VLDB 2026 Research / reviewers in the wild / expert
Na Ruan
dblp:157/4391 · also Ruan Na
· DBLP profile ↗
51ranked-venue papers
8as first author
23since 2021 · last 2025
0000-0002-7673-9843ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 2 first-author · 12 since 2021Computer networks · 16 · 5 first-author · 4 since 2021Systems, architecture and hardware · 5 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PromFuzz: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart ContractsabstractSmart contracts are fundamental pillars of the blockchain, playing a crucial role in facilitating various business transactions. However, these smart contracts are vulnerable to exploitable bugs that can lead to substantial monetary losses. A recent study reveals that over 80% of these exploitable bugs, which are primarily functional bugs, can evade the detection of current tools. Automatically identifying functional bugs in smart contracts presents challenges from multiple perspectives. The primary issue is the significant gap between understanding the high-level logic of the business model and checking the low-level implementations in smart contracts. Furthermore, identifying deeply rooted functional bugs in smart contracts requires the automated generation of effective detection oracles based on various bug features.To address these challenges, we design and implement PromFuzz, an automated and scalable system to detect functional bugs in smart contracts. In PromFuzz, we first propose a novel Large Language Model (LLM)-driven analysis framework, which leverages a dual-agent prompt engineering strategy to pinpoint potentially vulnerable functions for further scrutiny. We then implement a dual-stage coupling approach, which focuses on generating invariant checkers that leverage logic information extracted from potentially vulnerable functions. Finally, we design a bug-oriented fuzzing engine, which maps the logical information from the high-level business model to the low-level smart contract implementations, and performs the bug-oriented fuzzing on targeted functions. We evaluate PromFuzz from 4 perspectives on 5 ground-truth datasets and compare it with multiple state-of-the-art methods. The results show that PromFuzz achieves 86.96% recall and 93.02% F1-score in detecting functional bugs, marking at least a 50% improvement in both metrics over state-of-the-art methods. Moreover, we perform an in-depth analysis on 10 real-world DeFi projects and detect 30 zero-day bugs. Our further case studies, the risky first deposit bug and the AMM price oracle manipulation bug on real-world DeFi projects, demonstrate the serious risks of the exploitable functional bugs in smart contracts. Up to now, 24 zero-day bugs have been assigned CVE IDs. Our discoveries have safeguarded assets totaling $18.2 billion from potential monetary losses. Xingshuang Lin, Qinge Xie, Yuan Tian 0001, Saman A. Zonouz, Na Ruan, Raheem A. Beyah, Shouling Ji |
ASE | 6 |
| 2025 | AdvPurge: A Robust Personalized Federated Learning Framework Against Backdoor Attack
Tu Huang, Na Ruan |
ProvSec | 2 |
| 2025 | Pretender: Universal Active Defense against Diffusion Finetuning Attacks
Zekun Sun, Shouling Ji, Chenhao Lin, Na Ruan |
USENIX Security Symposium | 5 |
| 2025 | PRRQ: Privacy-Preserving Resilient RkNN Query Over Encrypted Outsourced Multiattribute DataabstractTraditional reverse k-nearest neighbor (RkNN) query schemes typically assume that users are available online in real-time for interactive key reception, overlooking scenarios where users might be offline. Moreover, existing privacy-preserving RkNN query schemes primarily focus on user features or spatial data, neglecting the significance of user reputation values. To address these limitations, we propose a privacy-preserving resilient RkNN query scheme over encrypted outsourced multi-attribute data (PRRQ). Specifically, to mitigate the challenges posed by resilient online presence (i.e., non-real-time online) of users for interactive key reception, we incorporate a non-interactive key exchange (NIKE) protocol and the Diffie-Hellman two-party key exchange algorithm to propose a multi-party NIKE algorithm (2K-NIKE), facilitating non-interactive key reception for multiple users. Considering the privacy leakage issues, PRRQ encodes original multi-attribute data (i.e., spatial, feature, and reputation values) alongside query requests based on formalized criteria. Additionally, we integrate the proposed 2K-NIKE and the improved symmetric homomorphic encryption (iSHE) algorithms to encrypt them. Furthermore, catering to the requirements of ciphertext-based RkNN queries, we propose a private RkNN query eligibility-checking (PREC) algorithm and a private reputation-verifying (PRRV) algorithm, which validate the compliance of encrypted outsourced multi-attribute data with query requests. Security analysis demonstrates that PRRQ achieves simulation-based security under anhonest-but-curiousmodel. Experimental results show that PRRQ offers superior computational efficiency compared to comparative schemes. Jing Wang 0239, Haiyong Bao, Na Ruan, Qinglei Kong, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Computers | 3 |
| 2025 | MKAC: Efficient and Privacy-Preserving Multi- Keyword Ranked Query With Ciphertext Access Control in Cloud EnvironmentsabstractWith the explosion of big data in cloud environments, data owners tend to delegate the storage and computation to cloud servers. Since cloud servers are generally untrustworthy, data owners often encrypt data before outsourcing it to the cloud. Numerous privacy-preserving schemes for the multi-keyword ranked query have been proposed, but most of these schemes do not support ciphertext access control, which can easily lead to malicious access by unauthorized users, causing serious damage to personal privacy and commercial secrets. To address the above challenges, we propose an efficient and privacy-preserving multi-keyword ranked query scheme (MKAC) that supports ciphertext access control. Specifically, in order to enhance the efficiency of the multi-keyword ranked query, we employ a vantage point (VP) tree to organize the keyword index. Additionally, we develop a VP tree-based multi-keyword ranked query algorithm, which utilizes the pruning strategy to minimize the number of nodes to search. Next, we propose a privacy-preserving multi-keyword ranked query scheme that combines asymmetric scalar-product-preserving encryption with the VP tree. Furthermore, attribute-based encryption mechanism is used to generate the decryption key based on the query user's attributes, which is then employed to decrypt the query results and trace any malicious query user who may leak the secret key. Finally, a rigorous analysis of the security of MKAC is conducted. The extensive experimental evaluation shows that the proposed scheme is efficient and practical. Haiyong Bao, Menghong Guan, Na Ruan, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Cloud Comput. | 5 |
