Xiaodan Gu

dblp:148/7260 · DBLP profile ↗
← Back
16ranked-venue papers
4as first author
10since 2021 · last 2026
0009-0001-0519-1358ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 6 · 1 first-author · 4 since 2021Computer networks · 4 · 4 since 2021Security and privacy · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Duplicate-Node Attack: Identifying Guards to Degrade and Triangulate Onion Services
Chunmian Wang, Xiaodan Gu
INFOCOM2
2026 Your Outer Appearance Mirrors Your Inner Self: Exploiting Unobservable Node Internals to Deanonymize Uploaders in Freenet
Yonghuan Xu, Ming Yang 0001, Shan Wang 0008, Xiaodan Gu, Zixia Liu, Zhen Ling 0001
INFOCOM4
2025 Do Not Trust What They Tell: Exposing Malicious Accomplices in Tor via Anomalous Circuit Detection
abstract
The Tor network, while offering anonymity through traffic routing across volunteer-operated nodes, remains vulnerable to attacks that aim to deanonymize users by correlating traffic patterns between colluded entry and exit nodes in circuits. This paper presents a novel approach for detecting anomalous circuits in the Tor network, and for the first time provides a more comprehensive identification of potential malicious accomplice nodes in Tor by taking roles of nodes in anomalous circuits into consideration. Our method strategically utilizes modified middle nodes to capture traffic data, followed by a novel circuit classification based on traffic patterns to pinpoint concerned circuits. Two kinds of anomalies are identified: routing anomalies and usage anomalies, that respectively represent the anomalies with explicit or implicit violation of Tor's circuit construction guidelines. This leads to a successful revealing of totally 1,960 anomalous nodes in Tor. Furthermore, we apply clustering analysis with considering corresponding anomalous circuits and other key characteristics to the detected anomalous nodes, revealing potential hidden organizations behind these nodes that can threaten the network's security. Our findings highlight the necessity for the Tor project to adopt targeted mitigation strategies to enhance overall network security and privacy.
Yixuan Yao, Ming Yang 0001, Zixia Liu, Kai Dong 0001, Xiaodan Gu, Chunmian Wang
WWW5
2024 A De-anonymization Attack against Downloaders in Freenet
abstract
Freenet is a well-known anonymous communication system that enables file sharing among users. It employs a probabilistic hops-to-live (HTL) decrement approach to hide the originator among nodes in a multi-hop path. Therefore, all nodes shall exhibit identical behaviors to preserve anonymity. However, we discover that the path folding mechanism in Freenet violates this principle due to behavior discrepancy between downloaders and intermediate nodes. The path folding mechanism is designed to optimize the network topology of Freenet. A delayed path folding message by a successor node may incur a timeout event at its predecessor, and an intermediate node reacts differently to such timeout with a downloader. Therefore, malicious nodes can deliberately trigger the timeout event to identify downloaders. The complex implementation of the path folding timeout detection mechanism in Freenet complicates our de-anonymization attack. We thoroughly analyze the underlying cause and develop three strategies to manipulate three types of messages respectively at the malicious node, minimizing the false positive rate. We conduct extensive real-world experiments to verify the feasibility and effectiveness of our attack. They show that our attack achieves a true positive rate of 100% and false positive rate of near 0% under two different Freenet download modes.
Yonghuan Xu, Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Xiaodan Gu
INFOCOM5
2023 Privacy Protection Based on Packet Filtering for Home Internet-of-Things
abstract
The development of home internet of things (H-IoT) devices brings convenience but poses significant privacy and security risks. Existing research minimizes data uploaded to the cloud but fails to process data locally, resulting in a trade-off between privacy and functionality. In this paper, we propose a privacy-preserving method that identifies and processes sensitive data sent from H-IoT devices at the edge side, ensuring functionality while preserving privacy. Our method applies different identification strategies to packets with different features, making it applicable to most H-IoT devices and scenarios. We validate our approach through experiments on a prototype system that monitors multiple cameras, demonstrating its effectiveness in preserving privacy while maintaining functionality.
