Chunpeng Ge 0001

dblp:20/7563-1 · DBLP profile ↗
← Back
87ranked-venue papers
13as first author
69since 2021 · last 2026
0000-0002-9274-7325ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 37 · 8 first-author · 32 since 2021Computer networks · 14 · 1 first-author · 10 since 2021Software engineering, systems software and programming languages · 11 · 10 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 1 first-author · 7 since 2021Systems, architecture and hardware · 7 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2Theory of computation · 1
YearPublicationVenuePosition
2026 GResMark: A swin transformer-based watermarking framework with geometric attack resilience
Weitong Chen 0002, Jiale Zhang 0001, Chunpeng Ge 0001, Di Wu 0050, Willy Susilo, Palaiahnakote Shivakumara
Expert Syst. Appl.4
2026 Optimized homomorphic linear computation in privacy-preserving CNN inference
Xirong Ma, Xiuhao Wang, Fanyu Kong 0002, Yunting Tao, Chunpeng Ge 0001
Expert Syst. Appl.6
2026 Generalized Collusion and Hop-Skipping Resistant Autonomous Path Proxy Re-Encryption for Blockchain
abstract
Blockchain has become a superior carrier for data storage due to its decentralization and immutability. How to realize privacy-preserving data sharing and controlled transfer of blockchain data access rights has become a challenging issue. Autonomous path proxy re-encryption allows the delegator to designate a series of delegatees to obtain decryption privileges according to a predefined sequence in a multi-hop manner. However, it faces the hop-skipping issue, where a malicious proxy can directly re-encrypt the ciphertext to the delegatees several hops afterwards, by skipping one or more delegatees in between, destroying the decryption privileges of the skipped delegatees. Furthermore, the intrinsic nature of proxy re-encryption makes it vulnerable to collusion attack, wherein the proxy and a delegatee might collude to construct a decryption device which can decrypt all the delegator’s ciphertexts, posing a serious threat to the delegator’s privacy. To address these challenging issues, we propose a generalized collusion and hop-skipping resistant autonomous path proxy re-encryption for blockchain (CHRAP-PRE). First, we decentralize the proxy’s privileges of re-encrypting ciphertexts to resist collusion attack. Second, we carefully design the decryption token mechanism so that only the person who gets the correct token can do the decryption, which is authorized by all previous persons in the path, thus controlling the decryption privileges to solve the hop-skipping problem. Finally, we formally prove that our proposed CHRAP-PRE achieves IND-HRA security under the Decisional Bilinear Diffie-Hellman (DBDH) assumption, resisting both collusion and hop-skipping attacks. Our comprehensive performance evaluation demonstrates that our scheme offers enhanced security while reducing communication overhead compared to the state-of-the-art.
Yile Chen 0007, Jun Zhou 0018, Zhenfu Cao, Xiaolei Dong, Chunpeng Ge 0001
IEEE Internet Things J.5
2026 Distributed Privacy-Preserving Reinforcement Learning via Sparse Matrix Encryption for IoT
abstract
Reinforcement learning (RL) has been increasingly adopted in IoT systems for tasks such as resource allocation and control. However, in privacy-critical and resource-constrained environments, existing privacy-preserving RL schemes suffer from high computational cost, slow convergence, and limited scalability due to the use of homomorphic encryption or differential privacy. We propose a distributed privacy-preserving Q-learning framework that enables secure and efficient policy updates across multiple clients. Each client independently trains a local Q-table and encrypts it using a sparse matrix transformation combined with additive secret sharing of structured perturbations. The encrypted Q-tables are uploaded to a cloud server for aggregation and averaging without decryption. The encrypted global Q-table is then returned and decrypted locally using the inverse sparse matrix. Experimental results on four benchmark environments (CartPole-v1, MountainCar-v0, Acrobot-v1, and LunarLander-v3) show that our scheme achieves up to 92% reduction in computation time compared to the FHE-based method, while maintaining comparable reward performance and faster convergence.
Tong Ji, Yunting Tao, Fanyu Kong 0002, Chunpeng Ge 0001, Baodong Qin, Jia Yu 0003
IEEE Internet Things J.5
2026 Nonprofiled Incremental Learning-Based Side-Channel Attack on Lattice-Based KEMs: The Case Study of Kyber
abstract
Post-quantum key-encapsulation mechanisms (KEMs) usually use the well-known Fujisaki-Okamoto (FO) transformation during key decapsulation to achieve chosen ciphertext attack (CCA) security. In the FO transformation, the re-encryption procedure depends on the message. The side-channel leakage of re-encryption can be exploited to recover the coefficients of the secret key under chosen ciphertexts, even if the KEM scheme is CCA secure. However, it still requires a large amount of trace during the profiling and attacking phase. In this work, we introduce the first non-profiled deep learning-based attack on lattice-based KEMs. We propose a chosen ciphertexts method that is suitable for non-profiled deep learning-based attacks. The horizontal chunking strategy is employed to partition the coefficients into chunks, enabling the independent recovery of multiple secret key coefficients within each chunk. Then, we adopt an incremental learning strategy to allow the deep learning model to gradually learn the knowledge of each chunk. Moreover, we push the limits of traditional non-profiled deep learning-based attacks by combining the unsupervised domain adaptation with the correlation distinguisher, eliminating the necessity of neural network training for each possible key guess. The feasibility of the attack is verified by practical experiments for the unprotected and masked implementations of Kyber on the ARM Cortex-M4.
Yanbin Li 0001, Yikang Guo, Xinru Cong, Chunpeng Ge 0001, Zhen Qin 0002, Willy Susilo
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.5
2026 ESVPH: Efficient Searchable and Verifiable Data Sharing Scheme With Partial Hidden Policy for IoT
abstract
The Internet of Things (IoT) is a key engine of global socio-economic transformation, where data sharing stands as a central catalyst for the IoT market's growth. However, data security and privacy concerns significantly impede the advancement of IoT data sharing. Consequently, Attribute-Based Encryption (ABE), offering fine-grained access control, is increasingly favored by data users. Unfortunately, existing ABE schemes still face these drawbacks: (1) the encryption and decryption computation overhead grows linearly with attributes; (2) keyword searches within ciphertexts are intricate and inefficient; (3) the access policy is at higher risk of privacy disclosure. To address these issues, this paper presents an efficient searchable and verifiable scheme with partial hidden policy for IoT (ESVPH). This scheme not only provides flexible keyword-based search and re-encryption verification, but also achieves fixed costs for encryption, decryption, searching and verifying. Additionally, ESVPH introduces an access policy where attribute names are disclosed while their values remain concealed, thereby enhancing user privacy. In conclusion, the scheme offers outstanding performance in computation and communication, proving its feasibility for practical IoT data sharing through rigorous proofs and extensive experimentation.
Yong Xie 0003, Chunpeng Ge 0001, Cong Peng 0005, Meng Shen 0001
IEEE Trans. Dependable Secur. Comput.3
2026 Secure Outsourcing Scheme for FCM-PSO Based Medical Image Segmentation Algorithm
abstract
Machine learning algorithm for multi-modal image segmentation is extensively employed in medical analysis and diagnosis. Clustering represents a mainstream approach for image segmentation, with the fuzzy c-means and particle swarm optimization (FCM-PSO) algorithm garnering significant attention. As image segmentation tasks have substantial computational costs, the outsourcing scheme offers an effective solution by leveraging cloud servers to execute complex computations. Given that medical images contain sensitive patient information, the image segmentation outsourcing scheme must ensure data privacy and confidentiality. In this paper, we propose a secure outsourcing scheme for the FCM-PSO based image segmentation algorithm through a novel sparse matrix encryption method. By analyzing each stage of the image segmentation algorithm, we delegate the computationally intensive task of calculating the Euclidean distance to an untrusted cloud server. We utilize sparse matrices to obscure the private image data. These matrices are created by incorporating multiple small-sized random invertible matrices, thereby circumventing the local storage of generation factors. Additionally, we implement a lightweight verification method to verify the correctness of returned results. Experimental results show that our scheme improves the efficiency of the image segmentation task by 29.99% to 49.50% with the increasing of image set, compared to the original algorithm executed locally.