| 2025 | Temporal Gradient Inversion Attacks With Robust OptimizationabstractFederated Learning (FL) has emerged as a promising approach for collaborative model training without sharing private data. However, privacy concerns regarding information exchanged during FL have received significant research attention.Gradient Inversion Attacks (GIAs)have been proposed to reconstruct the private data retained by local clients from the exchanged gradients. While recovering private data, the data dimensions and the model complexity increase, which thwart data reconstruction by GIAs. Existing methods adopt prior knowledge about private data to overcome those challenges. In this article, we first observe that GIAs with gradients from a single iteration fail to reconstruct private data due to insufficient dimensions of leaked gradients, complex model architectures, and invalid gradient information. We investigate a Temporal Gradient Inversion Attack with a Robust Optimization framework, called TGIAs-RO, which recovers private data without any prior knowledge by leveraging multiple temporal gradients. To eliminate the negative impacts of outliers, e.g., invalid gradients for collaborative optimization, robust statistics are proposed. Theoretical guarantees on the recovery performance and robustness of TGIAs-RO against invalid gradients are also provided. Extensive empirical results on MNIST, CIFAR10, ImageNet and Reuters 21578 datasets show that the proposed TGIAs-RO with 10 temporal gradients improves reconstruction performance compared to state-of-the-art methods, even for large batch sizes (up to 128), complex models like ResNet18, and large datasets like ImageNet (224× 224pixels). Furthermore, the proposed attack method inspires further exploration of privacy-preserving methods in the context of FL. Bowen Li 0013, Hanlin Gu, Ruoxin Chen, Jie Li 0002, Chentao Wu, Na Ruan, Xueming Si, Lixin Fan |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Privacy for Free: Spy Attack in Vertical Federated Learning by Both Active and Passive PartiesabstractVertical federated learning (VFL) is an emerging paradigm well-suitable for commercial collaborations among companies. These companies share a common user base but possess distinct features. VFL enables the training of a shared global model with features from different parties while maintaining the confidentiality of raw data. Despite its potential, the VFL mechanism still lacks certified integrity, posing a notable threat of potential commercial deception or privacy infringement. In this study, we introduce a novel form of attack in which the attacker can participate in VFL by free-riding on the collaborative process while surreptitiously extracting users’ private data. This attack, reminiscent of corporate espionage tactics, is called the “spy attack”. Specifically, spy attacks allow a dishonest party without sufficient data to hitch a ride by inferring the missing user features through the shared information from other participants. We design two types of spy attacks tailored for scenarios where the attacker either takes an active or passive role. Evaluations with four real-world datasets demonstrate the effectiveness of our attacks, not only fulfilling the stipulated collaboration through hitchhiking, but also successfully stealing users’ privacy. Even when the missing rate reaches 90%, the spy attack continues to yield a test accuracy that surpasses the model trained with non-missing data and achieves reconstruction results approaching the theoretically highest quality. Furthermore, we meticulously discuss and evaluate up to seven possible defense strategies. The findings underscore the necessity for designing more effective and efficient defense strategies to counteract spy attacks. Chaohao Fu, Na Ruan |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | The Halt Game: Sometimes Rewards Cannot Cover Expenses in the PoW-Based BlockchainabstractProof-of-work (PoW) blockchain relies on incentive mechanisms to ensure the security and correctness of its underlying consensus protocol. Most research about it, based on a static model only considering coin-base rewards and transaction fee rewards, fails to accurately describe the complex real-world blockchain ecosystem. We propose a generic selfish mining attack applicable to arbitrary PoW blockchain systems and introduce a dynamic PoW blockchain incentive model. This model takes into account static basic rewards, dynamic whale rewards related to network protocol, and expenditures tied to players’ strategies. Unlike traditional incentive models that assume players continuously mine by default, we find players prefer to halt mining at the beginning of each mining cycle to reduce operational expenses and then resume mining at an appropriate time to enhance their rewards. We further prove players’ optimal strategy exists and it is determined by reward parameters. We implement a modified PoW blockchain system simulator and comprehensively validate these results using 256 full nodes in it of three mainstream PoW blockchains: Bitcoin, Ethereum 1.x, and Bitcoin Cash. We finally discuss the impact of different parameters on the security of PoW blockchain systems and propose practical mitigating measures for the mining halt. Huan Yan 0001, Na Ruan, Jianhua Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | DDL: Effective and Comprehensible Interpretation Framework for Diverse Deepfake DetectorsabstractIn the context of escalating advancements in AI generative technologies, Deepfakes, the sophisticated face forgeries created using deep learning methods, have emerged as a significant security threat. The predominant countermeasures are Deepfake detectors based on deep learning (DL). However, due to the opaque nature of DL-model, they struggle to offer understandable explanations for their predictive decisions, which undermines their reliability and effectiveness in real-world applications. Existing mainstream DL-oriented interpretation approaches, the feature attribution methods, struggle to work on Deepfake detectors due to issues of low interpretation fidelity, poor intelligibility, and limited applicability across different types of detectors. This