VLDB 2026 Research / reviewers in the wild / expert
Kunrui Cao
dblp:195/8071
· DBLP profile ↗
26ranked-venue papers
8as first author
20since 2021 · last 2026
0000-0001-6021-8798ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 18 · 5 first-author · 16 since 2021Security and privacy · 6 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pinching-Antenna-Assisted Distributed Integrated Sensing and Communication SystemsabstractThis paper investigates a novel pinching antenna assisted multi-target integrated sensing and communication (ISAC) system. We propose a joint optimization of transmit and receive PA positions to enable the simultaneous service of multiple sensing targets and a downlink communication user. The objective of the formulated optimization problem is to maximize the minimum sensing signal-to-interference-plus-noise ratio (SINR), which addresses inter-target interference and ensures fairness across multiple targets. The design jointly considers both the transmit and receive antenna positions as well as the receive beamformer. An efficient alternating optimization framework is introduced to handle this non-convex problem. The receive beamformer is obtained in closed-form using the minimum variance distortionless response method, while the antenna position optimization is solved via the differential evolution (DE) algorithm. The DE search process is guided by a customized fitness function that incorporates both communication quality-of-service requirements and physical constraints. Numerical results demonstrate that the proposed joint optimization scheme substantially outperforms transmitter-only optimization benchmarks, receiver-only optimization, and fixed antenna placements. Furthermore, comparative studies show that the DE algorithm achieves a better trade-off between performance and complexity, it not only surpasses particle swarm optimization in terms of performance, but also outperforms element-wise search when the antenna number is small, while maintaining lower computational complexity than both alternatives. Yongxia Liu, Jian Xiao 0003, Wenwu Xie, Kunrui Cao, Liang Yang 0001 |
IEEE Internet Things J. | 6 |
| 2026 | Reliable and Secure Wireless-Powered Communications via Hybrid Active-Passive Double-RISabstractThis paper investigates the reliability and security of a hybrid double-reconfigurable intelligent surface (HDRIS) aided wireless-powered communication (WPC) system in the presence of eavesdroppers, where one active/passive RIS (RIS-1) is deployed between the power station and the information user, and the other passive/active RIS (RIS-2) is deployed between the information user and the access point. We propose two modes of HDRIS aided WPC, i.e., HDRIS-I with passive RIS-1 and active RIS-2, and HDRIS-II with active RIS-1 and passive RIS-2. Based on the two modes, we analyze the outage probability (OP) from the perspective of reliability and intercept probability (IP) from the perspective of security, and derive their accurate and asymptotic expressions, respectively. Moreover, a joint metric is proposed, i.e., reliability and security probability (RSP), to reveal the superiority of HDRIS compared to pure double-RIS (PDRIS). The results show that compared to PDRIS, the proposed HDRIS-I and HDRIS-II have better OPs than PDRIS-I with two passive RISs, but worse OPs than PDRIS-II with two active RISs. Both HDRIS-I and HDRIS-II have worse IPs than PDRIS-I, but better IPs than PDRIS-II. Interestingly, in HDRIS-I and HDRIS-II, the diversity gain for legitimate users is proportional to the number of elements of the RISs, while the diversity gain for eavesdroppers is only 1, indicating that HDRIS provide greater benefits for legitimate communications. In Particular, HDRIS-I achieves the best RSP under high transmission power, while HDRIS-II achieves the best RSP under low transmission power, demonstrating the superiority of HDRIS. Kunrui Cao, Tao Wang 0111, Panagiotis D. Diamantoulakis, Xingwang Li 0001, Chau Yuen, George K. Karagiannidis |
IEEE J. Sel. Areas Commun. | 1 |
| 2026 | Self-Sustainable Active Metasurface (SAM): Reliable and Secure CommunicationsabstractIn this paper, we propose a new concept of self-sustainable active metasurface (SAM), which exploits the dual advantages of energy harvesting in terms of self-sustainability and active metasurface in terms of information transmission, to achieve continuous operation and flexible deployment for reconfigurable intelligent surface (RIS) and simultaneously mitigate its multiplicative fading. SAM can enhance incident signals via power amplifiers and achieve self-sustainability by harvesting ambient energy. We propose three operation schemes to implement energy harvesting and information transmission for SAM, namely, time-switching based SAM (TS-SAM), power-splitting based SAM (PS-SAM), and element-splitting based SAM (ES-SAM). Then, we propose three new metrics, namely, energy-information outage