offers such control, its inherent computational overhead, static nature, and the need to trust outsourcers for complex operations often limit its practical application in evolving DT environments. In this paper, we proposed an Outsourced Attribute-Based Encryption Scheme with Verifiable Policy Update and Dynamic Attributes (OABE-VPUDA) for Digital Twins. OABE-VPUDA empowers Data Owners (DOs) and Data Users (DUs) by enabling verifiable outsourced encryption, where a Public Verifier confirms Cloud Server (CS) computations, and verifiable outsourced de cryption, validated by DUs using an inspired tag mechanism. The scheme further incorporates dynamic attribute management via on-chain expiration tags for timely, fine-grained revocation, and allows DOs to securely and verifiably modify ciphertext access policies with CS assistance. A consortium blockchain underpins these functionalities, significantly enhancing system transparency, auditability, and overall trust in collaborative DT ecosystems. Formal security analysis rigorously demonstrates that the OABE-VPUDA scheme is secure against chosen-plaintext attacks, thereby ensuring robust data confidentiality, and its de sign ensures the verifiability of all critical outsourced operations within a provable security framework. Experimental results from a prototype implementation confirm the scheme's operational efficiency and practical applicability, highlighting its suitability for secure and agile data sharing in resource-aware digital twin applications.
Zhaofeng Ma, Jiayu Dong, Zhiquan Liu 0001, Pengfei Duan 0002
IEEE Trans. Dependable Secur. Comput.3
2026 A Cloud-Assisted Multi-Dimensional Reputation Management Scheme With Privacy Preservation for Emergency Message Dissemination in VANETs
abstract
The proliferation of Vehicular Ad-hoc Networks (VANETs) has brought new security challenges, as malicious vehicles may disseminate fake messages, thereby threatening road safety. Therefore, it is crucial to ensure the credibility of emergency messages while enabling their rapid dissemination. Cloud computing can enhance the efficiency of VANETs, thus facilitating the application of cloud-assisted security mechanisms. Therefore, this paper proposes a Cloud-assisted Multi-dimensional Reputation Management (CMRM) scheme with privacy preservation for emergency message dissemination in VANETs. Specifically, vehicles are represented by multi-dimensional reputation vectors together with dynamically updated multi-dimensional threshold vectors, which enable more fine-grained and reliable reputation evaluation. A confusing process is employed to conceal vehicle identities, reputation vectors, and threshold vectors, thereby ensuring privacy preservation. Furthermore, we design a Reputation Judgment Vector Extraction (RJVE) algorithm. This algorithm, through the collaboration of two cloud servers, can obtain the reputation judgment vector without disclosing sensitive data. Based on this, receivers use the Credible Message Judgment (CMJ) algorithm to efficiently evaluate the credibility of emergency messages. Theoretical analysis demonstrates that the CMRM scheme achieves privacy preservation and resists common attacks with low computation and communication overhead on both the Trusted Authority (TA) and vehicle sides. Simulation results further verify the robustness and efficiency of the CMRM scheme. The probability that a true message is trusted can quickly converge to over 80%, and the probability that a fake message is trusted quickly drops to near 0.
Senting Ma, Zhiquan Liu 0001, Feixiang Ye, Guanggang Geng, Yinbin Miao, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.2
2026 UAP4MA: Leveraging Multi-Agent Bandits to Generate Universal Adversarial Perturbations for Malware Attribution
abstract
Advanced Persistent Threat (APT) malware group attribution is crucial for cybersecurity, yet current models remain vulnerable to adversarial attacks. Recent approaches for generating universal adversarial perturbations (UAPs) in the malware problem space have exposed substantial security risks, as a single UAP can mislead classification models across a wide range of malware. However, these methods are limited by suboptimal attack effectiveness and efficiency and rely heavily on confidence scores, restricting their practicality. To address these limitations, we propose UAP4MA, the first decision-based, problem-space, black-box UAP generation method tailored specifically for APT malware attribution models. UAP4MA employs a multi-agent Multi-Armed Bandit (MAB) framework, where agents collaboratively construct a UAP by applying functionality-preserving transformations chosen from 13 distinct types, leveraging Optimized Initialization, Collaborative Multi-Agents, and Dynamic Agent Strategies to enhance exploration and exploitation. Extensive experiments on our newly released AMG43 dataset and the APTMalware dataset demonstrate UAP4MA's outstanding attack performance, achieving over four times the fooling rate (FR), double the attack success rate (ASR), and an 80% reduction in training time compared to state-of-the-art methods. These results underscore UAP4MA's effectiveness and efficiency, establishing it as a powerful and practical approach for challenging APT attribution models.
Yuxia Sun, Hengfeng Hu, Yepang Liu 0001, Haocheng Liang, Zhiquan Liu 0001, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.6
2026 PDRU: A Privacy-Preserving Dual Reputation Updating Scheme With Multi-Dimensional Feedback Scores in Vehicle Platoon
abstract
Vehicle platoon, where multiple vehicles travel in formation under a leading vehicle, enhances road capacity and reduces energy consumption. Assessing the reliability of the leading vehicle through reputation management is critical for the vehicle platoon. In the domain of reputation management, reputation updating is of paramount importance. However, many existing schemes are limited by security vulnerabilities, privacy concerns, and reliance on simplistic strategies (i.e., single reputation updating and single-dimensional evaluation), with this reliance undermining their robustness. To address these issues, this paper proposes a Privacy-Preserving Dual Reputation Updating Scheme with Multi-Dimensional Feedback Scores in Vehicle Platoon (PDRU). The PDRU scheme employs a dual reputation model, which enhances the robustness of the reputation updating and provides resilience against the single reputation attack. Meanwhile, it introduces a multi-dimensional evaluation frame work that enables following vehicles to assess the leading vehicle across multiple dimensions, with feedback scores aggregated through weighted averaging according to the importance of each dimension. Moreover, it preserves the vehicle identity privacy, feedback score privacy, leading vehicle's reputation value privacy, and following vehicle's reputation value privacy. Theoretical analysis and simulation evaluation demonstrate that the PDRU scheme achieves a strong balance between robustness, privacy, security, and efficiency, particularly in reducing computation and communication overheads on the Trusted Authority (TA) side.
Zhiquan Liu 0001, Feixiang Ye, Jian Weng 0001, Yinbin Miao, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.2
2026 RD-PCN: A Secure Role-Differentiated Payment Channel Network for Heterogeneous Nodes
abstract
Scalability is a critical challenge for blockchain-based cryptocurrencies and has become a significant bottleneck in large-scale applications such as retail. Payment channel networks (PCNs) are among the most promising solutions to this challenge. However, nodes in real-world PCNs exhibit heterogeneous behaviors and capabilities, causing existing schemes to perform poorly when deployed in practical environments. In this paper, we first demonstrate, through a measurement study, the existence of node heterogeneity in real-world PCNs; and then propose RD-PCN, a role-differentiated PCN that accommodates such heterogeneity by explicitly separating node roles and responsibilities. We address two key challenges in realizing RD-PCN. To improve channel fund utilization, RD-PCN introduces multi-party payment channels (MPCs) to selectively connect nodes at the network edge. We accordingly design a PCN-compatible MPC, termed PC-MPC, representing the first practical solution for deploying MPCs in PCNs. To securely outsource routing tasks to resource-rich nodes, we design a privacy-preserving and fair routing scheme based on trusted execution environments and the proposed topology synchronization mechanism. We prove the security of PC-MPC and the routing scheme under the universally composable framework. Experiments show that RD-PCN improves the payment success ratio by at least 18.9% compared to representative schemes, while increasing fund utilization by 60%.
Qinghao Wang, Ning Lu 0005, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 Fault-Tolerant and Key-Leakage Resilient Lightweight Multidimensional Privacy-Preserving Data Aggregation Scheme in Smart Grid
abstract
Efficient power management in smart grid relies on collecting fine-grained power consumption data from users. However, these data may reveal sensitive information about individuals' habits and lifestyles. Various multidimensional data aggregation schemes leveraging public key encryption (PKE) algorithms have been proposed to address this problem. Never theless, most of these schemes come with significant performance costs. In addition, if the secret key of a smart meter was leaked, the confidentiality of encrypted user power data could be at risk. In this article, we propose a lightweight, multidimensional, and privacy-preserving data aggregation scheme with fault-tolerance and key-leakage resilience for smart grid without relying on a trusted third party (TTP), named FKLM-PDA, in which a novel data packaging method that transforms users' multidimensional data into a one-dimensional format is designed, enabling data center parse aggregated results in each dimension, reducing computation and communication costs. For better efficiency, an effective encryption algorithm is proposed to replace the expensive additive homomorphic PKE, like the Paillier cryptosystem, which combines a random masking with secret-sharing based key separation, ensuring threshold key-leakage resilience under a bounded, non-colluding leakage model. Furthermore, not only does FKLM-PDA enhance the fault tolerance mechanism of data transmission from smart meters to a corresponding fog node, but also it supports dynamic user management for joining and exiting improving scalability. Security analysis confirms that FKLM-PDA is privacy-preserving and secure while guaranteeing key-leakage resilience, fault tolerance, authentication, and data integrity. Through performance evaluations, FKLM-PDA outper forms the existing schemes and is superior in computation and functional in communication.
Liangliang Wang 0001, Chuankun Zhao, Zhiquan Liu 0001, Kai Zhang 0016, Mingze He, Weiwei Li 0007
IEEE Trans. Dependable Secur. Comput.3
2026 Defending PoW Blockchains Against Game-Theoretic DoS Attacks: A Rational Strategy Analysis
abstract
Game-theoretic denial-of-service (GDoS) attacks exploit rational miners' incentives to degrade the throughput and security of proof-of-work (PoW) blockchains, even when the attacker controls less than 20% of the total hash power. Existing defenses commonly rely on protocol modifications, which risk hard forks and destabilize the system. This paper presents the first rational, protocol-preserving defense against GDoS attacks. We formalize GDoS by unifying selfish-mining-based and blockchain-based denial-of-service variants under a common definition, and establish its theoretical foundation through a dynamic game model with a subgame perfect Nash equilibrium (SPNE). Unlike prior protocol-level defenses, our strategy maintains consensus integrity without introducing any changes to PoW. We propose a cooperative hash-power hopping mechanism in which miners temporarily reallocate hash power to larger pools when under attack to preserve expected payoffs and suppress attacker incentives. To quantify miner utilities under different strategies, we develop a combined game-theoretic and Markov-chain analytical framework and derive closed-form critical profitability thresholds. Simulations calibrated to real-world Bitcoin hash-power distributions show that the proposed strategy reduces attacker revenue gains by more than 20% and prevents throughput degradation across the entire attack range. These results demonstrate that rational, incentive-compatible cooperation can effectively strengthen PoW blockchains against emerging strategic threats.
Zhijun Wu 0001, Zhiquan Liu 0001, Meng Yue 0002, Yanrong Lu
IEEE Trans. Dependable Secur. Comput.3
2026 PPCDA: A Privacy-Preserving Cross-Domain Authentication Scheme for Vehicular Platoons
abstract
The rapid advancement of intelligent transportation systems has significantly improved vehicular networks, particularly in applications such as vehicular platoons, which enhance fuel efficiency, road capacity, and traffic safety. However, vehicular platoons require frequent cross-domain communication across different administrative jurisdictions, which poses significant challenges to cross-domain authentication and privacy preservation. Existing cross-domain authentication schemes often suffer from high computation overhead, insufficient privacy protection, and limited support for dynamic platoon membership, making them difficult to scale to large-scale and highly dynamic cross-domain vehicular platoon scenarios. To overcome these challenges, in this paper, we propose a novel privacy-preserving cross-domain authentication (PPCDA) scheme for vehicular platoons. The PPCDA scheme ensures both vehicle identity legitimacy and message integrity, while preserving privacy for vehicles. Additionally, we introduce a batch authentication mechanism to process multiple cross-domain requests from various vehicular platoons simultaneously, alongside a scalable dynamic authentication mechanism to accommodate the dynamic nature of vehicular platooning. Compared with existing cross-domain authentication schemes, the proposed PPCDA scheme achieves improved security and authentication efficiency for vehicular platoons, with average reductions of 56.4% in authentication latency and 8.8% in communication overhead, which makes it particularly suitable for large-scale and dynamic cross-domain vehicular platoon scenarios.
Nuo Xu 0007, Zhiquan Liu 0001, Jian Weng 0001, Gaopan Hou, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.2
2026 IIoT Data Sharing: CP-A$\!^{2}$2BE With Outsourced Decryption and Verifiable Revocation
abstract
With the rapid development of Industrial Internet of Things (IIoT), data sharing as a cornerstone function of IIoT, has attracted considerable attention. Ciphertext-policy attribute-based encryption is extensively used to ensure confidentiality and fine-grained access control in such scenarios. Nevertheless, most existing schemes face critical challenges, including high decryption overhead, inadequate attribute privacy protection, and the absence of verifiable revocation mechanisms, which significantly impede their applications in industrial manufacturing systems. To address these challenges, this paper introduces a ciphertext-policy anonymous attribute-based encryption (CP-A$^{2}$BE) scheme with outsourced decryption and verifiable revocation. It encompasses three key innovations: Firstly, a distributed edge computing architecture is established, leveraging pre-deployed edge nodes within factories to offer outsourced decryption services. Secondly, while safeguarding the privacy of industrial data, the attribute privacy of devices and personnel is also taken into consideration. Thirdly, a verifiable revocation mechanism employing commitment-based techniques is presented to enable real-time access control updates while ensuring the data integrity of revocation operations performed by cloud servers. Experimental evaluation shows that our proposed scheme is practical for data sharing in resource-limited IIoT, especially as the decryption time consistently remains at 26 milliseconds, regardless of the number of attributes involved.
Wenjie Yang 0001, Futai Zhang, Shengmin Xu, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 Meet Trick With Trick: Revealing Collusion Intentions in Highly Concealed Poisoning Behavior
Zhihai Yang, Jianxin Li 0001, Pinghui Wang, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.5
2026 CPFL: Lightweight Communication-Efficient and Privacy-Preserving Federated Learning
abstract
The combination of Deep Learning (DL) and Federated Learning (FL) makes it a popular paradigm to train powerful models securely on large-scale data in a distributed way. However, current solutions face challenges such as significant communication overheads for clients with limited resources, potential privacy risks arising from FL's distributed nature, and the inability to maintain model accuracy without loss under high compression ratios. To solve these issues, we propose a lightweight Communication-efficient and Privacy-preserving FL scheme CPFL by designing Cyclic Segmented Compressive Sensing (CSCS) and using efficient Symmetric Homomorphic Encryption (SHE), which greatly reduces the number of transmitted model weights without sacrificing model accuracy. Formal analysis shows the security of CPFL against known-plaintext attacks and ensures model convergence. Extensive experiments demonstrate that CPFL achieves remarkable model accuracy under more than 200× compression ratio, and even reduces the communication cost by 99.5% compared with previous solutions.
Li Yang 0005, Yinbin Miao, Rongpeng Xie, Xinghua Li 0001, Ju Wu, Guowen Xu, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.7
2026 PPFPS: A Privacy-Preserving Platoon Management Scheme for Flexible Platoon Splitting in Urban Freight Delivery
abstract
Vehicle platoon offers numerous benefits in terms of road safety, energy efficiency, and traffic management in urban freight delivery. Privacy preservation is critical here: location information ties to customer confidentiality and reputation guarantees platoon reliability, yet most existing platoon management schemes fail to preserve privacy while achieving vehicle location-matching. Meanwhile, traditional distance calculation methods such as Euclidean distance are unsuitable for urban road layouts, and most schemes assume member vehicles must follow to unified endpoints, a rigid constraint conflicting with the scenario's needs. In this paper, we propose a privacy-preserving platoon management scheme for flexible platoon splitting in urban freight delivery (PPFPS). In detail, the PPFPS scheme leverages location and reputation to achieve flexible platoon splitting in platoon management while preserving vehicle privacy. Specially, we design an encrypted Manhattan distance calculation method (EMC) by combining bloom filters and Paillier cryptosystem, which is tailored to the road layouts in urban environments and deployed on cloud servers. The EMC method enables privacy-preserving location matching to achieve flexible platoon splitting, and reputation is used to ensure the reliability of vehicle platoon. Furthermore, the EMC method significantly minimizes the involvement of the trusted authority by introducing cloud-assisted approaches. Theoretical analysis demonstrates that the PPFPS scheme effectively preserves privacy and defends a variety of potential attacks. Simulation evaluation confirms that the PPFPS scheme supports more functions while significantly reducing computation overheads by 66.59% to 78.72% on the TA side, and maintains communication overheads of the similar order of magnitude as the existing schemes.
Shuaiyu Zhou, Yudan Cheng, Zhiquan Liu 0001, Liangliang Wang 0001, Xiangyun Tang, Na Fan 0003, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.3
2026 BPFLH: Byzantine-Robust Privacy-Preserving Federated Learning for Heterogeneous Data
abstract
Byzantine-robust federated learning (FL) aims to obtain an accurate global model even with potentially Byzantine users. However, most existing schemes rely on measuring the overall differences between the entire gradient vectors of different users, which fail to effectively distinguish malicious gradients from benign ones caused by data heterogeneity under non-IID settings, thereby compromising model performance. To tackle this challenge, we propose BPFLH, a novel Byzantine-robust privacy preserving FL framework for heterogeneous data. BPFLH is the first to introduce Bray–Curtis dissimilarity into FL, capturing the element-wise differences among gradients from different users. This method reduces the risk of misclassifying benign gradi ents as malicious and enhance the model's robustness against Byzantine attacks in non-IID data environments. Furthermore, BPFLH leverages CKKS homomorphic encryption to protect local gradients, enabling secure aggregation and Byzantine user detection without compromising privacy. Extensive experiments on real-world datasets under various attack scenarios and data distributions demonstrate that BPFLH exhibits strong robustness against Byzantine attacks while preserving privacy and maintaining superior accuracy compared to existing Byzantine-robust FL methods, particularly in non-IID environments.
Guofu Zhu, Wenting Shen, Zhiquan Liu 0001, Jing Qin 0002, Jixin Ma 0001
IEEE Trans. Dependable Secur. Comput.3
2026 Verifiable Multi-User Dynamic Searchable Symmetric Encryption With Forward and Backward Privacy Feasible for Cloud Storage
abstract
With the evolution of cloud storage, data outsourcing has become a common trend. While cloud storage provides convenient services, its privacy and security issues have also attracted widespread attention. Dynamic searchable symmetric encryption (DSSE) provides an efficacious means of addressing data privacy issues by allowing data owners to directly perform retrieval or update operations on data while it is stored in the cloud. However, traditional DSSE cannot meet the needs of multi-user scenarios in practical applications. In addition, DSSE implements forward privacy and backward that is resistant to file-injection attack and support validation of search results. Therefore, we present verifiable multi-user dynamic searchable symmetric encryption with forward and backward privacy feasible for cloud storage (VM-DSSE-FB). The scheme constructs a DSSE framework that satisfies both forward and backward privacy by fusing symmetric encryption with homomorphic addition and bitmap indexing techniques. Meanwhile, we set up an encrypted update queue for each user to adapt to the requirements of multi-user scenarios. In addition, with the help of bitmap indexing and logicANDoperations, we realize the accurate multi-keyword query function. In particular, the cloud server returns the search results with a workload proof to realize the effective verification of the integrity and correctness of the search results. Security analysis proves that VM-DSSE-FB approach achieves adaptive security. The performance analysis shows that compared with existing similar schemes, VM-DSSE-FB achieves more functionality while improving efficiency and is more suitable for cloud storage services.
Liqing Chen, Yeting Wu, Jian Weng 0001, Zhiquan Liu 0001
IEEE Trans. Inf. Forensics Secur.5
2026 ScamSweeper: Detecting Illegal Accounts in Web3 Scams via Transactions Analysis
abstract
The web3 applications have recently been growing, especially on the Ethereum platform, starting to become the target of scammers. The web3 scams, imitating the services provided by legitimate platforms, mimic regular activity to deceive users. However, previous studies have primarily concentrated on de-anonymization and phishing nodes, neglecting the distinctive features of web3 scams. Moreover, the current phishing account detection tools utilize graph learning or sampling algorithms to obtain graph features. However, large-scale transaction networks with temporal attributes conform to a power-law distribution, posing challenges in detecting web3 scams. To overcome these challenges, we present ScamSweeper, anovelframework that emphasizes the dynamic evolution of transaction graphs, to identify web3 scams on Ethereum. ScamSweeper samples the network with a structure temporal random walk, which is an optimized sample walking method that considers both temporal attributes and structural information. Then, the directed graph encoder generates the features of each subgraph during different temporal intervals, sorting as a sequence. Moreover, a variational Transformer is utilized to extract the dynamic evolution in the subgraph sequence. Furthermore, we collect a large-scale transaction dataset consisting of web3 scams, phishing, and normal accounts, which are from the first 18 million block heights on Ethereum. Subsequently, we comprehensively analyze the distinctions in various attributes, including nodes, edges, and degree distribution. Our experiments indicate that ScamSweeper outperforms SIEGE, Ethident, and PDTGA in detecting web3 scams, achieving a weighted F1-score improvement of at least 17.29% with the base value of 0.59. In addition, ScamSweeper in phishing node detection achieves at least a 17.5% improvement over DGTSG and BERT4ETH in F1-score from 0.80.
Xiaoqi Li 0001, Meikang Qiu, Zhiquan Liu 0001, Sen Nie, Zongwei Li 0003, Shi Wu, Yuqing Zhang 0001
IEEE Trans. Inf. Forensics Secur.5
2026 Search Me in the Dark: Access Pattern-Hidden Range Query Over Encrypted Spatial Data
abstract
With the widespread use of encrypted spatial data, many range query schemes emerge to address potential security risks caused by access pattern leakage. However, most existing schemes rely on a dual-server model to hide access patterns and often involve complex spatial relation judgments during range comparisons, leading to low query efficiency. To address these issues, we propose a novel Fast and Access Hidden Range Query (FAHRQ) scheme. First, we introduce an efficient range membership verification technique based on Bloom filters and Lagrange interpolation function, combine homomorphic encryption to ensure the confidentiality of spatial data and the computational flexibility of related operations, and realize the access pattern hidden under single server. Then, we construct an index using R-tree and employ Bloom filters and prefix 0-1 encoding to accelerate the minimum bounding rectangle intersection judgment, enabling secure and efficient range queries over encrypted spatial data while maintaining retrieval accuracy. Finally, we give a formal security analysis to show that our scheme achieves access pattern hidden while protecting data security, and conduct extensive experiments to demonstrate that our scheme improves query efficiency by 5 – 7× compared to existing schemes.
Yinbin Miao, Xin Wang 0037, Kaifa Zheng, Xinghua Li 0001, Zhiquan Liu 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.7
2026 IP-Augmented Multimodal Malicious URL Detection via Token-Contrastive Representation Enhancement and Multigranularity Fusion
Ye Tian 0027, Yanqiu Yu, Zhiquan Liu 0001
IEEE Trans. Inf. Forensics Secur.4
2026 Efficient Heterogeneous Signcryption With Forward Privacy for Vehicular Platoon Communication
Xin Wang 0037, Yinbin Miao, Xinghua Li 0001, Zhiquan Liu 0001, Jun Feng 0007, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.5
2026 Revocable and Flexible Privacy-Preserving Data Computing With Bilateral Access Control for Cloud-Fog-Assisted EHR Systems
abstract
Cloud-fog-assisted electronic health record (EHR) systems offer promising solutions for large-scale medical data storage and processing. However, they also raise critical privacy concerns, particularly regarding secure computation over sensitive data, fine-grained bilateral access control, dynamic revocation, and decryption key exposure. Existing cryptographic primitives, such as functional encryption and matchmaking encryption, address some of these challenges individually but fail to offer a unified solution. In this work, we design a revocable and privacy-preserving data computing system with bilateral access control (RPDC-BAC) for cloud-fog-assisted EHR sharing by proposing a novel cryptographic primitive, called server-aided revocable attribute-based matchmaking functional encryption (SR-AB-MFE). Specifically, the proposed scheme supports expressive bilateral access control and computation over encrypted data. In addition, it incorporates time-evolving decryption keys and a server-aided revocation mechanism to mitigate key exposure and efficiently revoke users. To further reduce receiver-side overhead, fog nodes assist in ciphertext authentication and partial decryption. We formally define the proposed primitive and prove its security under static assumptions. Finally, extensive experimental results demonstrate the efficiency and practicality of our design.