paper addresses these critical challenges by proposing the Deepfake Detector Lens (DDL), a novel framework designed to enhance the interpretability of diverse architectural Deepfake detectors, encompassing those based on image, frequency domain, and video.DDLemploys a heuristic algorithm to enhance interpretation efficacy and incorporates image segmentation and face parsing techniques to bridge the gap between the machine-generated interpretation saliency map and human understanding. Comprehensive evaluations ofDDLdemonstrate its superiority over existing feature attribution methods in terms of fidelity, intelligibility, and applicability. The proposedDDLsignificantly advances the interpretability of Deepfake detection technology, offering a more reliable and understandable tool for combating AI-generated face forgeries. Zekun Sun, Na Ruan, Jianhua Li 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | GANK: Dynamic Geometric and Appearance Features for Efficient and Robust Detection of Face ForgeryabstractDeepfakes refers to various deep-learning-based techniques that manipulate the face in videos. Maliciously manufactured face forgeries could result in serious problems such as portrait infringement, information confusion, or even public panic. Previous countermeasures focused mainly on promoting detection accuracy while relatively overlooking robustness and computational overhead. In this work, we propose an efficient and robust framework named GANK , which discriminates Deepfake videos through temporal modeling on decoupled geometric and appearance features. A temporal denoising technique featuring landmark tracking and Kalman filtering is introduced to optimize the feature sequences, and multi-stream Recurrent Neural Networks (RNN) are constructed for sufficient exploitation of dynamic features. Besides, we introduce two optimizations to alleviate overfitting and enhance the utilization of temporal information, including channel-wise dropout and temporal random cropping. Our framework achieves outstanding robustness using very lightweight network backbones, reaching state-of-the-art performance on multiple benchmarks. Zekun Sun, Na Ruan |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2024 | FXChain: A Multi-consortium Permissioned Blockchain with Flexible Privacy-Preserving Strategies
Zenan Lou, Na Ruan |
ACISP (3) | 2 |
| 2024 | XSema: A Novel Framework for Semantic Extraction of Cross-chain TransactionsabstractAs the number of blockchain platforms continues to grow, the independence of these networks poses challenges for transferring assets and information across chains. Cross-chain bridge technology has emerged to address this issue, establishing communication protocols to facilitate cross-chain interaction of assets and information, thereby enhancing user experience. However, the complexity of cross-chain transactions increases the difficulty of security regulation, rendering traditional single-chain detection methods inadequate for cross-chain scenarios. Therefore, understanding cross-chain transaction semantics is crucial, as it forms the foundation for cross-chain security detection tasks. Although there are existing methods for extracting transaction semantics specifically for single chains, these approaches often overlook the unique characteristics of cross-chain scenarios, limiting their applicability. This paper introduces XSema, a novel cross-chain semantic extraction framework grounded in asset transfer and message-passing, designed specifically for cross-chain contexts. Experimental results demonstrate that XSema effectively distinguishes between cross-chain and non-cross-chain transactions, surpassing existing methods by over 9% for the generality metric and over 10% for the generalization metric. Furthermore, we analyze the underlying asset transfer patterns and message-passing event logs associated with cross-chain transactions. We offer new insights into the coexistence of multiple blockchains and the cross-chain ecosystem. Ziye Zheng, Jiajing Wu, Dan Lin 0007, Quanzhong Li 0001, Na Ruan |
HPCC | 5 |
| 2024 | Client-Free Federated Unlearning via Training Reconstruction with Anchor Subspace CalibrationabstractFederated learning (FL) model usually needs to forget what it has learned from a certain client for various considerations, which gives birth to the federated unlearning (FU) technique. Due to the distributed nature of FL, removing a specific client’s contribution from the global model potentially requires the cooperation of all participants, making FU difficult to apply in real-world scenarios. This paper proposes a simple-yet-effective client-free FU algorithm that runs solely on the central server. The algorithm utilizes the cached historical updates of the initial training from clients to rebuild the training after excluding the target client. To circumvent the issue of adaptivity, which is the key challenge for training reconstruction, we leverage the low-dimensional structure of gradient space in deep networks. Specifically, we propose to project the historical gradients to a low-dimensional subspace, which is given by the top gradient eigenspace on a small public dataset. According to experiments on three canonical datasets, our method achieves efficient unlearning while also preserving a high-level model utility. Chaohao Fu, Weijia Jia 0001, Na Ruan |
ICASSP | 3 |
| 2024 | From the Perspective of Prototypes: A Privacy-Preserving Personalized Federated Learning Framework
Na Ruan |
ISPEC | 3 |
| 2024 | Preserving Individual User's Right to Be Forgotten in Enterprise-Level Federated Learning
Chaohao Fu, Na Ruan |
PRICAI (2) | 3 |
| 2024 | Fool Attackers by Imperceptible Noise: A Privacy-Preserving Adversarial Representation Mechanism for Collaborative LearningabstractThe performance of deep learning models highly depends on the amount of training data. It is common practice for today's data holders to merge their datasets and train models collaboratively, which yet poses a threat to data privacy. Different from existing methods such as secure multi-party computation (MPC) and federated learning (FL), we find representation learning has unique advantages in collaborative learning due to its low privacy budget, wide applicability to tasks and lower communication overhead. However, data representations face the threat of model inversion attacks. In this article, we formally define the collaborative learning scenario, and present ARS (for adversarial representation sharing), a collaborative learning framework wherein users share representations of data to train models, and add imperceptible adversarial noise to data representations against reconstruction or attribute extraction attacks. By theoretical analysis and evaluating ARS in different contexts, we demonstrate that our mechanism is effective against model inversion attacks, and can achieve great utility and low communication complexity while preserving data privacy. Moreover, the ARS framework has wide applicability, which can be easily extended to the vertical data partitioning scenario and utilized in different tasks. Na Ruan, Jikun Chen, Tu Huang, Zekun Sun, Jie Li 0002 |