probability (EIOP), energy-information intercept probability (EIIP), and secure energy efficiency ratio (SEER). The accurate and asymptotic EIOP and EIIP as well as accurate SEER for the three proposed schemes are analyzed, respectively. The results show that compared to self-sustainable passive RIS, TS-SAM and ES-SAM have better EIOPs, and PS-SAM has a better EIIP. Among the three schemes, PS-SAM achieves the best EIOP at low RF energy, while TS-SAM and ES-SAM perform better in high-energy scenarios. For EIIP, PS-SAM outperforms the other two schemes. In particular, compared to self-sustainable passive RIS, TS-SAM and ES-SAM have better SEERs, verifying the superiority of the proposed TS-SAM and ES-SAM. Among all inter-node distances, the distance between user and SAM dominates the performance. When the harvested energy and the number of reflecting elements are sufficiently large, the EIOP and EIIP of TS-SAM and ES-SAM are unrelated to the amplification factor of SAM. Kunrui Cao, Panagiotis D. Diamantoulakis, Beixiong Zheng, Xingwang Li 0001, Chau Yuen |
IEEE Trans. Wirel. Commun. | 1 |
| 2026 | Secure Wireless-Powered zeRIS CommunicationsabstractThis paper introduces the concept of wireless-powered zero-energy reconfigurable intelligent surface (zeRIS), and investigates a wireless-powered zeRIS aided communication system in terms of security, reliability and energy efficiency. In particular, we propose three new wireless-powered zeRIS modes: 1) in mode-I,Nreconfigurable reflecting elements are adjusted to the optimal phase shift design of information user to maximize the reliability of the system; 2) in mode-II,Nreconfigurable reflecting elements are adjusted to the optimal phase shift design of cooperative jamming user to maximize the security of the system; 3) in mode-III,N1andN2(N1+N2=N) reconfigurable reflecting elements are respectively adjusted to the optimal phase shift designs of information user and cooperative jamming user to balance the reliability and security of the system. Then, we propose three new metrics, i.e., joint outage probability (JOP), joint intercept probability (JIP), and secrecy energy efficiency (SEE), and analyze their closed-form expressions in three modes, respectively. The results show that under high transmission power, all the diversity gains of three modes are 1. Among three modes, mode-I achieves the best JOP, while mode-II achieves the best JIP. We exploit two security-reliability trade-off (SRT) metrics, i.e., JOP versus JIP, and normalized joint intercept and outage probability (JIOP), to reveal the SRT performance of the proposed three modes. Interestingly, mode-III achieves the lowest normalized JIOP with increasing time allocation factor, and the highest SEE with increasing transmission power. However, mode-I has the highest SEE with increasing predefined data rate. The optimal zeRIS deployment for mode-I and mode-III is near the PS, while that for mode-II is near the AP. Jingyu Chen 0001, Kunrui Cao, Panagiotis D. Diamantoulakis, Lu Lv 0001, Liang Yang 0001, Haolian Chi, Haiyang Ding |
IEEE Trans. Wirel. Commun. | 2 |
| 2025 | Performance Analysis for STAR-RIS-Assisted Wireless Powered Communications With Cooperative JammingabstractThis article investigates the simultaneously transmitting and reflecting reconfigurable intelligent surface (STAR-RIS) assisted secure transmissions in wireless powered communication (WPC) systems. According to the conditions of communication links, three scenarios are considered. Correspondingly, two transmission schemes are proposed for outdoor and indoor users to enhance the reliability and security of the communication system in each scenario. To be specific, for the scenario-I with blocked energy harvesting links, the scenario-I based information transmission of outdoor-user and cooperative jamming of indoor-user (IbTOJI) scheme, and cooperative jamming of outdoor-user and information transmission of indoor-user (IbJOTI) scheme are proposed, respectively. For the scenario-II with blocked information transmission (IT) links, scenario-II-based IT of outdoor-user and cooperative jamming of indoor-user (IIbTOJI) scheme, and cooperative jamming of outdoor-user and IT of indoor-user (IIbJOTI) scheme are proposed, respectively. For the scenario-III which deploys a hybrid access point (HAP), the direct links of the energy harvesting and IT are blocked. Scenario-III-based IT of outdoor-user and cooperative jamming of indoor-user (IIIbTOJI) scheme, and cooperative jamming of outdoor-user and IT of indoor-user (IIIbJOTI) scheme are proposed, respectively. We analyze the closed-form expressions of outage probability and intercept probability for each scheme. The result shows that IIIbTOJI scheme has the best reliable performance among the proposed schemes, and IbJOTI and IIIbJOTI schemes perform best in security. Haolian Chi, Kunrui Cao, Haiyang Ding, Lu Lv 0001, Jingyu Chen 0001, Danyu Diao, Buhong Wang, Fengkui Gong |