Mengting Yao, Jian Weng 0001, Hongkai Liu, Jia-Nan Liu, Zhiquan Liu 0001, Jia-Si Weng 0001
IEEE Trans. Inf. Forensics Secur.6
2026 TITAN: Temporal-Implicit Topology Attention Network for Resource-Optimal Intelligent Vehicle Collaborative Sensing
abstract
Intelligent vehicle collaborative sensing faces critical challenges in dynamic spatio-temporal modeling and resource optimization. Existing approaches suffer from static topological assumptions and lack principled uncertainty quantification for sensing decisions. To address this, we present temporal-implicit topology attention network (TITAN)-strategic multicriteria active resource targeting (SMART), a unified framework integrating the TITAN with SMART. TITAN incorporates three innovations: implicit topology relation learner (ITRL), dynamic attention neighborhood aggregator (DANA), and temporal propagation attention module (TPAM). Importantly, TITAN is a spatio-temporal attention network, where ITRL and DANA operate on implicit and explicit spatial relationships, while TPAM captures multiscale temporal propagation dynamics. Experimental validation demonstrates that TITAN–SMART achieves target accuracy with up to 46.2% less resource cost than state-of-the-art baselines, maintaining scalability across large-scale networks. By explicitly targeting the gap between passive prediction on fully observed graphs and active sensing under strict sensing-resource constraints, TITAN–SMART enables principled selection of where to sense next rather than only forecasting future states. The framework’s interpretable decision patterns establish it as a practical solution for industrial Internet of Things (IoT) deployments.
Wenbiao Yang, Zhiquan Liu 0001, Lianhai Wang
IEEE Trans. Ind. Informatics3
2026 Federated Deep Reinforcement Learning for Combating Cyber-Threats Specific to EV Charging in Next-Gen WPT Infrastructure
abstract
With the popularity of electric vehicles (EVs), wireless power transmission (WPT) technology has become a hot research topic for next-generation battery charging technology. However, the vulnerability of wireless networks to malicious interference attacks is inherited by WPT. To alleviate the privacy and security issues of WPT, we propose a novel FedDQ, a federated deep reinforcement learning with Q-ensemble, to cope with interference attacks in EV wireless charging network environments. Federated learning protects the security privacy of EVs by training a global model that exploits the property that data and models will not be transmitted. In order to trade-off the training cost and efficiency, we introduce offline-to-online training models by pre-training the offline Q-network with pre-collected data, and the trained model serves as an initialization of the online model. Then, the online Q-network is obtained by weakening or removing the original pessimistic constraints to enhance the training speed. Secondly, we introduce the intelligent reflective surface (IRS) to enhance the security performance of WPT by modifying the IRS phase shift and amplitude to cancel the malicious interference signal. Experimental results show that our proposed FedDQ algorithm has superior performance and outperforms existing baseline methods in terms of anti-jamming metrics.
Miaojiang Chen, Kaiwen Luo, Pengshuo Wang, Wenjing Xiao, Zhiquan Liu 0001, Anfeng Liu, Ahmed Farouk, Min Chen 0003
IEEE Trans. Intell. Transp. Syst.5
2026 Deep Reinforcement Learning-Based Task Offloading With Collaborative Inference in UAV-Assisted Mobile Edge Computing Networks
abstract
Intelligent air-ground integration communication is an emerging technology. Uncrewed aerial vehicles (UAVs) serve as mobile edge computing (MEC) servers in large-scale Internet of Things (IoT) applications, alleviating the computational load on ground users. Existing multi-UAV MEC approaches struggle with the complex computation and large data sizes of deep neural network tasks. To address these challenges, we propose a Deep Reinforcement Learning (DRL)-based DNN Partitioning and Dynamic Trajectory Selection (DPDTS) method, which reduces end-to-end latency and system energy consumption through task offloading and collaborative inference. Specifically, we propose an Optimal Partition Point Selection (OPPS) algorithm to minimize transmission overhead by selecting optimal partition points for DNN tasks. Then, we design a fairness-based matching algorithm to optimize user offloading and resource allocation. Finally, OPPS and matching algorithms are integrated to optimize UAV flight trajectories and user transmission power via DRL. The simulation results show that DPDTS outperforms existing benchmark methods in terms of delay and energy efficiency.
Xiangping Bryce Zhai, Shuang Fu 0002, Changyan Yi, Zhiquan Liu 0001, Chao Dong 0001, Chee-Wei Tan 0001
IEEE Trans. Intell. Transp. Syst.4
2026 Attacks and Detections in Recommender Systems: A Comprehensive Analysis for Models, Progresses, and Trends
abstract
Recommender systems (RSs), as crucial components of online services, can help users efficiently obtain information they may like. In reality, RSs face long-term threats. Attackers manipulate recommendation results by injecting malicious data in order to obtain benefits. At present, research on the security of RSs lacks a comprehensive understanding of attack capabilities. Moreover, existing defense strategies have not yet been systematically associated with attack characteristics. More importantly, existing defense methods rarely focus on real unlabeled data in practical application scenarios for anomaly detection and forensics. Therefore, this survey systematically analyzes the security of RSs and provides new insights. Specifically, we first categorize attack models from an attack perspective into: attack strategies based on targets, attack strategies against security and privacy, attack strategies based on prior knowledge, and attack strategies against other RSs. From a perspective of defense, existing detection models, second, can be divided into: behavioral representation based on statistics, detection based on hidden features, detection against privacy attacks, anomaly discovery based on association mining, and abnormality forensics for real-world data. Finally, we propose several potential research directions aimed at providing guidance for the security research of RSs. Additionally, to facilitate experimental reproducibility and comparative research, this survey also provides a repository of resources for attacks and defenses (https://github.com/xiaofengbbb/RS-Papers).
Zhihai Yang, Jianxin Li 0001, Pinghui Wang, Zhiquan Liu 0001
IEEE Trans. Knowl. Data Eng.6
2026 SAPP: Achieving Semantic-Aware Differential Privacy for Spatiotemporal Trajectory Data Publishing
abstract
With the increasing availability of large-scale spatiotemporal data from location-based services, trajectory publishing has become essential for data-driven analysis and intelligent applications. However, insufficient protection of trajectory location data may result in the disclosure of user privacy and social relationship information. To address this issue, we propose a semantic-aware privacy-preserving trajectory data publishing scheme (SAPP). First, a sliding-window algorithm is employed to extract stay points as key semantic locations and to generate a uniformly sampled set of candidate obfuscation points. Then, a semantic-aware scoring function is designed to probabilistically select candidate points that preserve semantics while avoiding sensitive regions. Furthermore, SAPP computes the sensitivity of each location based on semantic frequency and dynamically allocates the privacy budget. Finally, random noise is added to candidate trajectories using the Laplace mechanism. Through a dual-perturbation mechanism, spatial correlations in sensitive regions are weakened. Security analysis and experimental results further demonstrate that, compared with existing approaches, SAPP reduces TPPS and SFRR by up to 18% and 14%, respectively, indicating stronger resistance against trajectory inference and semantic leakage attacks while maintaining high data utility and time efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Trans. Knowl. Data Eng.6
2026 Horizontal Multi-Party Data Publishing Under Differential Privacy via Weight-Aware Bidirectional Generative Adversarial Networks
Pengfei Zhang 0010, Zhikun Zhang 0001, Yang Cao 0011, Xiang Cheng 0003, Lihua Yin, Puning Zhao, Zhiquan Liu 0001, Li Sun 0008, Lei Shi 0030, Ji Zhang 0001
IEEE Trans. Knowl. Data Eng.7
2026 Locally Differentially Private Truth Discovery for Sparse Crowdsensing
abstract
Truth discovery has emerged as an effective tool to mitigate data inconsistency in crowdsensing by prioritizing data from high-quality responders. While local differential privacy (LDP) has emerged as a crucial privacy-preserving paradigm, existing studies under LDP rarely explore a worker's participation in specific tasks for sparse scenarios, which may also reveal sensitive information such as individual preferences and behaviors. Existing LDP mechanisms, when applied to truth discovery in sparse settings, may create undesirable dense distributions, provide insufficient privacy protection, and introduce excessive noise, compromising the efficacy of subsequent non-private truth discovery. Additionally, the interplay between noise injection and truth discovery remains insufficiently explored in the current literature. To address these issues, we propose a lOcally differentially private truth diSCovery approach for spArse cRowdsensing, namely OSCAR. The main idea is to use advanced optimization techniques to reconstruct the sparse data distribution and re-formalize truth discovery by considering the statistical characteristics of injected Laplacian noise while protecting the privacy of both the tasks being completed and the corresponding sensory data. Specifically, to address the data density concerns while alleviating noise, we design a randomized response based Bernoulli matrix factorization method BerRR. To recover the sparse structures from densified, perturbed data, we formalize a 0-1 integer programming problem and develop a sparse recovery solving method SpaIE based on implicit enumeration. We further devise a Laplacian-sensitive truth discovery method LapCRH that leverages maximum likelihood estimation to re-formalize truth discovery by measuring differences between noisy values and truths based on the statistical characteristic of Laplacian noise. Our comprehensive theoretical analysis establishes OSCAR's privacy guarantees, utility bounds, and computational complexity. Experimental results show that OSCAR surpasses the state-of-the-arts by at least 30% in accuracy improvement.
Pengfei Zhang 0010, Zhikun Zhang 0001, Yang Cao 0011, Xiang Cheng 0003, Youwen Zhu, Zhiquan Liu 0001, Ji Zhang 0001
IEEE Trans. Knowl. Data Eng.6
2026 SAPE: A Scalable Aggregation With Parallel Encoder for Federated Learning in VANETs
abstract
Federated Learning (FL) has recently gained prominence in the context of Vehicular Ad-hoc Networks (VANETs) as a promising approach to enhancing autonomous driving capabilities. However, vehicles' high mobility, real-time communication, and dynamic network topology lead to frequent disconnections during operation, which may slow down the convergence of FL or even lead to training failure. In this study, we propose a scalable aggregation scheme (SAPE) designed to improve computation efficiency and address vehicle dropouts. SAPE employs a lossless encoding algorithm with parallel technology for efficient aggregation of large vectors. Then, we leverage TJL (ACSAC '22) to reconstruct gradients for dropout vehicles, using online vehicles to establish a$k$-regular graph. In a network with$N$vehicles, SAPE achieves a secure aggregation overhead of$O(log^{2}(N))$, as opposed to$O(N^{2})$, tolerating a vehicle dropout rate of up to 33%. Furthermore, we conduct a theoretical security analysis of SAPE to prove its security under honest-but-curious (HBC) and malicious attack models. Extensive experiments show that SAPE outperforms existing baseline aggregation schemes by up to 1.4× speedups in aggregation time.
Xia Feng, Wenhao Cheng, Huijuan Zhu 0001, Zhiquan Liu 0001, Liangmin Wang 0001
IEEE Trans. Mob. Comput.5
2026 Cloud-Assisted Privacy-Preserving Safety Monitoring Scheme for Online Ride-Hailing Services
Chengzhe Lai, Jiping Ma, Zhiquan Liu 0001
IEEE Trans. Mob. Comput.3
2026 Utility-Aware Resource Allocation for Hybrid NOMA in MEC: A Matching-Coalition Game Approach
Haolin Liu 0001, Zhiquan Liu 0001, Shujuan Tian, Yong Xie 0003
IEEE Trans. Mob. Comput.4
2026 Security-Enhanced Spatial Range Query Over Large-Scale Encrypted Mobile Cloud Datasets
Yinbin Miao, Xinghua Li 0001, Jun Feng 0007, Zhiquan Liu 0001, Robert H. Deng
IEEE Trans. Mob. Comput.6
2026 Cer-FeaUn: Certified Feature Unlearning in Vertical Federated Learning
abstract
Feature unlearning, forgetting sensitive features while maintaining the accuracy of models, is a pressing issue against Feature Inference Attacks (FIA) in Vertical Federated Learning (VFL). This issue is addressed by retraining the model from scratch on a dataset without the sensitive features from scratch or Federated Unlearning (FU) for all samples. However, they either introduce high overheads due to retraining or reduce the accuracy of the unlearned model. In this paper, we proposedCer-FeaUn, a certified feature unlearning, trading off between the overheads and accuracy. Specifically, a novelfeature perturbation strategyis first proposed to construct a perturbed dataset, where the sensitive features are perturbed with noises. Then, the effect is defined as the parameters difference between models trained with the original and perturbed dataset. Finally, an unlearned model is trained in first-order, where the effect is removed from the original model in one epoch. Furthermore, Cer-FeaUn performscertified removalfor server-side models with strongly convex loss functions. That is, the distribution of the unlearned model is statistically indistinguishable from that of the retrained model. For the scenario with a few sensitive features, simulation results show that the accuracy of the unlearned model is up to 84.79%, and the runtime of Cer-FeaUn is 15 times faster than that of the retrained model.
Zhaobo Lu, Zhiquan Liu 0001, Tao Li 0043, Zhenhua Chen 0001, Willy Susilo
IEEE Trans. Mob. Comput.3
2026 Toward Energy-Saving Deployment in Large-Scale Heterogeneous Wireless Sensor Networks for Q-Coverage and C-Connectivity: An Efficient Parallel Framework
abstract
Efficient deployment of thousands of energy-constrained sensor nodes (SNs) in large-scale wireless sensor networks (WSNs) is critical for reliable data transmission and target sensing. This study addresses the Minimum Energy Q-Coverage and C-Connectivity (MinEQC) problem for heterogeneous SNs in three-dimensional environments. MnPF (Metaheuristic–Neural Network Parallel Framework), a two-phase method that can embed most metaheuristic algorithms (MAs) and neural networks (NNs), is proposed to address the above problem. Phase-I partitions the monitoring region via divide-and-conquer and applies NN-based dimensionality reduction to accelerate parallel optimization of local Q-coverage and C-connectivity. Phase-II employs an MA-based adaptive restoration strategy to restore connectivity among subregions and systematically assess how different partitioning strategies affect the number of restoration steps. Experiments with four NNs and twelve MAs demonstrate efficiency, scalability, and adaptability of MnPF, while ablation studies confirm the necessity of both phases. MnPF bridges scalability and energy efficiency, providing a generalizable approach to SN deployment in large-scale WSNs.
Yukang Jiang, Zishang Qiu, Donglin Zhu, Zhiquan Liu 0001, Zhenzhou Tang
IEEE Trans. Netw. Serv. Manag.5
2026 EPVFL: Efficient Privacy-Preserving and Verifiable Federated Learning
Guofu Zhu, Wenting Shen, Jiewang Cai, Zhiquan Liu 0001, Ye Su 0001, Jinlu Liu
IEEE Trans. Netw. Serv. Manag.4
2026 EAStream: An Environment-Aware Adaptive Bitrate Algorithm for Reliable Video Streaming Services
abstract
Video streaming has emerged as a widely used Internet service, in which adaptive bitrate (ABR) algorithms play a critical role in delivering high quality of experience (QoE). However, existing learning-based ABR methods often suffer from limited generalization in unseen and dynamically changing network conditions. Although some meta-reinforcement learning techniques have been proposed to mitigate this issue, they generally depend on additional online training or fine-tuning. To overcome these limitations, this paper introduces EAStream, an environment-aware ABR algorithm based on meta-reinforcement learning for reliable video streaming services. The method employs a variational autoencoder to extract a latent representation of the current network environment from historical interaction data. This latent variable, along with the current system state, is fed into a policy network that perceives network conditions in real time and adapts bitrate decisions accordingly, without requiring further online training. A comprehensive evaluation is conducted using diverse real-world network traces. Experimental results show that EAStream not only achieves leading performance on in-distribution test sets compared to state-of-the-art ABR algorithms, but also demonstrates superior generalization capability on out-of-distribution test scenarios.
Zeming Huang, Wenjing Xiao, Miaojiang Chen, Zhiquan Liu 0001, Min Chen 0003, Athanasios V. Vasilakos, Ahmed Farouk, Houbing Song
IEEE Trans. Serv. Comput.4
2026 SecDiv: Privacy-Preserving Diversity-Constrained Top-$k$k Query Processing in the Cloud
abstract
With the proliferation of cloud computing, outsourcing databases has become a common strategy for reducing on premise storage and computation costs. However, this approach raises serious privacy concerns, as sensitive data and query information may be exposed to the cloud. While existing top-$k$query methods have made progress in performance and privacy protection, they offer limited support for the more advanced requirement of diversity constrained queries. In light of this, we present SecDiv, the first privacy-preserving query system that supports diversity constraints over ciphertext in the cloud. SecDiv is built on a two-server distributed trust model and lightweight additive secret sharing, and hides data contents under an honest-but-curious, non-colluding adversary model to ensure that cloud servers learn no sensitive information. SecDiv comprises three customized secure components: SecDMap maps the structured database of the data owner into two secret-shared tables; SecQMap translates each SQL statement and its diversity constraints into vectors whose lengths match the database attributes, thereby hiding targeted attributes and literal values; and SecCQ performs secure filtering, ordering, and top-$k$selection in the cloud, centered on a secure most significant bit comparison implemented by a parallel-prefix adder. A formal security analysis is conducted to provide theoretical guarantees for the security of SecDiv. SecDiv is evaluated on three real datasets, with diversity constraints configured using top-$k$and category count conditions to emulate practical ranking scenarios. Compared with a plaintext baseline, SecDiv achieves identical results with 100% accuracy. Query latency remains practical, with second-level response times in typical settings, and communication overhead increases as expected. Overall, experimental results demonstrate that SecDiv attains a balanced trade-off among privacy, accuracy, and efficiency in real-world cloud service environments.
Yinxing Zhang, Guang Tang, Qingwang Wang, Songlei Wang, Zhiquan Liu 0001, Zhongyun Hua
IEEE Trans. Serv. Comput.5
2026 MalElves: Reinforcement Learning-Driven Adversarial Example Generation for Evading Cross-Platform ELF Malware Detection
abstract
Adversarial Example (AE) generation is a key instrument for stress-testing and hardening malware detectors, yet most existing techniques target Portable Executable (PE) files and do not transfer cleanly to Executable and Linkable Format (ELF) binaries prevalent in Internet of Things (IoT) environments. We proposeMalElves, a reinforcement learning-driven AE generation framework for cross-platform ELF malware.MalElvesmakes three core technical contributions. First, a code-data-aware manipulation framework unifies obfuscation and rewriting across ARM, ×86, and ×64 architectures while preserving functionality. Second, a sample-efficient state design reduces 2,350 raw ELF features to a compact 21-dimensional input. Third, a shaped multi-detector reward uses fully disclosed PPO settings for full reproducibility. We evaluateMalElveson 161,414 malware samples and 74,260 benign samples. We test against four static detectors and a behavioral-ensemble stress test. The method achieves average ASRs of 89.9%, 85.3%, 63.8%, 60.6%, and 24.7% across detectors. The overall average ASR reaches 64.8%. Each successful evasion requires 2.24 interaction rounds on average.
Zhangbo Long, Letian Sha, Yan Lin 0003, Peijie Sun, Haiping Huang, Fu Xiao 0001, Zhiquan Liu 0001
IEEE Trans. Software Eng.7
2026 Toward Autonomous Driving With Short-Packet Rate Splitting: Age of Information Analysis and Optimization
Zirui Zheng, Yingyang Chen, Xinyue Pei, Xingwei Wang 0001, Zhiquan Liu 0001, Theodoros A. Tsiftsis, Miaowen Wen, Pingzhi Fan
IEEE Trans. Wirel. Commun.5
2025 Curriculum Hierarchical Knowledge Distillation for Bias-Free Survival Prediction
abstract
Survival prediction is a pivotal task for estimating mortality risk within a given timeframe based on whole slide images (WSIs). Conventional models typically assume that WSIs across patients are independent and identically distributed, an assumption that may not hold due to inherent variability in WSI preparation and the uncertain condition of infected tissues. These uncontrollable external factors introduce significant variability in the numbers and resolutions of WSIs across patients, leading to bias and compromised performance, particularly for tail patients with limited data. In this paper, we propose a novel approach, PathoKD, based on knowledge distillation. Recognizing the hierarchical nature of disease progression and the data scarcity issues associated with vanilla knowledge distillation methods, PathoKD integrates a novel curriculum learning framework with hierarchical knowledge distillation. This integration effectively mitigates the performance gap between head and tail patients, thereby enhancing prediction accuracy across patient groups. Our proposal is extensively evaluated over popular datasets and experimental results demonstrate its superiority.
Chaozhuo Li, Zhihao Tang 0002, Mingji Zhang, Zhiquan Liu 0001, Litian Zhang, Xi Zhang 0008
IJCAI4
2025 Joint client-server selection and resource allocation based on split federated learning in Edge-to-Cloud computing environments
Yishan Chen 0001, Xiangwei Zeng, Xiansong Luo, Zhiquan Liu 0001
Comput. Networks4
2025 Multi-Attack Identification and Mitigation mechanism based on multi-agent collaboration in Vehicular Named Data Networking
Na Fan 0003, Zhiquan Liu 0001, Wenjun Fan
Comput. Networks4
2025 Optimizing cost through UAV deployment and task assignment in hybrid UAV-assisted MEC systems
Haolin Liu 0001, Tingrui Pei, Zhiquan Liu 0001, Qingyong Deng, Yanping Cheng
Comput. Networks4
2025 Robust and privacy-preserving federated learning scheme based on ciphertext-selected users
Xiaoming Wang 0004, Zhiquan Liu 0001, Binrui Huang
Comput. Networks2
2025 Malicious vehicle detection scheme based on UAV and vehicle cooperative authentication in vehicular networks
Wenming Wang 0001, Zhiquan Liu 0001, Lingyan Xue, Haiping Huang, Nageswara Rao Lavuri
Comput. Networks2
2025 EVFL-DCs: Enhancing verifiability of federated learning by double commitments based on blockchain
Qianjin Wei, Xuanjing Wu, Zhiquan Liu 0001, Gang Rao
Comput. Networks3
2025 AdaptPUD: An accurate URL-based detection approach against tailored deceptive phishing websites
Jinmin Wu, Ning Lu 0005, Zhiquan Liu 0001
Comput. Networks5
2025 ATSDetector: An Android Trojan spyware detection approach with multi-features
Haiyong Wu, Ning Lu 0005, Zhiquan Liu 0001
Comput. Secur.5
2025 A Verifiable and Efficient Multi-Keyword Fuzzy Rank Search Scheme Over Encrypted Data With Privacy-Preserving
abstract
ABSTRACT Searchable Encryption (SE) enables searching over encrypted data. Exact keyword search is supported in most SE schemes, which achieve higher search accuracy but suffer from lower completeness due to the inability to handle similar expressions. To realize fuzzy keyword search, some schemes employ Bloom Filters (BFs), but these may incur high false positive rates and risk exposing the Bloom Filter's internal values to cloud servers (CS). Besides, most existing schemes ignore the fact that CS may engage in malicious behaviors (e.g., undercounting parameters or forging results). To address these issues, we propose an efficient and verifiable ranked fuzzy multi‐keyword search scheme based on BFs. We propose a Twin Bloom Filter (TBF) to conceal insertion positions and introduce random numbers to obfuscate uninserted bits. Search results are ranked using Term Frequency‐Inverse Document Frequency (TF‐IDF) scores to improve relevance. To ensure correctness and integrity, we employ Real Homomorphic Message Authentication Codes (RealHomMAC) and a random challenge technique, respectively. Security analysis proves that our scheme remains secure under both the known‐ciphertext model and the known‐background model. Theoretical and experimental performance analysis confirms that our scheme achieves efficient and accurate keyword search.