Xinrong Sun, Yunting Tao, Chunpeng Ge 0001, Chuan Ma 0001, Fanyu Kong 0002, Hanlin Zhang 0001, Jia Yu 0003
IEEE Trans. Dependable Secur. Comput.3
2026 On Exploiting Single-Trace Side-Channel Leakage of SEAL-Embedded Library
Yanbin Li 0001, Yikang Guo, Tingyu Gu, Chunpeng Ge 0001
IEEE Trans. Inf. Forensics Secur.4
2026 GDetox: Purifying Backdoor Encoder in Graph Self-Supervised Learning via Knowledge Distillation
abstract
Graph Neural Networks (GNNs) have powerful representation capabilities for graph data, achieving excellent performance across various fields. Considering the scarcity of labels in real-world scenarios, graph self-supervised learning (GSSL) has gained increasing attention due to its ability to train without relying on labels. However, recent studies have revealed that GNNs are vulnerable to stealthy backdoor attacks in GSSL scenarios, enabling the encoder to learn backdoor features simply by injecting triggers. Existing graph backdoor defense methods mainly focus on supervised settings and cannot be directly transferred to self-supervised scenarios due to the lack of label guidance. To bridge this gap, we proposeGDetox, the first backdoor defense approach against backdoored encoders in GSSL.GDetoxaims to eliminate backdoor logic in encoders while maintaining the encoder's original performance. Specifically,GDetoxcan purify the graph backdoor encoder based on the self-supervised distillation approach without relying on label information. Further, we introduce an adversarial contrastive learning that augments node representations without relying on labels to enhance teacher model performance, thereby improving distilled encoder performance. We evaluate the defense performance ofGDetoxon four node classifications and four graph classification datasets by comparing with four state-of-the-art (SOTA) defense methods against seven latest backdoor attack methods on GSSL. Extensive experiments demonstrate thatGDetoxfar outperforms the SOTA defense methods, reducing the attack success rate to 4% with negligible degradation in encoder performance (within 2%) in both node-level and graph-level tasks.
Hao Sui 0003, Jiale Zhang 0001, Bing Chen 0002, Chunpeng Ge 0001, Weizhi Meng 0001, Willy Susilo
IEEE Trans. Inf. Forensics Secur.5
2026 TraceCluster: A Lightweight and Adaptive Clustering-Based Subgraph Attention Network for APT Detection in Provenance Graphs
abstract
Provenance graph-based anomaly detection, particularly for Advanced Persistent Threat (APT) detection, addresses the issues of large-scale graphs and data imbalance. However, existing methods struggle with information loss, high computational complexity, and low detection accuracy. To address the above challenges, this paper proposes TraceCluster, a lightweight and adaptive clustering-based Subgraph Attention Network (SAN) for APT detection in provenance graph. TraceCluster mitigates the neighborhood explosion problem by clustering nodes to partition large-scale graphs, thus reducing reliance on the global graph while preserving local neighborhood information. Furthermore, the method dynamically models complex inter-node dependencies within subgraphs. It employs an attention mechanism to adaptively highlight the most relevant connections. This enhances node representations and improves overall feature extraction. This design substantially reduces memory consumption and avoids the high computational complexity of global graph processing. In addition, an adaptive category-weighting loss function assigns variable weights to different classes, improving the detection of rare and anomalous behaviors. Experimental results show that on the OpTC dataset, the currently faster method is 37-fold and 3-fold slower than our approach in terms of inference time respectively. Furthermore, in the nine real-world scenarios of four evaluated datasets, TraceCluster outperforms state-of-the-art (SOTA) approaches in terms of overall performance, especially in node-level APT detection tasks.
Lijuan Xu 0001, Zicheng Zhao, Dawei Zhao 0001, Zhen Wang 0004, Chunpeng Ge 0001
IEEE Trans. Inf. Forensics Secur.5
2026 PUDSQ: Privacy-Preserving User-Defined Skyline Query Processing With Function Secret Sharing
abstract
Skyline query is a fundamental technique in multi-criteria decision-making, aiming to extract “optimal” results that are not dominated by any other data points across all attributes. It has significant value in applications that require trade-offs among multiple criteria. However, existing skyline query methods face two critical limitations: (i) conventional approaches adopt fixed dominance relationships, making it difficult to capture personalized user preferences; and (ii) cloud-based deployment models risk exposing sensitive data and query logic, making it difficult to ensure data privacy and protect query patterns while maintaining efficiency. To address these issues, we propose Privacy-Preserving User-Defined Skyline Query (PUDSQ), a novel privacy-preserving user-defined skyline query framework, which integrates efficient cryptographic techniques–secret sharing (SS) and function secret sharing (FSS)–with a secure database shuffling mechanism to achieve efficient query processing while ensuring robust privacy guarantees. PUDSQ introduces three main innovations: (i) a privacy-preserving filtering framework based on FSS provides dual protection for both data content and user preferences, effectively concealing database content and query logic; (ii) an FSS-based secure protocol suite supporting user-defined attribute retrieval, constrained-region retrieval, and secure skyline filtering; and (iii) a high-dimensional data processing strategy that integrates dimensionality reduction with an Sort-Filter-Skyline (SFS)-based presorting approach to address the high-dimensional data processing challenge and significantly improve efficiency. Experimental results demonstrate that, under equivalent security guarantees, PUDSQ reduces query latency by 8%-90% compared with state-of-the-art solution, with particularly notable advantages in high-dimensional scenarios, achieving an effective efficiency-privacy trade-off.
Zeqian Wang, Hao Wang 0007, Ye Su 0001, Ziyu Niu, Zhi Li 0056, Jing Qin 0002, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.7
2025 FRFL: Fair and Robust Federated Learning Incentive Model Based on Game Theory
Haocheng Ye, Lu Zhou 0002, Chunpeng Ge 0001
ACISP (3)4
2025 New Permutation Decomposition Techniques for Efficient Homomorphic Permutation
abstract
Homomorphic permutation is fundamental to privacy-preserving computations based on batch-encoding homomorphic encryption. It underpins nearly all homomorphic matrix operations and predominantly influences their complexity. Permutation decomposition as a potential approach to optimize this critical component remains underexplored. In this paper, we propose novel decomposition techniques to optimize homomorphic permutations, advancing homomorphic encryption-based privacy-preserving computations. We start by defining an ideal decomposition form for permutations and propose an algorithm searching for depth-1 ideal decompositions. Based on this, we prove the full-depth ideal decomposability of permutations used in specific homomorphic matrix transposition (HMT) and multiplication (HMM) algorithms, allowing them to achieve asymptotic improvement in speed and rotation key reduction. As a demonstration of applicability, substituting the HMM components in the best-known inference framework of encrypted neural networks with our enhanced version shows up to a 3.9× reduction in latency. We further devise a new method for computing arbitrary homomorphic permutations, specifically those with weak structures that cannot be ideally decomposed. We design a network structure that deviates from the conventional scope of decomposition and outperforms the state-of-the-art technique under a limited rotation key budget, achieving a speed-up of up to 1.69 ×.
Xirong Ma, Junling Fang, Chunpeng Ge 0001, Dung Hoang Duong, Yali Jiang 0004, Yanbin Li 0001, Willy Susilo, Li-Zhen Cui 0001
CCS3
2025 Beyond Single Tabs: A Transformative Few-Shot Approach to Multi-Tab Website Fingerprinting Attacks
abstract
Website Fingerprinting (WF) attacks allow passive eavesdroppers to deduce the websites a user visits by analyzing encrypted traffic, threatening user privacy. While current WF attacks achieve high accuracy, they typically assume single-tab browsing, which is unrealistic as users often open multiple tabs, creating mixed traffic. Existing multi-tab WF approaches require large datasets and frequent retraining due to evolving website content, limiting their practicality. In this paper, we introduce Few-shot Multi-tab Website Fingerprinting (FMWF), a novel approach designed to address the limitations of existing multi-tab WF attacks. FMWF directly tackles the challenges of mixed, overlapping traffic traces generated from multi-tab browsing, leveraging two key innovations: (1) an advanced data augmentation technique that synthesizes realistic multi-tab traffic sequences from easily collected single-tab traces, thereby dramatically reducing the need for large-scale real-world traffic data; and (2) a powerful fine-tuning algorithm based on transfer learning that adapts pre-trained models to new, multi-tab environments with minimal additional data. This two-stage framework enables FMWF to capture the complex effectively, overlapping traffic patterns inherent in multi-tab browsing while maintaining a high level of flexibility and significantly lowering computational and data collection burdens. Our experiments, conducted using real traffic traces collected from three widely-used browsers-Microsoft Edge, Google Chrome, and Tor Browser-highlight the superior performance of FMWF in both closed-world and open-world scenarios. Notably, FMWF achieves a minimum 12.3% improvement in accuracy compared to ARES (SP'23) [7], TMWF (CCS'23) [13], and BAPM (ACSAC'21) [10] in the open-world scenario. The code with related datasets is available at https://github.com/WW-Meng/FMWF.
Wenwen Meng, Chuan Ma 0001, Ming Ding 0001, Chunpeng Ge 0001, Yuwen Qian, Tao Xiang 0001
WWW4
2025 Adaptive Chosen-Plaintext Deep-Learning-Based Side-Channel Analysis
abstract
Profiled side-channel analysis presents a significant risk to embedded devices in Internet of Things (IoT). Typically, a single trace is insufficient to successfully key recovery in practical scenarios. It still requires several traces based on Bayes’ posterior probability. In this article, we introduce a chosen-plaintext (CP) strategy into the deep learning-based profiled attacks to improve the attack efficiency. First, we present a general strategy to profile the leakage model by exploiting the sensitivity analysis and clustering analysis. The leakage model derived from deep neural network is to characterize the leakage of the target algorithm. Second, we propose an adaptive CP method in the deep learning-based attack, transforming the conditional probability distribution of the leakage into the entropy of the key candidates under the profiled leakage model. Finally, we evaluate the efficiency of the attack by practical measurements. The results demonstrate that the proposed method requires fewer traces to retrieve the key of AES on devices of different types, e.g., Smartcard, FPGA, and ARM. Moreover, our attack improves the attack efficiency on masked implementations.