IEEE Internet Things J. | 2 |
| 2025 | Secure Phase Shift Configuration Strategies With UAV-Mounted STAR-RISabstractThis paper investigates a novel anti-eavesdropping strategy based on unmanned aerial vehicle (UAV)-mounted simultaneously transmitting and reflecting reconfigurable intelligent surface (STAR-RIS). In particular, a UAV equipped with a STAR-RIS acts as a passive relay to reflect desired signals and simultaneously acts as a friendly jammer to transmit artificial noise (AN) against eavesdroppers. Based on the phase shift coupling characteristics of STAR-RIS, three phase shift configuration strategies are proposed, namely reliability-priority (RP), security-priority (SP), and element-partitioning (EP) schemes. Analytical closed-form expressions of connection outage probability (COP), secrecy outage probability (SOP), effective secrecy throughput (EST) and secrecy energy efficiency (SEE) are derived to evaluate the reliable and secure performance achieved by the proposed schemes, respectively. The asymptotic analysis is also performed for further insights. Analysis and simulation results demonstrate that the proposed three schemes outperform traditional benchmark schemes. From the perspective of reliability, the RP scheme can achieve the best COP. In terms of security, as the number of STAR-RIS elements increases, the SOPs of the SP and EP exponentially decrease, whereas the SOP of the RP scheme increases. The EP scheme achieves the optimal EST, and the asymptotic EST is independent of phase estimation errors. Additionally, it is recommended that the UAV be deployed near the eavesdropper for the SP and EP schemes to enhance SEE. Danyu Diao, Buhong Wang, Kunrui Cao, Runze Dong, Tianhao Cheng, Jingyu Chen 0001, Ximing Wang |
IEEE Internet Things J. | 3 |
| 2025 | Double-RIS Enabled Physical Layer Security for Wireless-Powered Communication Systems Over Rayleigh Fading ChannelsabstractThis paper investigates the physical layer security for a double-reconfigurable intelligent surface (DRIS) aided wireless-powered communication (WPC) system in the presence of an eavesdropper, where one RIS (termed as RIS-1) is deployed between power station (PS) and information user (U) while the other RIS (termed as RIS-2) is deployed between U and access point (AP). Moreover, an idle user acts as a cooperative jamming user (J) to emit the artificial noise to improve the transmission security of U. According to different types in energy harvesting (EH) and information transmission (IT)/noise transmission (NT) of U/J, we propose four DRIS enabled wireless-powered cooperative jamming transmission schemes based on jointly enhancing EH and IT of U (namely DRIS-1), jointly enhancing EH of U and NT of J (namely DRIS-2), jointly enhancing EH of J and IT of U (namely DRIS-3), and jointly enhancing EH and NT of J (namely DRIS-4), respectively. We analyze connection outage probability (COP), secrecy outage probability (SOP), and effective secrecy throughput (EST) of the proposed four schemes, respectively. The results show that DRIS-1 scheme has the highest diversity gain among the four schemes. Besides, the gain of the number of reflecting elements at RIS-1 has the same order as that at RIS-2 in DRIS-1 scheme and DRIS-4 scheme. In DRIS-2 scheme, the gains of the number of reflecting elements at RIS-1 and RIS-2 are two powers and one power, respectively, while the opposite is true in DRIS-3 scheme. In addition, DRIS-1 scheme achieves the best COP, while DRIS-4 scheme achieves the best SOP. DRIS-1 scheme, DRIS-3 scheme, and DRIS-4 scheme respectively achieve the best EST in the low, middle, and high region of transmission power or number of RIS elements. Jingyu Chen 0001, Kunrui Cao, Haiyang Ding, Lu Lv 0001, Yinghui Ye, Haolian Chi, Tao Wang 0111, Liang Yang 0001 |
IEEE Trans. Commun. | 2 |
| 2024 | Security Enhancement of UAV Swarm Empowered Downlink Transmission with Integrated Sensing and CommunicationabstractAs a promising technique for the next generation communication network, integrated sensing and communication (ISAC) has attracted incremental research attentions due to its capabilities in spectrum sharing, cost saving, and data collecting. In this paper we utilize unmanned aerial vehicle (UAV) swarm to perform downlink ISAC transmission to serve multiple terrestrial legitimate users and sensing targets. To accommodate more practical application scenarios, we assume that there are also multiple malicious eavesdroppers in the network attempting to eavesdrop on the confidential signal. In order to enhance the security of the downlink transmission while maintaining sufficient sensing performance, we propose a joint optimization of the centralized trajectory of UAV swarm, the transmit beamforming on each UAV, and the ISAC schedule, which is eventually formulated as an average secrecy rate (ASR) maximization problem. A deep reinforcement learning (DRL) based algorithm is developed to solve the considered optimization problem and its effectiveness is validated via experimental simulations, which also proves its superiority over benchmark methods. Runze Dong, Buhong Wang, Jiang Weng, Kunrui Cao, Jiwei Tian, Tianhao Cheng |