Fengyi Gao, Na Wang 0003, Jianwei Liu 0001, Zhiquan Liu 0001, Junsong Fu 0001, Lunzhi Deng
Concurr. Comput. Pract. Exp.4
2025 A binary linear predictive evolutionary algorithm with feature analysis for multiobjective feature selection in classification
Xuming Han, Zhiquan Liu 0001, Minghan Gao
Eng. Appl. Artif. Intell.4
2025 Long-term abnormal gait recovery for gait recognition
Xin Chen 0021, Futian Zhu, Zhiquan Liu 0001, Qi Tian 0001
Expert Syst. Appl.3
2025 FeaUn: Feature unlearning in vertical federated learning for IIoT against feature inference attacks
Zhaobo Lu, Tao Li 0043, Guangshun Li, Zhiquan Liu 0001
Neurocomputing6
2025 Towards imbalanced regression over distributionally biased data: A fast static approach
Wentai Wu, Ligang He, Weiwei Lin 0001, Jinyi Long, Zhiquan Liu 0001, C. L. Philip Chen
Inf. Softw. Technol.5
2025 MSFD: Multiscale Feature Decomposition for Cross-Modality Visible-to-Infrared Drone Image Translation
abstract
In the global landscape of the Internet of Things (IoT), drone IoT technology has gained widespread application. This technology can monitor and analyze land use and land cover more quickly and more accurately. Currently, the images collected by drone IoT technology are mostly visible images, which are highly susceptible to external environmental factors, while the acquisition of infrared images is relatively more challenging. Visible-to-infrared drone image translation seeks to convert visible drone images into their corresponding infrared counterparts. Although existing GAN-based image-to-image translation methods have demonstrated impressive results in the domain of natural images, they still face challenges in generating highly realistic infrared drone images. Therefore, a novel Multi-Scale Feature Decomposition (MSFD) method is introduced for visible-to-infrared drone image translation. The proposed approach accomplishes the translation through spectral feature disentanglement and cross-modal recombination. In our model, spectral feature disentanglement is based on the separation of modality-specific spectral information and modality-invariant shared structural content from the image representation. Subsequently, the spectral features and underlying content from different modalities can be recombined by generators to facilitate cross-modality image translation. To enhance the quality of generated images, our method integrates a multi-scale spectral feature encoder to address significant spectral discrepancies between targets and backgrounds in drone images by extracting and fusing spectral features at different scales. Additionally, the strategy of multi-scale generators and discriminators further enhances the generation quality of infrared drone images. The experimental results highlight the superior performance of our model in visible-to-infrared drone image translation.
Zhiquan Liu 0001, Zonghao Han, Mingyang Ma 0004, Jian Zhao 0002
IEEE Internet Things J.2
2025 Decentralized-Voting-Based Federated Learning Framework for Lightweight Node Selection in Edge Collaborative IoT
abstract
Federated learning (FL) is an emerging distributed machine learning paradigm that has privacy-preserving properties, but still poses privacy leakage risks in traditional centralized FL (CFL) caused by the frequent transmission of model parameters during training. Due to the resource differences among nodes, the training process is constrained by the slowest node, while frequent data transmissions result in significant communication overhead, leading to the reduced overall efficiency. What is more, resource-rich nodes cannot fully utilize their potentials, and large models cannot be deployed on resource-constrained end devices. Therefore, selecting participating nodes and their local training strategies efficiently is a key issue in FL. To address the aforementioned issues, this article proposes an edge-cooperative decentralized lightweight FL framework (Dec-LWFL), which introduces a multiagent reinforcement learning (MARL) method, and designs a scoring voting mechanism for selecting participating FL nodes, determining their local training strategies, and allocating the model aggregation tasks. During agent interactions, Gaussian noise is added to the state information to safeguard the privacy of edge nodes and users, and Rényi differential privacy (RDP) is utilized to quantify the effectiveness of the privacy protection mechanism. To adapt to the resource-constrained IoT environment, Huffman coding is employed during FL training phase to compress the transmitted models and reduce the communication overhead; then, knowledge distillation is selected during the deployment phase to achieve the goal of lightweight deployment. Experimental results demonstrate that Dec-LWFL can effectively balance the privacy and performance. The framework can significantly optimize the training latency and energy consumption, while satisfying the requirements for lightweight deployment.
Yishan Chen 0001, Yuan Min, Zhiquan Liu 0001
IEEE Internet Things J.4
2025 Efficient and Secure Content-Based Image Retrieval in Cloud-Assisted Internet of Things
abstract
With the rapid growth of encrypted image data outsourced to cloud servers, achieving data confidentiality and searchability in cloud-assisted Internet of Things (IoT) environments has become increasingly feasible. However, achieving high efficiency and strong security simultaneously over large-scale encrypted image datasets remains a challenge. To address this, we propose a novel efficient and secure content-based image retrieval scheme in cloud-assisted IoT. Specifically, our scheme leverages lattice-based fully homomorphic encryption and homomorphic comparison techniques, utilizing Cheon-Kim–Kim-Song’s batch processing and single-instruction-multiple-data capabilities. This approach significantly reduces the overhead of fully homomorphic computations, making the query process computational complexity independent of dataset size under certain conditions. Moreover, by integrating private information retrieval technology, the scheme enhances privacy by hiding access patterns of image data. Formal security analysis demonstrates that our scheme achieves indistinguishability against chosen-plaintext attack (IND-CPA), and extensive experiments based on real datasets confirm that our scheme is both practical and efficient for real-world applications.
Lin Chen 0033, Yiwei Yang 0003, Li Yang 0005, Yinbin Miao, Zhiquan Liu 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Chao Hong
IEEE Internet Things J.6
2025 Secure and Fine-Grained Data Sharing in Internet of Things: Integration of Interplanetary File System and Cross-Blockchain for Access Control
abstract
With the proliferation of data sharing in the Internet of Things (IoT), protecting privacy-sensitive information and preventing unauthorized access have become paramount concerns. Existing centralized access control methods faces single-point-of-failure risks and lacks scalability for dynamic IoT systems. This paper proposes a fine-grained access control framework based on cross-blockchain technology for transparent and flexible IoT data sharing. In our framework, the cross-blockchain module is facilitated to eliminate data isolation across domains, the Interplanetary File System (IPFS) is used to mitigate centralized storage risks and reduce blockchain storage overhead, CP-ABE and symmetric encryption are integrated to enforce attribute-based, fine-grained access control with strong security guarantees. Meanwhile, the blockchain records data and key references to enforce secure access to shared data content. We further conduct security analysis and experimental evaluations, demonstrating the effectiveness and efficiency of the proposed scheme.
Jiqiang Liu, Wei Ni 0001, Chao Li 0023, Wei Wang 0012, Zhiquan Liu 0001, Abbas Jamalipour
IEEE Internet Things J.7
2025 A Multitarget Backdoor Attack Against Automatic Modulation Recognition for IoT Wireless Signals
abstract
Deep learning-based automatic modulation recognition (AMR) is essential for enabling access authorization and spectrum management for interconnected devices and sensors in Internet of Things (IoT) systems. However, the open collection of data and the use of third-party training resources may introduce security vulnerabilities, especially backdoor attacks. Current research allows attackers to mislead receivers into misclassifying signals as a specific modulation type, but the fixed position of the trigger restricts its use in complex wireless networks. In this work, we propose a novel spatially distributed multi-target backdoor attack (SMBA) method. This method utilizes a trigger pattern to manipulate all types of input signals into multiple target modulation types by embedding the stealthy trigger at different spatial locations within the input signals. SMBA disseminates malicious samples across multiple target types specified by attackers, making it difficult for defenders to predict the target type into which the modulation signal embedded with the trigger is classified. This work reveals new security threats to AMR and provides important insights for developing defense technologies for IoT systems.
Xu Gan, Hongjun Wang 0010, Zhiquan Liu 0001, Hao Jiang 0006, Jiangzhou Wang
IEEE Internet Things J.4
2025 A Searchable Encryption Scheme for Blockchain-Based Digital Twins
abstract
With the widespread adoption of digital twin (DT) technology in cross-domain data sharing scenarios, ensuring secure and efficient search over encrypted data has become a significant challenge. This article proposes a blockchain-based searchable encryption scheme tailored for DTs, supporting privacy-preserving keyword search, verifiable data access, and decentralized trust establishment. The scheme collects real-time data streams from digital sensors and devices to construct unified DT records for intelligent analytics and decision-making. The scheme integrates lightweight searchable encryption with blockchain-based trapdoor delegation and ciphertext-level indexing, enabling secure and low-complexity keyword matching. By introducing a delegated trapdoor mechanism, users can authorize repeated keyword queries via a single token, thereby minimizing communication and computational costs. Additionally, a blockchain-driven key generation protocol based on distributed voting eliminates reliance on centralized authorities and ensures transparent, auditable key management. Moreover, encrypted records are stored in IPFS, resolving the storage limitations of blockchain and preserving verifiable data availability. The trapdoor delegation records and result verification parameters are committed on-chain, enabling query correctness checking and traceable access control. Under the ciphertext indistinguishability (CI) and trapdoor indistinguishability (TI) security models, the proposed scheme is formally proven to achieve CI and trapdoor privacy, providing resistance to adaptive insider keyword guessing attacks. Compared with existing schemes, it offers stronger privacy guarantees with lower overhead, supporting scalable and secure DT data sharing.
Hongmin Gao 0002, Zhiquan Liu 0001, Zhaofeng Ma
IEEE Internet Things J.4
2025 PPFL: Privacy-Preserving Federated Learning Based on Differential Privacy and Personalized Data Transformation
abstract
Federated learning (FL) prevents direct exposure of raw data. However, it remains vulnerable to privacy and security threats such as inference and poisoning attacks. Traditional differential privacy (DP) methods utilize noise injection to mitigate these attacks, which inherently degrades the accuracy of the model. In this paper, we propose a robust FL framework with two alternative effective defense mechanisms to enhance privacy preservation for various scenarios. We first propose a dual-layer client-server collaborative differential privacy (CLDP). Clients utilize adaptive local differential privacy (LDP) for data privacy, while the server uses central differential privacy (CDP) on the global model to mitigate poisoning attacks. Second, we propose enhanced central differential privacy (ECDP), a layer-specific protection mechanism that strategically injects targeted noise into non-batch normalization layers to further preserve data privacy. To mitigate noise-induced model performance degradation, our solution combines personalized data transformation and gradient sparsification, effectively alleviating both non-IID data distribution skew and cumulative noise effects. Architecturally, we decentralize the federated learning system through edge node integration, thereby eradicating single points of failure. Experimental results demonstrate that our framework achieves a superior accuracy-privacy trade-off under strict privacy constraints, providing robust protection without compromising practical utility.
Jiali Han, Liangliang Wang 0001, Zhiquan Liu 0001, Baodong Qin, Kai Zhang 0016, Weiwei Li 0007
IEEE Internet Things J.3
2025 Cross-Cloud Associated Multireplica Auditing for Lightweight Devices in the IoT
abstract
Cloud storage has become prevalent in Internet of Things (IoT) systems, attributed to its robust storage capabilities and user convenience. However, the cloud-based storage model, which separates data ownership from management, introduces integrity challenges due to the vulnerability of data to tampering. To address the risk of data loss and ensure recoverability, the implementation of multiple replicas is a common strategy. Nonetheless, traditional multireplica auditing schemes are not well suited for IoT environments that employ lightweight devices with limited computational capabilities. In response to the aforementioned challenges, we propose a novel multireplica auditing scheme named CCMR, aimed at alleviating the heavy computation cost on the device side. Our scheme leverages an efficient aggregated multisignature algorithm, offloading computationally intensive tasks associated with data tags from lightweight devices to cloud service providers (CSPs) equipped with advanced computational power. The innovative cross-cloud multireplica hash tree structure, named CC-MHT, facilitates the secure and efficient verification of data block structures and ensures consistency of replicas across multicloud environments. Furthermore, by utilizing blockchain as a public random source, a robust challenge-response protocol is established to guard against potential audit failures that could arise from collusion between the third-party auditor and CSPs. The experimental results indicate the high efficiency of the proposed scheme in terms of computation cost.
Gaopan Hou, Zhiquan Liu 0001, Yinbin Miao, Jianfeng Ma 0001, Guisheng Liao
IEEE Internet Things J.2
2025 A Federated Framework for Air Quality Prediction With Predefined Graph and Adaptive Graph
abstract
Air quality prediction utilizes IoT technologies to collect data centrally for model training, which may cause regulatory risks, privacy concerns, and high costs of integrating data. Meanwhile, distributed training through federated learning relies on the pre-defined graph structure generated by the geographic locations of air monitoring stations, which fails to capture the potential spatial relationships between air monitoring stations. In addition, the inherent multi-period attribute of air quality data makes time series changes extremely complex. To this end, this paper proposes a Federated framework for air quality prediction with Pre-defined graph and Adaptive Graph (FedPAG). Specifically, the client encodes the air quality data and meteorological data provided by the Internet of Things (IoT) system using the multi-period interaction and encoder modules to capture the proximity and periodicity features of the time series data. Next, the server combines the hidden states uploaded by the clients with pre-defined graph and adaptive graph respectively and forms node embeddings to capture the spatial features among the clients. Then, the client concatenates the hidden states with node embeddings to fuse the spatial information and feeds them into the decoder to obtain the final predicted values. Finally, we conduct experiments on the Beijing and Shijiazhuang datasets to demonstrate the effectiveness of the proposed method.
Wei Huang 0037, Junling Chen, Jia Liu 0033, Zhiquan Liu 0001, Tianrui Li 0001
IEEE Internet Things J.5
2025 DPI-ITD: A Dual-Perspective Information-Driven Framework for Insider Threat Detection in IoT Systems
abstract
In Internet of Things (IoT) environments, insider threat detection has advanced with the integration of deep learning techniques, which can effectively model complex behaviors and heterogeneous data. However, the fragmented nature of IoT logs, behavioral redundancy, and the sparsity of insider actions increase detection complexity. While fine-grained behavior classification can improve accuracy, it also raises computational overhead, limiting applicability in resource-constrained scenarios. To address these challenges, we propose dual-perspective information-driven framework for insider threat detection (DPI-ITD), which combines user-centric and behavior-centric analyses to enhance detection efficiency and accuracy. DPI-ITD introduces a symbolic tagging strategy guided by tagging scores (TS), derived from user action diversity and behavioral context, to filter redundant fragments and focus on high-impact behaviors. It further incorporates an adaptive embedding mechanism based on GloVe, which dynamically adjusts the context window for rare but critical actions. Experiments on multiple closed and open behavioral datasets demonstrate DPI-ITD’s superior detection performance, scalability, and efficiency, confirming its suitability for lightweight deployment in real-world IoT security systems.
Kai-Chuan Kong, Xiao-Bo Jin, Dongjie Liu, Zhiquan Liu 0001, Guanggang Geng
IEEE Internet Things J.5
2025 SCRM: Secure and Controllable Similarity Retrieval in Multiuser Settings
abstract
Cloud computing has become an essential paradigm for facilitating large-scale and privacy-preserving encrypted image retrieval in Internet of Things (IoT) environments. However, existing encrypted image retrieval schemes face challenges in balancing retrieval efficiency and data security, which hinders their practical adoption. On one hand, retrieval-efficient schemes based on secure k-Nearest Neighbor (kNN) are prone to known-plaintext attacks; on the other hand, highly secure schemes based on homomorphic encryption often suffer from excessive computational and storage overhead. Furthermore, supporting multi-user environments and enforcing fine-grained access control over query users are critical challenges in IoT-based retrieval systems. To tackle these issues, we propose a Secure and Controllable similarity Retrieval scheme in Multi-user settings (SCRM), which achieves a practical trade-off between efficiency and security while enabling multi-user management. First, we design an efficient and privacy-preserving similarity computation method that is resilient against known-plaintext attacks. Second, we introduce a key conversion protocol that enables similarity retrieval in multi-user settings without requiring key sharing. Third, we integrate attribute-based encryption to enforce fine-grained access control and trace query users who may leak decryption keys. A correctness analysis confirms that SCRM ensures accurate similarity retrieval while supporting access control. Furthermore, a formal security analysis demonstrates that SCRM effectively protects data privacy against known-plaintext attacks. Finally, extensive experiments on real-world image dataset validate the efficiency and effectiveness of SCRM.
Yingying Li 0001, Feng Li 0041, Gaopan Hou, Yu Guan 0003, Zhiquan Liu 0001, Qi Xie 0001
IEEE Internet Things J.5
2025 Efficient Privacy-Preserving Similarity Retrieval With Fine-Grained Access Control
abstract
Privacy-preserving similarity retrieval for ciphertext images has broad applications in Internet of Things (IoT) areas, including smart healthcare, face recognition, and social networking. However, most existing privacy-preserving schemes suffer from inefficient retrieval and limited security guarantees due to the use of unreasonable encryption methods. In addition, those supporting fine-grained access control often lack scalability or are computationally inefficient. To address these challenges, we propose an efficient similarity retrieval scheme for ciphertext images that ensures both privacy preservation and fine-grained access control. First, we construct an encrypted index tree using clustering to improve retrieval efficiency while preserving high recall. Second, we achieve security against chosen-plaintext attacks (CPA) and result verification by employing symmetric homomorphic encryption and Merkle hash tree. Third, we realize access control for each image, enabling simultaneous access verification and similarity retrieval via a single inner product operation. Our theoretical and experimental analysis shows that the proposed scheme is CPA-secure and achieves up to 100× faster query processing than existing CPA-secure schemes, with the ability to retrieve 2000 ciphertext images within 0.5 seconds for 128-dimensional feature vectors.
Yingying Li 0001, Feng Li 0041, Fuqun Wang, Zhiquan Liu 0001, Qi Xie 0001, Song Han 0006
IEEE Internet Things J.4
2025 Latency-Aware Client Selection and Energy Management for Hierarchical Federated Learning
abstract
With the prosperity of deep learning (DL) in Internet of Things (IoT) fields, federated learning (FL), viewed as a critical element of numerous DL-aided IoT intelligent applications, enables cooperative DL training across decentralized clients without revealing their personal data. However, the computational capacity heterogeneity and limited energy resources of IoT devices cause a huge negative influence on FL training in IoT intelligence applications. To address the above issues, this paper proposes an excellent distributed training mechanism for hierarchical FL to reduce training latency and energy cost for achieving the desirable accuracy. Specifically, taking into account computational capacity heterogeneity of clients, we first design a latency-regularization-aware client selection algorithm to appropriately select participating clients in training epochs and control their participation frequencies for boosting distributed training efficiency. Subsequently, after obtaining the selected client subset in each hierarchical FL training epoch, by leveraging the variable transmission delays of clients in distributed training, we propose a mixed integer linear programming-based transmission power management strategy for participating clients to alleviate their energy consumption burden. Extensive numerical results demonstrate that our proposed mechanism can attain 576.93% training speedup and achieve 10.94% accuracy enhancement compared with the baseline General FL, and yield up to 56.91% energy cost savings compared with the baseline HierFAVG.
Jiamei Li, Kun Cao 0001, Yangguang Cui, Tong Liu 0001, Zhiquan Liu 0001
IEEE Internet Things J.6
2025 Privacy-Preserving Clustering-Based Image Retrieval in Cloud-Assisted Internet of Things
abstract
The advancement of cloud-assisted Internet of Things (IoT) has amplified the usability for secure and searchable image retrieval, addressing the growing demand for privacy protection in digital multimedia. Current encrypted image retrieval schemes focus either on search precision or search efficiency, making them less viable for deployment on IoT devices with limited resources. Therefore, in this article, we present a privacy-preserving clustering-based image retrieval (PPCBIR) scheme for IoT environment. First, we employ a convolutional neural networks (CNN) for feature extraction and design an extended k-nearest neighbor (kNN) algorithm to protect the privacy of image features. Then, we build a novel clustering-based hierarchical index tree structure to improve retrieval efficiency without compromising data privacy. Subsequently, a matrix re-encryption technique is implemented to achieve the availability of multiterminal key distribution in IoT. Furthermore, we propose an index merging method that is scalable to index trees constructed by different data owners. Finally, formal security analysis demonstrates that PPCBIR is resistant to various threat models. Extensive experiments using authentic datasets indicate that our proposed scheme is comparable to linear retrieval in search accuracy and outperforms existing state-of-the-art schemes in search efficiency, and demonstrate its practicability in IoT.
Peiya Li, Zhiquan Liu 0001, Hongliang He 0004
IEEE Internet Things J.3
2025 Budget-Feasible Truthfulness Mechanism for Task Offloading and Interaction in Edge-Vehicle Collaborative Computing
abstract
Mobile edge computing (MEC) affords high computing power but lacks sensing capability. Furthermore, intelligent vehicles, which possess rich sensing resources, consume limited energy. Motivated by this, we propose edge-vehicle collaborative computing and investigate the task offloading and interaction problem (TOIP), in which MEC servers and vehicles collaborate to leverage their strengths and mitigate their weaknesses. Motivated by practical application requirements, we propose a task interaction model where a user’s computing and sensing subtasks are respectively offloaded onto the MEC servers and vehicles, which then collaborate to complete the tasks. Aiming to maximize group efficiency, we formulate the TOIP in an auction-based setting. To motivate MEC servers and vehicles, we propose a reverse auction where each user is an auctioneer, while MEC servers and vehicles are the bidders. Our reverse auction mechanism achieves budget feasibility, where the rewards received by MEC servers and vehicles cannot exceed the budget. The proposed mechanism proves to be truthful; that is, MEC servers or vehicles cannot obtain higher utility by declaring untrue values. We also demonstrate how to make the mechanism meet the truthfulness requirement in TOIP. In addition, the proposed mechanism achieves individual rationality, consumer sovereignty, and computation efficiency. We also theoretically analyze the approximate ratio. The simulation results show that the proposed mechanism exhibits exceptional performance in all the scenarios.
Xi Liu 0002, Jun Liu 0081, Zhiquan Liu 0001, Weidong Li 0002
IEEE Internet Things J.3
2025 A Cross-Domain Authentication Scheme for Vehicular Networks Based on Mobile Edge Computing
abstract
The development of vehicular networks has significantly improved driving safety and enabled a wide range of intelligent transportation applications. However, in cross-domain scenarios, vehicular networks still face challenges, such as security risks, privacy breaches, and heavy computing burden. In this article, we propose a novel cross-domain authentication scheme for vehicular networks based on Mobile Edge Computing (MEC), in which the computing tasks on the vehicle side are offloaded to the edge server, which effectively alleviates the computation overhead on the resource-constrained vehicle side. Unlike existing schemes, we adopt a server function division and a distributed registration center approach to alleviate the burden and risk associated with the trusted authority (TA) during the authentication process. In addition, we use anonymity mechanism and batch verification to achieve privacy protection and improve authentication efficiency, respectively. Through rigorous security proofs and detailed security analyses, it is demonstrated that the proposed scheme meets the security requirements of vehicular networks and can withstand a broader range of security attacks. Performance comparison results indicate that the proposed scheme outperforms existing related schemes in terms of both communication and computation overheads.
Guijiang Liu, Wenming Wang 0001, Zhiquan Liu 0001, Haiping Huang
IEEE Internet Things J.4
2025 A Security-Enhanced Pairing-Free Certificateless Aggregate Signcryption Scheme for Decentralized Vehicular Sensor Networks
abstract
Vehicular Sensor Networks (VSNs) are integral to intelligent transportation systems, enabling real-time communication and collaborative sensing among vehicles. However, their open wireless communication environment presents significant challenges in terms of data security and privacy protection. Although various certificateless aggregate signcryption (CLASC) schemes have been proposed to address these issues, many still suffer from security vulnerabilities and performance inefficiencies. We conduct a detailed security analysis of a recently proposed CLASC scheme by Dai et al., highlighting its susceptibility to public key replacement attacks. To demonstrate this vulnerability, we construct a specific attack algorithm and, based on our findings, propose a security-enhanced CLASC scheme. The proposed solution integrates blockchain technology to improve system decentralization, enhances resistance to collusion attacks, and supports malicious identity revocation mechanism. We provide formal security proofs under standard cryptographic hardness assumptions and evaluate the performance of the scheme through both theoretical analysis and experimental validation. The results show that our approach significantly strengthens security while maintaining high efficiency, making it well-suited for secure and scalable communication in vehicular sensor network (VSN) environments.
