Weizhi Meng 0001

dblp:146/1188 · also Yuxin Meng 0001 · DBLP profile ↗
← Back
246ranked-venue papers
47as first author
157since 2021 · last 2026
0000-0003-4384-5786ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 119 · 27 first-author · 68 since 2021Computer networks · 60 · 12 first-author · 39 since 2021Systems, architecture and hardware · 28 · 5 first-author · 18 since 2021Artificial intelligence and machine learning · 24 · 1 first-author · 22 since 2021Databases, data management, data science and information retrieval · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
YearPublicationVenuePosition
2026 SuperEar: Eavesdropping on Mobile Voice Calls via Stealthy Acoustic Metamaterials
Zhiyuan Ning 0003, Zhanyong Tang, Juan He 0007, Weizhi Meng 0001, Yuntian Chen, Jie Zhang 0028, Zheng Wang 0001
WWW4
2026 FBAO: backdoor attack against object detection via frequency noise injection
Qiuhua Wang, Haojie Shen, Lin Wang 0108, Lifeng Yuan, Yizhi Ren, Xiyuan Jia, Shuochao Sun, Weizhi Meng 0001
Appl. Intell.8
2026 A social recommendation model based on cross-view contrastive learning and multi-head attention for multi-rating fusion
Rui Chen 0005, Zhuo Dai, Yanbu Guo, Weizhi Meng 0001, Xiangjie Kong 0001
Eng. Appl. Artif. Intell.5
2026 Obfuscation-resilient malware classification via spatial perception and multi-granular attention collaboration
Wenxin Zheng, Sung-Ryul Kim, Weizhi Meng 0001
Expert Syst. Appl.6
2026 Dynamic malware detection based on enhanced semantic API sequence features
Lei Zhou 0009, Qingcheng Liu, Weizhi Meng 0001, Jian Weng 0001
Expert Syst. Appl.4
2026 TraceMark-LDM: Authenticatable watermarking for latent diffusion models via binary-guided rearrangement
Zhangyi Shen, Ye Yao 0003, Feng Ding 0007, Guopu Zhu, Weizhi Meng 0001
Expert Syst. Appl.6
2026 MSGL: A multi-scale group learning model for insider threat detection
abstract
The insider threat refers to actions of organizational users who abuse their authorized privileges to compromise information assets, and the detection of it has become a crucial task in cybersecurity management. Existing approaches primarily rely on user behavior logs for detection, but they often fail to capture the multi-scale temporal dynamics of user behaviors and the structural relationships within user groups, which limits their effectiveness in insider threat detection. To address these limitations, we propose a multi-scale group learning model (MSGL) for insider threat detection. It mainly consists of three key components: (1) a multi-scale collaborative temporal feature extraction module that leverages a weighted attention mechanism to model behavioral dynamics at different granularities and achieves cross-scale information fusion; (2) the group structure-aware module is designed to capture structural dependencies among users by the aggregation mechanism of graph neural networks, while incorporating group-sparsity regularization to attenuate spurious associations and accentuate underlying common patterns; and (3) an individual learning module for capturing deviations via sparse attention, which facilitates disentangled representations of group-level commonalities and specific characteristics of users. Experimental results on the CERT r4.2 and CERT r5.2 datasets demonstrate the effectiveness of MSGL, achieving detection accuracies of 96.28% and 97.41%, respectively.
Mengxue Pang, Wei Ou, Weizhi Meng 0001, Meng Shen 0001, Qiuling Yue, Wenbao Han
Expert Syst. Appl.3
2026 PCL-BPRE: privacy-preserving certificateless-based broadcast proxy re-encryption for data sharing in cloud-based IIoT
abstract
With the rapid advancement of industrial automation and intelligent manufacturing, an increasing volume of sensing data generated by Industrial Internet of Things (IIoT) devices is being transmitted to cloud platforms. Identity-based broadcast proxy re-encryption (IB-BPRE), as an efficient cryptographic mechanism, has been deployed in IIoT data-sharing environments. However, existing IB-BPRE schemes are susceptible to identity privacy breaches of data recipients. Furthermore, IIoT devices are structurally vulnerable to key escrow compromises resulting from the exposure of encrypted key. To mitigate these critical security challenges, we propose a privacy-preserving certificateless-based broadcast proxy re-encryption scheme for data sharing in cloud-based IIoT, and formally prove its security against chosen ciphertext attacks under the random oracle model. The PCL-BPRE scheme employs a Lagrange interpolation polynomial to obfuscate the identity information of data receivers. Additionally, it integrates certificateless encryption to eliminate the inherent key escrow dependency in IB-BPRE, thereby preventing unauthorized disclosure of private keys in the event of a compromised key generation center. Experimental results validate that the proposed scheme achieves both strong practical feasibility and computational efficiency in IIoT data-sharing.
Yuanjian Zhou, Tianci Zhao, Zhenjun Jing, Weizhi Meng 0001, Chunsheng Gu, Huidan Hu
Future Gener. Comput. Syst.4
2026 FedCode: Addressing federated domain shift by contrastive feature decoupling
Shaobo Zhang 0001, Yijie Yin, Wei Liang 0005, Fan Wu 0014, Weizhi Meng 0001
Neurocomputing5
2026 QSDA: Quality-Aware Secure Multidimensional Data Aggregation With Location Privacy for HIoT
abstract
Data aggregation, as a data processing technique, facilitates accurate diagnosis in the Healthcare Internet of Things (HIoT) by integrating multi-source heterogeneous health data. However, achieving efficient and secure aggregation of multi-dimensional medical data remains challenging, particularly when simultaneously preserving location privacy and providing fair, quality-driven incentives. To address these issues, this paper proposes a Quality-Aware Secure Multi-Dimensional Data Aggregation scheme with Location Privacy for HIoT (QSDA). First, the scheme employs inner product encryption to support aggregation task matching without revealing users’ actual coordinates, and further integrates symmetric homomorphic encryption with super-increasing sequences to enable one-stop compressed aggregation of multi-dimensional data, thereby effectively supporting common statistical operations such as mean and variance. Second, it introduces a data quality incentive mechanism based on offset metrics, while leveraging blockchain auditing to ensure the traceability of the aggregation process and the verifiability of the aggregation results. Finally, security analysis and performance evaluation demonstrate the scheme’s effectiveness and efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Internet Things J.5
2026 A Lightweight and Privacy-Preserving Distributed Multidimensional Data Trend Query Scheme With Fault Tolerance for Machine-as-a-Service
abstract
In the Machine-as-a-Service (MaaS) model, enterprises can significantly reduce production costs by leasing devices from original equipment manufacturers (OEM), while OEM can enhance device quality by utilizing device data shared by enterprises. As such, MaaS is emerging as a very promising paradigm in modern manufacturing. However, the multidimensional data trend formed by the multidimensional data may leak the private production data of enterprises, particularly when the OEM leases the same type of device to enterprises. Currently, there is no targeted and feasible solution to ensure the privacy, integrity, and fault-tolerant of multi-user and multidimensional data in the MaaS model. To address this challenge, we propose a lightweight, privacy-preserving and fault-tolerant distributed multidimensional data trend query scheme for MaaS. The proposed scheme ensures multidimensional data privacy through local differential privacy (LDP), and guarantees fault-tolerant and data integrity using Shamir secret sharing and hash-based message authentication code (mac). To protect the privacy of multidimensional data aggregation trend, we design a weighted noise injection query algorithm based on LDP. Additionally, the scheme mitigates the risk of data leakage by introducing the blockchain (BC) instead of cloud server (CS). We formally prove the security of our proposed scheme, and the experimental evaluation demonstrates that it outperforms existing schemes in terms of computation and communication overhead.
Tianci Zhao, Yuanjian Zhou, Weizhi Meng 0001, Zhengjun Jing
IEEE Internet Things J.4
2026 Empowering IoT Security: Automated Identification of Standard Library Functions in RTOS Firmware With LLM and RAG
abstract
Reverse engineering embedded firmware for Real-Time Operating Systems (RTOS) is a formidable challenge in Internet of Things security. The common practice of stripping symbolic information from firmware to optimize performance and storage makes identifying standard library functions exceptionally difficult, creating a significant bottleneck for functional analysis and vulnerability discovery. This paper introduces a novel, automated method for identifying these functions in RTOS firmware by leveraging Large Language Models. Our approach operates directly on raw binary code, requiring no symbolic or debugging information, and demonstrates broad generalizability across diverse hardware architectures and compilers. At its core, the method combines Retrieval-Augmented Generation (RAG) to enhance identification accuracy with a newly designed Adaptive Iterative Screening Algorithm (AISA), which optimizes analysis efficiency by prioritizing candidate functions based on a weighted score of call frequency, call depth, and address proximity to reduce token costs. We validated our method through rigorous experimentation on Zephyr RTOS firmware spanning nine architectures (e.g., ARM, MIPS, RISC-V). The results are compelling: our approach achieves a 90.59% accuracy rate in identifying standard library function names. Moreover, its application to commercial IoT firmware confirms its high efficiency, identifying functions significantly faster and more economically than traditional heuristic techniques. This work contributes a powerful, general-purpose, and cost-effective solution for automated firmware analysis.
Zhihan Zheng, Yu-an Tan 0001, Weizhi Meng 0001, Shuo Wang 0027
IEEE Internet Things J.5
2026 TrustHFL: An Efficient Aggregation Method for Trustworthy Hierarchical Federated Learning
abstract
The hierarchical federated learning framework significantly reduces communication burdens on central servers; however, the integration of edge servers introduces potential risks such as Single Point of Failure (SPOF) and ongoing challenges like imbalanced data distribution. To tackle these challenges, we propose TrustHFL, an innovative aggregation method designed for secure hierarchical federated learning. TrustHFL enhances training efficiency by employing group training that clusters clients with similar data distribution characteristics. Inside each cluster, synchronous aggregation is implemented, while asynchronous aggregation is utilised between clusters to alleviate delays from bottleneck clients. We also introduce a robust access control mechanism for secure interactions between clients and edge servers, ensuring data privacy and system integrity. Moreover, our design favours off-chain computation and training, limiting on-chain storage to essential information and thereby minimising both storage and computational demands on the blockchain, ultimately enhancing training efficiency. Extensive experimental results demonstrate that the proposed method accelerates convergence speed and enhances model accuracy. Compared to existing classical federated learning methods, the model accuracy is improved by an average of 1.98% under various data distribution scenarios, while the time required to achieve the same accuracy is reduced by an average of 65.54%.
Wei Liang 0005, Kuanching Li, Weizhi Meng 0001
IEEE Internet Things J.5
2026 VFEFL: Privacy-preserving federated learning against malicious clients via verifiable functional encryption
Nina Cai, Jinguang Han, Weizhi Meng 0001
J. Inf. Secur. Appl.3
2026 BISE: Enhance data sharing security through consortium blockchain and IPFS
Mingxuan Chen, Puhe Hao, Weizhi Meng 0001, Yasen Aizezi, Guozi Sun
J. Inf. Secur. Appl.3
2026 Privacy-preserving federated learning from partial decryption verifiable threshold multi-client functional encryption
Jinguang Han, Weizhi Meng 0001
J. Inf. Secur. Appl.3
2026 Auditable cross-domain data sharing via threshold secret sharing and zero-knowledge proofs
abstract
Cross-domain data sharing in decentralised environments faces persistent challenges related to confidentiality, auditability, and trust decentralisation, particularly when data transmission relies on centralised intermediaries or single proxy entities. To address these issues, this paper proposes a blockchain-enabled auditable data sharing scheme that integrates threshold secret sharing with non-interactive zero-knowledge proofs. In the proposed framework, the encrypted file fragments and secret key shares are decentralised across multiple blockchain nodes using threshold cryptography, preventing any single entity from reconstructing the encryption key or unilaterally performing ciphertext transformations. Zero-knowledge proofs are employed to publicly verify the correctness of the transmission and sharing operations without disclosing plaintexts, secret keys, or sensitive metadata, while the blockchain records verifiable proofs to support tamper-evident auditing. Security analysis shows that the scheme achieves confidentiality, collusion resistance, and verifiable correctness under standard cryptographic assumptions.Experimental evaluations indicate that the proposed scheme incurs acceptable computational and on-chain overhead, suggesting its feasibility in decentralised and cross-domain data sharing scenarios.
Yuyang Yan, Zhexuan Yang, Junmin Cao, Weizhi Meng 0001, Guozi Sun
J. Inf. Secur. Appl.4
2026 Towards COLREGs-aware ship collision avoidance with multi-agent PPO-LSTM in maritime IoT
Weizhi Meng 0001, Shaoming He, Wenjuan Li 0001
J. Netw. Comput. Appl.2
2026 Exact constrained-training neural networks for confidential 8-bit arithmetic primitives in code obfuscation
Ning Shi, Tianqing Zhu, Wanlei Zhou 0001, Weizhi Meng 0001, Yu-an Tan 0001
J. Syst. Archit.5
2026 Singular transformation attack: Enhancing targeted transferability of adversarial examples via feature importance perturbation
Weizhi Meng 0001, Zhitao Guan, Yu-an Tan 0001
Knowl. Based Syst.2
2026 Hela: A System Call Restriction Framework for Protecting the Entire Containers Lifecycle
abstract
Limiting the number of system calls used by container processes can effectively reduce the kernel attack surface. Existing container system call restriction schemes only focus on the minimum system call set of applications in containers, and lack restrictions on the container runtime runc and other container components that create containers. To solve these problems, this paper proposes Hela, a system call restriction framework that can limit container runtimes and container applications. Hela introduces the Attack Surface Exposure Score (ASES), defined as the dot product of a container's system call usage vector and a risk-weight vector, to quantify exposure. Hela calculates and compares the ASES indicators of various partitioning schemes and selects the best partitioning boundary in the common hook nodes of runc. Hela divides the container creation phase into two phases and generates a minimum set of system calls for each phase. The advantage of Hela is that it combines seccomp with eBPF to achieve accurate parameter checking and efficient system call whitelist switching. Experimental results show that Hela can reduce the kernel attack surface of runc in container runtime compared to traditional schemes. Security experiments prove that our method can mitigate vulnerabilities involving runc and system call parameters.
Shaohu Li 0001, Jin Zhou 0017, Weizhi Meng 0001, Bei Gong
IEEE Trans. Cloud Comput.4
2026 LAHENet: A Lightweight Additive Homomorphic Edge Neural Network Framework for Industrial IoT
abstract
Edge nodes in the Industrial Internet of Things (IIoT) often face a fundamental trade-off between limited computational resources and stringent real-time inference requirements. Moreover, sensitive data they generated are exposed to significant privacy and security threats during transmission and computation. To address these challenges, this paper proposes a lightweight additive homomorphic edge neural network framework called LAHENet. This framework achieves millisecond-level inference latency in real-world industrial environments through a combination of a dual-metric feature selection strategy, an efficient additive homomorphic signcryption protocol, and a lightweight linear computation layer with adaptive layer collapsing. It ensures end-to-end confidentiality, unforgeability, forward security, and verifiable computation correctness. Experimental results show that LAHENet maintains a constant communication overhead at a few kilobytes per inference while preserving high model accuracy. It significantly enhances inference efficiency and reduces bandwidth consumption in edge environments, offering a practical private inference solution for large-scale IIoT deployments.
Mowei Gong, Zhe Li 0052, Xuepeng Lu, Bei Gong, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.6
2026 Ano2Rule: Rule-Based Global Interpretation for Unsupervised Anomaly Detection in Security
abstract
In the realm of cybersecurity, unsupervised anomaly detection models have emerged as pivotal tools for identifying novel threats in dynamic and evolving environments. However, the opaque nature of these black-box models presents a significant barrier to their adoption in high-stakes applications, where model interpretability is essential for trust and deployment. This paper presents a rule-based approach called Ano2Rule that enhances the interpretability of unsupervised anomaly detection. First, we propose the concept ofdistribution decomposition rulesthat decompose the complex distribution of normal data into multiple compositional distributions. To find such rules, we design an unsupervised Interior Clustering Tree that incorporates the model prediction into the splitting criteria. Then, we propose the Compositional Boundary Exploration (CBE) algorithm to obtain theboundary inference rulesthat estimate the decision boundary of the original model on each compositional distribution. By merging these two types of rules into a rule set, we can present the inferential process of the unsupervised black-box model in a human-understandable way, and build a surrogate rule-based model for online deployment at the same time. We validate Ano2Rule through extensive experiments on diverse real-world datasets, including network intrusion detection and IoT security, demonstrating superior fidelity and robustness compared to baseline methods. The results show that Ano2Rule achieves high fidelity with the original model's predictions while providing human-understandable insights.
Ruoyu Li 0003, Qing Li 0006, Nengwu Wu, Yong Jiang 0001, Weizhi Meng 0001, Laizhong Cui
IEEE Trans. Dependable Secur. Comput.6
2026 $\mathbb {ABC}$ABC-$ {\mathbb{Channel}}$Channel: An Advanced Blockchain-Based Covert Channel
abstract
Establishing efficient and robust covert channels is crucial for secure communication within insecure network environments. With its inherent benefits of decentralization and anonymization, blockchain has gained considerable attention in developing covert channels. To guarantee a highly secure covert channel, channel negotiation should be contactlessbeforethe communication, carrier transaction features must be indistinguishable from normal transactionsduringthe communication, and communication identities must be untraceableafterthe communication. Such a full-lifecycle covert channel is indispensable to defend against a versatile adversary who intercepts two communicating parties comprehensively (e.g., on-chain and off-chain). Unfortunately, it has not been thoroughly investigated in the literature. We make the first effort to achieve a full-lifecycle covert channel, a novel blockchain-based covert channel namedABC-Channel. We tackle a series of challenges, such as off-chain contact dependency, increased masquerading difficulties as growing transaction volume, and time-evolving, communicable yet untraceable identities, to achieve contactless channel negotiation, indistinguishable transaction features, and untraceable communication identities, respectively. We develop a working prototype to validateABC-Channeland conduct extensive tests on the Bitcoin testnet. The experimental results demonstrate thatABC-Channelachieves substantially secure covert capabilities. In comparison to existing methods, it also exhibits state-of-the-art transmission efficiency.
Xiaobo Ma 0001, Pengyu Pan, Jianfeng Li 0006, Wei Wang 0012, Weizhi Meng 0001, Xiaohong Guan
IEEE Trans. Dependable Secur. Comput.5
2026 An XSS Attack Detection Model Based on Two-Stage AST Analysis
abstract
Cross-site scripting (XSS) attacks pose a significant threat to web applications and user privacy, with the number of such attacks rapidly increasing. Although existing machine learning and deep learning-based XSS attack detection models are effective against common XSS attacks, these models all overlook their own security and often fail to defend against adversarial samples that exploit model vulnerabilities, allowing attackers to successfully bypass these models by using XSS adversarial samples. To address this challenge, in this paper, we propose a novel XSS attack detection model based on two-stage Abstract Syntax Tree (AST) analysis and Long Short-Term Memory (LSTM) neural networks, effectively mitigating the impact of adversarial samples. Our model leverages the ability of AST parsing and analysis of HTML and JavaScript code to effectively eliminate redundant information and adversarial perturbations introduced by adversarial samples. The two-stage process first extracts JavaScript code from the HTML AST, then identifies malicious code fragments from the JavaScript AST. Finally, the LSTM neural network is trained to classify samples as malicious or benign. By analyzing the HTML and JavaScript components of web pages, our model identifies and eliminates adversarial perturbations that interfere with detection, significantly enhancing the security and reliability of the detection process. Extensive experiments on real datasets demonstrate our model's superior performance, achieving an accuracy rate of 0.991 and an F1 score of 0.998 against standard XSS samples, outperforming existing models. More importantly, when facing adversarial XSS samples, most existing detection models exhibit severe robustness degradation with the detection rate (DR) below 0.880, whereas our model maintains a detection rate of over 0.982, significantly higher than state-of-the-art models and demonstrating its significant effectiveness in defending against XSS adversarial attacks.
Qiuhua Wang, Chuangchuang Li, Lifeng Yuan, Dong Wang 0019, Yeru Wang, Yizhi Ren, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.7
2026 An Efficiency-Improved and Conditional Privacy-Preserving Authentication Scheme Based on Merkle Hash Tree in MEC
abstract
Authentication is an important security issue for multi-access edge computing (MEC). However, the existing authentication schemes have not achieved a good balance between privacy preserving, efficiency, and low computation overhead on the device side. To address this issue, we propose an efficiency-improved and conditional privacy-preserving authentication scheme suitable for resource-constrained MEC devices. Our core idea is integrating the merkle hash tree (MHT) into the anonymous authentication scheme constructed by the blockchain and key derivation function (KDF) to improve efficiency. The MHT not only reduces the on-chain storage overhead brought by the increasing pseudo-public keys of KDF, but also utilizes few hash functions to achieve lightweight${\bm {k}}$-times authentications with the same edge server. Despite these advantages, managing pseudo-key pairs in the form of MHT leafs still brings efficiency and unlinkability problems. We construct the partially shuffled merkle hash tree to only shuffle leafs within the device group, and combine with the KDF to update MHTs in a public manner by synchronizing pseudo-key pairs. Consequently, the efficiency of key update can be ensured. Moreover, a time-bound key derivation function based on physically unclonable function and BIP-32 is developed to provide immediate and permanent device revocation. Only the remaining valid pseudo-public keys of the revoked device will be recorded on the blockchain, which reveals no linkable information and avoids frequently reconstructing all the MHTs. We prove the authentication security and discuss other security features. A proof-of-concept prototype was implemented to conduct experiments and comparative analysis for performance evaluation.