Beibei Cheng, Xiaodan Gu, Kai Dong 0001
CSCWD4
2023 Evaluating the Distinguishability of Tor Traffic over Censorship Circumvention Tools
abstract
Previous research has shown that Tor traffic can be easily identified, making Tor connections frequently blocked. In order to access the Tor network successfully, some censorship circumvention tools such as Shadowsocks and OpenVPN are utilized as front-proxy to connect to Tor entry nodes. However, the distinguishability of Tor traffic over these censorship circumvention tools has not yet been fully evaluated. By analyzing the equal-size segmentation mechanism of Tor and the transmission mechanisms of circumvention tools, we find that the payload length distribution of Tor traffic encrypted and encapsulated through these tools displays a distinct pattern, which makes such Tor traffic retain distinguishable from regular encrypted traffic. To verify this finding, we develop an automated, large-scale Tor traffic collection system to capture Tor traffic forwarded by various circumvention tools, and then design corresponding algorithms to extract traffic features in terms of payload length distribution. Finally, we perform the evaluation on the distin-guishability between the captured Tor traffic and the normal non-Tor traffic through extracted features. The F1-Score can achieve 0.99 with the false positive rate close to 0 when using Support Vector Machines for training and classification. The experimental results prove that circumvention tools cannot mask the inherent features of Tor traffic, and thus the Tor traffic forwarded by these tools can still be clearly distinguished from normal non-Tor traffic.
Yafeng Song, Ming Yang 0001, Xiaodan Gu, Yixuan Yao
CSCWD4
2023 Lightweight Gesture Based Trigger-Action Programming for Home Internet-of-Things
abstract
IFTTT is one of the most popular Trigger-Action Programming platforms. The rules generated in IFTTT are named IoT Applets. Despite the powerful programming interface provided by IFTTT, establishing an Applet requires technical skills and is not convenient enough for most users. To address this problem, we propose a gesture based programming method to help end users establish and manage IoT Applets in a convenient way. It requires employment of an RGB-D camera, and recognizes users’ pointing rays and hand actions. The obtained information is interpreted to certain devices and device events for Applet management. An experiment involving 20 participants validates the performance of our proposed method.
Kai Dong 0001, Xiaodan Gu, Zhen Ling 0001, Ming Yang 0001
CSCWD3
2023 TorDNS: A Novel Correlated Onion Address Generation Approach and Application
abstract
The onion service is the most important mechanism of the Tor network which enables service providers to publish anonymously various TCP services, such as web services. To access the target onion services, clients first know the 56-byte onion addresses. However, randomly generated onion addresses are difficult to memorize and can be easily used by attackers to generate phishing sites with similar onion addresses. In this paper, we propose a correlated onion address generation approach which is capable of generating a unique onion address via a customized string and a root onion address. This approach enables the generated onion addresses to be computed by clients using a human-memorable string, resulting in easier access to onion services. Based on this approach, we design and implement a Tor Domain Name System (TorDNS) that allows different service providers to register anonymously and clients to access anonymous services quickly through human-memorable pseudo-onion addresses. TorDNS is compatible with existing onion service mechanism and does not introduce additional privacy and security issues. In addition, similarity detection of pseudo-onion addresses can effectively reduce the risk of phishing sites on the Tor network.
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Xiaodan Gu, Yu Yao 0008
CSCWD5
2023 A practical multi-tab website fingerprinting attack
Xiaodan Gu, Ming Yang 0001, Bingchen Song, Zhen Ling 0001
J. Inf. Secur. Appl.1
2022 Towards an Efficient Defense against Deep Learning based Website Fingerprinting
abstract
Website fingerprinting (WF) attacks allow an attacker to eavesdrop on the encrypted network traffic between a victim and an anonymous communication system so as to infer the real destination websites visited by a victim. Recently, the deep learning (DL) based WF attacks are proposed to extract high level features by DL algorithms to achieve better performance than that of the traditional WF attacks and defeat the existing defense techniques. To mitigate this issue, we propose a-genetic-programming-based variant cover traffic search technique to generate defense strategies for effectively injecting dummy Tor cells into the raw Tor traffic. We randomly perform mutation operations on labeled original traffic traces by injecting dummy Tor cells into the traces to derive variant cover traffic. A high level feature distance based fitness function is designed to improve the mutation rate to discover successful variant traffic traces that can fool the DL-based WF classifiers. Then the dummy Tor cell injection patterns in the successful variant traces are extracted as defense strategies that can be applied to the Tor traffic. Extensive experiments demonstrate that we can introduce 8.1% of bandwidth overhead to significantly decrease the accuracy rate below 0.4% in the realistic open-world setting.
