VLDB 2026 Research / reviewers in the wild / expert
Weizhi Meng 0001
dblp:146/1188 · also Yuxin Meng 0001
· DBLP profile ↗
246ranked-venue papers
47as first author
157since 2021 · last 2026
0000-0003-4384-5786ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 119 · 27 first-author · 68 since 2021Computer networks · 60 · 12 first-author · 39 since 2021Systems, architecture and hardware · 28 · 5 first-author · 18 since 2021Artificial intelligence and machine learning · 24 · 1 first-author · 22 since 2021Databases, data management, data science and information retrieval · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SuperEar: Eavesdropping on Mobile Voice Calls via Stealthy Acoustic Metamaterials
Zhiyuan Ning 0003, Zhanyong Tang, Juan He 0007, Weizhi Meng 0001, Yuntian Chen, Jie Zhang 0028, Zheng Wang 0001 |
WWW | 4 |
| 2026 | FBAO: backdoor attack against object detection via frequency noise injection
Qiuhua Wang, Haojie Shen, Lin Wang 0108, Lifeng Yuan, Yizhi Ren, Xiyuan Jia, Shuochao Sun, Weizhi Meng 0001 |
Appl. Intell. | 8 |
| 2026 | A social recommendation model based on cross-view contrastive learning and multi-head attention for multi-rating fusion
Rui Chen 0005, Zhuo Dai, Yanbu Guo, Weizhi Meng 0001, Xiangjie Kong 0001 |
Eng. Appl. Artif. Intell. | 5 |
| 2026 | Obfuscation-resilient malware classification via spatial perception and multi-granular attention collaboration
Wenxin Zheng, Sung-Ryul Kim, Weizhi Meng 0001 |
Expert Syst. Appl. | 6 |
| 2026 | Dynamic malware detection based on enhanced semantic API sequence features
Lei Zhou 0009, Qingcheng Liu, Weizhi Meng 0001, Jian Weng 0001 |
Expert Syst. Appl. | 4 |
| 2026 | TraceMark-LDM: Authenticatable watermarking for latent diffusion models via binary-guided rearrangement
Zhangyi Shen, Ye Yao 0003, Feng Ding 0007, Guopu Zhu, Weizhi Meng 0001 |
Expert Syst. Appl. | 6 |
| 2026 | MSGL: A multi-scale group learning model for insider threat detectionabstractThe insider threat refers to actions of organizational users who abuse their authorized privileges to compromise information assets, and the detection of it has become a crucial task in cybersecurity management. Existing approaches primarily rely on user behavior logs for detection, but they often fail to capture the multi-scale temporal dynamics of user behaviors and the structural relationships within user groups, which limits their effectiveness in insider threat detection. To address these limitations, we propose a multi-scale group learning model (MSGL) for insider threat detection. It mainly consists of three key components: (1) a multi-scale collaborative temporal feature extraction module that leverages a weighted attention mechanism to model behavioral dynamics at different granularities and achieves cross-scale information fusion; (2) the group structure-aware module is designed to capture structural dependencies among users by the aggregation mechanism of graph neural networks, while incorporating group-sparsity regularization to attenuate spurious associations and accentuate underlying common patterns; and (3) an individual learning module for capturing deviations via sparse attention, which facilitates disentangled representations of group-level commonalities and specific characteristics of users. Experimental results on the CERT r4.2 and CERT r5.2 datasets demonstrate the effectiveness of MSGL, achieving detection accuracies of 96.28% and 97.41%, respectively. Mengxue Pang, Wei Ou, Weizhi Meng 0001, Meng Shen 0001, Qiuling Yue, Wenbao Han |
Expert Syst. Appl. | 3 |
| 2026 | PCL-BPRE: privacy-preserving certificateless-based broadcast proxy re-encryption for data sharing in cloud-based IIoTabstractWith the rapid advancement of industrial automation and intelligent manufacturing, an increasing volume of sensing data generated by Industrial Internet of Things (IIoT) devices is being transmitted to cloud platforms. Identity-based broadcast proxy re-encryption (IB-BPRE), as an efficient cryptographic mechanism, has been deployed in IIoT data-sharing environments. However, existing IB-BPRE schemes are susceptible to identity privacy breaches of data recipients. Furthermore, IIoT devices are structurally vulnerable to key escrow compromises resulting from the exposure of encrypted key. To mitigate these critical security challenges, we propose a privacy-preserving certificateless-based broadcast proxy re-encryption scheme for data sharing in cloud-based IIoT, and formally prove its security against chosen ciphertext attacks under the random oracle model. The PCL-BPRE scheme employs a Lagrange interpolation polynomial to obfuscate the identity information of data receivers. Additionally, it integrates certificateless encryption to eliminate the inherent key escrow dependency in IB-BPRE, thereby preventing unauthorized disclosure of private keys in the event of a compromised key generation center. Experimental results validate that the proposed scheme achieves both strong practical feasibility and computational efficiency in IIoT data-sharing. Yuanjian Zhou, Tianci Zhao, Zhenjun Jing, Weizhi Meng 0001, Chunsheng Gu, Huidan Hu |
Future Gener. Comput. Syst. | 4 |
| 2026 | FedCode: Addressing federated domain shift by contrastive feature decoupling
Shaobo Zhang 0001, Yijie Yin, Wei Liang 0005, Fan Wu 0014, Weizhi Meng 0001 |
Neurocomputing | 5 |
| 2026 | QSDA: Quality-Aware Secure Multidimensional Data Aggregation With Location Privacy for HIoTabstractData aggregation, as a data processing technique, facilitates accurate diagnosis in the Healthcare Internet of Things (HIoT) by integrating multi-source heterogeneous health data. However, achieving efficient and secure aggregation of multi-dimensional medical data remains challenging, particularly when simultaneously preserving location privacy and providing fair, quality-driven incentives. To address these issues, this paper proposes a Quality-Aware Secure Multi-Dimensional Data Aggregation scheme with Location Privacy for HIoT (QSDA). First, the scheme employs inner product encryption to support aggregation task matching without revealing users’ actual coordinates, and further integrates symmetric homomorphic encryption with super-increasing sequences to enable one-stop compressed aggregation of multi-dimensional data, thereby effectively supporting common statistical operations such as mean and variance. Second, it introduces a data quality incentive mechanism based on offset metrics, while leveraging blockchain auditing to ensure the traceability of the aggregation process and the verifiability of the aggregation results. Finally, security analysis and performance evaluation demonstrate the scheme’s effectiveness and efficiency. Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001 |
IEEE Internet Things J. | 5 |
| 2026 | A Lightweight and Privacy-Preserving Distributed Multidimensional Data Trend Query Scheme With Fault Tolerance for Machine-as-a-ServiceabstractIn the Machine-as-a-Service (MaaS) model, enterprises can significantly reduce production costs by leasing devices from original equipment manufacturers (OEM), while OEM can enhance device quality by utilizing device data shared by enterprises. As such, MaaS is emerging as a very promising paradigm in modern manufacturing. However, the multidimensional data trend formed by the multidimensional data may leak the private production data of enterprises, particularly when the OEM leases the same type of device to enterprises. Currently, there is no targeted and feasible solution to ensure the privacy, integrity, and fault-tolerant of multi-user and multidimensional data in the MaaS model. To address this challenge, we propose a lightweight, privacy-preserving and fault-tolerant distributed multidimensional data trend query scheme for MaaS. The proposed scheme ensures multidimensional data privacy through local differential privacy (LDP), and guarantees fault-tolerant and data integrity using Shamir secret sharing and hash-based message authentication code (mac). To protect the privacy of multidimensional data aggregation trend, we design a weighted noise injection query algorithm based on LDP. Additionally, the scheme mitigates the risk of data leakage by introducing the blockchain (BC) instead of cloud server (CS). We formally prove the security of our proposed scheme, and the experimental evaluation demonstrates that it outperforms existing schemes in terms of computation and communication overhead. Tianci Zhao, Yuanjian Zhou, Weizhi Meng 0001, Zhengjun Jing |
IEEE Internet Things J. | 4 |
| 2026 | Empowering IoT Security: Automated Identification of Standard Library Functions in RTOS Firmware With LLM and RAGabstractReverse engineering embedded firmware for Real-Time Operating Systems (RTOS) is a formidable challenge in Internet of Things security. The common practice of stripping symbolic information from firmware to optimize performance and storage makes identifying standard library functions exceptionally difficult, creating a significant bottleneck for functional analysis and vulnerability discovery. This paper introduces a novel, automated method for identifying these functions in RTOS firmware by leveraging Large Language Models. Our approach operates directly on raw binary code, requiring no symbolic or debugging information, and demonstrates broad generalizability across diverse hardware architectures and compilers. At its core, the method combines Retrieval-Augmented Generation (RAG) to enhance identification accuracy with a newly designed Adaptive Iterative Screening Algorithm (AISA), which optimizes analysis efficiency by prioritizing candidate functions based on a weighted score of call frequency, call depth, and address proximity to reduce token costs. We validated our method through rigorous experimentation on Zephyr RTOS firmware spanning nine architectures (e.g., ARM, MIPS, RISC-V). The results are compelling: our approach achieves a 90.59% accuracy rate in identifying standard library function names. Moreover, its application to commercial IoT firmware confirms its high efficiency, identifying functions significantly faster and more economically than traditional heuristic techniques. This work contributes a powerful, general-purpose, and cost-effective solution for automated firmware analysis. Zhihan Zheng, Yu-an Tan 0001, Weizhi Meng 0001, Shuo Wang 0027 |
IEEE Internet Things J. | 5 |
| 2026 | TrustHFL: An Efficient Aggregation Method for Trustworthy Hierarchical Federated LearningabstractThe hierarchical federated learning framework significantly reduces communication burdens on central servers; however, the integration of edge servers introduces potential risks such as Single Point of Failure (SPOF) and ongoing challenges like imbalanced data distribution. To tackle these challenges, we propose TrustHFL, an innovative aggregation method designed for secure hierarchical federated learning. TrustHFL enhances training efficiency by employing group training that clusters clients with similar data distribution characteristics. Inside each cluster, synchronous aggregation is implemented, while asynchronous aggregation is utilised between clusters to alleviate delays from bottleneck clients. We also introduce a robust access control mechanism for secure interactions between clients and edge servers, ensuring data privacy and system integrity. Moreover, our design favours off-chain computation and training, limiting on-chain storage to essential information and thereby minimising both storage and computational demands on the blockchain, ultimately enhancing training efficiency. Extensive experimental results demonstrate that the proposed method accelerates convergence speed and enhances model accuracy. Compared to existing classical federated learning methods, the model accuracy is improved by an average of 1.98% under various data distribution scenarios, while the time required to achieve the same accuracy is reduced by an average of 65.54%. Wei Liang 0005, Kuanching Li, Weizhi Meng 0001 |
IEEE Internet Things J. | 5 |
| 2026 | VFEFL: Privacy-preserving federated learning against malicious clients via verifiable functional encryption
Nina Cai, Jinguang Han, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 3 |
| 2026 | BISE: Enhance data sharing security through consortium blockchain and IPFS
Mingxuan Chen, Puhe Hao, Weizhi Meng 0001, Yasen Aizezi, Guozi Sun |
J. Inf. Secur. Appl. | 3 |
| 2026 | Privacy-preserving federated learning from partial decryption verifiable threshold multi-client functional encryption
Jinguang Han, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 3 |
| 2026 | Auditable cross-domain data sharing via threshold secret sharing and zero-knowledge proofsabstractCross-domain data sharing in decentralised environments faces persistent challenges related to confidentiality, auditability, and trust decentralisation, particularly when data transmission relies on centralised intermediaries or single proxy entities. To address these issues, this paper proposes a blockchain-enabled auditable data sharing scheme that integrates threshold secret sharing with non-interactive zero-knowledge proofs. In the proposed framework, the encrypted file fragments and secret key shares are decentralised across multiple blockchain nodes using threshold cryptography, preventing any single entity from reconstructing the encryption key or unilaterally performing ciphertext transformations. Zero-knowledge proofs are employed to publicly verify the correctness of the transmission and sharing operations without disclosing plaintexts, secret keys, or sensitive metadata, while the blockchain records verifiable proofs to support tamper-evident auditing. Security analysis shows that the scheme achieves confidentiality, collusion resistance, and verifiable correctness under standard cryptographic assumptions.Experimental evaluations indicate that the proposed scheme incurs acceptable computational and on-chain overhead, suggesting its feasibility in decentralised and cross-domain data sharing scenarios. Yuyang Yan, Zhexuan Yang, Junmin Cao, Weizhi Meng 0001, Guozi Sun |
J. Inf. Secur. Appl. | 4 |
| 2026 | Towards COLREGs-aware ship collision avoidance with multi-agent PPO-LSTM in maritime IoT
Weizhi Meng 0001, Shaoming He, Wenjuan Li 0001 |
J. Netw. Comput. Appl. | 2 |
| 2026 | Exact constrained-training neural networks for confidential 8-bit arithmetic primitives in code obfuscation
Ning Shi, Tianqing Zhu, Wanlei Zhou 0001, Weizhi Meng 0001, Yu-an Tan 0001 |
J. Syst. Archit. | 5 |
| 2026 | Singular transformation attack: Enhancing targeted transferability of adversarial examples via feature importance perturbation
Weizhi Meng 0001, Zhitao Guan, Yu-an Tan 0001 |
Knowl. Based Syst. | 2 |
| 2026 | Hela: A System Call Restriction Framework for Protecting the Entire Containers LifecycleabstractLimiting the number of system calls used by container processes can effectively reduce the kernel attack surface. Existing container system call restriction schemes only focus on the minimum system call set of applications in containers, and lack restrictions on the container runtime runc and other container components that create containers. To solve these problems, this paper proposes Hela, a system call restriction framework that can limit container runtimes and container applications. Hela introduces the Attack Surface Exposure Score (ASES), defined as the dot product of a container's system call usage vector and a risk-weight vector, to quantify exposure. Hela calculates and compares the ASES indicators of various partitioning schemes and selects the best partitioning boundary in the common hook nodes of runc. Hela divides the container creation phase into two phases and generates a minimum set of system calls for each phase. The advantage of Hela is that it combines seccomp with eBPF to achieve accurate parameter checking and efficient system call whitelist switching. Experimental results show that Hela can reduce the kernel attack surface of runc in container runtime compared to traditional schemes. Security experiments prove that our method can mitigate vulnerabilities involving runc and system call parameters. Shaohu Li 0001, Jin Zhou 0017, Weizhi Meng 0001, Bei Gong |
IEEE Trans. Cloud Comput. | 4 |
| 2026 | LAHENet: A Lightweight Additive Homomorphic Edge Neural Network Framework for Industrial IoTabstractEdge nodes in the Industrial Internet of Things (IIoT) often face a fundamental trade-off between limited computational resources and stringent real-time inference requirements. Moreover, sensitive data they generated are exposed to significant privacy and security threats during transmission and computation. To address these challenges, this paper proposes a lightweight additive homomorphic edge neural network framework called LAHENet. This framework achieves millisecond-level inference latency in real-world industrial environments through a combination of a dual-metric feature selection strategy, an efficient additive homomorphic signcryption protocol, and a lightweight linear computation layer with adaptive layer collapsing. It ensures end-to-end confidentiality, unforgeability, forward security, and verifiable computation correctness. Experimental results show that LAHENet maintains a constant communication overhead at a few kilobytes per inference while preserving high model accuracy. It significantly enhances inference efficiency and reduces bandwidth consumption in edge environments, offering a practical private inference solution for large-scale IIoT deployments. Mowei Gong, Zhe Li 0052, Xuepeng Lu, Bei Gong, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Ano2Rule: Rule-Based Global Interpretation for Unsupervised Anomaly Detection in SecurityabstractIn the realm of cybersecurity, unsupervised anomaly detection models have emerged as pivotal tools for identifying novel threats in dynamic and evolving environments. However, the opaque nature of these black-box models presents a significant barrier to their adoption in high-stakes applications, where model interpretability is essential for trust and deployment. This paper presents a rule-based approach called Ano2Rule that enhances the interpretability of unsupervised anomaly detection. First, we propose the concept ofdistribution decomposition rulesthat decompose the complex distribution of normal data into multiple compositional distributions. To find such rules, we design an unsupervised Interior Clustering Tree that incorporates the model prediction into the splitting criteria. Then, we propose the Compositional Boundary Exploration (CBE) algorithm to obtain theboundary inference rulesthat estimate the decision boundary of the original model on each compositional distribution. By merging these two types of rules into a rule set, we can present the inferential process of the unsupervised black-box model in a human-understandable way, and build a surrogate rule-based model for online deployment at the same time. We validate Ano2Rule through extensive experiments on diverse real-world datasets, including network intrusion detection and IoT security, demonstrating superior fidelity and robustness compared to baseline methods. The results show that Ano2Rule achieves high fidelity with the original model's predictions while providing human-understandable insights. Ruoyu Li 0003, Qing Li 0006, Nengwu Wu, Yong Jiang 0001, Weizhi Meng 0001, Laizhong Cui |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | $\mathbb {ABC}$ABC-$ {\mathbb{Channel}}$Channel: An Advanced Blockchain-Based Covert ChannelabstractEstablishing efficient and robust covert channels is crucial for secure communication within insecure network environments. With its inherent benefits of decentralization and anonymization, blockchain has gained considerable attention in developing covert channels. To guarantee a highly secure covert channel, channel negotiation should be contactlessbeforethe communication, carrier transaction features must be indistinguishable from normal transactionsduringthe communication, and communication identities must be untraceableafterthe communication. Such a full-lifecycle covert channel is indispensable to defend against a versatile adversary who intercepts two communicating parties comprehensively (e.g., on-chain and off-chain). Unfortunately, it has not been thoroughly investigated in the literature. We make the first effort to achieve a full-lifecycle covert channel, a novel blockchain-based covert channel namedABC-Channel. We tackle a series of challenges, such as off-chain contact dependency, increased masquerading difficulties as growing transaction volume, and time-evolving, communicable yet untraceable identities, to achieve contactless channel negotiation, indistinguishable transaction features, and untraceable communication identities, respectively. We develop a working prototype to validateABC-Channeland conduct extensive tests on the Bitcoin testnet. The experimental results demonstrate thatABC-Channelachieves substantially secure covert capabilities. In comparison to existing methods, it also exhibits state-of-the-art transmission efficiency. Xiaobo Ma 0001, Pengyu Pan, Jianfeng Li 0006, Wei Wang 0012, Weizhi Meng 0001, Xiaohong Guan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | An XSS Attack Detection Model Based on Two-Stage AST AnalysisabstractCross-site scripting (XSS) attacks pose a significant threat to web applications and user privacy, with the number of such attacks rapidly increasing. Although existing machine learning and deep learning-based XSS attack detection models are effective against common XSS attacks, these models all overlook their own security and often fail to defend against adversarial samples that exploit model vulnerabilities, allowing attackers to successfully bypass these models by using XSS adversarial samples. To address this challenge, in this paper, we propose a novel XSS attack detection model based on two-stage Abstract Syntax Tree (AST) analysis and Long Short-Term Memory (LSTM) neural networks, effectively mitigating the impact of adversarial samples. Our model leverages the ability of AST parsing and analysis of HTML and JavaScript code to effectively eliminate redundant information and adversarial perturbations introduced by adversarial samples. The two-stage process first extracts JavaScript code from the HTML AST, then identifies malicious code fragments from the JavaScript AST. Finally, the LSTM neural network is trained to classify samples as malicious or benign. By analyzing the HTML and JavaScript components of web pages, our model identifies and eliminates adversarial perturbations that interfere with detection, significantly enhancing the security and reliability of the detection process. Extensive experiments on real datasets demonstrate our model's superior performance, achieving an accuracy rate of 0.991 and an F1 score of 0.998 against standard XSS samples, outperforming existing models. More importantly, when facing adversarial XSS samples, most existing detection models exhibit severe robustness degradation with the detection rate (DR) below 0.880, whereas our model maintains a detection rate of over 0.982, significantly higher than state-of-the-art models and demonstrating its significant effectiveness in defending against XSS adversarial attacks. Qiuhua Wang, Chuangchuang Li, Lifeng Yuan, Dong Wang 0019, Yeru Wang, Yizhi Ren, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2026 | An Efficiency-Improved and Conditional Privacy-Preserving Authentication Scheme Based on Merkle Hash Tree in MECabstractAuthentication is an important security issue for multi-access edge computing (MEC). However, the existing authentication schemes have not achieved a good balance between privacy preserving, efficiency, and low computation overhead on the device side. To address this issue, we propose an efficiency-improved and conditional privacy-preserving authentication scheme suitable for resource-constrained MEC devices. Our core idea is integrating the merkle hash tree (MHT) into the anonymous authentication scheme constructed by the blockchain and key derivation function (KDF) to improve efficiency. The MHT not only reduces the on-chain storage overhead brought by the increasing pseudo-public keys of KDF, but also utilizes few hash functions to achieve lightweight${\bm {k}}$-times authentications with the same edge server. Despite these advantages, managing pseudo-key pairs in the form of MHT leafs still brings efficiency and unlinkability problems. We construct the partially shuffled merkle hash tree to only shuffle leafs within the device group, and combine with the KDF to update MHTs in a public manner by synchronizing pseudo-key pairs. Consequently, the efficiency of