Yan Zhang 0097, Chunsheng Gu, Peizhong Shi, Zhengjun Jing, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.6
2026 GDetox: Purifying Backdoor Encoder in Graph Self-Supervised Learning via Knowledge Distillation
abstract
Graph Neural Networks (GNNs) have powerful representation capabilities for graph data, achieving excellent performance across various fields. Considering the scarcity of labels in real-world scenarios, graph self-supervised learning (GSSL) has gained increasing attention due to its ability to train without relying on labels. However, recent studies have revealed that GNNs are vulnerable to stealthy backdoor attacks in GSSL scenarios, enabling the encoder to learn backdoor features simply by injecting triggers. Existing graph backdoor defense methods mainly focus on supervised settings and cannot be directly transferred to self-supervised scenarios due to the lack of label guidance. To bridge this gap, we proposeGDetox, the first backdoor defense approach against backdoored encoders in GSSL.GDetoxaims to eliminate backdoor logic in encoders while maintaining the encoder's original performance. Specifically,GDetoxcan purify the graph backdoor encoder based on the self-supervised distillation approach without relying on label information. Further, we introduce an adversarial contrastive learning that augments node representations without relying on labels to enhance teacher model performance, thereby improving distilled encoder performance. We evaluate the defense performance ofGDetoxon four node classifications and four graph classification datasets by comparing with four state-of-the-art (SOTA) defense methods against seven latest backdoor attack methods on GSSL. Extensive experiments demonstrate thatGDetoxfar outperforms the SOTA defense methods, reducing the attack success rate to 4% with negligible degradation in encoder performance (within 2%) in both node-level and graph-level tasks.
Hao Sui 0003, Jiale Zhang 0001, Bing Chen 0002, Chunpeng Ge 0001, Weizhi Meng 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.6
2026 CoGA: A Collaborative Gray-Box Adversarial Attack for Multimodal Language Models
abstract
Multimodal language models (LMs) have shown significant potential for applications across various domains but remain vulnerable to adversarial attacks. Current research in white-box or black-box settings generally struggles with unrealistic attack assumptions and limited efficacy of targeted attacks. This paper introduces CoGA, a novel gray-box collaborative adversarial attack method for multimodal LMs. Under our gray-box settings, attackers have access only to the victim model’s input encoders. With the guidance of different modalities, we perturb the embedding representations from encoders to disrupt the semantic alignment across modalities, ultimately causing inaccurate outputs on various downstream tasks. Specifically, we integrate text embeddings into the loss calculations of the image attack and utilize image embeddings to guide the ranking of vulnerable words and the selection of final samples. Extensive experiments demonstrate that our method achieves superior attack performance across diverse models and tasks, suggesting the shared vulnerability of multimodal LMs in confronting adversarial challenges. Our work provides new insights into the security of multimodal LMs, facilitating the deployment of more robust and secure models in practical applications.
Feng Lin 0004, Gaojian Wang, Tiantian Liu 0002, Zhibo Wang 0001, Weizhi Meng 0001, Ajian Liu 0001, Kui Ren 0001
IEEE Trans. Inf. Forensics Secur.6
2026 SAPP: Achieving Semantic-Aware Differential Privacy for Spatiotemporal Trajectory Data Publishing
abstract
With the increasing availability of large-scale spatiotemporal data from location-based services, trajectory publishing has become essential for data-driven analysis and intelligent applications. However, insufficient protection of trajectory location data may result in the disclosure of user privacy and social relationship information. To address this issue, we propose a semantic-aware privacy-preserving trajectory data publishing scheme (SAPP). First, a sliding-window algorithm is employed to extract stay points as key semantic locations and to generate a uniformly sampled set of candidate obfuscation points. Then, a semantic-aware scoring function is designed to probabilistically select candidate points that preserve semantics while avoiding sensitive regions. Furthermore, SAPP computes the sensitivity of each location based on semantic frequency and dynamically allocates the privacy budget. Finally, random noise is added to candidate trajectories using the Laplace mechanism. Through a dual-perturbation mechanism, spatial correlations in sensitive regions are weakened. Security analysis and experimental results further demonstrate that, compared with existing approaches, SAPP reduces TPPS and SFRR by up to 18% and 14%, respectively, indicating stronger resistance against trajectory inference and semantic leakage attacks while maintaining high data utility and time efficiency.
Lei Wu 0011, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001, Zhiquan Liu 0001
IEEE Trans. Knowl. Data Eng.5
2026 ROMA: Enhancing Container OOM Resilience via Reinforced Isolation and Adaptive Shared Resource Reclamation
abstract
Container-based virtualization is a cornerstone of modern cloud orchestration, but the shared-kernel architecture also introduces subtle risks to memory isolation. Our study shows that Linux cgroups and the default Out-of-Memory (OOM) mechanism lack sufficient container context when selecting victim processes. As a result, a malicious container may disrupt critical co-located services and leave behind unreclaimed shared resources, such as POSIX/SysV shared memory, message queues, semaphores, and tmpfs files. These residual resources can accumulate over time and eventually lead to denial-of-service conditions. To address this problem, we propose ROMA, an adaptive memory-governance framework for containerized environments. ROMA introduces container awareness into the OOM handling path while maintaining low runtime overhead. It combines eBPF-based monitoring with two lightweight LSM hooks to confine OOM victim selection to the offending container and to proactively reclaim shared resources left behind after OOM events. Extensive experiments show that ROMA incurs only a 6.94% throughput overhead across eight workloads. Under up to eight concurrent attackers, ROMA preserves isolation, avoids collateral kills, reclaims all leaked resources, and keeps recovery time within 6.9 seconds. In 24-hour runs with up to 64 containers, ROMA remains stable with low CPU and memory overhead, negligible event loss, and limited impact on benign services.
Shaohu Li 0001, Jin Zhou 0017, Weizhi Meng 0001, Bei Gong, Yong Wang 0028
IEEE Trans. Serv. Comput.5
2025 Reinforcement Learning-Based Autonomous Collision Avoidance for Ships in Realistic Physical Environments
Weizhi Meng 0001, Shaoming He
ICA3PP (4)2
2025 Traffic Accident Detection Via Fusion-Gru Based Future Frame Detection Box Prediction
abstract
With the rapid development of autonomous driving and advanced driver assistance systems, efforts to enhance driving safety, especially in detecting traffic accidents when natural driving states are unclear, have increased significantly. Generally, traffic anomalies are defined as events that deviate from common occurrences and expected behaviors, such as vehicles and pedestrians disregarding traffic signals to cross arbitrarily, or vehicles abruptly stopping ahead. In real driving scenarios, timely detection of potential traffic accidents by autonomous vehicles is crucial for prompt response and accident prevention. In this work, we aim to address such challenges regarding traffic accident detection by proposing a future frame detection box prediction model based on Fusion-GRU for predicting future vehicle positions. In the evaluation based on two datasets, our results demonstrate that our approach can provide significant improvements in detection performance over similar studies.
Weizhi Meng 0001, Rongxing Lu
ICC2
2025 Actions Speak Louder Than Words: Evidence-Based Trust Level Evaluation in Multi-agent Systems
Nikolaos Fotos, Koffi Ismael Ouattara, Dimitrios S. Karas, Ioannis Krontiris, Weizhi Meng 0001, Thanassis Giannetsos
ICICS (2)5
2025 Parallel FHE-Based Neural Network Inference with Knowledge Distillation for Efficient Privacy-Preserving Image Classification
Junyu Lin 0001, Jiageng Chen, Jichao Xiong, Weizhi Meng 0001, Chunhua Su
KSEM (4)5
2025 StressSentry-FHE: A Transformer-Based Privacy-Preserving Framework for Stress Detection Using Quantized Attention
Jichao Xiong, Jiageng Chen, Junyu Lin 0001, Chunhua Su, Weizhi Meng 0001
KSEM (2)6
2025 Towards Practical Automotive Intrusion Detection Systems: An Adaptive Rule-Based Approach
Lucien Kiven Tamo, Brooke Kidmose, Weizhi Meng 0001, Thanassis Giannetsos
NSS3
2025 A Deep Reinforcement Learning Framework for Robust Maritime Collision Avoidance Under GPS Spoofing
Weizhi Meng 0001, Shaoming He, Wenjuan Li 0001
ProvSec2
2025 A Dual-Stage Anomaly Detection Framework for Stealthy Attacks in 5G Core Networks
abstract
The N4 interface, which connects the Session Management Function (SMF) and the User Plane Function (UPF) via the PFCP protocol in the 5G core network, is vulnerable to attacks such as unauthorized access and signaling injection. These threats can lead to session interruptions and denial-of-service (DoS) attacks. Due to the stealthy nature of such anomalies, existing detection methods struggle with issues such as sample imbalance and ambiguous category boundaries. To address these challenges, this paper proposes a dual-stage anomaly detection framework based on the distribution characteristics of signaling. First, we statistically analyze the distributional differences between normal and abnormal PFCP signaling to uncover behavioral patterns and define precise categories of anomalies, each associated with a specific probabilistic model. Then, a Dual-Stage Abnormal Detection Framework (DSAF) is developed, integrating a KNN-based distance detector with a deep learning classifier to achieve hierarchical detection of abnormal signaling on the N4 interface. Experimental results on a real-world PFCP dataset demonstrate that the proposed method outperforms mainstream detection approaches in terms of accuracy, recall, and F1 score, providing solid theoretical and technical support for signaling security in 5G core networks.
Weizhi Meng 0001, Zilong Wang 0001
TrustCom3
2025 Intelligent routing methods for low-Earth orbit satellite networks based on machine learning: A comprehensive survey
Zheheng Rao, Shitong Xiao, Ye Yao 0003, Yanyan Xu 0003, Weizhi Meng 0001
Ad Hoc Networks6
2025 Interpretable adversarial example detection via high-level concept activation vector
Jiaxing Li 0012, Yu-an Tan 0001, Weizhi Meng 0001, Yuanzhang Li 0001
Comput. Secur.4
2025 FeatureBA: Hard label black box attack based on internal layer features of surrogate model
Jiaxing Li 0012, Yu-an Tan 0001, Runke Liu, Weizhi Meng 0001, Yuanzhang Li 0001
Expert Syst. Appl.4
2025 Blockchain-Driven Distributed Edge Intelligence for Enhanced Internet of Vehicles
abstract
In the evolving landscape of vehicular networks, it is crucial to ensure robust security and efficient data handling. In this work, we introduce a novel federated learning (FL) algorithm integrated within a distributed edge intelligence (DEI) framework, enhanced by a blockchain consensus mechanism, specifically designed for Internet of Vehicles (IoV) to enhance data privacy, efficiency, and system resilience. Motivated by the pressing need for improved data privacy and security in the IoV, our approach can not only prioritize these aspects but also enhance the efficiency and accuracy of distributed machine learning. The proposed consensus mechanism, by integrating Proof-of-Knowledge (PoK) with practical Byzantine fault tolerance (PBFT), is crafted to be lightweight, making it suitable for the dynamic and resource-constrained vehicular environments. Our evaluation findings demonstrate the algorithm’s superior performance and scalability, suggesting its applicability in diverse IoV scenarios and its potential to facilitate secure, robust, and efficient collaborative learning.
Xiaofu Chen, Weizhi Meng 0001, Heyang Huang
IEEE Internet Things J.2
2025 Verifiable Aggregation for Heterogeneous Decentralized Identity in Internet of Things
abstract
Blockchain-based decentralized identity (DID) typically employs identity aggregation techniques to support efficient and trustworthy identity authentication in order to meet the requirements of the high volume of service requests in Internet of Things (IoT). Due to the lack of effective mechanisms for heterogeneous DID (H-DID) aggregation, a complete aggregated identity authentication often requires multiple rounds of signature verification for different identity attributes. However, this setting brings trust and privacy issues, and one notable threat is the potential disclosure of secret identity information through the linkage of heterogeneous identity attributes when enormous IoT devices/accesses are involved. In this article, we focus on trustworthy authentication of DID and propose a novel anonymous verifiable credential-based aggregation for h-DID (AVCA-hDID). Our AVCA-hDID model supports anonymous ownership verification of DIDs through label randomization, thereby effectively safeguarding identity privacy in IoT. AVCA-hDID involves identifier aggregation and attribute aggregation for H-DIDs, ensuring both authentication efficiency and balancing trustworthiness and adoptability. We analyze the security and unlinkablility of our proposed model and further experiment evaluation demonstrates the efficiency and effectiveness of AVCA-hDID.
Kai Ding 0008, Tianxiu Xie, Keke Gai, Jing Yu 0007, Chennan Guo, Zhengkang Fang, Liehuang Zhu, Weizhi Meng 0001
IEEE Internet Things J.8
2025 Privacy-Enhanced Federated WiFi Sensing for Health Monitoring in Internet of Things
abstract
The development of the Internet of Things (IoT) has led to the widespread use of WiFi-enabled consumer electronic devices, which are now common in everyday life. These advancements in IoT have greatly improved data collection and analysis capabilities, especially for health monitoring applications. However, traditional centralized machine learning methods often fall short, raising significant privacy concerns and requiring extensive data collection, which is inefficient. To address these limitations within the distributed IoT environment, this article presents a federated learning (FL)-based WiFi sensing system specifically designed for health monitoring. By enabling local model training, our system prevents the sharing of sensitive data, thus reducing the risk of privacy breaches. We further enhance our system with a secret sharing mechanism coupled with model sparsification to significantly improve privacy. Additionally, our improved top-k model sparsification algorithm, equipped with adaptive residuals, reduces communication overhead while ensuring high accuracy. Extensive testing across various datasets and models confirms that our system outperforms existing benchmarks in terms of privacy protection and communication efficiency, marking a substantial advancement in health monitoring within the IoT.
Zhuotao Lian, Qingkui Zeng, Zhusen Liu, Haoda Wang, Chuan Ma 0001, Weizhi Meng 0001, Chunhua Su, Kouichi Sakurai
IEEE Internet Things J.6
2025 Guest Editorial Special Issue on Security and Privacy of Intelligent Vehicles
abstract
Intelligent vehicles are systems tightly integrating computation, communication, and physical behavior. The recent proliferation of artificial intelligence, machine learning, the Internet of Things (IoT), and edge-fog–cloud computing envisions that intelligent vehicles are capable of innovative solutions to change our lifestyles. However, the potential benefits come along with new challenges and concerns on security and privacy. This special issue consists of 12 papers and covers broad research contributions, including 1) intrusion detection from in-vehicular networks to connected vehicles, drones, and global positioning systems; 2) authentication with matchmaking encryption, certificateless cryptography, and blockchains for Internet of Vehicles; 3) privacy protection with data sharing and cross-vehicle federated learning; and 4) secure data analysis supported by the cloud. The special issue seeks to assist theoretical analysis, system architecture design, emerging applications, and social impacts of intelligent vehicles.
Chung-Wei Lin, Bo Chen 0028, Weizhi Meng 0001, Yu Chen 0002, Qi Zhu 0002
IEEE Internet Things J.3
2025 AATM: An Anonymous Authentication Protocol for Time Span of Membership With Self-Blindness and Accountability
abstract
Internet of Things (IoT) devices using subscription services (e.g. connected vehicles accessing entertainment programs) often purchase membership credentials from service providers with limited usage counts or validity periods, we call them pay-per-use or time span of membership services. However, users’ access records, usage preferences, and habits are collected by network adversarys or membership providers for creating users’ profiles, targeted advertising, and even for being sold maliciously. To deal with these problems, lots of anonymous authentication protocols are proposed to provide users with pseudonyms to conceal their real identities. Although these protocols effectively prevent network adversarys from compromising users’ privacy, membership service providers can still gather users’ behavioral privacy via their membership credentials. Therefore, several scholars proposed k-times anonymous authentication protocols and self-blind credentials to enhance users’ privacy protection, but the k-times anonymous authentication protocols are only for pay-per-use membership services and the schemes of self-blind credentials are lack of regulating malicious users. To address these issues, this article proposes an anonymous authentication protocol for time span of membership (AATM) with self-blindness and accountability. Specifically, we utilize Structure Preserving Signatures on Equivalence Classes (SPS-EQ) and Signatures with Flexible Public Key (SFPK) to build accountable, self-blinding credentials that ensure that every time a user visits a member, he or she can create a brand new identity on their own, which not only prevents users from being linked by service providers, but also supports conditional fair regulation. Security and performance analyses show that AATM is better than the state-of-the-art schemes in terms of security and privacy-preserving capabilities, and its computation cost also meets the practical application requirements.
Qiuyun Lyu, Xiwen Liang, Shaopeng Cheng, Yizhi Ren, Chengli Xu, Weizhi Meng 0001, Duohe Ma
IEEE Internet Things J.7
2025 BANN-TMGuard: Toward Touch-Movement-Based Screen Unlock Patterns via Blockchain-Enabled Artificial Neural Networks on IoT Devices
abstract
Internet of Things (IoT) devices, such as smartphones, have become important to people’s everyday usage, especially the number of smartphone shipment has surpassed six billion and is forecast to further grow. The smartphone security is the top priority as people may store various sensitive information on these devices. Currently, phone unlock patterns, e.g., Android unlock patterns, are one of the main protection methods to protect smartphones from unauthorized access. However, many research studies have revealed that cyber-attackers can easily compromise this type of unlock mechanism, i.e., learning the pattern from the touch residue. In this work, we advocate that an additional security layer should be added to enhance the security of Android unlock patterns, and thus develop a touch movement-based unlock mechanism via blockchain-enabled artificial neural networks (ANNs), named BANN-TMGuard, which can examine the biometric features of a user’s touch movement as well as the input pattern. Further, BANN-TMGuard adopts blockchain technology to secure the robustness and reliability when building the ANN models. In the evaluation, we perform a user study with 100 participants in the aspects of authentication accuracy, time consumption and user feedback. As compared with similar schemes, our BANN-TMGuard demonstrates better results and is preferred by most participants in the user study.
Weizhi Meng 0001, Wenjuan Li 0001, Andrei Nicolae Calugar
IEEE Internet Things J.1
2025 Equipment failure data trends focused privacy preserving scheme for Machine-as-a-Service
Zhengjun Jing, Yongkang Zhu, Quanyu Zhao, Yuanjian Zhou, Chunsheng Gu, Weizhi Meng 0001
J. Inf. Secur. Appl.6
2025 Privacy-preserving and verifiable multi-task data aggregation for IoT-based healthcare
Xinzhe Zhang, Lei Wu 0011, Lijuan Xu 0001, Zhien Liu, Ye Su 0001, Hao Wang 0007, Weizhi Meng 0001
J. Inf. Secur. Appl.7
2025 ABA-LEP: Autonomous Bidirectional Authentication and Lightweight Encryption Protocol for drones under ARM architecture
Qian Zhou 0005, Jiayang Wu 0003, Weizhi Meng 0001
J. Inf. Secur. Appl.3
2025 Verifiable decentralized identity-based meta-computing in Industrial Internet of Things (IIoT)
Kai Ding 0008, Tianxiu Xie, Keke Gai, Chennan Guo, Liangqi Lei, Dongjue Wang, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001
J. Syst. Archit.9
2025 FedPG: a privacy-friendly and universal method for solving non-IID data in federated learning
Baolu Xue, Jiale Zhang 0001, Bing Chen 0002, Weizhi Meng 0001
Pattern Anal. Appl.4
2025 PPSKSQ: Towards Efficient and Privacy-Preserving Spatial Keyword Similarity Query in Cloud
abstract
The growth of cloud computing has led to the widespread use of location-based services, such as spatial keyword queries, which return spatial data points within a given range that have the highest similarity in keyword sets to the user’s. As the volume of spatial data increases, providers commonly outsource data to powerful cloud servers. Because cloud servers are untrustworthy, privacy-preserving keyword query schemes have been proposed. However, existing schemes consider only location queries or exact keyword matching. To address these issues, we propose the Privacy-Preserving Spatial Keyword Similarity Query Scheme (PPSKSQ), designed to search for spatial data points with the highest similarity while protecting the privacy of outsourced data, query requests, and results. First, we design two sub-protocols based on improved symmetric homomorphic encryption (iSHE): iSHE-SC for secure size comparison and iSHE-SIP for secure inner product computation. Then, we encode range information and integrate it with a quadtree to construct a novel index structure. Additionally, we use the Jaccard to measure similarity in conjunction with the iSHE-SC protocol, transforming similarity comparison into a matrix trace operation. Finally, rigorous security analysis and extensive simulation experiments confirm the flexibility, efficiency, and scalability of our scheme.