IEEE Trans. Mob. Comput. | 1 |
| 2023 | Steal from Collaboration: Spy Attack by a Dishonest Party in Vertical Federated Learning
Chaohao Fu, Na Ruan |
ACNS (1) | 3 |
| 2023 | Deep multi-locality convolutional neural network for DDoS detection in smart home IoTabstractInternet of things (IoT) devices usually offer limited resources such as processing, memory, and network capacity, bringing more security threats to the environment. Distributed denial of service (DDoS) signal attacks are among the most serious threats. Software-defined networking (SDN) is a promising paradigm that could offer a scalable security solution optimised for the IoT ecosystem. However, investigating a robust security solution is still one of the most challenging problems that a smart home environment faces in SDN. In this paper, we introduce a multi-locality deep learning model for the detection of DDoS signals in an SDN-based smart home. It employs convolutional neural networks (CNNs) by learning different levels of local information from the data. In this work, an ensemble of two CNNs to detect malicious traffic flows with low computation overhead framework is proposed. Experimental results demonstrate the robustness, effectiveness, and efficiency of our solution in detecting DDoS attacks in SDN smart home. Mohammed Almehdhar, Mohammed M. Abdelsamea, Na Ruan |
Int. J. Inf. Comput. Secur. | 3 |
| 2023 | A General Quantitative Analysis Framework for Attacks in BlockchainabstractDecentralized cryptocurrency systems have become primary targets for attackers due to substantial profit gain and economic rewards. A number of attack models have been proposed during last few years. However, the evaluation and comparison of those attack models remain problematic due to the lack of systematic framework to analyze them. In this work, we propose a general quantitative analysis framework for attack models in the network and consensus layer of blockchain. We identify the problem statement and evolution process. And we show how to apply our general framework in previous attacks such as selfish mining and bribery attack. We also explained that the framework is suitable for other attacks in blockchain. For further exploration, we simulate the success rate and benefits of different attacks through experiments. We provide several defensive strategies, and study how these strategies against previous attack models. Na Ruan, Hanyi Sun, Zenan Lou, Jie Li 0002 |
IEEE/ACM Trans. Netw. | 1 |
| 2022 | Secure Collaboration Between Consortiums in Permissioned Blockchains
Juzheng Huang, Qiang Tang 0005, Chunhua Su, Na Ruan |
ProvSec | 4 |
| 2021 | ALRS: An Adversarial Noise Based Privacy-Preserving Data Sharing Mechanism
Jikun Chen, Ruoyu Deng, Na Ruan, Yao Liu 0007, Chunhua Su |
ACISP | 4 |
| 2021 | Improving the Efficiency and Robustness of Deepfakes Detection Through Precise Geometric FeaturesabstractDeepfakes is a branch of malicious techniques that transplant a target face to the original one in videos, resulting in serious problems such as infringement of copyright, confusion of information, or even public panic. Previous efforts for Deepfakes videos detection mainly focused on appearance features, which have a risk of being bypassed by sophisticated manipulation, also resulting high model complexity and sensitiveness to noise. Besides, how to mine the temporal features of manipulated videos and exploit them is still an open question. We propose an efficient and robust framework named LRNet for detecting Deepfakes videos through temporal modeling on precise geometric features. A novel calibration module is devised to enhance the precision of geometric features, making it more discriminative, and a two-stream Recurrent Neural Network (RNN) is constructed for sufficient exploitation of temporal features. Compared to previous methods, our proposed method is lighter-weighted and easier to train. Moreover, our method has shown robustness in detecting highly compressed or noise corrupted videos. Our model achieved 0.999 AUC on FaceForensics+ + dataset. Meanwhile, it has a graceful decline in performance (-0.042 AUC) when faced with highly compressed videos.1 Zekun Sun, Yujie Han, Zeyu Hua, Na Ruan, Weijia Jia 0001 |
CVPR | 4 |
| 2021 | MSOM: Efficient Mechanism for Defense against DDoS Attacks in VANETabstractThe wireless nature of the Vehicular Ad Hoc Network (VANET), a technology that offers facilities such as traffic management and safety services, makes it vulnerable to distributed denial‐of‐service (DDoS) attacks that exploit network communications and reduce network reliability and performance. This paper proposes a design of a secure VANET architecture using a Software‐Defined Networking (SDN) controller and Neural Network Self‐Organizing Maps (SOMs). In the proposed design, we adopt the SDN architecture by using its separation of the control plane from the data plane and adding intelligent capabilities to the VANET. To resolve the drawbacks of standard SOMs and to enhance the SOM’s efficiency, a Multilayer Distributed SOM (MSOM) model based on two levels of clustering and classification is used. Experimental results show that our solution can efficiently detect malicious traffic, prevent and mitigate DDoS attacks, and increase system security and recovery speed from the attacking traffic. Moreover, the proposed scheme achieves a high accuracy rate (99.67%). Simulation results demonstrate the effectiveness and efficiency of the MSOM regarding detection accuracy and other studied metrics. Mohammed Al-Mehdhara, Na Ruan |
Wirel. Commun. Mob. Comput. | 2 |