key update can be ensured. Moreover, a time-bound key derivation function based on physically unclonable function and BIP-32 is developed to provide immediate and permanent device revocation. Only the remaining valid pseudo-public keys of the revoked device will be recorded on the blockchain, which reveals no linkable information and avoids frequently reconstructing all the MHTs. We prove the authentication security and discuss other security features. A proof-of-concept prototype was implemented to conduct experiments and comparative analysis for performance evaluation. Yan Zhang 0097, Chunsheng Gu, Peizhong Shi, Zhengjun Jing, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | GDetox: Purifying Backdoor Encoder in Graph Self-Supervised Learning via Knowledge DistillationabstractGraph Neural Networks (GNNs) have powerful representation capabilities for graph data, achieving excellent performance across various fields. Considering the scarcity of labels in real-world scenarios, graph self-supervised learning (GSSL) has gained increasing attention due to its ability to train without relying on labels. However, recent studies have revealed that GNNs are vulnerable to stealthy backdoor attacks in GSSL scenarios, enabling the encoder to learn backdoor features simply by injecting triggers. Existing graph backdoor defense methods mainly focus on supervised settings and cannot be directly transferred to self-supervised scenarios due to the lack of label guidance. To bridge this gap, we proposeGDetox, the first backdoor defense approach against backdoored encoders in GSSL.GDetoxaims to eliminate backdoor logic in encoders while maintaining the encoder's original performance. Specifically,GDetoxcan purify the graph backdoor encoder based on the self-supervised distillation approach without relying on label information. Further, we introduce an adversarial contrastive learning that augments node representations without relying on labels to enhance teacher model performance, thereby improving distilled encoder performance. We evaluate the defense performance ofGDetoxon four node classifications and four graph classification datasets by comparing with four state-of-the-art (SOTA) defense methods against seven latest backdoor attack methods on GSSL. Extensive experiments demonstrate thatGDetoxfar outperforms the SOTA defense methods, reducing the attack success rate to 4% with negligible degradation in encoder performance (within 2%) in both node-level and graph-level tasks. Hao Sui 0003, Jiale Zhang 0001, Bing Chen 0002, Chunpeng Ge 0001, Weizhi Meng 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | CoGA: A Collaborative Gray-Box Adversarial Attack for Multimodal Language ModelsabstractMultimodal language models (LMs) have shown significant potential for applications across various domains but remain vulnerable to adversarial attacks. Current research in white-box or black-box settings generally struggles with unrealistic attack assumptions and limited efficacy of targeted attacks. This paper introduces CoGA, a novel gray-box collaborative adversarial attack method for multimodal LMs. Under our gray-box settings, attackers have access only to the victim model’s input encoders. With the guidance of different modalities, we perturb the embedding representations from encoders to disrupt the semantic alignment across modalities, ultimately causing inaccurate outputs on various downstream tasks. Specifically, we integrate text embeddings into the loss calculations of the image attack and utilize image embeddings to guide the ranking of vulnerable words and the selection of final samples. Extensive experiments demonstrate that our method achieves superior attack performance across diverse models and tasks, suggesting the shared vulnerability of multimodal LMs in confronting adversarial challenges. Our work provides new insights into the security of multimodal LMs, facilitating the deployment of more robust and secure models in practical applications. Feng Lin 0004, Gaojian Wang, Tiantian Liu 0002, Zhibo Wang 0001, Weizhi Meng 0001, Ajian Liu 0001, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2026 | SAPP: Achieving Semantic-Aware Differential Privacy for Spatiotemporal Trajectory Data PublishingabstractWith the increasing availability of large-scale spatiotemporal data from location-based services, trajectory publishing has become essential for data-driven analysis and intelligent applications. However, insufficient protection of trajectory location data may result in the disclosure of user privacy and social relationship information. To address this issue, we propose a semantic-aware privacy-preserving trajectory data publishing scheme (SAPP). First, a sliding-window algorithm is employed to extract stay points as key semantic locations and to generate a uniformly sampled set of candidate obfuscation points. Then, a semantic-aware scoring function is designed to probabilistically select candidate points that preserve semantics while avoiding sensitive regions. Furthermore, SAPP computes the sensitivity of each location based on semantic frequency and dynamically allocates the privacy budget. Finally, random noise is added to candidate trajectories using the Laplace mechanism. Through a dual-perturbation mechanism, spatial correlations in sensitive regions are weakened. Security analysis and experimental results further demonstrate that, compared with existing approaches, SAPP reduces TPPS and SFRR by up to 18% and 14%, respectively, indicating stronger resistance against trajectory inference and semantic leakage attacks while maintaining high data utility and time efficiency. Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001 |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2026 | ROMA: Enhancing Container OOM Resilience via Reinforced Isolation and Adaptive Shared Resource ReclamationabstractContainer-based virtualization is a cornerstone of modern cloud orchestration, but the shared-kernel architecture also introduces subtle risks to memory isolation. Our study shows that Linux cgroups and the default Out-of-Memory (OOM) mechanism lack sufficient container context when selecting victim processes. As a result, a malicious container may disrupt critical co-located services and leave behind unreclaimed shared resources, such as POSIX/SysV shared memory, message queues, semaphores, and tmpfs files. These residual resources can accumulate over time and eventually lead to denial-of-service conditions. To address this problem, we propose ROMA, an adaptive memory-governance framework for containerized environments. ROMA introduces container awareness into the OOM handling path while maintaining low runtime overhead. It combines eBPF-based monitoring with two lightweight LSM hooks to confine OOM victim selection to the offending container and to proactively reclaim shared resources left behind after OOM events. Extensive experiments show that ROMA incurs only a 6.94% throughput overhead across eight workloads. Under up to eight concurrent attackers, ROMA preserves isolation, avoids collateral kills, reclaims all leaked resources, and keeps recovery time within 6.9 seconds. In 24-hour runs with up to 64 containers, ROMA remains stable with low CPU and memory overhead, negligible event loss, and limited impact on benign services. Shaohu Li 0001, Jin Zhou 0017, Weizhi Meng 0001, Bei Gong, Yong Wang 0028 |
IEEE Trans. Serv. Comput. | 5 |
| 2025 | Reinforcement Learning-Based Autonomous Collision Avoidance for Ships in Realistic Physical Environments
Weizhi Meng 0001, Shaoming He |
ICA3PP (4) | 2 |
| 2025 | Traffic Accident Detection Via Fusion-Gru Based Future Frame Detection Box PredictionabstractWith the rapid development of autonomous driving and advanced driver assistance systems, efforts to enhance driving safety, especially in detecting traffic accidents when natural driving states are unclear, have increased significantly. Generally, traffic anomalies are defined as events that deviate from common occurrences and expected behaviors, such as vehicles and pedestrians disregarding traffic signals to cross arbitrarily, or vehicles abruptly stopping ahead. In real driving scenarios, timely detection of potential traffic accidents by autonomous vehicles is crucial for prompt response and accident prevention. In this work, we aim to address such challenges regarding traffic accident detection by proposing a future frame detection box prediction model based on Fusion-GRU for predicting future vehicle positions. In the evaluation based on two datasets, our results demonstrate that our approach can provide significant improvements in detection performance over similar studies. Weizhi Meng 0001, Rongxing Lu |
ICC | 2 |
| 2025 | Actions Speak Louder Than Words: Evidence-Based Trust Level Evaluation in Multi-agent Systems
Nikolaos Fotos, Koffi Ismael Ouattara, Dimitrios S. Karas, Ioannis Krontiris, Weizhi Meng 0001, Thanassis Giannetsos |
ICICS (2) | 5 |
| 2025 | Parallel FHE-Based Neural Network Inference with Knowledge Distillation for Efficient Privacy-Preserving Image Classification
Junyu Lin 0001, Jiageng Chen, Jichao Xiong, Weizhi Meng 0001, Chunhua Su |
KSEM (4) | 5 |
| 2025 | StressSentry-FHE: A Transformer-Based Privacy-Preserving Framework for Stress Detection Using Quantized Attention
Jichao Xiong, Jiageng Chen, Junyu Lin 0001, Chunhua Su, Weizhi Meng 0001 |
KSEM (2) | 6 |
| 2025 | Towards Practical Automotive Intrusion Detection Systems: An Adaptive Rule-Based Approach
Lucien Kiven Tamo, Brooke Kidmose, Weizhi Meng 0001, Thanassis Giannetsos |
NSS | 3 |
| 2025 | A Deep Reinforcement Learning Framework for Robust Maritime Collision Avoidance Under GPS Spoofing
Weizhi Meng 0001, Shaoming He, Wenjuan Li 0001 |
ProvSec | 2 |
| 2025 | A Dual-Stage Anomaly Detection Framework for Stealthy Attacks in 5G Core NetworksabstractThe N4 interface, which connects the Session Management Function (SMF) and the User Plane Function (UPF) via the PFCP protocol in the 5G core network, is vulnerable to attacks such as unauthorized access and signaling injection. These threats can lead to session interruptions and denial-of-service (DoS) attacks. Due to the stealthy nature of such anomalies, existing detection methods struggle with issues such as sample imbalance and ambiguous category boundaries. To address these challenges, this paper proposes a dual-stage anomaly detection framework based on the distribution characteristics of signaling. First, we statistically analyze the distributional differences between normal and abnormal PFCP signaling to uncover behavioral patterns and define precise categories of anomalies, each associated with a specific probabilistic model. Then, a Dual-Stage Abnormal Detection Framework (DSAF) is developed, integrating a KNN-based distance detector with a deep learning classifier to achieve hierarchical detection of abnormal signaling on the N4 interface. Experimental results on a real-world PFCP dataset demonstrate that the proposed method outperforms mainstream detection approaches in terms of accuracy, recall, and F1 score, providing solid theoretical and technical support for signaling security in 5G core networks. Weizhi Meng 0001, Zilong Wang 0001 |
TrustCom | 3 |
| 2025 | Intelligent routing methods for low-Earth orbit satellite networks based on machine learning: A comprehensive survey
Zheheng Rao, Shitong Xiao, Ye Yao 0003, Yanyan Xu 0003, Weizhi Meng 0001 |
Ad Hoc Networks | 6 |
| 2025 | Interpretable adversarial example detection via high-level concept activation vector
Jiaxing Li 0012, Yu-an Tan 0001, Weizhi Meng 0001, Yuanzhang Li 0001 |
Comput. Secur. | 4 |
| 2025 | FeatureBA: Hard label black box attack based on internal layer features of surrogate model
Jiaxing Li 0012, Yu-an Tan 0001, Runke Liu, Weizhi Meng 0001, Yuanzhang Li 0001 |
Expert Syst. Appl. | 4 |
| 2025 | Blockchain-Driven Distributed Edge Intelligence for Enhanced Internet of VehiclesabstractIn the evolving landscape of vehicular networks, it is crucial to ensure robust security and efficient data handling. In this work, we introduce a novel federated learning (FL) algorithm integrated within a distributed edge intelligence (DEI) framework, enhanced by a blockchain consensus mechanism, specifically designed for Internet of Vehicles (IoV) to enhance data privacy, efficiency, and system resilience. Motivated by the pressing need for improved data privacy and security in the IoV, our approach can not only prioritize these aspects but also enhance the efficiency and accuracy of distributed machine learning. The proposed consensus mechanism, by integrating Proof-of-Knowledge (PoK) with practical Byzantine fault tolerance (PBFT), is crafted to be lightweight, making it suitable for the dynamic and resource-constrained vehicular environments. Our evaluation findings demonstrate the algorithm’s superior performance and scalability, suggesting its applicability in diverse IoV scenarios and its potential to facilitate secure, robust, and efficient collaborative learning. Xiaofu Chen, Weizhi Meng 0001, Heyang Huang |
IEEE Internet Things J. | 2 |
| 2025 | Verifiable Aggregation for Heterogeneous Decentralized Identity in Internet of ThingsabstractBlockchain-based decentralized identity (DID) typically employs identity aggregation techniques to support efficient and trustworthy identity authentication in order to meet the requirements of the high volume of service requests in Internet of Things (IoT). Due to the lack of effective mechanisms for heterogeneous DID (H-DID) aggregation, a complete aggregated identity authentication often requires multiple rounds of signature verification for different identity attributes. However, this setting brings trust and privacy issues, and one notable threat is the potential disclosure of secret identity information through the linkage of heterogeneous identity attributes when enormous IoT devices/accesses are involved. In this article, we focus on trustworthy authentication of DID and propose a novel anonymous verifiable credential-based aggregation for h-DID (AVCA-hDID). Our AVCA-hDID model supports anonymous ownership verification of DIDs through label randomization, thereby effectively safeguarding identity privacy in IoT. AVCA-hDID involves identifier aggregation and attribute aggregation for H-DIDs, ensuring both authentication efficiency and balancing trustworthiness and adoptability. We analyze the security and unlinkablility of our proposed model and further experiment evaluation demonstrates the efficiency and effectiveness of AVCA-hDID. Kai Ding 0008, Tianxiu Xie, Keke Gai, Jing Yu 0007, Chennan Guo, Zhengkang Fang, Liehuang Zhu, Weizhi Meng 0001 |
IEEE Internet Things J. | 8 |
| 2025 | Privacy-Enhanced Federated WiFi Sensing for Health Monitoring in Internet of ThingsabstractThe development of the Internet of Things (IoT) has led to the widespread use of WiFi-enabled consumer electronic devices, which are now common in everyday life. These advancements in IoT have greatly improved data collection and analysis capabilities, especially for health monitoring applications. However, traditional centralized machine learning methods often fall short, raising significant privacy concerns and requiring extensive data collection, which is inefficient. To address these limitations within the distributed IoT environment, this article presents a federated learning (FL)-based WiFi sensing system specifically designed for health monitoring. By enabling local model training, our system prevents the sharing of sensitive data, thus reducing the risk of privacy breaches. We further enhance our system with a secret sharing mechanism coupled with model sparsification to significantly improve privacy. Additionally, our improved top-k model sparsification algorithm, equipped with adaptive residuals, reduces communication overhead while ensuring high accuracy. Extensive testing across various datasets and models confirms that our system outperforms existing benchmarks in terms of privacy protection and communication efficiency, marking a substantial advancement in health monitoring within the IoT. Zhuotao Lian, Qingkui Zeng, Zhusen Liu, Haoda Wang, Chuan Ma 0001, Weizhi Meng 0001, Chunhua Su, Kouichi Sakurai |
IEEE Internet Things J. | 6 |
| 2025 | Guest Editorial Special Issue on Security and Privacy of Intelligent VehiclesabstractIntelligent vehicles are systems tightly integrating computation, communication, and physical behavior. The recent proliferation of artificial intelligence, machine learning, the Internet of Things (IoT), and edge-fog–cloud computing envisions that intelligent vehicles are capable of innovative solutions to change our lifestyles. However, the potential benefits come along with new challenges and concerns on security and privacy. This special issue consists of 12 papers and covers broad research contributions, including 1) intrusion detection from in-vehicular networks to connected vehicles, drones, and global positioning systems; 2) authentication with matchmaking encryption, certificateless cryptography, and blockchains for Internet of Vehicles; 3) privacy protection with data sharing and cross-vehicle federated learning; and 4) secure data analysis supported by the cloud. The special issue seeks to assist theoretical analysis, system architecture design, emerging applications, and social impacts of intelligent vehicles. Chung-Wei Lin, Bo Chen 0028, Weizhi Meng 0001, Yu Chen 0002, Qi Zhu 0002 |
IEEE Internet Things J. | 3 |
| 2025 | AATM: An Anonymous Authentication Protocol for Time Span of Membership With Self-Blindness and AccountabilityabstractInternet of Things (IoT) devices using subscription services (e.g. connected vehicles accessing entertainment programs) often purchase membership credentials from service providers with limited usage counts or validity periods, we call them pay-per-use or time span of membership services. However, users’ access records, usage preferences, and habits are collected by network adversarys or membership providers for creating users’ profiles, targeted advertising, and even for being sold maliciously. To deal with these problems, lots of anonymous authentication protocols are proposed to provide users with pseudonyms to conceal their real identities. Although these protocols effectively prevent network adversarys from compromising users’ privacy, membership service providers can still gather users’ behavioral privacy via their membership credentials. Therefore, several scholars proposed k-times anonymous authentication protocols and self-blind credentials to enhance users’ privacy protection, but the k-times anonymous authentication protocols are only for pay-per-use membership services and the schemes of self-blind credentials are lack of regulating malicious users. To address these issues, this article proposes an anonymous authentication protocol for time span of membership (AATM) with self-blindness and accountability. Specifically, we utilize Structure Preserving Signatures on Equivalence Classes (SPS-EQ) and Signatures with Flexible Public Key (SFPK) to build accountable, self-blinding credentials that ensure that every time a user visits a member, he or she can create a brand new identity on their own, which not only prevents users from being linked by service providers, but also supports conditional fair regulation. Security and performance analyses show that AATM is better than the state-of-the-art schemes in terms of security and privacy-preserving capabilities, and its computation cost also meets the practical application requirements. Qiuyun Lyu, Xiwen Liang, Shaopeng Cheng, Yizhi Ren, Chengli Xu, Weizhi Meng 0001, Duohe Ma |
IEEE Internet Things J. | 7 |
| 2025 | BANN-TMGuard: Toward Touch-Movement-Based Screen Unlock Patterns via Blockchain-Enabled Artificial Neural Networks on IoT DevicesabstractInternet of Things (IoT) devices, such as smartphones, have become important to people’s everyday usage, especially the number of smartphone shipment has surpassed six billion and is forecast to further grow. The smartphone security is the top priority as people may store various sensitive information on these devices. Currently, phone unlock patterns, e.g., Android unlock patterns, are one of the main protection methods to protect smartphones from unauthorized access. However, many research studies have revealed that cyber-attackers can easily compromise this type of unlock mechanism, i.e., learning the pattern from the touch residue. In this work, we advocate that an additional security layer should be added to enhance the security of Android unlock patterns, and thus develop a touch movement-based unlock mechanism via blockchain-enabled artificial neural networks (ANNs), named BANN-TMGuard, which can examine the biometric features of a user’s touch movement as well as the input pattern. Further, BANN-TMGuard adopts blockchain technology to secure the robustness and reliability when building the ANN models. In the evaluation, we perform a user study with 100 participants in the aspects of authentication accuracy, time consumption and user feedback. As compared with similar schemes, our BANN-TMGuard demonstrates better results and is preferred by most participants in the user study. Weizhi Meng 0001, Wenjuan Li 0001, Andrei Nicolae Calugar |
IEEE Internet Things J. | 1 |
| 2025 | Equipment failure data trends focused privacy preserving scheme for Machine-as-a-Service
Zhengjun Jing, Yongkang Zhu, Quanyu Zhao, Yuanjian Zhou, Chunsheng Gu, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 6 |
| 2025 | Privacy-preserving and verifiable multi-task data aggregation for IoT-based healthcare
Xinzhe Zhang, Lei Wu 0011, Lijuan Xu 0001, Zhien Liu, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 7 |
| 2025 | ABA-LEP: Autonomous Bidirectional Authentication and Lightweight Encryption Protocol for drones under ARM architecture
Qian Zhou 0005, Jiayang Wu 0003, Weizhi Meng 0001 |
J. Inf. Secur. Appl. | 3 |
| 2025 | Verifiable decentralized identity-based meta-computing in Industrial Internet of Things (IIoT)
Kai Ding 0008, Tianxiu Xie, Keke Gai, Chennan Guo, Liangqi Lei, Dongjue Wang, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001 |
J. Syst. Archit. | 9 |
| 2025 | FedPG: a privacy-friendly and universal method for solving non-IID data in federated learning
Baolu Xue, Jiale Zhang 0001, Bing Chen 0002, Weizhi Meng 0001 |
Pattern Anal. Appl. | 4 |
| 2025 | PPSKSQ: Towards Efficient and Privacy-Preserving Spatial Keyword Similarity Query in CloudabstractThe growth of cloud computing has led to the widespread use of location-based services, such as spatial keyword queries, which return spatial data points within a given range that have the highest similarity in keyword sets to the user’s. As the volume of spatial data increases, providers commonly outsource data to powerful cloud servers. Because cloud servers are untrustworthy, privacy-preserving keyword query schemes have been proposed. However, existing schemes consider only location queries or exact keyword matching. To address these issues, we propose the Privacy-Preserving Spatial Keyword Similarity Query Scheme (PPSKSQ), designed to search for spatial data points with the highest similarity while protecting the privacy of outsourced data, query requests, and results. First, we design two sub-protocols based on improved symmetric homomorphic encryption (iSHE): iSHE-SC for secure size comparison and iSHE-SIP for secure inner product computation. Then, we encode range information and integrate it with a quadtree to construct a novel index structure. Additionally, we use the Jaccard to measure similarity in conjunction with the iSHE-SC protocol, transforming similarity comparison into a matrix trace operation. Finally, rigorous security analysis and extensive simulation experiments confirm the flexibility, efficiency, and scalability of our scheme. Changrui Wang, Lei Wu 0011, Lijuan Xu 0001, Hao Wang 0007, Wenying Zhang 0001, Weizhi Meng 0001 |
IEEE Trans. Cloud Comput. | 7 |