Yanbin Li 0001, Yikang Guo, Chunpeng Ge 0001, Fanyu Kong 0002, Yongjun Ren
IEEE Internet Things J.4
2025 How to Securely Outsource the Multiple Kernel Fuzzy Clustering Task in Edge Computing
abstract
For the huge amount of data from the Internet of Things (IoT) devices, multiple kernel learning is a widely concerned issue in data analyzing, among which the multiple kernel fuzzy clustering (MKFC) algorithm is an effective approach for extracting linear features in high-dimensional space. For a time-consuming multiple kernel clustering task, it is meaningful to find a secure and efficient outsourcing scheme in the edge-end collaborative architecture, which utilizes edge computing resources while resisting untrusted edge servers. However, existing secure outsourcing schemes cannot align well with the distributed and real-time characteristics of edge computing due to their complex encryption processes. In this article, we propose a secure MKFC outsourcing scheme based on a novel matrix blinding method. The proposed novel matrix blinding method conducts two related encryption operations with disturbance terms, which avoids specific disturbance elimination computations, to reduce the computational burdens in the decryption phase. Additionally, we introduce a sampling verification method to detect the server’s deceptive behaviors. The theoretical analysis demonstrates that our scheme guarantees data privacy and has the capability to verify incorrect results. The experimental results indicate that our scheme is 6.73% superior to other schemes on average when conducting matrix outsourcing computation and enhances the efficiency of conducting the MKFC algorithm by 10.44% to 55.70% on different datasets.
Xinrong Sun, Yunting Tao, Fanyu Kong 0002, Chunpeng Ge 0001, Qiuliang Xu, Hanlin Zhang 0001
IEEE Internet Things J.5
2025 CFVDT: A Cost-Effective Data Trading Framework With Fine-Grained and Verifiable Access Control
Yu Tao 0004, Lu Zhou 0002, Hao Wang 0189, Liming Fang 0001, Chunpeng Ge 0001, Zhe Liu 0001
IEEE Internet Things J.7
2025 Efficient privacy-preserving outsourcing of imbalanced clustering in cloud computing
Xinrong Sun, Yunting Tao, Fanyu Kong 0002, Guoqiang Yang, Chunpeng Ge 0001, Qiuliang Xu
J. Inf. Secur. Appl.6
2025 TextDefense: Adversarial Text Detection Based on Word Importance Score Dispersion
abstract
Natural language processing (NLP) models are widely used in various scenarios, yet they are vulnerable to adversarial attacks. Existing works aim to mitigate this vulnerability, but each work targets a specific attack category or has computational overhead limitations, making them vulnerable to adaptive attacks. In this paper, we exhaustively investigate the adversarial attack algorithms in NLP and discover that existing attack algorithms mainly disrupt the importance distribution of words in a text. A well-trained model can distinguish subtle importance distribution differences between clean and adversarial texts. Based on this intuition, we propose TextDefense, a new adversarial example detection framework that utilizes the target model’s capability to defend against adversarial attacks, requiring no prior knowledge. Unlike previous approaches, TextDefense is attack-type agnostic and outperforms existing methods in experiments with different architectures, datasets, and attack methods. We also discover that the target model’s generalizability is a leading factor influencing the performance of TextDefense. Finally, we provide insights into the adversarial attacks in NLP and the principles of our defense method by analyzing the properties of the target model and the adversarial example.
Lujia Shen, Yuwen Pu, Xuhong Zhang 0002, Chunpeng Ge 0001, Xing Yang 0004, Hao Peng 0002, Wei Wang 0012, Shouling Ji
IEEE Trans. Dependable Secur. Comput.4
2025 SVOC: Secure Aggregatable and Extractable System for Outsourced Cloud Computation
abstract
With the rapid advancement of technology, cloud computing has emerged as the most popular and promising service platform. A cloud user can delegate heavy computation tasks to cloud servers. To ensure the correctness of outsourced processing (e.g., machine learning and data mining), the cloud server must prove that the processing has been executed properly. However, even without malicious intent, it is possible for a cloud server to produce incorrect results. Consequently, clients may outsource the same task to multiple cloud servers and receive various results, aiding them in selecting the best outcome. To protect data privacy, the cloud server must encrypt the results before sending them back to the user. Yet, processing and verifying encrypted results remain significant challenges. To avoid the expensive computational overhead of decrypting ciphertexts from cloud servers one by one, clients prefer to use homomorphic encryption (HE) to obtain the combined output from a single server. However, existing schemes fall short of efficiently verifying the correctness of computations over encrypted data processed by multiple cloud servers, especially in extracting the results computed by each server. In this paper, we introduce a new framework for verifiable outsourced computing systems. In this system, each cloud server's computation result is protected by Paillier encryption, and the edge server can verify these results using zero-knowledge proofs and aggregate the verified ciphertexts. The client can extract the combined plaintext through the Base-3 conversion algorithm to identify each cloud server's results and any non-participating servers. We also prove the security of our scheme and analyze its performance from both theoretical and experimental aspects. Performance analysis shows that our system significantly reduces the client's workload and is userfriendly
Willy Susilo, Yumei Li 0003, Fuchun Guo, Zhen Zhao 0005, Yannan Li 0001, Chunpeng Ge 0001
IEEE Trans. Dependable Secur. Comput.6
2025 AdaptiveShard: Enhancing Throughput and Security of Sharded Blockchain With Adaptive Verifiable Coding
abstract
The blockchain technology provides a revolutionary solution for information exchange through its decentralized, tamper-proof, and highly secure characteristics. It has wide application in many industries, with the potential to improve efficiency, reduce costs, and promote innovation. However, the full replication mechanism of blockchain results in the need for each device to store complete blockchain data, leading to inefficient storage. Additionally, as the scale of the blockchain network expands, the increasing data volume and frequent transactions can cause network congestion and latency, posing scalability issues for blockchain. Coded sharding blockchain has been proposed to address these issues. However, the current solutions face challenges such as dealing with malicious nodes and low computational efficiency, which hinder the enhancement of their scalability and computational performance. To resolve these problems, we propose AdaptiveShard by combining coded sharding blockchain with adaptive verifiable coded computing (AVCC). This solution is designed based on the Unspent Transaction Output (UTXO) model and is suitable for cryptocurrency transaction scenarios. Compared to traditional coded sharding blockchain solutions, AdaptiveShard can: 1) enhance the computational performance of coded sharding blockchain during block validation by combining AVCC with Gaussian variant of Freivalds algorithm (GVFA), reducing the decoding complexity toO(N2logN); 2) validate the computation results of each shard using GVFA and replace balance check verification functions with matrix multiplication, reducing the computational complexity of verification toO(√n); 3) reduce the additional number of nodes required to resolve malicious nodes from two to one using verifiable computation; 4) balance the system in the presence of straggler or malicious nodes through dynamic coding techniques, eliminating their impact and improving system reliability. Experiments demonstrate that at t=1000, the throughput is 25.6% higher compared to Polyshard. Compared to the solution without dynamic coding, the solution with dynamic coding can reduce the running time by 9.7% at t=50.
Yongjun Ren, Chunpeng Ge 0001, Huawei Huang
IEEE Trans. Inf. Forensics Secur.4
2025 GraphCleanse: Defending Backdoor Attacks in Graph Learning via Contrastive Training
abstract
Graph Neural Networks (GNNs) are highly susceptible to numerous adversarial attacks, among which the backdoor attack is one of the toughest to deal with due to the fact that it can lead to misclassification of the model. Similar to Deep Neural Networks (DNNs), backdoor attacks in GNNs work by an attacker changing a portion of the graph data with a hidden trigger and modifying their labels to target labels, which induces the model to learn the trigger feature during its training phase. Although recent defense techniques have emerged, approaches based on explainability and data isolation often fail to detect malicious samples with covert triggers, while discrepancy learning methods tend to degrade performance by removing useful features. To overcome these limitations, we propose a novel backdoor defense method, namedGraphCleanse, on GNNs that can effectively eliminate the possible backdoor features during the training process. Specifically,GraphCleansecan easily break the strong correlation between backdoor features and target labels based on graph contrastive training. To further improve the model accuracy, we present a mutual information maximization method to learn the important feature information in the labeled credible samples and unlabeled suspicious samples by clustering the features obtained from the graph contrastive encoder. Compared with the potential solutions, such as randomized smoothing,GraphCleanseeffectively avoids the negative influence of backdoored samples while maintaining a high model performance. Extensive experimental evaluations on four benchmark datasets demonstrate thatGraphCleansecan reduce the attack success rate to 10% with less performance degradation (within 7%).
