Qingtao Wang

dblp:186/0816 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
7since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2024 A High-Performance IPv6 Fragment Evasion Threat Detection Method Based on eBPF and XDP
abstract
The IPv6 fragment header can be exploited by threateners to evade security systems like firewalls, leading to IPv6 fragment evasion threats. Current detection techniques for these threats face limitations in identification capabilities and poor detection performance. To address these issues, a high-performance threat detection method based on eBPF and XDP (named FragEva6-Guard) is proposed. First, XDP is employed at the network driver level to filter IPv6 packets in real time, allowing threat packets to be identified and processed at the earliest stage. Then, an eBPF program is used to further analyze packets that have passed the initial filtering and detect potential threats. A feature matching based upper-layer header integrity detection method is introduced to identify IPv6 fragment evasion threats. FragEva6-Guard extracts critical threat features and performs feature matching during packet analysis. Finally, the XDP decision making module executes appropriate actions based on the feature matching results to complete the detection process. Experimental results show that FragEva6-Guard successfully detects all 16 types of IPv6 fragment evasion threats from the Frag6-TestSuite, achieving an average detection rate of approximately 99.98% across various threat intensities, FragEva6-Guard outperforms both Baseline and Suricata. In terms of processing latency, FragEva6-Guard reduces delays by an average of 99.96% compared to Baseline and by approximately 8% compared to Suricata, while also lowering CPU usage by an average of 95.03% and 85.77%, respectively. Additionally, FragEva6-Guard has minimal impact on network performance, maintaining a consistent packet loss rate of 0%.
Liancheng Zhang, Qingtao Wang
HPCC6
2023 Private Transaction Retrieval for Lightweight Bitcoin Clients
abstract
Running a typical Bitcoin client (also called full node) needs more than 444 GB of disk space, considerable time, and computational resources to synchronize the entire blockchain, which is infeasible for resource-constrained devices. To address such concerns, the lightweight Bitcoin client proposed by Satoshi outsources most of computational and storage burdens to full nodes. Unfortunately, interacting with full nodes to query transactions leaks considerable information like addresses and transactions of lightweight client users. Thus, Bitcoin users that rely on lightweight clients are subject to de-anonymization, which defeats users privacy. Traditional schemes cannot support lightweight clients to query transactions from full nodes in an efficient yet privacy-preserving way. In this article, we propose a new efficient yet privacy-preserving transaction query scheme that specially targets the missing support for lightweight clients. We identify unique characteristics of the Bitcoin blockchain and craft a highly customized private information retrieval scheme called BIT-PIR to match the Bitcoin transaction query scenario and boost performances. Moreover, we customize a storage structure of the Bitcoin blockchain so that it further improves the query efficiency of our scheme. Finally, we develop a prototype implementation to demonstrate the feasibility of our proposed scheme.
Yankai Xie, Qingtao Wang, Ruoyue Li, Chi Zhang 0001, Lingbo Wei
IEEE Trans. Serv. Comput.2
2022 Multi-Party Secure Computation with Intel SGX for Graph Neural Networks
abstract
The current privacy-preserving Graph Neural Networks (GNNs) cannot provide security and privacy guarantees against malicious adversaries without sacrificing accuracy and efficiency. For example, the Secure Multi-party Computation (MPC) can resist malicious adversaries while adding severe overhead. Trusted Execution Environment (TEE), such as Intel Software Guard Extension (SGX), can guarantee privacy and faithful execution without compromising efficiency. However, existing attacks can compromise the confidentiality of SGXs. Besides, the CPU-based structure of SGX restricts its extensibility that cannot perform collaborative computation with GPUs. To address the above issues, we propose a novel GNN training and inference framework to support data holders outsourcing their computation tasks to servers. First, we combine the advantage of MPC and the code integrity protection provided by SGXs to resist malicious adversaries without sacrificing efficiency. Second, we adopt a strategy that allows the servers to transfer the parallelizable computation task to the untrusted yet high-performance GPUs, further improving efficiency without hindering privacy. To the best of our knowledge, our proposal is the first privacy-preserving GNN framework against malicious adversaries without sacrificing accuracy and efficiency. Experiments on real-world citation datasets have demonstrated the performance of our framework regarding security, privacy, accuracy, and efficiency.