| 2025 | CAPE: Commitment-Based Privacy-Preserving Payment Channel Scheme in BlockchainabstractEnsuring scalability in cryptocurrency systems is significant in guaranteeing real-world utility along with the remarkable increment of cryptographic currency. As an alternative in solving scalability issue, payment channel allows users to deliver extensive offline transactions without uploading massive transaction details to the blockchain, such that increasing efficiency can be achieved. However, the implementation of payment channel still encounters privacy concerns when considering the publicly available transaction amounts and the potentials in mining associations between transaction parties. In this paper, we propose a novel payment channel scheme, entitledCommitment-basedAnonymousPayment ChannEl (CAPE), to facilitate unlimited off-chain bidirectional payments while guaranteeing participants’ privacy. The proposed scheme adopts zero-knowledge proof (zk-SNARKs) and verifiable timed (VTD) commitments to ensure the anonymity of the relationship between on-chain and off-chain transactions, privacy of transaction amounts, and security of balances. We comprehensively formalize security definitions and present rigorous proofs for each security attribute. Experiment results further demonstrate the practical viability of CAPE. Keke Gai, Yunwei Guo, Jing Yu 0007, Weilin Chan, Liehuang Zhu, Yinqian Zhang, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | A Scheme of Robust Privacy-Preserving Multi-Party Computation via Public VerificationabstractMulti-Party Computation (MPC), as a distributed computing paradigm, is considered to be a potential solution for providing privacy-preserving for applications following the client-server model. However, traditional MPC solutions cannot satisfy the publicly verifiable requirement of the client-server model. In this paper, we propose a blockchain-based verifiable MPC solution using Pedersen's threshold secret sharing and Lifted ElGamal encryption. We first build a data distribution method using Pedersen's threshold secret sharing and symmetric encryption to protect the privacy of inputs while ensuring robustness. Then, we propose a result processing algorithm using Lifted ElGamal encryption to safeguard the privacy of the outputs. Finally, we employ non-interactive zero-knowledge proof and Pedersen commitment to publicly verify the correctness of the encrypted outputs in the smart contract, enabling the detection of malicious parties. Theoretical analysis indicates that the proposed method can publicly verify the correctness of outputs without revealing plain-text inputs and outputs, which satisfy the privacy-preserving requirements of the client-server model. Experimental evaluations have demonstrated that our proposed approach is efficient regarding computation overhead, communication overhead, and response time in the output verification phase while achieving stronger privacy and robustness. Keke Gai, Dongjue Wang, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | StealthPath: Privacy-Preserving Path Validation in the Data Plane of Path-Aware NetworksabstractNetwork path validation aims to give more control over the forwarding path of data packets in a path-aware network, which shields the network from security threats and allows end hosts to receive better services. Therefore, network path validation becomes a vital primitive for secure and reliable Internet services in the next generation networks. The path validation enables end hosts and intermediate router nodes to check whether a packet has followed the intended path. However, the existing solutions fail to protect path privacy and incur significant bandwidth and computation overhead on packet transferring, which degrades packet delivery performance. In this paper, we propose the StealthPath to protect path privacy and improve delivery efficiency. Firstly, StealthPath uses lightweight cryptographic primitives to generate nested proofs and ensures all nodes on the path to check the compliance of the forwarding path efficiently. Secondly, StealthPath hides the forwarding path in the proofs and reduces the proof size from linear to constant, which protects the path information and path length, and decreases the bandwidth consumption. Moreover, StealthPath allows on-path nodes to extract their proofs and the next hop address from proof without leaking on-path node index. Finally, StealthPath is proved to resist various attacks and preserves the path privacy. The experiments show that StealthPath saves nearly 60% header size and bandwidth, and is more efficient than state-of-the-art schemes. Yuan Su, Rongxing Lu, Zhou Su 0001, Weizhi Meng 0001, Meng Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Blockchain-Assisted Searchable Integrity Auditing for Large-Scale Similarity Data With ArbitrationabstractData integrity auditing technology serves as an essential tool to ensure the data's integrity with the popularity of remote storage. However, existing data integrity auditing models are unsuitable for a large number of files with interrelationships and heavily depend on a centralized Third-Party Auditor (TPA). To address these issues, in this paper we propose a blockchain-assisted searchable integrity auditing scheme for large-scale similarity data. To broaden the scope of the auditing model and enhance its ability to handle interconnected files, we utilize the keyword to design a search index and a trapdoor to achieve authenticator searchability for the interconnected files. The integrity of the searching result from the cloud side can be guaranteed at the same time. To reduce reliance on centralized TPA and enhance the credibility and transparency of auditing, we integrate blockchain technology along with smart contracts to replace TPA and achieve multitask auditing. We adopt a certificateless cryptosystem to generate the authenticator, while considering the cost reduction. Moreover, an arbitrator is proposed to achieve fairness judge. Theoretical and security analysis demonstrate that the proposed scheme is efficient and secure, making it a promising solution for data auditing in a wide range of applications. Ying Miao 0002, Keke Gai, Yu-an Tan 0001, Liehuang Zhu, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | High Capacity Reversible Data Hiding in Encrypted 3D Mesh Models Based on Dynamic Prediction and Virtual ConnectionabstractIn recent years, reversible data hiding in encrypted domain (RDH-ED) has garnered considerable interest among researchers, resulting in the development of high-performance methods based on various carriers. However, the challenge of enhancing the data embedding capacity while ensuring reversibility becomes increasingly pronounced when the carrier is a three-dimensional (3D) model. In this paper, a high capacity RDH-ED method based on dynamic prediction and virtual connection for 3D models is proposed. Unlike existing methods that partition the vertices in the model into embeddable and prediction sets, where each vertex can only serve one function, the proposed dynamic prediction mechanism constructs a data embedding order set by leveraging the connectivity relationships between vertices. This allows each vertex within the set to both embed data and provide predictions, significantly increasing the proportion of embeddable vertices. Moreover, the proposed method is the first work to consider independent vertices within the model and integrates a novel virtual connection approach with the dynamic prediction process, enabling all independent vertices to participate in data embedding and prediction, thereby further enhancing the data embedding capacity. Experimental results demonstrated that the proposed method significantly outperforms other state-of-the-art methods in terms of data embedding capacity while ensuring reversibility. Ke Wang 0039, Ye Yao 0003, Yanzhao Shen, Fengjun Xiao, Yizhi Ren, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | FedAMM: Federated Learning Against Majority Malicious Clients Using Robust AggregationabstractAs a collaborative framework designed to safeguard privacy,Federated Learning(FL) seeks to protect participants’ data throughout the training process. However, the framework still faces security risks from poisoning attacks, arising from the unmonitored process of client-side model updates. Most existing solutions address scenarios where less than half of clients are malicious, i.e., which leaves a significant challenge to defend against attacks when more than half of participants are malicious. In this paper, we propose a FL scheme, named FedAMM, that resists backdoor attacks across various data distributions and malicious client ratios. We develop a novel backdoor defense mechanism to filter out malicious models, aiming to reduce the performance degradation of the model. The proposed scheme addresses the challenge of distance measurement in high-dimensional spaces by applyingPrincipal Component Analysis(PCA) to improve clustering effectiveness. We borrow the idea of critical parameter analysis to enhance discriminative ability in non-iid data scenarios, via assessing the benign or malicious nature of models by comparing the similarity of critical parameters across different models. Finally, our scheme employs a hierarchical noise perturbation to improve the backdoor mitigation rate, effectively eliminating the backdoor and reducing the adverse effects of noise on task accuracy. Through evaluations conducted on multiple datasets, we demonstrate that the proposed scheme achieves superior backdoor defense across diverse client data distributions and different ratios of malicious participants. With 80% malicious clients, FedAMM achieves low backdoor attack success rates of 1.14%, 0.28%, and 5.53% on MNIST, FMNIST, and CIFAR-10, respectively, demonstrating enhanced robustness of FL against backdoor attacks. Keke Gai, Dongjue Wang, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | ECGSH: An Efficient Certificateless Group Signcryption-Based Homomorphic in Industrial IoTabstractWith the growth of the Industrial Internet of Things (IIoT), millions of smart devices are transmitting and processing data globally. However, this extensive interconnectivity also poses significant security challenges, particularly in data transmission. Traditional security mechanisms often incur high computational costs and long processing times, which are impractical for resource-constrained devices. In this paper, we propose an efficient and secure data processing and transmission scheme for the IIoT called ECGSH. This scheme combines certificateless signcryption and homomorphic encryption to enable homomorphic processing in an encrypted state, thus enhancing both security and flexibility. Moreover, it reduces the complexity of large-scale data processing by eliminating bilinear pair computations. The ECGSH scheme also supports homomorphic data transmission in the IIoT. A rigorous security analysis proves that the scheme has the properties of confidentiality, non-repudiation, and forward security under the random oracle model. An attack resistance analysis proves that the scheme can effectively resist man-in-the-middle (MITM) attacks, replay attacks, and eavesdropping attacks. The performance evaluation demonstrates that ECGSH excels in terms of security, computational efficiency, and communication overhead. It requires at most 31% CPU utilization, and less than 1.2% memory footprint on IIoT hardware, making it particularly suitable for IIoT environments with limited resources and high transmission costs. Bei Gong, Mowei Gong, Zhe Li 0052, Weizhi Meng 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Enhancing EEG-Based Authentication With Transformer in Internet of ThingsabstractWith the rapid growth of Internet of Things (IoT) and edge computing platforms, the Internet of Medical Things (IoMT) has become popular and important in healthcare industry, i.e., there is an increase of brainwave headsets and headbands. However, the security and privacy of shared data can be easily compromised if an attacker can access the IoMT devices and check all the data. There is a need to authenticate users before they can use the healthcare devices. For this reason, Electroencephalography (EEG) based authentication is a necessary security solution. In recent years, EEG-based authentication has witnessed significant advancements, but traditional models face challenges in capturing the complex spatial and temporal dependencies present in EEG signals. This work aims to address these limitations and explore the effect of Transformer model in the domain of EEG-based authentication. In particular, we devise a modified Vision Transformer model (ViT) to handle the specific characteristics of EEG data, such as spatial and temporal dependencies. In the evaluation, we compare our approach with the similar methods in the literature and examine the effect of fine-tune based on two datasets. The results demonstrate that our approach can effectively capture long-range dependencies and outperform conventional models. Chunxue Li, Weizhi Meng 0001, Wenjuan Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Blockchain-Empowered Keyword Searchable Provable Data Possession for Large Similar DataabstractProvable Data Possession (PDP) is an alternative technique that guarantees the integrity of remote data. However, most current PDP schemes are inapplicable to similarity-like data checking with the same attribute, i.e., when there are numerous similar files to be checked by Data Owners (DOs). Some traditional models cannot resist the corrupt auditors who always generate biased challenge information. Besides, a copy-summation attack exists in some schemes, which means the Cloud Server (CS) can bypass the verification by storing the median value instead of initial data via summation operation. To address the issues above, in this work, we propose a keyword searchable PDP scheme for large similar data checking. To achieve searchability, we introduce the notion of a keyword in PDP and design a specific index structure to match the authenticator. The scheme enables all matched files to be auditable and verifiable, while guaranteeing privacy protections. Unlike existing methods, our Third Party Auditor (TPA) checks all similar data containing the same keyword simultaneously. We utilize unpredictable yet verifiable public information on the blockchain to generate challenge information, rather than relying on a centralized TPA. The proposed scheme can resist copy-summation attacks. Theoretical analysis demonstrates that the proposed scheme satisfies the security requirements, and our evaluations demonstrate its efficiency. Ying Miao 0002, Keke Gai, Jing Yu 0007, Yu-an Tan 0001, Liehuang Zhu, Weizhi Meng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | FlashAttest: Self-Attestation for Low-End Internet of Things via Flash DevicesabstractRemote Attestation (RA) is an effective security service that allows a trusted party (verifier) to initiate the attestation routine on a potentially untrusted remote device (prover) to verify its correct state. Despite their usefulness, traditional challenge-response remote attestation protocols suffer from certain limitations, such as challenges in scaling attestation collection and the forced suspension of normal operation during attestation. Self-attestation tackles these issues by enabling the prover to measure its own state asynchronously with the verifier’s attestation request. Existing self-attestation methods rely on hybrid architectures to provide the required security properties, which may not be compatible with low-end Internet of Things (IoT) devices due to hardware limitations. In addition, these protocols currently lack formal verification of design correctness. In this paper, we present FlashAttest, a formally verified self-attestation protocol for low-end IoT devices. FlashAttest leverages the flash device to fulfill the security properties required by self-attestation, eliminating the requirement for hardware modifications. In particular, FlashAttest allows the prover to initiate the attestation routine and guarantee the trustworthiness of the results based on the verified software-based security architecture. By collaborating with the flash device during attestation to generate timestamped reports, FlashAttest enables the verifier to collect and verify the legitimacy of the attestation results. More importantly, FlashAttest achieves strong security guarantees supported by a formally verified design using the Tamarin prover. We implement and evaluate FlashAttest on MSP430 architecture, showing a reasonable overhead in terms of memory footprint, communication overhead, runtime and power consumption. Compared with state-of-the-art self-attestation schemes, our approach achieves similar runtime overhead, low energy consumption, and reasonable memory overhead while eliminating the need for hardware modifications. The results confirm the suitability of FlashAttest for low-end devices. Zheng Zhang 0060, Jingfeng Xue, Weizhi Meng 0001, Xu Qiao, Yuanzhang Li 0001, Yu-an Tan 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | SSLDefender: Backdoor Defense in Self-Supervised Learning via Distillation-Guided UnlearningabstractSelf-supervised learning utilizes unlabelled data to train encoders, acquiring high-quality representations of input data, significantly advancing the field of computer vision. However, recent studies have demonstrated that self-supervised learning suffers from numerous adversarial attacks. Among them, backdoor attack is one of the focal issues, where downstream classifiers inherit the backdoor behavior of the pre-trained encoder. Existing defense methods against backdoor attacks primarily focus on supervised learning, which heavily relies on labeled data and cannot be directly migrated to self-supervised scenarios. Furthermore, defense methods for self-supervised backdoor aims to separate poisoned samples on assumed small-scale datasets and retraining to obtain a clean encoder. However, these approaches are useless against encoders that have been implanted with a backdoor. To address these issues, we propose SSLDefender, a novel image-based backdoor mitigation method specially designed for self-supervised learning, which can remove backdoor attributes directly from the backdoor encoder. Specifically, we employ a trigger recovery method based on mutual information maximization to efficiently obtain trigger that resembles the target backdoor’s influence. Additionally, we design a distillation-guided unlearning strategy to purify backdoor features steadily and ensure the retention of clean knowledge to prevent overforgetting. Extensive experimental evaluations on six benchmark datasets demonstrate that SSLDefender can successfully reduce the attack success rate of Badencoder to around 2% while maintaining high model accuracy on the main task. Its performance surpasses state-of-the-art methods. Jiale Zhang 0001, Wanquan Zhu, Kai Wang 0062, Xiaobing Sun 0001, Weizhi Meng 0001, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Lightweight Continuous Authentication via IMU Fingerprinting for V2XabstractInertial measurement unit (IMU) fingerprinting is a promising physical authentication technique based on hardware imperfections produced during sensor manufacturing. This paper presents a two-stage feature extraction process that combines feature selection and mapping; the proposed approach is tailored for the lightweight vehicle-to-everything (V2X) application scenario. Specifically, the selected features are transformed into images via Gramian angular difference field (GADF), Gramian angular summation field (GASF), and Markov transition field (MTF) mappings, as well as feature extraction implemented via a convolutional neural network (CNN). Owing to the advances provided by the proposed scheme, a lightweight feature extraction system achieves satisfactory accuracy levels above 99.10% with fewer sample data and a short training time. The effectiveness and robustness of the developed approach were validated under various driving conditions via 20 IMU sensors, Arduino, and a Raspberry Pi across 20 vehicles. Additionally, tests conducted across different deep learning models demonstrated the generalizability of the proposed preprocessing and mapping methods. Bei Gong, Zhe Li 0052, Mowei Gong, Weizhi Meng 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | EASTER: Embedding Aggregation-Based Heterogeneous Models Training in Vertical Federated LearningabstractVertical Federated Learning (VFL) allows collaborative machine learning without sharing local data. However, existing VFL methods face challenges when dealing with heterogeneous local models among participants, which affects optimization convergence and generalization of participants' local knowledge aggregation. To address this challenge, this paper proposes a novel approach calledEmbeddingAggregation-based HeterogeneousModelsTraining in Vertical Federated Learning(EASTER). EASTER focuses on aggregating the local embeddings of each participant's knowledge during forward propagation. We propose an embedding protection method based on lightweight blinding factors, which injects the blinding factors into the local embedding of the passive party. However, the passive party does not own the sample labels, so the local model's gradient cannot be calculated locally. To overcome this limitation, we propose a new method in which the active party assists the passive party in computing its local heterogeneous model gradients. Theoretical analysis and extensive experiments demonstrate that EASTER can simultaneously train multiple heterogeneous models and outperform some recent methods in model performance. For example, compared with the state-of-the-art method, the model accuracy of EASTER was improved by 7.22% under the CIFAR-10 dataset. Shuo Wang 0026, Keke Gai, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001, Bin Xiao 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | AggNoteBot: A Robust Botnet Building Using Aggressive Cloud Notes
Yi-Ning Liu 0002, Yanze Kang, Weizhi Meng 0001 |
ACISP (3) | 5 |
| 2024 | Towards Alarm Reduction in Intrusion Detection: A Recurrent Neural Network ApproachabstractIntrusion detection systems (IDSs) are one of the most commonly deployed systems to detect cyber attacks. One major problem of IDSs is the large amount of false alarms (or false positives) generated in a practical network. In recent decades, many researchers utilized machine learning techniques to help reduce false alarms, i.e., deep learning is quite popular in recent years. However, most research studies mainly consider one dataset in the evaluation, and it is unclear whether the approach can be scalable for other network settings. Motivated by such challenges, in this work, we introduce a hybrid deep learning-based false alarm filtration method, by combining a modern recurrent neural network (RNN) and a concise alert correlation method to reduce false positives for an IDS. To evaluate the performance, we consider three publicly available datasets such as DARPA, UNSW-NB and CSE-CIC-IDS. Experimental results demonstrate that our approach can reduce up to 99.35% false alarms in the best case. Alexander Gödeke, Weizhi Meng 0001, Yu Wang 0017 |
HPCC | 2 |
| 2024 | Incremental Learning Strategy with Multi-dimensional Knowledge Distillation for One-stage Object DetectionabstractIn practical applications, object detectors often encounter unknown classes samples. As object detection datasets undergo continuous development, the need arises for object detectors to adeptly recognize an escalating array of new classes while retaining the original detection capability. This paper introduces a new class incremental object detection learning framework with multi-dimensional knowledge distillation, using Yolov5 as the foundational detection model. Specifically, we utilize local feature distillation, attention distillation and global feature distillation to preserve information in the original model's feature maps. Additionally, we employ response distillation to ensure the model remains responsive to previous classes. In comparison to the state-of-the-art methods, our approach achieves higher overall accuracy on PASCAL VOC 2007. Especially in the “19+1” incremental task, our approach gets the highest [email protected] of 0.697 with a minimum mean AP decline rate of 4.45%. For the “4+3” and “6+1” tasks on KITTI, our approach preserves the model's responsiveness to the original task more effectively while achieving the highest overall accuracy. Xuejiao Liu 0001, Xueshuang Xiang, Yu-an Tan 0001, Weizhi Meng 0001 |
INDIN | 5 |
| 2024 | An eID-Based Privacy-Enhanced Public Transportation Ticket System
Kanagaratnam Anojjan, Weizhi Meng 0001, Brooke Kidmose, Yu Wang 0017 |
ISPEC | 2 |
| 2024 | A Comparative Analysis of Phishing Tools: Features and Countermeasures
Rishikesh Sahay, Weizhi Meng 0001, Wenjuan Li 0001 |
ISPEC | 2 |