Jiale Zhang 0001, Hao Sui 0003, Wanquan Zhu, Xiaobing Sun 0001, Chunpeng Ge 0001, Bing Chen 0002, Mingsheng Cao 0001
IEEE Trans. Inf. Forensics Secur.6
2025 ADSS: An Available-but-Invisible Data Service Scheme for Fine-Grained Usage Control
abstract
The demand for mobile terminals to participate in data services is increasingly vital. The General Data Protection Regulation (GDPR) has established several principled requirements for data services. Existing studies focusing on data service put emphasis on data privacy and accessibility. However, they face challenges in achieving data forgetability and portability on mobile devices under GDPR and lack consideration of usage control. In this article, we propose ADSS, an app-level data service scheme for mobile devices that can beavailable-but-invisibleand guarantee fine-grained usage control. ADSS addresses the challenges by executing the logic of data usage in the Trusted Execution Environment (TEE) and managing the TEE states (i.e., data usage states) in the blockchain smart contracts. It not only satisfies the requirements of GDPR, ensuring strong security and confidentiality guarantees, but also enables the functionality of “pay-per-use”. We implement a prototype of the ADSS framework based on ARM Trustzone and conduct experimental evaluations. The results demonstrate that our scheme brings high efficiency compared with other data service schemes and exhibits feasibility on mobile-grade devices.
Hao Wang 0189, Jun Wang 0020, Chunpeng Ge 0001, Lu Zhou 0002, Zhe Liu 0001, Weibin Wu 0003, Mingsheng Cao 0001
IEEE Trans. Serv. Comput.3
2024 CARE-EMRs: Efficient and Privacy-Preserving Data Sharing Framework for Electronic Medical Records
abstract
Cross-institutional Electronic Medical Records (EMRs) sharing significantly improves healthcare quality and reduces costs. Current EMRs are often stored on cloud servers and protected by Attribute-based Encryption (ABE) for access control. Cross-institutional sharing allows doctors to request EMRs access from target Healthcare Institutions (HIs) through attribute-based collaboration, enabling flexible and secure access. However, existing collaboration in practical EMRs sharing scenarios suffers from inefficiency, hindering timely access and treatment. This paper proposes an efficient and privacy-preserving data sharing framework for EMRs, called CARE-EMRs. CARE-EMRs enables efficient EMRs data access for doctors across different HIs through an outsourcing mechanism. Furthermore, we designed an improved cryptographic primitive PPD-CP-ABE to serve as the security foundation for CARE-EMRs framework, ensuring privacy of the outsourced process. We prove the security of CARE-EMRs. Performance analysis indicates that it significantly reduces the computation and communication overhead.
Yu Tao 0004, Lu Zhou 0002, Chunpeng Ge 0001
BIBM5
2024 Improving the Robustness of Transformer-based Large Language Models with Dynamic Attention
Lujia Shen, Yuwen Pu, Shouling Ji, Changjiang Li, Xuhong Zhang 0002, Chunpeng Ge 0001, Ting Wang 0006
NDSS6
2024 SMDT: A Blockchain-Based Secure Multi-version Data Trading Scheme with Fair Profit Sharing
Yu Tao 0004, Hao Wang 0189, Lu Zhou 0002, Chunpeng Ge 0001
SecureComm (2)6
2024 Improved privacy-preserving PCA using optimized homomorphic matrix multiplication
Xirong Ma, Chuan Ma 0001, Yali Jiang 0004, Chunpeng Ge 0001
Comput. Secur.4
2024 ORR-CP-ABE: A secure and efficient outsourced attribute-based encryption scheme with decryption results reuse
Yu Tao 0004, Chunpeng Ge 0001, Lu Zhou 0002, Shouchen Zhou, Yongjing Zhang, Jiarong Liu, Liming Fang 0001
Future Gener. Comput. Syst.3
2024 Accelerating Graph Embedding Through Secure Distributed Outsourcing Computation in Internet of Things
abstract
With the advancement of the Internet of Things (IoT), numerous machine learning applications on IoT are encountering performance bottlenecks. Graph embedding is an emerging type of machine learning that has achieved commendable results in areas such as network anomaly detection, malware detection, IoT device management, and service recommendation within the Internet of Things. However, for some resource-constrained IoT devices, computing graph embedding algorithms is highly complex and time-consuming. In this paper, we introduce an efficient and secure distributed outsourcing scheme, employing four non-colluding cloud servers to facilitate the computation of graph embedding for IoT devices. Our scheme utilizes a novel blinding factor generated through QR decomposition to blind matrices containing sensitive information. We partition the blinded matrix into several segments, distributing different small matrix blocks across four servers, each of which executes only a portion of the computational tasks. The proposed outsourcing solution ensures the privacy of input and output information is not compromised. In our scheme, we utilize an effective verification method that can detect the erroneous behaviors of cloud servers with a probability close to one. Theoretical analysis and experimental results indicate that our solution achieves a computational efficiency of (35m2+2m)/(3m3) compared to the original algorithm.
Pengyu Cui, Yunting Tao, Bin Zhen, Fanyu Kong 0002, Chunpeng Ge 0001, Chuan Ma 0001, Jia Yu 0003
IEEE Internet Things J.5
2024 Secure outsourced decryption for FHE-based privacy-preserving cloud computing
Xirong Ma, Yuchang Hu, Yunting Tao, Yali Jiang 0004, Yanbin Li 0001, Fanyu Kong 0002, Chunpeng Ge 0001
J. Inf. Secur. Appl.8
2024 SF-CABD: Secure Byzantine fault tolerance federated learning on Non-IID data
Xiaoci Lin, Yanbin Li 0001, Xuehui Wu, Chunpeng Ge 0001
Knowl. Based Syst.6
2024 A Publicly Verifiable Outsourcing Matrix Computation Scheme Based on Smart Contracts
abstract
Matrix computation is a crucial mathematical tool in scientific fields such as Artificial Intelligence and Cryptographic computation. However, it is difficult for resource-limited devices to execute large-scale matrix computations independently. Outsourcing matrix computation (OMC) is a promising solution that engages a cloud server to process complicated matrix computations for resource-limited devices. However, existing OMC schemes lack public verifiability, and thus resource-limited devices cannot verdict the correctness of the computing results. In this paper, for the first time, we propose a smart contract-based OMC scheme that publicly verifies the outsourcing matrix computation results. In our scheme, a smart contract running over the blockchain serves as a decentralized trusted third party to ensure the correctness of the matrix computation results. To overcome the Verifier's Dilemma in the blockchain, we present a blockchain-compatible matrix verification method that decreases the time complexity from$O(n^{3})$to$O(n^{2})$by utilizing a blinding method with the check digit and padding matrices. We make the verification become the form of comparing whether two results are identical rather than naive re-computing. Finally, we perform experiments on Ethereum and ARM Cortex-M4 and give in-depth analysis and performance evaluation, demonstrating our scheme's practicability and effectiveness.
Hao Wang 0189, Chunpeng Ge 0001, Lu Zhou 0002, Zhe Liu 0001, Dongwan Lan, Xiaozhen Lu, Danni Jiang
IEEE Trans. Cloud Comput.2
2024 Attribute-Based Encryption With Reliable Outsourced Decryption in Cloud Computing Using Smart Contract
abstract
Outsourcing the heavy decryption computation to a cloud service provider has been a promising solution for a resource-constrained mobile device to deploy an attribute-based encryption scheme. However, the current attribute based encryption with outsourced decryption schemes only enable the mobile device to verify whether the cloud service provider has returned a correct decryption result, they lack a mechanism to enable the cloud service provider to escape from a mobile device's wrong claim if it has returned a correct decryption result. This article, for the first time, proposes an attribute based encryption with reliable outsourced decryption scheme using the blockchain smart contract. In the proposed scheme, not only can the mobile device verify whether the cloud service provider has returned a correct decryption result, but also the cloud service provider can escape from a wrong claim if the returned decryption result is correct. Moreover, our system achieves the fairness property, which means the cloud service provider can get the reward from the mobile device if and only if it has returned a correct decryption result. Finally, we conduct an implementation to demonstrate that the proposed scheme is practical and efficient.
Chunpeng Ge 0001, Zhe Liu 0001, Willy Susilo, Liming Fang 0001, Hao Wang 0189
IEEE Trans. Dependable Secur. Comput.1
2024 Attribute-Based Proxy Re-Encryption With Direct Revocation Mechanism for Data Sharing in Clouds
abstract
Cloud computing, which provides adequate storage and computation capability, has been a prevalent information infrastructure. Secure data sharing is a basic demand when data was outsourced to a cloud server. Attribute-based proxy re-encryption has been a promising approach that allows secure encrypted data sharing on clouds. With attribute-based proxy re-encryption, a delegator can designate a set of shared users through issuing a re-encryption key which will be used by the cloud server to transform the delegator's encrypted data to the shared users’. However, the existing attribute-based proxy re-encryption schemes lack a mechanism of revoking users from the sharing set which is critical for data sharing systems. Therefore, in this article, we propose a concrete attribute-based proxy re-encryption with direct revocation mechanism (ABPRE-DR) for encrypted data sharing that enables the cloud server to directly revoke users from the original sharing set involved in the re-encryption key. We implemented the new schemes and evaluated its performance. The experimental results show that the proposed ABPRE-DR scheme is efficient and practical.