Changrui Wang, Lei Wu 0011, Lijuan Xu 0001, Hao Wang 0007, Wenying Zhang 0001, Weizhi Meng 0001
IEEE Trans. Cloud Comput.7
2025 CAPE: Commitment-Based Privacy-Preserving Payment Channel Scheme in Blockchain
abstract
Ensuring scalability in cryptocurrency systems is significant in guaranteeing real-world utility along with the remarkable increment of cryptographic currency. As an alternative in solving scalability issue, payment channel allows users to deliver extensive offline transactions without uploading massive transaction details to the blockchain, such that increasing efficiency can be achieved. However, the implementation of payment channel still encounters privacy concerns when considering the publicly available transaction amounts and the potentials in mining associations between transaction parties. In this paper, we propose a novel payment channel scheme, entitledCommitment-basedAnonymousPayment ChannEl (CAPE), to facilitate unlimited off-chain bidirectional payments while guaranteeing participants’ privacy. The proposed scheme adopts zero-knowledge proof (zk-SNARKs) and verifiable timed (VTD) commitments to ensure the anonymity of the relationship between on-chain and off-chain transactions, privacy of transaction amounts, and security of balances. We comprehensively formalize security definitions and present rigorous proofs for each security attribute. Experiment results further demonstrate the practical viability of CAPE.
Keke Gai, Yunwei Guo, Jing Yu 0007, Weilin Chan, Liehuang Zhu, Yinqian Zhang, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.7
2025 A Scheme of Robust Privacy-Preserving Multi-Party Computation via Public Verification
abstract
Multi-Party Computation (MPC), as a distributed computing paradigm, is considered to be a potential solution for providing privacy-preserving for applications following the client-server model. However, traditional MPC solutions cannot satisfy the publicly verifiable requirement of the client-server model. In this paper, we propose a blockchain-based verifiable MPC solution using Pedersen's threshold secret sharing and Lifted ElGamal encryption. We first build a data distribution method using Pedersen's threshold secret sharing and symmetric encryption to protect the privacy of inputs while ensuring robustness. Then, we propose a result processing algorithm using Lifted ElGamal encryption to safeguard the privacy of the outputs. Finally, we employ non-interactive zero-knowledge proof and Pedersen commitment to publicly verify the correctness of the encrypted outputs in the smart contract, enabling the detection of malicious parties. Theoretical analysis indicates that the proposed method can publicly verify the correctness of outputs without revealing plain-text inputs and outputs, which satisfy the privacy-preserving requirements of the client-server model. Experimental evaluations have demonstrated that our proposed approach is efficient regarding computation overhead, communication overhead, and response time in the output verification phase while achieving stronger privacy and robustness.
Keke Gai, Dongjue Wang, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.5
2025 StealthPath: Privacy-Preserving Path Validation in the Data Plane of Path-Aware Networks
abstract
Network path validation aims to give more control over the forwarding path of data packets in a path-aware network, which shields the network from security threats and allows end hosts to receive better services. Therefore, network path validation becomes a vital primitive for secure and reliable Internet services in the next generation networks. The path validation enables end hosts and intermediate router nodes to check whether a packet has followed the intended path. However, the existing solutions fail to protect path privacy and incur significant bandwidth and computation overhead on packet transferring, which degrades packet delivery performance. In this paper, we propose the StealthPath to protect path privacy and improve delivery efficiency. Firstly, StealthPath uses lightweight cryptographic primitives to generate nested proofs and ensures all nodes on the path to check the compliance of the forwarding path efficiently. Secondly, StealthPath hides the forwarding path in the proofs and reduces the proof size from linear to constant, which protects the path information and path length, and decreases the bandwidth consumption. Moreover, StealthPath allows on-path nodes to extract their proofs and the next hop address from proof without leaking on-path node index. Finally, StealthPath is proved to resist various attacks and preserves the path privacy. The experiments show that StealthPath saves nearly 60% header size and bandwidth, and is more efficient than state-of-the-art schemes.
Yuan Su, Rongxing Lu, Zhou Su 0001, Weizhi Meng 0001, Meng Shen 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Blockchain-Assisted Searchable Integrity Auditing for Large-Scale Similarity Data With Arbitration
abstract
Data integrity auditing technology serves as an essential tool to ensure the data's integrity with the popularity of remote storage. However, existing data integrity auditing models are unsuitable for a large number of files with interrelationships and heavily depend on a centralized Third-Party Auditor (TPA). To address these issues, in this paper we propose a blockchain-assisted searchable integrity auditing scheme for large-scale similarity data. To broaden the scope of the auditing model and enhance its ability to handle interconnected files, we utilize the keyword to design a search index and a trapdoor to achieve authenticator searchability for the interconnected files. The integrity of the searching result from the cloud side can be guaranteed at the same time. To reduce reliance on centralized TPA and enhance the credibility and transparency of auditing, we integrate blockchain technology along with smart contracts to replace TPA and achieve multitask auditing. We adopt a certificateless cryptosystem to generate the authenticator, while considering the cost reduction. Moreover, an arbitrator is proposed to achieve fairness judge. Theoretical and security analysis demonstrate that the proposed scheme is efficient and secure, making it a promising solution for data auditing in a wide range of applications.
Ying Miao 0002, Keke Gai, Yu-an Tan 0001, Liehuang Zhu, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.5
2025 High Capacity Reversible Data Hiding in Encrypted 3D Mesh Models Based on Dynamic Prediction and Virtual Connection
abstract
In recent years, reversible data hiding in encrypted domain (RDH-ED) has garnered considerable interest among researchers, resulting in the development of high-performance methods based on various carriers. However, the challenge of enhancing the data embedding capacity while ensuring reversibility becomes increasingly pronounced when the carrier is a three-dimensional (3D) model. In this paper, a high capacity RDH-ED method based on dynamic prediction and virtual connection for 3D models is proposed. Unlike existing methods that partition the vertices in the model into embeddable and prediction sets, where each vertex can only serve one function, the proposed dynamic prediction mechanism constructs a data embedding order set by leveraging the connectivity relationships between vertices. This allows each vertex within the set to both embed data and provide predictions, significantly increasing the proportion of embeddable vertices. Moreover, the proposed method is the first work to consider independent vertices within the model and integrates a novel virtual connection approach with the dynamic prediction process, enabling all independent vertices to participate in data embedding and prediction, thereby further enhancing the data embedding capacity. Experimental results demonstrated that the proposed method significantly outperforms other state-of-the-art methods in terms of data embedding capacity while ensuring reversibility.
Ke Wang 0039, Ye Yao 0003, Yanzhao Shen, Fengjun Xiao, Yizhi Ren, Weizhi Meng 0001
IEEE Trans. Dependable Secur. Comput.6
2025 FedAMM: Federated Learning Against Majority Malicious Clients Using Robust Aggregation
abstract
As a collaborative framework designed to safeguard privacy,Federated Learning(FL) seeks to protect participants’ data throughout the training process. However, the framework still faces security risks from poisoning attacks, arising from the unmonitored process of client-side model updates. Most existing solutions address scenarios where less than half of clients are malicious, i.e., which leaves a significant challenge to defend against attacks when more than half of participants are malicious. In this paper, we propose a FL scheme, named FedAMM, that resists backdoor attacks across various data distributions and malicious client ratios. We develop a novel backdoor defense mechanism to filter out malicious models, aiming to reduce the performance degradation of the model. The proposed scheme addresses the challenge of distance measurement in high-dimensional spaces by applyingPrincipal Component Analysis(PCA) to improve clustering effectiveness. We borrow the idea of critical parameter analysis to enhance discriminative ability in non-iid data scenarios, via assessing the benign or malicious nature of models by comparing the similarity of critical parameters across different models. Finally, our scheme employs a hierarchical noise perturbation to improve the backdoor mitigation rate, effectively eliminating the backdoor and reducing the adverse effects of noise on task accuracy. Through evaluations conducted on multiple datasets, we demonstrate that the proposed scheme achieves superior backdoor defense across diverse client data distributions and different ratios of malicious participants. With 80% malicious clients, FedAMM achieves low backdoor attack success rates of 1.14%, 0.28%, and 5.53% on MNIST, FMNIST, and CIFAR-10, respectively, demonstrating enhanced robustness of FL against backdoor attacks.
Keke Gai, Dongjue Wang, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001
IEEE Trans. Inf. Forensics Secur.5
2025 ECGSH: An Efficient Certificateless Group Signcryption-Based Homomorphic in Industrial IoT
abstract
With the growth of the Industrial Internet of Things (IIoT), millions of smart devices are transmitting and processing data globally. However, this extensive interconnectivity also poses significant security challenges, particularly in data transmission. Traditional security mechanisms often incur high computational costs and long processing times, which are impractical for resource-constrained devices. In this paper, we propose an efficient and secure data processing and transmission scheme for the IIoT called ECGSH. This scheme combines certificateless signcryption and homomorphic encryption to enable homomorphic processing in an encrypted state, thus enhancing both security and flexibility. Moreover, it reduces the complexity of large-scale data processing by eliminating bilinear pair computations. The ECGSH scheme also supports homomorphic data transmission in the IIoT. A rigorous security analysis proves that the scheme has the properties of confidentiality, non-repudiation, and forward security under the random oracle model. An attack resistance analysis proves that the scheme can effectively resist man-in-the-middle (MITM) attacks, replay attacks, and eavesdropping attacks. The performance evaluation demonstrates that ECGSH excels in terms of security, computational efficiency, and communication overhead. It requires at most 31% CPU utilization, and less than 1.2% memory footprint on IIoT hardware, making it particularly suitable for IIoT environments with limited resources and high transmission costs.
Bei Gong, Mowei Gong, Zhe Li 0052, Weizhi Meng 0001
IEEE Trans. Inf. Forensics Secur.5
2025 Enhancing EEG-Based Authentication With Transformer in Internet of Things
abstract
With the rapid growth of Internet of Things (IoT) and edge computing platforms, the Internet of Medical Things (IoMT) has become popular and important in healthcare industry, i.e., there is an increase of brainwave headsets and headbands. However, the security and privacy of shared data can be easily compromised if an attacker can access the IoMT devices and check all the data. There is a need to authenticate users before they can use the healthcare devices. For this reason, Electroencephalography (EEG) based authentication is a necessary security solution. In recent years, EEG-based authentication has witnessed significant advancements, but traditional models face challenges in capturing the complex spatial and temporal dependencies present in EEG signals. This work aims to address these limitations and explore the effect of Transformer model in the domain of EEG-based authentication. In particular, we devise a modified Vision Transformer model (ViT) to handle the specific characteristics of EEG data, such as spatial and temporal dependencies. In the evaluation, we compare our approach with the similar methods in the literature and examine the effect of fine-tune based on two datasets. The results demonstrate that our approach can effectively capture long-range dependencies and outperform conventional models.
Chunxue Li, Weizhi Meng 0001, Wenjuan Li 0001
IEEE Trans. Inf. Forensics Secur.2
2025 Blockchain-Empowered Keyword Searchable Provable Data Possession for Large Similar Data
abstract
Provable Data Possession (PDP) is an alternative technique that guarantees the integrity of remote data. However, most current PDP schemes are inapplicable to similarity-like data checking with the same attribute, i.e., when there are numerous similar files to be checked by Data Owners (DOs). Some traditional models cannot resist the corrupt auditors who always generate biased challenge information. Besides, a copy-summation attack exists in some schemes, which means the Cloud Server (CS) can bypass the verification by storing the median value instead of initial data via summation operation. To address the issues above, in this work, we propose a keyword searchable PDP scheme for large similar data checking. To achieve searchability, we introduce the notion of a keyword in PDP and design a specific index structure to match the authenticator. The scheme enables all matched files to be auditable and verifiable, while guaranteeing privacy protections. Unlike existing methods, our Third Party Auditor (TPA) checks all similar data containing the same keyword simultaneously. We utilize unpredictable yet verifiable public information on the blockchain to generate challenge information, rather than relying on a centralized TPA. The proposed scheme can resist copy-summation attacks. Theoretical analysis demonstrates that the proposed scheme satisfies the security requirements, and our evaluations demonstrate its efficiency.
Ying Miao 0002, Keke Gai, Jing Yu 0007, Yu-an Tan 0001, Liehuang Zhu, Weizhi Meng 0001
IEEE Trans. Inf. Forensics Secur.6
2025 FlashAttest: Self-Attestation for Low-End Internet of Things via Flash Devices
abstract
Remote Attestation (RA) is an effective security service that allows a trusted party (verifier) to initiate the attestation routine on a potentially untrusted remote device (prover) to verify its correct state. Despite their usefulness, traditional challenge-response remote attestation protocols suffer from certain limitations, such as challenges in scaling attestation collection and the forced suspension of normal operation during attestation. Self-attestation tackles these issues by enabling the prover to measure its own state asynchronously with the verifier’s attestation request. Existing self-attestation methods rely on hybrid architectures to provide the required security properties, which may not be compatible with low-end Internet of Things (IoT) devices due to hardware limitations. In addition, these protocols currently lack formal verification of design correctness. In this paper, we present FlashAttest, a formally verified self-attestation protocol for low-end IoT devices. FlashAttest leverages the flash device to fulfill the security properties required by self-attestation, eliminating the requirement for hardware modifications. In particular, FlashAttest allows the prover to initiate the attestation routine and guarantee the trustworthiness of the results based on the verified software-based security architecture. By collaborating with the flash device during attestation to generate timestamped reports, FlashAttest enables the verifier to collect and verify the legitimacy of the attestation results. More importantly, FlashAttest achieves strong security guarantees supported by a formally verified design using the Tamarin prover. We implement and evaluate FlashAttest on MSP430 architecture, showing a reasonable overhead in terms of memory footprint, communication overhead, runtime and power consumption. Compared with state-of-the-art self-attestation schemes, our approach achieves similar runtime overhead, low energy consumption, and reasonable memory overhead while eliminating the need for hardware modifications. The results confirm the suitability of FlashAttest for low-end devices.
Zheng Zhang 0060, Jingfeng Xue, Weizhi Meng 0001, Xu Qiao, Yuanzhang Li 0001, Yu-an Tan 0001
IEEE Trans. Inf. Forensics Secur.3
2025 SSLDefender: Backdoor Defense in Self-Supervised Learning via Distillation-Guided Unlearning
abstract
Self-supervised learning utilizes unlabelled data to train encoders, acquiring high-quality representations of input data, significantly advancing the field of computer vision. However, recent studies have demonstrated that self-supervised learning suffers from numerous adversarial attacks. Among them, backdoor attack is one of the focal issues, where downstream classifiers inherit the backdoor behavior of the pre-trained encoder. Existing defense methods against backdoor attacks primarily focus on supervised learning, which heavily relies on labeled data and cannot be directly migrated to self-supervised scenarios. Furthermore, defense methods for self-supervised backdoor aims to separate poisoned samples on assumed small-scale datasets and retraining to obtain a clean encoder. However, these approaches are useless against encoders that have been implanted with a backdoor. To address these issues, we propose SSLDefender, a novel image-based backdoor mitigation method specially designed for self-supervised learning, which can remove backdoor attributes directly from the backdoor encoder. Specifically, we employ a trigger recovery method based on mutual information maximization to efficiently obtain trigger that resembles the target backdoor’s influence. Additionally, we design a distillation-guided unlearning strategy to purify backdoor features steadily and ensure the retention of clean knowledge to prevent overforgetting. Extensive experimental evaluations on six benchmark datasets demonstrate that SSLDefender can successfully reduce the attack success rate of Badencoder to around 2% while maintaining high model accuracy on the main task. Its performance surpasses state-of-the-art methods.
Jiale Zhang 0001, Wanquan Zhu, Kai Wang 0062, Xiaobing Sun 0001, Weizhi Meng 0001, Xiapu Luo
IEEE Trans. Inf. Forensics Secur.6
2025 Lightweight Continuous Authentication via IMU Fingerprinting for V2X
abstract
Inertial measurement unit (IMU) fingerprinting is a promising physical authentication technique based on hardware imperfections produced during sensor manufacturing. This paper presents a two-stage feature extraction process that combines feature selection and mapping; the proposed approach is tailored for the lightweight vehicle-to-everything (V2X) application scenario. Specifically, the selected features are transformed into images via Gramian angular difference field (GADF), Gramian angular summation field (GASF), and Markov transition field (MTF) mappings, as well as feature extraction implemented via a convolutional neural network (CNN). Owing to the advances provided by the proposed scheme, a lightweight feature extraction system achieves satisfactory accuracy levels above 99.10% with fewer sample data and a short training time. The effectiveness and robustness of the developed approach were validated under various driving conditions via 20 IMU sensors, Arduino, and a Raspberry Pi across 20 vehicles. Additionally, tests conducted across different deep learning models demonstrated the generalizability of the proposed preprocessing and mapping methods.
Bei Gong, Zhe Li 0052, Mowei Gong, Weizhi Meng 0001
IEEE Trans. Intell. Transp. Syst.5
2025 EASTER: Embedding Aggregation-Based Heterogeneous Models Training in Vertical Federated Learning
abstract
Vertical Federated Learning (VFL) allows collaborative machine learning without sharing local data. However, existing VFL methods face challenges when dealing with heterogeneous local models among participants, which affects optimization convergence and generalization of participants' local knowledge aggregation. To address this challenge, this paper proposes a novel approach calledEmbeddingAggregation-based HeterogeneousModelsTraining in Vertical Federated Learning(EASTER). EASTER focuses on aggregating the local embeddings of each participant's knowledge during forward propagation. We propose an embedding protection method based on lightweight blinding factors, which injects the blinding factors into the local embedding of the passive party. However, the passive party does not own the sample labels, so the local model's gradient cannot be calculated locally. To overcome this limitation, we propose a new method in which the active party assists the passive party in computing its local heterogeneous model gradients. Theoretical analysis and extensive experiments demonstrate that EASTER can simultaneously train multiple heterogeneous models and outperform some recent methods in model performance. For example, compared with the state-of-the-art method, the model accuracy of EASTER was improved by 7.22% under the CIFAR-10 dataset.
Shuo Wang 0026, Keke Gai, Jing Yu 0007, Liehuang Zhu, Weizhi Meng 0001, Bin Xiao 0001
IEEE Trans. Mob. Comput.5
2024 AggNoteBot: A Robust Botnet Building Using Aggressive Cloud Notes
Yi-Ning Liu 0002, Yanze Kang, Weizhi Meng 0001
ACISP (3)5
2024 Towards Alarm Reduction in Intrusion Detection: A Recurrent Neural Network Approach
abstract
Intrusion detection systems (IDSs) are one of the most commonly deployed systems to detect cyber attacks. One major problem of IDSs is the large amount of false alarms (or false positives) generated in a practical network. In recent decades, many researchers utilized machine learning techniques to help reduce false alarms, i.e., deep learning is quite popular in recent years. However, most research studies mainly consider one dataset in the evaluation, and it is unclear whether the approach can be scalable for other network settings. Motivated by such challenges, in this work, we introduce a hybrid deep learning-based false alarm filtration method, by combining a modern recurrent neural network (RNN) and a concise alert correlation method to reduce false positives for an IDS. To evaluate the performance, we consider three publicly available datasets such as DARPA, UNSW-NB and CSE-CIC-IDS. Experimental results demonstrate that our approach can reduce up to 99.35% false alarms in the best case.
Alexander Gödeke, Weizhi Meng 0001, Yu Wang 0017
HPCC2
2024 Incremental Learning Strategy with Multi-dimensional Knowledge Distillation for One-stage Object Detection
abstract
In practical applications, object detectors often encounter unknown classes samples. As object detection datasets undergo continuous development, the need arises for object detectors to adeptly recognize an escalating array of new classes while retaining the original detection capability. This paper introduces a new class incremental object detection learning framework with multi-dimensional knowledge distillation, using Yolov5 as the foundational detection model. Specifically, we utilize local feature distillation, attention distillation and global feature distillation to preserve information in the original model's feature maps. Additionally, we employ response distillation to ensure the model remains responsive to previous classes. In comparison to the state-of-the-art methods, our approach achieves higher overall accuracy on PASCAL VOC 2007. Especially in the “19+1” incremental task, our approach gets the highest [email protected] of 0.697 with a minimum mean AP decline rate of 4.45%. For the “4+3” and “6+1” tasks on KITTI, our approach preserves the model's responsiveness to the original task more effectively while achieving the highest overall accuracy.