TrustCom | 4 |
| 2024 | On the Reliability and Security Enhancements of Double-RIS Enabled WPC System with JammingabstractThis paper studies the physical layer security for a double reconfigurable intelligent surface (RIS) aided wireless powered communication system in the presence of an eaves-dropper, where a user acts as friendly jammer (J) to emit the artificial noise to improve the transmission security of another user. In particular, three RIS transmission schemes are proposed: 1) In scheme-I, both RISs are designed as optimal phase shift of wireless user (U); 2) In scheme-II, the first RIS is designed as optimal phase shift of U and the second RIS is designed as optimal phase shift of J, respectively; 3) In scheme-III, the first RIS is designed as optimal phase shift of J and the second RIS is designed as optimal phase shift of U, respectively. To reveal the achieved reliability and security performance of proposed three schemes, we analyze the connection outage probability (COP) and secrecy outage probability (SOP), respectively. The results show that scheme-II and scheme-III have the same COP performance and both of them are worse than scheme-I. The scheme-III achieves the best SOP performance, while scheme-I achieves the worst SOP performance that is slightly inferior to scheme-II. Jingyu Chen 0001, Kunrui Cao, Lu Lv 0001, Beixiong Zheng, Haolian Chi, Siwei Tang, Danyu Diao |
WCNC | 2 |
| 2024 | STAR-RIS Aided Secure Wireless Powered Communication with Indoor and Outdoor UsersabstractThis paper studies simultaneous transmitting and reflecting reconfigurable intelligent surface (STAR-RIS) aided secure wireless powered communication. Specifically, we propose an energy splitting protocol based STAR-RIS transmission scheme, combined with an uplink non-orthogonal multiple access (NOMA), to enhance both energy transfer and information transmission for indoor and outdoor users against eavesdropping attacks. The accurate and asymptotic connection outage probabil-ities, secrecy outage probability, and effective secrecy throughput are analyzed to evaluate the proposed scheme's performance and the impact of key parameters. Simulation results indicate that the proposed scheme significantly outperforms the dual transmit/reflect-only RIS scheme. Although slightly less effective than traditional direct transmission scheme at the low transmit power region, the proposed scheme's efficacy rapidly surpasses that of direct transmission as the transmit power increases. Siwei Tang, Kunrui Cao, Lu Lv 0001, Jingyu Chen 0001 |
WCNC | 2 |
| 2024 | Secure RIS Deployment Strategies for Wireless-Powered Multi-UAV CommunicationabstractReconfigurable intelligent surface (RIS) is viewed as a promising technique that can be utilized to improve the performance of systems by reconfiguring signal propagation environments. This article investigates green and secure unmanned aerial vehicle (UAV) Internet of Things (IoT) communications with the aid of RIS, where multiple UAVs harvest energy from a power beacon (PB) and send information uplink to access point (AP) with nonorthogonal multiple access (NOMA). In particular, communication can be divided into two phases during each time frame: 1) energy transfer and 2) information transmission (IT). Three RIS deployment strategies are proposed. In mode I, RISs are deployed between UAVs and AP to enhance the IT. In mode II, RISs are deployed between PB and UAVs to enhance the energy transfer. In mode III, RISs are deployed between UAVs and a hybrid AP (HAP) to enhance energy transfer and IT simultaneously. Considering phase compensation error caused by imperfect conditions, we define and evaluate ergodic capacity (EC), EC probability (ECP) and ergodic secrecy capacity (ESC) of three modes to measure the reliability and security of the system. The asymptotic expressions are also derived for further insights. Numerical results are presented to validate the correctness of theoretical derivations. Results demonstrate that the passive beamforming gain promised by RIS can significantly enhance the performance of systems. Mode III outperforms other modes in terms of reliability and security. When the transmission power and the number of UAVs increase, the ESCs of modes I and III converge to the same performance floor. Danyu Diao, Buhong Wang, Kunrui Cao, Beixiong Zheng, Jiang Weng, Jingyu Chen 0001 |
IEEE Internet Things J. | 3 |