Chunpeng Ge 0001, Willy Susilo, Zhe Liu 0001, Joonsang Baek, Xiapu Luo, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2024 BadCleaner: Defending Backdoor Attacks in Federated Learning via Attention-Based Multi-Teacher Distillation
abstract
As a privacy-preserving distributed learning paradigm, federated learning (FL) has been proven to be vulnerable to various attacks, among which backdoor attack is one of the toughest. In this attack, malicious users attempt to embed backdoor triggers into local models, resulting in the crafted inputs being misclassified as the targeted labels. To address such attack, several defense mechanisms are proposed, but may lose the effectiveness due to the following drawbacks. First, current methods heavily rely on massive labeled clean data, which is an impractical setting in FL. Moreover, an in-avoidable performance degradation usually occurs in the defensive procedure. To alleviate such concerns, we proposeBadCleaner, a lossless and efficient backdoor defense scheme via attention-based federated multi-teacher distillation. Firstly,BadCleanercan effectively tune the backdoored joint model without performance degradation, by distilling the in-depth knowledge from multiple teachers with only a small part of unlabeled clean data. Secondly, to fully eliminate the hidden backdoor patterns, we present an attention transfer method to alleviate the attention of models to the trigger regions. The extensive evaluation demonstrates thatBadCleanercan reduce the success rates of state-of-the-art backdoor attacks without compromising the model performance.
Jiale Zhang 0001, Chunpeng Ge 0001, Chuan Ma 0001, Yanchao Zhao, Xiaobing Sun 0001, Bing Chen 0002
IEEE Trans. Dependable Secur. Comput.3
2024 Voltran: Unlocking Trust and Confidentiality in Decentralized Federated Learning Aggregation
abstract
The decentralized Federated Learning (FL) paradigm built upon blockchain architectures leverages distributed node clusters to replace the single server for executing FL model aggregation. This paradigm tackles the vulnerability of the centralized malicious server in vanilla FL and inherits the trustfulness and robustness offered by blockchain. However, existing blockchain-enabled schemes face challenges related to inadequate confidentiality on models and limited computational resources of blockchains. In this paper, we present Voltran, an innovative hybrid platform designed to achieve trust, confidentiality, and robustness for FL based on the combination of the Trusted Execution Environment (TEE) and blockchain technology. We offload the FL aggregation computation into TEE to provide an isolated, trusted and customizable off-chain execution and then guarantee the authenticity and verifiability of aggregation results on the blockchain. Moreover, we provide strong scalability on multiple FL scenarios by introducing a multi-SGX parallel execution strategy to amortize the large-scale FL workload. We implement a prototype of Voltran and conduct a comprehensive performance evaluation. Extensive experimental results demonstrate that Voltran incurs minimal additional overhead while guaranteeing trust, confidentiality, and authenticity, and it significantly brings a significant speed-up compared to state-of-the-art ciphertext aggregation schemes.
Hao Wang 0189, Yichen Cai 0002, Jun Wang 0020, Chuan Ma 0001, Chunpeng Ge 0001, Xiangmou Qu, Lu Zhou 0002
IEEE Trans. Inf. Forensics Secur.5
2024 FLPurifier: Backdoor Defense in Federated Learning via Decoupled Contrastive Training
abstract
Recent studies have demonstrated that backdoor attacks can cause a significant security threat to federated learning. Existing defense methods mainly focus on detecting or eliminating the backdoor patterns after the model is backdoored. However, these methods either cause model performance degradation or heavily rely on impractical assumptions, such as labeled clean data, which exhibit limited effectiveness in federated learning. To this end, we proposeFLPurifier, a novel backdoor defense method in federated learning that can effectively purify the possible backdoor attributes before federated aggregation. Specifically,FLPurifiersplits a complete model into a feature extractor and classifier, in which the extractor is trained in a decoupled contrastive manner to break the strong correlation between trigger features and the target label. Compared with existing backdoor mitigation methods,FLPurifierdoesn’t rely on impractical assumptions since it can effectively purify the backdoor effects in the training process rather than an already trained model. Moreover, to decrease the negative impact of backdoored classifiers and improve global model accuracy, we further design an adaptive classifier aggregation strategy to dynamically adjust the weight coefficients. Extensive experimental evaluations on six benchmark datasets demonstrate thatFLPurifieris effective against known backdoor attacks in federated learning with negligible performance degradation and outperforms the state-of-the-art defense methods.
Jiale Zhang 0001, Xiaobing Sun 0001, Chunpeng Ge 0001, Bing Chen 0002, Willy Susilo, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.4
2024 Hierarchically Contrastive Hard Sample Mining for Graph Self-Supervised Pretraining
abstract
Contrastive learning has recently emerged as a powerful technique for graph self-supervised pretraining (GSP). By maximizing the mutual information (MI) between a positive sample pair, the network is forced to extract discriminative information from graphs to generate high-quality sample representations. However, we observe that, in the process of MI maximization (Infomax), the existing contrastive GSP algorithms suffer from at least one of the following problems: 1) treat all samples equally during optimization and 2) fall into a single contrasting pattern within the graph. Consequently, the vast number of well-categorized samples overwhelms the representation learning process, and limited information is accumulated, thus deteriorating the learning capability of the network. To solve these issues, in this article, by fusing the information from different views and conducting hard sample mining in a hierarchically contrastive manner, we propose a novel GSP algorithm called hierarchically contrastive hard sample mining (HCHSM). The hierarchical property of this algorithm is manifested in two aspects. First, according to the results of multilevel MI estimation in different views, the MI-based hard sample selection (MHSS) module keeps filtering the easy nodes and drives the network to focus more on hard nodes. Second, to collect more comprehensive information for hard sample learning, we introduce a hierarchically contrastive scheme to sequentially force the learned node representations to involve multilevel intrinsic graph features. In this way, as the contrastive granularity goes finer, the complementary information from different levels can be uniformly encoded to boost the discrimination of hard samples and enhance the quality of the learned graph embedding. Extensive experiments on seven benchmark datasets indicate that the HCHSM performs better than other competitors on node classification and node clustering tasks. The source code of HCHSM is available at https://github.com/WxTu/HCHSM.
Wenxuan Tu, Shaohua Kevin Zhou, Xinwang Liu 0002, Chunpeng Ge 0001, Zhiping Cai, Yue Liu 0008
IEEE Trans. Neural Networks Learn. Syst.4
2024 GrabPhisher: Phishing Scams Detection in Ethereum via Temporally Evolving GNNs
abstract
Phishing scams are one of Ethereum's most representative security risks that can defraud many transactions in a short period and severely threaten network security. Existing deep learning-based phishing scam detection methods mainly rely on constructing static transaction graphs which are assumed to be accessible before model training. However, static methods that have a high false positive rate to detect newly generated phishing scams by adding this newly generated data to existing algorithms for execution, due to new accounts and transactions constantly appearing in the real-world Ethereum network. Therefore, this article, for the first time, proposes a novel evolve-based phishing scams detection method (named GrabPhisher) that extracts temporal features of accounts and captures information about the dynamic topology of the graph as it evolves. Specifically, GrabPhisher can build the evolutionary pattern of accounts trading on Ethereum as a diffusion network graph in continuous time. It can continue to capture new transaction features based on existing transactions, which facilitates the identification of phishing accounts. Additionally, we implement GrabPhisher on the real-world Ethereum phishing scams datasets. Extensive experimental results demonstrate that GrabPhisher can effectively extract dynamic temporal features and outperform state-of-the-art methods (95% Recall, and 88% F1-score).
Jiale Zhang 0001, Hao Sui 0003, Xiaobing Sun 0001, Chunpeng Ge 0001, Lu Zhou 0002, Willy Susilo
IEEE Trans. Serv. Comput.4
2023 Mining for Better: An Energy-Recycling Consensus Algorithm to Enhance Stability with Deep Learning
Zhen Xia, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
ISPEC8
2023 MMDSSE: Multi-client and Multi-keyword Dynamic Searchable Symmetric Encryption for Cloud Storage
abstract
Since data outsourcing poses privacy concerns with data leakage, searchable symmetric encryption (SSE) has emerged as a powerful solution that enables clients to perform query operations on encrypted data while preserving their privacy. Dynamic SSE schemes have been proposed to handle update operations. However, it is shown that updates might increase the risk of information leakage. Meanwhile, to meet the requirement of real-world applications, it is desirable to have the searchable encryption scheme which supports both multiple clients and multi-keyword queries. To address these issues, this paper proposes MMDSSE, a multi-client forward secure dynamic SSE scheme that supports multi-keyword queries. MMDSSE allows the clients narrow down the results by providing an arbitrary subset of the entire archive, and thus suitable for cloud storage environment. Security analysis and experimental evaluations show that MMDSSE is secure and efficient.