| 2020 | Rational Manager in Bitcoin Mining Pool: Dynamic Strategies to Gain Extra RewardsabstractParticipants of the Bitcoin system form mining pools, which have become the leading institutions of the Bitcoin mining economy, to smooth their reward of mining. Many attacks towards mining pools have been proposed. Block Withholding attack is an attacker splitting some of the power to mine in a pool, submitting shares while withholding blocks, which is one of the most famous and original attacks. Few pieces of research pay attention to the case that managers work rationally to gain extra rewards themselves at the same time of countering withholding attack. However, some different reward functions have been proposed to avoid rational miners' withholding. In this paper, we offer a model that a rational manager gain extra rewards and incentivize miners not to withhold blocks by applying a dynamic mining strategy. We conduct quantitive analysis and simulations to verify the availability and effectiveness of our attacks. We show the attack benefits the miners in the pool in some circumstances, and further discuss improvement for our attack. Feifan Yu, Na Ruan, Siyuan Cheng 0006 |
AsiaCCS | 2 |
| 2020 | How to Model the Bribery Attack: A Practical Quantification Method in Blockchain
Hanyi Sun, Na Ruan, Chunhua Su |
ESORICS (2) | 2 |
| 2020 | GADM: Manual fake review detection for O2O commercial platforms
Na Ruan, Ruoyu Deng, Chunhua Su |
Comput. Secur. | 1 |
| 2020 | WiFind: Driver Fatigue Detection with Fine-Grained Wi-Fi Signal FeaturesabstractDriver fatigue is a leading factor in road accidents that can cause severe fatalities. Existing fatigue detection works focus on vision and electroencephalography (EEG) based means of detection. However, vision-based approaches suffer from view-blocking or vision distortion problems and EEG-based systems are intrusive, and the drivers have to use/wear the devices with inconvenience or additional costs. In our work, we propose a novel Wi-Fi signals based fatigue detection approach, called WiFind to overcome the drawbacks as associated with the current works. WiFind is simple and (wearable) device-free. It can detect the fatigue symptoms in the vehicle without relying on any visual image or video. By applying self-adaptive method, it can recognize the body features of drivers in multiple modes. It applies Hilbert-Huang transform (HHT) based pattern extract method results in accuracy increase in motion detection mode. WiFind can be easily deployed in a commodity Wi-Fi infrastructure, and we have evaluated its performance in real driving environments. The experimental results have shown that WiFind can achieve the recognition accuracy of 89.6 percent in a single driver scenario. Weijia Jia 0001, Hongjian Peng, Na Ruan, Zhiqing Tang, Wei Zhao 0001 |
IEEE Trans. Big Data | 3 |
| 2020 | Revealing Your Mobile Password via WiFi Signals: Attacks and CountermeasuresabstractIn this study, we present WindTalker, a novel and practical keystroke inference framework that can be used to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from an observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). An attacker can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's password input. Compared with the previous keystroke inference approaches, WindTalker neither deploys external equipment physically close to the target device nor compromises the target device. Instead, it employs a more practical setting by deploying a free public WiFi hotspot and collects the CSI data from the target device as long as the device is connected to the hotspot. In addition, to improve inference accuracy and efficiency, it analyzes the WiFi traffic to selectively collect CSI only for the sensitive period where password entering occurs. WindTalker can be implemented without the requirement of visually seeing the target device, or installing any malware on the device. We tested Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. Furthermore, we proposed a novel CSI obfuscation countermeasure to thwart the inference attack. The evaluation results show that the performance of WindTalker can be dramatically reduced by adopting the proposed countermeasures. Yan Meng 0001, Jinlei Li, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan |
IEEE Trans. Mob. Comput. | 6 |
| 2020 | Ursa: Robust Performance for Nakamoto Consensus with Self-adaptive ThroughputabstractWith the increasing number of users in blockchain-based cryptocurrencies, the public has raised the demand for transaction throughput, and many protocols are designed to improve the throughput following the Nakamoto consensus. Although astonishing progress has been made in the on-chain throughput improvement, high throughput makes the blockchains suffer from the increasing blockchain size, hard forks, and possible attacks. In this work, we propose a quantitative model to describe and analyze the Nakamoto consensus. We then design a robust scheme named Ursa to reduce storage requirements and to reduce the forks by automatically adjusting block size according to users’ needs. Na Ruan, Dongli Zhou, Weijia Jia 0001 |
ACM Trans. Internet Techn. | 1 |
| 2019 | FraudJudger: Fraud Detection on Digital Payment Platforms with Fewer Labels
Ruoyu Deng, Na Ruan |
ICICS | 2 |
| 2019 | Ethereum Analysis via Node Clustering
Hanyi Sun, Na Ruan |
NSS | 2 |
| 2019 | Time-Sync Video Tag Extraction Using Semantic Association GraphabstractTime-sync comments (TSCs) reveal a new way of extracting the online video tags. However, such TSCs have lots of noises due to users’ diverse comments, introducing great challenges for accurate and fast video tag extractions. In this article, we propose an unsupervised video tag extraction algorithm named Semantic Weight-Inverse Document Frequency (SW-IDF). Specifically, we first generate corresponding semantic association graph (SAG) using semantic similarities and timestamps of the TSCs. Second, we propose two graph cluster algorithms, i.e., dialogue-based algorithm and topic center-based algorithm, to deal with the videos with different density of comments. Third, we design a graph iteration algorithm to assign the weight to each comment based on the degrees of the clustered subgraphs, which can differentiate the meaningful comments from the noises. Finally, we gain the weight of each word by combining Semantic Weight (SW) and Inverse Document Frequency (IDF). In this way, the video tags are extracted automatically in an unsupervised way. Extensive experiments have shown that SW-IDF (dialogue-based algorithm) achieves 0.4210 F1-score and 0.4932 MAP (Mean Average Precision) in high-density comments, 0.4267 F1-score and 0.3623 MAP in low-density comments; while SW-IDF (topic center-based algorithm) achieves 0.4444 F1-score and 0.5122 MAP in high-density comments, 0.4207 F1-score and 0.3522 MAP in low-density comments. It has a better performance than the state-of-the-art unsupervised algorithms in both F1-score and MAP. Wenmian Yang, Kun Wang 0005, Na Ruan, Wenyuan Gao, Weijia Jia 0001, Wei Zhao 0001, Yunyong Zhang |