Zhen Ling 0001, Gui Xiao, Wenjia Wu, Xiaodan Gu, Ming Yang 0001, Xinwen Fu
INFOCOM4
2020 A Novel IM Sync Message-Based Cross-Device Tracking
abstract
Cybercrime is significantly growing as the development of internet technology. To mitigate this issue, the law enforcement adopts network surveillance technology to track a suspect and derive the online profile. However, the traditional network surveillance using the single-device tracking method can only acquire part of a suspect’s online activities. With the emergence of different types of devices (e.g., personal computers, mobile phones, and smart wearable devices) in the mobile edge computing (MEC) environment, one suspect can employ multiple devices to launch a cybercrime. In this paper, we investigate a novel cross-device tracking approach which is able to correlate one suspect’s different devices so as to help the law enforcement monitor a suspect’s online activities more comprehensively. Our approach is based on the network traffic analysis of instant messaging (IM) applications, which are typical commercial service providers (CSPs) in the MEC environment. We notice a new habit of using IM applications, that is, one individual logs in the same account on multiple devices. This habit brings about devices’ receiving sync messages, which can be utilized to correlate devices. We choose five popular apps (i.e., WhatsApp, Facebook Messenger, WeChat, QQ, and Skype) to prove our approach’s effectiveness. The experimental results show that our approach can identify IM messages with high F1 -scores (e.g., QQ’s PC message is 0.966, and QQ’s phone message is 0.924) and achieve an average correlating accuracy of 89.58% of five apps in an 8-people experiment, with the fastest correlation speed achieved in 100 s.
Naixuan Guo, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Wenjia Wu, Xiaodan Gu
Secur. Commun. Networks6
2018 Fingerprinting Network Entities Based on Traffic Analysis in High-Speed Network Environment
abstract
For intrusion detection, it is increasingly important to detect the suspicious entities and potential threats. In this paper, we introduce the identification technologies of network entities to detect the potential intruders. However, traditional entities identification technologies based on the MAC address, IP address, or other explicit identifiers can be deactivated if the identifier is hidden or tampered. Meanwhile, the existing fingerprinting technology is also restricted by its limited performance and excessive time lapse. In order to realize entities identification in high-speed network environment, PFQ kernel module and Storm are used for high-speed packet capture and online traffic analysis, respectively. On this basis, a novel device fingerprinting technology based on runtime environment analysis is proposed, which employs logistic regression to implement online identification with a sliding window mechanism, reaching a recognition accuracy of 77.03% over a 60-minute period. In order to realize cross-device user identification, Web access records, domain names in DNS responses, and HTTP User-Agent information are extracted to constitute user behavioral fingerprints for online identification with Multinomial Naive Bayes model. When the minimum effective feature dimension is set to 9, it takes only 5 minutes to reach an accuracy of 79.51%. Performance test results show that the proposed methods can support over 10Gbps traffic capture and online analysis, and the system architecture is justified in practice because of its practicability and extensibility.
Xiaodan Gu, Ming Yang 0001, Peilong Pan, Zhen Ling 0001
Secur. Commun. Networks1
2017 A novel attack to track users based on the behavior patterns
abstract
Summary Currently, people around the world daily use the Internet to access various services, such as e‐mail and online shopping. However, the behavior‐based tracking attacks have posed a considerable threat to users' privacy. Relying on characteristic patterns within the Internet activities, this attack can link a user's multiple sessions. In this paper, we investigate the behavior‐based tracking attack and propose some countermeasures to mitigate the threat. We preprocess the raw traffic data and then extract features ranging from lower layer network packets to high‐level application‐related traffic. Specifically, we focus on four types of application‐level traffic to infer users' habits, including HTTP, IM, e‐mail, and P2P. In addition, we extract the web queries entered into shopping websites and classify them to infer users' preferences. Then, we construct the preference models and propose an improved method. For evaluation, we collect traffic in the real‐world environment to construct a large‐scale dataset. Five hundred and nine users are selected in terms of the user's active degree. When the term frequency–inverse document frequency transformation is used, the improved method can identify an average of 93.79% instances correctly. Our extensive empirical experiments demonstrate the effectiveness and efficiency of our approaches. Finally, we discuss and evaluate several countermeasures. Copyright © 2016 John Wiley & Sons, Ltd.