| 2024 | can-fp: An Attack-Aware Analysis of False Alarms in Automotive Intrusion Detection ModelsabstractThe automotive controller area network (CAN) bus functions as the communications backbone of automobiles around the globe. Unfortunately, the CAN bus was developed for the closed-system vehicles of the 1980s, not the inter-connected—even autonomous—vehicles hitting the roads today, meaning that the CAN bus is extraordinarily insecure. Much of the literature points to automotive intrusion detection as the solution; it is lightweight and does not involve re-engineering the CAN bus. That said, in safety-critical automotive environments, we can expect to see millions of messages every ten minutes; as such, accuracy is paramount. A false positive rate (FPR) of 0.00001 corresponds to about ten false positives every ten minutes. Therefore, in this paper, we investigate false positives generated by the machine learning models that constitute automotive intrusion detection systems (IDSs). In particular, we explore the timestamp and time delta features to determine if they have a positive or negative impact on the FPR. Then, we look into the patterns of false positives, and we discover that many false positives are produced during actual attacks. Essentially, when legitimate messages are interlaced with attack messages, anomalous patterns are produced, and legitimate messages are flagged as anomalous. The IDS has done its job and detected an attack-it simply misidentified legitimate messages as part of the attack. When it comes to automotive attacks, many of the mitigation strategies do not require precise identification of the attack messages; that is, it is enough to know that an attack is ongoing. As such, we exclude false positives that occur during attack conditions from the FPR, and we examine the results. We find that, for a number of machine learning models, discounting attack-related false positives can significantly improve the FPR. Brooke Kidmose, Weizhi Meng 0001 |
PST | 2 |
| 2024 | Pitfalls of Data Masking Techniques: Re-identification Attacks
Samir Hodzic, Andreas B. Kidmose, Brooke Kidmose, Lars R. Knudsen, Weizhi Meng 0001 |
SecureComm (3) | 5 |
| 2024 | User Authentication Based on the Integration of Musical Signals and Ear Canal AcousticsabstractThis study presents a new biometric authentication system leveraging ear canal acoustic features for secure identity authentication. The proposed system can capture ear acoustics using an earphone integrated with a microphone, with musical signals as the probing signal. By taking the Ear Canal Transfer Function (ECTF) as the primary feature, we develop and implement a prototype that integrates data collection and deep feature extraction using particularly modified earphones. We then employ a convolutional neural network (CNN) to address the challenge of feature space overlap due to the diverse frequency components in musical signals. Our evaluation demonstrates the feasibility and the robustness of our method by using ear canal acoustics for user authentication, highlighting its potential for widespread application in security-sensitive environments. Tongxi Chen, Weizhi Meng 0001, Wenjuan Li 0001 |
TrustCom | 2 |
| 2024 | DAR-DRL: A dynamic adaptive routing method based on deep reinforcement learning
Zheheng Rao, Yanyan Xu 0003, Ye Yao 0003, Weizhi Meng 0001 |
Comput. Commun. | 4 |
| 2024 | can-train-and-test: A curated CAN dataset for automotive intrusion detectionabstractWhen it comes to in-vehicle networks (IVNs), the controller area network (CAN) bus dominates the market; automobiles manufactured and sold worldwide depend on the CAN bus for safety-critical communications between various components of the vehicle (e.g., the engine, the transmission, the steering column). Unfortunately, the CAN bus is inherently insecure; in fact, it completely lacks controls such as authentication, authorization, and confidentiality (i.e., encryption). Therefore, researchers have travailed to develop automotive security enhancements. The automotive intrusion detection system (IDS) is especially popular in the literature—due to its relatively low cost in terms of money, resource utilization, and implementation effort. That said, developing and evaluating an automotive IDS is often challenging; if researchers do not have access to a test vehicle, then they are forced to depend on publicly available CAN data—which is not without limitations. Lack of access to adequate CAN data, then, becomes a barrier to entry into automotive security research. We seek to lower that barrier to entry by introducing a new CAN dataset to facilitate the development and evaluation of automotive IDSs. Our datasets—dubbed can-dataset, can-log, can-csv, can-ml, and can-train-and-test—provide CAN data from four different vehicles produced by two different manufacturers. The attack captures for each vehicle model are equivalent, enabling researchers to assess the ability of a given IDS to generalize to different vehicle models and even different vehicle manufacturers. Our datasets contain replayable .log files as well as labeled and unlabeled .csv files, thereby meeting a variety of development and evaluation needs. In particular, the can-train-and-test dataset offers nine unique attacks, ranging from denial of service (DoS) to gear spoofing to standstill; as such, researchers can select a subset of the attacks for training and save the remainder for testing in order to assess a given IDS against unseen attacks. Many of our attacks, particularly the spoofing-related attacks, were conducted during live, on-the-road experiments with real vehicles. These attacks have known physical impacts. As a benchmark, we pit a number of machine learning IDSs against our dataset and analyze the results. We present our datasets—especially can-train-and-test—as a contribution to the existing catalogue of open-access datasets in hopes of filling in the gaps left by those datasets. Brooke Kidmose, Weizhi Meng 0001 |
Comput. Secur. | 2 |
| 2024 | Deep video inpainting detection and localization based on ConvNeXt dual-stream networkabstractCurrently, deep learning-based video inpainting algorithms can fill in a specified video region with visually plausible content, usually leaving imperceptible traces. Since deep video inpainting methods can be used to maliciously manipulate video content, there is an urgent need for an effective method to detect and localize deep video inpainting. In this paper, we propose a dual-stream video inpainting detection network, which includes a ConvNeXt dual-stream encoder and a multi-scale feature cross-fusion decoder. To further explore the spatial and temporal traces left by deep inpainting, we extract motion residuals and enhance them using 3D convolution and SRM filtering. Furthermore, we extract filtered residuals using LoG and Laplacian filtering. These residuals are then entered into ConvNeXt, thereby learning discriminative inpainting features. To enhance detection accuracy, we design a top-down pyramid decoder that aims at deep fusion of multi-dimensional multi-scale features to fully exploit the information of different dimensions and levels in detail. We created two datasets containing state-of-the-art video inpainting algorithms and conducted various experiments to evaluate our approach. The experimental results demonstrate that our approach outperforms existing methods and attains a competitive performance despite encountering unseen inpainting algorithms. Ye Yao 0003, Tingfeng Han, Yizhi Ren, Weizhi Meng 0001 |
Expert Syst. Appl. | 5 |
| 2024 | High invisibility image steganography with wavelet transform and generative adversarial network
Ye Yao 0003, Yizhi Ren, Weizhi Meng 0001 |
Expert Syst. Appl. | 5 |
| 2024 | Practical Privacy-Preserving Scheme With Fault Tolerance for Smart GridsabstractIn smart grid services, the leakage of crowdsourced consumption data on smart meters (SMs) poses potential risks of privacy disclosure and data misuse. Existing solutions, which rely on complex encrypted computations, are often impractical for resource-limited SMs due to their high computation and storage resource requirements. To address these challenges, this article proposes a practical privacy-preserving scheme with fault tolerance for smart grid services named 3PFT. In our scheme, we employ a masking approach that ensures user privacy preservation on SMs while consuming minimal resources. Unlike existing masking schemes, 3PFT provides fault tolerance, supports complex data analysis tasks, and mitigates vulnerabilities to key leakage attacks. To achieve these objectives, we incorporate a secret sharing technique into the masking approach, enabling the recovery of the master key using only a portion of the data. Additionally, we design a flexible data aggregation protocol for 3PFT, facilitating the execution of diverse data analysis missions, such as load forecasting, in smart grids. Furthermore, we introduce a negotiation-based key update method to enhance the protocol’s forward security and alleviate the additional overhead on SMs. Finally, we provide a rigorous proof of privacy preservation and fault tolerance for our scheme and validate its feasibility and effectiveness through extensive simulations. Ning Lu 0005, Zhou Su 0001, Weizhi Meng 0001 |
IEEE Internet Things J. | 6 |
| 2024 | Scalable Graph-Aware Edge Representation Learning for Wireless IoT Intrusion DetectionabstractNetwork Intrusion Detection Systems (NIDSs) have emerged as a frontline defense against potential attacks in wireless Internet of Things (IoT) networks. However, existing machine learning methods follow an unstructured data processing patterns and can barely incorporate all information due to the network dynamicity as well as data imbalance. In this study, we propose Graph Isomorphism Network model based on Edge (GINE), an innovative graph-based algorithm tailored to pinpoint malicious network traffic within wireless IoT networks. Specifically, we initiate by presenting the wireless IoT network graph, capturing the global topological interactions of its edges. Subsequently, we design an edge representation learning algorithm, capable of encoding network data frames in a discerning pattern-aware manner. Moreover, we integrate a data interpolation module into the edges of our structured graph data targeting at data imbalance, which fosters a more balanced distribution across the various classes of edges. Our empirical analysis on select wireless IoT intrusion datasets shows GINE’s superiority, consistently outperforming state-of-the-art methods in classification metrics, including accuracy, F1-Score, False Alarm Rate, etc. Through a simulated wireless environment, we demonstrate GINE’s robust scalability, even in unpredictable wireless networks. Qinnan Hu, Weizhi Meng 0001, Witold Pedrycz, Zhou Su 0001 |
IEEE Internet Things J. | 4 |
| 2024 | Traffic Sign Recognition Using Optimized Federated Learning in Internet of VehiclesabstractTraffic sign recognition (TSR) is vital for vehicle safety and navigation, especially in the era of autonomous cars. Internet of Vehicles (IoV) provide a promising infrastructure for vehicular networks due to their agility and interoperability. However, privacy concerns and network restrictions hinder the collection of massive data from distributed automotive sensors in IoV. To address these challenges, this article proposes the application of federated learning (FL) and model sparsification to optimize traffic sign recognition (TSR) in autonomous vehicles. FL enables decentralized learning while preserving data privacy, and model sparsification significantly reduces communication costs. Furthermore, we incorporate the Adam optimizer for local training, ensuring efficient model optimization on each vehicle. Experimental results demonstrate the effectiveness of our approach, with improved TSR performance while mitigating privacy risks and enhancing communication efficiency. This research contributes to the advancement of TSR in IoV by introducing FL, model sparsification, and the use of the Adam optimizer for local training, facilitating efficient and privacy-preserving vehicular network learning. Zhuotao Lian, Qingkui Zeng, Weizheng Wang 0001, Dequan Xu, Weizhi Meng 0001, Chunhua Su |
IEEE Internet Things J. | 5 |
| 2024 | Traceable and Privacy-Preserving Authentication Scheme for Energy Trading in V2G NetworksabstractWith the rapid popularization of electric vehicles (EVs) in modern society, vehicle-to-grid (V2G) has been widely concerned as an emerging technology. However, various privacy and security issues arise frequently in the energy interaction between EVs and the smart grid (SG), such as the lack of secure authentication and disclosure of EVs’ identity. Although many crypto-based schemes are proposed to achieve secure authentication of V2G networks, they rely on certificate authority (CA) or private key generator (PKG). In response to this problem, some certificateless signature-based schemes have been proposed. Nevertheless, most of them are not suitable for V2G networks due to the high computational cost and communication overhead, and they do not consider the problem of tracking illegal signatures. Therefore, we propose a traceable and privacy-preserving authentication scheme with supporting batch verification for energy trading in V2G networks. We use the method of binary tree level traversal to quickly track EVs with illegal signatures, which can reduce computational resources. Besides, the proposed scheme is easier to be deployed in real world because of avoiding the problems of key escrow and certificate management. Finally, we conduct a comprehensive security analysis and performance evaluation regarding our scheme. We prove that our proposed scheme is secure under the random oracle model (ROM), and the experimental results illustrate that the proposed scheme has less computational cost and communication overhead as compared to the existing schemes. Gang Shen 0003, Chengliangyi Xia, Yumei Li 0003, Hua Shen 0002, Weizhi Meng 0001, Mingwu Zhang |
IEEE Internet Things J. | 5 |
| 2024 | Delayed packing attack and countermeasure against transaction information based applications
Yuan Su, Zhou Su 0001, Yuyi Wang 0001, Weizhi Meng 0001, Yinghua Shen |
Inf. Sci. | 6 |
| 2024 | TridentShell: An enhanced covert and scalable backdoor injection attack on web applicationsabstractWeb backdoor attack is an increasingly prevalent network attack that can result in substantial losses for webmasters. During a cyber-attack, system vulnerabilities and web application flaws are usually used to implant a web shell inside victim servers. To mitigate the many threats posed by web shells, research has focused on static feature detection, which has evolved rapidly in recent years. However, static feature detection has inherent limitations and security risks. In this paper, we present TridentShell, a novel web backdoor attack that can inject an invisible backdoor into a victim server without leaving any traces of the attack. Furthermore, TridentShell can circumvent almost all static detection methods. Unlike existing approaches, which leverage traditional encryption and obfuscation technologies to avoid detection, our proposed attack is intended to blend into the web application server naturally. In this work, we introduce enhancements to the original TridentShell, which is not traceable—in theory—since it uses a blockchain-based decentralized C&C server with better presentation capability. The experimental results show that our TridentShell can effectively compromise five different types of Java application servers (covering around 87% Java application servers in the market), and can scrub any attack traces from the server, making it especially difficult to detect. Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002 |
J. Netw. Comput. Appl. | 2 |
| 2024 | Blockchain-based privacy-preserving public key searchable encryption with strong traceability
Jinguang Han, Weizhi Meng 0001, Jianchang Lai, Ge Wu 0001 |
J. Syst. Archit. | 3 |
| 2024 | Flash controller-based secure execution environment for protecting code confidentialityabstractWith the rapid evolution of Internet-of-Things (IoT), billions of IoT devices have connected to the Internet, collecting information via tags and sensors. For an IoT device, the application code itself and data collected by sensors can be of great commercial value. It is challenging to protect them because IoT devices are prone to compromise due to the inevitable vulnerabilities of commodity OSes. Trusted Execution Environment (TEE) is one of the solutions that protects sensitive data by running security-sensitive workloads in a secure world. However, this solution does not work for most of the IoT devices that are limited in resources. In this paper, we propose Flash Controller-based Secure Execution Environment (FCSEE), an approach to protect security-sensitive code and data for IoT devices using the flash controller. Our approach constructs a secure execution environment on the target flash memory by modifying the execution logic of its controller, leveraging it as a co-processor to execute security-sensitive workloads of the host device. By extending the original functionality of the flash firmware, FCSEE also provides several much-needed security primitives to protect sensitive data. We constructed a prototype based on a Trans-Flash (TF) card and implemented proof of its confidentiality. Our evaluation results indicate that FCSEE can confidentially execute security-sensitive workloads from the host and efficiently protects its sensitive data. Zheng Zhang 0060, Jingfeng Xue, Yuhang Zhao 0003, Weizhi Meng 0001 |
J. Syst. Archit. | 5 |
| 2024 | GPOD: An Efficient and Secure Graphical Password Authentication System by Fast Object Detection
Palash Ray, Debasis Giri, Weizhi Meng 0001, Soumyadeep Hore |
Multim. Tools Appl. | 3 |
| 2024 | Distributed Robust Artificial-Noise-Aided Secure Precoding for Wiretap MIMO Interference ChannelsabstractWe propose a distributed artificial noise-assisted precoding scheme for secure communications over wiretap multi-input multi-output (MIMO) interference channels, where K legitimate transmitter-receiver pairs communicate in the presence of a sophisticated eavesdropper having more receive-antennas than the legitimate user. Realistic constraints are considered by imposing statistical error bounds for the channel state information of both the eavesdropping and interference channels. Based on the asynchronous distributed pricing model, the proposed scheme maximizes the total utility of all the users, where each user’s utility function is defined as the secrecy rate minus the interference cost imposed on other users. Using the weighted minimum mean square error, Schur complement and sign-definiteness techniques, the original non-concave optimization problem is approximated with high accuracy as a quasi-concave problem, which can be solved by the alternating convex search method. Simulation results consolidate our theoretical analysis and show that the proposed scheme outperforms the artificial noise-assisted interference alignment and minimum total mean-square error-based schemes. Zhengmin Kong, Shaoshi Yang, Li Gan, Weizhi Meng 0001, Tao Huang 0008, Sheng Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Decentralized Threshold Signatures With Dynamically Private AccountabilityabstractThreshold signature is a fundamental cryptographic primitive used in many practical applications. As proposed by Boneh and Komlo (CRYPTO’22), TAPS is a threshold signature that is a hybrid of privacy and accountability. It enables a combiner to combine$t$signature shares while revealing nothing about the threshold$t$or signing quorum to the public and asks a tracer to track a signature to the quorum that generates it. However, TAPS has three disadvantages: it 1) structures upon a centralized model, 2) assumes that both combiner and tracer are honest, and 3) leaves the tracing unnotarized and static. In this work, we introduce Decentralized, Threshold, dynamically Accountable and Private Signature (DeTAPS) that provides decentralized combining and tracing, enhanced privacy against untrusted combiners (tracers), and notarized and dynamic tracing. Specifically, we adopt Dynamic Threshold Public-Key Encryption (DTPKE) to dynamically notarize the tracing process, design non-interactive zero knowledge proofs to achieve public verifiability of notaries, and utilize the Key-Aggregate Searchable Encryption to bridge TAPS and DTPKE so as to awaken the notaries securely and efficiently. In addition, we formalize the definitions and security requirements for DeTAPS. Then we present a concrete construction and formally prove its security and privacy. To evaluate the performance, we build a prototype based on SGX2 and Ethereum. Meng Li 0006, Hanni Ding, Qing Wang 0060, Weizhi Meng 0001, Liehuang Zhu, Zijian Zhang 0001, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Embedding Secret Message in Chinese Characters via Glyph Perturbation and Style TransferabstractGlyph perturbation adjusts the characters’ structures and strokes to make the original characters change subtly, which cannot be detected by the naked eye. These generated variants with different glyph perturbation can represent different status of secret messages, which can be used to embed information in Chinese text documents. However, Chinese characters have characteristics in large numbers, complex structures, and diverse fonts, which limit the generation of glyph perturbation and make the design of Chinese characters time-consuming and laborious. Many font style transfer methods for Chinese characters have been proposed to improve the efficiency of Chinese character generation based on deep learning. At present, there are few studies on efficient font style transfer for glyph perturbation of Chinese characters. In this paper, a stylized glyph perturbation method based on style extractor and attention augmented convolution is proposed. It adopts a multi-head attention mechanism to enhance convolution in the font transfer, which concatenates the convolution feature maps and the self-attention activation maps to weaken the limitations of ordinary convolution in processing images. The extracted style features are sent into the decoder of the font transfer network so as to improve the stylized ability. Particularly, the impact of style extractor and attention augmented convolution on the glyph perturbation generation is addressed. The extraction accuracy and embedding capacity are tested in our experiments. The embedding capacity of secret message can achieve around 1.8 bit/character. Ye Yao 0003, Chen Wang 0113, Hui Wang 0020, Ke Wang 0039, Yizhi Ren, Weizhi Meng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | Differential Cryptanalysis of Bloom Filters for Privacy-Preserving Record LinkageabstractPrivacy-preserving record linkage (PPRL) aims to link records of the same real-world entity from different databases without exposing any private information about the entity. Bloom filters are widely used in PPRL due to their effectiveness in encoding records while enabling fast approximate linkage in the case of attribute value errors and changes. However, the basic Bloom filters used for PPRL can be subject to cryptanalysis attacks that expose the plain-text values encoded in them. Recent studies have successfully attacked some improved Bloom filter encodings in PPRL but require specific conditions or knowledge of various encoding parameters to obtain high accuracy. This paper presents a novel attack based on differential analysis against Bloom filters used for PPRL. The attack exploits graphs to model the relationship between attribute value variation and the difference between Bloom filters. Then, features are generated for the node in graphs according to a clustering algorithm that we propose. Thus, we can match nodes with similar features to re-identify encoded records. Experiments on two real-world databases show that even with improved Bloom filter encoding and some hardening techniques, our attack can re-identify private information from encoded records with high accuracy and require less priori knowledge. Weifeng Yin, Lifeng Yuan, Yizhi Ren, Weizhi Meng 0001, Dong Wang 0019, Qiuhua Wang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Detecting Post Editing of Multimedia Images using Transfer Learning and Fine TuningabstractIn the domain of general image forgery detection, a myriad of different classification solutions have been developed to distinguish a “tampered” image from a “pristine” image. In this work, we aim to develop a new method to tackle the problem of binary image forgery detection. Our approach builds upon the extensive training that state-of-the-art image classification models have undergone on regular images from the ImageNet dataset, and transfers that knowledge to the image forgery detection space. By leveraging transfer learning and fine tuning, we can fit state-of-the-art image classification models to the forgery detection task. We train the models on a diverse and evenly distributed image forgery dataset. With five models—EfficientNetB0, VGG16, Xception, ResNet50V2, and NASNet-Large—we transferred and adapted pre-trained knowledge from ImageNet to the forgery detection task. Each model was fitted, fine-tuned, and evaluated according to a set of performance metrics. Our evaluation demonstrated the efficacy of large-scale image classification models—paired with transfer learning and fine tuning—at detecting image forgeries. When pitted against a previously unseen dataset, the best-performing model of EfficientNetB0 could achieve an accuracy rate of nearly 89.7%. Simon Lucas Jonker, Malthe Jelstrup, Weizhi Meng 0001, Brooke Kidmose |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2024 | LightPay: A Lightweight and Secure Off-Chain Multi-Path Payment Scheme Based on Adapter SignaturesabstractThe payment channel network aims to solve the problems of long payment confirmation time and limited throughput in cryptocurrencies through off-chain payments. Hash Time-Lock Contract (HTLC) is an off-chain payment protocol that Lightning Network (LN) adopted. Unfortunately, when performing high-valued payments off-chain, due to the impact of payment channel capacity, it is often necessary to split a single payment, which increases the transaction fees and time. Therefore, we propose LightPay, an atomic off-chain multi-path payment protocol based on adapter signature and discrete logarithm problem. Among different conditions encoded in the multi-path contract, the multi-path transmission of a single high-valued payment can be realized under the premise of the unlinkability of partial payments. We construct an ideal functionality in the Universal Composability framework and demonstrate that LightPay UC-realizes it, thereby providing proof of its security and privacy. Experimental results indicate that the payment success rate of LightPay can be increased by 11.08% in 0.0025 BTC payments compared with the single-path payment protocol Multihop HTLC in LN. Additionally, compared with the multi-path payment protocol CryptoMaze, the communication overhead required by LightPay is reduced to about 55.6% on average in the simulated network. Overall, LightPay has advantages regarding payment success rate and overhead. Yaqin Liu, Wei Liang 0005, Kun Xie 0001, Songyou Xie, Kuanching Li, Weizhi Meng 0001 |