Yixin Jie, Yixuan Ren, Qingtao Wang, Yankai Xie, Chi Zhang 0001, Lingbo Wei, Jianqing Liu
ICC3
2022 Secure and Efficient Decentralized Bitcoin Mixing Scheme using Trusted Execution Environment
abstract
Mixing schemes have been applied by Bitcoin users to break their payment links in the blockchain to enhance privacy. However, most mixing schemes cannot provide secure mixing service without compromising efficiency since they are relying on complex cryptographic techniques or interactive protocols. To provide secure yet efficient mixing service, researchers introduce Intel SGX enclave, which provides Trusted Execution Environment (TEE) with confidentiality and integrity guarantees to execute mixing operations. Unfortunately, users will lose their mixing funds if a malicious service provider compromises the confidentiality guarantee of his/her enclave. Moreover, the scheme cannot scale to a large number of users in a single mixing round, that is, limited scalability. In this paper, we present a novel decentralized mixing scheme with multiple enclaves run by different service providers, which uses Shamir secret sharing scheme and additive homomorphic property of keys in Elliptic Curve Cryptography to tolerate a subset of enclaves to be compromised. Moreover, our scheme also provides stronger scalability so it achieves anonymity sets by orders of magnitude higher than the existing TEE-based mixing scheme. The experiment shows our scheme can provide stronger security and anonymity guarantees without compromising efficiency which outperforms existing mixing schemes.
Yankai Xie, Qingtao Wang, Ruiyang Xiao, Chi Zhang 0001, Lingbo Wei
ICC2
2021 HyperChannel: A Secure Layer-2 Payment Network for Large-Scale IoT Ecosystem
abstract
For the future large-scale IoT ecosystem, the number and frequency of micro-payments will increase dramatically. However, the mainstream of cryptocurrencies such as Bitcoin and Ethereum fail to meet the need for a large-scale IoT ecosystem due to limit transaction throughput and high transaction fee. Although Layer-2 solutions such as Lightning Network (LN) increases the throughput of cryptocurrencies by allowing participants to conduct off-chain transactions, LN still suffers from two main limitations: participants need to access the Blockchain within a short bounded time, and a payment channel can only accommodate two participants. To overcome these limitations, we propose HyperChannel, a novel distributed layer-2 payment network designed specifically for the IoT ecosystem which outsources the transaction processing task safely to a group of Intel Software Guard Extensions (SGXs) run by for-profit selfish third parties. Clients such as IoT devices and IoT service providers who often trade with each other will be assigned to a channel to conduct high-frequency in-channel transactions while being allowed to conduct crosschannel transactions in a fee-saving fashion. Compared with existing SGX-based layer-2 payment framework, HyperChannel achieves maximum throughput, addresses both limitations of LN, and further lightens the burden of participants so that IoT devices can conduct layer-2 transactions without running an SGX by themselves.
Qingtao Wang, Chi Zhang 0001, Lingbo Wei, Yankai Xie
ICC1
2021 A Secure and Efficient Bitcoin Payment Channel Using Intel SGX
abstract
Hardware trusted execution environment (TEE) provided by Intel SGX enclave has been introduced in existing payment channel schemes as a root-of-trust to enforce faithful protocol execution so that participants do not need to monitor Bitcoin blockchain anymore. However, the security of these schemes relies totally on enclaves. Since private keys of all channel funds are kept by both payment channel participants’ enclaves, a malicious participant can steal funds from the counterparty by defeating her own enclave. To solve the above problem, we present a novel TEE-based payment channel scheme that transfers the responsibility of running enclaves from participants to a third party committee, while relieving both participants from monitoring the blockchain at the same time. Furthermore, since committee members can try to steal funds by defeating their own enclaves, we exploit the additive homomorphic property of signature keys in Elliptic Curve Cryptography to design a novel secret sharing scheme to tolerate a subset of committee members to be malicious. By using the above secret sharing scheme, private keys of the channel funds are never constructed in any committee member’s enclave, so that a malicious committee member cannot steal funds by defeating his own enclave. Finally, experiment shows our scheme can ensure payment channel funds security without efficient compromises compared with existing TEE-based payment channel schemes.