Xiaodan Gu, Ming Yang 0001, Congcong Shi, Zhen Ling 0001, Junzhou Luo
Concurr. Comput. Pract. Exp.1
2015 A novel Website Fingerprinting attack against multi-tab browsing behavior
abstract
Website Fingerprinting (WF) attacks have posed a serious threat to users' privacy, which allow an adversary to infer the anonymous communication content by using traffic analysis. Recent studies have demonstrated the effectiveness of WF attacks through a large number of experiments. However, some researchers believe that the assumptions of WF attacks vastly simplify the problem and are critical in the practical scenarios. In this paper, we assess the threat model of WF and relax the assumptions about browsing behavior to improve the practical feasibility. To deal with the multi-tab browsing scenario, we propose a novel WF attack and identify webpages respectively. The main idea resides in the fact that the user visits the second page with a short delay after opening the first page due to the think time. We analyze the anonymous traffic transmitted in the delay and select fine-grained features to identify the first page. Furthermore, we exclude the first page's traffic and utilize coarse features to identify the second page. We deploy our attack in real word environment and the experiment lasts for two months. The Naive Bayes classifier is then applied on the collected datasets to classify the visited websites among 50 top ranked websites in Alexa. When the delay is set to 2 seconds, our attack can classify the first page with 75.9% accuracy, and the second page is 40.5%. The results show that the WF attack is still effective in the practical scenarios and we can't dismiss WF as a threat.
Xiaodan Gu, Ming Yang 0001, Junzhou Luo
CSCWD1
2015 A novel application classification attack against Tor
abstract
Summary Tor is a famous anonymous communication system for preserving users' online privacy. It supports TCP applications and packs upper‐layer application data into encrypted equal‐sized cells with onion routing to hide private information of users. However, we note that the current Tor design cannot conceal certain application behaviors. For example, P2P applications usually upload and download files simultaneously, and this behavioral feature is also kept in Tor traffic. Motivated by this observation, we investigate a new attack against Tor, application classification attack, which can recognize application types from Tor traffic. An attacker first carefully selects some flow features such asburst volumesanddirectionsto represent the application behaviors and takes advantage of some efficient machine‐learning algorithm (e.g., Profile Hidden Markov Model) to model different types of applications. Then he or she can use these established models to classify target's Tor traffic and infer its application type. We have implemented the application classification attack on Tor using parallel computing, and our experiments validate the feasibility and effectiveness of the attack. We argue that the disclosure of application type information is a serious threat to Tor users' anonymity because it can be used to reduce the anonymity set and facilitate other attacks. We also present guidelines to defend against application classification attack. Copyright © 2015 John Wiley & Sons, Ltd.
Gaofeng He, Ming Yang 0001, Junzhou Luo, Xiaodan Gu
Concurr. Comput. Pract. Exp.4
2014 A novel active website fingerprinting attack against Tor anonymous system
abstract
Tor is a popular anonymizing network and the existing work shows that it can preserve users' privacy from website fingerprinting attacks well. However, based on our extensive analysis, we find it is the overlap of web objects in returned web pages that make the traffic features obfuscated, thus degrading the attack detection rate. In this paper, we propose a novel active website fingerprinting attack under Tor's local adversary model. The main idea resides in the fact that the attacker can delay HTTP requests originated from users for a certain period to isolate responding traffic segments containing different web objects. We deployed our attack in PlanetLab and the experiment lasted for one month. The SVM multi-classification algorithm was then applied on the collected datasets with the introduced features to identify the visited website among 100 top ranked websites in Alexa. Compared to the stat-of-the-art work, the classification result is improved from 48.5% to 65% by delaying at most 10 requests. We also analyzed the timing characteristics of Tor traffic to prove the stealth of our attack. The research results show that anonymity in Tor is not as strong as expected and should be enhanced in the future.
Gaofeng He, Ming Yang 0001, Xiaodan Gu, Junzhou Luo
CSCWD3