IEEE Trans. Serv. Comput. | 6 |
| 2023 | Securing Offshore Installations Against Automatic Identification System SpoofingabstractThe AIS (Automatic Identification System) is a maritime navigation safety communication system that transmits data, such as vessel location and identification, both to nearby vessels and to coastal facilities. Unfortunately, AIS spoofing is a growing concern: malicious actors could transmit false AIS messages in order to mislead vessels and potentially cause accidents. In this work, we developed a tool for AIS message validation. Under evaluation, the tool delivered promising results in terms of AIS spoofing detection and prevention, thereby demonstrating the tool's efficacy and potential to complement existing detection and prevention techniques. Grzegorz Jacek Kot, Weizhi Meng 0001, Brooke Kidmose |
GLOBECOM | 2 |
| 2023 | A Closer Look at Cross-Domain Maximal Extractable Value for Blockchain DecentralisationabstractIn the current literature, many solutions for solving blockchain scaling have been tried historically, whereas most of them usually may compromise the decentralisation. Ethereum has chosen to scale by switching to Proof of Stake consensus and adding data sharding to allow Layer 2 execution to be cheaper. However, in the light of cross-domain Maximal Extractable Value (MEV), even this strategy may have centralising forces built-in. In this work, we focus on cross-domain MEV and try to identify cross domain arbitrage. In particular, we extract Uniswap data from four different domains and provide an initial analysis of how to identify cross domain arbitrages. Johan Hagelskjar Sjursen, Weizhi Meng 0001, Wei-Yang Chiu |
ICBC | 2 |
| 2023 | DataVaults: A Secure, Distributed and Privacy Preserving Personal Data Management PlatformabstractWith the rapid development of information technology, the ethical use of data and users' privacy has become a big concern. In European Union, the General Data Protection Regulation (GDPR) has been enforced since 2018, aiming to protect a person's privacy. However, the growth of the data economy might be hindered due to the lack of a trusted, secure and privacy-aware tool. Motivated by this observation, this work presents Data Vaults - a secure, distributed and privacy-preserving personal data management platform. The main goal is to mitigate various privacy concerns through allowing an individual to maintain the ownership, handle and share the data based on their willingness. The platform enables a flexible data sharing method with fair compensation schemes. In particular, with the Data Vaults platform, an individual can protect the sharing of personal data and fairly define how value can be captured, created, released and cashed out for the benefit of all the stakeholders involved (companies or not). Weizhi Meng 0001, Wei-Yang Chiu |
ICDCS | 1 |
| 2023 | BlockPAT: A Blockchain-Enabled Second-Hand Physical Asset Tokenization Management SystemabstractIn this work, we develop BlockPAT, a blockchain-enabled management system for the tokenization of second-hand physical assets, e.g., laptops. With this system, the information gap between buyers and sellers in the second-hand market will be eliminated, and with the help of a price oracle, the liquidity of the second-hand market can be greatly improved. Furthermore, our system is built upon the latest ZK-rollups solution; thus, the overall transaction cost and time delay will be limited to an affordable value. Wei-Yang Chiu, Weizhi Meng 0001, Brooke Kidmose |
ICDCS | 3 |
| 2023 | Towards Quantifying Cross-Domain Maximal Extractable Value for Blockchain Decentralisation
Johan Hagelskjar Sjursen, Weizhi Meng 0001, Wei-Yang Chiu |
ICICS | 2 |
| 2023 | Delay-masquerading Technique Upheld StrongBox: A Reinforced Side-Channel ProtectionabstractIn recent years, Graphical Processing Unit (GPU) is not only becoming a piece of hardware that accelerates graphics but also playing a key role in accelerating the fields of machine learning and artificial intelligence. The GPU’s heightened importance has led to increasing concern about the confidentiality of a GPU’s computing data as well as its internal communications. Although the GPU Trusted Execution Environment (TEE) has been implemented as a solution toward this issue, side-channel attacks in GPUs still remain as an open problem. In this work, we introduce Delay-masquerading Technique Upheld StrongBox (DTUBox) to strengthen the resilience of existing GPU TEE over StrongBox against side-channel attacks by injecting obfuscated noise with our developed algorithm, making the correlations difficult to reference between a task and workload. In our evaluation, we demonstrate that with only around 5% performance overhead, our approach could effectively lower the correlation rate to 38% between the original behavior sequences and the obfuscated sequences. Shuoqiang Zeng, Wei-Yang Chiu, Peichen Liu, Weizhi Meng 0001, Brooke Kidmose |
ICPADS | 5 |
| 2023 | Look Closer to Touch Behavior-enabled Android Pattern Locks: A Study in the WildabstractAndroid pattern lock is one of the most popular unlocking mechanisms on the Android platform. In order to enhance the security of Android’s unlocking functionality, a number of researchers have tried to combine touch biometrics with the pattern lock. Several studies have reported adequate— even excellent—authentication results, but, unlike fingerprint-and face recognition-based authentication, no biometrics-enabled pattern lock exists in the Android marketplace. Furthermore, most studies of biometrics-enabled pattern locks were conducted in controlled lab environments. As such, in this work, our goal is to investigate and validate the performance of touch behavior-enabled Android pattern locks in a more practical scenario, in which users have to download the application and learn to use it by themselves (as was often the case during the pandemic). During the course of our investigation, we collected substantial data, namely, the properties provided by the Android API for motion events, as well as measurements that could be extracted from the devices’ sensors. Our investigation found that touch-enabled Android pattern locks could achieve an average equal error ratio of 23.5% for user authentication—without changing the process from the user’s perspective. Next, we modified the user experience such that each user would train the authenticator with different fingers, similar to fingerprint-based authentication. With this modification, an average equal error ratio of 13.5% was achieved. Gergely Tuskó, Weizhi Meng 0001, Brooke Kidmose |
TrustCom | 2 |
| 2023 | can-train-and-test: A New CAN Intrusion Detection DatasetabstractThe controller area network (CAN) bus facilitates communication between a vehicle's microcontrollers, known as electronic control units (ECUs). Developed in 1983, the CAN bus is exceedingly robust—and exceedingly insecure. The CAN bus lacks conventional security controls (e.g., authentication, authorization, access control, encryption—to name a few). Significant research work has focused on improving automotive security; however, it has been challenging to add security to the CAN bus ex post facto.The automotive intrusion detection system (IDS) has been popularized in the literature as a relatively low-cost, low-effort security improvement for the CAN bus. Unfortunately, would-be IDS designers are often confronted with a shortage of adequate datasets to facilitate IDS development and evaluation. For intrusion detection systems built from machine learning models, the dataset shortage is particularly problematic; machine learning models require a lot of data for training and testing. The shortage of CAN datasets might impede or even deter would-be automotive IDS researchers.In this work, we introduce a new CAN dataset, dubbed can-train-and-test, to ameliorate the shortage of CAN datasets for IDS development and evaluation. Our dataset contains CAN data from four different vehicles manufactured by two different organizations—Chevrolet (General Motors) and Subaru. We provide attack-free traffic captures as well as captures that demonstrate nine distinct types of attacks—e.g., denial of service (DoS), fuzzing, standstill. We conduct all nine attacks against each of the four vehicles; thus, IDS designers can use the attack captures to evaluate an IDS's ability to generalize to different vehicles. We provide (1) replayable .log files, (2) unlabeled .csv files, and (3) labeled .csv files in order to meet a variety of IDS development and evaluation needs. Brooke Kidmose, Weizhi Meng 0001 |
VTC Fall | 2 |
| 2023 | A comparative risk analysis on CyberShip system with STPA-Sec, STRIDE and CORASabstractThe widespread use of software-intensive cyber systems in critical infrastructures such as ships (CyberShips) has brought huge benefits, yet it has also opened new avenues for cyber attacks to potentially disrupt operations. Cyber risk assessment plays a vital role in identifying cyber threats and vulnerabilities that can be exploited to compromise cyber systems. Understanding the nature of cyber threats and their potential risks and impact is essential to improve the security and resilience of cyber systems, and to build systems that are secure by design and better prepared to detect and mitigate cyber attacks. A number of methodologies have been proposed to carry out these analyses. This paper evaluates and compares the application of three risk assessment methodologies: system theoretic process analysis (STPA-Sec), STRIDE and CORAS for identifying threats and vulnerabilities in a CyberShip system. We specifically selected these three methodologies because they identify threats not only at the component level, but also threats or hazards caused due to the interaction between components, resulting in sets of threats identified with each methodology and relevant differences. Moreover, STPA-Sec, which is a variant of the STPA, is widely used for safety and security analysis of cyber physical systems (CPS); CORAS offers a framework to perform cyber risk assessment in a top-down approach that aligns with STPA-Sec; and STRIDE (Spoofing, Tampering, Repudiation,Information disclosure, Denial of Service, Elevation of Privilege) considers threat at the component level as well as during the interaction that is similar to STPA-Sec. As a result of this analysis, this paper highlights the pros and cons of these methodologies, illustrates areas of special applicability, and suggests that their complementary use as threats identified through STRIDE can be used as an input to CORAS and STPA-Sec to make these methods more structured. Rishikesh Sahay, Daniel A. Sepulveda Estay, Weizhi Meng 0001, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Comput. Secur. | 3 |
| 2023 | UAF-GUARD: Defending the use-after-free exploits via fine-grained memory permission management
Guangquan Xu, Wenqing Lei, Lixiao Gong, Jian Liu 0004, Hongpeng Bai, Kai Chen 0012, Wei Wang 0012, Kaitai Liang, Weizhi Meng 0001, Shaoying Liu |
Comput. Secur. | 11 |
| 2023 | GenDroid: A query-efficient black-box android adversarial attack framework
Guangquan Xu, Hongfei Shao, Jingyi Cui, Hongpeng Bai, Guangdong Bai, Shaoying Liu, Weizhi Meng 0001, James Xi Zheng |
Comput. Secur. | 8 |
| 2023 | ADFL: Defending backdoor attacks in federated learning via adversarial distillation
Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002, Weizhi Meng 0001 |
Comput. Secur. | 5 |
| 2023 | MLCT: A multi-level contact tracing scheme with strong privacyabstractAbstract With the outbreak of Covid‐19, both people's health and the world economy are facing great challenges. Contact tracing scheme based on Bluetooth of smartphones has been regarded as a viable way to mitigate the spread of Covid‐19. The existing schemes mainly belong to the centralized or the decentralized structure, both of which have their own limitations. It is infeasible for the existing schemes to balance the different demands of governments and users for user privacy and tracing efficiency at different periods of the epidemic. In this paper, we propose a hybrid contact tracing scheme named MLCT (multi‐level contact tracing scheme) which is mainly based on short group signature. MLCT provides multiple privacy levels by applying anonymous credential technology and secret sharing technology to desensitize user identity privacy and encounter privacy. Comparing to the previous schemes, MLCT fully considers the different demands of the government, patients, and close contacts for user privacy and tracing efficiency in the different stages of Covid‐19. The experimental results show viability in terms of the required resource from both server and mobile phone perspectives. And the security analysis demonstrates that MLCT can achieve the five targets security goals. It is expected that MLCT can contribute to the design and development of contact tracing schemes. Jixin Zhang, Jiageng Chen, Weizhi Meng 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2023 | A survey of deep learning-based intrusion detection in automotive applicationsabstractModern automobiles depend on internal vehicle networks (IVNs) to control systems from the anti-lock brakes to the transmission to the locks on the doors. Many IVNs, particularly the Controller Area Network (CAN) bus, were developed with little regard for security, since the IVNs of the past were isolated from the outside world. In the present day, the assumption of isolation no longer applies. Cellular service, Wi-Fi, and Bluetooth are just a few examples of the connectivity of contemporary automobiles. Researchers have explored a number of automotive security enhancements, but such enhancements are often roadblocked by implementation challenges, complexity, and expense. An intrusion detection system (IDS) is a promising automotive security enhancement that requires little, if any, adjustment to a vehicle’s existing infrastructure. Deep learning techniques can augment the capability of automotive IDSs, improving detection accuracy and precision. This paper provides a comprehensive overview of deep learning-based IDSs in automotive networks. We assemble various deep learning schemes, categorize them according to their topologies and techniques, and highlight their distinct contributions. In addition, we analyze each scheme’s evaluation in terms of datasets, attack types, and metrics. We summarize the results of the schemes and assess the advantages and disadvantages of different deep learning architectures. Brooke Kidmose, Weizhi Meng 0001 |
Expert Syst. Appl. | 2 |
| 2023 | A privacy-preserving blockchain-based tracing model for virus-infected people in cloud
Chengyi Qin, Lei Wu 0011, Weizhi Meng 0001, Zihui Xu, Hao Wang 0007 |
Expert Syst. Appl. | 3 |
| 2023 | Trusting Computing as a Service for Blockchain ApplicationsabstractRecently, blockchain and smart contracts have been one of most popular technology to establish trustworthy applications in several fields. However, due to the transparency and publicity of blockchain, the information processed by a smart contract is visible to every party in a blockchain. In light of this, this study proposes a trusted computing as a service (TCaaS) framework based on the blockchain. One of the critical component is the Execution Environment for Secured Smart Contract Computing (ESC)2 node. In the proposed framework, people can deploy (ESC)2 nodes in a blockchain. Users can upload general-purposed programs and associated parameters and discover an (ESC)2 node for execution via related smart contracts. The programs and parameters are encrypted so that only selected (ESC)2 node can decrypt the data. Then the execution environment calculates the result and returns it to the blockchain. We evaluate our concept with the ESP32 microcontroller with the ATECC508A security chip and the Quorum blockchain platform. Therefore, the study contributes to ensure faithful execution of programs without losing confidentiality. Wen-Wei Li, Weizhi Meng 0001, Kuo-Hui Yeh, Shi-Cho Cha 0001 |
IEEE Internet Things J. | 2 |
| 2023 | ADCL: Toward an Adaptive Network Intrusion Detection System Using Collaborative Learning in IoT NetworksabstractWith the widespread of cyber attacks, network intrusion detection system (NIDS) is becoming an important and essential tool to protect Internet of Things (IoT) environments. However, it is well known that the NIDS performance depends heavily on the effectiveness of the detection model, which can be influenced significantly by the learning mechanism and the available training data. Many existing studies try to mitigate the above challenges, but few of them consider the adaptability and the cost of deploying an NIDS, the integrity of the learning process, the capacity of model based on concrete traffic samples at the same time. To fill this gap and improve the detection performance, we propose a collaborative learning-based detection framework called ADCL, which can mitigate the limitations on the knowledge of a single model by leveraging multiple models trained in similar environments and detecting intrusions in a collaborative manner. Our evaluation results indicate that ADCL can provide better performance compared with a single model on detecting various attacks in IoT networks. Specifically, ADCL improves F-score by up to 80% for adaptability, 42% in mitigating the reliance on learning integrity, 85% for model capacity. Furthermore, the detection results of ADCL guide those single models to update and increase the F-score by 15%. Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001, Xiapu Luo, Lisong Wang, Wenjuan Li 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Analysis of hybrid attack and defense based on block withholding strategy
Binjie Liao, Yu Wang 0017, Weizhi Meng 0001, Jun Zhang 0010 |
J. Inf. Secur. Appl. | 4 |
| 2023 | Dummy trajectory generation scheme based on generative adversarial networks
Jingkang Yang 0001, Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002 |
Neural Comput. Appl. | 3 |
| 2023 | Optimal Repair Strategy Against Advanced Persistent Threats Under Time-Varying NetworksabstractAdvanced persistent threat (APT) is a kind of stealthy, sophisticated, and long-term cyberattack that has brought severe financial losses and critical infrastructure damages. Existing works mainly focus on APT defense under stable network topologies, while the problem under time-varying dynamic networks (e.g., vehicular networks) remains unexplored, which motivates our work. Besides, the spatiotemporal dynamics in defense resources, complex attackers’ lateral movement behaviors, and lack of timely defense make APT defense a challenging issue under time-varying networks. In this paper, we propose a novel game-theoretical APT defense approach to promote real-time and optimal defense strategy-making under both periodic time-varying and general time-varying environments. Specifically, we first model the interactions between attackers and defenders in an APT process as a dynamic APT repair game, and then formulate the APT damage minimization problem as the precise prevention and control (PPAC) problem. To derive the optimal defense strategy under both latency and defense resource constraints, we further devise an online optimal control-based mechanism integrated with two backtracking-forward algorithms to fastly derive the near-optimal solution of the PPAC problem in real time. Extensive experiments are carried out, and the results demonstrate that our proposed scheme can efficiently obtain optimal defense strategy in 54481 ms under seven attack-defense interactions with 9.64% resource occupancy in stimulated periodic time-varying and general time-varying networks. Besides, even under static networks, our proposed scheme still outperforms existing representative APT defense approaches in terms of service stability and defense resource utilization. Zixuan Wang 0014, Yuntao Wang 0004, Zhou Su 0001, Shui Yu 0001, Weizhi Meng 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | NoSneaky: A Blockchain-Based Execution Integrity Protection Scheme in Industry 4.0abstractThe advancement of information technology allows the creation of smart devices that not only are programable, but also can perform machine-to-machine communication in order to reach a flexible large-scale manufacturing strategy in Industry 4.0. However, as more components are connected to the Internet, cyber-criminals can perform malicious actions remotely. As one lasting threat, sabotaging smart devices' execution integrity can cause a large financial loss, i.e., causing malfunctioning. Hence, it is important to secure the execution integrity of smart devices in Industry 4.0. Motivated by the emerging blockchain technology, in this paper, we focus on how blockchain can help Industry 4.0 application protect execution integrity and propose a blockchain-based execution protection scheme namedNoSneaky, which is low-cost and can be easily integrated into the current production systems. In the evaluation, we demonstrate its performance and effectiveness in securing the execution integrity. Wei-Yang Chiu, Weizhi Meng 0001, Chunpeng Ge 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | Attribute-Based Data Sharing Scheme With Flexible Search Functionality for Cloud-Assisted Autonomous Transportation SystemabstractThe existing group public key encryption with equality test schemes could only support one-to-one data sharing and are not suitable for cloud-assisted autonomous transportation systems, which demand one-to-many data sharing. To tackle this problem efficiently, in this article, we put forward the group-attribute-based encryption with equality test (G-ABEET) scheme. The presented G-ABEET allows sensors equipped in vehicles to encrypt traffic data with an expressive access policy before sharing it. Only users with attributes required by the access policy ought to access the shared ciphertexts, thus achieving selective one-to-many data sharing. Meanwhile, the authorized cloud server could provide group users with equality tests over the ciphertexts, realizing ciphertext search ability. Furthermore, with the group mechanism, the G-ABEET scheme could resist offline message recovery attacks. Besides, in the standard model, we give rigorous security proof of the G-ABEET construction. The feasibility and efficiency of G-ABEET are demonstrated by experimental simulations. Hu Xiong, Hanxiao Wang 0002, Weizhi Meng 0001, Kuo-Hui Yeh |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Towards Intelligent Attack Detection Using DNA ComputingabstractIn recent years, frequent network attacks have seriously threatened the interests and security of humankind. To address this threat, many detection methods have been studied, some of which have achieved good results. However, with the development of network interconnection technology, massive amounts of network data have been produced, and considerable redundant information has been generated. At the same time, the frequently changing types of cyberattacks result in great difficulty collecting samples, resulting in a serious imbalance in the sample size of each attack type in the dataset. These two problems seriously reduce the robustness of existing detection methods, and existing research methods do not provide a good solution. To address these two problems, we define an unbalanced index and an optimal feature index to directly reflect the performance of a detection method in terms of overall accuracy, feature subset optimization, and detection balance. Inspired by DNA computing, we propose intelligent attack detection based on DNA computing (ADDC). First, we design a set of regular encoding and decoding features based on DNA sequences and obtain a better subset of features through biochemical reactions. Second, nondominated ranking based on reference points is used to select individuals to form a new population to optimize the detection balance. Finally, a large number of experiments are carried out on four datasets to reflect real-world cyberattack situations. Experimental results show that compared with the most recent detection methods, our method can improve the overall accuracy of multiclass classification by up to 10%; the imbalance index decreased by 0.5, and 1.5 more attack types were detected on average; and the optimal index of the feature subset increased by 83.8%. ZengRi Zeng, Baokang Zhao, Han-Chieh Chao, Ilsun You, Kuo-Hui Yeh, Weizhi Meng 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 6 |