Panyu Wu, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
PST9
2023 MDPPC: Efficient Scalable Multiparty Delegated PSI and PSI Cardinality
abstract
Private Set Intersection (PSI) is one of the most important functions in secure multiparty computation (MPC). PSI protocols have been a practical cryptographic primitive and there are many privacy-preserving applications based on PSI protocols such as computing conversion of advertising and distributed computation. Private Set Intersection Cardinality (PSI-CA) is a useful variant of PSI protocol. PSI and PSI-CA allow several parties, each holding a private set, to jointly compute the intersection and cardinality, respectively without leaking any additional information. Nowadays, most PSI protocols mainly focus on two-party settings, while in multiparty settings, parties are able to share more valuable information and thus more desirable. On the other hand, with the advent of cloud computing, delegating computation to an untrusted server becomes an interesting problem. However, most existing delegated PSI protocols are unable to efficiently scale to multiple clients. In order to solve these problems, this paper proposes MDPPC, an efficient PSI protocol which supports scalable multiparty delegated PSI and PSI-CA operations. Security analysis shows that MDPPC is secure against semi-honest adversaries and it allows any number of colluding clients. For 15 parties with set size of 220on server side and 216on clients side, MDPPC costs only 81 seconds in PSI and 80 seconds in PSI-CA, respectively. The experimental results show that MDPPC has high scalability.
Xiaolei Dong, Zhenfu Cao, Yunbo Yang, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su, Zongyang Hou
PST9
2023 Efficient and Low Overhead Website Fingerprinting Attacks and Defenses based on TCP/IP Traffic
abstract
Website fingerprinting attack is an extensively studied technique used in a web browser to analyze traffic patterns and thus infer confidential information about users. Several website fingerprinting attacks based on machine learning and deep learning tend to use the most typical features to achieve a satisfactory performance of attacking rate. However, these attacks suffer from several practical implementation factors, such as a skillfully pre-processing step or a clean dataset. To defend against such attacks, random packet defense (RPD) with a high cost of excessive network overhead is usually applied. In this work, we first propose a practical filter-assisted attack against RPD, which can filter out the injected noises using the statistical characteristics of TCP/IP traffic. Then, we propose a list-assisted defensive mechanism to defend the proposed attack method. To achieve a configurable trade-off between the defense and the network overhead, we further improve the list-based defense by a traffic splitting mechanism, which can combat the mentioned attacks as well as save a considerable amount of network overhead. In the experiments, we collect real-life traffic patterns using three mainstream browsers, i.e., Microsoft Edge, Google Chrome, and Mozilla Firefox, and extensive results conducted on the closed and open-world datasets show the effectiveness of the proposed algorithms in terms of defense accuracy and network efficiency.
Guodong Huang, Chuan Ma 0001, Ming Ding 0001, Yuwen Qian, Chunpeng Ge 0001, Liming Fang 0001, Zhe Liu 0001
WWW5
2023 Tips: towards automating patch suggestion for vulnerable smart contracts
Qianguo Chen, Teng Zhou, Kui Liu 0001, Li Li 0029, Chunpeng Ge 0001, Zhe Liu 0001, Jacques Klein, Tegawendé F. Bissyandé
Autom. Softw. Eng.5
2023 Geometric Searchable Encryption Without False Positive And Its Applications
abstract
Abstract As a prominent cryptographic tool, geometric searchable encryption (GSE) can be applied in many scenarios, such as location-based services (LBS), social networks and vehicle networks. Unfortunately, most of existing searchable encryption schemes supporting the functionality of geometric range searches suffer from false positives, which will lead people to make a wrong decision and further raise some serious consequences such as financial loss. In addition, some of them are designed under a symmetric system, which is not enough flexible deployed in LBS since in a symmetric system only a private key holder creates ciphertext, whereas in a public-key system anyone who holds a public key can produce ciphertext. In this paper, we intend to design a novel GSE scheme without any false positive under a public-key system supporting arbitrary geometric area searches, which is able to guarantee an accurate query result. Toward this goal, we develop a novel technique in handling the relation between a point and any convex polygon in combination with an inner product encryption, which is able to support arbitrary convex polygon range searches without any false positive. A comprehensive experiment demonstrates that, compared with the known schemes, our scheme possesses a 100% accuracy as well as an acceptable efficiency in the sense that it can guarantee that all files retrieved by users are exactly matched ones. Finally, we provide two practical examples of our GSE scheme: privacy-preserving friend-nearby notification with a common point of interest and privacy-preserving parking monitor and guiding system.
Zhenhua Chen 0001, Jingjing Nie, Zhanli Li, Chunpeng Ge 0001, Willy Susilo
Comput. J.4
2023 Smart Optimization Solution for Channel Access Attack Defense Under UAV-Aided Heterogeneous Network
abstract
6G-based wireless communication system is poised to redefine the next-generation network landscape by enabling novel services and applications, such as intelligent link establishment, power control, data collection, transmission, and distribution. However, security issues, particularly recently revealed channel access attack (CAA), present significant challenges to performance optimization tasks in the heterogeneous wireless networks of 6G, namely, Age of Information (AoI) oriented Network (AoN), Throughput oriented Network (ToN), and Latency oriented Network (LoN). To address these challenges, this article presents a game theory-based smart optimization solution to enable unmanned aerial vehicles (UAV) to resist CAA within a 6G-based heterogeneous network. Our methodology begins by outlining the advantages and challenges associated with UAV usage, followed by the design of performance indicators and intelligent resource allocation schemes under the influence of CAA. Subsequently, we introduce definitions and categories within game theory, encompassing the concept and equilibrium of three typical game models. The efficacy of our proposed framework is validated through simulation results, which demonstrate the achievement of optimal AoI, enhanced throughput, and reduced latency compared with baseline methodologies when countering CAA in a UAV-assisted heterogeneous network.
Yaoqi Yang, Muhammad Bilal 0003, Weizheng Wang 0001, Moez Krichen, Abeer Abdullah Alsadhan, Chunpeng Ge 0001
IEEE Internet Things J.7
2023 Efficient transformer with code token learner for code clone detection
Aiping Zhang, Liming Fang 0001, Chunpeng Ge 0001, Piji Li, Zhe Liu 0001
J. Syst. Softw.3
2023 NoSneaky: A Blockchain-Based Execution Integrity Protection Scheme in Industry 4.0
abstract
The advancement of information technology allows the creation of smart devices that not only are programable, but also can perform machine-to-machine communication in order to reach a flexible large-scale manufacturing strategy in Industry 4.0. However, as more components are connected to the Internet, cyber-criminals can perform malicious actions remotely. As one lasting threat, sabotaging smart devices' execution integrity can cause a large financial loss, i.e., causing malfunctioning. Hence, it is important to secure the execution integrity of smart devices in Industry 4.0. Motivated by the emerging blockchain technology, in this paper, we focus on how blockchain can help Industry 4.0 application protect execution integrity and propose a blockchain-based execution protection scheme namedNoSneaky, which is low-cost and can be easily integrated into the current production systems. In the evaluation, we demonstrate its performance and effectiveness in securing the execution integrity.
Wei-Yang Chiu, Weizhi Meng 0001, Chunpeng Ge 0001
IEEE Trans. Ind. Informatics3
2023 Reliable Fix Patterns Inferred from Static Checkers for Automated Program Repair
abstract
Fix pattern-based patch generation is a promising direction in automated program repair (APR). Notably, it has been demonstrated to produce more acceptable and correct patches than the patches obtained with mutation operators through genetic programming. The performance of pattern-based APR systems, however, depends on the fix ingredients mined from fix changes in development histories. Unfortunately, collecting a reliable set of bug fixes in repositories can be challenging. In this article, we propose investigating the possibility in an APR scenario of leveraging fix patterns inferred from code changes that address violations detected by static analysis tools. To that end, we build a fix pattern-based APR tool, Avatar , which exploits fix patterns of static analysis violations as ingredients for the patch generation of repairing semantic bugs. Evaluated on four benchmarks (i.e., Defects4J, Bugs.jar, BEARS, and QuixBugs), Avatar presents the potential feasibility of fixing semantic bugs with the fix patterns inferred from the patches for fixing static analysis violations and can correctly fix 26 semantic bugs when Avatar is implemented with the normal program repair pipeline. We also find that Avatar achieves performance metrics that are comparable to that of the closely related approaches in the literature. Compared with CoCoNut, Avatar can fix 18 new bugs in Defects4J and 3 new bugs in QuixBugs. When compared with HDRepair, JAID, and SketchFix, Avatar can newly fix 14 Defects4J bugs. In terms of the number of correctly fixed bugs, Avatar is also comparable to the program repair tools with the normal fault localization setting and presents better performance than most program repair tools. These results imply that Avatar is complementary to current program repair approaches. We further uncover that Avatar can present different bug-fixing performances when it is configured with different fault localization tools, and the stack trace information from the failed executions of test cases can be exploited to improve the bug-fixing performance of Avatar by fixing more bugs with fewer generated patch candidates. Overall, our study highlights the relevance of static bug-finding tools as indirect contributors of fix ingredients for addressing code defects identified with functional test cases (i.e., dynamic information).