Xuejiao Liu 0001, Xueshuang Xiang, Yu-an Tan 0001, Weizhi Meng 0001
INDIN5
2024 An eID-Based Privacy-Enhanced Public Transportation Ticket System
Kanagaratnam Anojjan, Weizhi Meng 0001, Brooke Kidmose, Yu Wang 0017
ISPEC2
2024 A Comparative Analysis of Phishing Tools: Features and Countermeasures
Rishikesh Sahay, Weizhi Meng 0001, Wenjuan Li 0001
ISPEC2
2024 can-fp: An Attack-Aware Analysis of False Alarms in Automotive Intrusion Detection Models
abstract
The automotive controller area network (CAN) bus functions as the communications backbone of automobiles around the globe. Unfortunately, the CAN bus was developed for the closed-system vehicles of the 1980s, not the inter-connected—even autonomous—vehicles hitting the roads today, meaning that the CAN bus is extraordinarily insecure. Much of the literature points to automotive intrusion detection as the solution; it is lightweight and does not involve re-engineering the CAN bus. That said, in safety-critical automotive environments, we can expect to see millions of messages every ten minutes; as such, accuracy is paramount. A false positive rate (FPR) of 0.00001 corresponds to about ten false positives every ten minutes. Therefore, in this paper, we investigate false positives generated by the machine learning models that constitute automotive intrusion detection systems (IDSs). In particular, we explore the timestamp and time delta features to determine if they have a positive or negative impact on the FPR. Then, we look into the patterns of false positives, and we discover that many false positives are produced during actual attacks. Essentially, when legitimate messages are interlaced with attack messages, anomalous patterns are produced, and legitimate messages are flagged as anomalous. The IDS has done its job and detected an attack-it simply misidentified legitimate messages as part of the attack. When it comes to automotive attacks, many of the mitigation strategies do not require precise identification of the attack messages; that is, it is enough to know that an attack is ongoing. As such, we exclude false positives that occur during attack conditions from the FPR, and we examine the results. We find that, for a number of machine learning models, discounting attack-related false positives can significantly improve the FPR.
Brooke Kidmose, Weizhi Meng 0001
PST2
2024 Pitfalls of Data Masking Techniques: Re-identification Attacks
Samir Hodzic, Andreas B. Kidmose, Brooke Kidmose, Lars R. Knudsen, Weizhi Meng 0001
SecureComm (3)5
2024 User Authentication Based on the Integration of Musical Signals and Ear Canal Acoustics
abstract
This study presents a new biometric authentication system leveraging ear canal acoustic features for secure identity authentication. The proposed system can capture ear acoustics using an earphone integrated with a microphone, with musical signals as the probing signal. By taking the Ear Canal Transfer Function (ECTF) as the primary feature, we develop and implement a prototype that integrates data collection and deep feature extraction using particularly modified earphones. We then employ a convolutional neural network (CNN) to address the challenge of feature space overlap due to the diverse frequency components in musical signals. Our evaluation demonstrates the feasibility and the robustness of our method by using ear canal acoustics for user authentication, highlighting its potential for widespread application in security-sensitive environments.
Tongxi Chen, Weizhi Meng 0001, Wenjuan Li 0001
TrustCom2
2024 DAR-DRL: A dynamic adaptive routing method based on deep reinforcement learning
Zheheng Rao, Yanyan Xu 0003, Ye Yao 0003, Weizhi Meng 0001
Comput. Commun.4
2024 can-train-and-test: A curated CAN dataset for automotive intrusion detection
abstract
When it comes to in-vehicle networks (IVNs), the controller area network (CAN) bus dominates the market; automobiles manufactured and sold worldwide depend on the CAN bus for safety-critical communications between various components of the vehicle (e.g., the engine, the transmission, the steering column). Unfortunately, the CAN bus is inherently insecure; in fact, it completely lacks controls such as authentication, authorization, and confidentiality (i.e., encryption). Therefore, researchers have travailed to develop automotive security enhancements. The automotive intrusion detection system (IDS) is especially popular in the literature—due to its relatively low cost in terms of money, resource utilization, and implementation effort. That said, developing and evaluating an automotive IDS is often challenging; if researchers do not have access to a test vehicle, then they are forced to depend on publicly available CAN data—which is not without limitations. Lack of access to adequate CAN data, then, becomes a barrier to entry into automotive security research. We seek to lower that barrier to entry by introducing a new CAN dataset to facilitate the development and evaluation of automotive IDSs. Our datasets—dubbed can-dataset, can-log, can-csv, can-ml, and can-train-and-test—provide CAN data from four different vehicles produced by two different manufacturers. The attack captures for each vehicle model are equivalent, enabling researchers to assess the ability of a given IDS to generalize to different vehicle models and even different vehicle manufacturers. Our datasets contain replayable .log files as well as labeled and unlabeled .csv files, thereby meeting a variety of development and evaluation needs. In particular, the can-train-and-test dataset offers nine unique attacks, ranging from denial of service (DoS) to gear spoofing to standstill; as such, researchers can select a subset of the attacks for training and save the remainder for testing in order to assess a given IDS against unseen attacks. Many of our attacks, particularly the spoofing-related attacks, were conducted during live, on-the-road experiments with real vehicles. These attacks have known physical impacts. As a benchmark, we pit a number of machine learning IDSs against our dataset and analyze the results. We present our datasets—especially can-train-and-test—as a contribution to the existing catalogue of open-access datasets in hopes of filling in the gaps left by those datasets.
Brooke Kidmose, Weizhi Meng 0001
Comput. Secur.2
2024 Deep video inpainting detection and localization based on ConvNeXt dual-stream network
abstract
Currently, deep learning-based video inpainting algorithms can fill in a specified video region with visually plausible content, usually leaving imperceptible traces. Since deep video inpainting methods can be used to maliciously manipulate video content, there is an urgent need for an effective method to detect and localize deep video inpainting. In this paper, we propose a dual-stream video inpainting detection network, which includes a ConvNeXt dual-stream encoder and a multi-scale feature cross-fusion decoder. To further explore the spatial and temporal traces left by deep inpainting, we extract motion residuals and enhance them using 3D convolution and SRM filtering. Furthermore, we extract filtered residuals using LoG and Laplacian filtering. These residuals are then entered into ConvNeXt, thereby learning discriminative inpainting features. To enhance detection accuracy, we design a top-down pyramid decoder that aims at deep fusion of multi-dimensional multi-scale features to fully exploit the information of different dimensions and levels in detail. We created two datasets containing state-of-the-art video inpainting algorithms and conducted various experiments to evaluate our approach. The experimental results demonstrate that our approach outperforms existing methods and attains a competitive performance despite encountering unseen inpainting algorithms.
Ye Yao 0003, Tingfeng Han, Yizhi Ren, Weizhi Meng 0001
Expert Syst. Appl.5
2024 High invisibility image steganography with wavelet transform and generative adversarial network
Ye Yao 0003, Yizhi Ren, Weizhi Meng 0001
Expert Syst. Appl.5
2024 Practical Privacy-Preserving Scheme With Fault Tolerance for Smart Grids
abstract
In smart grid services, the leakage of crowdsourced consumption data on smart meters (SMs) poses potential risks of privacy disclosure and data misuse. Existing solutions, which rely on complex encrypted computations, are often impractical for resource-limited SMs due to their high computation and storage resource requirements. To address these challenges, this article proposes a practical privacy-preserving scheme with fault tolerance for smart grid services named 3PFT. In our scheme, we employ a masking approach that ensures user privacy preservation on SMs while consuming minimal resources. Unlike existing masking schemes, 3PFT provides fault tolerance, supports complex data analysis tasks, and mitigates vulnerabilities to key leakage attacks. To achieve these objectives, we incorporate a secret sharing technique into the masking approach, enabling the recovery of the master key using only a portion of the data. Additionally, we design a flexible data aggregation protocol for 3PFT, facilitating the execution of diverse data analysis missions, such as load forecasting, in smart grids. Furthermore, we introduce a negotiation-based key update method to enhance the protocol’s forward security and alleviate the additional overhead on SMs. Finally, we provide a rigorous proof of privacy preservation and fault tolerance for our scheme and validate its feasibility and effectiveness through extensive simulations.
Ning Lu 0005, Zhou Su 0001, Weizhi Meng 0001
IEEE Internet Things J.6
2024 Scalable Graph-Aware Edge Representation Learning for Wireless IoT Intrusion Detection
abstract
Network Intrusion Detection Systems (NIDSs) have emerged as a frontline defense against potential attacks in wireless Internet of Things (IoT) networks. However, existing machine learning methods follow an unstructured data processing patterns and can barely incorporate all information due to the network dynamicity as well as data imbalance. In this study, we propose Graph Isomorphism Network model based on Edge (GINE), an innovative graph-based algorithm tailored to pinpoint malicious network traffic within wireless IoT networks. Specifically, we initiate by presenting the wireless IoT network graph, capturing the global topological interactions of its edges. Subsequently, we design an edge representation learning algorithm, capable of encoding network data frames in a discerning pattern-aware manner. Moreover, we integrate a data interpolation module into the edges of our structured graph data targeting at data imbalance, which fosters a more balanced distribution across the various classes of edges. Our empirical analysis on select wireless IoT intrusion datasets shows GINE’s superiority, consistently outperforming state-of-the-art methods in classification metrics, including accuracy, F1-Score, False Alarm Rate, etc. Through a simulated wireless environment, we demonstrate GINE’s robust scalability, even in unpredictable wireless networks.
Qinnan Hu, Weizhi Meng 0001, Witold Pedrycz, Zhou Su 0001
IEEE Internet Things J.4
2024 Traffic Sign Recognition Using Optimized Federated Learning in Internet of Vehicles
abstract
Traffic sign recognition (TSR) is vital for vehicle safety and navigation, especially in the era of autonomous cars. Internet of Vehicles (IoV) provide a promising infrastructure for vehicular networks due to their agility and interoperability. However, privacy concerns and network restrictions hinder the collection of massive data from distributed automotive sensors in IoV. To address these challenges, this article proposes the application of federated learning (FL) and model sparsification to optimize traffic sign recognition (TSR) in autonomous vehicles. FL enables decentralized learning while preserving data privacy, and model sparsification significantly reduces communication costs. Furthermore, we incorporate the Adam optimizer for local training, ensuring efficient model optimization on each vehicle. Experimental results demonstrate the effectiveness of our approach, with improved TSR performance while mitigating privacy risks and enhancing communication efficiency. This research contributes to the advancement of TSR in IoV by introducing FL, model sparsification, and the use of the Adam optimizer for local training, facilitating efficient and privacy-preserving vehicular network learning.
Zhuotao Lian, Qingkui Zeng, Weizheng Wang 0001, Dequan Xu, Weizhi Meng 0001, Chunhua Su
IEEE Internet Things J.5
2024 Traceable and Privacy-Preserving Authentication Scheme for Energy Trading in V2G Networks
abstract
With the rapid popularization of electric vehicles (EVs) in modern society, vehicle-to-grid (V2G) has been widely concerned as an emerging technology. However, various privacy and security issues arise frequently in the energy interaction between EVs and the smart grid (SG), such as the lack of secure authentication and disclosure of EVs’ identity. Although many crypto-based schemes are proposed to achieve secure authentication of V2G networks, they rely on certificate authority (CA) or private key generator (PKG). In response to this problem, some certificateless signature-based schemes have been proposed. Nevertheless, most of them are not suitable for V2G networks due to the high computational cost and communication overhead, and they do not consider the problem of tracking illegal signatures. Therefore, we propose a traceable and privacy-preserving authentication scheme with supporting batch verification for energy trading in V2G networks. We use the method of binary tree level traversal to quickly track EVs with illegal signatures, which can reduce computational resources. Besides, the proposed scheme is easier to be deployed in real world because of avoiding the problems of key escrow and certificate management. Finally, we conduct a comprehensive security analysis and performance evaluation regarding our scheme. We prove that our proposed scheme is secure under the random oracle model (ROM), and the experimental results illustrate that the proposed scheme has less computational cost and communication overhead as compared to the existing schemes.
Gang Shen 0003, Chengliangyi Xia, Yumei Li 0003, Hua Shen 0002, Weizhi Meng 0001, Mingwu Zhang
IEEE Internet Things J.5
2024 Delayed packing attack and countermeasure against transaction information based applications
Yuan Su, Zhou Su 0001, Yuyi Wang 0001, Weizhi Meng 0001, Yinghua Shen
Inf. Sci.6
2024 TridentShell: An enhanced covert and scalable backdoor injection attack on web applications
abstract
Web backdoor attack is an increasingly prevalent network attack that can result in substantial losses for webmasters. During a cyber-attack, system vulnerabilities and web application flaws are usually used to implant a web shell inside victim servers. To mitigate the many threats posed by web shells, research has focused on static feature detection, which has evolved rapidly in recent years. However, static feature detection has inherent limitations and security risks. In this paper, we present TridentShell, a novel web backdoor attack that can inject an invisible backdoor into a victim server without leaving any traces of the attack. Furthermore, TridentShell can circumvent almost all static detection methods. Unlike existing approaches, which leverage traditional encryption and obfuscation technologies to avoid detection, our proposed attack is intended to blend into the web application server naturally. In this work, we introduce enhancements to the original TridentShell, which is not traceable—in theory—since it uses a blockchain-based decentralized C&C server with better presentation capability. The experimental results show that our TridentShell can effectively compromise five different types of Java application servers (covering around 87% Java application servers in the market), and can scrub any attack traces from the server, making it especially difficult to detect.
Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002
J. Netw. Comput. Appl.2
2024 Blockchain-based privacy-preserving public key searchable encryption with strong traceability
Jinguang Han, Weizhi Meng 0001, Jianchang Lai, Ge Wu 0001
J. Syst. Archit.3
2024 Flash controller-based secure execution environment for protecting code confidentiality
abstract
With the rapid evolution of Internet-of-Things (IoT), billions of IoT devices have connected to the Internet, collecting information via tags and sensors. For an IoT device, the application code itself and data collected by sensors can be of great commercial value. It is challenging to protect them because IoT devices are prone to compromise due to the inevitable vulnerabilities of commodity OSes. Trusted Execution Environment (TEE) is one of the solutions that protects sensitive data by running security-sensitive workloads in a secure world. However, this solution does not work for most of the IoT devices that are limited in resources. In this paper, we propose Flash Controller-based Secure Execution Environment (FCSEE), an approach to protect security-sensitive code and data for IoT devices using the flash controller. Our approach constructs a secure execution environment on the target flash memory by modifying the execution logic of its controller, leveraging it as a co-processor to execute security-sensitive workloads of the host device. By extending the original functionality of the flash firmware, FCSEE also provides several much-needed security primitives to protect sensitive data. We constructed a prototype based on a Trans-Flash (TF) card and implemented proof of its confidentiality. Our evaluation results indicate that FCSEE can confidentially execute security-sensitive workloads from the host and efficiently protects its sensitive data.
Zheng Zhang 0060, Jingfeng Xue, Yuhang Zhao 0003, Weizhi Meng 0001
J. Syst. Archit.5
2024 GPOD: An Efficient and Secure Graphical Password Authentication System by Fast Object Detection
Palash Ray, Debasis Giri, Weizhi Meng 0001, Soumyadeep Hore
Multim. Tools Appl.3
2024 Distributed Robust Artificial-Noise-Aided Secure Precoding for Wiretap MIMO Interference Channels
abstract
We propose a distributed artificial noise-assisted precoding scheme for secure communications over wiretap multi-input multi-output (MIMO) interference channels, where K legitimate transmitter-receiver pairs communicate in the presence of a sophisticated eavesdropper having more receive-antennas than the legitimate user. Realistic constraints are considered by imposing statistical error bounds for the channel state information of both the eavesdropping and interference channels. Based on the asynchronous distributed pricing model, the proposed scheme maximizes the total utility of all the users, where each user’s utility function is defined as the secrecy rate minus the interference cost imposed on other users. Using the weighted minimum mean square error, Schur complement and sign-definiteness techniques, the original non-concave optimization problem is approximated with high accuracy as a quasi-concave problem, which can be solved by the alternating convex search method. Simulation results consolidate our theoretical analysis and show that the proposed scheme outperforms the artificial noise-assisted interference alignment and minimum total mean-square error-based schemes.
Zhengmin Kong, Shaoshi Yang, Li Gan, Weizhi Meng 0001, Tao Huang 0008, Sheng Chen 0001
IEEE Trans. Inf. Forensics Secur.5
2024 Decentralized Threshold Signatures With Dynamically Private Accountability
abstract
Threshold signature is a fundamental cryptographic primitive used in many practical applications. As proposed by Boneh and Komlo (CRYPTO’22), TAPS is a threshold signature that is a hybrid of privacy and accountability. It enables a combiner to combine$t$signature shares while revealing nothing about the threshold$t$or signing quorum to the public and asks a tracer to track a signature to the quorum that generates it. However, TAPS has three disadvantages: it 1) structures upon a centralized model, 2) assumes that both combiner and tracer are honest, and 3) leaves the tracing unnotarized and static. In this work, we introduce Decentralized, Threshold, dynamically Accountable and Private Signature (DeTAPS) that provides decentralized combining and tracing, enhanced privacy against untrusted combiners (tracers), and notarized and dynamic tracing. Specifically, we adopt Dynamic Threshold Public-Key Encryption (DTPKE) to dynamically notarize the tracing process, design non-interactive zero knowledge proofs to achieve public verifiability of notaries, and utilize the Key-Aggregate Searchable Encryption to bridge TAPS and DTPKE so as to awaken the notaries securely and efficiently. In addition, we formalize the definitions and security requirements for DeTAPS. Then we present a concrete construction and formally prove its security and privacy. To evaluate the performance, we build a prototype based on SGX2 and Ethereum.
Meng Li 0006, Hanni Ding, Qing Wang 0060, Weizhi Meng 0001, Liehuang Zhu, Zijian Zhang 0001, Xiaodong Lin 0001
IEEE Trans. Inf. Forensics Secur.5
2024 Embedding Secret Message in Chinese Characters via Glyph Perturbation and Style Transfer
abstract
Glyph perturbation adjusts the characters’ structures and strokes to make the original characters change subtly, which cannot be detected by the naked eye. These generated variants with different glyph perturbation can represent different status of secret messages, which can be used to embed information in Chinese text documents. However, Chinese characters have characteristics in large numbers, complex structures, and diverse fonts, which limit the generation of glyph perturbation and make the design of Chinese characters time-consuming and laborious. Many font style transfer methods for Chinese characters have been proposed to improve the efficiency of Chinese character generation based on deep learning. At present, there are few studies on efficient font style transfer for glyph perturbation of Chinese characters. In this paper, a stylized glyph perturbation method based on style extractor and attention augmented convolution is proposed. It adopts a multi-head attention mechanism to enhance convolution in the font transfer, which concatenates the convolution feature maps and the self-attention activation maps to weaken the limitations of ordinary convolution in processing images. The extracted style features are sent into the decoder of the font transfer network so as to improve the stylized ability. Particularly, the impact of style extractor and attention augmented convolution on the glyph perturbation generation is addressed. The extraction accuracy and embedding capacity are tested in our experiments. The embedding capacity of secret message can achieve around 1.8 bit/character.
Ye Yao 0003, Chen Wang 0113, Hui Wang 0020, Ke Wang 0039, Yizhi Ren, Weizhi Meng 0001
IEEE Trans. Inf. Forensics Secur.6
2024 Differential Cryptanalysis of Bloom Filters for Privacy-Preserving Record Linkage
abstract
Privacy-preserving record linkage (PPRL) aims to link records of the same real-world entity from different databases without exposing any private information about the entity. Bloom filters are widely used in PPRL due to their effectiveness in encoding records while enabling fast approximate linkage in the case of attribute value errors and changes. However, the basic Bloom filters used for PPRL can be subject to cryptanalysis attacks that expose the plain-text values encoded in them. Recent studies have successfully attacked some improved Bloom filter encodings in PPRL but require specific conditions or knowledge of various encoding parameters to obtain high accuracy. This paper presents a novel attack based on differential analysis against Bloom filters used for PPRL. The attack exploits graphs to model the relationship between attribute value variation and the difference between Bloom filters. Then, features are generated for the node in graphs according to a clustering algorithm that we propose. Thus, we can match nodes with similar features to re-identify encoded records. Experiments on two real-world databases show that even with improved Bloom filter encoding and some hardening techniques, our attack can re-identify private information from encoded records with high accuracy and require less priori knowledge.
Weifeng Yin, Lifeng Yuan, Yizhi Ren, Weizhi Meng 0001, Dong Wang 0019, Qiuhua Wang
IEEE Trans. Inf. Forensics Secur.4
2024 Detecting Post Editing of Multimedia Images using Transfer Learning and Fine Tuning
abstract
In the domain of general image forgery detection, a myriad of different classification solutions have been developed to distinguish a “tampered” image from a “pristine” image. In this work, we aim to develop a new method to tackle the problem of binary image forgery detection. Our approach builds upon the extensive training that state-of-the-art image classification models have undergone on regular images from the ImageNet dataset, and transfers that knowledge to the image forgery detection space. By leveraging transfer learning and fine tuning, we can fit state-of-the-art image classification models to the forgery detection task. We train the models on a diverse and evenly distributed image forgery dataset. With five models—EfficientNetB0, VGG16, Xception, ResNet50V2, and NASNet-Large—we transferred and adapted pre-trained knowledge from ImageNet to the forgery detection task. Each model was fitted, fine-tuned, and evaluated according to a set of performance metrics. Our evaluation demonstrated the efficacy of large-scale image classification models—paired with transfer learning and fine tuning—at detecting image forgeries. When pitted against a previously unseen dataset, the best-performing model of EfficientNetB0 could achieve an accuracy rate of nearly 89.7%.