Guangheng Wang, Yang Liu 0291, Liangliang Wang 0001, Zhiquan Liu 0001, Kai Zhang 0016, Weiwei Li 0007
IEEE Internet Things J.5
2025 Secure and Efficient Cross-Modal Data Retrieval in Internet of Things
abstract
With the rapid development of the Internet of Things (IoT), a large amount of multimodal medical data is outsourced to the IoT cloud to reduce local computation and storage costs. To retrieve encrypted multimodal medical data in cloud computing, privacy-preserving cross-modal retrieval (PPCMR) has attracted significant attention. However, existing PPCMR solutions are challenging to meet real-time retrieval requirements for large-scale datasets due to linear index structures and complex encryption algorithms. To solve these issues, we propose a novel PPCMR scheme, named CSCMR, based on canonical correlation analysis (CCA) and symmetric key hidden vector encryption (SHVE). First, we use locality-sensitive hashing and CCA to cluster multimodal medical data according to semantic similarity. Then, we build an index structure for Bloom filter based on the clustering results, achieving constant retrieval complexity. Finally, we encrypt each value in the filter using SHVE algorithm, protecting data privacy while reducing encryption computation overheads. Formal security analysis proves that our scheme can resist selective chosen-plaintext attack. Extensive experiments demonstrate that our scheme is effective and feasible.
Shuying Liu, Yinbin Miao, Zhiquan Liu 0001, Yanfei Zou, Kim-Kwang Raymond Choo
IEEE Internet Things J.4
2025 An Efficient Supply-Demand-Aligned and Trustworthy MultiKeyword Search Scheme in Edge-Assisted IoT Environments
abstract
With the integrating development of Internet of Things (IoT) and edge computing, data sharing among various IoT devices has become the trend for extensive applications. However, data sharing in IoT environments is challenged by limited terminal resources and distributed data storage, which places higher demands on security and effectiveness. Even though existing searchable encryption technologies provide feasible solutions, there remain challenges in terms of trustworthy retrieval and execution efficiency. To address these issues, this paper proposes an efficient supply-demand-aligned and trustworthy multi-keyword (ESTM) search scheme in edge-assisted IoT environments, where encrypted documents are stored in edge servers. Furthermore, blockchain-based smart contracts are employed so that search results are consensus on the Fabric ledger and data users can verify whether the returned encrypted documents are reliable using encrypted hashes. To achieve the supply-demand-aligned requirement, the RoBERTa (Robustly optimized BERT approach) model is introduced for text classification and data users can judge which edge server stores data best suits their demands. Meanwhile, coordinate (COO) format is adopted into index vectors and search vectors, which can decrease the time required for constructing an index tree to about 2.7% and the time required for generating trapdoors to about 4.6%. Finally, we conducted an in-depth security analysis and performance comparison with existing works, results show that the proposed scheme is effective and feasible.
Wenming Wang 0001, Jia Chao, Zhiquan Liu 0001, Haiping Huang
IEEE Internet Things J.6
2025 Efficient and Secure Federated Knowledge Transfer Under Non-IID Settings in IoT
abstract
In the era of Internet of Things (IoT) and federated learning (FL), where distributed training models are essential, the FL paradigm has come into the spotlight for researchers. However, the inconsistency in the sources of client data and non-independent and identically distributed (Non-IID) heterogeneous characteristics lead to loss in model accuracy. Existing method which attempts to homogenize data distribution among clients based on generative adversarial networks (GANs) incurs high computation overheads on clients in IoT. In this article, we propose a lightweight feature prototype knowledge transfer (FPKT) mechanism. By capturing the essence of data categories, FPKT generates pseudo-features without requiring the original data features, thereby efficiently enhancing model accuracy. We formally prove that FPKT resists chosen plaintext attack (CPA) and experiments demonstrate that our scheme achieves a hundredfold increase in computational efficiency and improves model accuracy by up to 40%.
Shuying Liu, Rongpeng Xie, Yinbin Miao, Tao Leng, Zhiquan Liu 0001, Kim-Kwang Raymond Choo
IEEE Internet Things J.6
2025 Stones From Other Hills: Intrusion Detection in Statistical Heterogeneous IoT by Self-Labeled Personalized Federated Learning
abstract
With the fast development of the Internet of Things (IoT), the growing amounts of data transmitted through edge devices tempt hackers to attack vulnerabilities. Because of data fragmentation and heterogeneous data distribution of IoT, attack detection models on edge devices are proficient at detecting only a limited set of specific attacks, causing a high false alarm rate when detecting new traffic data. Personalized Federated Learning (PFL) widely expands the range of detectable attacks and adapts local models to new traffic data by one step of gradient descent. However, it demands a part of the new traffic data (test-support set) with correct labels to realize adaptation, which is labor-consuming when detecting large amounts of traffic data. To solve this issue, our main idea is to find helpful models to pre-label the test-support set, we propose a novel self-labeled PFL called SOH-FL, including an autoencoder based on cosine similarity (CT-AE) to extract features and an aggregation method (BS-Agg) to tailor models for pre-labeling test-support sets depending on features extracted from edge devices. SOH-FL is evaluated in three heterogeneous scenarios using the CICIDS2017 dataset, and consistently outperforms the baselines across all metrics, achieving performance comparable to PFL without manual labeling. In the real-world feature heterogeneous scenarios of the IoT-23 and TON-IoT datasets, SOH-FL achieves accuracy improvements of 11.5% and 9.1% over the baseline, respectively. The experimental code is publicly available at https://github.com/deer-echo/SOH-FL.git.
Wenting Lu, Ayong Ye, Peixin Xiao, Yuanhuang Liu, Longjing Yang, Donglin Zhu, Zhiquan Liu 0001
IEEE Internet Things J.7
2025 A Survey of DDoS Attack and Defense Technologies in Multiaccess Edge Computing
abstract
Multiaccess edge computing (MEC) is a novel service paradigm located at the network’s edge, where servers with computation and storage capabilities are placed in proximity to network endpoints to meet the high-speed computation and low-latency requirements of these endpoints. MEC faces numerous security challenges, with Distributed Denial of Service (DDoS) attacks being one of the primary threats. On one hand, the edge server layer (ESL) encounters a greater number of attack sources and has relatively fewer defense resources, making traditional defense techniques less applicable. On the other hand, the ESL can integrate with new technologies for earlier detection and interception of attack traffic, achieving more real-time attack mitigation. To provide comprehensive insights into the latest research developments and inspire new DDoS defense solutions, this article conducts an extensive survey and synthesis. This article begins with a summary of the basic concepts, application scenarios, and security vulnerabilities of MEC networks. It then introduces the types and principles of DDoS attacks faced by MEC networks. Subsequently, various security solutions for DDoS attacks in MEC were detailed and extensively compared, followed by an introduction to current application cases of DDoS defense deployment in practical MEC scenarios. Finally, open issues and future research directions are listed for further exploration.
Yong Ma 0005, Zhiquan Liu 0001, Fagen Li, Qilin Xie, Kaiwei Chen, Chenyang Lv, Ying He 0006
IEEE Internet Things J.3
2025 An Efficient and Privacy-Preserving Range Retrieval Scheme for Location-Based Services
abstract
With the rapid development of positioning technology and mobile devices, location-based services (LBS) have witnessed extensive adoption. However, privacy leakage issues have become increasingly severe. Existing solutions often focus solely on protecting users’ location privacy while neglecting query privacy requirements, and further exhibit suboptimal retrieval efficiency when handling large-scale datasets. To comprehensively preserve user and server privacy while enhancing data retrieval efficiency, this paper proposes an efficient and privacy-preserving range retrieval scheme for location-based services (EPRL). The scheme proposes a Geohash-based query range generation algorithm, enabling users to generate query ranges according to their privacy requirements dynamically. To protect the user’s location privacy and query privacy, EPRL employs a ring signature policy. Furthermore, we innovatively design a Geohash-Trie Tree structure to store server data resources, effectively improving retrieval efficiency. Theoretical analysis and extensive experiments indicate that compared with other state-of-the-art LBS retrieval schemes, EPRL exhibits broader applicability, lower computational costs, and higher efficiency. When the number of ring signature users reaches 1,000, the total computational overhead of the scheme is approximately 5 seconds, merely one-fifth of that required by similar schemes.
Haojia Qi, Guobiao He, Na Wang 0003, Jianwei Liu 0001, Junsong Fu 0001, Zhiquan Liu 0001
IEEE Internet Things J.6
2025 Energy-Efficient Trajectory Design and Unsupervised Clustering for AAV-Aided Fair Data Collections With Dense Ground Users
abstract
In remote or high-demand wireless cellular networks, efficient data collection from ground users (GUs) with fixed infrastructure poses a significant challenge. Unmanned aerial vehicles (UAVs) have emerged as a promising solution due to their flexible deployment and cost-effectiveness. This paper focuses on a UAV-aided wireless cellular communication system comprising a UAV and multiple adjacent GUs, where the mission of the UAV is to collect data from these GUs. The objective is to minimize UAV propulsion energy consumption while ensuring fair data uploading among all GUs. Due to the non-convex and intractable nature of the above problem, we propose a novel real-time waypoint localization method based on the parallel projection method from a geometric perspective. By enhancing the projection process, this approach achieves energy-efficient and fair data collection, along with an efficient trajectory design algorithm. Further, considering the scenario of densely distributed GUs in large-scale areas, a GU-clustering algorithm is proposed based on Mean Shift. Additionally, this paper categorizes GUs into homogeneous and heterogeneous scenarios and designs distinct trajectory designing algorithms to accommodate diverse real-world situations. Simulations and comparisons validate the effectiveness and efficiency of the proposed algorithms in tackling the UAV trajectory design challenges.
Xiangping Bryce Zhai, Xin Liu 0009, Zhiquan Liu 0001, Chee-Wei Tan 0001, Congduan Li
IEEE Internet Things J.4
2025 Enabling Secure Cross-Modal Search Over Encrypted Data via Federated Learning
abstract
Cross-modal search with deep learning shows an attractive potential on heterogeneous data sets due to its accuracy and effectiveness. Usually, it has to aggregate and train large amounts of data to make precise predictions, which is feasible in the single-user environment and plaintext areas. However, the challenge lies in maintaining search accuracy within a multiuser environment while simultaneously safeguarding user data privacy. In this article, we address these challenges by centering on the development of secure cross-modal search techniques that are supported by federated learning. To our knowledge, this marks the first endeavor to execute cross-modal encrypted data search through the auspices of federated learning. Our approach specifically employs a secure and reliable federated learning technique to extract key features from diverse heterogeneous data, ensuring precise model training in a distributed data environment. Consequently, while the data is encrypted, it achieves the protection of data privacy and simultaneously enhances the efficiency and accuracy of cross-modal search. To further enhance retrieval efficiency, we propose a tag classification algorithm that employs homomorphic encryption and locality-sensitive hashing. Furthermore, we design a secure method for calculating Euclidean distance that utilizes the k-nearest neighbor algorithm. This method efficiently identifies the result nearest to the query data, thereby enhancing the accuracy of the search results. Both theoretical analysis and experimental evaluation demonstrate that our proposed scheme not only protects user data privacy but also has high accuracy and efficiency.
Xiaoming Wang 0004, Zhiquan Liu 0001, Quan Tang 0008, Xixian Wang
IEEE Internet Things J.3
2025 Efficient Homomorphic-Encryption-Based Secure Search in Multiowner Setting for Internet of Things
abstract
Ensuring the security of data outsourced to cloud is a prerequisite for the application of Internet of Things (IoT) in actual production. Secure search based on homomorphic encryption can provide high security and require no expensive setup procedure, which can be applied to resource-limited devices in IoT. However, the existing schemes usually have poor search performance and do not consider multiowner setting. To solve these issues, we propose an efficient homomorphic encryption-based secure search scheme in multiowner setting. Specifically, we construct a secure search protocol based on multikey homomorphic encryption, which can be deployed in multiowner setting. Meanwhile, we improve the efficiency of our scheme by optimizing the search algorithm. Formal security analysis proves that our scheme is secure against chosen plaintext attack, and extensive experiments demonstrate that our scheme improves the search efficiency by$1000\times $when compared with state-of-the-art solutions.
Yinbin Miao, Xinghua Li 0001, Tao Leng, Zhiquan Liu 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Internet Things J.5
2025 S3A: State-Attention Inducing Adversarial Attacks on Closed-Box Proximal Policy Optimization Models
abstract
In the current era when the Internet of Things (IoT) is booming and various smart devices are closely interconnected to build a complex network system, the demand for efficient control and resource management strategies is extremely urgent. Proximal Policy Optimization (PPO), as a highly representative algorithm in deep reinforcement learning, has great potential in aspects such as precise control of IoT devices, rational resource allocation, and intelligent interaction. However, in the practical applications of the IoT, PPO mostly exists as a black-box model, which is vulnerable to adversarial attacks. Moreover, the continuous action space scenarios applicable to PPO further increase the difficulty of analysis and protection. Therefore, this paper innovatively proposes a State-Attention Adversarial Attack (S3A) for black-box PPO models in continuous action space scenarios. This method is based on the model’s attention to states, has a low cost, integrates the parts of model extraction, action clustering, and decision-making interference of the model under specific states, and has a clear interference purpose. By constructing an IoT-related victim model in the MuJoCo environment provided by the Gym library and implementing adversarial attacks, experiments have found that under four repetitions in five simulation environments, S3A reduces the final reward of the victim model by an average of 48.5%, which strongly verifies the effectiveness and influence of this attack method.
Yichuan Wang 0003, Zhiquan Liu 0001, Xinhong Hei 0001, Jianfeng Ma 0001
IEEE Internet Things J.3
2025 A Detection Method for Malware Communication Traffic via Encrypted Traffic Analysis
abstract
As the proportion of encrypted traffic in network communications continues to increase, encryption technologies are widely used to protect user privacy and data security. Meanwhile, this also makes it more covert for hackers to spread malware, steal sensitive information, or conduct other harmful behaviors in the network. How to effectively detect encrypted malicious traffic in communications while protecting user privacy has become a key task to be addressed in the field of network security. To address this challenge, this paper proposes a detection method for malware communication traffic via encrypted traffic analysis. It extracts contextual correlations and temporal features from raw data traffic without decrypting the encrypted data using Session-Transformer. The method uses Deep Neural Networks as the classifier to detect and classify encrypted malicious traffic. The experimental results show that our method has the best performance in accuracy, precision, recall, and F1-score on the DataCon2020 encrypted malicious traffic dataset and the CIC-AndMal-2017 dataset. In particular, the recall on the DataCon2020 dataset reaches 98.34%, and the precision on the CIC-AndMal-2017 dataset achieves 93.54%.
Linfeng Wei, Yuqin Huang, Zhiquan Liu 0001
IEEE Internet Things J.6
2025 FCLLM-DT: Enpowering Federated Continual Learning With Large Language Models for Digital-Twin-Based Industrial IoT
abstract
The Industrial Internet of Things (IIoT) represents a sophisticated technology designed to enhance production management and predict output in industrial settings, including machinery fault diagnostics. The precision of fault diagnosis is contingent upon the training efficacy of diagnostic models and their interoperability with models from other industrial facilities. Nonetheless, several critical challenges persist in maintaining these diagnostic models: 1) machinery sensors may generate abnormal data, resulting in suboptimal quality in model training; 2) sensor malfunctions may lead to interruptions in continuous data flow, thus impeding model training; and 3) collaborative interactions with other factories aiming at improving model performance may pose risks of privacy breaches. In this study, we introduce the FCLLM-DT scheme, which integrates the digital twin (DT) methodology to create a physical model of bearing for fixing abnormal sensor data. Additionally, retrieval-augmented generation (RAG)-assisted large language models (LLMs) are utilized to generate virtual datasets in instances of sensor failure. Moreover, for IIoT applications across distributed industrial environments, federated continual learning (FCL) is employed to enhance global model training by aggregating localized models from diverse facilities, thereby improving the accuracy of bearing fault diagnosis while safeguarding data privacy. The experiments on the accuracy of DT for abnormal data fix, RAG-assisted LLM for virtual data generation, and FCL for bearing fault diagnosis are conducted in comparison with three alternative methods across two datasets. The results indicate that our proposed scheme surpasses existing methods in both the enhancement of sensing data quality and the accuracy of bearing fault diagnosis.
Yingjie Xia, Yunxiao Zhao, Li Kuang, Xuejiao Liu 0002, Ji Hu 0002, Zhiquan Liu 0001
IEEE Internet Things J.7
2025 Personalized Privacy Preserving for Spatial Crowdsourcing by Reinforcement Learning in VANETs
abstract
Spatial crowdsourcing is widely used in various applications in vehicular ad hoc networks (VANETs), such as navigation system, traffic control, and event reporting. However, exposing and disclosing the spatial-temporal features of vehicles in the crowdsourcing services will definitely raise serious privacy issues. Existing unified privacy-preserving strategy for vehicles will cause excessive or insufficient preservation, thus result in relatively low-quality services. To solve these problems, we propose personalized privacy preserving for spatial crowdsourcing by reinforcement learning in VANETs. First, we propose a multifactor-based personalized privacy-preserving model to adjust the vehicles’ privacy-preserving level in the scenario of spatial crowdsourcing. And, we employ reinforcement learning to dynamically adjust the model in different situations. Furthermore, we propose an optimal local differential privacy mechanism to maintain the optimal tradeoff between data privacy and data utility, which can achieve personalized privacy preserving in the task allocation. We conduct extensive simulations with the real-world traffic trajectory dataset T-drive, and use the Q-learning algorithm to dynamically adjust the model. The experiments demonstrate that our scheme can enhance data utility by 78.5% with personalized privacy settings.
Yingjie Xia, Tiancong Cao, Xuejiao Liu 0002, Zhiquan Liu 0001
IEEE Internet Things J.5
2025 A Novel Radio Frequency Fingerprint Identification Scheme for Few-Shot Open-Set Recognition
abstract
Radio frequency fingerprint identification (RFFI) has become a crucial technology in physical layer authentication, and plays an important role in authenticating the identities of wireless communication devices in the Internet of Things (IoT). Although open-set recognition has been applied in RFFI tasks, these schemes still demand extensive RF signal samples. In this paper, few-shot open-set recognition is being dedicated to exploring in RFFI tasks. To surmount mentioned challenges, we propose meta-learning by gaussian prototype network (MLGPN) scheme to achieve the goal of few-shot open-set recognition. MLGPN adopts the Mahalanobis distance between the embedding feature and the gaussian prototype as its metric. With the introduction of open-set loss function, the proposed scheme shows excellent open-set recognition performance. It is worth mentioning that meta-learning not only satisfies the demands of few-shot scenarios, but also enables new devices to join and leave without the need for retraining. Experiments conducted based on real LoRa RF signals confirmed the excellent performance of our proposed scheme for few-shot open-set recognition which surpasses traditional prototypical network model by 5.3% of AUC and 6.7% of ACC under the 1-shot condition. Compared with other schemes, the proposed scheme also demonstrated significant advantages.
Wei Xie 0001, Hongjun Wang 0010, Zhexian Shen, Zhiquan Liu 0001, Hao Jiang 0006
IEEE Internet Things J.5
2025 Verifiable and Redactable Blockchain for Internet of Vehicles Data Sharing
abstract
Blockchain enhances the security and interoperability of Internet of Vehicles (IoV) systems by serving as a secure and decentralized platform for data sharing. The rapid growth of IoV data makes it challenging to store the entire blockchain on edge nodes with limited storage resources due to the blockchain’s immutability. Redactable blockchain represents a potential solution for enabling the controlled modification of data on blocks. However, current redactable blockchain schemes suffer from high-computational overhead and lack support for stateful redaction and consistency checking. In this article, we propose a secure and efficient decentralized chameleon hash scheme (CHSTS) based on Schnorr threshold signatures. CHSTS allows${t}$-out-of-${n}$edge nodes to collaborate with the transaction proposer to compute chameleon hash collisions, enabling modification and deletion of block data without breaking the hash links between the blocks. We then construct a redactable blockchain utilizing CHSTS to alleviate the storage limitations of edge nodes. To ensure consistency checking and stateful redaction of the redactable blockchain, we design a novel modification verification mechanism based on vector commitments. Finally, we provide detailed security analysis of the CHSTS scheme and integrate the proposed scheme into hyperledger fabric to evaluate the redactable blockchain through extensive experiments. The results demonstrate that our scheme incurs less computational overhead compared to the state-of-the-art chameleon hash schemes. Furthermore, our scheme maintains close efficiency compared to immutable blockchain, incurring negligible storage overhead.
Yuxiang Yang 0006, Yuling Chen 0002, Zhiquan Liu 0001, Chaoyue Tan
IEEE Internet Things J.3
2025 Secure Pairing-Free Certificate-Based Online/Offline Signcryption Scheme With Conditional Privacy Preserving for VANETs
abstract
In vehicular ad hoc networks (VANETs), the core feature lies in the secure and prompt exchange of information between vehicles. To further enhance this feature, many signcryption schemes adopted to VANETs are proposed. However, most existing schemes still suffer from security or efficiency drawbacks. In this article, we propose a pairing-free certificate-based online/offline signcryption scheme constructed by elliptic curve, aiming to make the communication system of VANETs more lightweight and more secure. It not only ensures data confidentiality and unforgeability within one logic step but also eliminates the need of secure channels for key distribution. When deployed in VANETs, it can precompute many intricate operations in the offline phase and support batch verification of multiple messages. Moreover, our deployment provides pseudonym-based conditional privacy preserving for vehicles and its traceability results about malicious behaviors can be publicly verified, guaranteeing accountability. It also considers common attacks involved in VANETs, including but not limited to impersonation attacks, collusion attacks, and man-in-the-middle attacks. These advantages of our construction make it highly practical for VANETs, which have been demonstrated in our simulation experiments.
Wenjie Yang 0001, Peiwei Cao, Futai Zhang, Zhiquan Liu 0001
IEEE Internet Things J.4
2025 An Efficient Revocable Identity-Based Aggregate Signature Scheme With Designated Verifiers in Healthcare Wireless Sensor Networks
abstract
In healthcare wireless sensor networks (HWSNs), a process of medical diagnosis heavily relies on the medical data collected by lightweight sensors, as any malicious modification may result in severe consequences. Furthermore, large-scale data transmission in HWSNs would impose significant communication overhead. Therefore, efficiently guaranteeing the availability of these data while reducing the communication cost is crucial in HWSNs. Aggregate signatures suit the resource-limited environments, but existing ones still face several challenges, including vulnerability to coalition attacks, privacy preservation, and revocation of misbehaving signers. In this paper, we propose an efficient revocable identity-based aggregate signature scheme with designated verifiers (R-IBAS-DV) for HWSNs. In our proposed scheme, numerous individual signatures on the collected medical data can be aggregated into a succinct aggregate signature and their validity is equivalent to that of the aggregate signature. The equivalence property of our proposed scheme is sound even under coalition attacks and exclusively verifiable by designated healthcare professionals. Meanwhile, our proposed scheme is rooted in Hess’s practical identity-based signature, thereby circumventing costly certificate management. Additionally, it incorporates RSA accumulators to facilitate the efficient revocation of malicious signers. Security analysis and performance comparisons demonstrate that our R-IBAS-DV scheme offers enhanced security and lower computation overhead, making it particularly suitable for resource-constrained HWSNs.
Wenjie Yang 0001, Junzhe Fan, Futai Zhang, Anjia Yang, Zhiquan Liu 0001
IEEE Internet Things J.5
2025 Wireless Signal Identification for Secure Spectrum Sensing Based on Multiscale Fourier Segmented Attention Mechanism
abstract
The rapid development of the Internet of Things (IoT) has led to exponential growth in wireless network traffic and the number of connected devices, thereby intensifying the demand for scarce spectrum resources. In this context, Wireless signal identification, a key technology in spectrum sensing, is crucial for enhancing spectrum utilization by mitigating interference and ensuring system security. In this study, we treat wireless signal identification as a time series classification task and propose a novel model based on Fourier-segmented attention. In our proposed model, instead of computing point-level attention, we extract sequence dependencies by computing segment-level attention. Moreover, we introduce a method based on the Fourier transform to determine the segment length, ensuring that each segment captures multi-scale features. Experimental results indicate that the proposed method outperforms existing models, achieving an accuracy of approximately 95% on our dataset and representing an improvement of around 1.6% in accuracy over competing approaches. Furthermore, experiments were conducted to evaluate the model’s effectiveness in detecting fake signals and its potential to enhance system security.
