Xinshu Ma

dblp:199/8301 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0003-1370-4608ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2
YearPublicationVenuePosition
2026 Looma: A Low-Latency PQTLS Authentication Architecture for Cloud Applications
Xinshu Ma, Michio Honda
NDSS1
2026 Designing Transport-Level Encryption for Datacenter Networks
abstract
Cloud applications need network data encryption to isolate from other tenants and protect their data from potential eavesdroppers in the network infrastructure. This paper presents SMT, a protocol design for emerging datacenter transport protocols, such as NDP and Homa, to integrate data encryption. SMT integrates TLS-based encryption with a message-based transport protocol that supports efficient Remote Procedure Calls (RPCs), a common workload in datacenters. This architecture enables the use of per-message record sequence number spaces in a secure session, while ensuring unique message identities to prevent replay attacks. It also enables the use of existing NIC offloads designed for TLS over TCP, while being a native transport protocol alongside TCP and UDP. We implement SMT in the Linux kernel by extending Homa/Linux and improve RPC throughput by up to 41 % and latency by up to 35 % in comparison to TLS/TCP.
Tianyi Gao 0001, Xinshu Ma, Suhas Narreddy, Eugenio Luo, Steven W. D. Chien, Michio Honda
SP2
2025 Designing Transport-Level Encryption for Datacenter Networks
Tianyi Gao 0001, Xinshu Ma, Suhas Narreddy, Eugenio Luo, Steven W. D. Chien, Michio Honda
APNet2
2025 Designing Transport-Level Encryption for Datacenter Networks
abstract
This paper presents SDP, a protocol design for emerging datacenter transports, such as NDP and Homa, to integrate data encryption. It supports NIC offloading designed for TLS over TCP, native protocol number alongside TCP and UDP, and message-based abstraction that enables low latency RPCs with fine-grained parallelism.
Tianyi Gao 0001, Xinshu Ma, Suhas Narreddy, Eugenio Luo, Steven W. D. Chien, Michio Honda
SIGCOMM2
2022 Stopping Silent Sneaks: Defending against Malicious Mixes with Topological Engineering
abstract
Mixnets provide strong meta-data privacy and recent academic research and industrial projects have made strides in making them more secure, performant, and scalable. In this paper, we focus our work on stratified Mixnets, a popular design with real-world adoption. We identify and measure significant impacts of practical aspects such as: relay sampling and topology placement, network churn, and risks due to real-world usage patterns. We show that, due to the lack of incorporating these aspects in design decisions, Mixnets of this type are far more susceptible to user deanonymization than expected. In order to reason about and resolve these issues, we model Mixnets as a three-stage “Sample-Placement-Forward” pipeline and develop tools to analyze and evaluate design decisions. To address the identified gaps and weaknesses we propose Bow-Tie, a design that mitigates user deanonymization through a novel adaption of Tor’s guard design with an engineered guard layer and client guard-logic for stratified mixnets. We show that Bow-Tie has significantly higher user anonymity in the dynamic setting, where the Mixnet is used over a period of time, and is no worse in the static setting, where the user only sends a single message. We show the necessity of both the guard layer and client guard-logic in tandem as well as their individual effect when incorporated into other reference designs. We develop and implement two tools, 1) a mixnet topology generator (Mixnet-Topology-Generator (MTG)) and 2) a path simulator and security evaluator (routesim) that takes into account temporal dynamics and user behavior, to assist our analysis and empirical data collection. These tools are designed to help Mixnet designers assess the security and performance impact of their design decisions.
Xinshu Ma, Florentin Rochet, Tariq Elahi
ACSAC1
2020 Intelligent Detection Algorithm Against UAVs' GPS Spoofing Attack
abstract
Unmanned Aerial Vehicle (UAV) technology is more and more widely used in the field of civil and military information acquisition. GPS plays the most critical part of UAVs' navigation and positioning. However, since the communication channel of the GPS signals is open, attackers can disguise as real GPS signals to launch GPS spoofing attacks on civilian UAVs. At present, the detection schemes for GPS spoofing attacks can be divided into three categories respectively based on encryption and digital signatures, the characteristics of the GPS signal and various external characteristics of UAVs. However, there are some problems in these methods, such as low computing efficiency, difficulty in equipment upgrading, and limited application scenarios. To solve these problems, we propose a new GPS spoofing attack detection method based on Long Short-Term Memory (LSTM) which is a machine learning algorithm. In order to improve the detection ratio, after the machine learning algorithm, we let the UAVs fly according to the path of a specific shape to accurately detect GPS spoofing attacks. This is also the first time machine learning has been used to detect GPS spoofing attacks. According to our algorithm, we can detect GPS spoofing attacks accurately and quickly in a short time. This paper describes in detail the algorithm we proposed to resist GPS spoofing attacks, and the corresponding experiments are carried out in the simulation environment. The experimental results show that our method can quickly and accurately detect UAV GPS spoofing attacks without requiring upgrades to existing equipment.
Shenqing Wang, Jian Wang 0038, Chunhua Su, Xinshu Ma
ICPADS4
2020 A semi-autonomous distributed blockchain-based framework for UAVs system
Chunpeng Ge 0001, Xinshu Ma, Zhe Liu 0001
J. Syst. Archit.2
2019 Blockchain-Enabled Privacy-Preserving Internet of Vehicles: Decentralized and Reputation-Based Network Architecture
Xinshu Ma, Chunpeng Ge 0001, Zhe Liu 0001
NSS1
2017 Exact Algorithms for Maximizing Lifetime of WSNs Using Integer Linear Programming
abstract
In wireless sensor networks, maximizing the lifetime of a data gathering tree is known to be NP-hard, so various (exponential-time) exact algorithms are designed to find the best data gathering tree. The state-of-the-art exact algorithm recursively performs graph decomposition to reduce search space. However, it essentially enumerates all possibilities in adjacent graph decompositions, and cannot handle moderately large sensor networks. In this paper, we propose an exact algorithm using integer linear programming. The challenge is that some constraints are not linear in the optimization problem. To address this challenge, instead of the optimization problem, we formulate the decision problem, and solve each decision problem by integer linear programming. The optimal value is then found by binary search over all possible lifetimes. To reduce the running time, we preprocess the graph by decomposing it into bi- connected subnetworks, and propose various rules to reduce the number of candidate lifetimes. Numerical results on simulated networks show that, within two hours, our algorithm can solve more problem instances than previous algorithms.
Xinshu Ma, Xiaojun Zhu 0001, Bing Chen 0002
WCNC1