ACM Trans. Knowl. Discov. Data | 3 |
| 2018 | On the Strategy and Behavior of Bitcoin Mining with N-attackersabstractSelfish mining is a well-known mining attack strategy discovered by Eyal and Sirer in 2014. After that, the attackers' strategy has been further discussed by many other works, which analyze the strategy and behavior of a single attacker. The extension of the strategy research is greatly restricted by the assumption that there is only one attacker in the blockchain network, since, in many cases, a proof of work blockchain has multiple attackers. The attackers can be independent of others instead of sharing information and attacking the blockchain as a whole. In this paper, we will establish a new model to analyze the miners' behavior in a proof of work blockchain with multiple attackers. Based on our model, we extend the attackers' strategy by proposing a new strategy set publish-n. Meanwhile, we will also review other attacking strategies such as selfish mining and stubborn mining in our model to explore whether these strategies work or not when there are multiple attackers. The performances of different strategies are compared using relative stale block rate of the attackers. In a proof of work blockchain model with two attackers, strategy publish-n can beat selfish mining by up to 26.3%. Na Ruan, Rongtian Du, Weijia Jia 0001 |
AsiaCCS | 2 |
| 2018 | SpamTracer: Manual Fake Review Detection for O2O Commercial Platforms by Using Geolocation Features
Ruoyu Deng, Na Ruan, Ruidong Jin, Weijia Jia 0001, Chunhua Su, Dandan Xu |
Inscrypt | 2 |
| 2017 | Crowdsourced time-sync video tagging using semantic association graphabstractTime-sync comments reveal a new way of extracting the online video tags. However, such time-sync comments have lots of noises due to users' diverse comments, introducing great challenges for accurate and fast video tag extractions. In this paper, we propose an unsupervised video tag extraction algorithm named Semantic Weight-Inverse Document Frequency (SW-IDF). SW-IDF first generates corresponding semantic association graph (SAG) using semantic similarities and timestamps of the time-sync comments. Then it clusters the comments into sub-graphs of different topics and assigns weight to each comment based on SAG. This can clearly differentiate the meaningful comments with the noises. In this way, the noises can be identified, and effectively eliminated. Extensive experiments have shown that SW-IDF can achieve 0.3045 precision and 0.6530 recall in high-density comments; 0.3800 precision and 0.4460 recall in low-density comments. It is the best performance among the existing unsupervised algorithms. Wenmian Yang, Na Ruan, Wenyuan Gao, Kun Wang 0005, Wensheng Ran, Weijia Jia 0001 |
ICME | 2 |
| 2017 | Privacy-Preserving Fraud Detection via Cooperative Mobile Carriers with Improved AccuracyabstractWith the explosive growth of users in mobile carrier, telecommunication fraud causes a serious loss to both of the users and carriers. The academia has an increasing interest in the issue of detecting and recognizing fraudster, and varies strategies have been proposed to prevent the attack and fraudulent activity. However, fraudsters are always inclined to hide their identity and perform the fraudulent activity through different mobile carriers, which makes the previous methods less effective in fraud detection. In this paper, we propose a novel strategy with a high accuracy and security through the cooperation among mobile carriers. We introduce the Latent Dirichlet Allocation (LDA) model to profile users in different carriers. In order to match the fraud accounts, we propose a strategy based on Maximum Mean Discrepancy (MMD) to analyze and compare the distribution of statistical samples. Meantime, during the cooperation of carriers, there is a risk of privacy disclosure. To deal with this weakness, we also demonstrate that our method can detect the fraudulent accounts without leaking the private records and data of user accounts based on the differential privacy. Wenyan Yao, Na Ruan, Feifan Yu, Weijia Jia 0001, Haojin Zhu |
SECON | 2 |
| 2017 | Detect SIP Flooding Attacks in VoLTE by Utilizing and Compressing Counting Bloom Filter
Na Ruan, Shiheng Ma, Haojin Zhu, Weijia Jia 0001, Qingshui Xue |
WASA | 2 |
| 2017 | SPFM: Scalable and Privacy-Preserving Friend Matching in Mobile CloudabstractProfile (e.g., contact list, interest, and mobility) matching is more than important for fostering the wide use of mobile social networks. The social networks such as Facebook, Line, or WeChat recommend the friends for the users based on users personal data such as common contact list or mobility traces. However, outsourcing users' personal information to the cloud for friend matching will raise a serious privacy concern due to the potential risk of data abusing. In this paper, we propose a novel scalable and privacy-preserving friend matching (SPFM) protocol, which aims to provide a scalable friend matching and recommendation solutions without revealing the users personal data to the cloud. Different from the previous works which involves multiple rounds of protocols, SPFM presents a scalable solution which can prevent honest-but-curious mobile cloud from obtaining the original data and support the friend matching of multiple users simultaneously. We give detailed feasibility and security analysis on SPFM and its accuracy and security have been well demonstrated via extensive simulations. The result show that our scheme works even better when original data is large. Mengyuan Li 0004, Na Ruan, Qiyang Qian, Haojin Zhu, Xiaohui Liang 0002, Le Yu 0002 |
IEEE Internet Things J. | 2 |
| 2017 | A novel broadcast authentication protocol for internet of vehicles
Na Ruan, Mengyuan Li 0004, Jie Li 0002 |
Peer-to-Peer Netw. Appl. | 1 |
| 2017 | Privacy-Preserving Selective Aggregation of Online User Behavior DataabstractTons of online user behavior data are being generated every day on the booming and ubiquitous Internet. Growing efforts have been devoted to mining the abundant behavior data to extract valuable information for research purposes or business interests. However, online users' privacy is thus under the risk of being exposed to third-parties. The last decade has witnessed a body of research works trying to perform data aggregation in a privacy-preserving way. Most of existing methods guarantee strong privacy protection yet at the cost of very limited aggregation operations, such as allowing only summation, which hardly satisfies the need of behavior analysis. In this paper, we propose a scheme PPSA, which encrypts users' sensitive data to prevent privacy disclosure from both outside analysts and the aggregation service provider, and fully supports selective aggregate functions for online user behavior analysis while guaranteeing differential privacy. We have implemented our method and evaluated its performance using a trace-driven evaluation based on a real online behavior dataset. Experiment results show that our scheme effectively supports both overall aggregate queries and various selective aggregate queries with acceptable computation and communication overheads. Jianwei Qian, Fudong Qiu, Fan Wu 0006, Na Ruan, Guihai Chen, Shaojie Tang 0001 |