| 2022 | Towards Enhanced EEG-based Authentication with Motor Imagery Brain-Computer InterfaceabstractElectroencephalography (EEG) is the record of electrogram of the electrical activity on the scalp typically using non-invasive electrodes. In recent years, many studies started using EEG as a human characteristic to construct biometric identification or authentication. Being a kind of behavioral characteristics, EEG has its natural advantages whereas some characteristics have not been fully evaluated. For instance, we find that Motor Imagery (MI) brain-computer interface is mainly used for improving neurological motor function, but has not been widely studied in EEG authentication. Currently, there are many mature methods for understanding such signals. In this paper, we propose an enhanced EEG authentication framework with Motor Imagery, by offering a complete EEG signal processing and identity verification. Our framework integrates signal preprocess, channel selection and deep learning classification to provide an end-to-end authentication. In the evaluation, we explore the requirements of a biometric system such as uniqueness, permanency, collectability, and investigate the framework regarding insider and outsider attack performance, cross-session performance, and influence of channel selection. We also provide a large comparison with state-of-the-art methods, and our experimental results indicate that our framework can provide better performance based on two public datasets. Bingkun Wu, Weizhi Meng 0001, Wei-Yang Chiu |
ACSAC | 2 |
| 2022 | Towards Artificial Neural Network Based Intrusion Detection with Enhanced Hyperparameter TuningabstractDue to the development of complex communication paradigms and the rise in the number of inter-connected digital devices, intrusion detection system (IDS) has become one basic and important security mechanism to identify cyber intrusions and protect computer networks. Currently, various deep learning algorithms have been studied in intrusion detection to achieve a high detection rate, whereas the detection performance may be still dependent on specific datasets. To maintain the detection performance, parameter optimization is believed as an effective solution. Motivated by this observation, in this work, we propose a concise but effective hyperparameter tuning process to enhance the artificial neural network (ANN) based IDS. In the evaluation, we consider three ANN variants and four datasets. The experimental results indicate that our approach can outperform similar studies and typical learning algorithms. Andrei Nicolae Calugar, Weizhi Meng 0001, Haijun Zhang 0002 |
GLOBECOM | 2 |
| 2022 | IDS for CAN: A Practical Intrusion Detection System for CAN Bus SecurityabstractModern automobiles depend heavily on electronics, controlled by the vehicle's internal network. The controller area network (CAN bus) is the predominant protocol, known for its reliability but also its grievous lack of security. Unfortunately, security is expensive and automotive manufacturers seem disinclined to invest in CAN bus protection. Thus, consumers are left with few options to improve security. In this work, we develop IDS for CAN – an Android application that functions as an intrusion detection system (IDS) for the CAN bus system. In particular, it communicates with a standard ELM 327-type device, plugged into the diagnostic port that is mandatory in the United States and Europe. The application will detect suspicious traffic on the CAN bus and generate an alert to notify the user. In our evaluation, we investigate the performance with both datasets and real vehicles. The results indicate the practicability and the effectiveness of our proposed system. Our application will allow consumers to take charge of automotive security. Brooke Kidmose, Weizhi Meng 0001 |
GLOBECOM | 2 |
| 2022 | TDL-IDS: Towards A Transfer Deep Learning based Intrusion Detection SystemabstractWith the development of Internet of Things (IoT), network security has become very important as cyber-attackers can easily compromise such distributed networks and systems. An intrusion detection system (IDS) is a basic and essential security mechanism to detect malicious traffic. In the literature, in addition to traditional machine learning algorithms, many deep learning schemes have been examined to enhance the detection performance. However, insufficient amounts of labeled samples are still a challenge for real-world implementation, especially in some scenarios such as smart home and Internet of Vehicles. To address this issue, we explore transfer learning as a promising solution. In this work, we develop TDL-IDS, a transfer deep learning based IDS that can work with limited labeled data items. Our approach first uses Long Short Term Memory (LSTM) to train a model on the source domain and then leverages transfer learning to continue the training process on the target domain. In the evaluation, we use NSL-KDD as the source domain, and AWID as the target domain. Our results indicate that TDL-IDS can outperform many similar approaches. Xingguo Sun, Weizhi Meng 0001, Wei-Yang Chiu, Brooke Kidmose |
GLOBECOM | 2 |
| 2022 | AirChain - Towards Blockchain-based Aircraft Maintenance Record SystemabstractCivil aviation (aircraft) is one of the public transportation industries that requires the highest safety standards. However, several accidents on aircraft maintenance system had revealed that there is a need to secure the record integrity and traceability. Motivated by this issue and supported by an airline, in this work, we design and implement AirChain, a blockchain-based aircraft maintenance record system, in which the data can be stored in a way that is both resistant to tampering and easy to access. The experimental results indicate the viability and practicability of our system. Wictor Lang Jensen, Sille Jessing, Wei-Yang Chiu, Weizhi Meng 0001 |
ICBC | 4 |
| 2022 | Lightweight and Practical Privacy-Preserving Image Masking in Smart Community
Yi-Ning Liu 0002, Weizhi Meng 0001 |
ICICS | 3 |
| 2022 | Towards A Scalable and Privacy-Preserving Blockchain-based European Parking SystemabstractThe importance of efficient and accessible parking systems has been growing over the past decades. Steady growth in urban population and car ownership has increased problems with traffic congestion and air pollution caused by inadequate parking systems. Blockchain-based parking systems have been proposed to increase system availability and resilience and improve trust among participants. However, these systems are not transferable to the parking systems of European cities such as Copenhagen, as they are based on assumptions about the parking infrastructure, which do not hold, and are inherently incompatible with regional privacy protection regulations such as the GDPR. Furthermore, many blockchain solutions suffer from scalability issues, severely limiting their efficiency. In this work, we develop a blockchainbased parking system in Denmark, aiming to make up the gap in the existing research by directly considering GDPR compliance. Our work focuses on the municipal parking system for on-street parking in Copenhagen (Denmark), where Hyperledger Fabric is used to maintain a trusted distributed ledger for parking data shared by the network. Personal data is protected through offchain storage while maintaining on-chain verifiability. The proposed system is implemented as a proof-of-concept application, which can deliver sufficient throughput to support the needs of municipal parking. Jonathan Kvist Brittain, Wei-Yang Chiu, Weizhi Meng 0001 |
ICPADS | 3 |
| 2022 | Towards Blockchain-Enabled Intrusion Detection for Vehicular Navigation Map System
Bodi Bodi, Wei-Yang Chiu, Weizhi Meng 0001 |
ISPEC | 3 |
| 2022 | Designing Enhanced Robust 6G Connection Strategy with Blockchain
August Lykke Thomsen, Bastian Preisel, Victor Rodrigues Andersen, Wei-Yang Chiu, Weizhi Meng 0001 |
ISPEC | 5 |
| 2022 | A Privacy-Preserving Distributed Machine Learning Protocol Based on Homomorphic Hash Authentication
Lisong Wang, Weizhi Meng 0001, Chunpeng Ge 0001 |
NSS | 3 |
| 2022 | FolketID: A Decentralized Blockchain-Based NemID Alternative Against DDoS Attacks
Wei-Yang Chiu, Weizhi Meng 0001, Wenjuan Li 0001, Liming Fang 0001 |
ProvSec | 2 |
| 2022 | Security Analysis in Satellite Communication based on Geostationary OrbitabstractWith the rapid growth of Internet of Things (IoT) devices and evolving 5G/6G networks, satellite communication has become extremely important, which can provide the capability of sending information from one place to another via a communication satellite in orbit around the Earth. Due to the increasing needs, the Internet traffic is naturally part of satellite communication, carrying a large number of sensitive or private information and data. As such, the proliferation of satellites may bring increased security risks. Motivated by this concern, in this work, we aim to investigate the potential security breaches in satellite communication, with a specific focus on geostationary orbit (GEO) satellites. In particular, we firstly set up an experimental environment to collect data from satellites that the hardware equipment supports, and then perform a risk assessment based on NIST. In terms of our experimental findings and risk analysis, we identify a total of 15 threat sources that may cause various security issues. In the end, we discuss potential solutions to enhance the security and lessons learnt in our setup. Jacob Krabbe Pedersen, Mikkel Bøchman, Weizhi Meng 0001 |
PST | 3 |
| 2022 | Designing In-Air Hand Gesture-based User Authentication System via Convex HullabstractWith the rapid development of personal computers and mobile devices, it is very important to properly authenticate a user’s identity to protect the information and data stored on these devices. Due to various privacy and security concerns, contactless authentication has received much attention, among which in-air gesture based authentication is one promising solution. Motivated by this observation, in this work, we develop and implement a real-time in-air hand gesture-based user authentication system, where users can define or select various gestures and generate their credentials. Our system can verify a user using a deep learning-enabled inference framework without the need of being trained by a powerful device. Different from the state-of-the-art, our system uses a method of convex hull to recognize the hand gesture. In our user study, we involve 20 participants to examine the system performance, and find that our system is viable and usable with a success rate of 95%. Weizhi Meng 0001, Wenjuan Li 0001 |
PST | 2 |
| 2022 | For a few diversities more: A voting-attack-immune voting scheme for social question and answer websitesabstractSummary Social question and answer (Q&A) communities or websites, such as Quora, StackOverflow, become popular from the last decade. They provide collected answers in a crowdsourcing way by encouraging the interactive between users. The ranking of answers in such Q&A websites depends on many factors, such as received upvotes, downvotes, publishing time, and so on. When there exist malicious users, they can manipulate the ranking of answers by launching voting spamming attacks. In this article, we propose a metric, diversity of visibility, to characterize the balance between rankings of answers with conflicting opinions and propose a time‐diversitybased voting scheme to reach a high diversity of visibility, so as to minimize the impact of voting spamming attacks. We evaluate the proposed metric and voting scheme in the case study of a Chinese Q&A website, Zhihu, and show that the proposed voting scheme consistently shows a good balance of answers with conflicting opinions in both actual scenarios and synthetic scenarios. Jun Zhang 0019, Houda Labiod, Weizhi Meng 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2022 | Threshold identity authentication signature: Impersonation prevention in social network servicesabstractSummary While the social network services (SNS) have dominate the ways that people communicate with each other on the Internet, identity impersonation remains to be a serious issue that needs to be solved due to the anonymity in the cyber network. Currently, the potential solution to the problem relies heavily on the administration from the central server, which requires intensive workload of the identity management. In this article, we propose a threshold identity authentication signature scheme to solve the impersonation problem from the protocol layer rather than software design in the traditional upper level. In our scheme, with the help of some authenticated accounts, trusted relationship can be shared in a group to other unauthenticated accounts, which largely decrease the workload of authenticating all the accounts. Users are given the ability to verify other accounts' identity information by their signatures. Then, we establish three security goals to prevent the malicious adversary to launch the impersonation attack on a group. We claim that our scheme is suitable for the SNS scenario since the procedure of generating a signature to prove the identity requires little computation cost, it is user‐friendly especially on the lightweight devices such as mobile devices and so on. Zhanwen Chen, Jiageng Chen, Weizhi Meng 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2022 | An empirical study of supervised email classification in Internet of Things: Practical performance and key influencing factorsabstract202111 bcwh Wenjuan Li 0001, Lishan Ke, Weizhi Meng 0001, Jinguang Han |
Int. J. Intell. Syst. | 3 |
| 2022 | Editorial: Security and Privacy Challenges in Internet of Things
Ding Wang 0002, Weizhi Meng 0001 |
Mob. Networks Appl. | 2 |
| 2022 | DVPPIR: privacy-preserving image retrieval based on DCNN and VHE
Lei Wu 0011, Weizhi Meng 0001, Zihui Xu, Chengyi Qin, Hao Wang 0007 |
Neural Comput. Appl. | 3 |
| 2022 | A novel rough set-based approach for minimum vertex cover of hypergraphs
Qian Zhou 0005, Hua Dai 0003, Weizhi Meng 0001 |
Neural Comput. Appl. | 4 |
| 2021 | Mind the Scraps: Attacking Blockchain Based on Selfdestruct
Wei-Yang Chiu, Weizhi Meng 0001 |
ACISP | 2 |
| 2021 | ActAnyware - Blockchain-Based Software Licensing Scheme
Wei-Yang Chiu, Lu Zhou 0002, Weizhi Meng 0001, Zhe Liu 0001, Chunpeng Ge 0001 |
BlockSys | 3 |
| 2021 | NGS: Mitigating DDoS Attacks using SDN-based Network Gate ShieldabstractThe Internet of Things (IoT) implements a tremendous environment of extensive data streams, whereby any suspicious activities should be detected to safeguard systems' reliability and availability. Distributed Denial of Service (DDoS) attack is a major threat on computer networks, in which an attacker can send huge traffic with multiple IP addresses or machines. In this work, we focus on detecting DDoS attacks, and design Network Gate Shield (NGS), a tool that works on SDN architecture based on the RYU controller. It can examine the traffic trustworthiness, and then determine whether the current traffic is normal based on packet specification, such as the average packet size and the packet per-sec threshold. In the evaluation with an emulated environment, our experimental results indicate that NGS is viable and effective in mitigating DDoS traffic compared with several similar detection approaches. Mohamad Suhel Dalati, Weizhi Meng 0001, Wei-Yang Chiu |
GLOBECOM | 2 |
| 2021 | TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications
Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002 |
ISC | 2 |
| 2021 | BALSAPro: Towards A Security Protocol for Bluetooth Low EnergyabstractThe rapid and increasing application of wireless technology, especially Bluetooth Low Energy (BLE), provides many benefits to our daily lives. With BLE, the small packets of data can be exchanged over a wireless channel, whereas the data security is a concern. For example, the BLE standards define that if one BLE device with input-output capabilities tries to establish a connection while the other BLE device does not support input-output, an unauthenticated channel will be established. That is, in the worst case, the connection is established where no security is applied. To mitigate this issue, we propose a security protocol, named BALSAPro, at the application layer that complements the existing protocols such as Security Manager Protocol (SMP), which can help establish a secure channel with authentication and non-repudiation, when pairing has not been used. In the evaluation, we implement and evaluate our protocol performance compared with similar work at the application layer. The results demonstrate that our protocol can enhance the security level with less time consumption. Mohamad Muwfak Hlal, Weizhi Meng 0001 |
MSN | 2 |
| 2021 | Towards DTW-based Unlock Scheme using Handwritten Graphics on SmartphonesabstractNowadays, due to the increasing capability, mobile devices especially smartphones have become a necessity in people’s daily life, which would store a lot of personal and private information. This makes smartphones a major target for cyber-attackers, i.e., either loss of such mobile deices or illegal access will cause personal data breach and economic damage. Hence it is of great importance to safeguard smartphones from unauthorized access with the purpose of reducing the risk of privacy leakage and economic losses. To achieve this purpose, designing a suitable scheme to unlock phone screen is one promising solution. For instance, Android unlock scheme is a typical example, where users can unlock the phone screen by inputting a correct pattern. However, its password space is low due to the adoption of only nine dots on a 2D grid. In this work, we design a new unlock scheme using handwritten graphics, which uses an improved DTW-based algorithm for authentication. Also, we implement a prototype and evaluate our scheme using both a public dataset (SUSIG) and a self-collected dataset (SCD). Our results indicated that our scheme could achieve 7.12% and 8.75% EER on SUSIG and SCD respectively. Weizhi Meng 0001, Wenjuan Li 0001 |
MSN | 2 |
| 2021 | Efficient Attribute-Based Signature for Monotone Predicates
Jixin Zhang, Jiageng Chen, Weizhi Meng 0001 |
ProvSec | 3 |
| 2021 | LibBlock - Towards Decentralized Library System based on Blockchain and IPFSabstractIn modern times, the definition and the library’s expected functionality did not change much as before. It is still a place for us to hold massive collections of information. Traditionally, libraries require physical storage space for writings and publications, but storing and managing costs can be tremendous. Although the aid of digital promises and computers allows a super high density of information storage, it does not lower the library’s complexity. As our main source of information is moving away from physical writings toward digital, the new digital library (i.e., state-run library) faces the challenges of records’ integrity and storage efficiency. Focused on this issue, we learn the demands from the Royal Library in Denmark and try to explore the use of blockchain technology. We introduce a system named LibBlock, by integrating with both smart contract and IPFS in order to provide a robust, decentralized, flexible, and adaptive e-Library, which enables the ease of scalability and rigid record keeping. In the evaluation, we investigate the initial performance of LibBlock with Ethereum and show its viability and efficiency. Wei-Yang Chiu, Weizhi Meng 0001, Wenjuan Li 0001 |
PST | 2 |
| 2021 | Enhancing Trust-based Medical Smartphone Networks via Blockchain-based Traffic SamplingabstractWith more devices being inter- or intra-connected, Internet of Things (IoT) has gradually been adopted in many disciplines, such as healthcare industry, coined as Internet of Medical Things (IoMT). The purpose of IoMT is to facilitate the efficiency and effectiveness of medical operations, i.e., remotely monitoring the status of patients. In such healthcare environments, smartphones have become an important device to communicate with others and update the information of patients, resulting in a special type of IoMT called Medical Smartphone Networks (MSNs). To reinforce the distributed architecture, trust management schemes are often implemented to defend against insider attacks. However, how to maintain the robustness of trust management in heavy traffic networks still remains a challenge, i.e., COVID-19 incident would cause excessive traffic for healthcare organizations and increase the difficulty of validating trustworthiness among MSN nodes. In this work, we focus on this issue and propose a blockchain-enabled adaptive traffic sampling method to help enhance the robustness of trust management under high traffic environments. The use of blockchain technology aims to build a verified database of malicious traffic among all nodes. The evaluation in a real healthcare environment demonstrates the viability and effectiveness of our approach. Wenjuan Li 0001, Weizhi Meng 0001, Laurence T. Yang |
TrustCom | 2 |
| 2021 | Mind the Amplification: Cracking Content Delivery Networks via DDoS Attacks
Weizhi Meng 0001 |
WASA (2) | 2 |
| 2021 | Enhancing Blackslist-Based Packet Filtration Using Blockchain in Wireless Sensor Networks
Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017, Jin Li 0002 |
WASA (2) | 2 |
| 2021 | Mobile network traffic pattern classification with incomplete a priori information
Zhiping Jin, Zhibiao Liang, Yu Wang 0017, Weizhi Meng 0001 |
Comput. Commun. | 4 |
| 2021 | Corrigendum to "CyberShip-IoT: A Dynamic and Adaptive SDN-Based Security Policy Enforcement Framework for Ships" [Future Gener. Comput. Syst. 100 (2019) 736-750]
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Future Gener. Comput. Syst. | 2 |
| 2021 | Accurate Range Query With Privacy Preservation for Outsourced Location-Based Service in IoTabstractWith the maturity of Internet-of-Things technology, location-based service (LBS) is developing rapidly in intelligent terminal devices, and it brings new vitality to the fields of logistics, transportation, product traceability and so on. The popularity of LBS produces a lot of spatial data, which inevitably brings burden to the storage and management of LBS provider (LBSP). With the help of cloud computing and cloud storage, outsourcing spatial data to cloud server has become a new trend. However, due to the cloud server is not trusted, data outsourcing will face the problems of data disclosure and query disclosure. Range query is a common query in LBS, considering the situation of data outsourcing, this article proposes an accurate range query (ARQ) scheme, which can realize efficient range query while preserving LBSP's data privacy and user's query privacy from being disclosed to the cloud server. The ARQ scheme is suitable for spatial data in any form without being limited to the case that the data points are only integers, which has a certain practical significance. In addition, by dividing the region into atomic regions, ARQ can realize sublinear search time and ensure dynamic update of spatial data. We proved the security of the proposed scheme through security analysis, and demonstrated the effectiveness of the scheme through experiments. Zhaoman Liu, Lei Wu 0011, Weizhi Meng 0001, Hao Wang 0007, Wei Wang 0012 |