| 2024 | STAR-RIS Assisted Reliable and Secure Transmissions in Wireless-Powered CommunicationsabstractThis article investigates a reliable and secure wireless-powered communication system assisted by a simultaneous transmitting and reflecting reconfigurable intelligent surface (STAR-RIS) serving indoor and outdoor users. To align with practical application, we consider two eavesdropping conditions: mixed and indirect eavesdropping links. To improve the reliability and security of downlink energy transfer (ET) and uplink information transmission (IT), we propose four STAR-RIS schemes utilizing time-switching (TS) and energy-splitting (ES) protocols: 1) The dual-TS (DTS) scheme employs the TS protocol for both downlink ET and uplink IT; 2) The mixed ES-TS (MET) scheme switches from the ES protocol in downlink ET to the TS protocol in uplink IT; 3) The dual-ES (DES) scheme employs the ES protocol for both downlink ET and uplink IT; 4) The mixed TS-ES (MTE) scheme switches from the TS protocol in downlink ET to the ES protocol in uplink IT. Further, accurate and asymptotic connection outage probability, secrecy outage probability, and effective secrecy throughput are analyzed for each proposed scheme. Theoretical analysis and simulation results demonstrate that: 1) At high transmission power or with a large number of STAR-RIS elements, the MTE scheme achieves the highest reliability. Conversely, the DES scheme provides the best reliability at lower transmission power or with fewer STAR-RIS elements; 2) Under indirect eavesdropping links, the DES scheme achieves the highest security, followed by the MTE, MET, and DTS schemes. However, this performance order is reversed under mixed eavesdropping links; 3) The DES scheme achieves the best overall performance, followed by the MTE, MET, and DTS schemes, all of which outperform the benchmark schemes. Siwei Tang, Kunrui Cao, Lu Lv 0001, Haiyang Ding, Beixiong Zheng, Jingyu Chen 0001, Danyu Diao, Buhong Wang |
IEEE Trans. Wirel. Commun. | 2 |
| 2023 | Physical-Layer Security for Intelligent-Reflecting-Surface-Aided Wireless-Powered Communication SystemsabstractThis article investigates physical-layer security (PLS) of a typical wireless-powered communication (WPC) system with the aid of intelligent reflecting surface (IRS) in the presence of a passive eavesdropper for Internet of Things (IoT), and proposes three IRS-aided secure WPC modes. Specifically, in mode-I, the IRS is deployed between hybrid access point (HAP) and wireless user (U) for co-located power station (PS) and access point (AP). In mode-II, the IRS is deployed between AP and U for separate PS and AP, while in mode-III, the IRS is deployed between PS and U for separate PS and AP. For each mode, the optimal phase shift is designed to maximize the reception of energy and information at the legitimate receiver. We comprehensively analyze the performance of each mode, and derive the closed-form expressions of connection outage probability (COP), secrecy outage probability (SOP), and effective secrecy throughput (EST) for each mode, respectively. The theoretical analysis and simulation results reveal that from the perspective of reliability, mode-I can achieve the best COP with the increased number of IRS elements, while mode-II and mode-III have a similar COP. From the perspective of security, mode-II can achieve the best SOP with the increased number of IRS elements, while mode-I and mode-III have a similar SOP. Moreover, under the condition of small transmission power at HAP/PS or small number of IRS elements, mode-I has the best EST, while as the power or the number increases, the EST of mode-II becomes the best one. Kunrui Cao, Haiyang Ding, Lu Lv 0001, Zhou Su 0001, Fengkui Gong, Buhong Wang |
IEEE Internet Things J. | 1 |
| 2023 | Secure SWIPT-powered UAV communication against full-duplex active eavesdropper
Danyu Diao, Buhong Wang, Kunrui Cao |
Wirel. Networks | 3 |
| 2022 | NOMA aided Semi-Grant-Free Transmission: A Security PerspectiveabstractNon-orthogonal multiple access (NOMA) assisted semi-grant-free transmission admits grant-free users to access the channels otherwise solely occupied by grant-based users, and has been recently attracting considerable attention in terms of accommodating massive connectivity and reduce access delay. In this paper, we investigate the security of semi-grant-free NOMA transmission in the presence of passive and active eavesdropping attacks. In particular, the maximal user scheduling (MUS) and optimal user scheduling (OUS) schemes are proposed to combat the passive and active eavesdropping, respectively. Based on the proposed schemes, the exact secrecy outage probability (SOP) are analyzed to evaluate the system performance. The simulation results show the correctness of theoretic analysis and the superiority of the proposed schemes. The OUS scheme can achieve better performance than the MUS scheme owing to the use of active eavesdropper’s channel state information (CSI). The SOP achieved by the proposed schemes can be further improved with the increasing number of grant-free users and decreasing target rate (or target secrecy rate). Kunrui Cao, Buhong Wang |
ISNCC | 1 |