IEEE Trans. Computers | 4 |
| 2016 | When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi SignalsabstractIn this study, we present WindTalker, a novel and practical keystroke inference framework that allows an attacker to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from the observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). The adversary can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's number input. WindTalker presents a novel approach to collect the target's CSI data by deploying a public WiFi hotspot. Compared with the previous keystroke inference approach, WindTalker neither deploys external devices close to the target device nor compromises the target device. Instead, it utilizes the public WiFi to collect user's CSI data, which is easy-to-deploy and difficult-to-detect. In addition, it jointly analyzes the traffic and the CSI to launch the keystroke inference only for the sensitive period where password entering occurs. WindTalker can be launched without the requirement of visually seeing the smart phone user's input process, backside motion, or installing any malware on the tablet. We implemented Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. The evaluation results show that the attacker can recover the key with a high successful rate. Mengyuan Li 0004, Yan Meng 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan |
CCS | 7 |
| 2016 | Who Moved My Cheese: Towards Automatic and Fine-Grained Classification and Modeling Ad NetworkabstractThe mobile advertisement (ad) network is gaining an increasing interest due to the high popularity of smart phones. Previous researches on the security issues of ad network primarily focus on the privacy, permission and malware detection while less attention has been paid to the traffic consumption issue incurred by ad network. Though it is well known that ad network plays an important role in network consumption, it represents a great challenge of giving a fine-grained classification of ad networks. Inspired by this, different from any previous researches, in this study, we take the initial step towards modeling the network consumption of Ad network in Android. We develop an automatic ad analysis platform to quantify the ad network traffic consumed by android applications (app). To achieve a fine-grained quantification, we combine two sources of network traffic. On one hand, we modify the android webview and log system in system level to capture network traffic accurately. On the other hand, we capture network traffic in router level to collect detailed information of traffic packets, such as packet size and URI. We have evaluated the developed system in terms of normal apps, repacked apps and malicious apps based on the real-world dataset, which is comprised of 93 Android apps. We find out that ad traffic takes major percentage of the whole network traffic caused by Android app. We have also studied the ad library mechanism for 10 popular ad libraries. We found ads from some ad libraries use much more network traffic because they have to be fetched from remote ad libraries each time they are shown to users while other ad libraries allow apps to store ads locally. Jiafa Liu, Huaxin Li, Haojin Zhu, Na Ruan, Di Ma 0001 |
GLOBECOM | 5 |
| 2016 | A Traffic Based Lightweight Attack Detection Scheme for VoLTEabstractWith rapid growth of LTE network and Voice-over-LTE(VoLTE), detecting and preventing security threats like Denial of Service attack becomes a necessary and urgent requirement. VoLTE is an voice solution based on Internet Protocol and 4G LTE technology, at the same time exposing many vulnerabilities when using packet-switched network. There are many heavy weighted detection systems using content analysis, while high demands of computing resource constraint their practical use. In this paper, we purpose a lightweight detection scheme for VoLTE network security, based on analysis of data traffic flow. To optimize parameters in our scheme, we formulate a Bayesian game model. Bayesian game has the features of incomplete information and asymmetry, similar to practical attack-defense model. Besides, The dynamic Bayesian game is more realistic, since both sides can update believes about their opponents. Simulation results provide some guidances on parameter selection, as well as verifying the superiority of our scheme. Na Ruan, Haojin Zhu, Qingshui Xue, Weijia Jia 0001, Jingyu Cui |
GLOBECOM | 1 |
| 2016 | Efficient and secure message authentication in cooperative driving: A game-theoretic approachabstractRequirement of safety, roadway capacity and efficiency in vehicular network, which makes autonomous driving concept continue to be of interest. To achieve automated cooperative driving, vehicles form a platoon. For the authentication in vehicular platoons, efficiency and security are the two things of great significance. Cooperative authentication is a way to help recognize false identities and messages as well as saving resources. However, selfish behaviors of the vehicles may be caused by the concern of privacy leakage and unfair resources consuming. To deal with these weaknesses, we devised an enhanced cooperative authentication protocol based on mechanisms which discourages non-cooperating behavior. An infinitely repeated game for our designed protocol in is proposed to analyze the utility of all users to help analyse the threat of selfish behavior. We also proposed a method to optimize the system parameters in our designed protocol to achieve better efficiency and security. Na Ruan, Haojin Zhu |
ICC | 2 |