IEEE Internet Things J. | 3 |
| 2021 | Hybrid Emotion-Aware Monitoring System Based on Brainwaves for Internet of Medical ThingsabstractDriven by an increasing number of connected medical devices, Internet of Medical Things (IoMT), as an application of Internet of Things (IoT) in healthcare, is developed to help collect, analyze, and transmit medical data. During the outbreak of a pandemic like COVID-19, IoMT can be useful to monitor the status of patients and detect main symptoms remotely, by using various smart sensors. However, due to the lack of emotional care in the current IoMT, it is still a challenge to reach an efficient medical process. Especially under COVID-19, there is a need to monitor emotional status among particular people like the elderly. In this work, we propose an emotion-aware healthcare monitoring system in IoMT, based on brainwaves. With the fast development of electroencephalography (EEG) sensors in current headsets and some devices, brainwave-based emotion detection becomes feasible. The IoMT devices are used to capture the brainwaves of a patient in a scenario of smart home. Also, our system involves the analysis of touch behavior as the second layer to enhance the brainwave-based emotion recognition. In the user study with 60 participants, the results indicate the viability and effectiveness of our approach in detecting emotions like comfortable and uncomfortable, which can complement existing emotion-aware healthcare applications and mechanisms. Weizhi Meng 0001, Laurence T. Yang, Wei-Yang Chiu |
IEEE Internet Things J. | 1 |
| 2021 | My data, my control: A secure data sharing and access scheme over blockchain
Wei-Yang Chiu, Weizhi Meng 0001, Christian Damsgaard Jensen |
J. Inf. Secur. Appl. | 2 |
| 2021 | EdgeTC - a PBFT blockchain-based ETC scheme for smart cities
Wei-Yang Chiu, Weizhi Meng 0001 |
Peer-to-Peer Netw. Appl. | 2 |
| 2021 | Towards efficient and energy-aware query processing for industrial internet of things
Liang Liu 0006, Weizhi Meng 0001, Wenzhao Gao, Zuchao Ma |
Peer-to-Peer Netw. Appl. | 3 |
| 2021 | User recognition based on periocular biometrics and touch dynamics
Andrea Casanova, Lucia Cascone, Aniello Castiglione, Weizhi Meng 0001, Chiara Pero |
Pattern Recognit. Lett. | 4 |
| 2021 | Exploring touch-based behavioral authentication on smartphone email applications in IoT-enabled smart cities
Wenjuan Li 0001, Weizhi Meng 0001, Steven Furnell |
Pattern Recognit. Lett. | 2 |
| 2021 | Designing Leakage-Resilient Password Entry on Head-Mounted Smart Wearable Glass DevicesabstractWith the boom of Augmented Reality (AR) and Virtual Reality (VR) applications, head-mounted smart wearable glass devices are becoming popular to help users access various services like E-mail freely. However, most existing password entry schemes on smart glasses rely on additional computers or mobile devices connected to smart glasses, which require users to switch between different systems and devices. This may greatly lower the practicability and usability of smart glasses. In this paper, we focus on this challenge and design three practical anti-eavesdropping password entry schemes on stand-alone smart glasses, named gTapper, gRotator and gTalker. The main idea is to break the correlation between the underlying password and the interaction observable to adversaries. In our IRB-approved user study, these schemes are found to be easy-to-use without additional hardware under various test conditions, where the participants can enter their passwords within moderate time, at high accuracy, and in various situations. Yan Li 0075, Weizhi Meng 0001, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Sparse Trust Data MiningabstractAs recommendation systems continue to evolve, researchers are using trust data to improve the accuracy of recommendation prediction and help users find relevant information. However, large recommendation systems with trust data suffer from the sparse trust problem, which leads to grade inflation and severely affects the reliability of trust propagation. This paper presents a novel research on sparse trust data mining, which includes the new concept of sparse trust, a sparse trust model, and a trust mining framework. It lays a foundation for the trust-related research in large recommended systems. The new trust mining framework is based on customized normalization functions and a novel transitive gossip trust model, which discovers potential trust information between entities in a large-scale user network and applies it to a recommendation system. We conducts a comprehensive performance evaluation on both real-world and synthetic datasets. The results confirm that our framework mines new trust and effectively ameliorates sparse trust problem. Pengli Nie, Guangquan Xu, Litao Jiao, Shaoying Liu, Jian Liu 0004, Weizhi Meng 0001, Hongyue Wu, Meiqi Feng, Zhengjun Jing, James Xi Zheng |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2020 | DCONST: Detection of Multiple-Mix-Attack Malicious Nodes Using Consensus-Based Trust in IoT Networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001 |
ACISP | 3 |
| 2020 | ELD: Adaptive Detection of Malicious Nodes under Mix-Energy-Depleting-Attacks Using Edge Learning in IoT Networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001 |
ISC | 3 |
| 2020 | Evaluation of Anomaly-Based Intrusion Detection with Combined Imbalance Correction and Feature Selection
Andreas Heidelbach Engly, Anton Ruby Larsen, Weizhi Meng 0001 |
NSS | 3 |
| 2020 | Towards Collaborative Intrusion Detection Enhancement against Insider Attacks with Multi-Level TrustabstractWith the speedy growth of distributed networks such as Internet of Things (IoT), there is an increasing need to protect network security against various attacks by deploying collaborative intrusion detection systems (CIDSs), which allow different detector nodes to exchange required information and data with each other. While due to the distributed architecture, insider attacks are a big threat for CIDSs, in which an attacker can reside inside the network. To address this issue, designing an appropriate trust management scheme is considered as an effective solution. In this work, we first analyze the development of CIDSs in the past decades and identify the major challenges on building an effective trust management scheme. Then we introduce a generic framework aiming to enhance the security of CIDSs against advanced insider threats by deriving multilevel trust. In the study, our results demonstrate the viability and the effectiveness of our framework. Wenjuan Li 0001, Weizhi Meng 0001 |
TrustCom | 2 |
| 2020 | SCAFFISD: A Scalable Framework for Fine-grained Identification and Security Detection of Wireless RoutersabstractThe security of wireless network devices has received widespread attention, but most existing schemes cannot achieve fine-grained device identification. In practice, the security vulnerabilities of a device are heavily depending on its model and firmware version. Motivated by this issue, we propose a universal, extensible and device-independent framework called SCAFFISD, which can provide fine-grained identification of wireless routers. It can generate access rules to extract effective information from the router admin page automatically and perform quick scans for known device vulnerabilities. Meanwhile, SCAFFISD can identify rogue access points (APs) in combination with existing detection methods, with the purpose of performing a comprehensive security assessment of wireless networks. We implement the prototype of SCAFFISD and verify its effectiveness through security scans of actual products. Fangzhou Zhu, Liang Liu 0006, Weizhi Meng 0001, Ting Lv, Renjun Ye |
TrustCom | 3 |
| 2020 | MSYM: A multichannel communication system for android devices
Donghai Tian, Weizhi Meng 0001, Xiaoqi Jia, Rui Ma 0004 |
Comput. Networks | 3 |
| 2020 | Towards multiple-mix-attack detection via consensus-based trust management in IoT networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001 |
Comput. Secur. | 3 |
| 2020 | Detecting insider attacks in medical cyber-physical networks based on behavioral profiling
Weizhi Meng 0001, Wenjuan Li 0001, Yu Wang 0017, Man Ho Au |
Future Gener. Comput. Syst. | 1 |
| 2020 | THP: A Novel Authentication Scheme to Prevent Multiple Attacks in SDN-Based IoT NetworkabstractSDN has provided significant convenience for network providers and operators in cloud computing. Such a great advantage is extending to the Internet of Things network. However, it also increases the risk if the security of an SDN network is compromised. For example, if the network operator's permission is illegally obtained by a hacker, he/she can control the entry of the SDN network. Therefore, an effective authentication scheme is needed to fit various application scenarios with high-security requirements. In this article, we design, implement, and evaluate a new authentication scheme called the hidden pattern (THP), which combines graphics password and digital challenge value to prevent multiple types of authentication attacks at the same time. We examined THP in the perspectives of both security and usability, with a total number of 694 participants in 63 days. Our evaluation shows that THP can provide better performance than the existing schemes in terms of security and usability. Liming Fang 0001, Yang Li 0103, Xinyu Yun, Zhenyu Wen, Shouling Ji, Weizhi Meng 0001, Zehong Cao, Muhammad Tanveer 0001 |
IEEE Internet Things J. | 6 |
| 2020 | Analysis of differential distribution of lightweight block cipher based on parallel processing on GPU
Zhanwen Chen, Jiageng Chen, Weizhi Meng 0001, Je Sen Teh, Bingqing Ren |
J. Inf. Secur. Appl. | 3 |
| 2020 | Lightweight privacy-preserving data aggregation protocol against internal attacks in smart grid
Xiao-di Wang, Weizhi Meng 0001, Yi-Ning Liu 0002 |
J. Inf. Secur. Appl. | 2 |
| 2020 | Enhancing collaborative intrusion detection via disagreement-based semi-supervised learning in IoT environments
Wenjuan Li 0001, Weizhi Meng 0001, Man Ho Au |
J. Netw. Comput. Appl. | 2 |
| 2020 | A swipe-based unlocking mechanism with supervised learning on smartphones: Design and evaluation
Wenjuan Li 0001, Jiao Tan, Weizhi Meng 0001, Yu Wang 0017 |
J. Netw. Comput. Appl. | 3 |
| 2020 | Towards blockchain-enabled single character frequency-based exclusive signature matching in IoT-assisted smart cities
Weizhi Meng 0001, Wenjuan Li 0001, Steven Tug, Jiao Tan |
J. Parallel Distributed Comput. | 1 |
| 2020 | Secure Information Transmissions in Wireless-Powered Cognitive Radio Networks for Internet of Medical ThingsabstractIn this paper, we consider the issue of the secure transmissions for the cognitive radio-based Internet of Medical Things (IoMT) with wireless energy harvesting. In these systems, a primary transmitter (PT) will transmit its sensitive medical information to a primary receiver (PR) by a multi-antenna-based secondary transmitter (ST), where we consider that a potential eavesdropper may listen to the PT’s sensitive information. Meanwhile, the ST also transmits its own information concurrently by utilizing spectrum sharing. We aim to propose a novel scheme for jointly designing the optimal parameters, i.e., energy harvesting (EH) time ratio and secure beamforming vectors, for maximizing the primary secrecy transmission rate while guaranteeing secondary transmission requirement. For solving the nonconvex optimization problem, we transfer the problem into convex optimization form by adopting the semidefinite relaxation (SDR) method and Charnes–Cooper transformation technique. Then, the optimal secure beamforming vectors and energy harvesting duration can be obtained easily by utilizing the CVX tools. According to the simulation results of secrecy transmission rate, i.e., secrecy capacity, we can observe that the proposed protocol for the considered system model can effectively promote the primary secrecy transmission rate when compared with traditional zero-forcing (ZF) scheme, while ensuring the transmission rate of the secondary system. Wenjuan Tang, Zhiyuan Tan 0001, Weizhi Meng 0001, Lianyong Qi |
Secur. Commun. Networks | 5 |
| 2020 | Editorial: Blockchain in Industrial IoT Applications: Security and Privacy Advances, Challenges, and OpportunitiesabstractBlockchain is an emerging technology that has widespread applications, such as those relating to Internet of Things (IoT) and Industrial IoT (IIoT). While there are many (potential) applications of blockchain in IIoT (the focus of this special issue), there are a number of ongoing challenges. For example, blockchain technology provides a solution to ensure a trust relationship without a centralized entity. However, such technology is still under development and suffers from a number of limitations and challenges during implementation, such as computational costs (e.g., mining), security (e.g., attacks such as distributed denial-of-service attacks, and theft of content). In an IIoT application, such as smart cities, Industry 4.0, and in military and battlefield context (also referred to as Internet of battlefield things and Internet of Military Things), there are more factors that need to be taken into consideration in the design of blockchain-based solutions. Therefore, in the following sections we will describe the advances presented in the editorial accepted in this special issue, designed to address different security and privacy challenges associated with the deployment of blockchain-based solutions in an IIoT setting. Kim-Kwang Raymond Choo, Zheng Yan 0002, Weizhi Meng 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2019 | A Closer Look Tells More: A Facial Distortion Based Liveness Detection for Face AuthenticationabstractFace authentication is vulnerable to media-based virtual face forgery (MVFF) where adversaries display photos/videos or 3D virtual face models of victims to spoof face authentication systems. In this paper, we propose a liveness detection mechanism, called FaceCloseup, to protect the face authentication on mobile devices. FaceCloseup detects MVFF-based attacks by analyzing the distortion of face regions in a user's closeup facial videos captured by built-in camera on mobile device. It can detect MVFF-based attacks with an accuracy of 99.48%. Yan Li 0075, Zilong Wang 0001, Yingjiu Li, Robert H. Deng, Binbin Chen 0001, Weizhi Meng 0001, Hui Li 0006 |
AsiaCCS | 6 |
| 2019 | CAVAEva: An Engineering Platform for Evaluating Commercial Anti-malware Applications on Smartphones
Weizhi Meng 0001, Chunhua Su, Kim-Kwang Raymond Choo |
Inscrypt | 2 |
| 2019 | Practical Bayesian Poisoning Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Kim-Kwang Raymond Choo, Chunhua Su |
ESORICS (1) | 1 |
| 2019 | Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001 |
ICICS | 7 |
| 2019 | Evaluating Intrusion Sensitivity Allocation with Support Vector Machine for Collaborative Intrusion Detection
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok |
ISPEC | 2 |
| 2019 | Towards Secure Open Banking Architecture: An Evaluation with OWASP
Deina Kellezi, Christian Boegelund, Weizhi Meng 0001 |
NSS | 3 |
| 2019 | SocialAuth: Designing Touch Behavioral Smartphone User Authentication Based on Social Networking Applications
Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Jianying Zhou 0001 |
SEC | 1 |
| 2019 | Attribute-Based Information Flow ControlabstractAbstract Information flow control (IFC) regulates where information is permitted to travel within information systems. To enforce IFC, access control encryption (ACE) was proposed to support both the no read-up rule and the no write-down rule. There are some problems in existing schemes. First, the communication cost is linear with the number of receivers. Second, senders are not authenticated, namely an unauthorized sender can send a message to a receiver. To reduce communication cost and implement sender authentication, we propose an attribute-based IFC (ABIFC) scheme by introducing attribute-based systems into IFC. Our ABIFC scheme captures the following features: (i) flexible IFC policies are defined over a universal set of descriptive attributes; (ii) both the no read-up rule and the no write-down rule are supported; (iii) the communication cost is linear with the number of required attributes, instead of receivers; (iv) receivers can outsource heavy computation to a server without compromising data confidentiality; (v) authorized senders can control release their attributes when sending messages to receivers. To the best of our knowledge, it is the first IFC scheme where flexible policies are defined over descriptive attributes and outsourced computation is supported. Jinguang Han, Maoxuan Bei, Liqun Chen 0002, Yang Xiang 0001, Jie Cao 0001, Fuchun Guo, Weizhi Meng 0001 |
Comput. J. | 7 |
| 2019 | Adaptive machine learning-based alarm reduction via edge computing for distributed intrusion detection systemsabstractSummary To protect assets and resources from being hacked, intrusion detection systems are widely implemented in organizations around the world. However, false alarms are one challenging issue for such systems, which would significantly degrade the effectiveness of detection and greatly increase the burden of analysis. To solve this problem, building an intelligent false alarm filter using machine learning classifiers is considered as one promising solution, where an appropriate algorithm can be selected in an adaptive way in order to maintain the filtration accuracy. By means of cloud computing, the task of adaptive algorithm selection can be offloaded to the cloud, whereas it could cause communication delay and increase additional burden. In this work, motivated by the advent of edge computing, we propose a framework to improve the intelligent false alarm reduction for DIDS based on edge computing devices. Our framework can provide energy efficiency as the data can be processed at the edge for shorter response time. The evaluation results demonstrate that our framework can help reduce the workload for the central server and the delay as compared to the similar studies. Yu Wang 0017, Weizhi Meng 0001, Wenjuan Li 0001, Zhe Liu 0001, Hanxiao Xue |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | Designing collaborative blockchained signature-based intrusion detection in IoT environments
Wenjuan Li 0001, Steven Tug, Weizhi Meng 0001, Yu Wang 0017 |
Future Gener. Comput. Syst. | 3 |
| 2019 | Detection of multiple-mix-attack malicious nodes using perceptron-based trust in IoT networks
Liang Liu 0006, Zuchao Ma, Weizhi Meng 0001 |
Future Gener. Comput. Syst. | 3 |
| 2019 | Enhancing the security of FinTech applications with map-based graphical password authentication
Weizhi Meng 0001, Liqiu Zhu, Wenjuan Li 0001, Jinguang Han, Yan Li 0075 |
Future Gener. Comput. Syst. | 1 |
| 2019 | CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod |
Future Gener. Comput. Syst. | 2 |
| 2019 | Efficient Image Recognition and Retrieval on IoT-Assisted Energy-Constrained Platforms From Big Data RepositoriesabstractThe advanced computational capabilities of many resource constrained devices, such as smartphones have enabled various research areas including image retrieval from big data repositories for numerous Internet of Things (IoT) applications. The major challenges for image retrieval using smartphones in an IoT environment are the computational complexity and storage. To deal with big data in IoT environment for image retrieval, this paper proposes a light-weighted deep learning-based system for energy-constrained devices. The system first detects and crops face regions from an image using Viola-Jones algorithm with additional face and nonface classifier to eliminate the miss-detection problem. Second, the system uses convolutional layers of a cost effective pretrained CNN model with defined features to represent faces. Next, features of the big data repository are indexed to achieve a faster matching process for real-time retrieval. Finally, Euclidean distance is used to find similarity between query and repository images. For experimental evaluation, we created a local facial images dataset, including both single and group facial images. This dataset can be used by other researchers as a benchmark for comparison with other real-time facial image retrieval systems. The experimental results show that our proposed system outperforms other state-of-the-art feature extraction methods in terms of efficiency and retrieval for IoT-assisted energy-constrained platforms. Irfan Mehmood, Amin Ullah, Khan Muhammad 0001, Der-Jiunn Deng, Weizhi Meng 0001, Fadi M. Al-Turjman, Victor Hugo C. de Albuquerque |
IEEE Internet Things J. | 5 |
| 2019 | Design of multi-view based email classification for IoT systems via semi-supervised learning
Wenjuan Li 0001, Weizhi Meng 0001, Zhiyuan Tan 0001, Yang Xiang 0001 |
J. Netw. Comput. Appl. | 2 |
| 2019 | The application of Software Defined Networking on securing computer networks: A survey
Rishikesh Sahay, Weizhi Meng 0001, Christian Damsgaard Jensen |
J. Netw. Comput. Appl. | 2 |
| 2019 | Machine Learning for Wireless Multimedia Data Security
Zhaoqing Pan, Ching-Nung Yang, Victor S. Sheng, Naixue Xiong, Weizhi Meng 0001 |
Secur. Commun. Networks | 5 |
| 2019 | Security, Privacy, and Trust on Internet of Things
Constantinos Kolias, Weizhi Meng 0001, Georgios Kambourakis, Jiageng Chen |
Wirel. Commun. Mob. Comput. | 2 |
| 2018 | Enhancing Intelligent Alarm Reduction for Distributed Intrusion Detection Systems via Edge Computing
Weizhi Meng 0001, Yu Wang 0017, Wenjuan Li 0001, Zhe Liu 0001, Jin Li 0002, Christian W. Probst |
ACISP | 1 |
| 2018 | Analysis of Variance of Graph-Clique Mining for Scalable Proof of Work
Hiroaki Anada, Tomohiro Matsushima, Chunhua Su, Weizhi Meng 0001, Junpei Kawamoto, Samiran Bag, Kouichi Sakurai |
Inscrypt | 4 |
| 2018 | Evaluating the Impact of Intrusion Sensitivity on Securing Collaborative Intrusion Detection Networks Against SOOA
David Madsen, Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017 |
ICA3PP (4) | 3 |
| 2018 | Towards Securing Challenge-Based Collaborative Intrusion Detection Networks via Message Verification
Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017, Jinguang Han, Jin Li 0002 |
ISPEC | 2 |
| 2018 | TMGMap: Designing Touch Movement-Based Geographical Password Authentication on Smartphones
Weizhi Meng 0001, Zhe Liu 0001 |
ISPEC | 1 |
| 2018 | Analyzing the Communication Security Between Smartphones and IoT Based on CORAS
Motalib Hossain Bhuyan, Nur A. Azad, Weizhi Meng 0001, Christian Damsgaard Jensen |
NSS | 3 |
| 2018 | Position Paper on Blockchain Technology: Smart Contract and Applications
Weizhi Meng 0001, Jianfeng Wang 0001, Xianmin Wang, Joseph K. Liu, Zuoxia Yu, Jin Li 0002, Yongjun Zhao 0001, Sherman S. M. Chow |
NSS | 1 |
| 2018 | PrivacySearch: An End-User and Query Generalization Tool for Privacy Enhancement in Web Search
Francisco-Javier Rodrigo-Ginés, Javier Parra-Arnau, Weizhi Meng 0001, Yu Wang 0017 |
NSS | 3 |
| 2018 | CPMap: Design of Click-Points Map-Based Graphical Password Authentication
Weizhi Meng 0001, Fei Fei, Lijun Jiang, Zhe Liu 0001, Chunhua Su, Jinguang Han |
SEC | 1 |
| 2018 | JFCGuard: Detecting juice filming charging attack via processor usage analysis on smartphones
Weizhi Meng 0001, Lijun Jiang, Yu Wang 0017, Jin Li 0002, Jun Zhang 0010, Yang Xiang 0001 |
Comput. Secur. | 1 |
| 2018 | TouchWB: Touch behavioral user authentication based on web browsing on smartphones
Weizhi Meng 0001, Yu Wang 0017, Duncan S. Wong, Sheng Wen, Yang Xiang 0001 |
J. Netw. Comput. Appl. | 1 |
| 2018 | A fog-based privacy-preserving approach for distributed signature-based intrusion detection
Yu Wang 0017, Weizhi Meng 0001, Wenjuan Li 0001, Jin Li 0002, Waixi Liu 0001, Yang Xiang 0001 |
J. Parallel Distributed Comput. | 2 |
| 2018 | Enhancing touch behavioral authentication via cost-based intelligent mechanism on smartphones
Weizhi Meng 0001, Wenjuan Li 0001, Duncan S. Wong |
Multim. Tools Appl. | 1 |