Ziyi Yang 0009, Yaojun Lu, Liang Zeng 0006, Shuai Wang 0013, Jianping An, Zhiquan Liu 0001
IEEE Internet Things J.6
2025 Dynamic Cooperative Whale Optimization Algorithm for Multivehicle IoV Path Planning
abstract
The Internet of Vehicles (IoV) presents significant challenges for path planning algorithms in dynamic traffic environments. This paper proposes the Dynamic Cooperative Whale Optimization Algorithm (DCWOA) for multi-vehicle path planning in IoV. DCWOA enhances the Whale Optimization Algorithm with a three-layer structure (Individual, Group, and Group Cooperation) to optimize from local to global scope. Key innovations include: (1) a dynamic adjustment factor combining improved encircling and spiral update mechanisms; (2) local and global cooperation mechanisms enabling coordinated planning through vehicle communications; and (3) a multi-objective weighted decision model integrating travel time, fuel consumption, safety, and emissions. Comparisons with five stateof-the-art algorithms (WOA, MEWOA, PSBES, MGO, DGCO) on the CEC2017 benchmark suite show DCWOA achieving optimal performance in 27-29 of 30 test functions. In IoV environments, DCWOA demonstrates 36% improvement in optimization efficiency at 60% traffic density and reduces travel time by 21-26%. During unexpected events, DCWOA achieves 7-second path adjustment time with 100% success rate, outperforming comparison algorithms’ 12-28 seconds and 65-85%. The code is available at: https://github.com/yangwb02/MVPP-DCWOA.
Wenbiao Yang, Zhiquan Liu 0001
IEEE Internet Things J.3
2025 FuzzCoder: Code Large Language Model-Based Fuzz Testing for Industrial IoT Programs
abstract
Fuzz testing is an dynamic program analysis technique designed for discovering vulnerabilities in IoT systems. The core goal is to deliberately feed maliciously crafted inputs into an IoT device or service, triggering vulnerabilities such as system crashes, buffer overflow exploits, and memory corruption, etc. Efficiently generating malicious inputs remains challenging, with leading methods often relying on randomly mutating existing valid inputs. In this work, we propose to adopt fine-tuned large language models (FuzzCoder) to learn patterns in the input files from successful attacks to guide future fuzzing explorations. Specifically, we develop a framework that leverages code LLMs to guide the mutation process to perform meaningful input mutations. We formulate the mutation process as the sequenceto-sequence modeling, where LLM receives a sequence of bytes and outputs the mutated byte sequence. FuzzCoder is fine-tuned on our created instruction dataset (FuzzInstruct), where the successful fuzzing history is collected from the heuristic fuzzing tool. FuzzCoder can predict mutation positions and strategies for input files to trigger abnormal behaviors of the program. Most importantly, the experiment reveals results that FuzzCoder achieves better fuzzing performance compared to traditional and other AFL-based fuzzers, such as AFL, AFL++, AFLSmart, etc. On average, FuzzCoder achieves an improvement in code coverage of more than 20%, along with a significant increase in the number of crashes. 1
Liqun Yang, Chaoren Wei, Jian Yang 0030, Wanxu Xia, Yuze Yang, Dusit Niyato, Liang Sun 0007, Zhiquan Liu 0001
IEEE Internet Things J.9
2025 Efficient and Verifiable Bilateral Fine-Grained Access Control for Cloud-Edge IoT Healthcare
abstract
The integration of cloud-edge computing with Internet of Things (IoT) healthcare greatly improves medical service efficiency and reduces home monitoring costs. However, in an untrusted and open environment, it still faces significant privacy and security challenges, especially in terms of confidentiality and authenticity of medical data, as well as bilateral access control between patients and healthcare providers. At present, there are few solutions capable of addressing the aforementioned issues efficiently, as they typically come with significant communication and computational overhead. This poses a substantial challenge for IoT devices that are usually resource-constrained. To address the above issues, this paper proposes an efficient and verifiable fine-grained bilateral access control scheme for cloud-edge IoT healthcare. The scheme adopts flexible attribute-based threshold bilateral access control to provide data confidentiality and authenticity at the same time. In addition, our scheme achieves constant-size ciphertexts, utilizes offline/online technology to accelerate ciphertext generation, and outsources the data authenticity verification and partial decryption process to edge nodes, thereby improving the communication and computational efficiency. Furthermore, our scheme implements verification of outsourced results to resist attacks from malicious edge nodes. The formal security proof and experimental evaluation show that our scheme is more functional and practical than other bilateral access control schemes for IoT healthcare.
Mengting Yao, Jian Weng 0001, Jia-Nan Liu, Hongkai Liu, Jia-Si Weng 0001, Zhiquan Liu 0001
IEEE Internet Things J.7
2025 EFSC: Efficient and Forward-Secure Conditional Privacy-Preserving Scheme for Internet of Vehicles
abstract
The interconnected environment of the Internet of Vehicles (IoV) facilitates the development of various low-carbon and secure location-based services. However, sharing data with semi-trusted service providers poses serious security risks. In particular, it can threaten the confidentiality of past messages after the leakage of the user’s key. In this article, we propose an efficient and forward-secure conditional privacy-preserving scheme for IoV, namely, EFSC. We construct a cryptographic method with forward secrecy in the proposed EFSC scheme, which ensures the confidentiality of past messages even after the user’s secret key has been compromised. This method incorporates key derivation functionality and efficiently addresses the complex certificate management issue with the assistance of smart contracts. Additionally, the designed smart contract facilitates authentication. We analyze and prove that the proposed EFSC scheme satisfies the proposed privacy and security requirements with better security performance. We use Goerli, an Ethernet test network, to deploy customized smart contracts to prove its feasibility. Furthermore, the proposed EFSC scheme exhibits high-index generation and pairing efficiency and realizes less computational and communication overhead. Compared with the existing schemes, its computational overhead in message signing, signature verification, and user revocation can be reduced by up to 95.61%, 36.53%, and 67.01%, respectively. Moreover, the communication overhead for initiating a location service query is only 0.3760 kB. These results show that the proposed EFSC scheme has certain advantages regarding efficiency and security.
Zhikang Zeng, Chunming Tang 0003, Quan Zhou 0009, Zhiquan Liu 0001, Debiao He
IEEE Internet Things J.4
2025 Hybrid Transfer and Self-Supervised Learning Approaches in Neural Networks for Intelligent Vehicle Intrusion Detection and Analysis
abstract
Intrusion detection is crucial for safeguarding intelligent vehicle systems, aiming to identify abnormal network traffic and operational anomalies. Traditional methods primarily focus on spatial features of attacks, often neglecting temporal dynamics essential for detecting complex, evolving threats. Additionally, the effectiveness of existing techniques is limited by the scope and quality of available datasets, reducing their ability to detect novel, unseen attacks. To address these challenges, this article introduces a Transformer-based transfer learning intrusion detection system (TIDS), designed to capture and analyze spatiotemporal sequence features from vehicle data. TIDS generates high-dimensional feature representations of intricate intrusion patterns, improving the detection of known attack types through instance-based transfer learning, enhancing domain adaptability. Moreover, we proposed a novel self-supervised box classification method that enhances the system’s capability to detect previously unknown attacks, thereby increasing the overall robustness of the intrusion detection process. Comparative experiments demonstrate that TIDS outperforms traditional methods in detection speed and accuracy across various intrusion scenarios, effectively responding to emerging threats in intelligent vehicle networks.
Tian Zhang 0019, Cuifeng Du, Yuyu Zhou, Quanlong Guan, Zhiquan Liu 0001, Xiujie Huang, Zhiguo Gong
IEEE Internet Things J.5
2025 BPRM: Blockchain-Based Privacy Preserving and Robust Data Aggregation Supporting Multifunctionality for Fog-Assisted Smart Grid
abstract
While the collection of users’ live or periodic electricity consumption data brings significant advantages for the operation of smart grids, it also heightens the risk of user privacy leakage. Numerous data aggregation schemes have been proposed to address this issue. However, most of these schemes either fail to accommodate the need for multifunctional data analysis or rely on a trusted third party (TTP). Given the efficient data processing capabilities offered by fog computing, we propose a blockchain-based privacy-preserving data aggregation (BPRM) scheme supporting multifunctionality for fog-assisted smart grid without TTP. This scheme ensures data confidentiality and data integrity while providing various statistical functions. In addition, we implement a consensus mechanism between smart meters, further enhancing the security and robustness of the smart grid system. Moreover, not only does the proposed the batch verification reduce the authentication costs but also support error detection in signatures. With BPRM, data center can calculate multiple statistical functions, achieving a win-win strategy. Extensive security and performance analyses demonstrate that BPRM can withstand various security threats and effectively protect user privacy while maintaining efficiency in both computational and communication overhead.
Chuankun Zhao, Liangliang Wang 0001, Zhiquan Liu 0001, Kai Zhang 0016, Weiwei Li 0007, Kefei Chen
IEEE Internet Things J.3
2025 Optimal Secure NOMA Clustering and Power Allocation in Distributed Satellite-Enabled Internet of Things
abstract
The satellite-enabled Internet of Things (S-IoT) plays a crucial role by providing stable and global connectivity. However, its rapid growth brings many challenges in managing massive devices and addressing security threats. In this paper, we propose a new distributed network architecture combined with non-orthogonal multiple access (NOMA) for S-IoT. We consider a secure NOMA transmission scenario, where an appropriate legitimate device in an NOMA cluster is chosen as a jammer. To maximize the system’s total secrecy rate, we formulate an optimal secure NOMA clustering and power allocation, which is non-convex and difficult to solve directly. To solve the joint optimization problem, the original problem is transformed into two subproblems, and we propose staged algorithms to solve them efficiently. Firstly, a distributed iterative NOMA clustering algorithm is proposed to iteratively group S-IoT devices into multiple NOMA clusters. Then, a particle swarm optimization (PSO)-based optimal secure power allocation (OSPA) algorithm and a soft actor critic (SAC)-based OSPA are proposed to allocate powers for intra-cluster devices. The PSO/SAC-based OSPA algorithm can be performed among different NOMA clusters in a parallel way, which greatly improves the efficiency of power allocation. Finally, an optimal dynamic jammer strategy is proposed to dynamically select an idle device to act as a jammer, greatly improving the security performance of the systems. The simulation results demonstrate the advantages of the proposed distributed algorithms and also show that the proposed scheme greatly outperforms the state-of-the-art schemes in terms of the secrecy rate.
Bo Zhao 0022, Ruotong Zhang, Zhiquan Liu 0001, Siyang Sun, Guangliang Ren, Haolin Zhu
IEEE Internet Things J.3
2025 Privacy-Preserving IoT Data Retrieval Scheme With Lightweight Fine-Grained Access Control in Cloud Computing
abstract
With the rapid development of cloud computing technology, cloud services, represented by cloud storage and data retrieval, have been widely researched in Internet of Things (IoT). As a result, various data retrieval schemes have been proposed. The multikeyword Ranked Searchable Encryption Scheme (MRSE) was developed to improve the accuracy and experience of users searching data. However, MRSE has its drawbacks, such as the security risk of key leakage and limited functionality. Therefore, this article proposes a Privacy-preserving IoT Data Retrieval Scheme (PDRS) that supports lightweight fine-grained access control. We analyze the risk of key information leakage in MRSE, and perform permutation operations on encrypted indexes and trapdoors in PDRS to prevent key leakage and improve system security. Furthermore, in IoT scenarios with multiusers and multikeys, the secure user identity authentication mechanism ensures that only authorized users can acquire legitimate keys to generate search trapdoors, preventing malicious users from impersonating legitimate users and accessing private data. A novel polynomial-based access control is designed to realize attribute-based fine-grained access control, which enables resource-limited devices to limit data access to data users and achieves lightweight overhead. Finally, a formal theoretical analysis demonstrates that PDRS is secure. Simulation experiments verify that PDRS is efficient and lightweight.
Wen Zhou 0021, Na Wang 0003, Zhiquan Liu 0001, Junsong Fu 0001, Lunzhi Deng, Qianhong Wu
IEEE Internet Things J.3
2025 Computation bits maximization in multi-UAV-assisted-multi-vehicle edge computing system
Linbo Zhai, Meiyu Jin, Jiande Sun 0001, Chuanfen Feng, Zhiquan Liu 0001, Linfeng Wei, Xiaochuan Li 0001, Youlei Zhang, Jie Liu 0040
J. Netw. Comput. Appl.6
2025 Enhancing cross-city spatio-temporal prediction via dynamic multi-scale hypergraph learning with domain adversarial training
Xiaocao Ouyang, Xin Yang 0012, Yan Yang 0001, Junbo Zhang 0004, Wei Huang 0037, Tianrui Li 0001, Zhiquan Liu 0001
Knowl. Based Syst.9
2025 A security enhanced certificateless aggregate signcryption scheme for VANETs
Dong Li 0016, Liangliang Wang 0001, Yang Liu 0291, Zhiquan Liu 0001, Kai Zhang 0008, Weiwei Li 0007
Peer Peer Netw. Appl.5
2025 Image analysis by fractional-order weighted spherical Bessel-Fourier moments
Zhiquan Liu 0001
Pattern Recognit.2
2025 Bidirectional Identity-Based Inner-Product Functional Re-Encryption in Vaccine Data Sharing
abstract
With the development of cloud computing, more and more data is stored in cloud servers, which leads to an increasing degree of privacy of data stored in cloud servers. For example, in the critical domain of medical vaccine trials, where public health outcomes hinge on the analysis of sensitive patient data, the imperative to safeguard privacy has never been more pronounced. Traditional encryption methods, though effective at protecting data, often expose vulnerabilities during decryption and lack the ability to support granular data access and computation. One-way re-encryption schemes further impede the agility of data sharing, which is indispensable for the collaborative efforts of research institutions. To address these limitations, we propose a novel bidirectional re-encryption scheme for inner-product functional encryption (IPFE). Our scheme secures data while allowing computation and sharing in an encrypted state, preserving patient privacy without hindering research. By harnessing inner-product functional encryption, our approach allows authorized researchers to extract valuable insights from encrypted data, significantly enhancing privacy protections. Our scheme’s security is predicated on the$l$-ABDHE (augmented bilinear Diffie-Hellman exponent) assumption, ensuring robustness against chosen plaintext attacks within the standard model. This foundation not only secures the data but also yields compact ciphertext length, minimizing storage demands. We introduce a protocol specifically designed for medical vaccine trials, which leverages our bidirectional IB-IPFRE (Identity-Based Inner-Product Functional Re-Encryption) scheme. This protocol enhances data security, supports collaborative research, and maintains patient privacy. Its application in vaccine trials demonstrates the scheme’s effectiveness in protecting sensitive information while enabling critical research insights.
Yanwei Zhou, Yasi Zhu, Zhiquan Liu 0001, Bo Yang 0003, Mingwu Zhang
IEEE Trans. Cloud Comput.4
2025 Privacy-Preserving Multi-Key Image Retrieval in Cloud Environment
abstract
The rapid development of cloud computing has created more favorable conditions for the practical application of privacy-preserving image retrieval technology. However, most existing schemes fail to fully leverage the potential of cloud computing and still face several challenges, primarily in terms of low retrieval precision, weak security, and reliance on the single-key mechanism. To this end, we propose a privacy-preserving multi key image retrieval in cloud environment, named PPMKIR. First, PPMKIR utilizes a convolutional neural network EfficientNetB7 to extract image feature vectors and employs the mini-batch K Means algorithm for feature clustering. Then, PPMKIR encrypts the obtained clusters using the threshold Paillier cryptosystem and constructs a novel index forest based on the encrypted clusters to aggregate data from different sources. Additionally, PPMKIR introduces a tailored search algorithm for the index forest, significantly accelerating the image retrieval process. Comprehensive security analysis demonstrates that PPMKIR not only protects the privacy of outsourced data and queries but also ensures strong security at all stages of the system. Extensive experiments on real-world image datasets validate that PPMKIR achieves outstanding retrieval precision and efficiency.
Zhiquan Liu 0001, Yinbin Miao, Baodong Qin
IEEE Trans. Cloud Comput.3
2025 FastFace: Fast-Converging Scheduler for Large-Scale Face Recognition Training With One GPU
abstract
Computing power has evolved into a foundational and indispensable resource in the area of deep learning, particularly in tasks such as Face Recognition (FR) model training on large-scale datasets, where multiple GPUs are often a necessity. Recognizing this challenge, some FR methods have started exploring ways to compress the fully-connected layer in FR models. Unlike other approaches, our observations reveal that without prompt scheduling of the learning rate (LR) during FR model training, the loss curve tends to exhibit numerous stationary subsequences. To address this issue, we introduce a novel LR scheduler leveraging Exponential Moving Average (EMA) and Haar Convolutional Kernel (HCK) to eliminate stationary subsequences, resulting in a significant reduction in converging time. However, the proposed scheduler incurs a considerable computational overhead due to its time complexity. To overcome this limitation, we propose FastFace, a fast-converging scheduler with negligible time complexity, i.e.O(1) per iteration, during training. In practice, FastFace is able to accelerate FR model training to a quarter of its original time without sacrificing more than 1% accuracy, making large-scale FR training feasible even with just one single GPU in terms of both time and space complexity. Extensive experiments validate the efficiency and effectiveness of FastFace. The code is publicly available at: https://github.com/amoonfana/FastFace.
Xueyuan Gong, Zhiquan Liu 0001, Yain-Whar Si, Xiaochen Yuan, Ke Wang 0068, Xiaoxiang Liu
IEEE Trans. Circuits Syst. Video Technol.2
2025 PPDR: A Privacy-Preserving Dual Reputation Management Scheme in Vehicle Platoon
abstract
Vehicle platoon has attracted much attention in recent years for its benefits in improving traffic efficiency, road safety, and energy consumption. In a vehicle platoon, vehicles can take on the roles of either a leading vehicle or a following vehicle, depending on the need. Selecting a reliable leading vehicle is crucial to improve the reliability of the vehicle platoon, and reputation management plays a vital role in this selection process. However, the existing reputation management schemes do not distinguish the leading vehicle's reputation value (LV-Reputation value) and the following vehicle's reputation value (FV-Reputation value), and merge them into a single reputation value, which exposes the reputation management scheme to the single reputation attack, an attack identified for the first time in this work. Additionally, some schemes fail to preserve the vehicle reputation value privacy, feedback score privacy, or identity privacy, and some overlook the security of the reputation management scheme. To address these issues, we propose a Privacy-Preserving Dual Reputation (PPDR) management scheme in vehicle platoon. The PPDR scheme separates a vehicle's reputation value into LV-Reputation value and FV-Reputation value, effectively mitigating the single reputation attack. Furthermore, under the premise of preserving reputation value privacy, feedback score privacy, and identity privacy, the PPDR scheme employs a score difference calculation algorithm to support the weighted average mechanism and the dual reputation management mechanism, which can significantly improve the accuracy of reputation management scheme. It also provides strong security with acceptable computation communication overheads. Comprehensive theoretical analysis and simulation evaluation have been carried out, and the results demonstrate that the PPDR scheme is significantly superior than the existing schemes in several aspects.
Zhiquan Liu 0001, Yingjie Xia, Zhen Guo 0003, Gao Liu, Leping Li, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.2
2025 SDB: Scalable Blockchain Database via Searchable Encryption and Cross-Shard Mechanism
abstract
Blockchain database has been widely applied in various fields, providing a secure architecture for data storage and sharing. In blockchain databases, the use of sharding technology can enhance the system’s scalability and improve transactions in the network to be processed in parallel. However, when applying searchable encryption techniques to query encrypted data in sharding blockchains, frequent data access to different shards results in uneven load distribution, leading to hotspot issues and reducing system efficiency. To tackle the challenge, we presentSDB, a scheme integrating searchable encryption with sharding technology to enhance the scalability of blockchain databases. Firstly, we introduce a two-stage sharding mechanism. It performs pre-sharding based on keywords, and then implements fine-grained dynamic adjustments through improved jump consistent hashing, effectively resolving the load imbalance problem. Secondly, we present a cross-shard query strategy based on encrypted indexes, which constructs verifiable indexes for encrypted data and converts user queries into a multiway query tree. This addresses the cross-shard query optimization problem in encrypted environments. Under the experiment and security analysis,SDBachieves efficient cross-shard queries with higher query performance and throughput, at least 30% and 20% higher than state-of-the-art scalable blockchain database schemes.
Kaiye Li, Xia Feng, Pujie Jing, Zhiquan Liu 0001
IEEE Trans. Inf. Forensics Secur.5
2025 Penetrating the Hostile: Detecting DeFi Protocol Exploits Through Cross-Contract Analysis
abstract
Decentralized finance (DeFi) protocols are crypto projects developed on the blockchain to manage digital assets. Attacks on DeFi have been frequent and have resulted in losses exceeding $80 billion. Current tools detect and locate possible vulnerabilities in contracts by analyzing the state changes that may occur during malicious events. However, this victim-only approaches seldom possess the capability to cover the attacker’s interaction intention logic. Furthermore, only a minuscule percentage of DeFi protocols experience attacks in real-world scenarios, which poses a significant challenge for these detection tools to demonstrate practical effectiveness. In this paper, we propose DeFiTail, thefirstframework that utilizes deep learning technology for access control and flash loan exploit detection. Through feeding the cross-contract static data flow, DeFiTail automatically learns the attack logic in real-world malicious events that occur on DeFi protocols, capturing the threat patterns between attacker and victim contracts. Since the DeFi protocol events involve interactions with multi-account transactions, the execution path with external and internal transactions requires to be unified. Moreover, to mitigate the impact of mistakes in Control Flow Graph (CFG) connections, DeFiTail validates the data path by employing the symbolic execution stack. Furthermore, we feed the data paths through our model to achieve the inspection of DeFi protocols. Comparative experiment results indicate that DeFiTail achieves the highest accuracy, with 98.39% in access control and 97.43% in flash loan exploits. DeFiTail also demonstrates an enhanced capability to detect malicious contracts, identifying 86.67% accuracy from the CVE dataset. By monitoring existing contracts, we identified five distinct categories of vulnerabilities: repetition abuse, unsafe unintended exploitation, signature violated exploitation, insecure interfaces exploitation, and unrestricted token transfer.
Xiaoqi Li 0001, Zhiquan Liu 0001, Yuqing Zhang 0001, Yingjie Mao
IEEE Trans. Inf. Forensics Secur.3
2025 Trace Your Footprint: Efficient Spatial Keyword Query Over Encrypted Trajectory Data
abstract
With the popularity of mobile devices, spatial-textual trajectory query has been deployed in applications such as trajectory-based navigation and travel route recommendation. Massive trajectory data have been outsourced to cloud servers for storage and sharing such as spatial keyword search. However, existing solutions only support similarity queries in the spatial dimension and still incur high storage and query costs, which cannot scale well in large-scale trajectory data scenarios. To solve the above issues, we first achieve an Efficient Range Query over Encrypted Trajectory Data (ERT) using Douglas-Peucker trajectory compression algorithm, random matrix multiplication, filtering-verification mechanism and polynomial fitting technology. Then, we further propose an enhanced Efficient Spatial Keyword Query over Encrypted Trajectory Data (ESKT) by constructing a unified spatial-textual index structure, which can find relevant trajectories that are within some arbitrary geometric range and contain all query keywords. Finally, we formally prove that our schemes are secure against chosen-plaintext-attack, and conduct extensive experiments to demonstrate that our schemes improve the query efficiency by almost 100× when compared with state-of-the-art solutions.
Yinbin Miao, Xin Wang 0037, Xinghua Li 0001, Shujiang Xu, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.6
2025 ROBY: A Byzantine-Robust and Privacy-Preserving Serverless Federated Learning Framework
abstract
Federated Learning (FL) allows multiple data owners to jointly train machine learning models by sharing local models instead of raw private data, alleviating data privacy concerns. However, as the local computation of data owners is unpredictable, it increases its vulnerability to Byzantine attacks, where compromised data owners submit abnormal local models that can severely degrade global model accuracy. Existing Byzantine-robust FL methods depend on a semi-honest server executing predefined Byzantine-robust aggregation rules (ByRules) to filter out abnormal local models, but these methods fail when the server is compromised. Although recent serverless Byzantine-robust FL approaches mitigate the risk of a compromised server, they suffer from challenges in achieving consensus on ByRules and impose a heavy burden on privacy protection. In this paper, we propose ROBY, a novel serverless FL framework that extends existing ByRules to a decentralized setting, effectively defending against Byzantine attacks and ensuring privacy protection for local models. ROBY introduces a shared, dynamically updated consensus dataset that serves as a reliable benchmark for applying ByRules and enabling efficient consensus on ByRules among decentralized data owners. Moreover, we design a dual-layer privacy shielding strategy in ROBY to protect local model privacy without sacrificing global model accuracy or incurring extra computational and communication overhead. Extensive evaluations demonstrate that ROBY substantially enhances both Byzantine robustness and privacy protection compared to server-based FL methods.