| 2016 | Toward Optimal DoS-Resistant Authentication in Crowdsensing Networks via Evolutionary GameabstractWith the increasing demand of Quality of Service(QoS) in Crowdsensing Networks, providing broadcast authentication and preventing Denial of Service (DoS) attacks become not only a fundamental issue but also a challenging security service. The multi-level TESLA is a series of lightweight broadcast authentication protocols, which can effectively mitigate DoS attacks via randomly selected messages. However, the rule of the parameter selection still remains a problem. In this paper, we formulate the attack-defense model as an evolutionary game accordingly, and then present an optimal solution, which achieves security assurance along with minimum resource cost. We then analyze the stability of our evolutionary strategy theoretically. Simulation results are given to evaluate the performance of the proposed algorithm under low QoS channels and severe DoS attacks, which demonstrates that our proposed protocol canworks even in the extreme case. Na Ruan, Haojin Zhu, Weijia Jia 0001 |
ICDCS | 1 |
| 2016 | Privacy-Preserving Mining of Association Rules for Horizontally Distributed Databases Based on FP-Tree
Yaoan Jin, Chunhua Su, Na Ruan, Weijia Jia 0001 |
ISPEC | 3 |
| 2016 | Automatic Detection of SIP-Aware Attacks on VoLTE DeviceabstractDue to the worldwide deployment of Long Term Evolution (LTE), the fourth-generation (4G) mobile cellular networking technology, Voice over LTE (VoLTE) [2] has been also well developed in past few years. It exploits packet-switched network to provide call services instead of the traditional circuit- switched telephony. Similar to the Voice over IP (VoIP), VoLTE adopts Session Initiation Protocol (SIP) to achieve some control functions. Therefore, it means attack techniques against the SIP will also be effective against VoLTE devices. In this paper, we propose a novel device-side SIP-aware detecting system against two kinds of SIP attacks, SIP message flooding attack and malformed SIP message attack. To detect the message flooding attack, we set threshold for the traffic of SIP message received from VoLTE interface within one minute. And for the malformed message attack, we provide the structure and formalization rules of SIP messages to detect malformed SIP messages by utilizing ontology descriptions. This paper presents the design and implementation of this detecting system. The simulation test shows that this system will improve the security level of VoLTE service in real applications. Zhushou Tang, Na Ruan, Haojin Zhu |
VTC Fall | 5 |
| 2015 | A Differentially Private Selective Aggregation Scheme for Online User Behavior AnalysisabstractOnline user behavior analysis is becoming increasingly important, and offers valuable information to analysts for developing better e-commerce strategies. However, it also raises significant privacy concerns. Recently, growing efforts have been devoted to protecting the privacy of individuals while data aggregation is performed, which is a critical operation in behavior analysis. Unfortunately, existing methods allow very limited aggregation over user data, such as allowing only summation, which hardly satisfies the need of behavior analysis. In this paper, we propose a scheme PPSA, which encrypts users' sensitive data to prevent privacy leakage from both analysts and the aggregation service provider, and fully supports selective aggregate functions for differentially private data analysis. We have implemented our design and evaluated its performance using a trace-driven evaluation based on an online behavior dataset. Evaluation results show that our scheme effectively supports various selective aggregate queries with acceptable computation and communication overheads. Jianwei Qian, Fudong Qiu, Fan Wu 0006, Na Ruan, Guihai Chen, Shaojie Tang 0001 |
GLOBECOM | 4 |
| 2014 | Efficient and enhanced broadcast authentication protocols based on multilevel μTESLAabstractProviding lightweight authentication and resisting Denial of Service (DoS) attacks are challenging problems in wireless ad hoc networks, such as wireless sensor networks (WSNs). We introduce two improved protocols based on fault-tolerant protocol and DoS-resistant protocol in Multilevel μTESLA to overcome these difficulties. The proposed Efficient Fault-Tolerant Protocol contributes in shortening the recovery time when highlevel packets are lost, and hence reduces the risk of memory-based DoS attacks. The proposed Enhanced DoS-Resistant Protocol enhances the resistance to DoS attacks by offering packet-loss recovery of authentication message. Na Ruan, Fan Wu 0006, Jie Li 0002, Mengyuan Li 0004 |
IPCCC | 2 |
| 2014 | A Paralleling Broadcast Authentication Protocol for Sparse RSUs in Internet of VehiclesabstractSince the era of Internet of Vehicles (IoVs) is coming in next few years, real-time data transmission between vehicles and road-side sensor nodes has many application scenarios. However, due to different characteristics of IoVs and WSNs (Wireless Sensor Networks), real-time traffic data transmission is too complicated and slow when emergencies occurred in many RSUs-sparse (Road Side Units) areas. We build a simple integrated network model and propose a broadcast authentication protocol, namely Paralleling Broadcast Authentication Protocol (PBAP), aiming at enhance energy efficiency and providing network security in the direct communication between vehicles and WSNs. The simulation results demonstrate that the protocol can effectively extend lifetime of WSNs by improving the utilization rate of the keys and show nice properties in different channel loss ratio and different degrees of DoS attacks. Mengyuan Li 0004, Na Ruan, Haojin Zhu, Jie Li 0002 |
MSN | 2 |
| 2011 | Performance Analysis of Key Management Schemes in Wireless Sensor Network Using Analytic Hierarchy ProcessabstractTo achieve security in wireless sensor networks (WSNs), key management is one of the most challenging issues in design of WSN due to resource-constrained sensor nodes. Various key management schemes (KMs) have been proposed to enable encryption and authentication in WSN for different application scenarios. According to different equirements, it is important to select the trustworthy KMs in a WSN for setting up a fully appropriate WSN mechanism. An Analytic Hierarchy Process (AHP)-aided method helping with the complex decision has been presented in our previous work. Our purpose in this paper is to do performance analysis of KMs in WSN using our previous AHP-aided method. We analyze the characters of abundance KMs intuitively. The following five performance criteria are considered: scalability, key connectivity, resilience, storage overhead and communication overhead. As all permutations of five performance criteria include 120 types' situations, experimental analyses on 43 KMs for the optimum selection are presented. Na Ruan, Yizhi Ren, Yoshiaki Hori, Kouichi Sakurai |
TrustCom | 1 |