Simon Lucas Jonker, Malthe Jelstrup, Weizhi Meng 0001, Brooke Kidmose
ACM Trans. Multim. Comput. Commun. Appl.3
2024 LightPay: A Lightweight and Secure Off-Chain Multi-Path Payment Scheme Based on Adapter Signatures
abstract
The payment channel network aims to solve the problems of long payment confirmation time and limited throughput in cryptocurrencies through off-chain payments. Hash Time-Lock Contract (HTLC) is an off-chain payment protocol that Lightning Network (LN) adopted. Unfortunately, when performing high-valued payments off-chain, due to the impact of payment channel capacity, it is often necessary to split a single payment, which increases the transaction fees and time. Therefore, we propose LightPay, an atomic off-chain multi-path payment protocol based on adapter signature and discrete logarithm problem. Among different conditions encoded in the multi-path contract, the multi-path transmission of a single high-valued payment can be realized under the premise of the unlinkability of partial payments. We construct an ideal functionality in the Universal Composability framework and demonstrate that LightPay UC-realizes it, thereby providing proof of its security and privacy. Experimental results indicate that the payment success rate of LightPay can be increased by 11.08% in 0.0025 BTC payments compared with the single-path payment protocol Multihop HTLC in LN. Additionally, compared with the multi-path payment protocol CryptoMaze, the communication overhead required by LightPay is reduced to about 55.6% on average in the simulated network. Overall, LightPay has advantages regarding payment success rate and overhead.
Yaqin Liu, Wei Liang 0005, Kun Xie 0001, Songyou Xie, Kuanching Li, Weizhi Meng 0001
IEEE Trans. Serv. Comput.6
2023 Securing Offshore Installations Against Automatic Identification System Spoofing
abstract
The AIS (Automatic Identification System) is a maritime navigation safety communication system that transmits data, such as vessel location and identification, both to nearby vessels and to coastal facilities. Unfortunately, AIS spoofing is a growing concern: malicious actors could transmit false AIS messages in order to mislead vessels and potentially cause accidents. In this work, we developed a tool for AIS message validation. Under evaluation, the tool delivered promising results in terms of AIS spoofing detection and prevention, thereby demonstrating the tool's efficacy and potential to complement existing detection and prevention techniques.
Grzegorz Jacek Kot, Weizhi Meng 0001, Brooke Kidmose
GLOBECOM2
2023 A Closer Look at Cross-Domain Maximal Extractable Value for Blockchain Decentralisation
abstract
In the current literature, many solutions for solving blockchain scaling have been tried historically, whereas most of them usually may compromise the decentralisation. Ethereum has chosen to scale by switching to Proof of Stake consensus and adding data sharding to allow Layer 2 execution to be cheaper. However, in the light of cross-domain Maximal Extractable Value (MEV), even this strategy may have centralising forces built-in. In this work, we focus on cross-domain MEV and try to identify cross domain arbitrage. In particular, we extract Uniswap data from four different domains and provide an initial analysis of how to identify cross domain arbitrages.
Johan Hagelskjar Sjursen, Weizhi Meng 0001, Wei-Yang Chiu
ICBC2
2023 DataVaults: A Secure, Distributed and Privacy Preserving Personal Data Management Platform
abstract
With the rapid development of information technology, the ethical use of data and users' privacy has become a big concern. In European Union, the General Data Protection Regulation (GDPR) has been enforced since 2018, aiming to protect a person's privacy. However, the growth of the data economy might be hindered due to the lack of a trusted, secure and privacy-aware tool. Motivated by this observation, this work presents Data Vaults - a secure, distributed and privacy-preserving personal data management platform. The main goal is to mitigate various privacy concerns through allowing an individual to maintain the ownership, handle and share the data based on their willingness. The platform enables a flexible data sharing method with fair compensation schemes. In particular, with the Data Vaults platform, an individual can protect the sharing of personal data and fairly define how value can be captured, created, released and cashed out for the benefit of all the stakeholders involved (companies or not).
Weizhi Meng 0001, Wei-Yang Chiu
ICDCS1
2023 BlockPAT: A Blockchain-Enabled Second-Hand Physical Asset Tokenization Management System
abstract
In this work, we develop BlockPAT, a blockchain-enabled management system for the tokenization of second-hand physical assets, e.g., laptops. With this system, the information gap between buyers and sellers in the second-hand market will be eliminated, and with the help of a price oracle, the liquidity of the second-hand market can be greatly improved. Furthermore, our system is built upon the latest ZK-rollups solution; thus, the overall transaction cost and time delay will be limited to an affordable value.
Wei-Yang Chiu, Weizhi Meng 0001, Brooke Kidmose
ICDCS3
2023 Towards Quantifying Cross-Domain Maximal Extractable Value for Blockchain Decentralisation
Johan Hagelskjar Sjursen, Weizhi Meng 0001, Wei-Yang Chiu
ICICS2
2023 Delay-masquerading Technique Upheld StrongBox: A Reinforced Side-Channel Protection
abstract
In recent years, Graphical Processing Unit (GPU) is not only becoming a piece of hardware that accelerates graphics but also playing a key role in accelerating the fields of machine learning and artificial intelligence. The GPU’s heightened importance has led to increasing concern about the confidentiality of a GPU’s computing data as well as its internal communications. Although the GPU Trusted Execution Environment (TEE) has been implemented as a solution toward this issue, side-channel attacks in GPUs still remain as an open problem. In this work, we introduce Delay-masquerading Technique Upheld StrongBox (DTUBox) to strengthen the resilience of existing GPU TEE over StrongBox against side-channel attacks by injecting obfuscated noise with our developed algorithm, making the correlations difficult to reference between a task and workload. In our evaluation, we demonstrate that with only around 5% performance overhead, our approach could effectively lower the correlation rate to 38% between the original behavior sequences and the obfuscated sequences.
Shuoqiang Zeng, Wei-Yang Chiu, Peichen Liu, Weizhi Meng 0001, Brooke Kidmose
ICPADS5
2023 Look Closer to Touch Behavior-enabled Android Pattern Locks: A Study in the Wild
abstract
Android pattern lock is one of the most popular unlocking mechanisms on the Android platform. In order to enhance the security of Android’s unlocking functionality, a number of researchers have tried to combine touch biometrics with the pattern lock. Several studies have reported adequate— even excellent—authentication results, but, unlike fingerprint-and face recognition-based authentication, no biometrics-enabled pattern lock exists in the Android marketplace. Furthermore, most studies of biometrics-enabled pattern locks were conducted in controlled lab environments. As such, in this work, our goal is to investigate and validate the performance of touch behavior-enabled Android pattern locks in a more practical scenario, in which users have to download the application and learn to use it by themselves (as was often the case during the pandemic). During the course of our investigation, we collected substantial data, namely, the properties provided by the Android API for motion events, as well as measurements that could be extracted from the devices’ sensors. Our investigation found that touch-enabled Android pattern locks could achieve an average equal error ratio of 23.5% for user authentication—without changing the process from the user’s perspective. Next, we modified the user experience such that each user would train the authenticator with different fingers, similar to fingerprint-based authentication. With this modification, an average equal error ratio of 13.5% was achieved.
Gergely Tuskó, Weizhi Meng 0001, Brooke Kidmose
TrustCom2
2023 can-train-and-test: A New CAN Intrusion Detection Dataset
abstract
The controller area network (CAN) bus facilitates communication between a vehicle's microcontrollers, known as electronic control units (ECUs). Developed in 1983, the CAN bus is exceedingly robust—and exceedingly insecure. The CAN bus lacks conventional security controls (e.g., authentication, authorization, access control, encryption—to name a few). Significant research work has focused on improving automotive security; however, it has been challenging to add security to the CAN bus ex post facto.The automotive intrusion detection system (IDS) has been popularized in the literature as a relatively low-cost, low-effort security improvement for the CAN bus. Unfortunately, would-be IDS designers are often confronted with a shortage of adequate datasets to facilitate IDS development and evaluation. For intrusion detection systems built from machine learning models, the dataset shortage is particularly problematic; machine learning models require a lot of data for training and testing. The shortage of CAN datasets might impede or even deter would-be automotive IDS researchers.In this work, we introduce a new CAN dataset, dubbed can-train-and-test, to ameliorate the shortage of CAN datasets for IDS development and evaluation. Our dataset contains CAN data from four different vehicles manufactured by two different organizations—Chevrolet (General Motors) and Subaru. We provide attack-free traffic captures as well as captures that demonstrate nine distinct types of attacks—e.g., denial of service (DoS), fuzzing, standstill. We conduct all nine attacks against each of the four vehicles; thus, IDS designers can use the attack captures to evaluate an IDS's ability to generalize to different vehicles. We provide (1) replayable .log files, (2) unlabeled .csv files, and (3) labeled .csv files in order to meet a variety of IDS development and evaluation needs.
Brooke Kidmose, Weizhi Meng 0001
VTC Fall2
2023 A comparative risk analysis on CyberShip system with STPA-Sec, STRIDE and CORAS
abstract
The widespread use of software-intensive cyber systems in critical infrastructures such as ships (CyberShips) has brought huge benefits, yet it has also opened new avenues for cyber attacks to potentially disrupt operations. Cyber risk assessment plays a vital role in identifying cyber threats and vulnerabilities that can be exploited to compromise cyber systems. Understanding the nature of cyber threats and their potential risks and impact is essential to improve the security and resilience of cyber systems, and to build systems that are secure by design and better prepared to detect and mitigate cyber attacks. A number of methodologies have been proposed to carry out these analyses. This paper evaluates and compares the application of three risk assessment methodologies: system theoretic process analysis (STPA-Sec), STRIDE and CORAS for identifying threats and vulnerabilities in a CyberShip system. We specifically selected these three methodologies because they identify threats not only at the component level, but also threats or hazards caused due to the interaction between components, resulting in sets of threats identified with each methodology and relevant differences. Moreover, STPA-Sec, which is a variant of the STPA, is widely used for safety and security analysis of cyber physical systems (CPS); CORAS offers a framework to perform cyber risk assessment in a top-down approach that aligns with STPA-Sec; and STRIDE (Spoofing, Tampering, Repudiation,Information disclosure, Denial of Service, Elevation of Privilege) considers threat at the component level as well as during the interaction that is similar to STPA-Sec. As a result of this analysis, this paper highlights the pros and cons of these methodologies, illustrates areas of special applicability, and suggests that their complementary use as threats identified through STRIDE can be used as an input to CORAS and STPA-Sec to make these methods more structured.
Rishikesh Sahay, Daniel A. Sepulveda Estay, Weizhi Meng 0001, Christian Damsgaard Jensen, Michael Bruhn Barfod
Comput. Secur.3
2023 UAF-GUARD: Defending the use-after-free exploits via fine-grained memory permission management
Guangquan Xu, Wenqing Lei, Lixiao Gong, Jian Liu 0004, Hongpeng Bai, Kai Chen 0012, Wei Wang 0012, Kaitai Liang, Weizhi Meng 0001, Shaoying Liu
Comput. Secur.11
2023 GenDroid: A query-efficient black-box android adversarial attack framework
Guangquan Xu, Hongfei Shao, Jingyi Cui, Hongpeng Bai, Guangdong Bai, Shaoying Liu, Weizhi Meng 0001, James Xi Zheng
Comput. Secur.8
2023 ADFL: Defending backdoor attacks in federated learning via adversarial distillation
Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002, Weizhi Meng 0001
Comput. Secur.5
2023 MLCT: A multi-level contact tracing scheme with strong privacy
abstract
Abstract With the outbreak of Covid‐19, both people's health and the world economy are facing great challenges. Contact tracing scheme based on Bluetooth of smartphones has been regarded as a viable way to mitigate the spread of Covid‐19. The existing schemes mainly belong to the centralized or the decentralized structure, both of which have their own limitations. It is infeasible for the existing schemes to balance the different demands of governments and users for user privacy and tracing efficiency at different periods of the epidemic. In this paper, we propose a hybrid contact tracing scheme named MLCT (multi‐level contact tracing scheme) which is mainly based on short group signature. MLCT provides multiple privacy levels by applying anonymous credential technology and secret sharing technology to desensitize user identity privacy and encounter privacy. Comparing to the previous schemes, MLCT fully considers the different demands of the government, patients, and close contacts for user privacy and tracing efficiency in the different stages of Covid‐19. The experimental results show viability in terms of the required resource from both server and mobile phone perspectives. And the security analysis demonstrates that MLCT can achieve the five targets security goals. It is expected that MLCT can contribute to the design and development of contact tracing schemes.
Jixin Zhang, Jiageng Chen, Weizhi Meng 0001
Concurr. Comput. Pract. Exp.4
2023 A survey of deep learning-based intrusion detection in automotive applications
abstract
Modern automobiles depend on internal vehicle networks (IVNs) to control systems from the anti-lock brakes to the transmission to the locks on the doors. Many IVNs, particularly the Controller Area Network (CAN) bus, were developed with little regard for security, since the IVNs of the past were isolated from the outside world. In the present day, the assumption of isolation no longer applies. Cellular service, Wi-Fi, and Bluetooth are just a few examples of the connectivity of contemporary automobiles. Researchers have explored a number of automotive security enhancements, but such enhancements are often roadblocked by implementation challenges, complexity, and expense. An intrusion detection system (IDS) is a promising automotive security enhancement that requires little, if any, adjustment to a vehicle’s existing infrastructure. Deep learning techniques can augment the capability of automotive IDSs, improving detection accuracy and precision. This paper provides a comprehensive overview of deep learning-based IDSs in automotive networks. We assemble various deep learning schemes, categorize them according to their topologies and techniques, and highlight their distinct contributions. In addition, we analyze each scheme’s evaluation in terms of datasets, attack types, and metrics. We summarize the results of the schemes and assess the advantages and disadvantages of different deep learning architectures.
Brooke Kidmose, Weizhi Meng 0001
Expert Syst. Appl.2
2023 A privacy-preserving blockchain-based tracing model for virus-infected people in cloud
Chengyi Qin, Lei Wu 0011, Weizhi Meng 0001, Zihui Xu, Hao Wang 0007
Expert Syst. Appl.3
2023 Trusting Computing as a Service for Blockchain Applications
abstract
Recently, blockchain and smart contracts have been one of most popular technology to establish trustworthy applications in several fields. However, due to the transparency and publicity of blockchain, the information processed by a smart contract is visible to every party in a blockchain. In light of this, this study proposes a trusted computing as a service (TCaaS) framework based on the blockchain. One of the critical component is the Execution Environment for Secured Smart Contract Computing (ESC)2 node. In the proposed framework, people can deploy (ESC)2 nodes in a blockchain. Users can upload general-purposed programs and associated parameters and discover an (ESC)2 node for execution via related smart contracts. The programs and parameters are encrypted so that only selected (ESC)2 node can decrypt the data. Then the execution environment calculates the result and returns it to the blockchain. We evaluate our concept with the ESP32 microcontroller with the ATECC508A security chip and the Quorum blockchain platform. Therefore, the study contributes to ensure faithful execution of programs without losing confidentiality.
Wen-Wei Li, Weizhi Meng 0001, Kuo-Hui Yeh, Shi-Cho Cha 0001
IEEE Internet Things J.2
2023 ADCL: Toward an Adaptive Network Intrusion Detection System Using Collaborative Learning in IoT Networks
abstract
With the widespread of cyber attacks, network intrusion detection system (NIDS) is becoming an important and essential tool to protect Internet of Things (IoT) environments. However, it is well known that the NIDS performance depends heavily on the effectiveness of the detection model, which can be influenced significantly by the learning mechanism and the available training data. Many existing studies try to mitigate the above challenges, but few of them consider the adaptability and the cost of deploying an NIDS, the integrity of the learning process, the capacity of model based on concrete traffic samples at the same time. To fill this gap and improve the detection performance, we propose a collaborative learning-based detection framework called ADCL, which can mitigate the limitations on the knowledge of a single model by leveraging multiple models trained in similar environments and detecting intrusions in a collaborative manner. Our evaluation results indicate that ADCL can provide better performance compared with a single model on detecting various attacks in IoT networks. Specifically, ADCL improves F-score by up to 80% for adaptability, 42% in mitigating the reliance on learning integrity, 85% for model capacity. Furthermore, the detection results of ADCL guide those single models to update and increase the F-score by 15%.
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001, Xiapu Luo, Lisong Wang, Wenjuan Li 0001
IEEE Internet Things J.3
2023 Analysis of hybrid attack and defense based on block withholding strategy
Binjie Liao, Yu Wang 0017, Weizhi Meng 0001, Jun Zhang 0010
J. Inf. Secur. Appl.4
2023 Dummy trajectory generation scheme based on generative adversarial networks
Jingkang Yang 0001, Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002
Neural Comput. Appl.3
2023 Optimal Repair Strategy Against Advanced Persistent Threats Under Time-Varying Networks
abstract
Advanced persistent threat (APT) is a kind of stealthy, sophisticated, and long-term cyberattack that has brought severe financial losses and critical infrastructure damages. Existing works mainly focus on APT defense under stable network topologies, while the problem under time-varying dynamic networks (e.g., vehicular networks) remains unexplored, which motivates our work. Besides, the spatiotemporal dynamics in defense resources, complex attackers’ lateral movement behaviors, and lack of timely defense make APT defense a challenging issue under time-varying networks. In this paper, we propose a novel game-theoretical APT defense approach to promote real-time and optimal defense strategy-making under both periodic time-varying and general time-varying environments. Specifically, we first model the interactions between attackers and defenders in an APT process as a dynamic APT repair game, and then formulate the APT damage minimization problem as the precise prevention and control (PPAC) problem. To derive the optimal defense strategy under both latency and defense resource constraints, we further devise an online optimal control-based mechanism integrated with two backtracking-forward algorithms to fastly derive the near-optimal solution of the PPAC problem in real time. Extensive experiments are carried out, and the results demonstrate that our proposed scheme can efficiently obtain optimal defense strategy in 54481 ms under seven attack-defense interactions with 9.64% resource occupancy in stimulated periodic time-varying and general time-varying networks. Besides, even under static networks, our proposed scheme still outperforms existing representative APT defense approaches in terms of service stability and defense resource utilization.
Zixuan Wang 0014, Yuntao Wang 0004, Zhou Su 0001, Shui Yu 0001, Weizhi Meng 0001
IEEE Trans. Inf. Forensics Secur.6
2023 NoSneaky: A Blockchain-Based Execution Integrity Protection Scheme in Industry 4.0
abstract
The advancement of information technology allows the creation of smart devices that not only are programable, but also can perform machine-to-machine communication in order to reach a flexible large-scale manufacturing strategy in Industry 4.0. However, as more components are connected to the Internet, cyber-criminals can perform malicious actions remotely. As one lasting threat, sabotaging smart devices' execution integrity can cause a large financial loss, i.e., causing malfunctioning. Hence, it is important to secure the execution integrity of smart devices in Industry 4.0. Motivated by the emerging blockchain technology, in this paper, we focus on how blockchain can help Industry 4.0 application protect execution integrity and propose a blockchain-based execution protection scheme namedNoSneaky, which is low-cost and can be easily integrated into the current production systems. In the evaluation, we demonstrate its performance and effectiveness in securing the execution integrity.
Wei-Yang Chiu, Weizhi Meng 0001, Chunpeng Ge 0001
IEEE Trans. Ind. Informatics2
2023 Attribute-Based Data Sharing Scheme With Flexible Search Functionality for Cloud-Assisted Autonomous Transportation System
abstract
The existing group public key encryption with equality test schemes could only support one-to-one data sharing and are not suitable for cloud-assisted autonomous transportation systems, which demand one-to-many data sharing. To tackle this problem efficiently, in this article, we put forward the group-attribute-based encryption with equality test (G-ABEET) scheme. The presented G-ABEET allows sensors equipped in vehicles to encrypt traffic data with an expressive access policy before sharing it. Only users with attributes required by the access policy ought to access the shared ciphertexts, thus achieving selective one-to-many data sharing. Meanwhile, the authorized cloud server could provide group users with equality tests over the ciphertexts, realizing ciphertext search ability. Furthermore, with the group mechanism, the G-ABEET scheme could resist offline message recovery attacks. Besides, in the standard model, we give rigorous security proof of the G-ABEET construction. The feasibility and efficiency of G-ABEET are demonstrated by experimental simulations.