Yankai Xie, Chi Zhang 0001, Lingbo Wei, Qingtao Wang
ICC4
2021 A Hybrid Secure Computation Framework for Graph Neural Networks
abstract
The Multi-party Secure Computation (MPC)-based methods for privacy-preserving Graph Neural Networks (GNNs) are still challenged by high communication overhead. Moreover, the security guarantee of most MPC-based methods can only defend against the semi-honest adversary, while a few methods which can defend against the malicious adversary will cause a further increase in communication overhead. Moreover, Software Guard Extensions (SGX), which can provide the data confidentiality and code integrity, has been considered as a novel solution to privacy-preserving GNN. Unfortunately, previous work has shown that SGX is vulnerable to side-channel attacks that deprive its confidentiality and preserve only its integrity. To solve the above problems, we propose an n-party secure computation framework for GNNs using SGX. This framework can reduce the communication overhead and improve the security guarantee without relying on the confidentiality of SGX. Specifically, both data holders and the server hold SGX. Data holders enrich the data and train the model by MPC efficiently with the assistance of the server. SGX ensures integrity, where data holders and the server must execute according to protocols, so malicious adversaries cannot deviate from the protocol to breach privacy and security. Even if the confidentiality of SGX was breached, the adversary could only access the ciphertext in MPC instead of the plaintext. We conduct experiments on public datasets to demonstrate that our framework has achieved comparable performance with traditional GNNs and perform security analysis to validate that our framework satisfies security and privacy requirements.
Yixuan Ren, Yixin Jie, Qingtao Wang, Chi Zhang 0001, Lingbo Wei
PST3
2020 Multi-Order Feature Statistical Model for Fine-Grained Visual Categorization
abstract
Fine-grained visual categorization aims to learn a robust image representation modeling subtle differences from similar categories. Existing methods in this field tackle the problem by designing complex frameworks, which produce high-level features by performing first-order or second-order pooling. Despite the impressive performance achieved by these strategies, the single-order networks only carry linear or non-linear information of the last convolutional layer, neglecting the fact that features from different orders are mutually complementary. In this paper, we propose a multi-order feature statistical method (MOFS), which learns fine-grained features characterizing multiple orders. Specifically, the MOFS consists of two sub-modules: (i) a first-order module modeling both mid-level and high-level features. (ii) a covariance feature statistical module capturing high-order features. By deploying these two sub-modules on the top of existing backbone networks, MOFS simultaneously captures multi-level of discriminative patters including local, global and co-related patters. We evaluate the proposed method on three challenging benchmarks, namely CUB-200-2011, Stanford Cars, and FGVC-Aircraft. Compared with state-of-the-art methods, experiment results exhibit superior performance in recognizing fine-grained objects.
Qingtao Wang, Ke Zhang 0029, Jin Fan 0003, Shaoli Huang, Lianbo Zhang
ICPR1
2016 Network Codes-based Multi-Source Transmission Control Protocol for Content-centric Networks
abstract
With the rapid shift from end-to-end communications to content-based data retrieval, there are increasing interests in exploiting Content-centric Networks (CCN) to deliver data. As the special characteristics of CCN, in-network caching and naming-based routing make traditional TCP-like transmission control protocol unsuitable. Although there are some existing efforts on improving the congestion control in CCN, the big issue of redundant transmissions caused by multiple sources has received little attention. To eliminate the redundancy and speed up the transmission, we propose a complete Network Codes-based Multi-Source Transmission Control Protocol (MSTCP), which provides an efficient and controllable multi-source content retrieval service over CCN. MSTCP takes advantage of random network coding to make full use of the coded data responded by different sources to speed up decoding and data receiving at the request side. Moreover, we design a scheduling algorithm based on a simple Expected Reception Deadline (ERD) to efficiently control the number of coded packets to send at each source. This not only effectively eliminates the redundant transmissions in CCN, but also helps to significantly speed up the information retrieval. Extensive simulations show that our mechanism greatly reduces the redundancy while speeding up the content retrievals by the network users.
Dongliang Xie, Xin Wang 0001, Qingtao Wang
IWQoS3