Xiangyun Tang, Minyang Li, Meng Shen 0001, Jiawen Kang 0001, Liehuang Zhu, Zhiquan Liu 0001, Guomin Yang, Dusit Niyato, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.6
2025 PBRU: Privacy-Preserving and Blockchain-Assisted Reputation Updating With Malicious Detection for Cloud-Supported Vehicular Networks
abstract
Reputation updating plays a vital role in cloud-supported vehicular networks, ensuring the continuous freshness of trustworthiness. However, the existing solutions suffer from insufficient privacy and security, as well as impose significant computation and communication overheads on resource-constrained vehicles. In addition, they require vehicles to pre-load numerous keys and reputation certificates, complicating certificate management along with key escrow and revocation issues. Thus, in this paper, we introduce an innovative Privacy-preserving and Blockchain-assisted Reputation Updating (PBRU) scheme with malicious detection, for cloud-supported vehicular networks. Specifically, based on the improved exponential ElGamal variant, the reputation feedback generation and verification process avoids time-consuming homomorphic exponential and bilinear pairing operations, such that computation and communication overheads of vehicles are significantly reduced by 87.42% and 43.32%, respectively. Besides, the PBRU scheme reconstructs the key derivation algorithm and records reputation certificates on the blockchain, eliminating the need for pre-loading keys and certificates on vehicles while enabling traceability. Moreover, the PBRU scheme is capable of detecting duplicate malicious feedbacks by utilizing Bloom filter. Furthermore, theoretical proof and analysis present that the PBRU scheme satisfies more security requirements than the state-of-the-art schemes. Finally, the comprehensive simulation evaluation demonstrates the effectivity and practicality of our PBRU scheme.
Yue Cao 0002, Changbing Bi, Zhiquan Liu 0001, Jianfeng Ma 0001, Yi Ren 0001
IEEE Trans. Inf. Forensics Secur.4
2025 Enhanced Model Poisoning Attack and Multi-Strategy Defense in Federated Learning
abstract
As a new paradigm of distributed learning, Federated Learning (FL) has been applied in industrial fields, such as intelligent retail, finance and autonomous driving. However, several schemes that aim to attack robust aggregation rules and reducing the model accuracy have been proposed recently. These schemes do not maintain the sign statistics of gradients unchanged during attacks. Therefore, the sign statistics-based scheme SignGuard can resist most existing attacks. To defeat SignGuard and most existing cosine or distance-based aggregation schemes, we propose an enhanced model poisoning attack, ScaleSign. Specifically, ScaleSign uses a scaling attack and a sign modification component to obtain malicious gradients with higher cosine similarity and modify the sign statistics of malicious gradients, respectively. In addition, these two components have the least impact on the magnitudes of gradients. Then, we propose MSGuard, a Multi-Strategy Byzantine-robust scheme based on cosine mechanisms, symbol statistics, and spectral methods. Formal analysis proves that malicious gradients generated by ScaleSign have a closer cosine similarity than honest gradients. Extensive experiments demonstrate that ScaleSign can attack most of the existing Byzantine-robust rules, especially achieving a success rate of up to 98.23% for attacks on SignGuard. MSGuard can defend against most existing attacks including ScaleSign. Specifically, in the face of ScaleSign attack, the accuracy of MSGuard improves by up to 41.78% compared to SignGuard.
Li Yang 0005, Yinbin Miao, Zhiquan Liu 0001, Xinghua Li 0001, Da Kuang, Hongwei Li 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.4
2025 Personalized Federated Learning for Green Industrial IoT
abstract
In recent years, federated learning (FL) has gained increasing attention in industrial Internet-of-Things (IIoT) domains due to its privacy-preserving advantages. However, prior works commonly adopt a one-size-fits-all strategy for FL computation resource management and reward allocation, disregarding the time-varying participant states across different FL training rounds. Consequently, these methods fail to ensure the sustainability and active participation of IIoT devices in realistic FL deployments. To bridge this gap, we propose a personalized FL methodology for green IIoT systems powered by renewable energy sources. We first establish an incentive model along with its preference parameter-solving scheme to accurately characterize the incentive preferences of individual FL participants. Subsequently, a personalized participant scheduling approach is developed to accommodate dynamic resource usage patterns and diverse incentive preferences among FL participants. Our technique integrates empirical insights into conventional proximal policy optimization methods to accelerate policy learning within reinforcement learning frameworks. Experimental results on an FL prototype system show that our methodology improves the FL model accuracy by 25.92% compared with representative baseline algorithms.
Kun Cao 0001, Yangguang Cui, Rui Xu 0013, Yuxia Sun, Zhiquan Liu 0001, Chaohong Tan
IEEE Trans. Ind. Informatics5
2025 Large-Scale Cross-Modal Ranked Search in Secure Intelligent Computing
abstract
With the development of intelligent industrial computing, cross-modal search technology has become crucial in fields, such as the Internet of things and industrial networks. Existing solutions, while supporting cross-modal retrieval and ensuring data privacy, suffer from high training complexity, low search efficiency, and vulnerability to attacks. To tackle these issues, this article presents a large-scale cross-modal search scheme designed for fast, efficient, and secure ranked retrieval. Specifically, we use collective matrix factorization to train heterogeneous data features and obtain unified feature vectors, simplifying the training process. Second, we design a label classification algorithm that employs homomorphic encryption and locality sensitive hash to improve search efficiency. In addition, we improve a secure method utilizing the$k$-nearest neighbor algorithm to compute Euclidean distances, which effectively identifies results closest to the query data and resists linear analysis attacks. Both theoretical analysis and experimental results show that our proposed scheme not only protects the privacy of cross-modal data, but also offers high efficiency and practicality.
Zhiquan Liu 0001, Yanman Li, Xixian Wang
IEEE Trans. Ind. Informatics2
2025 Trust Model-Based Consensus Optimization for Vehicle Platooning Networks: A Novel Deep Reinforcement Learning Approach With GenAI
abstract
Vehicle platooning has emerged as a promising solution for efficient traffic management. Multiple platoons traveling in a cooperative way can alleviate congestion and enhance driving safety by information sharing and consensus. To address the data security and privacy concerns, blockchain could be applied to enable secure data sharing and consensus across multiple platoons. However, existing performance of blockchain is insufficient to ensure reliable and efficient data consensus among multiple platoons. First, the hierarchical structure of platoons with different roles of vehicles complicates the trust establishment between platoons, making it challenging to evaluate their trustworthiness and ensure consensus reliability. Additionally, data sharing in vehicle platooning networks demands timely information and efficient consensus-building. To tackle above challenges, we design a role-adaptive trust model for trust evaluation of platoons in consideration of different roles of vehicles within a platoon. Based on the proposed model, we formulate a blockchain consensus optimization problem to facilitate both reliability and efficiency of data consensus among multiple platoons. Leveraging Generative Artificial Intelligence (GenAI) techniques, we then propose the Diffusion Enhanced Soft Actor-Critic (DESAC) by integrating the diffusion model and SAC, to further improve the performance of blockchain consensus. Experiment results demonstrate the effectiveness and efficiency of the proposed consensus optimization approach.
Xiaoyuan Fu, Quan Yuan 0004, Zirui Zhuang, Jiawen Kang 0001, Zhiquan Liu 0001, Jingyu Wang 0001, Dusit Niyato
IEEE Trans. Intell. Transp. Syst.6
2025 Task Offloading Based on the Fusion of Model- and Data-Driven Intelligence for Vehicular Edge Computing Networks
abstract
Vehicular edge computing (VEC) is an efficient solution to alleviate the limitations of local computing resources in vehicular networks. However, the high mobility of vehicles and the dynamic variability of network topologies make it significantly challengeable. In this work, we make a fusion of model-driven and data-driven intelligence to design a multi-agent deep reinforcement learning (DRL) solution for task offloading in urban VEC networks. First, computational models for task queue, transmission, computation, energy consumption, and expense are meticulously developed for the VEC network that integrates communication and computation. Vehicular tasks vary in type, urgency, size, and timeframe, leading to different latency requirements. Tasks may be executed locally within the vehicle, at a server after V2I offloading via cellular communications, or in a neighboring vehicle after V2V offloading via millimeter-wave (mmWave) communications. Each of these options incurs different levels of latency, energy consumption, and expense. Second, based on these models and the utility function that combines latency, energy consumption, and expense, an optimization problem for task offloading is formulated. This problem can be interpreted as a Markov decision process with a carefully designed reward function. Third, to address the offloading problem, we propose a multi-agent proximal policy optimization-based task and target selection algorithm (MAPPO-TTSA). This algorithm also utilizes convolutional neural networks to extract features from large-scale states, thereby enhancing their correlation. Fourth, comprehensive training is performed on the observational data to determine the optimal parameters for predicting task offloading. Finally, extensive experiments are conducted, and simulation results are provided to demonstrate that the proposed intelligent task offloading scheme offers significant advantages in terms of average task completion delay and utility level across various scenarios.
Xiujie Huang, Zhiquan Liu 0001, Shancheng Zhao, Zhetao Li, Renzhang Chen, Quanlong Guan
IEEE Trans. Intell. Transp. Syst.3
2025 LWAKA: Lightweight Anonymous Authenticated Key Agreement for VANETs
abstract
Authenticated key agreement (AKA) between vehicles and road side units (RSUs) is crucial in vehicular ad-hoc networks (VANETs). However, existing solutions still suffer from high overheads of AKA and lack a mechanism to balance privacy strength and system efficiency. In this paper, we present a lightweight anonymous authenticated key agreement (LWAKA) scheme for VANETs, supporting lightweight anonymous authentication and key agreement between vehicles and RSUs simultaneously. In particular, vehicles’ authentication information is synchronized to target RSUs in advance for accelerating authentication, and lightweight cryptographic operations (i.e., hash function, hash-based message authentication, physical unclonable function, fuzzy extractor and symmetric encryption) are employed to ensure the high efficiency of AKA in terms of computation and communication overheads. The system efficiency and privacy are balanced through modeling the relationship between the frequency of pseudonym updates and the unlinkability of the vehicles’ new and old pseudonyms. Security analysis shows that LWAKA not only achieves anonymity, conditional privacy, pseudonym unlinkability, key escrow freeness, and physical security, but also resists against most known attacks. Comparative experimental results demonstrate that LWAKA outperforms existing schemes in terms of lightweight design.
Gao Liu, Hao Li 0103, Junqing Le, Ning Wang 0003, Nankun Mu, Zhiquan Liu 0001, Yi-Ning Liu 0002, Tao Xiang 0001
IEEE Trans. Intell. Transp. Syst.6
2025 An Efficient and Multi-Dimensional Privacy-Preserving Platoon Communication Scheme in Vehicular Networks
abstract
Vehicular platoon, a cutting-edge technology in the realm of intelligent transportation systems, holds the promise of transforming vehicle operations on roadways. By fostering seamless communication among vehicles and leveraging advanced automation, vehicular platoon enables vehicles to travel closely together, thereby reducing aerodynamic drag, optimizing fuel consumption, and improving road safety. However, due to their open and highly dynamic characteristics, the existing platoon communication schemes face efficiency and privacy challenges. These challenges stem from a substantial overhead on the Trusted Authority (TA) and vehicle sides during platoon communication, and a lack of multi-dimensional privacy preservation (e.g., identity privacy, location privacy, attribute privacy, and reputation value privacy) for platoon vehicles. To overcome these challenges, in this paper, we propose an efficient and multi-dimensional privacy-preserving platoon communication (EMPPC) scheme. Specifically, platoon formation is cloud-assisted and relies on the location, attribute, and reputation value of vehicles. We introduce a secure reputation value ciphertext comparison (SRCC) protocol during platoon leader selection, and present an attribute verification and matching (AVM) algorithm during platoon followers matching. Theoretical analysis and simulation evaluation demonstrate that the EMPPC scheme can offer multi-dimensional privacy preservation, and it is secure and efficient for platoon communication.
Nuo Xu 0007, Zhiquan Liu 0001, Xuming Han, Quanlong Guan, Xiujie Huang, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.2
2025 A Redactable Blockchain-Based Anonymous Announcement Scheme for VANETs
abstract
Blockchain serves as a trust layer for data exchange in Vehicular Ad-hoc Networks (VANETs) due to its immutability and transparency. However, it can also be abused to spread false and inaccurate information. Additionally, the explosive growth of data in VANETs and the limited storage capacity of edge nodes make it challenging to maintain the entire blockchain. To address these challenges, we propose an anonymous vehicle announcement scheme based on redactable blockchain. Specifically, we propose a novel ephemeral trapdoor revocable chameleon hash scheme (ETRCH) that enables decentralized management and enforced revocation of redaction privileges. ETRCH deploys multiple regulators, each capable of creating multiple ephemeral trapdoors. These regulators enable${\boldsymbol}{k}$-out-of-${\boldsymbol}{n}$edge nodes associated with the same ephemeral trapdoor to collaboratively rewrite blockchain data, thereby addressing storage limitations. In addition,${\boldsymbol}{k}$-out-of-${\boldsymbol}{n}$regulators can cooperate to update the ephemeral trapdoor and revoke the redaction privileges of any malicious regulator discovered to be abusing their privileges. To facilitate the threshold authentication of announcement messages, we construct a redactable threshold ring signature scheme (RTRS) based on ETRCH, enabling anonymous signing of announcements in VANETs. Additionally, if a regulator detects a false or misleading message, the content can be promptly rewritten. Finally, we conducted rigorous security analysis and comprehensive experiments to evaluate the performance of the proposed scheme. The results demonstrate that compared to VANETs systems based on immutable blockchains, our scheme is both secure and efficient.
Yuxiang Yang 0006, Yuling Chen 0002, Zhiquan Liu 0001, Yan Meng 0001, Haiwei Sang
IEEE Trans. Intell. Transp. Syst.3
2025 LCEFL: A Lightweight Contribution Evaluation Approach for Federated Learning
abstract
The prerequisite for implementing incentive mechanisms and reliable participant selection schemes in federated learning is to obtain the contribution of each participant. Available evaluation methods for participant contributions require the server to possess a test dataset, often impractical. Additionally, the excessively high complexity of these works is unacceptable when training complex models in large-scale federated learning system. To address these issues, we propose a lightweight contribution evaluation method for federated learning participants, named LCEFL, based on model projection theory, which does not require the server to provide a test dataset. In addition, a model compression method is designed to be used in LCEFL to reduce the computational complexity. Furthermore, a trusted aggregation method based on LCEFL is proposed, where the weight of each participant's local model is determined by its trust level, which can be calculated using its contribution evaluation result. Experimental results show that LCEFL can achieve nearly the same accuracy as schemes based on Shapley Value, while significantly reducing computational overhead by more than 50%. Compared to available aggregation methods, the proposed trusted aggregation scheme is able to accelerate the convergence speed of the global model and improve its accuracy by 2% to 45%.
Jiaxing Li 0004, Zhiquan Liu 0001, Yupeng Xiong, Yong Ma 0005, Athanasios V. Vasilakos, Xinghua Li 0001, Jianfeng Ma 0001
IEEE Trans. Mob. Comput.3
2025 Decentralized QoS-Aware Model Inference Using Federated Split Learning for Cloud-Edge Medical Detection
abstract
The application of federated learning (FL) has been widely extended to medical domains, including medical image analysis and health monitoring. With the increasing computation power demand on edge devices, split federated learning has emerged as a promising FL architecture. In this work, a home healthcare monitoring scenario is explored. Unlike existing split federated learning studies that primarily focus on model-level optimization, this study considers a system-level optimization involving latency, packet error rate, and federated training time. Specifically, a k-means algorithm is presented to select inference nodes, participating training clients, and aggregation servers referring to network conditions and data quality. Furthermore, a reinforcement learning method is utilized to allocate the computation and bandwidth resources during inference, training, and aggregation, thereby further improving the quality of service (QoS) and training efficiency. Simulation results demonstrate that the proposed architecture can achieve the target accuracy while offering the enhanced QoS and reduced the FL training time.
Yishan Chen 0001, Xiangwei Zeng, Huashuai Cai, Zhiquan Liu 0001
IEEE Trans. Parallel Distributed Syst.5
2024 LBVP: Lightweight Blockchain-Based Vehicle Platooning Scheme for Secure and Efficient Platoon Management
Zhiquan Liu 0001, Ying He 0006, Xia Feng, Jianfeng Ma 0001
ICA3PP (6)2
2024 An Efficient and Privacy-Preserving Participant Selection Scheme based on Location in Mobile Crowdsensing
abstract
With the increasing demand for sensing data, the selection efficiency of task participants in mobile crowdsensing (MCS) becomes more and more important. How to efficiently choose eligible task participants while preserving privacy is an urgent issue. In this paper, we propose an efficient and privacy-preserving participant selection scheme based on location in MCS, named EPPS. Specifically, the k-anonymity technique is adopted to generate anonymous location matrices to preserve location privacy of sensing tasks and task participants. To improve selection efficiency, the anonymous location matrices of multiple sensing tasks are consolidated into a matrix called merged location matrix. Similarly, the anonymous location matrices of multiple task participants are also merged. Then, the cloud server computes the Hadamard product for merged location matrices to judge whether task participants locate in the corresponding sensing areas. By judging the merged location matrices of sensing tasks and task participants, multiple participants which satisfy the requirements of sensing tasks can be selected at the same time. Finally, the performance evaluations demonstrate that the proposed scheme outperforms the existing schemes in terms of efficiency, to be specific, the computation overhead of EPPS is decreased by 77% - 85%, the communication overhead of EPPS is decreased by 41%, the selection efficiency of the EPPS is increased by 66% when multiple task participants and one sensing tasks, and the selection efficiency of the EPPS is increased by 96% when multiple task participants and multiple sensing tasks.
Yudan Cheng, Tao Feng 0007, Zhiquan Liu 0001, Lulu Han, Jianfeng Ma 0001
TrustCom3
2024 Two-View Image Semantic Cooperative Nonorthogonal Transmission in Distributed Edge Networks
abstract
With the wide application of deep learning (DL) across various fields, deep joint source–channel coding (DeepJSCC) schemes have emerged as a new coding approach for image transmission. Compared with traditional separated source and CC (SSCC) schemes, DeepJSCC is more robust to the channel environment. To address the limited sensing capability of individual devices, distributed cooperative transmission is implemented among edge devices. However, this approach significantly increases communication overhead. In addition, existing distributed DeepJSCC schemes primarily focus on specific tasks, such as classification or data recovery. In this paper, we explore the wireless semantic image collaborative nonorthogonal transmission for distributed edge networks, where edge devices distributed across the network extract features of the same target image from different viewpoints and transmit these features to an edge server. A two‐view distributed cooperative DeepJSCC (two‐view‐DC‐DeepJSCC) with or without information disentanglement scheme is proposed. In particular, the two‐view‐DC‐DeepJSCC with information disentanglement (two‐view‐DC‐DeepJSCC‐D) is proposed for achieving balancing performance between multitasking of image semantic communication; while the two‐view‐DC‐DeepJSCC without information disentanglement only pursues outstanding data recovery performance. Through curriculum learning (CL), the proposed two‐view‐DC‐DeepJSCC‐D effectively captures both common and private information from two‐view data. The edge server uses the received information to accomplish tasks such as image recovery, classification, and clustering. The experimental results demonstrate that our proposed two‐view‐DC‐DeepJSCC‐D scheme is capable of simultaneously performing image recovery, classification, and clustering tasks. In addition, the proposed two‐view‐DC‐DeepJSCC has better recovery performance compared to the existing schemes, while the proposed two‐view‐DC‐DeepJSCC‐D not only maintains a competitive advantage in image recovery but also has a significant improvement in classification and clustering accuracy. However, the proposed two‐view‐DC‐DeepJSCC‐D will sacrifice some image recovery performance to balance multiple tasks. Furthermore, two‐view‐DC‐DeepJSCC‐D exhibits stronger robustness across various signal‐to‐noise ratios.
Wei Wang 0021, Donghong Cai, Zhicheng Dong 0003, Lisu Yu, Yanqing Xu 0003, Zhiquan Liu 0001
Int. J. Intell. Syst.6
2024 Preimage Attacks on Xoodyak and Gaston Based on Algebraic Strategies
abstract
As the Internet of Things (IoT) continues to grow, the urgency to bolster IoT device security escalates, particularly in evaluating the security of lightweight ciphers. Since the inception of Keccak (also known as SHA-3), embedding a permutation within a certain operational mode has become a pivotal approach in designing lightweight cryptography. This led to numerous permutation-based lightweight ciphers tailored for IoT applications. Among them, Xoodyak and Gaston are typical examples and even incorporate Keccak’s nonlinear operation$\chi $within their round functions. This article focuses on assessing the security of Keccak-like lightweight hash functions against preimage attacks. We introduce a generic preimage attack framework from an algebraic perspective and propose a new linearization method that leverages the algebraic properties of$\chi $in the permutation. Additionally, in order to find good guessing strategies, we develop automatic tools based on bit-level mixed-integer linear programming on Xoodyak and Gaston. As a result, the complexity of finding a preimage for 2-round Xoodyak-XOF with a 128-bit digest is$2^{94.66}$while that for 3-round Xoodyak-XOF can be reduced from$2^{125.06}$to$2^{123.91}$and memory consumption from$2^{97}$to a negligible level. This marks the most efficient preimage attack against a 3-round Xoodyak-XOF to date. Furthermore, we present the first preimage attacks on 1-/2-round Gaston with complexities of$2^{90.56}$and$2^{122.15}$, respectively.
Qinggan Fu, Yin Lv, Zhiquan Liu 0001, Yingying Li 0001, Ling Song 0001, Jian Weng 0001
IEEE Internet Things J.3
2024 CCID-CAN: Cross-Chain Intrusion Detection on CAN Bus for Autonomous Vehicles
abstract
Autonomous vehicles (AVs) rely on controller area network (CAN), which ensures the communication between massive electronic control units (ECUs) and passenger safety. Although CAN is a lightweight and reliable broadcast protocol, its vulnerability has caused CAN to confront serious security threats. Adversaries and malicious organizations can impair CAN bus in a variety of ways, such as injecting malicious messages into CAN bus. These malicious messages can directly intervene the functions inside AVs. Therefore, this article proposes a novel cross-chain-based intrusion detection for CAN bus (CCID-CAN) model that uses rule-based Valid Bit index (VBIN) model for initial intrusion detection on CAN bus inside AVs, followed by the Kalman filter and Naïve Bayes model for detecting attacks missed in the VBIN, where a cross-chain mechanism implements the exchange of attack logs among connected AVs that may not trust each other so as to optimize the Naïve Bayes detector. Afterwards, a series of experiments against several types of attacks are conducted on real vehicle supported by XPeng, and the results reveal that the CCID-CAN model outperforms existing models in terms of detection performance, time overhead, and memory footprint. In addition, attack log exchange for cross-chain networks in this proposed model is of high performance in latency, memory footprint, and throughput.
Jian Weng 0001, Zhiquan Liu 0001, Weihua Tan, Zaobo He, Biaobang Wu, Long Li 0005, Xinyuan Peng
IEEE Internet Things J.4
2024 Secure and Traceable Multikey Image Retrieval in Cloud-Assisted Internet of Things
abstract
The privacy-preserving image retrieval technology permits users to retrieve outsourced images in a secure manner in cloud-assisted Internet of Things (IoT) environment. However, most of the existing schemes still have some blemishes, such as low performance, shared key, and untraceable malicious users. To this end, we present a secure and traceable multikey image retrieval, named as secure and traceable multikey image retrieval (STMIR). First, we design a novel privacy-preserving Mahalanobis distance comparison method (PPMDC) based on the learning with errors technology and Mahalanobis distance. And STMIR extracts image features utilizing the convolutional neural network (CNN) model to improve retrieval accuracy. Then, STMIR employs extracted image features, PPMDC and key conversion technology to achieve secure image retrieval that supports the multikey setting. Meanwhile, STMIR uses encrypted image watermarking technology to protect the content of images and track malicious users who redistribute images. Formal security analysis shows that STMIR can resist both ciphertext only attack and known background attack, and extensive experiments in the real-world image data sets demonstrate effectiveness of STMIR in terms of retrieval accuracy, retrieval efficiency, and traceability to malicious query users.