Kui Liu 0001, Jingtang Zhang, Li Li 0029, Anil Koyuncu, Dongsun Kim 0001, Chunpeng Ge 0001, Zhe Liu 0001, Jacques Klein, Tegawendé F. Bissyandé
ACM Trans. Softw. Eng. Methodol.6
2023 Geometric Searchable Encryption for Privacy-Preserving Location-Based Services
abstract
Location data play an important role in location-based services (LBS) since they can help a service provider analyze users’ daily activities and further derive users’ behavioral patterns. However, in the meanwhile the use of the location data in LBS can also enable the service provider to track users’ journeys which will reveal their personal information, such as house address and places of interest they visited, all of which users are usually unwilling to disclose. Therefore, security and privacy incidents can and do occur often. In this article, aiming at how to hide location privacy and meanwhile provide an accurate search for LBS, we design a new geometric searchable encryption scheme under a public-key system (a.k.a. asymmetric system) for different types of geometric range queries, which enables the service provider to respond to the range queries from users accurately without learning the information about users’ location. Towards this goal, we first exploit a novel encoding, and then develop some sophisticated transformations in combination with a special pairing function, which eventually converts different types of geometric range queries in LBS into different inner product problems. Finally, we present our construction by virtue of the techniques above with the inner product encryption technique. In addition, a comprehensive experimental analysis running on a specific application of privacy-preserving LBS and comparison demonstrate, our proposal is able to guarantee a higher accuracy for users’ range queries without any false positive, and meanwhile express richer queries. Furthermore, we show another application of our proposal to privacy-preserving remote medical diagnosis at the end of this article.
Zhenhua Chen 0001, Jingjing Nie, Li Zhan-Li, Willy Susilo, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.5
2023 Lightweight Privacy-Preserving Federated Incremental Decision Trees
abstract
Tree-based models are wildly adopted in various real-world scenarios. Recently, there is a growing interest in vertical federated tree-based model learning to build tree-based models by exploiting data from multiple organizations without violating data privacy regulations. However, most existing work focuses on batch learning settings where all training samples are prepared at once. They cannot be applied to scenarios where local samples come in a streaming manner. Additionally, the present federated learning algorithms suffer from inference attacks. In this paper, we present a novel solution that enables different organizations to jointly train a tree-based model in an incremental and privacy-preserving manner. Our solution is based on Very Fast Decision Tree (VFDT) for incrementally building a tree model. Since data statistics exchanged in the training process may implicitly disclose private information, we propose a protection mechanism based on order-preserving encryption. To further improve the efficiency of the solution, we compress the size of statistics by means of regional counting, which not only maintains model accuracy but also enhances privacy. We conduct extensive experiments on various real-world datasets and the results show the superiority of our solution in terms of both efficiency and privacy.
Chunpeng Ge 0001, Bingzhe Wu, Zhe Liu 0001
IEEE Trans. Serv. Comput.2
2023 Secure Replication-Based Outsourced Computation Using Smart Contracts
abstract
The replication-Based Outsourced Computation (RBOC) mechanism allows a client to outsource the same computing job to multiple contractors and the honest contractors will get paid in the incentivized system based on the fact that a majority of contractors will honestly perform the computation. As self-executing contracts, smart contracts are utilized in the decentralized blockchain networks to execute coded programs automatically transparently, and publicly. It is natural to apply smart contracts to RBOC to improve performance by setting smart contracts as the converter between the client and contractors to reduce the load on the client. However, it is infeasible to directly combine these two blocks together because the data including returned computing results from contractors in the decentralized blockchain are in the form of plaintexts such that some lazy contractors could copy others’ results as their own and still get paid, which will compromise the security of RBOC. The existing public-key encryption with equality test (PKEET) is a promising candidate solution to stop the above lazy contractors, where the results are encrypted by PKEET and then transferred without hindering smart contracts to compare the equality of underlying results. Unfortunately, we found that the advanced lazy contractors can still compromise security by forging ciphertexts to pass the equality test only with the encrypted results of other contractors. In this paper, to achieve security against lazy contractors, we introduce the notion of PKEET against lazy encryptors (PKEET-LE). Besides the fundamental property of PKEET that performs equality test on ciphertexts without decryption, PKEET-LE additionally realizes the security against the lazy encryptors who aim to forge a ciphertext for a given one to pass the equality test between them without the knowledge of the underlying plaintext. We further propose a concrete and practical PKEET-LE construction along with formal security proof. Finally, we conduct a performance evaluation to demonstrate that our PKEET-LE scheme is efficient and practical in the RBOC system using smart contracts.
Willy Susilo, Fuchun Guo, Zhen Zhao 0005, Yinhao Jiang, Chunpeng Ge 0001
IEEE Trans. Serv. Comput.5
2023 Privacy-Preserving Classification in Multiple Clouds eHealthcare
abstract
Internet of Things (IoT) is increasingly being used in real life, especially in the eHealthcare field. Among eHealthcare, the application of predicting patients' health status based on their daily activity data which is collected by IoT equipment has attracted extensive attentions and researches. In this application, patients' data which are treated as time-series data are transmitted to healthcare center (HC), then HC makes predictions based on an established classification model. However, making predictions using classification models requires a lot of computing resources, while HC usually cannot afford such numerous calculations. The use of the cloud solves the problem of insufficient computing resources, but it causes another problem, namely the leakage of user privacy. In particular, not only patients' data leak patients' privacy information, the classification model also causes the privacy disclosure of patients and HC. We design a new system model and propose an algorithm which can protect patients' data and classification model from leakage and offload calculation to multiple clouds. Our algorithm can better protect privacy of patients and HC in more complex classification scene, and can effectively reduce the computational cost of the healthcare center
Shenqing Wang, Chunpeng Ge 0001, Lu Zhou 0002, Huaqun Wang, Zhe Liu 0001, Jian Wang 0038
IEEE Trans. Serv. Comput.2
2022 CCOM: Cost-Efficient and Collusion-Resistant Oracle Mechanism for Smart Contracts
Hao Wang 0007, Chunpeng Ge 0001, Lu Zhou 0002, Qiong Huang 0001, Lanju Kong, Li-Zhen Cui 0001, Zhe Liu 0001
ACISP3
2022 A Privacy-Preserving Distributed Machine Learning Protocol Based on Homomorphic Hash Authentication
Lisong Wang, Weizhi Meng 0001, Chunpeng Ge 0001
NSS5
2022 Robust privacy-preserving federated learning framework for IoT devices
abstract
Federated Learning (FL) is a framework where multiple parties can train a model jointly without sharing private data. Private information protection is a critical problem in FL. However, the communication overheads of existing solutions are too heavy for IoT devices in resource-constrained environments. Additionally, they cannot ensure robustness when IoT devices become offline. In this paper, Democratic Federated Learning (DemoFL) is proposed, which is a privacy-preserving FL framework that has sufficiently low communication overheads. DemoFL involves a consensus module to ensure the system is robust. It also utilizes a tree structure to reduce the time communication overheads and realizes high robustness without reducing accuracy. The proposed algorithm reduces the communication complexity of aggregation at training by M $M$ times, M $M$ being a controllable parameter. Sufficient experiments have been conducted to evaluate the efficiency of the proposed method. The experimental results also demonstrate the practicality of the proposed framework for IoT devices in unstable environments.
Lu Zhou 0002, Chunpeng Ge 0001, Juan Li 0011, Zhe Liu 0001
Int. J. Intell. Syst.3
2022 A Secure Revocable Fine-Grained Access Control and Data Sharing Scheme for SCADA in IIoT Systems
abstract
The supervisory control and data acquisition (SCADA) system is widely used in industrial control and the contemporary Industrial Internet of Things (IIoT). Unfortunately, due to its relatively weak design in terms of data security and access control, SCADA systems are becoming a favorite target for attackers. End-to-end encryption, such as SSL/TLS protocol, is used to protect the data transmission, but it cannot guarantee security in third-party cloud platforms. In this article, we propose a secure revocable fine-grained access control and data sharing scheme. This scheme not only ensures the confidentiality of the data but also enhances the access control of the SCADA system. Our scheme is based on three key observations. The common communication architecture of SCADA systems cannot protect data security itself. The security supports provided by industrial control protocols are limited. Moreover, the third-party cloud platforms are semitrusted. In addition, we have introduced digital signature technology to assure the integrity of the data in the SCADA system. We prove that our scheme is secure. This scheme has been experimentally evaluated to introduce negligible performance losses while improving data security in the SCADA system.
Weiting Zhang, Hanyi Zhang, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001
IEEE Internet Things J.5
2022 A Secure and Authenticated Mobile Payment Protocol Against Off-Site Attack Strategy
abstract
Mobile payment system has been expected to provide more efficient and convenient payment methods. However, compared to traditional payments, mobile payment issues related to the security of electronic accounts and payment apps present serious challenges. In this paper, we find the potential security risks by analyzing the commonly used tokenized mobile payment method and put forward the corresponding off-site attack strategy. In this scenario, the attackers are not only limited to malicious third parties but also can be illegal merchants. To address the off-site attack, especially the potential attackers who may be malicious merchants, we also propose SALP, a secure and authenticated payment protocol, using time and position as necessary conditions for the payment confirmation. Furthermore, we leverage identity-based signature (IBS) to prevent altering the information and reduce the overhead of the third-party authentication. We conduct case studies to demonstrate that the SALP can effectively prevent the off-site payment attack without a trusted hardware environment. In particular, we finally argue that SALP does not bring additional system overhead without degrading the convenience of mobile payment.