Hu Xiong, Hanxiao Wang 0002, Weizhi Meng 0001, Kuo-Hui Yeh
IEEE Trans. Ind. Informatics3
2023 Towards Intelligent Attack Detection Using DNA Computing
abstract
In recent years, frequent network attacks have seriously threatened the interests and security of humankind. To address this threat, many detection methods have been studied, some of which have achieved good results. However, with the development of network interconnection technology, massive amounts of network data have been produced, and considerable redundant information has been generated. At the same time, the frequently changing types of cyberattacks result in great difficulty collecting samples, resulting in a serious imbalance in the sample size of each attack type in the dataset. These two problems seriously reduce the robustness of existing detection methods, and existing research methods do not provide a good solution. To address these two problems, we define an unbalanced index and an optimal feature index to directly reflect the performance of a detection method in terms of overall accuracy, feature subset optimization, and detection balance. Inspired by DNA computing, we propose intelligent attack detection based on DNA computing (ADDC). First, we design a set of regular encoding and decoding features based on DNA sequences and obtain a better subset of features through biochemical reactions. Second, nondominated ranking based on reference points is used to select individuals to form a new population to optimize the detection balance. Finally, a large number of experiments are carried out on four datasets to reflect real-world cyberattack situations. Experimental results show that compared with the most recent detection methods, our method can improve the overall accuracy of multiclass classification by up to 10%; the imbalance index decreased by 0.5, and 1.5 more attack types were detected on average; and the optimal index of the feature subset increased by 83.8%.
ZengRi Zeng, Baokang Zhao, Han-Chieh Chao, Ilsun You, Kuo-Hui Yeh, Weizhi Meng 0001
ACM Trans. Multim. Comput. Commun. Appl.6
2022 Towards Enhanced EEG-based Authentication with Motor Imagery Brain-Computer Interface
abstract
Electroencephalography (EEG) is the record of electrogram of the electrical activity on the scalp typically using non-invasive electrodes. In recent years, many studies started using EEG as a human characteristic to construct biometric identification or authentication. Being a kind of behavioral characteristics, EEG has its natural advantages whereas some characteristics have not been fully evaluated. For instance, we find that Motor Imagery (MI) brain-computer interface is mainly used for improving neurological motor function, but has not been widely studied in EEG authentication. Currently, there are many mature methods for understanding such signals. In this paper, we propose an enhanced EEG authentication framework with Motor Imagery, by offering a complete EEG signal processing and identity verification. Our framework integrates signal preprocess, channel selection and deep learning classification to provide an end-to-end authentication. In the evaluation, we explore the requirements of a biometric system such as uniqueness, permanency, collectability, and investigate the framework regarding insider and outsider attack performance, cross-session performance, and influence of channel selection. We also provide a large comparison with state-of-the-art methods, and our experimental results indicate that our framework can provide better performance based on two public datasets.
Bingkun Wu, Weizhi Meng 0001, Wei-Yang Chiu
ACSAC2
2022 Towards Artificial Neural Network Based Intrusion Detection with Enhanced Hyperparameter Tuning
abstract
Due to the development of complex communication paradigms and the rise in the number of inter-connected digital devices, intrusion detection system (IDS) has become one basic and important security mechanism to identify cyber intrusions and protect computer networks. Currently, various deep learning algorithms have been studied in intrusion detection to achieve a high detection rate, whereas the detection performance may be still dependent on specific datasets. To maintain the detection performance, parameter optimization is believed as an effective solution. Motivated by this observation, in this work, we propose a concise but effective hyperparameter tuning process to enhance the artificial neural network (ANN) based IDS. In the evaluation, we consider three ANN variants and four datasets. The experimental results indicate that our approach can outperform similar studies and typical learning algorithms.
Andrei Nicolae Calugar, Weizhi Meng 0001, Haijun Zhang 0002
GLOBECOM2
2022 IDS for CAN: A Practical Intrusion Detection System for CAN Bus Security
abstract
Modern automobiles depend heavily on electronics, controlled by the vehicle's internal network. The controller area network (CAN bus) is the predominant protocol, known for its reliability but also its grievous lack of security. Unfortunately, security is expensive and automotive manufacturers seem disinclined to invest in CAN bus protection. Thus, consumers are left with few options to improve security. In this work, we develop IDS for CAN – an Android application that functions as an intrusion detection system (IDS) for the CAN bus system. In particular, it communicates with a standard ELM 327-type device, plugged into the diagnostic port that is mandatory in the United States and Europe. The application will detect suspicious traffic on the CAN bus and generate an alert to notify the user. In our evaluation, we investigate the performance with both datasets and real vehicles. The results indicate the practicability and the effectiveness of our proposed system. Our application will allow consumers to take charge of automotive security.
Brooke Kidmose, Weizhi Meng 0001
GLOBECOM2
2022 TDL-IDS: Towards A Transfer Deep Learning based Intrusion Detection System
abstract
With the development of Internet of Things (IoT), network security has become very important as cyber-attackers can easily compromise such distributed networks and systems. An intrusion detection system (IDS) is a basic and essential security mechanism to detect malicious traffic. In the literature, in addition to traditional machine learning algorithms, many deep learning schemes have been examined to enhance the detection performance. However, insufficient amounts of labeled samples are still a challenge for real-world implementation, especially in some scenarios such as smart home and Internet of Vehicles. To address this issue, we explore transfer learning as a promising solution. In this work, we develop TDL-IDS, a transfer deep learning based IDS that can work with limited labeled data items. Our approach first uses Long Short Term Memory (LSTM) to train a model on the source domain and then leverages transfer learning to continue the training process on the target domain. In the evaluation, we use NSL-KDD as the source domain, and AWID as the target domain. Our results indicate that TDL-IDS can outperform many similar approaches.
Xingguo Sun, Weizhi Meng 0001, Wei-Yang Chiu, Brooke Kidmose
GLOBECOM2
2022 AirChain - Towards Blockchain-based Aircraft Maintenance Record System
abstract
Civil aviation (aircraft) is one of the public transportation industries that requires the highest safety standards. However, several accidents on aircraft maintenance system had revealed that there is a need to secure the record integrity and traceability. Motivated by this issue and supported by an airline, in this work, we design and implement AirChain, a blockchain-based aircraft maintenance record system, in which the data can be stored in a way that is both resistant to tampering and easy to access. The experimental results indicate the viability and practicability of our system.
Wictor Lang Jensen, Sille Jessing, Wei-Yang Chiu, Weizhi Meng 0001
ICBC4
2022 Lightweight and Practical Privacy-Preserving Image Masking in Smart Community
Yi-Ning Liu 0002, Weizhi Meng 0001
ICICS3
2022 Towards A Scalable and Privacy-Preserving Blockchain-based European Parking System
abstract
The importance of efficient and accessible parking systems has been growing over the past decades. Steady growth in urban population and car ownership has increased problems with traffic congestion and air pollution caused by inadequate parking systems. Blockchain-based parking systems have been proposed to increase system availability and resilience and improve trust among participants. However, these systems are not transferable to the parking systems of European cities such as Copenhagen, as they are based on assumptions about the parking infrastructure, which do not hold, and are inherently incompatible with regional privacy protection regulations such as the GDPR. Furthermore, many blockchain solutions suffer from scalability issues, severely limiting their efficiency. In this work, we develop a blockchainbased parking system in Denmark, aiming to make up the gap in the existing research by directly considering GDPR compliance. Our work focuses on the municipal parking system for on-street parking in Copenhagen (Denmark), where Hyperledger Fabric is used to maintain a trusted distributed ledger for parking data shared by the network. Personal data is protected through offchain storage while maintaining on-chain verifiability. The proposed system is implemented as a proof-of-concept application, which can deliver sufficient throughput to support the needs of municipal parking.
Jonathan Kvist Brittain, Wei-Yang Chiu, Weizhi Meng 0001
ICPADS3
2022 Towards Blockchain-Enabled Intrusion Detection for Vehicular Navigation Map System
Bodi Bodi, Wei-Yang Chiu, Weizhi Meng 0001
ISPEC3
2022 Designing Enhanced Robust 6G Connection Strategy with Blockchain
August Lykke Thomsen, Bastian Preisel, Victor Rodrigues Andersen, Wei-Yang Chiu, Weizhi Meng 0001
ISPEC5
2022 A Privacy-Preserving Distributed Machine Learning Protocol Based on Homomorphic Hash Authentication
Lisong Wang, Weizhi Meng 0001, Chunpeng Ge 0001
NSS3
2022 FolketID: A Decentralized Blockchain-Based NemID Alternative Against DDoS Attacks
Wei-Yang Chiu, Weizhi Meng 0001, Wenjuan Li 0001, Liming Fang 0001
ProvSec2
2022 Security Analysis in Satellite Communication based on Geostationary Orbit
abstract
With the rapid growth of Internet of Things (IoT) devices and evolving 5G/6G networks, satellite communication has become extremely important, which can provide the capability of sending information from one place to another via a communication satellite in orbit around the Earth. Due to the increasing needs, the Internet traffic is naturally part of satellite communication, carrying a large number of sensitive or private information and data. As such, the proliferation of satellites may bring increased security risks. Motivated by this concern, in this work, we aim to investigate the potential security breaches in satellite communication, with a specific focus on geostationary orbit (GEO) satellites. In particular, we firstly set up an experimental environment to collect data from satellites that the hardware equipment supports, and then perform a risk assessment based on NIST. In terms of our experimental findings and risk analysis, we identify a total of 15 threat sources that may cause various security issues. In the end, we discuss potential solutions to enhance the security and lessons learnt in our setup.
Jacob Krabbe Pedersen, Mikkel Bøchman, Weizhi Meng 0001
PST3
2022 Designing In-Air Hand Gesture-based User Authentication System via Convex Hull
abstract
With the rapid development of personal computers and mobile devices, it is very important to properly authenticate a user’s identity to protect the information and data stored on these devices. Due to various privacy and security concerns, contactless authentication has received much attention, among which in-air gesture based authentication is one promising solution. Motivated by this observation, in this work, we develop and implement a real-time in-air hand gesture-based user authentication system, where users can define or select various gestures and generate their credentials. Our system can verify a user using a deep learning-enabled inference framework without the need of being trained by a powerful device. Different from the state-of-the-art, our system uses a method of convex hull to recognize the hand gesture. In our user study, we involve 20 participants to examine the system performance, and find that our system is viable and usable with a success rate of 95%.
Weizhi Meng 0001, Wenjuan Li 0001
PST2
2022 For a few diversities more: A voting-attack-immune voting scheme for social question and answer websites
abstract
Summary Social question and answer (Q&A) communities or websites, such as Quora, StackOverflow, become popular from the last decade. They provide collected answers in a crowdsourcing way by encouraging the interactive between users. The ranking of answers in such Q&A websites depends on many factors, such as received upvotes, downvotes, publishing time, and so on. When there exist malicious users, they can manipulate the ranking of answers by launching voting spamming attacks. In this article, we propose a metric, diversity of visibility, to characterize the balance between rankings of answers with conflicting opinions and propose a time‐diversitybased voting scheme to reach a high diversity of visibility, so as to minimize the impact of voting spamming attacks. We evaluate the proposed metric and voting scheme in the case study of a Chinese Q&A website, Zhihu, and show that the proposed voting scheme consistently shows a good balance of answers with conflicting opinions in both actual scenarios and synthetic scenarios.
Jun Zhang 0019, Houda Labiod, Weizhi Meng 0001
Concurr. Comput. Pract. Exp.3
2022 Threshold identity authentication signature: Impersonation prevention in social network services
abstract
Summary While the social network services (SNS) have dominate the ways that people communicate with each other on the Internet, identity impersonation remains to be a serious issue that needs to be solved due to the anonymity in the cyber network. Currently, the potential solution to the problem relies heavily on the administration from the central server, which requires intensive workload of the identity management. In this article, we propose a threshold identity authentication signature scheme to solve the impersonation problem from the protocol layer rather than software design in the traditional upper level. In our scheme, with the help of some authenticated accounts, trusted relationship can be shared in a group to other unauthenticated accounts, which largely decrease the workload of authenticating all the accounts. Users are given the ability to verify other accounts' identity information by their signatures. Then, we establish three security goals to prevent the malicious adversary to launch the impersonation attack on a group. We claim that our scheme is suitable for the SNS scenario since the procedure of generating a signature to prove the identity requires little computation cost, it is user‐friendly especially on the lightweight devices such as mobile devices and so on.
Zhanwen Chen, Jiageng Chen, Weizhi Meng 0001
Concurr. Comput. Pract. Exp.3
2022 An empirical study of supervised email classification in Internet of Things: Practical performance and key influencing factors
abstract
202111 bcwh
Wenjuan Li 0001, Lishan Ke, Weizhi Meng 0001, Jinguang Han
Int. J. Intell. Syst.3
2022 Editorial: Security and Privacy Challenges in Internet of Things
Ding Wang 0002, Weizhi Meng 0001
Mob. Networks Appl.2
2022 DVPPIR: privacy-preserving image retrieval based on DCNN and VHE
Lei Wu 0011, Weizhi Meng 0001, Zihui Xu, Chengyi Qin, Hao Wang 0007
Neural Comput. Appl.3
2022 A novel rough set-based approach for minimum vertex cover of hypergraphs
Qian Zhou 0005, Hua Dai 0003, Weizhi Meng 0001
Neural Comput. Appl.4
2021 Mind the Scraps: Attacking Blockchain Based on Selfdestruct
Wei-Yang Chiu, Weizhi Meng 0001
ACISP2
2021 ActAnyware - Blockchain-Based Software Licensing Scheme
Wei-Yang Chiu, Lu Zhou 0002, Weizhi Meng 0001, Zhe Liu 0001, Chunpeng Ge 0001
BlockSys3
2021 NGS: Mitigating DDoS Attacks using SDN-based Network Gate Shield
abstract
The Internet of Things (IoT) implements a tremendous environment of extensive data streams, whereby any suspicious activities should be detected to safeguard systems' reliability and availability. Distributed Denial of Service (DDoS) attack is a major threat on computer networks, in which an attacker can send huge traffic with multiple IP addresses or machines. In this work, we focus on detecting DDoS attacks, and design Network Gate Shield (NGS), a tool that works on SDN architecture based on the RYU controller. It can examine the traffic trustworthiness, and then determine whether the current traffic is normal based on packet specification, such as the average packet size and the packet per-sec threshold. In the evaluation with an emulated environment, our experimental results indicate that NGS is viable and effective in mitigating DDoS traffic compared with several similar detection approaches.
Mohamad Suhel Dalati, Weizhi Meng 0001, Wei-Yang Chiu
GLOBECOM2
2021 TridentShell: a Covert and Scalable Backdoor Injection Attack on Web Applications
Xiaobo Yu, Weizhi Meng 0001, Yi-Ning Liu 0002
ISC2
2021 BALSAPro: Towards A Security Protocol for Bluetooth Low Energy
abstract
The rapid and increasing application of wireless technology, especially Bluetooth Low Energy (BLE), provides many benefits to our daily lives. With BLE, the small packets of data can be exchanged over a wireless channel, whereas the data security is a concern. For example, the BLE standards define that if one BLE device with input-output capabilities tries to establish a connection while the other BLE device does not support input-output, an unauthenticated channel will be established. That is, in the worst case, the connection is established where no security is applied. To mitigate this issue, we propose a security protocol, named BALSAPro, at the application layer that complements the existing protocols such as Security Manager Protocol (SMP), which can help establish a secure channel with authentication and non-repudiation, when pairing has not been used. In the evaluation, we implement and evaluate our protocol performance compared with similar work at the application layer. The results demonstrate that our protocol can enhance the security level with less time consumption.
Mohamad Muwfak Hlal, Weizhi Meng 0001
MSN2
2021 Towards DTW-based Unlock Scheme using Handwritten Graphics on Smartphones
abstract
Nowadays, due to the increasing capability, mobile devices especially smartphones have become a necessity in people’s daily life, which would store a lot of personal and private information. This makes smartphones a major target for cyber-attackers, i.e., either loss of such mobile deices or illegal access will cause personal data breach and economic damage. Hence it is of great importance to safeguard smartphones from unauthorized access with the purpose of reducing the risk of privacy leakage and economic losses. To achieve this purpose, designing a suitable scheme to unlock phone screen is one promising solution. For instance, Android unlock scheme is a typical example, where users can unlock the phone screen by inputting a correct pattern. However, its password space is low due to the adoption of only nine dots on a 2D grid. In this work, we design a new unlock scheme using handwritten graphics, which uses an improved DTW-based algorithm for authentication. Also, we implement a prototype and evaluate our scheme using both a public dataset (SUSIG) and a self-collected dataset (SCD). Our results indicated that our scheme could achieve 7.12% and 8.75% EER on SUSIG and SCD respectively.
Weizhi Meng 0001, Wenjuan Li 0001
MSN2
2021 Efficient Attribute-Based Signature for Monotone Predicates
Jixin Zhang, Jiageng Chen, Weizhi Meng 0001
ProvSec3
2021 LibBlock - Towards Decentralized Library System based on Blockchain and IPFS
abstract
In modern times, the definition and the library’s expected functionality did not change much as before. It is still a place for us to hold massive collections of information. Traditionally, libraries require physical storage space for writings and publications, but storing and managing costs can be tremendous. Although the aid of digital promises and computers allows a super high density of information storage, it does not lower the library’s complexity. As our main source of information is moving away from physical writings toward digital, the new digital library (i.e., state-run library) faces the challenges of records’ integrity and storage efficiency. Focused on this issue, we learn the demands from the Royal Library in Denmark and try to explore the use of blockchain technology. We introduce a system named LibBlock, by integrating with both smart contract and IPFS in order to provide a robust, decentralized, flexible, and adaptive e-Library, which enables the ease of scalability and rigid record keeping. In the evaluation, we investigate the initial performance of LibBlock with Ethereum and show its viability and efficiency.
Wei-Yang Chiu, Weizhi Meng 0001, Wenjuan Li 0001
PST2
2021 Enhancing Trust-based Medical Smartphone Networks via Blockchain-based Traffic Sampling
abstract
With more devices being inter- or intra-connected, Internet of Things (IoT) has gradually been adopted in many disciplines, such as healthcare industry, coined as Internet of Medical Things (IoMT). The purpose of IoMT is to facilitate the efficiency and effectiveness of medical operations, i.e., remotely monitoring the status of patients. In such healthcare environments, smartphones have become an important device to communicate with others and update the information of patients, resulting in a special type of IoMT called Medical Smartphone Networks (MSNs). To reinforce the distributed architecture, trust management schemes are often implemented to defend against insider attacks. However, how to maintain the robustness of trust management in heavy traffic networks still remains a challenge, i.e., COVID-19 incident would cause excessive traffic for healthcare organizations and increase the difficulty of validating trustworthiness among MSN nodes. In this work, we focus on this issue and propose a blockchain-enabled adaptive traffic sampling method to help enhance the robustness of trust management under high traffic environments. The use of blockchain technology aims to build a verified database of malicious traffic among all nodes. The evaluation in a real healthcare environment demonstrates the viability and effectiveness of our approach.
Wenjuan Li 0001, Weizhi Meng 0001, Laurence T. Yang
TrustCom2
2021 Mind the Amplification: Cracking Content Delivery Networks via DDoS Attacks
Weizhi Meng 0001
WASA (2)2
2021 Enhancing Blackslist-Based Packet Filtration Using Blockchain in Wireless Sensor Networks
Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017, Jin Li 0002
WASA (2)2
2021 Mobile network traffic pattern classification with incomplete a priori information
Zhiping Jin, Zhibiao Liang, Yu Wang 0017, Weizhi Meng 0001
Comput. Commun.4
2021 Corrigendum to "CyberShip-IoT: A Dynamic and Adaptive SDN-Based Security Policy Enforcement Framework for Ships" [Future Gener. Comput. Syst. 100 (2019) 736-750]
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod
Future Gener. Comput. Syst.2
2021 Accurate Range Query With Privacy Preservation for Outsourced Location-Based Service in IoT
abstract
With the maturity of Internet-of-Things technology, location-based service (LBS) is developing rapidly in intelligent terminal devices, and it brings new vitality to the fields of logistics, transportation, product traceability and so on. The popularity of LBS produces a lot of spatial data, which inevitably brings burden to the storage and management of LBS provider (LBSP). With the help of cloud computing and cloud storage, outsourcing spatial data to cloud server has become a new trend. However, due to the cloud server is not trusted, data outsourcing will face the problems of data disclosure and query disclosure. Range query is a common query in LBS, considering the situation of data outsourcing, this article proposes an accurate range query (ARQ) scheme, which can realize efficient range query while preserving LBSP's data privacy and user's query privacy from being disclosed to the cloud server. The ARQ scheme is suitable for spatial data in any form without being limited to the case that the data points are only integers, which has a certain practical significance. In addition, by dividing the region into atomic regions, ARQ can realize sublinear search time and ensure dynamic update of spatial data. We proved the security of the proposed scheme through security analysis, and demonstrated the effectiveness of the scheme through experiments.