Zhiquan Liu 0001, Gaopan Hou
IEEE Internet Things J.4
2024 Explanatory Object Part Aggregation for Zero-Shot Learning
abstract
Zero-shot learning (ZSL) aims to recognize objects from unseen classes only based on labeled images from seen classes. Most existing ZSL methods focus on optimizing feature spaces or generating visual features of unseen classes, both in conventional ZSL and generalized zero-shot learning (GZSL). However, since the learned feature spaces are suboptimal, there exists many virtual connections where visual features and semantic attributes are not corresponding to each other. To reduce virtual connections, in this paper, we propose to discover comprehensive and fine-grained object parts by building explanatory graphs based on convolutional feature maps, then aggregate object parts to train a part-net to obtain prediction results. Since the aggregated object parts contain comprehensive visual features for activating semantic attributes, the virtual connections can be reduced by a large extent. Since part-net aims to extract local fine-grained visual features, some attributes related to global structures are ignored. To take advantage of both local and global visual features, we design a feature distiller to distill local features into a master-net which aims to extract global features. The experimental results on AWA2, CUB, FLO, and SUN dataset demonstrate that our proposed method obviously outperforms the state-of-the-arts in both conventional ZSL and GZSL tasks.
Xin Chen 0021, Xiaoling Deng, Yubin Lan, Yongbing Long, Jian Weng 0001, Zhiquan Liu 0001, Qi Tian 0001
IEEE Trans. Pattern Anal. Mach. Intell.6
2024 Lightweight and Privacy-Preserving Dual Incentives for Mobile Crowdsensing
abstract
Incentive plays an important role in mobile crowdsensing (MCS), as it impels mobile users to participate in sensing tasks and provide high-quality sensing data. However, considering the privacy (including identity privacy, sensing data privacy, and reputation value privacy) and practicality (including reliability, quality awareness, and efficiency) issues in practice, it is a challenge to design such an effective incentive scheme for MCS applications. Existing studies either fail to provide adequate privacy-preserving capabilities or have low practicality. To address these issues, we propose a scheme called BRRV in MCS which relies on two rounds of range reliability assessment to guarantee the reliability of data while achieving privacy preservation. In addition, we also present a lightweight scheme called LRRV in MCS which relies on a single round of range reliability assessment to guarantee the reliability of data while achieving lightweight and privacy preservation. Moreover, to fairly stimulate participants, constrain participants' malicious behavior, and improve the probability of high-quality data, we design a quality-aware reputation-based reward and penalty strategy to achieve dual incentives (including money incentives and reputation incentives) for participants. Furthermore, comprehensive theoretical analysis and experimental evaluation demonstrate that our proposed schemes are significantly superior to the existing schemes in several aspects.
Zhiquan Liu 0001, Yong Ma 0005, Yudan Cheng, Yongdong Wu, Runchuan Li, Jianfeng Ma 0001
IEEE Trans. Cloud Comput.2
2024 EViT: Privacy-Preserving Image Retrieval via Encrypted Vision Transformer in Cloud Computing
abstract
Image retrieval systems help users to browse and search among extensive images in real time. With the rise of cloud computing, retrieval tasks are usually outsourced to cloud servers. However, the cloud scenario brings a daunting challenge of privacy protection as cloud servers cannot be fully trusted. To this end, image-encryption-based privacy-preserving image retrieval (PPIR) schemes have been developed, which first extract features from cipher-images, and then build retrieval models based on these features. Yet, most existing PPIR approaches extract shallow features and design trivial unsupervised retrieval models, resulting in insufficient expressiveness for the cipher-images. In this paper, we propose a novel paradigm named Encrypted Vision Transformer (EViT), which advances the discriminative representations capability of cipher-images. First, to capture comprehensive ruled information, we extract multi-level local length sequence and global Huffman-Code frequency features from the cipher-images which are encrypted by permutation encryption, sign encryption, and stream cipher during the JPEG compression process. Second, we design the modified self-supervised Vision Transformer with Huffman-embedding and propose two robust data augmentations on cipher-images to improve representation power of the retrieval model. Moreover, our proposal can be easily adapted to unsupervised or supervised settings. Extensive experiments reveal that EViT achieves both excellent encryption and retrieval performance, outperforming current schemes in terms of retrieval accuracy by large margins while protecting image privacy effectively. Code is publicly available at https://github.com/onlinehuazai/EViT.
Qihua Feng, Peiya Li, Zhixun Lu, Chaozhuo Li, Zefan Wang, Zhiquan Liu 0001, Chunhui Duan, Feiran Huang, Jian Weng 0001, Philip S. Yu
IEEE Trans. Circuits Syst. Video Technol.6
2024 Privacy-Preserving and Byzantine-Robust Federated Learning
abstract
Federated learning (FL) trains a model over multiple datasets by collecting the local models rather than raw data, which can help facilitate distributed data analysis in many real-world applications. Since the model parameters can leak information about the training datasets, it is necessary to preserve the privacy of the FL participants’ local models. Furthermore, FL is vulnerable to poisoning attacks which can significantly decrease the model utility. To settle the above issues, we propose a privacy-preserving and Byzantine-robust FL scheme$\Pi _{\text{P2Brofl}}$that maintains robustness in the presence of poisoning attacks and preserves the privacy of local models simultaneously. Specifically,$\Pi _{\text{P2Brofl}}$leverages three-party computation (3 PC) to securely achieve a Byzantine-robust aggregation method. To improve the efficiency of privacy-preserving local model selection and aggregation, we propose a maliciously secure top-$k$protocol$\Pi _{\text{top}-k}$that has low communication overhead. Moreover, we present an efficient maliciously secure shuffling protocol$\Pi _{\text{shuffle}}$since secure shuffling is necessary for our secure top-$k$protocol. The security proof of the scheme is given and experiments on real-world datasets are conducted in this paper. When the proportion of Byzantine participants is 50%, the error rate of the model only increases by 1.05% while it increases by 23.78% without using our protection.
Caiqin Dong, Jian Weng 0001, Ming Li 0049, Jia-Nan Liu, Zhiquan Liu 0001, Yudan Cheng, Shui Yu 0001
IEEE Trans. Dependable Secur. Comput.5
2024 Efficient and Secure Federated Learning Against Backdoor Attacks
abstract
Due to the powerful representation ability and superior performance of Deep Neural Networks (DNN), Federated Learning (FL) based on DNN has attracted much attention from both academic and industrial fields. However, its transmitted plaintext data causes privacy disclosure. FL based on Local Differential Privacy (LDP) solutions can provide privacy protection to a certain extent, but these solutions still cannot achieve adaptive perturbation in DNN model. In addition, this kind of schemes cause high communication overheads due to the curse of dimensionality of DNN, and are naturally vulnerable to backdoor attacks due to the inherent distributed characteristic. To solve these issues, we propose anEfficient andSecureFederatedLearning scheme (ESFL) against backdoor attacks by using adaptive LDP and compressive sensing. Formal security analysis proves that ESFL satisfies$\epsilon$-LDP security. Extensive experiments using three datasets demonstrate that ESFL can solve the problems of traditional LDP-based FL schemes without a loss of model accuracy and efficiently resist the backdoor attacks.
Yinbin Miao, Rongpeng Xie, Xinghua Li 0001, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2024 Efficient Privacy-Preserving Federated Learning With Improved Compressed Sensing
abstract
To solve the data silos issue in distributed machine learning with privacy leakage, privacy-preserving federated learning (PPFL) has been extensively explored in both academic and industrial fields. However, the existing PPFL solutions still suffer from high computation and communication overheads, which result in excessive consumption of communication bandwidth and slow down the training process of FL. To address these issues, we propose a secure and communication-efficient FL scheme using improved compressed sensing and CKKS homomorphic encryption. Specifically, we implement a lossy compression of the model by using discrete cosine transform, then use CKKS homomorphic encryption to encrypt the data transmitted between clients and center server due to its high efficiency and support for batch encryption. Formal security analysis proves that our scheme is secure against indistinguishability under chosen plaintext attack and extensive experiments demonstrate that our scheme achieves a high accuracy at 0.05% compression rate.
Yinbin Miao, Xinghua Li 0001, Linfeng Wei, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Ind. Informatics5
2024 PBAG: A Privacy-Preserving Blockchain-Based Authentication Protocol With Global-Updated Commitment in IoVs
abstract
Internet of Vehicles (IoVs) is increasingly used as a medium to propagate critical information via establishing connections between entities such as vehicles and infrastructures. During message transmission, privacy-preserving authentication is considered the first line of defence against attackers and malicious information. To achieve a more secure and stable communication environment, ever-increasing numbers of blockchain-based authentication schemes are proposed. At first glance, existing approaches provide robust architectures and achieve transparent authentication. However, in these schemes, verifiers need to conduct real-time operations in the blockchain (e.g., querying certificates). To remedy this limit, we propose a privacy-preserving blockchain-based authentication protocol with global-updated commitment (PBAG). In PBAG, based on the issued certificates, a public global commitment is computed, and a unique evaluation proof is generated for each authorized vehicle. Instead of querying the blockchain in real-time, verifiers can independently authenticate vehicles using the global commitment that is pre-updated with the assistance of the blockchain. Moreover, our scheme proposes a dynamic update mechanism to ensure the freshness of the global commitment and evaluation proofs. Benefiting from the update mechanism, there will be an authentication failure for vehicles holding invalid certificates when using the latest global commitment, thus avoiding the time-consuming of checking the Certificate Revocation List (CRL). In terms of privacy protection, our scheme provides privacy properties such as anonymity and unlinkability. It allows anonymous authentication based on evaluation proofs and achieves traceability of identity in the event of a dispute. The simulation demonstrates that the average computation cost of verifying per message is 0.36ms under the batch-enabled mechanism, reducing by more than 63.7% compared with existing schemes.
Xia Feng, Kaiping Cui, Liangmin Wang 0001, Zhiquan Liu 0001, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.4
2024 RPPM: A Reputation-Based and Privacy-Preserving Platoon Management Scheme in Vehicular Networks
abstract
Platoon refers to a group of vehicles traveling in a train-like strategy with a lean inter-vehicle gap, which can increase road capacity and reduce energy consumption. A platoon is composed of several member vehicles and one leader vehicle which determines the driving pattern of the platoon. Therefore, it is crucial to select a vehicle with the highest reputation value as the leader vehicle in a platoon. Reputation value is a private parameter of each vehicle, and how to preserve its privacy is also an issue worth paying attention to. Therefore, in this paper, a reputation-based and privacy-preserving platoon management (RPPM) scheme in vehicular networks is proposed. Specifically, we design a secure comparison protocol (SCP) to select a leader vehicle for each platoon. The SCP protocol not only reduces the involvement of trust authority but also preserves the privacy of vehicles’ reputation values. Furthermore, the cloud server aggregates reputation ciphertexts and feedback scores of the member vehicles based on the homomorphism characteristic of Paillier ciphertexts, and the reputation value privacy of member vehicles is preserved without affecting the aggregation results. The theoretical analysis indicates that the RPPM scheme is privacy-preserving and secure enough to resist several common attacks in vehicular networks. Simulations are conducted to demonstrate the performance of the RPPM scheme, and the results show that the RPPM scheme significantly outperforms the existing schemes in computation and communication overheads.
Runchuan Li, Zhiquan Liu 0001, Yong Ma 0005, Yunni Xia, Yudan Cheng, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.2
2024 MTDCAP: Moving Target Defense-Based CAN Authentication Protocol
abstract
The convenience behind modern intelligent vehicles is simply that a group of intelligent electronic control units (ECUs) connected to controller area network (CAN) work in concert. However, quite a lot of studies have shown their security concerns about CAN. In this era of rampant cyberattacks, due to the broadcast mechanism of CAN and the lack of necessary security mechanisms such as encryption and authentication, ECUs are easily disturbed by various cyberattacks, thus leading to vehicle failures. To solve this problem, we propose a novel security authentication protocol based on the core concept of moving target defense, namely MTDCAP, which utilizes MaskedID and hash chains to maintain anonymity externally and ensure the authentication of the sender internally. Unlike general hash chain-based authentication, our protocol creatively incorporates a self-renewal mechanism into the hash chain, which effectively reduces the time overhead and security risk of negotiating the update of the hash chain between both communicating parties. In addition, AES serves to encrypt CAN message payload so as to prevent adversaries from eavesdropping. The theoretical analysis for the security against four kinds of attacks (i.e., eavesdropping, impersonation, replay, and bus-off attacks) in MTDCAP is detailed. Afterwards, a series of protocol evaluations are conducted on two kinds of typical hardware platforms, including T-Box from real vehicle supported by XPeng, and the results reveal that the proposed protocol significantly outperforms the existing protocols in the robustness, bus load, and time overhead. In particular, the authentication overhead on T-Box is only 0.18 ms for MTDCAP.
Huibiao Su, Jian Weng 0001, Zhiquan Liu 0001, Ming Li 0049, Yi Liu 0053, Yucheng Zhong, Wenzhen Sun
IEEE Trans. Intell. Transp. Syst.4
2024 Efficient Privacy-Preserving Spatial Data Query in Cloud Computing
abstract
With the rapid development of geographic location technology and the explosive growth of data, a large amount of spatial data is outsourced to the cloud server for reducing the local high storage and computing burdens, but at the same time causes security issues. Thus, extensive privacy-preserving spatial data query schemes have been proposed. Most of the existing schemes use Asymmetric Scalar-Product-Preserving Encryption (ASPE) to encrypt data, but ASPE has proven to be insecure against known plaintext attack. And the existing schemes require users to provide more information about query range and thus generate a large amount of ciphertexts, which causes high storage and computational burdens. To solve these issues, based on enhanced ASPE designed in our conference version, we first propose a basic Privacy-preserving Spatial Data Query (PSDQ) scheme by using a new unified index structure, which only requires users to provide less information about query range. Then, we propose an enhanced PSDQ scheme (PSDQ$^+$) by using Geohash-based$R$-tree structure (called$GR$-tree) and efficient pruning strategy, which greatly reduces the query time. Formal security analysis proves that our schemes achieve Indistinguishability under Chosen Plaintext Attack (IND-CPA), and extensive experiments demonstrate that our schemes are efficient in practice.
Yinbin Miao, Yutao Yang, Xinghua Li 0001, Linfeng Wei, Zhiquan Liu 0001, Robert H. Deng
IEEE Trans. Knowl. Data Eng.5
2024 Time-Controllable Keyword Search Scheme With Efficient Revocation in Mobile E-Health Cloud
abstract
Electronic health (e-health) systems may outsource data such as patient e-health records to mobile cloud servers for efficiency gains (e.g., minimizing local storage and computation costs). However, such a move may result in privacy implications in the presence of semi-honest cloud servers. Searchable Encryption (SE) can potentially facilitate privacy-preserving searches based on keywords for encrypted data stored in the mobile cloud, but most existing SE solutions do not support temporal access control (i.e., a mechanism that grants access permissions to users for specified time ranges). Hence, in this paper we design a time-controllable keyword search scheme by using an attribute-based comparable access control. This allows users to match indexes encrypted at specified time intervals. Then, we improve the basic framework to support efficient user revocation using secret sharing. We then formally prove the security of our proposed frameworks against chosen-keyword attack and key collusion attack, as well as achieving keyword secrecy. We also evaluate the performance of our proposed approach using a real-world dataset to demonstrate their practical utility.
Yinbin Miao, Feng Li 0041, Xinghua Li 0001, Zhiquan Liu 0001, Jianting Ning, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Mob. Comput.4
2023 Improved Differential Cryptanalysis on SPECK Using Plaintext Structures
Zhuohui Feng, Qianqian Yang 0003, Zhiquan Liu 0001, Ling Song 0001
ACISP5
2023 Efficient Anonymous Authentication and Privacy-Preserving Reliability Evaluation for Mobile Crowdsensing in Vehicular Networks
abstract
Mobile crowdsensing (MCS) is widely applied in vehicular networks where several sensing vehicles complete the same sensing task. Recently, the privacy and reliability of sensing vehicles have aroused extensive attention of researchers in academia. Although the majority of existing schemes have achieved anonymous authentication with large computation and communication overheads, they do not take the reliability of sensing vehicles into account when selecting sensing vehicles. In this article, we propose an efficient anonymous authentication and privacy-preserving reliability evaluation (AARE) scheme for MCS, which not only improves the efficiency of mutual authentication but also guarantees the reliability of sensing vehicles. Specifically, an efficient anonymous authentication method is proposed to achieve the anonymous authentication of sensing vehicles. Besides, even if a sensing vehicle passes anonymous authentication, it is difficult to fully guarantee its reliability. Then, a privacy-preserving reliability evaluation algorithm is adopted to evaluate the reliability of sensing vehicles. Meanwhile, in dynamic vehicular networks, the reliability of sensing vehicles is uncertain since there exist many attacks, thus, an accurate reputation update algorithm is designed. Subsequently, the privacy features, computation, and communication overheads in the proposed scheme are analyzed. Comparisons with the existing schemes show that the authentication efficiency of the proposed scheme is increased by 46%–74%, the communication overhead is reduced by 50%–80%, and the accuracy of reputation values of sensing vehicles which submit the reliable/unreliable sensing data is improved/reduced by 16%–22%/67%–74%.
Yudan Cheng, Jianfeng Ma 0001, Zhiquan Liu 0001, Zuobin Ying, Xin Chen 0021
IEEE Internet Things J.3
2023 A Game Theory-Based Incentive Mechanism for Collaborative Security of Federated Learning in Energy Blockchain Environment
abstract
With the digital transformation of the energy industry, energy blockchain is playing an important role in application areas, such as energy data sharing and distributed power trading. In this process, the use of energy data is a top priority. Federated learning (FL) can enable the analysis and computation of energy data while protecting their privacy. However, traditional FL relies on a central server and parties involved are not fully trusted. In energy blockchain environment, FL also faces data poisoning attacks launched by energy departments, besides, the supervisory committee carrying out checking models can launch deception attacks. Therefore, we propose a game theory-based incentive mechanism for collaborative security of FL in energy blockchain environment, which can discourage nodes from taking malicious behaviors in iterative training of FL. First, we propose an FL model in energy blockchain environment, which can protect privacy and achieve collaborative security. Considering that game theory can be used to analyze the strategies of participants, we build a game model with energy departments and supervisory committee as players and design our incentive mechanism based on game theory, which is implemented by smart contracts. Even if the accuracy of model checking algorithm is low, malicious behaviors in FL can be reduced by using our incentive mechanism. In particular, we prove that our mechanism can lead game model to a Nash equilibrium (NE) that achieve collaborative security. Security analysis and experimental evaluation show that our incentive mechanism is feasible in energy blockchain with robustness, reliability, and low complexity.
Yunhua He, Mingshun Luo, Bin Wu 0011, Limin Sun 0001, Yongdong Wu, Zhiquan Liu 0001, Ke Xiao 0001
IEEE Internet Things J.6
2023 TFL-DT: A Trust Evaluation Scheme for Federated Learning in Digital Twin for Mobile Networks
abstract
Due to the distributed collaboration and privacy protection features, federated learning is a promising technology to perform the model training in virtual twins of Digital Twin for Mobile Networks (DTMN). In order to enhance the reliability of the model, it is always expected that the users involved in federated learning have trustworthy behaviors. Yet, available trust evaluation schemes for federated learning have the problems of considering simplex evaluation factor and using coarse-grained trust calculation method. In this paper, we propose a trust evaluation scheme for federated learning in DTMN, which takes direct trust evidence and recommended trust information into account. A user behavior model is designed based on multiple attributes to depict users’ behavior in a fine-grained manner. Furthermore, the trust calculation methods for local trust value and recommended trust value of a user are proposed using the data of user behavior model as trust evidence. Several experiments were conducted to verify the effectiveness of the proposed scheme. The results show that the proposed method is able to evaluate the trust levels of users with different behavior patterns accurately. Moreover, it performs better in resisting attacks from users that alternately execute good and bad behaviors compared with state-of-the-art scheme.
Zhiquan Liu 0001, Siyi Tian, Feiran Huang, Jiaxing Li 0004, Xinghua Li 0001, Kostromitin Konstantin, Jianfeng Ma 0001
IEEE J. Sel. Areas Commun.2
2023 Towards Efficient Verifiable Boolean Search Over Encrypted Cloud Data
abstract
Symmetric Searchable Encryption (SSE) schemes facilitate searching over encrypted data, and have been extensively explored to improve function, efficiency or security. There are, however, additional functions that we need to consider in a real-world setting. For example, forward and backward privacy are required to adequately secure newly added documents and deleted documents in Dynamic SSE (DSSE) schemes, and support boolean search (that allows users to search over encrypted data using basic boolean operations) to achieve improved efficiency and retrieval accuracy. Therefore, in this article we first construct the Verifiable Boolean Search over encrypted data (VBS), and then improve VBS to achieve Forward and Backward privacy (VBS-FB). Finally, we formally prove the security of our proposed schemes, and evaluate their performance using real-world datasets.
Feng Li 0041, Jianfeng Ma 0001, Yinbin Miao, Zhiquan Liu 0001, Kim-Kwang Raymond Choo, Ximeng Liu, Robert H. Deng
IEEE Trans. Cloud Comput.4
2023 A Privacy-Preserving and Reputation-Based Truth Discovery Framework in Mobile Crowdsensing
abstract
In mobile crowdsensing (MCS), truth discovery (TD) plays an important role in sensing task completion. Most of the existing studies focus on the privacy preservation of mobile users, and the reliability of mobile users is evaluated by their weights which are calculated based on the submitted sensing data. However, if mobile users are unreliable, the submitted sensing data and their weights are also unreliable, which may influence the accuracy of the ground truths of sensing tasks. Therefore, this article proposes a privacy-preserving and reputation-based truth discovery framework named PRTD which can generate the ground truths of sensing tasks with high accuracy while preserving privacy. Specifically, we first preserve sensing data privacy, weight privacy, and reputation value privacy by utilizing the Paillier algorithm and Pedersen commitment. Then, to verify whether the reputation values of mobile users are tampered with and select mobile users that satisfy the corresponding reputation requirements, we design a privacy-preserving reputation verification algorithm based on reputation commitment and zero-knowledge proof and propose a concept of reliability level to select mobile users. Finally, a general TD algorithm with reliability level is presented to improve the accuracy of the ground truths of sensing tasks. Moreover, theoretical analysis and performance evaluation are conducted, and the evaluation results demonstrate that the PRTD framework outperforms the existing TD frameworks in several evaluation metrics in the synthetic dataset and real-world dataset.
Yudan Cheng, Jianfeng Ma 0001, Zhiquan Liu 0001, Zhetao Li, Yongdong Wu, Caiqin Dong, Runchuan Li
IEEE Trans. Dependable Secur. Comput.3
2023 A Lightweight Privacy Preservation Scheme With Efficient Reputation Management for Mobile Crowdsensing in Vehicular Networks
abstract
Mobile crowdsensing (MCS) refers to a group of mobile users utilizing their sensing devices to accomplish the same sensing task. However, in vehicular networks, how to evaluate the reliability of sensing vehicles and achieve lightweight privacy preservation are urgent issues. Therefore, this paper proposes a lightweight privacy preservation scheme with efficient reputation management (PPRM) for MCS in vehicular networks. Specifically, we design a lightweight privacy-preserving sensing task matching algorithm which can preserve the location privacy, identity privacy, sensing data privacy, and reputation value privacy while reducing communication and computation overheads of sensing vehicles. In particular, to prevent reputation values from being forged and select reliable sensing vehicles, we present a privacy-preserving reputation value equality verification algorithm to verify reputation values and a privacy-preserving reputation value range proof algorithm to choose sensing vehicles. Afterwards, a three-factor reputation value update algorithm is constructed to efficiently and accurately update the reputation values for sensing vehicles. Simulations are conducted to demonstrate the performance of the PPRM scheme, and the results show that the PPRM scheme significantly outperforms the existing schemes in security and robustness aspects.