| 2018 | Towards Bayesian-Based Trust Management for Insider Attacks in Healthcare Software-Defined NetworksabstractThe medical industry is increasingly digitalized and Internet-connected (e.g., Internet of Medical Things), and when deployed in an Internet of Medical Things environment, software-defined networks (SDNs) allow the decoupling of network control from the data plane. There is no debate among security experts that the security of Internet-enabled medical devices is crucial, and an ongoing threat vector is insider attacks. In this paper, we focus on the identification of insider attacks in healthcare SDNs. Specifically, we survey stakeholders from 12 healthcare organizations (i.e., two hospitals and two clinics in Hong Kong, two hospitals and two clinics in Singapore, and two hospitals and two clinics in China). Based on the survey findings, we develop a trust-based approach based on Bayesian inference to figure out malicious devices in a healthcare environment. Experimental results in either a simulated and a real-world network environment demonstrate the feasibility and effectiveness of our proposed approach regarding the detection of malicious healthcare devices, i.e., our approach could decrease the trust values of malicious devices faster than similar approaches. Weizhi Meng 0001, Kim-Kwang Raymond Choo, Steven Furnell, Athanasios V. Vasilakos, Christian W. Probst |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2017 | Exploring Effect of Location Number on Map-Based Graphical Password Authentication
Weizhi Meng 0001, Lee Wang Hao, Man Ho Au, Zhe Liu 0001 |
ACISP (2) | 1 |
| 2017 | A Pilot Study of Multiple Password Interference Between Text and Map-Based Passwords
Weizhi Meng 0001, Wenjuan Li 0001, Lee Wang Hao, Lijun Jiang, Jianying Zhou 0001 |
ACNS | 1 |
| 2017 | Evaluating Challenge-Based Trust Mechanism in Medical Smartphone Networks: An Empirical StudyabstractIntrusion detection systems (IDSs) are one of the widely adopted security tools in protecting computer networks, whereas it is still a big challenge for a single IDS to identify various threats in practice. Collaborative intrusion detection networks (CIDNs) are then developed in order to enhance the detection capability of a single IDS. However, CIDNs are known to suffer from insider attacks, in which malicious nodes can perform adversary actions. To mitigate this issue, challenge-based trust mechanisms are one of the promising solutions in literature, which are robust against various common insider threats. With the popularity of mobile devices, medical smartphone networks (MSNs) have become an emerging network architecture for healthcare organizations to improve the quality of medical services. Due to the sensitivity, there is a great need to defend MSNs against insider attacks. In this work, we conduct an empirical study to investigate and evaluate the implementation of challenge-based mechanism in MSNs. Our work aims to complement current literature, through providing insights and learned lessens (i.e., whether it is suitable to deploy such a mechanism in MSNs). Weizhi Meng 0001, Fei Fei, Wenjuan Li 0001, Man Ho Au |
GLOBECOM | 1 |
| 2017 | SOOA: Exploring Special On-Off Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok |
GPC | 2 |
| 2017 | Harvesting Smartphone Privacy Through Enhanced Juice Filming Charging Attacks
Weizhi Meng 0001, Fei Fei, Wenjuan Li 0001, Man Ho Au |
ISC | 1 |
| 2017 | Exploring Energy Consumption of Juice Filming Charging Attack on Smartphones: A Pilot Study
Lijun Jiang, Weizhi Meng 0001, Yu Wang 0017, Chunhua Su, Jin Li 0002 |
NSS | 2 |
| 2017 | Towards enhancing click-draw based graphical passwords using multi-touch behaviours on smartphones
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok, Kim-Kwang Raymond Choo |
Comput. Secur. | 1 |
| 2017 | Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok, Horace Ho-Shing Ip |
J. Netw. Comput. Appl. | 2 |
| 2017 | A bayesian inference-based detection mechanism to defend medical smartphone networks against insider attacks
Weizhi Meng 0001, Wenjuan Li 0001, Yang Xiang 0001, Kim-Kwang Raymond Choo |
J. Netw. Comput. Appl. | 1 |
| 2017 | Towards Effective Trust-Based Packet Filtering in Collaborative Network EnvironmentsabstractOverhead network packets are a big challenge for intrusion detection systems (IDSs), which may increase system burden, degrade system performance, and even cause the whole system collapse, when the number of incoming packets exceeds the maximum handling capability. To address this issue, packet filtration is considered as a promising solution, and our previous research efforts have proven that designing a trust-based packet filter was able to refine unwanted network packets and reduce the workload of a local IDS. With the development of Internet cooperation, collaborative intrusion detection environments (e.g., CIDNs) have been developed, which allow IDS nodes to collect information and learn experience from others. However, it would not be effective for the previously built trust-based packet filter to work in such a collaborative environment, since the process of trust computation can be easily compromised by insider attacks. In this paper, we adopt the existing CIDN framework and aim to apply a collaborative trust-based approach to reduce unwanted packets. More specifically, we develop a collaborative trust-based packet filter, which can be deployed in collaborative networks and be robust against typical insider attacks (e.g., betrayal attacks). Experimental results in various simulated and practical environments demonstrate that our filter can perform effectively in reducing unwanted traffic and can defend against insider attacks through identifying malicious nodes in a quick manner, as compared to similar approaches. Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2016 | TMGuard: A Touch Movement-Based Security Mechanism for Screen Unlock Patterns on Smartphones
Weizhi Meng 0001, Wenjuan Li 0001, Duncan S. Wong, Jianying Zhou 0001 |
ACNS | 1 |
| 2016 | On Multiple Password Interference of Touch Screen Patterns and Text PasswordsabstractThe memorability of multiple passwords is an important topic for user authentication systems. With the advent of Android unlock pattern mechanism, research studies started investigating its usability and security features. This paper presents a study of recalling multiple passwords between text passwords and touch screen unlock patterns, as well as exploring whether users have difficulty in remembering those patterns after a period of time. In our study, participants create unlock patterns for various account scenarios. Our results reveal that participants in the unlock pattern condition with three accounts can outperform those in the text password condition (i.e., achieve higher success rates), not only in a one-hour session (short-term), but also after two weeks (long-term). However, there was no statistically significant difference between participants in the text password and unlock pattern condition in the long-term, when dealing with six accounts. Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Liying Meng |
CHI | 1 |
| 2016 | PMFA: Toward Passive Message Fingerprint Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok, Horace Ho-Shing Ip |
NSS | 2 |
| 2016 | MVPSys: Toward practical multi-view based false alarm reduction system in network intrusion detection
Wenjuan Li 0001, Weizhi Meng 0001, Xiapu Luo, Lam-for Kwok |
Comput. Secur. | 2 |
| 2016 | Enhancing collaborative intrusion detection networks using intrusion sensitivity in detecting pollution attacksabstractPurpose This paper aims to propose and evaluate an intrusion sensitivity (IS)-based approach regarding the detection of pollution attacks in collaborative intrusion detection networks (CIDNs) based on the observation that each intrusion detection system may have different levels of sensitivity in detecting specific types of intrusions. Design/methodology/approach In this work, the authors first introduce their adopted CIDN framework and a newly designed aggregation component, which aims to collect feedback, aggregate alarms and identify important alarms. The authors then describe the details of trust computation and alarm aggregation. Findings The evaluation on the simulated pollution attacks indicates that the proposed approach is more effective in detecting malicious nodes and reducing the negative impact on alarm aggregation as compared to similar approaches. Research limitations/implications More efforts can be made in improving the mapping of the satisfaction level, enhancing the allocation, evaluation and update of IS and evaluating the trust models in a large-scale network. Practical implications This work investigates the effect of the proposed IS-based approach in defending against pollution attacks. The results would be of interest for security specialists in deciding whether to implement such a mechanism for enhancing CIDNs. Originality/value The experimental results demonstrate that the proposed approach is more effective in decreasing the trust values of malicious nodes and reducing the impact of pollution attacks on the accuracy of alarm aggregation as compare to similar approaches. Wenjuan Li 0001, Weizhi Meng 0001 |
Inf. Comput. Secur. | 2 |
| 2016 | Evaluating the effect of multi-touch behaviours on Android unlock patternsabstractPurpose This paper aims to evaluate the effect of multi-touch behaviours on creating Android unlock patterns (AUPs) by realising that users can perform more actions in touch-enabled mobile phones. Design/methodology/approach The author conducted two user studies with a total of 45 participates and performed two major experiments in the main user study. Findings The user study indicates that the multi-touch behaviours can have a positive impact on creating patterns; however, there are only nine touchable points for the original AUPs, which may reduce the usability when performing a multi-touch movement. Research limitations/implications An even larger user study could be conducted to further analyse the patterns generated by users, that is, to analyse the specific password space by integrating the behaviours of multi-touch and to involve more types of multi-touch behaviours in creating an AUP. Practical implications This work explores the effect of multi-touch movement on creating AUPs. The results should be of interest for software developers and security researchers for exploring the effect of multi-touch behaviours on the creation of graphical passwords on mobile phones. Originality/value The author conducts two user studies with a total of 45 participants to investigate the impact of multi-touch behaviours on creating AUPs. In addition, to address the issue of usability, the author proposes two ways: increasing the number of touchable points and improve the rules of pattern creation. Weizhi Meng 0001 |
Inf. Comput. Secur. | 1 |
| 2016 | A survey on OpenFlow-based Software Defined Networks: Security challenges and countermeasures
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok |
J. Netw. Comput. Appl. | 2 |
| 2016 | JuiceCaster: Towards automatic juice filming attacks on smartphones
Weizhi Meng 0001, Lee Wang Hao, Murali Srirangam Ramanujam, S. P. T. Krishnan |
J. Netw. Comput. Appl. | 1 |
| 2015 | An empirical study on email classification using supervised machine learning in real environmentsabstractSpam emails are considered as one of the biggest challenges for the Internet. Thus email classification, which aims to correctly classify legitimate and spam emails, becomes an important topic for both industry and academia. To achieve this goal, machine learning techniques, especially supervised machine learning algorithms, have been extensively applied to this field. In literature, several studies reveal that supervised machine learning (SML) suffers from some limitations such as performance fluctuation, hence many works start focusing on designing more complex algorithms. However, we identify that most existing research efforts are based on datasets, while more research should be conducted to investigate the performance of SML in real environments. In this paper, we thus perform an empirical study with three different environments and over 1,000 users regarding this issue. In the study, we find that SML classifiers like decision tree and SVMs are acceptable by users in real email classification. In addition, we discuss promising directions and provide new insights in this area. Wenjuan Li 0001, Weizhi Meng 0001 |
ICC | 2 |
| 2015 | RouteMap: A Route and Map Based Graphical Password Scheme for Better Multiple Password Memory
Weizhi Meng 0001 |
NSS | 1 |
| 2015 | Design of intelligent KNN-based alarm filter using knowledge-based alert verification in intrusion detectionabstractAbstract Network intrusion detection systems (NIDSs) have been widely deployed in various network environments to defend against different kinds of network attacks. However, a large number of alarms especially unwanted alarms such as false alarms and non‐critical alarms could be generated during the detection, which can greatly decrease the efficiency of the detection and increase the burden of analysis. To address this issue, we advocate that constructing an alarm filter in terms of expert knowledge is a promising solution. In this paper, we develop a method of knowledge‐based alert verification and design an intelligent alarm filter based on a multi‐classk‐nearest‐neighbor classifier to filter out unwanted alarms. In particular, the alarm filter employs a rating mechanism by means of expert knowledge to classify incoming alarms to proper clusters for labeling. We further analyze the effect of different classifier settings on classification accuracy with two alarm datasets. In the evaluation, we investigate the performance of the alarm filter with a real dataset and in a network environment, respectively. Experimental results indicate that our alarm filter can effectively filter out a number of NIDS alarms and can achieve a better outcome under the advanced mode. Copyright © 2015 John Wiley & Sons, Ltd. Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
Secur. Commun. Networks | 1 |
| 2014 | Enhancing email classification using data reduction and disagreement-based semi-supervised learningabstractEmail classification is an important topic in literature attempting to correctly classify user emails and filter out spam emails. In this paper, we identify some challenges regarding this topic and propose an effective email classification model based on both data reduction and disagreement-based semi-supervised learning. In particular, the main objective of the data reduction is to select an optimum collection of email features and reduce the pointless data, while the objective of the disagreement-based approach is to enhance the accuracy of detecting spam emails by utilizing unlabeled data automatically. In the evaluation, we explore the performance of our proposed email classification model using two public datasets and a private dataset. The experimental results demonstrate that our proposed model can overall enhance the performance of email classification through improving detection accuracy and reducing false rates. Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
ICC | 1 |
| 2014 | An Evaluation of Single Character Frequency-Based Exclusive Signature Matching in Distinct IDS Environments
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
ISC | 1 |
| 2014 | Towards Designing an Email Classification System Using Multi-view Based Semi-supervised LearningabstractThe goal of email classification is to classify user emails into spam and legitimate ones. Many supervised learning algorithms have been invented in this domain to accomplish the task, and these algorithms require a large number of labeled training data. However, data labeling is a labor intensive task and requires in-depth domain knowledge. Thus, only a very small proportion of the data can be labeled in practice. This bottleneck greatly degrades the effectiveness of supervised email classification systems. In order to address this problem, in this work, we first identify some critical issues regarding supervised machine learning-based email classification. Then we propose an effective classification model based on multi-view disagreement-based semi-supervised learning. The motivation behind the attempt of using multi-view and semi-supervised learning is that multi-view can provide richer information for classification, which is often ignored by literature, and semi-supervised learning supplies with the capability of coping with labeled and unlabeled data. In the evaluation, we demonstrate that the multi-view data can improve the email classification than using a single view data, and that the proposed model working with our algorithm can achieve better performance as compared to the existing similar algorithms. Wenjuan Li 0001, Weizhi Meng 0001, Zhiyuan Tan 0001, Yang Xiang 0001 |
TrustCom | 2 |
| 2014 | Adaptive non-critical alarm reduction using hash-based contextual signatures in intrusion detection
Weizhi Meng 0001, Lam-for Kwok |
Comput. Commun. | 1 |
| 2014 | EFM: Enhancing the performance of signature-based network intrusion detection systems using enhanced filter mechanism
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
Comput. Secur. | 1 |
| 2014 | The effect of adaptive mechanism on behavioural biometric based mobile phone authenticationabstractPurpose – This paper aims to design a compact scheme of behavioural biometric-based user authentication, develop an adaptive mechanism that selects an appropriate classifier in an adaptive way and conduct a study to explore the effect of this mechanism. Design/methodology/approach – As a study, the proposed adaptive mechanism was implemented using a cost-based metric, which enables mobile phones to adopt a less costly classifier in an adaptive way to build the user normal-behaviour model and detect behavioural anomalies. Findings – The user study with 50 participants indicates that our proposed mechanism can positively affect the authentication performance by maintaining the authentication accuracy at a relatively high and stable level. Research limitations/implications – The authentication accuracy can be further improved by incorporating other appropriate classifiers (e.g. neural networks) and considering other touch-gesture-related features (e.g. the speed of a touch). Practical implications – This work explores the effect of adaptive mechanism on behavioural biometric-based user authentication. The results should be of interest for software developers and security specialists in deciding whether to implement such a mechanism for enhancing authentication performance on mobile phones. Originality/value – The user study with 50 participants indicates that this mechanism can positively affect the authentication performance by maintaining the authentication accuracy at a relatively high and stable level. To the best of our knowledge, our work is an early work discussing the implementation of an adaptive mechanism on a mobile phone. Weizhi Meng 0001, Duncan S. Wong, Lam-for Kwok |
Inf. Manag. Comput. Secur. | 1 |
| 2014 | Adaptive blacklist-based packet filter with a statistic-based approach in network intrusion detection
Weizhi Meng 0001, Lam-for Kwok |
J. Netw. Comput. Appl. | 1 |
| 2013 | Improving the Performance of Neural Networks with Random Forest in Detecting Network Intrusions
Wenjuan Li 0001, Weizhi Meng 0001 |
ISNN (2) | 2 |
| 2013 | Enhancing False Alarm Reduction Using Pool-Based Active Learning in Network Intrusion Detection
Weizhi Meng 0001, Lam-for Kwok |
ISPEC | 1 |
| 2013 | Evaluation of Detecting Malicious Nodes Using Bayesian Model in Wireless Intrusion Detection
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
NSS | 1 |
| 2013 | Enhancing Click-Draw Based Graphical Passwords Using Multi-Touch on Mobile Phones
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
SEC | 1 |
| 2013 | Towards adaptive character frequency-based exclusive signature matching scheme and its applications in distributed intrusion detection
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
Comput. Networks | 1 |
| 2012 | Touch Gestures Based Biometric Authentication Scheme for Touchscreen Mobile Phones
Weizhi Meng 0001, Duncan S. Wong, Roman Schlegel, Lam-for Kwok |
Inscrypt | 1 |
| 2012 | Evaluating the Effect of Tolerance on Click-Draw Based Graphical Password Scheme
Weizhi Meng 0001, Wenjuan Li 0001 |
ICICS | 1 |
| 2012 | Intelligent Alarm Filter Using Knowledge-Based Alert Verification in Network Intrusion Detection
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok |
ISMIS | 1 |
| 2012 | Designing Click-Draw Based Graphical Password Scheme for Better AuthenticationabstractNowadays, graphical password is being regarded as a promising alternative in network security to replace traditional text-based password in which users interact with images for authentication rather than input alphanumeric stings. In general, this image-based authentication can be classified into three categories: click-based graphical password, choice-based graphical password and draw-based graphical password. However, each of them suffers from several intrinsic limitations. In this paper, we propose and develop a click-draw based graphical password scheme (CD-GPS) with the purpose of improving the image-based authentication in both security and usability by combining the above three techniques. Specifically, our scheme mainly contains two operational steps: image selection and secret drawing. That is, users first choose an ordered sequence of images and then select some of them to click-draw their secrets. We present an initial user study which shows positive results that our scheme is good at both security and usability, and subsequently give a preliminary security analysis of our scheme against several well-known attacks (e.g., dictionary attack). Weizhi Meng 0001 |
NAS | 1 |
| 2012 | Enhancing List-Based Packet Filter Using IP Verification Mechanism against IP Spoofing Attack in Network Intrusion Detection
Weizhi Meng 0001, Lam-for Kwok |
NSS | 1 |
| 2012 | Towards Designing Packet Filter with a Trust-Based Approach Using Bayesian Inference in Network Intrusion Detection
Weizhi Meng 0001, Lam-for Kwok, Wenjuan Li 0001 |
SecureComm | 1 |
| 2012 | Adaptive Character Frequency-Based Exclusive Signature Matching Scheme in Distributed Intrusion Detection EnvironmentabstractCurrently, signature-based network intrusion detection systems (NIDSs) are being widely deployed in distributed network environment with the purpose of protecting network communications from various attacks. However, signature matching has become a key limiting factor to restrict the performance of a signature-based NIDS in large-scale distributed network environment. The overhead network packets can greatly reduce the effectiveness of such detection systems and heavily consume computer resources. To mitigate this issue, a more efficient signature matching algorithm is desirable. In this paper, we therefore develop an adaptive character frequency-based exclusive signature matching scheme that can be implemented in a signature-based NIDS to help improve the performance of signature matching. In the experiment, we implemented our scheme in a distributed network environment and evaluated the performance of our scheme compared with Snort. The experimental results show that, in our distributed network environment, our scheme can positively reduce the time consumption in the range from 11.2% to 37.6%. Weizhi Meng 0001, Wenjuan Li 0001 |
TrustCom | 1 |
| 2011 | Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detectionabstractBy using string matching, signature-based network intrusion detection systems (NIDSs) can achieve a higher accuracy and lower false alarm rate than the anomaly-based systems. But the matching process is very expensive regarding to the performance of a signature-based NIDS in which the cost is at least linear to the size of the input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem greatly limits the high performance of a signature-based NIDS in a large operational network. In this paper, we present a context-aware packet filter scheme aiming to mitigate this problem. In particular, our scheme incorporates a list technique, namely the blacklist to help filter network packets based on the confidence of the IP domains. Moreover, our scheme will adapt and update the blacklist contents by using the method of statistic-based blacklist generation according to the actual network environment. In the experiment, we implemented our scheme and showed the first experimental evaluation of its effectiveness. Weizhi Meng 0001, Lam-for Kwok |
IAS | 1 |