| 2022 | Enhancing Physical-Layer Security for IoT With Nonorthogonal Multiple Access Assisted Semi-Grant-Free TransmissionabstractNonorthogonal multiple access (NOMA) assisted semi-grant-free transmission admits grant-free users to access the channels otherwise solely occupied by grant-based users, and has been recently attracting considerable attention in terms of accommodating massive connectivity and reducing access delay in Internet of Things (IoT). In this work, we investigate the security of semi-grant-free NOMA transmission in the presence of passive and active eavesdropping attacks. In particular, for the scenario-I with strong grant-based user and weak grant-free users, the scenario-I-based maximal user scheduling (IbMUS) and scenario-I-based optimal user scheduling (IbOUS) schemes are proposed to combat the passive and active eavesdropping, respectively. For the scenario-II with weak grant-based user and strong grant-free users, two parallel schemes, namely, the scenario-II-based maximal user scheduling (IIbMUS) and scenario-II-based optimal user scheduling (IIbOUS) schemes, are proposed to combat the passive and active eavesdropping, respectively. These proposed schemes enhance the security by scheduling a grant-free user with maximal main channel capacity/maximal secrecy capacity to access the NOMA channel on the premise of ensuring the grant-based user’s Quality of Service. Based on these proposed schemes, the exact secrecy outage probability (SOP) are analyzed to evaluate the system performance. The simulation results validates the theoretic analysis and the superiority of the proposed schemes. The IbOUS and IIbOUS schemes can achieve better performance than the IbMUS and IIbMUS schemes owing to the use of active eavesdropper’s channel state information (CSI). The SOP achieved by the proposed schemes can be further improved with the increasing number of grant-free users and decreasing target rate (or target secrecy rate). Kunrui Cao, Haiyang Ding, Buhong Wang, Lu Lv 0001, Jiwei Tian, Qingmei Wei, Fengkui Gong |
IEEE Internet Things J. | 1 |
| 2022 | Adversarial Attacks and Defenses for Deep-Learning-Based Unmanned Aerial VehiclesabstractThe introduction of deep learning (DL) technology can improve the performance of cyber–physical systems (CPSs) in many ways. However, this also brings new security issues. To tackle these challenges, this article explores the vulnerabilities of DL-based unmanned aerial vehicles (UAVs), which are typical CPSs. Although many research works have been reported previously on adversarial attacks of DL models, only few of them are concerned about safety-critical CPSs, especially regression models in such systems. In this article, we analyze the problem of adversarial attacks against DL-based UAVs and propose two adversarial attack methods against regression models in UAVs. The experiments demonstrate that the proposed nontargeted and targeted attack methods both can craft imperceptible adversarial images and pose a considerable threat to the navigation and control of UAVs. To address this problem, adversarial training and defensive distillation methods are further investigated and evaluated, increasing the robustness of DL models in UAVs. To our knowledge, this is the first study on adversarial attacks and defenses against DL-based UAVs, which calls for more attention to the security and safety of such safety-critical applications. Jiwei Tian, Buhong Wang, Rongxiao Guo, Zhen Wang 0020, Kunrui Cao |
IEEE Internet Things J. | 5 |
| 2022 | Joint Adversarial Example and False Data Injection Attacks for State Estimation in Power SystemsabstractAlthough state estimation using a bad data detector (BDD) is a key procedure employed in power systems, the detector is vulnerable to false data injection attacks (FDIAs). Substantial deep learning methods have been proposed to detect such attacks. However, deep neural networks are susceptible to adversarial attacks or adversarial examples, where slight changes in inputs may lead to sharp changes in the corresponding outputs in even well-trained networks. This article introduces the joint adversarial example and FDIAs (AFDIAs) to explore various attack scenarios for state estimation in power systems. Considering that perturbations added directly to measurements are likely to be detected by BDDs, our proposed method of adding perturbations to state variables can guarantee that the attack is stealthy to BDDs. Then, malicious data that are stealthy to both BDDs and deep learning-based detectors can be generated. Theoretical and experimental results show that our proposed state-perturbation-based AFDIA method (S-AFDIA) can carry out attacks stealthy to both conventional BDDs and deep learning-based detectors, while our proposed measurement-perturbation-based adversarial FDIA method (M-AFDIA) succeeds if only deep learning-based detectors are used. The comparative experiments show that our proposed methods provide better performance than state-of-the-art methods. Besides, the ultimate effect of attacks can also be optimized using the proposed joint attack methods. Jiwei Tian, Buhong Wang, Zhen Wang 0020, Kunrui Cao, Mete Ozay |