Zhaoman Liu, Lei Wu 0011, Weizhi Meng 0001, Hao Wang 0007, Wei Wang 0012
IEEE Internet Things J.3
2021 Hybrid Emotion-Aware Monitoring System Based on Brainwaves for Internet of Medical Things
abstract
Driven by an increasing number of connected medical devices, Internet of Medical Things (IoMT), as an application of Internet of Things (IoT) in healthcare, is developed to help collect, analyze, and transmit medical data. During the outbreak of a pandemic like COVID-19, IoMT can be useful to monitor the status of patients and detect main symptoms remotely, by using various smart sensors. However, due to the lack of emotional care in the current IoMT, it is still a challenge to reach an efficient medical process. Especially under COVID-19, there is a need to monitor emotional status among particular people like the elderly. In this work, we propose an emotion-aware healthcare monitoring system in IoMT, based on brainwaves. With the fast development of electroencephalography (EEG) sensors in current headsets and some devices, brainwave-based emotion detection becomes feasible. The IoMT devices are used to capture the brainwaves of a patient in a scenario of smart home. Also, our system involves the analysis of touch behavior as the second layer to enhance the brainwave-based emotion recognition. In the user study with 60 participants, the results indicate the viability and effectiveness of our approach in detecting emotions like comfortable and uncomfortable, which can complement existing emotion-aware healthcare applications and mechanisms.
Weizhi Meng 0001, Laurence T. Yang, Wei-Yang Chiu
IEEE Internet Things J.1
2021 My data, my control: A secure data sharing and access scheme over blockchain
Wei-Yang Chiu, Weizhi Meng 0001, Christian Damsgaard Jensen
J. Inf. Secur. Appl.2
2021 EdgeTC - a PBFT blockchain-based ETC scheme for smart cities
Wei-Yang Chiu, Weizhi Meng 0001
Peer-to-Peer Netw. Appl.2
2021 Towards efficient and energy-aware query processing for industrial internet of things
Liang Liu 0006, Weizhi Meng 0001, Wenzhao Gao, Zuchao Ma
Peer-to-Peer Netw. Appl.3
2021 User recognition based on periocular biometrics and touch dynamics
Andrea Casanova, Lucia Cascone, Aniello Castiglione, Weizhi Meng 0001, Chiara Pero
Pattern Recognit. Lett.4
2021 Exploring touch-based behavioral authentication on smartphone email applications in IoT-enabled smart cities
Wenjuan Li 0001, Weizhi Meng 0001, Steven Furnell
Pattern Recognit. Lett.2
2021 Designing Leakage-Resilient Password Entry on Head-Mounted Smart Wearable Glass Devices
abstract
With the boom of Augmented Reality (AR) and Virtual Reality (VR) applications, head-mounted smart wearable glass devices are becoming popular to help users access various services like E-mail freely. However, most existing password entry schemes on smart glasses rely on additional computers or mobile devices connected to smart glasses, which require users to switch between different systems and devices. This may greatly lower the practicability and usability of smart glasses. In this paper, we focus on this challenge and design three practical anti-eavesdropping password entry schemes on stand-alone smart glasses, named gTapper, gRotator and gTalker. The main idea is to break the correlation between the underlying password and the interaction observable to adversaries. In our IRB-approved user study, these schemes are found to be easy-to-use without additional hardware under various test conditions, where the participants can enter their passwords within moderate time, at high accuracy, and in various situations.
Yan Li 0075, Weizhi Meng 0001, Yingjiu Li, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.3
2021 Sparse Trust Data Mining
abstract
As recommendation systems continue to evolve, researchers are using trust data to improve the accuracy of recommendation prediction and help users find relevant information. However, large recommendation systems with trust data suffer from the sparse trust problem, which leads to grade inflation and severely affects the reliability of trust propagation. This paper presents a novel research on sparse trust data mining, which includes the new concept of sparse trust, a sparse trust model, and a trust mining framework. It lays a foundation for the trust-related research in large recommended systems. The new trust mining framework is based on customized normalization functions and a novel transitive gossip trust model, which discovers potential trust information between entities in a large-scale user network and applies it to a recommendation system. We conducts a comprehensive performance evaluation on both real-world and synthetic datasets. The results confirm that our framework mines new trust and effectively ameliorates sparse trust problem.
Pengli Nie, Guangquan Xu, Litao Jiao, Shaoying Liu, Jian Liu 0004, Weizhi Meng 0001, Hongyue Wu, Meiqi Feng, Zhengjun Jing, James Xi Zheng
IEEE Trans. Inf. Forensics Secur.6
2020 DCONST: Detection of Multiple-Mix-Attack Malicious Nodes Using Consensus-Based Trust in IoT Networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001
ACISP3
2020 ELD: Adaptive Detection of Malicious Nodes under Mix-Energy-Depleting-Attacks Using Edge Learning in IoT Networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001
ISC3
2020 Evaluation of Anomaly-Based Intrusion Detection with Combined Imbalance Correction and Feature Selection
Andreas Heidelbach Engly, Anton Ruby Larsen, Weizhi Meng 0001
NSS3
2020 Towards Collaborative Intrusion Detection Enhancement against Insider Attacks with Multi-Level Trust
abstract
With the speedy growth of distributed networks such as Internet of Things (IoT), there is an increasing need to protect network security against various attacks by deploying collaborative intrusion detection systems (CIDSs), which allow different detector nodes to exchange required information and data with each other. While due to the distributed architecture, insider attacks are a big threat for CIDSs, in which an attacker can reside inside the network. To address this issue, designing an appropriate trust management scheme is considered as an effective solution. In this work, we first analyze the development of CIDSs in the past decades and identify the major challenges on building an effective trust management scheme. Then we introduce a generic framework aiming to enhance the security of CIDSs against advanced insider threats by deriving multilevel trust. In the study, our results demonstrate the viability and the effectiveness of our framework.
Wenjuan Li 0001, Weizhi Meng 0001
TrustCom2
2020 SCAFFISD: A Scalable Framework for Fine-grained Identification and Security Detection of Wireless Routers
abstract
The security of wireless network devices has received widespread attention, but most existing schemes cannot achieve fine-grained device identification. In practice, the security vulnerabilities of a device are heavily depending on its model and firmware version. Motivated by this issue, we propose a universal, extensible and device-independent framework called SCAFFISD, which can provide fine-grained identification of wireless routers. It can generate access rules to extract effective information from the router admin page automatically and perform quick scans for known device vulnerabilities. Meanwhile, SCAFFISD can identify rogue access points (APs) in combination with existing detection methods, with the purpose of performing a comprehensive security assessment of wireless networks. We implement the prototype of SCAFFISD and verify its effectiveness through security scans of actual products.
Fangzhou Zhu, Liang Liu 0006, Weizhi Meng 0001, Ting Lv, Renjun Ye
TrustCom3
2020 MSYM: A multichannel communication system for android devices
Donghai Tian, Weizhi Meng 0001, Xiaoqi Jia, Rui Ma 0004
Comput. Networks3
2020 Towards multiple-mix-attack detection via consensus-based trust management in IoT networks
Zuchao Ma, Liang Liu 0006, Weizhi Meng 0001
Comput. Secur.3
2020 Detecting insider attacks in medical cyber-physical networks based on behavioral profiling
Weizhi Meng 0001, Wenjuan Li 0001, Yu Wang 0017, Man Ho Au
Future Gener. Comput. Syst.1
2020 THP: A Novel Authentication Scheme to Prevent Multiple Attacks in SDN-Based IoT Network
abstract
SDN has provided significant convenience for network providers and operators in cloud computing. Such a great advantage is extending to the Internet of Things network. However, it also increases the risk if the security of an SDN network is compromised. For example, if the network operator's permission is illegally obtained by a hacker, he/she can control the entry of the SDN network. Therefore, an effective authentication scheme is needed to fit various application scenarios with high-security requirements. In this article, we design, implement, and evaluate a new authentication scheme called the hidden pattern (THP), which combines graphics password and digital challenge value to prevent multiple types of authentication attacks at the same time. We examined THP in the perspectives of both security and usability, with a total number of 694 participants in 63 days. Our evaluation shows that THP can provide better performance than the existing schemes in terms of security and usability.
Liming Fang 0001, Yang Li 0103, Xinyu Yun, Zhenyu Wen, Shouling Ji, Weizhi Meng 0001, Zehong Cao, Muhammad Tanveer 0001
IEEE Internet Things J.6
2020 Analysis of differential distribution of lightweight block cipher based on parallel processing on GPU
Zhanwen Chen, Jiageng Chen, Weizhi Meng 0001, Je Sen Teh, Bingqing Ren
J. Inf. Secur. Appl.3
2020 Lightweight privacy-preserving data aggregation protocol against internal attacks in smart grid
Xiao-di Wang, Weizhi Meng 0001, Yi-Ning Liu 0002
J. Inf. Secur. Appl.2
2020 Enhancing collaborative intrusion detection via disagreement-based semi-supervised learning in IoT environments
Wenjuan Li 0001, Weizhi Meng 0001, Man Ho Au
J. Netw. Comput. Appl.2
2020 A swipe-based unlocking mechanism with supervised learning on smartphones: Design and evaluation
Wenjuan Li 0001, Jiao Tan, Weizhi Meng 0001, Yu Wang 0017
J. Netw. Comput. Appl.3
2020 Towards blockchain-enabled single character frequency-based exclusive signature matching in IoT-assisted smart cities
Weizhi Meng 0001, Wenjuan Li 0001, Steven Tug, Jiao Tan
J. Parallel Distributed Comput.1
2020 Secure Information Transmissions in Wireless-Powered Cognitive Radio Networks for Internet of Medical Things
abstract
In this paper, we consider the issue of the secure transmissions for the cognitive radio-based Internet of Medical Things (IoMT) with wireless energy harvesting. In these systems, a primary transmitter (PT) will transmit its sensitive medical information to a primary receiver (PR) by a multi-antenna-based secondary transmitter (ST), where we consider that a potential eavesdropper may listen to the PT’s sensitive information. Meanwhile, the ST also transmits its own information concurrently by utilizing spectrum sharing. We aim to propose a novel scheme for jointly designing the optimal parameters, i.e., energy harvesting (EH) time ratio and secure beamforming vectors, for maximizing the primary secrecy transmission rate while guaranteeing secondary transmission requirement. For solving the nonconvex optimization problem, we transfer the problem into convex optimization form by adopting the semidefinite relaxation (SDR) method and Charnes–Cooper transformation technique. Then, the optimal secure beamforming vectors and energy harvesting duration can be obtained easily by utilizing the CVX tools. According to the simulation results of secrecy transmission rate, i.e., secrecy capacity, we can observe that the proposed protocol for the considered system model can effectively promote the primary secrecy transmission rate when compared with traditional zero-forcing (ZF) scheme, while ensuring the transmission rate of the secondary system.
Wenjuan Tang, Zhiyuan Tan 0001, Weizhi Meng 0001, Lianyong Qi
Secur. Commun. Networks5
2020 Editorial: Blockchain in Industrial IoT Applications: Security and Privacy Advances, Challenges, and Opportunities
abstract
Blockchain is an emerging technology that has widespread applications, such as those relating to Internet of Things (IoT) and Industrial IoT (IIoT). While there are many (potential) applications of blockchain in IIoT (the focus of this special issue), there are a number of ongoing challenges. For example, blockchain technology provides a solution to ensure a trust relationship without a centralized entity. However, such technology is still under development and suffers from a number of limitations and challenges during implementation, such as computational costs (e.g., mining), security (e.g., attacks such as distributed denial-of-service attacks, and theft of content). In an IIoT application, such as smart cities, Industry 4.0, and in military and battlefield context (also referred to as Internet of battlefield things and Internet of Military Things), there are more factors that need to be taken into consideration in the design of blockchain-based solutions. Therefore, in the following sections we will describe the advances presented in the editorial accepted in this special issue, designed to address different security and privacy challenges associated with the deployment of blockchain-based solutions in an IIoT setting.
Kim-Kwang Raymond Choo, Zheng Yan 0002, Weizhi Meng 0001
IEEE Trans. Ind. Informatics3
2019 A Closer Look Tells More: A Facial Distortion Based Liveness Detection for Face Authentication
abstract
Face authentication is vulnerable to media-based virtual face forgery (MVFF) where adversaries display photos/videos or 3D virtual face models of victims to spoof face authentication systems. In this paper, we propose a liveness detection mechanism, called FaceCloseup, to protect the face authentication on mobile devices. FaceCloseup detects MVFF-based attacks by analyzing the distortion of face regions in a user's closeup facial videos captured by built-in camera on mobile device. It can detect MVFF-based attacks with an accuracy of 99.48%.
Yan Li 0075, Zilong Wang 0001, Yingjiu Li, Robert H. Deng, Binbin Chen 0001, Weizhi Meng 0001, Hui Li 0006
AsiaCCS6
2019 CAVAEva: An Engineering Platform for Evaluating Commercial Anti-malware Applications on Smartphones
Weizhi Meng 0001, Chunhua Su, Kim-Kwang Raymond Choo
Inscrypt2
2019 Practical Bayesian Poisoning Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Kim-Kwang Raymond Choo, Chunhua Su
ESORICS (1)1
2019 Provably Secure Group Authentication in the Asynchronous Communication Model
Zhe Xia, Lein Harn, Bo Yang 0003, Mingwu Zhang, Yi Mu 0001, Willy Susilo, Weizhi Meng 0001
ICICS7
2019 Evaluating Intrusion Sensitivity Allocation with Support Vector Machine for Collaborative Intrusion Detection
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok
ISPEC2
2019 Towards Secure Open Banking Architecture: An Evaluation with OWASP
Deina Kellezi, Christian Boegelund, Weizhi Meng 0001
NSS3
2019 SocialAuth: Designing Touch Behavioral Smartphone User Authentication Based on Social Networking Applications
Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Jianying Zhou 0001
SEC1
2019 Attribute-Based Information Flow Control
abstract
Abstract Information flow control (IFC) regulates where information is permitted to travel within information systems. To enforce IFC, access control encryption (ACE) was proposed to support both the no read-up rule and the no write-down rule. There are some problems in existing schemes. First, the communication cost is linear with the number of receivers. Second, senders are not authenticated, namely an unauthorized sender can send a message to a receiver. To reduce communication cost and implement sender authentication, we propose an attribute-based IFC (ABIFC) scheme by introducing attribute-based systems into IFC. Our ABIFC scheme captures the following features: (i) flexible IFC policies are defined over a universal set of descriptive attributes; (ii) both the no read-up rule and the no write-down rule are supported; (iii) the communication cost is linear with the number of required attributes, instead of receivers; (iv) receivers can outsource heavy computation to a server without compromising data confidentiality; (v) authorized senders can control release their attributes when sending messages to receivers. To the best of our knowledge, it is the first IFC scheme where flexible policies are defined over descriptive attributes and outsourced computation is supported.
Jinguang Han, Maoxuan Bei, Liqun Chen 0002, Yang Xiang 0001, Jie Cao 0001, Fuchun Guo, Weizhi Meng 0001
Comput. J.7
2019 Adaptive machine learning-based alarm reduction via edge computing for distributed intrusion detection systems
abstract
Summary To protect assets and resources from being hacked, intrusion detection systems are widely implemented in organizations around the world. However, false alarms are one challenging issue for such systems, which would significantly degrade the effectiveness of detection and greatly increase the burden of analysis. To solve this problem, building an intelligent false alarm filter using machine learning classifiers is considered as one promising solution, where an appropriate algorithm can be selected in an adaptive way in order to maintain the filtration accuracy. By means of cloud computing, the task of adaptive algorithm selection can be offloaded to the cloud, whereas it could cause communication delay and increase additional burden. In this work, motivated by the advent of edge computing, we propose a framework to improve the intelligent false alarm reduction for DIDS based on edge computing devices. Our framework can provide energy efficiency as the data can be processed at the edge for shorter response time. The evaluation results demonstrate that our framework can help reduce the workload for the central server and the delay as compared to the similar studies.
Yu Wang 0017, Weizhi Meng 0001, Wenjuan Li 0001, Zhe Liu 0001, Hanxiao Xue
Concurr. Comput. Pract. Exp.2
2019 Designing collaborative blockchained signature-based intrusion detection in IoT environments
Wenjuan Li 0001, Steven Tug, Weizhi Meng 0001, Yu Wang 0017
Future Gener. Comput. Syst.3
2019 Detection of multiple-mix-attack malicious nodes using perceptron-based trust in IoT networks
Liang Liu 0006, Zuchao Ma, Weizhi Meng 0001
Future Gener. Comput. Syst.3
2019 Enhancing the security of FinTech applications with map-based graphical password authentication
Weizhi Meng 0001, Liqiu Zhu, Wenjuan Li 0001, Jinguang Han, Yan Li 0075
Future Gener. Comput. Syst.1
2019 CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
Rishikesh Sahay, Weizhi Meng 0001, Daniel A. Sepulveda Estay, Christian Damsgaard Jensen, Michael Bruhn Barfod
Future Gener. Comput. Syst.2
2019 Efficient Image Recognition and Retrieval on IoT-Assisted Energy-Constrained Platforms From Big Data Repositories
abstract
The advanced computational capabilities of many resource constrained devices, such as smartphones have enabled various research areas including image retrieval from big data repositories for numerous Internet of Things (IoT) applications. The major challenges for image retrieval using smartphones in an IoT environment are the computational complexity and storage. To deal with big data in IoT environment for image retrieval, this paper proposes a light-weighted deep learning-based system for energy-constrained devices. The system first detects and crops face regions from an image using Viola-Jones algorithm with additional face and nonface classifier to eliminate the miss-detection problem. Second, the system uses convolutional layers of a cost effective pretrained CNN model with defined features to represent faces. Next, features of the big data repository are indexed to achieve a faster matching process for real-time retrieval. Finally, Euclidean distance is used to find similarity between query and repository images. For experimental evaluation, we created a local facial images dataset, including both single and group facial images. This dataset can be used by other researchers as a benchmark for comparison with other real-time facial image retrieval systems. The experimental results show that our proposed system outperforms other state-of-the-art feature extraction methods in terms of efficiency and retrieval for IoT-assisted energy-constrained platforms.
Irfan Mehmood, Amin Ullah, Khan Muhammad 0001, Der-Jiunn Deng, Weizhi Meng 0001, Fadi M. Al-Turjman, Victor Hugo C. de Albuquerque
IEEE Internet Things J.5
2019 Design of multi-view based email classification for IoT systems via semi-supervised learning
Wenjuan Li 0001, Weizhi Meng 0001, Zhiyuan Tan 0001, Yang Xiang 0001
J. Netw. Comput. Appl.2
2019 The application of Software Defined Networking on securing computer networks: A survey
Rishikesh Sahay, Weizhi Meng 0001, Christian Damsgaard Jensen
J. Netw. Comput. Appl.2
2019 Machine Learning for Wireless Multimedia Data Security
Zhaoqing Pan, Ching-Nung Yang, Victor S. Sheng, Naixue Xiong, Weizhi Meng 0001
Secur. Commun. Networks5
2019 Security, Privacy, and Trust on Internet of Things
Constantinos Kolias, Weizhi Meng 0001, Georgios Kambourakis, Jiageng Chen
Wirel. Commun. Mob. Comput.2
2018 Enhancing Intelligent Alarm Reduction for Distributed Intrusion Detection Systems via Edge Computing
Weizhi Meng 0001, Yu Wang 0017, Wenjuan Li 0001, Zhe Liu 0001, Jin Li 0002, Christian W. Probst
ACISP1
2018 Analysis of Variance of Graph-Clique Mining for Scalable Proof of Work
Hiroaki Anada, Tomohiro Matsushima, Chunhua Su, Weizhi Meng 0001, Junpei Kawamoto, Samiran Bag, Kouichi Sakurai
Inscrypt4
2018 Evaluating the Impact of Intrusion Sensitivity on Securing Collaborative Intrusion Detection Networks Against SOOA
David Madsen, Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017
ICA3PP (4)3
2018 Towards Securing Challenge-Based Collaborative Intrusion Detection Networks via Message Verification
Wenjuan Li 0001, Weizhi Meng 0001, Yu Wang 0017, Jinguang Han, Jin Li 0002
ISPEC2
2018 TMGMap: Designing Touch Movement-Based Geographical Password Authentication on Smartphones
Weizhi Meng 0001, Zhe Liu 0001
ISPEC1
2018 Analyzing the Communication Security Between Smartphones and IoT Based on CORAS
Motalib Hossain Bhuyan, Nur A. Azad, Weizhi Meng 0001, Christian Damsgaard Jensen
NSS3
2018 Position Paper on Blockchain Technology: Smart Contract and Applications
Weizhi Meng 0001, Jianfeng Wang 0001, Xianmin Wang, Joseph K. Liu, Zuoxia Yu, Jin Li 0002, Yongjun Zhao 0001, Sherman S. M. Chow
NSS1
2018 PrivacySearch: An End-User and Query Generalization Tool for Privacy Enhancement in Web Search
Francisco-Javier Rodrigo-Ginés, Javier Parra-Arnau, Weizhi Meng 0001, Yu Wang 0017
NSS3
2018 CPMap: Design of Click-Points Map-Based Graphical Password Authentication
Weizhi Meng 0001, Fei Fei, Lijun Jiang, Zhe Liu 0001, Chunhua Su, Jinguang Han
SEC1
2018 JFCGuard: Detecting juice filming charging attack via processor usage analysis on smartphones
Weizhi Meng 0001, Lijun Jiang, Yu Wang 0017, Jin Li 0002, Jun Zhang 0010, Yang Xiang 0001
Comput. Secur.1
2018 TouchWB: Touch behavioral user authentication based on web browsing on smartphones
Weizhi Meng 0001, Yu Wang 0017, Duncan S. Wong, Sheng Wen, Yang Xiang 0001
J. Netw. Comput. Appl.1
2018 A fog-based privacy-preserving approach for distributed signature-based intrusion detection
Yu Wang 0017, Weizhi Meng 0001, Wenjuan Li 0001, Jin Li 0002, Waixi Liu 0001, Yang Xiang 0001
J. Parallel Distributed Comput.2
2018 Enhancing touch behavioral authentication via cost-based intelligent mechanism on smartphones
Weizhi Meng 0001, Wenjuan Li 0001, Duncan S. Wong
Multim. Tools Appl.1
2018 Towards Bayesian-Based Trust Management for Insider Attacks in Healthcare Software-Defined Networks
abstract
The medical industry is increasingly digitalized and Internet-connected (e.g., Internet of Medical Things), and when deployed in an Internet of Medical Things environment, software-defined networks (SDNs) allow the decoupling of network control from the data plane. There is no debate among security experts that the security of Internet-enabled medical devices is crucial, and an ongoing threat vector is insider attacks. In this paper, we focus on the identification of insider attacks in healthcare SDNs. Specifically, we survey stakeholders from 12 healthcare organizations (i.e., two hospitals and two clinics in Hong Kong, two hospitals and two clinics in Singapore, and two hospitals and two clinics in China). Based on the survey findings, we develop a trust-based approach based on Bayesian inference to figure out malicious devices in a healthcare environment. Experimental results in either a simulated and a real-world network environment demonstrate the feasibility and effectiveness of our proposed approach regarding the detection of malicious healthcare devices, i.e., our approach could decrease the trust values of malicious devices faster than similar approaches.