Yudan Cheng, Jianfeng Ma 0001, Zhiquan Liu 0001, Yongdong Wu, Kaimin Wei, Caiqin Dong
IEEE Trans. Dependable Secur. Comput.3
2023 Maliciously Secure and Efficient Large-Scale Genome-Wide Association Study With Multi-Party Computation
abstract
Genome-Wide Association Study (GWAS) aims at detecting the association between diseases and Single-Nucleotide Polymorphisms (SNPs) with statistical techniques and has great potential for disease diagnosis. To obtain high-quality results, GWAS requires large-scale genomic data containing individuals’ privacy information. Thus, how to improve the efficiency of GWAS while protecting the privacy of genomic data becomes a critical challenge. In this paper, we propose a secure and efficient GWAS scheme. By using secure three-party computation, we present a series of protocols, i.e., Secure Quality Control, Secure Principle Component Analysis, Secure Cochran-Armitage trend test, and Secure Logistic Regression, to cover the most significant procedures of secure GWAS. In these protocols, a new comparison protocol is designed to reduce communication and improve efficiency. Furthermore, by extending the above comparison protocol to be maliciously secure and utilizing other technologies, e.g., consistency check, we extend the whole GWAS scheme to malicious security with rationally additional overhead. Experimental results demonstrate that our protocols achieve about 33% performance improvement than the state-of-art secure GWAS scheme using two-party computation in terms of runtime and communication in the semi-honest setting. The cost of our scheme in the malicious setting is around 1.5X than that in the semi-honest setting.
Caiqin Dong, Jian Weng 0001, Jia-Nan Liu, Anjia Yang, Zhiquan Liu 0001, Yaxi Yang, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.5
2023 Attacks on Acceleration-Based Secure Device Pairing With Automatic Visual Tracking
abstract
In an acceleration-based Secure Device Pairing (SDP) scheme, two unauthenticated devices continuously measure their own acceleration. If the similarity of their measurements are sufficiently high, the devices will build a secure communication channel assume that it is hard for any attacker to estimate their measurements in real-time. This paper demonstrates that the assumption does not hold and further proposes an effective Man-in-the-Middle (MitM) attack on acceleration-based SDP schemes. That is to say, an MitM adversary is able to quickly estimate the acceleration measurements of the target devices with automatic visual tracking technologies, and then compromise the device’s communication channel by impersonating the target devices with the estimated measurements. The present attack is extensively evaluated on acceleration-based SDP schemes in indoor and outdoor environments. The evaluation results show that the device’s acceleration can be estimated with high accuracy in real time. Thus, the present MitM attack is practical to defeat the acceleration-based SDP schemes.
Hongshuang Hu, Yongdong Wu, Jian Weng 0001, Kaimin Wei, Zhiquan Liu 0001, Feiran Huang, Yinyan Zhang
IEEE Trans. Inf. Forensics Secur.5
2023 Efficient Privacy-Preserving Spatial Range Query Over Outsourced Encrypted Data
abstract
With the rapid development of Location-Based Services (LBS), a large number of LBS providers outsource spatial data to cloud servers to reduce their high computational and storage burdens, but meanwhile incur some security issues such as location privacy leakage. Thus, extensive privacy-preserving LBS schemes have been proposed. However, the existing solutions using Bloom filter do not take into account the redundant bits that do not map information in Bloom filter, resulting in high computational overheads, and reveal the inclusion relationship in Bloom filter. To solve these issues, we propose an efficient Privacy-preserving Spatial Range Query (PSRQ) scheme by skillfully combining Geohash algorithm with Circular Shift and Coalesce Bloom Filter (CSC-BF) framework and Symmetric-key Hidden Vector Encryption (SHVE), which not only greatly reduces the computational cost of generating token but also speeds up the query efficiency on large-scale datasets. In addition, we design a Confused Bloom Filter (CBF) to confuse the inclusion relationship by confusing the values of 0 and 1 in the Bloom filter. Base on this, we further propose a more secure and practical enhanced scheme PSRQ+by using CBF and Geohash algorithm, which can support more query ranges and achieve adaptive security. Finally, formal security analysis proves that our schemes are secure against Indistinguishability under Chosen-Plaintext Attacks (IND-CPA) and PSRQ+achieves adaptive IND-CPA, and extensive experimental tests demonstrate that our schemes using million-level dataset improve the query efficiency by 100x compared with previous state-of-the-art solutions.
Yinbin Miao, Yutao Yang, Xinghua Li 0001, Zhiquan Liu 0001, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.4
2023 ICRA: An Intelligent Clustering Routing Approach for UAV Ad Hoc Networks
abstract
As an important means of obtaining information of marine situation, the marine monitoring system relying on UAV has been paid more and more attention by all countries in the world, and the demand for tasks is growing continually. In UAV ad hoc networks, routing protocols with immutable routing policies that lack flexibility are generally incapable of maintaining effective performance due to the complicated and rapidly changing environmental situation and application requirements. In this paper, we propose an intelligent clustering routing approach (ICRA) for UANETs. The ICRA is composed of three components: the clustering module, the clustering strategy adjustment module and the routing module. In the clustering process, each node needs to calculate its utility. In order to maintain high topology stability and long network lifetime in different network states, the reinforcement learning based clustering strategy adjustment module needs continuous learning the benefits brought by adopting different strategies to calculate the nodes utility in a specific network state. With the learned knowledge, clustering strategy adjustment module could determine the optimal clustering strategy according to the current network state. In the routing phase, the proposed scheme can reduce the end-to-end delay and improve the packet delivery rate by introducing inter-cluster forwarding nodes to forward messages among different clusters. Extensive experiments have been conducted to verify ICRA’s robustness and superiority over existing schemes. The results demonstrate that ICRA could achieve better performance than its state-of-the-art counterparts with regard to the clustering efficiency, topology stability, energy efficiency and quality of service.
Huamin Gao, Zhiquan Liu 0001, Feiran Huang, Junwei Zhang 0008, Xinghua Li 0001, Jianfeng Ma 0001
IEEE Trans. Intell. Transp. Syst.3
2023 Seeking Based on Dynamic Prices: Higher Earnings and Better Strategies in Ride-on-Demand Services
abstract
In recent years, ride-on-demand (RoD) services such as Uber and DiDi are becoming increasingly popular. Different from traditional taxi services, RoD services adopt dynamic pricing mechanisms to manipulate the supply and demand on the road, and such mechanisms improve service capacity and quality. Seeking route recommendation has been widely studied in taxi service. In RoD service, the dynamic price is a new and accurate indicator describing the supply and demand, but it is yet rarely studied in providing clues for drivers to seek for passengers. In this paper, we propose to incorporate the impacts of dynamic prices as a key factor in recommending seeking routes to drivers. We first justfiy why it is necessary to recommend seeking routes and consider dynamic prices, by analyzing real service data from a typical RoD service. We then design a reinforcement learning model based on order and GPS trajectories datasets, and take into account dynamic prices in the design. Results prove that our model improves both driver earnings and seeking strategies. On driver earnings, the reinforcement learning model increases revenue efficiency by up to 34.52%, and considering dynamic prices leads to another increase of 6.19%. On seeking strategies, drivers are encouraged to serve local demand first, and they are redistributed more evenly and effectively.
Suiming Guo, Qianrong Shen, Zhiquan Liu 0001, Chao Chen 0004, Chaoxiong Chen, Jingyuan Wang 0001, Zhetao Li, Ke Xu 0002
IEEE Trans. Intell. Transp. Syst.3
2023 Lightweight Trustworthy Message Exchange in Unmanned Aerial Vehicle Networks
abstract
Unmanned Aerial Vehicle (UAV) networks have huge potential for a variety of military and civilian uses, such as intelligent transportation system, smart city, and so on. The 6th Generation (6G) communication technology is expected to provide 3-Dimensional (3D) wireless coverage and greatly improve the performance of UAV networks. The UAV-to-UAV (U2U) message exchange (or message exchange for short) is an important basis of multi-UAV cooperation. However, due to the unique characteristics of UAV networks, the U2U messages (or messages for short) are vulnerable to both the external and internal attackers. In this work, we propose a Lightweight Trustworthy Message Exchange (LTME) scheme for UAV networks by efficiently aggregating the cryptography and trust management technologies. In the LTME scheme, a centralized Ground Control Station (GCS) periodically updates the reputation levels of registered UAVs (or UAVs for short) and securely distributes secret values to the UAVs. Based on the received secret values, each trustworthy broadcasting UAV can generate its encrypted messages so that only trustworthy receiving UAVs can decrypt them, and each trustworthy receiving UAV can accurately judge whether the received messages and the corresponding broadcasting UAVs are trustworthy in a lightweight manner. Furthermore, we present a simplified LTME (sLTME) scheme and conduct a comprehensive theoretical analysis and simulation evaluation for the LTME and sLTME schemes. The results demonstrate that the proposed schemes can provide rich functionality and strong robustness with low computation and communication overheads, and are significantly superior to the existing schemes in several aspects.
Zhiquan Liu 0001, Feiran Huang, Donghong Cai, Yongdong Wu, Xin Chen 0021, Kostromitin Konstantin
IEEE Trans. Intell. Transp. Syst.1
2022 A Lightweight Privacy-Preserving Participant Selection Scheme for Mobile Crowdsensing
abstract
As a new sensing paradigm, mobile crowdsensing (MCS) needs to select task participants that satisfy the sensing requirements to accomplish sensing tasks. How to choose eligible task participants while preserving privacy is an urgent issue. In this paper, we propose a lightweight privacy-preserving participant selection (LPPS) scheme for MCS. Specifically, data requesters and task participants utilize the k-anonymity technique to generate anonymous location matrices, then the cloud server computes the Hadamard product for location matrices to judge whether task participants locate in the corresponding sensing areas. Meanwhile, the Paillier algorithm is adopted to ensure sensing data privacy. Finally, both theoretical analysis and performance evaluation demonstrate that the proposed scheme outperforms the existing schemes in terms of security and efficiency.
Yudan Cheng, Jianfeng Ma 0001, Zhiquan Liu 0001
WCNC3
2022 Active device detection and performance analysis of massive non-orthogonal transmissions in cellular Internet of Things
Donghong Cai, Pingzhi Fan, Qiuyun Zou, Yanqing Xu 0003, Zhiguo Ding 0001, Zhiquan Liu 0001
Sci. China Inf. Sci.6
2022 Edge Intelligent Joint Optimization for Lifetime and Latency in Large-Scale Cyber-Physical Systems
abstract
In recent years, the exploration on large-scale cyber–physical systems (CPSs) has become a fertile research field of significant impact. Large-scale CPS applications cover not only manufacturing and production areas but also daily living domains. Traditional solutions dedicated for large-scale CPSs mainly concentrate on the service latency or reliability optimization, but neglect the resultant negative impact on system lifetime. In this article, we conduct the first study on jointly optimizing the service latency and system lifetime subject to the constraints of reliability, energy consumption, and schedulability for large-scale CPSs. We propose an edge intelligent solution composed of offline and online phases. At the offline phase, the long short-term memory (LSTM) technique is leveraged to predict task offloading rates at individual user groups. Afterward, the multiobjective evolutionary algorithm with dual local search (DLS-MOEA) is exploited to determine optimal system static settings of computation offloading mapping and task replication number. At the online phase, an affinity-driven scheme incurring minimal system dynamic overheads is designed to deal with the inherent mobility of terminal users. We also build an algorithm validation platform upon which extensive simulation experiments are carried out. Experimental results show that our offline and online schemes outperform the state-of-the-art benchmarking methods by 27.1% and 43.5%, respectively.
Kun Cao 0001, Yangguang Cui, Zhiquan Liu 0001, Wuzheng Tan, Jian Weng 0001
IEEE Internet Things J.3
2022 PPTM: A Privacy-Preserving Trust Management Scheme for Emergency Message Dissemination in Space-Air-Ground-Integrated Vehicular Networks
abstract
Vehicular networks have tremendous potential to improve the road safety and traffic efficiency, and the adoption of the space–air–ground-integrated network (SAGIN) architecture in vehicular networks can greatly improve the performance of vehicular networks by leveraging the respective advantages of the space, air, and ground segments on coverage, flexibility, reliability, and availability, which results in space–air–ground-integrated vehicular networks (SAGIVNs). Trust management is an important tool for constructing trustworthy SAGIVNs, and privacy preservation is also a primary concern in SAGIVNs. They have conflicting requirements and a satisfactory balance between them is urgently required. In this article, we propose a novel privacy-preserving trust management (PPTM) scheme for the emergency message dissemination in SAGIVNs. The proposed scheme can realize precise trust management and strong conditional privacy preservation simultaneously with low communication overhead, and can provide strong applicability, strong robustness, and multiple other attractive features. Furthermore, the exhaustive theoretical analysis and simulation evaluation are detailed. The results reveal that the proposed scheme is significantly superior to the existing schemes in several aspects.
Zhiquan Liu 0001, Jian Weng 0001, Jianfeng Ma 0001, Feiran Huang, Yudan Cheng
IEEE Internet Things J.1
2022 Antitampering Scheme of Evidence Transfer Information in Judicial System Based on Blockchain
abstract
In the process of handling criminal cases, it is crucial to avoid evidence tampering and ensure the integrity, consistency, and nonrepudiation of evidence transfer records, which is highly related to the fairness and credibility of the judiciary. To address this problem, we propose a consortium blockchain network to record evidence transfer events among different departments of China's judicial system. We design the format of a transaction and a block. In addition, the smart contracts for three types of transactions are also proposed. The Raft consensus algorithm is adopted to accomplish the consensus process. A security analysis shows that the proposed scheme can achieve the design goal (the integrity, consistency, and nonrepudiation of evidence transfer records stored in blockchain). Furthermore, a set of experiments were conducted to analyse the performance of the proposed scheme. The experiments results show that the throughput of the system is proportional to the send rate within a certain threshold. The latency decreases with increasing send rate if the send rate is within a certain threshold. Peer nodes in the system consume the most storage and communication cost. The values of block size and block generation interval time have a slight influence on the performance of the system.
Xuliang Wei, Jianfeng Ma 0001, Huamin Gao, Zhiquan Liu 0001
Secur. Commun. Networks7
2022 ADFL: A Poisoning Attack Defense Framework for Horizontal Federated Learning
abstract
Recently, federated learning has received widespread attention, which will promote the implementation of artificial intelligence technology in various fields. Privacy-preserving technologies are applied to users’ local models to protect users’ privacy. Such operations make the server not see the true model parameters of each user, which opens wider door for a malicious user to upload malicious parameters and make the training result converge to an ineffective model. To solve this problem, in this article, we propose a poisoning attack defense framework for horizontal federated learning systems called ADFL. Specifically, we design a proof generation method for users to generate proofs to verify whether it is malicious or not. An aggregation rule is also proposed to make sure the global model has a high accuracy. Several verification experiments were conducted and the results show that our method can detect malicious user effectively and ensure the global model has a high accuracy.
Feiran Huang, Zhiquan Liu 0001, Yanguo Peng, Xinghua Li 0001, Jianfeng Ma 0001, Varun G. Menon, Kostromitin Konstantin
IEEE Trans. Ind. Informatics4
2021 BTMPP: Balancing Trust Management and Privacy Preservation for Emergency Message Dissemination in Vehicular Networks
abstract
As a potential application field of the sixth-generation (6G) communication technology and a promising part of massive Internet of Things (IoT), vehicular networks have attracted considerable attention from both academia and industry in recent years, where the cooperative safety applications are a significant branch. It is widely acknowledged that 6G is able to provide high-throughput and low-latency wireless communication capability for vehicular networks, support massive interconnectivity in vehicular networks with diverse service requirements, and significantly improve the performance of vehicular networks. Both trust management and privacy preservation play significant roles in vehicular networks, and there exists a tradeoff between them. For providing a satisfactory solution to balance the trust management and privacy preservation in vehicular networks, we put forward a novel scheme named as BTMPP (which is able to provide both the precise trust management and strong conditional privacy preservation simultaneously) in this article by leveraging the famous bloom filter (BF)-based private set intersection (PSI) technology. Furthermore, the theoretical analysis for the correctness, strong conditional privacy preservation capability, strong robustness, precise trust management, and the other features is detailed, and a series of simulations are conducted. The results reveal that the proposed scheme significantly outperforms the existing schemes in several aspects.
Zhiquan Liu 0001, Feiran Huang, Jian Weng 0001, Kun Cao 0001, Yinbin Miao, Yongdong Wu
IEEE Internet Things J.1
2020 Variable Rate Syndrome-Trellis Codes for Steganography on Bursty Channels
Bingwen Feng, Zhiquan Liu 0001, Kaimin Wei, Wei Lu 0001, Yuchun Lin
IWDW2
2020 TROVE: A Context-Awareness Trust Model for VANETs Using Reinforcement Learning
abstract
Vehicular networks have become a visible reality enabling information sharing between vehicles to enhance driving safety and provide value-added services to drivers and passengers. However, false information might be injected into the network because of defective sensors, malicious vehicles, and so on. Therefore, an efficient mechanism to guarantee the reliability of information used by vehicles is of great importance in vehicular networks. To solve this problem, this article proposes a context-awareness trust management model to evaluate the trustworthiness of messages received by vehicles to ensure bogus information will not influence the driving decision-making process. In the proposed scheme, the trust evaluation result of an evaluation request is determined by available related information and the evaluation strategy in the current situation, which is unaffected by the presence of conflicting evidence and the trust level of entities in the network. Moreover, we design a reinforcement learning model that allows vehicles to adjust the evaluation strategy so as to maintain an accurate evaluation result in different driving scenarios. Extensive experiments were conducted in different driving scenarios to verify the effectiveness of the proposed model. The results show that our model is adaptive to different driving scenarios with negligible time overhead, regardless of the proportion of malicious nodes in the network. Furthermore, compared with three types of state-of-the-art trust models in different scenarios, our scheme can achieve a higher evaluation precision rate with no more computational and communication overhead in nonrandom road conditions.
Xinghua Li 0001, Zhiquan Liu 0001, Jianfeng Ma 0001, Chao Yang 0016, Junwei Zhang 0001, Dapeng Wu 0002
IEEE Internet Things J.3
2020 TCEMD: A Trust Cascading-Based Emergency Message Dissemination Model in VANETs
abstract
Vehicular ad-hoc networks (VANETs) have recently attracted considerable attention from both industry and academia for improving road safety and traffic efficiency. Trust modeling plays a significant role in VANETs, however, the existing trust models cannot primely conform to the characteristics of VANETs. This article proposes a novel trust cascading-based emergency message dissemination (TCEMD) model which incorporates the entity-oriented trust values into data-oriented trust evaluation in an efficient manner. In the proposed model, when an emergency event (e.g., an obstacle in front of the road) occurs, the emergency messages can be disseminated among the nearby vehicles in a trust cascading manner, where the entity-oriented trust values (which are evaluated and updated by leveraging the trust certificates and are contained in the messages) are adopted as important weights. Subsequently, the theoretical analysis for the robustness against several kinds of attacks and malicious behaviors, failure tolerance features, compatibility for several kinds of special situations, and incentive mechanisms in the TCEMD model are detailed. Afterwards, a series of simulations and analyses are conducted in a typical highway environment, and the results reveal that the proposed model significantly outperforms the existing models in several cases.
Zhiquan Liu 0001, Jian Weng 0001, Jianfeng Ma 0001, Bingwen Feng, Zhongyuan Jiang, Kaimin Wei
IEEE Internet Things J.1
2020 Multimedia access control with secure provenance in fog-cloud computing networks
Yang Yang 0026, Ximeng Liu, Wenzhong Guo, Xianghan Zheng, Chen Dong 0002, Zhiquan Liu 0001
Multim. Tools Appl.6
2018 Practical Attribute-Based Multi-Keyword Search Scheme in Mobile Crowdsourcing
abstract
Cloud-based mobile crowd-sourcing has been an attractive solution to provide data storage and share services for resource-limited mobile devices in a privacy-preserving manner, but how to enable mobile users to issue search queries and achieve fine-grained access control over ciphertexts simultaneously is still a big challenge for various circumstances. Although the ciphertext-policy attribute-based keyword search technology combining attribute-based encryption with searchable encryption has become a hot research topic, it just deals with equivalent attributes rather than more practical attribute comparisons, like “greater than” or “less than.” In this paper, we devise a practical cryptographic primitive called attribute-based multi-keyword search scheme to support comparable attributes through utilizing 0-encoding and 1-encoding. Formal security analysis proves that our scheme is selectively secure against chosen-keyword attack in generic bilinear group model and extensive experiments using real-world dataset demonstrate that our scheme can drastically decrease both computational and storage costs.
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Xinghua Li 0001, Zhiquan Liu 0001, Hui Li 0006
IEEE Internet Things J.5
2018 Enabling verifiable multiple keywords search over encrypted cloud data
Yinbin Miao, Jian Weng 0001, Ximeng Liu, Kim-Kwang Raymond Choo, Zhiquan Liu 0001, Hongwei Li 0001
Inf. Sci.5
2018 VMKDO: Verifiable multi-keyword search over encrypted cloud data for dynamic data-owner
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Zhiquan Liu 0001, Fushan Wei
Peer-to-Peer Netw. Appl.4
2018 DOAS: Efficient data owner authorized search over encrypted cloud data
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Zhiquan Liu 0001, Junwei Zhang 0001, Fushan Wei
Peer-to-Peer Netw. Appl.4
2017 FCT: a fully-distributed context-aware trust model for location based service recommendation
Zhiquan Liu 0001, Jianfeng Ma 0001, Zhongyuan Jiang, Yinbin Miao
Sci. China Inf. Sci.1
2017 VKSE-MO: verifiable keyword search over encrypted data in multi-owner settings
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Junwei Zhang 0001, Zhiquan Liu 0001
Sci. China Inf. Sci.5
2017 VCKSM: Verifiable conjunctive keyword search over mobile e-health cloud in shared multi-owner settings
Yinbin Miao, Jianfeng Ma 0001, Ximeng Liu, Qi Jiang 0001, Junwei Zhang 0001, Zhiquan Liu 0001
Pervasive Mob. Comput.7
2017 VCSE: Verifiable conjunctive keywords search over encrypted data without secure-channel
Yinbin Miao, Jianfeng Ma 0001, Fushan Wei, Zhiquan Liu 0001, Xu An Wang 0014, Cunbo Lu
Peer-to-Peer Netw. Appl.4
2016 Revocable and anonymous searchable encryption in multi-user setting
abstract
Summary With powerful storage and computing capacities provided by cloud server provider(CSP), cloud customers can relieve from heavy storage and maintenance burden in cloud computing. Therefore, searchable encryption(SE) technology becomes a fundamental solution to search over encrypted data in outsourcing service. However, the genuine safety of SE schemes should concentrate not only on keyword privacy but also on user privacy as information tracking may leak user identity. For example, in the personal health record system, the malicious CSP may match sensitive disease information(cancer or AIDS) with certain patient. In addition, practical SE scheme should not be confined to single‐user setting because of its limitations. While SE schemes applied to multi‐user setting may result in additional secret key and ciphertext updating burden due to frequent user revocation. Along this direction, we define a revocable and anonymous SE scheme in multiple‐user setting, which is scalable and efficient in user revocation and anonymity. Security analysis shows that our scheme is Anonymous‐Revocable‐ID‐CPA secure under Decision Bilinear Diffie–Hellman assumption and is able to effectively resist decryption key exposure threat. Copyright © 2015 John Wiley & Sons, Ltd.
Yinbin Miao, Jianfeng Ma 0001, Zhiquan Liu 0001
Concurr. Comput. Pract. Exp.3
2015 An approach to quality assessment for web service selection based on the analytic hierarchy process for cases of incomplete information
Cong Gao 0002, Jianfeng Ma 0001, Zhiquan Liu 0001, XinDi Ma
Sci. China Inf. Sci.3
2014 Trustworthy Service Composition in Service-Oriented Mobile Social Networks
abstract
In service-oriented mobile social networks (S-MSN), many location-based services are developed to provide various applications to social participants. Services can in turn be composed with the help of these participants. However, the composite structure, the subjective interpretation of trust demand, and the opportunistic connectivity make service composition a challenging task in S-MSN. In this paper, we propose a novel approach to enable trustworthy service evaluation and invocation during the process of composition. By analyzing dependency relationships, our approach can decentralizedly evaluate the trust degree of each service based on a lattice-based trust model to prevent data from being transmitted to untrustworthy counterparts. Besides, service consumers and vendors are able to specify their global and local constraints on the trust degree of service components on demand for more effective composition. Finally, by introducing acquaintances to the neighbors iteratively, social participants form a trust-aware acquaintance graph to forward invocation messages.
Tao Zhang 0029, Jianfeng Ma 0001, Ning Xi 0002, Ximeng Liu, Zhiquan Liu 0001, Jinbo Xiong
ICWS5