IEEE Trans. Cybern. | 4 |
| 2021 | TOTAL: Optimal Protection Strategy Against Perfect and Imperfect False Data Injection Attacks on Power Grid Cyber-Physical SystemsabstractThis article explores the problem of protection against false data injection attacks (FDIAs) on the power system state estimation. Although many research works have been reported previously to solve the same problem, yet most of them are only for perfect FDIAs. To address the problem reasonably, all related factors influencing the success probability and corresponding attack impact of imperfect FDIAs should also be considered. Based on such considerations, a topology, parameter, accuracy, level (TOTAL) protection strategy considering all corresponding factors is proposed. The TOTAL protection strategy minimizes the attack impact of typical imperfect FDIAs (single measurement attacks) while defending against typical perfect FDIAs (single-state variable attacks). Depending on whether the protection scheme contains phasor measurement units (PMUs), we formulate the meter selection as a linear binary programming or integer programming problem, which can be solved by suitable solvers. The proposed strategy is compared with the existing methods in the literature and evaluated using the standard IEEE test cases. Jiwei Tian, Buhong Wang, Tengyao Li, Fute Shang, Kunrui Cao, Rongxiao Guo |
IEEE Internet Things J. | 5 |
| 2021 | Improving Physical Layer Security of Uplink NOMA via Energy Harvesting JammersabstractWe investigate the secrecy transmission of uplink non-orthogonal multiple access (NOMA) with the aid of energy harvesting (EH) jammers. During each time frame, communication is divided into two phases. At the first phase, the base station (BS) transfers wireless power to EH receivers (EHRs). At the second phase, users perform uplink NOMA transmission to BS, while one of EHRs is selected as a friendly jammer that uses the energy harvested from the previous phase to emit the artificial noise for confusing the eavesdropper. In terms of the requirement of channel state information (CSI), we propose three friendly EH jammer selection schemes, namely random EH jammer selection (REJS) scheme without the requirement of any CSI, maximal EH jammer selection (MEJS) scheme with the CSI between BS and each EHR, and optimal EH jammer selection (OEJS) scheme where both the CSIs from BS to EHRs and from EHRs to the eavesdropper need to be known. Analytical closed-form expressions for the connection outage probability (COP), secrecy outage probability (SOP) and effective secrecy throughput (EST) are derived to evaluate the system performance achieved by the proposed schemes, respectively. Also, the asymptotic analysis is provided to gain further insights. The analytical and numerical results indicate that the proposed schemes can realize better secrecy performance than conventional scheme without an EH jammer. Both the secrecy diversity orders of the REJS and MEJS schemes are one while the OEJS scheme can achieve a full secrecy diversity order. Furthermore, owing to the impact of connection outage, the three schemes converge to the same EST floor with the increase of signal-to-noise ratio (SNR). Kunrui Cao, Buhong Wang, Haiyang Ding, Lu Lv 0001, Runze Dong, Tianhao Cheng, Fengkui Gong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Dynamic temporal ADS-B data attack detection based on sHDP-HMM
Tengyao Li, Buhong Wang, Fute Shang, Jiwei Tian, Kunrui Cao |
Comput. Secur. | 5 |
| 2020 | Secrecy precoding in MIMOME wireless communication system under partial CSIabstractIn this study, a precoding scheme which is called singular value decomposition and null space (SVDNS) based scheme is proposed to enhance physical layer security of a multiple‐input multiple‐output multiantenna eavesdropper (MIMOME) system. Under the partial channel state information (CSI) of the eavesdropper, the precoding matrix for the information bearing signal is constructed firstly via SVDNS‐based scheme to acquire a compromise between improving performance of the main channel and impairing that of the wiretap channel. Then the optimal power allocation over subchannels formed by precoding matrix is obtained through solving the secrecy rate maximise problem to further improve secrecy performance. After that, under the scenario that CSI of the wiretap channel is less knowable, precoding matrix for artificial noise (AN) is proposed via SVDNS‐based scheme, and then the optimal power allocation between the information bearing signal and AN is obtained while optimal power allocation over subchannels is solved subsequently. Simulation results show that the SVDNS‐based scheme with optimal power allocation achieves a higher secrecy rate than the existing schemes, and the SVDNS‐based scheme with AN aiding could make up for the performance degradation of it without AN in the situation that CSI of the wiretap channel is more unknowable. Runze Dong, Buhong Wang, Kunrui Cao |