Weizhi Meng 0001, Kim-Kwang Raymond Choo, Steven Furnell, Athanasios V. Vasilakos, Christian W. Probst
IEEE Trans. Netw. Serv. Manag.1
2017 Exploring Effect of Location Number on Map-Based Graphical Password Authentication
Weizhi Meng 0001, Lee Wang Hao, Man Ho Au, Zhe Liu 0001
ACISP (2)1
2017 A Pilot Study of Multiple Password Interference Between Text and Map-Based Passwords
Weizhi Meng 0001, Wenjuan Li 0001, Lee Wang Hao, Lijun Jiang, Jianying Zhou 0001
ACNS1
2017 Evaluating Challenge-Based Trust Mechanism in Medical Smartphone Networks: An Empirical Study
abstract
Intrusion detection systems (IDSs) are one of the widely adopted security tools in protecting computer networks, whereas it is still a big challenge for a single IDS to identify various threats in practice. Collaborative intrusion detection networks (CIDNs) are then developed in order to enhance the detection capability of a single IDS. However, CIDNs are known to suffer from insider attacks, in which malicious nodes can perform adversary actions. To mitigate this issue, challenge-based trust mechanisms are one of the promising solutions in literature, which are robust against various common insider threats. With the popularity of mobile devices, medical smartphone networks (MSNs) have become an emerging network architecture for healthcare organizations to improve the quality of medical services. Due to the sensitivity, there is a great need to defend MSNs against insider attacks. In this work, we conduct an empirical study to investigate and evaluate the implementation of challenge-based mechanism in MSNs. Our work aims to complement current literature, through providing insights and learned lessens (i.e., whether it is suitable to deploy such a mechanism in MSNs).
Weizhi Meng 0001, Fei Fei, Wenjuan Li 0001, Man Ho Au
GLOBECOM1
2017 SOOA: Exploring Special On-Off Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok
GPC2
2017 Harvesting Smartphone Privacy Through Enhanced Juice Filming Charging Attacks
Weizhi Meng 0001, Fei Fei, Wenjuan Li 0001, Man Ho Au
ISC1
2017 Exploring Energy Consumption of Juice Filming Charging Attack on Smartphones: A Pilot Study
Lijun Jiang, Weizhi Meng 0001, Yu Wang 0017, Chunhua Su, Jin Li 0002
NSS2
2017 Towards enhancing click-draw based graphical passwords using multi-touch behaviours on smartphones
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok, Kim-Kwang Raymond Choo
Comput. Secur.1
2017 Enhancing collaborative intrusion detection networks against insider attacks using supervised intrusion sensitivity-based trust management model
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok, Horace Ho-Shing Ip
J. Netw. Comput. Appl.2
2017 A bayesian inference-based detection mechanism to defend medical smartphone networks against insider attacks
Weizhi Meng 0001, Wenjuan Li 0001, Yang Xiang 0001, Kim-Kwang Raymond Choo
J. Netw. Comput. Appl.1
2017 Towards Effective Trust-Based Packet Filtering in Collaborative Network Environments
abstract
Overhead network packets are a big challenge for intrusion detection systems (IDSs), which may increase system burden, degrade system performance, and even cause the whole system collapse, when the number of incoming packets exceeds the maximum handling capability. To address this issue, packet filtration is considered as a promising solution, and our previous research efforts have proven that designing a trust-based packet filter was able to refine unwanted network packets and reduce the workload of a local IDS. With the development of Internet cooperation, collaborative intrusion detection environments (e.g., CIDNs) have been developed, which allow IDS nodes to collect information and learn experience from others. However, it would not be effective for the previously built trust-based packet filter to work in such a collaborative environment, since the process of trust computation can be easily compromised by insider attacks. In this paper, we adopt the existing CIDN framework and aim to apply a collaborative trust-based approach to reduce unwanted packets. More specifically, we develop a collaborative trust-based packet filter, which can be deployed in collaborative networks and be robust against typical insider attacks (e.g., betrayal attacks). Experimental results in various simulated and practical environments demonstrate that our filter can perform effectively in reducing unwanted traffic and can defend against insider attacks through identifying malicious nodes in a quick manner, as compared to similar approaches.
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
IEEE Trans. Netw. Serv. Manag.1
2016 TMGuard: A Touch Movement-Based Security Mechanism for Screen Unlock Patterns on Smartphones
Weizhi Meng 0001, Wenjuan Li 0001, Duncan S. Wong, Jianying Zhou 0001
ACNS1
2016 On Multiple Password Interference of Touch Screen Patterns and Text Passwords
abstract
The memorability of multiple passwords is an important topic for user authentication systems. With the advent of Android unlock pattern mechanism, research studies started investigating its usability and security features. This paper presents a study of recalling multiple passwords between text passwords and touch screen unlock patterns, as well as exploring whether users have difficulty in remembering those patterns after a period of time. In our study, participants create unlock patterns for various account scenarios. Our results reveal that participants in the unlock pattern condition with three accounts can outperform those in the text password condition (i.e., achieve higher success rates), not only in a one-hour session (short-term), but also after two weeks (long-term). However, there was no statistically significant difference between participants in the text password and unlock pattern condition in the long-term, when dealing with six accounts.
Weizhi Meng 0001, Wenjuan Li 0001, Lijun Jiang, Liying Meng
CHI1
2016 PMFA: Toward Passive Message Fingerprint Attacks on Challenge-Based Collaborative Intrusion Detection Networks
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok, Horace Ho-Shing Ip
NSS2
2016 MVPSys: Toward practical multi-view based false alarm reduction system in network intrusion detection
Wenjuan Li 0001, Weizhi Meng 0001, Xiapu Luo, Lam-for Kwok
Comput. Secur.2
2016 Enhancing collaborative intrusion detection networks using intrusion sensitivity in detecting pollution attacks
abstract
Purpose This paper aims to propose and evaluate an intrusion sensitivity (IS)-based approach regarding the detection of pollution attacks in collaborative intrusion detection networks (CIDNs) based on the observation that each intrusion detection system may have different levels of sensitivity in detecting specific types of intrusions. Design/methodology/approach In this work, the authors first introduce their adopted CIDN framework and a newly designed aggregation component, which aims to collect feedback, aggregate alarms and identify important alarms. The authors then describe the details of trust computation and alarm aggregation. Findings The evaluation on the simulated pollution attacks indicates that the proposed approach is more effective in detecting malicious nodes and reducing the negative impact on alarm aggregation as compared to similar approaches. Research limitations/implications More efforts can be made in improving the mapping of the satisfaction level, enhancing the allocation, evaluation and update of IS and evaluating the trust models in a large-scale network. Practical implications This work investigates the effect of the proposed IS-based approach in defending against pollution attacks. The results would be of interest for security specialists in deciding whether to implement such a mechanism for enhancing CIDNs. Originality/value The experimental results demonstrate that the proposed approach is more effective in decreasing the trust values of malicious nodes and reducing the impact of pollution attacks on the accuracy of alarm aggregation as compare to similar approaches.
Wenjuan Li 0001, Weizhi Meng 0001
Inf. Comput. Secur.2
2016 Evaluating the effect of multi-touch behaviours on Android unlock patterns
abstract
Purpose This paper aims to evaluate the effect of multi-touch behaviours on creating Android unlock patterns (AUPs) by realising that users can perform more actions in touch-enabled mobile phones. Design/methodology/approach The author conducted two user studies with a total of 45 participates and performed two major experiments in the main user study. Findings The user study indicates that the multi-touch behaviours can have a positive impact on creating patterns; however, there are only nine touchable points for the original AUPs, which may reduce the usability when performing a multi-touch movement. Research limitations/implications An even larger user study could be conducted to further analyse the patterns generated by users, that is, to analyse the specific password space by integrating the behaviours of multi-touch and to involve more types of multi-touch behaviours in creating an AUP. Practical implications This work explores the effect of multi-touch movement on creating AUPs. The results should be of interest for software developers and security researchers for exploring the effect of multi-touch behaviours on the creation of graphical passwords on mobile phones. Originality/value The author conducts two user studies with a total of 45 participants to investigate the impact of multi-touch behaviours on creating AUPs. In addition, to address the issue of usability, the author proposes two ways: increasing the number of touchable points and improve the rules of pattern creation.
Weizhi Meng 0001
Inf. Comput. Secur.1
2016 A survey on OpenFlow-based Software Defined Networks: Security challenges and countermeasures
Wenjuan Li 0001, Weizhi Meng 0001, Lam-for Kwok
J. Netw. Comput. Appl.2
2016 JuiceCaster: Towards automatic juice filming attacks on smartphones
Weizhi Meng 0001, Lee Wang Hao, Murali Srirangam Ramanujam, S. P. T. Krishnan
J. Netw. Comput. Appl.1
2015 An empirical study on email classification using supervised machine learning in real environments
abstract
Spam emails are considered as one of the biggest challenges for the Internet. Thus email classification, which aims to correctly classify legitimate and spam emails, becomes an important topic for both industry and academia. To achieve this goal, machine learning techniques, especially supervised machine learning algorithms, have been extensively applied to this field. In literature, several studies reveal that supervised machine learning (SML) suffers from some limitations such as performance fluctuation, hence many works start focusing on designing more complex algorithms. However, we identify that most existing research efforts are based on datasets, while more research should be conducted to investigate the performance of SML in real environments. In this paper, we thus perform an empirical study with three different environments and over 1,000 users regarding this issue. In the study, we find that SML classifiers like decision tree and SVMs are acceptable by users in real email classification. In addition, we discuss promising directions and provide new insights in this area.
Wenjuan Li 0001, Weizhi Meng 0001
ICC2
2015 RouteMap: A Route and Map Based Graphical Password Scheme for Better Multiple Password Memory
Weizhi Meng 0001
NSS1
2015 Design of intelligent KNN-based alarm filter using knowledge-based alert verification in intrusion detection
abstract
Abstract Network intrusion detection systems (NIDSs) have been widely deployed in various network environments to defend against different kinds of network attacks. However, a large number of alarms especially unwanted alarms such as false alarms and non‐critical alarms could be generated during the detection, which can greatly decrease the efficiency of the detection and increase the burden of analysis. To address this issue, we advocate that constructing an alarm filter in terms of expert knowledge is a promising solution. In this paper, we develop a method of knowledge‐based alert verification and design an intelligent alarm filter based on a multi‐classk‐nearest‐neighbor classifier to filter out unwanted alarms. In particular, the alarm filter employs a rating mechanism by means of expert knowledge to classify incoming alarms to proper clusters for labeling. We further analyze the effect of different classifier settings on classification accuracy with two alarm datasets. In the evaluation, we investigate the performance of the alarm filter with a real dataset and in a network environment, respectively. Experimental results indicate that our alarm filter can effectively filter out a number of NIDS alarms and can achieve a better outcome under the advanced mode. Copyright © 2015 John Wiley & Sons, Ltd.
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
Secur. Commun. Networks1
2014 Enhancing email classification using data reduction and disagreement-based semi-supervised learning
abstract
Email classification is an important topic in literature attempting to correctly classify user emails and filter out spam emails. In this paper, we identify some challenges regarding this topic and propose an effective email classification model based on both data reduction and disagreement-based semi-supervised learning. In particular, the main objective of the data reduction is to select an optimum collection of email features and reduce the pointless data, while the objective of the disagreement-based approach is to enhance the accuracy of detecting spam emails by utilizing unlabeled data automatically. In the evaluation, we explore the performance of our proposed email classification model using two public datasets and a private dataset. The experimental results demonstrate that our proposed model can overall enhance the performance of email classification through improving detection accuracy and reducing false rates.
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
ICC1
2014 An Evaluation of Single Character Frequency-Based Exclusive Signature Matching in Distinct IDS Environments
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
ISC1
2014 Towards Designing an Email Classification System Using Multi-view Based Semi-supervised Learning
abstract
The goal of email classification is to classify user emails into spam and legitimate ones. Many supervised learning algorithms have been invented in this domain to accomplish the task, and these algorithms require a large number of labeled training data. However, data labeling is a labor intensive task and requires in-depth domain knowledge. Thus, only a very small proportion of the data can be labeled in practice. This bottleneck greatly degrades the effectiveness of supervised email classification systems. In order to address this problem, in this work, we first identify some critical issues regarding supervised machine learning-based email classification. Then we propose an effective classification model based on multi-view disagreement-based semi-supervised learning. The motivation behind the attempt of using multi-view and semi-supervised learning is that multi-view can provide richer information for classification, which is often ignored by literature, and semi-supervised learning supplies with the capability of coping with labeled and unlabeled data. In the evaluation, we demonstrate that the multi-view data can improve the email classification than using a single view data, and that the proposed model working with our algorithm can achieve better performance as compared to the existing similar algorithms.
Wenjuan Li 0001, Weizhi Meng 0001, Zhiyuan Tan 0001, Yang Xiang 0001
TrustCom2
2014 Adaptive non-critical alarm reduction using hash-based contextual signatures in intrusion detection
Weizhi Meng 0001, Lam-for Kwok
Comput. Commun.1
2014 EFM: Enhancing the performance of signature-based network intrusion detection systems using enhanced filter mechanism
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
Comput. Secur.1
2014 The effect of adaptive mechanism on behavioural biometric based mobile phone authentication
abstract
Purpose – This paper aims to design a compact scheme of behavioural biometric-based user authentication, develop an adaptive mechanism that selects an appropriate classifier in an adaptive way and conduct a study to explore the effect of this mechanism. Design/methodology/approach – As a study, the proposed adaptive mechanism was implemented using a cost-based metric, which enables mobile phones to adopt a less costly classifier in an adaptive way to build the user normal-behaviour model and detect behavioural anomalies. Findings – The user study with 50 participants indicates that our proposed mechanism can positively affect the authentication performance by maintaining the authentication accuracy at a relatively high and stable level. Research limitations/implications – The authentication accuracy can be further improved by incorporating other appropriate classifiers (e.g. neural networks) and considering other touch-gesture-related features (e.g. the speed of a touch). Practical implications – This work explores the effect of adaptive mechanism on behavioural biometric-based user authentication. The results should be of interest for software developers and security specialists in deciding whether to implement such a mechanism for enhancing authentication performance on mobile phones. Originality/value – The user study with 50 participants indicates that this mechanism can positively affect the authentication performance by maintaining the authentication accuracy at a relatively high and stable level. To the best of our knowledge, our work is an early work discussing the implementation of an adaptive mechanism on a mobile phone.
Weizhi Meng 0001, Duncan S. Wong, Lam-for Kwok
Inf. Manag. Comput. Secur.1
2014 Adaptive blacklist-based packet filter with a statistic-based approach in network intrusion detection
Weizhi Meng 0001, Lam-for Kwok
J. Netw. Comput. Appl.1
2013 Improving the Performance of Neural Networks with Random Forest in Detecting Network Intrusions
Wenjuan Li 0001, Weizhi Meng 0001
ISNN (2)2
2013 Enhancing False Alarm Reduction Using Pool-Based Active Learning in Network Intrusion Detection
Weizhi Meng 0001, Lam-for Kwok
ISPEC1
2013 Evaluation of Detecting Malicious Nodes Using Bayesian Model in Wireless Intrusion Detection
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
NSS1
2013 Enhancing Click-Draw Based Graphical Passwords Using Multi-Touch on Mobile Phones
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
SEC1
2013 Towards adaptive character frequency-based exclusive signature matching scheme and its applications in distributed intrusion detection
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
Comput. Networks1
2012 Touch Gestures Based Biometric Authentication Scheme for Touchscreen Mobile Phones
Weizhi Meng 0001, Duncan S. Wong, Roman Schlegel, Lam-for Kwok
Inscrypt1
2012 Evaluating the Effect of Tolerance on Click-Draw Based Graphical Password Scheme
Weizhi Meng 0001, Wenjuan Li 0001
ICICS1
2012 Intelligent Alarm Filter Using Knowledge-Based Alert Verification in Network Intrusion Detection
Weizhi Meng 0001, Wenjuan Li 0001, Lam-for Kwok
ISMIS1
2012 Designing Click-Draw Based Graphical Password Scheme for Better Authentication
abstract
Nowadays, graphical password is being regarded as a promising alternative in network security to replace traditional text-based password in which users interact with images for authentication rather than input alphanumeric stings. In general, this image-based authentication can be classified into three categories: click-based graphical password, choice-based graphical password and draw-based graphical password. However, each of them suffers from several intrinsic limitations. In this paper, we propose and develop a click-draw based graphical password scheme (CD-GPS) with the purpose of improving the image-based authentication in both security and usability by combining the above three techniques. Specifically, our scheme mainly contains two operational steps: image selection and secret drawing. That is, users first choose an ordered sequence of images and then select some of them to click-draw their secrets. We present an initial user study which shows positive results that our scheme is good at both security and usability, and subsequently give a preliminary security analysis of our scheme against several well-known attacks (e.g., dictionary attack).
Weizhi Meng 0001
NAS1
2012 Enhancing List-Based Packet Filter Using IP Verification Mechanism against IP Spoofing Attack in Network Intrusion Detection
Weizhi Meng 0001, Lam-for Kwok
NSS1
2012 Towards Designing Packet Filter with a Trust-Based Approach Using Bayesian Inference in Network Intrusion Detection
Weizhi Meng 0001, Lam-for Kwok, Wenjuan Li 0001
SecureComm1
2012 Adaptive Character Frequency-Based Exclusive Signature Matching Scheme in Distributed Intrusion Detection Environment
abstract
Currently, signature-based network intrusion detection systems (NIDSs) are being widely deployed in distributed network environment with the purpose of protecting network communications from various attacks. However, signature matching has become a key limiting factor to restrict the performance of a signature-based NIDS in large-scale distributed network environment. The overhead network packets can greatly reduce the effectiveness of such detection systems and heavily consume computer resources. To mitigate this issue, a more efficient signature matching algorithm is desirable. In this paper, we therefore develop an adaptive character frequency-based exclusive signature matching scheme that can be implemented in a signature-based NIDS to help improve the performance of signature matching. In the experiment, we implemented our scheme in a distributed network environment and evaluated the performance of our scheme compared with Snort. The experimental results show that, in our distributed network environment, our scheme can positively reduce the time consumption in the range from 11.2% to 37.6%.
Weizhi Meng 0001, Wenjuan Li 0001
TrustCom1
2011 Adaptive context-aware packet filter scheme using statistic-based blacklist generation in network intrusion detection
abstract
By using string matching, signature-based network intrusion detection systems (NIDSs) can achieve a higher accuracy and lower false alarm rate than the anomaly-based systems. But the matching process is very expensive regarding to the performance of a signature-based NIDS in which the cost is at least linear to the size of the input string and the CPU occupancy rate can reach more than 80 percent in the worst case. This problem greatly limits the high performance of a signature-based NIDS in a large operational network. In this paper, we present a context-aware packet filter scheme aiming to mitigate this problem. In particular, our scheme incorporates a list technique, namely the blacklist to help filter network packets based on the confidence of the IP domains. Moreover, our scheme will adapt and update the blacklist contents by using the method of statistic-based blacklist generation according to the actual network environment. In the experiment, we implemented our scheme and showed the first experimental evaluation of its effectiveness.
Weizhi Meng 0001, Lam-for Kwok
IAS1