IET Commun. | 3 |
| 2020 | Threat model and construction strategy on ADS-B attack dataabstractWith the fast increase in airspace density and high‐safety requirements on aviation, automatic dependent surveillance‐broadcast (ADS‐B) is regarded as the primary method in the next generation air traffic surveillance. The ADS‐B data is broadcast with the plain text without sufficient security measures, which results in various attack patterns emerging. However, in terms of constrictions with laws and regulations, ADS‐B attack data is difficult to collect and obtain, which is essential for data security research studies. To deal with the absence of ADS‐B attack data in real environments, the construction strategy on ADS‐B attack data is proposed. For construction fidelity, ADS‐B data features are analysed and modelled at first. Then the popular and classical attack patterns on ADS‐B data are analysed to establish threat models. Based on the original ADS‐B data sets, the construction strategy is designed to focus on attack target selection, key parameter determination, and mixture strategy, reproducing the attack intentions. The constructed ADS‐B attack data sets are hybrid data sets including the normal and attack data. By simulation analyses, the feasibility and availability of the construction strategy were validated with real ADS‐B data. Tengyao Li, Buhong Wang, Fute Shang, Jiwei Tian, Kunrui Cao |
IET Inf. Secur. | 5 |
| 2020 | On the Security Enhancement of Uplink NOMA Systems With Jammer SelectionabstractWe investigate physical layer security of an uplink NOMA system consisting of one base station, multiple users and one eavesdropper. During each uplink transmission, two users are paired to perform NOMA and another user is opportunistically selected from the remaining idle users to act as a friendly jammer to emit artificial noise for confusing the eavesdropper. To enhance the transmission security for the system, we propose two friendly jammer selection aided uplink NOMA transmission schemes, namely random jammer selection aided uplink NOMA transmission (RJS-UNT) scheme without knowing the eavesdropper's channel state information (CSI), and optimal jammer selection aided uplink NOMA transmission (OJS-UNT) scheme where the eavesdropper's CSI is available. For comparison purpose, a non-jammer selection aided uplink NOMA transmission (NJS-UNT) scheme is also considered. Analytical closed-form expressions for the secrecy outage probability (SOP) are derived to evaluate the secrecy performance achieved by the proposed schemes. Also, the asymptotic SOPs are provided to obtain further insights. The analysis and simulation results indicate that the schemes converge to SOP floors with the increasing SNR, while the floors achieved by the RJS-UNT and OJS-UNT schemes are significantly lower than that achieved by the NJS-UNT scheme, showing the security advantage of the proposed schemes. Kunrui Cao, Buhong Wang, Haiyang Ding, Lu Lv 0001, Jiwei Tian, Fengkui Gong |
IEEE Trans. Commun. | 1 |
| 2020 | Secure Transmission Designs for NOMA Systems Against Internal and External EavesdroppingabstractThe key idea of non-orthogonal multiple access (NOMA) is to serve multiple users in the same resource block to improve the spectral efficiency. Whereas due to the resource sharing, a security flaw of NOMA emerges in the presence of internal untrusted users, especially untrusted near users who are closer to the base station and can easily access the confidential information for paired far users. To mitigate the flaw, in this paper, we investigate the reliable and secure transmission of NOMA systems with untrusted near users, and propose joint beamforming and power allocation (JBP) scheme for the scenario. Meanwhile, from security point of view, we extend to a worse-case scenario where both untrusted near users and external eavesdroppers exist, and propose joint artificial noise aided beamforming and power allocation (JANBP) scheme to achieve a reliable and secure transmission for the scenario. The exact and asymptotic closed-form expressions of secrecy outage probability (SOP) for the two scenarios are derived to evaluate the secrecy performance achieved by the proposed schemes, respectively. The analysis and simulation results show the superiority of the proposed JBP and JANBP schemes in terms of combating internal and external eavesdropping, and also indicate the two schemes can achieve the same SOP at high SNR. Kunrui Cao, Buhong Wang, Haiyang Ding, Tengyao Li, Jiwei Tian, Fengkui Gong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | Online sequential attack detection for ADS-B data based on hierarchical temporal memory
Tengyao Li, Buhong Wang, Fute Shang, Jiwei Tian, Kunrui Cao |
Comput. Secur. | 5 |