Liming Fang 0001, Zhe Liu 0001, Changting Lin, Shouling Ji, Anni Zhou, Willy Susilo, Chunpeng Ge 0001
IEEE Trans. Dependable Secur. Comput.8
2022 Revocable Attribute-Based Encryption With Data Integrity in Clouds
abstract
Cloud computing enables enterprises and individuals to outsource and share their data. This way, cloud computing eliminates the heavy workload of local information infrastructure. Attribute-based encryption has become a promising solution for encrypted data access control in clouds due to the ability to achieve one-to-many encrypted data sharing. Revocation is a critical requirement for encrypted data access control systems. After outsourcing the encrypted attribute-based ciphertext to the cloud, the data owner may want to revoke some recipients that were authorized previously, which means that the outsourced attribute-based ciphertext needs to be updated to a new one that is under the revoked policy. The integrity issue arises when the revocation is executed. When a new ciphertext with the revoked access policy is generated by the cloud server, the data recipient cannot be sure that the newly generated ciphertext guarantees to be decrypted to the same plaintext as the originally encrypted data, since the cloud server is provided by a third party, which is not fully trusted. In this article, we consider a new security requirement for the revocable attribute-based encryption schemes: integrity. We introduce a formal definition and security model for the revocable attribute-based encryption with data integrity protection (RABE-DI). Then, we propose a concrete RABE-DI scheme and prove its confidentiality and integrity under the defined security model. Finally, we present an implementation result and provide performance evaluation which shows that our scheme is efficient and practical.
Chunpeng Ge 0001, Willy Susilo, Joonsang Baek, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2022 A Verifiable and Fair Attribute-Based Proxy Re-Encryption Scheme for Data Sharing in Clouds
abstract
To manage outsourced encrypted data sharing in clouds, attribute-based proxy re-encryption (ABPRE) has become an elegant primitive. In ABPRE, a cloud server can transform an original recipient’s ciphertext to a new one of a shared user’s. As the transformation is computation consuming, a malicious cloud server may return an incorrect re-encrypted ciphertext to save its computation resources. Moreover, a shared user may accuse the cloud server of returning an incorrect re-encrypted ciphertext to refuse to pay the cost of using the cloud service. However, existing ABPRE schemes do not support a mechanism to achieve verifiability and fairness. In this article, a novel verifiable and fair attribute-based proxy re-encryption (VF-ABPRE) scheme is introduced to support verifiability and fairness. The verifiability enables a shared user to verify whether the re-encrypted ciphertext returned by the server is correct and the fairness ensures a cloud server escape from malicious accusation if it has indeed conducted the re-encryption operation honestly. Additionally, we conduct a performance experiment to show the efficiency and practicality of the new VF-ABPRE scheme.
Chunpeng Ge 0001, Willy Susilo, Joonsang Baek, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2022 RobustFL: Robust Federated Learning Against Poisoning Attacks in Industrial IoT Systems
abstract
Industrial Internet of Things (IIoT) systems are key enabling infrastructures that sustain the functioning of production and manufacturing. To satisfy the intelligence demands, federated learning has been envisioned as a promising technique for IIoT applications with privacy training requirements. However, research works have shown that, by training the local model on crafted poisoning samples malicious participants can jeopardize the functionalities of the global model. In this article, we propose a robust federated learning method, named RobustFL, in IIoT systems to defend against poisoning attacks. The main idea is that we conduct an adversarial training framework, in which an extra logits-based predictive model is built at the server-side to predict which participant a given logit belongs to. Meanwhile, the federated model is adversarially trained to prevent this predictive behavior, thus mitigating the poisoning attack influences. We evaluate the poisoning attack and our defense method on three benchmark datasets. Experimental results demonstrate the superiority of our proposed method in terms of high accuracy and efficiency in defending against poisoning attacks.
Jiale Zhang 0001, Chunpeng Ge 0001, Feng Hu 0003, Bing Chen 0002
IEEE Trans. Ind. Informatics2
2021 ActAnyware - Blockchain-Based Software Licensing Scheme
Wei-Yang Chiu, Lu Zhou 0002, Weizhi Meng 0001, Zhe Liu 0001, Chunpeng Ge 0001
BlockSys5
2021 Multi-Level IoT Device Identification
abstract
The rapid development of the Internet of Things (IoT) has brought challenges to IoT platforms for high-efficiency deployments and low-budget management. Identifying IoT devices is the prerequisite for monitoring, protecting, and managing them. Considering different providers and IoT device renovation, centralized device identification solutions require large amounts of training data and frequent model updates. Traditional solutions based on machine learning cannot preserve identification precision for the long term at a low cost in reality. In this paper, we propose a multi-level IoT device identification framework, alleviating the problem of novel class detection and large-scale updating of IoT models in IoT device identification. The proposed framework improves the usability of device identification technology in the real world. We also designed an IoT device identification method, achieving an average identification accuracy of 93.37 %. With this proposed multi-level IoT device identification framework, IoT device identification can achieve a high precision over a long time.
Ruohong Jiao, Zhe Liu 0001, Liang Liu 0006, Chunpeng Ge 0001, Gerhard P. Hancke 0002
ICPADS4
2021 Fully Discover the Balance of Lightning Network Payment Channels
Chunpeng Ge 0001, Lu Zhou 0002, Huaqun Wang
WASA (1)2
2021 Ciphertext-policy attribute-based proxy re-encryption via constrained PRFs
Zengpeng Li 0001, Vishal Sharma 0001, Chunguang Ma, Chunpeng Ge 0001, Willy Susilo
Sci. China Inf. Sci.4
2021 A Provenance-Aware Distributed Trust Model for Resilient Unmanned Aerial Vehicle Networks
abstract
An unmanned aerial vehicle (UAV) network is an emerging industrial IoT network for collaborative UAV communication and management. The open architecture and dynamic topology, which provide functional benefits, unfortunately make UAVNs more vulnerable to a variety of attacks. In UAVNs, malicious nodes not only eavesdrop the communications between UAV nodes but also attempt to attack the entire network by injecting or modifying messages. This work proposes a provenance-aware distributed trust model, named UAV-pro, for UAVNs that aim to achieve accurate peer-to-peer trust assessment and maximize the delivery of correct messages received by destination nodes while minimizing the message delay and communication cost under resource-constrained network environments. Provenance refers to the history of ownership of messages transmitted on the network. The behavior of message creators and operators can be effectively evaluated based on message integrity, then generate the observational evidence. We collect the observational evidence for distributed trust evaluation, then identify malicious nodes in the network and isolate them from the network. UAVN-pro takes a data-driven approach to reduce resource consumption in the presence of selfish or malicious nodes while ensuring the safe transmission of data by digital signature technology. The experimental results show that UAVN-pro works are compatible with the existing UAV network routing protocols, and can effectively identify attacks, such as the black hole, gray hole, message modification, fake recommendation, and fake identity in UAV networks. UAVN-pro is superior to the existing security model in terms of detection rate, delivery rate, and system energy consumption in most cases.
Chunpeng Ge 0001, Lu Zhou 0002, Gerhard P. Hancke 0002, Chunhua Su
IEEE Internet Things J.1
2021 Revocable Identity-Based Broadcast Proxy Re-Encryption for Data Sharing in Clouds
abstract
Cloud computing has become prevalent due to its nature of massive storage and vast computing capabilities. Ensuring a secure data sharing is critical to cloud applications. Recently, a number of identity-based broadcast proxy re-encryption (IB-BPRE) schemes have been proposed to resolve the problem. However, the IB-BPRE requires a cloud user (Alice) who wants to share data with a bunch of other users (e.g., colleagues) to participate the group shared key renewal process because Alice's private key is a prerequisite for shared key generation. This, however, does not leverage the benefit of cloud computing and causes the inconvenience for cloud users. Therefore, a novel security notion named revocable identity-based broadcast proxy re-encryption (RIB-BPRE) is presented to address the issue of key revocation in this work. In a RIB-BPRE scheme, a proxy can revoke a set of delegates, designated by the delegator, from the re-encryption key. The performance evaluation reveals that the proposed scheme is efficient and practical.
Chunpeng Ge 0001, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2021 Secure Keyword Search and Data Sharing Mechanism for Cloud Computing
abstract
The emergence of cloud infrastructure has significantly reduced the costs of hardware and software resources in computing infrastructure. To ensure security, the data is usually encrypted before it's outsourced to the cloud. Unlike searching and sharing the plain data, it is challenging to search and share the data after encryption. Nevertheless, it is a critical task for the cloud service provider as the users expect the cloud to conduct a quick search and return the result without losing data confidentiality. To overcome these problems, we propose a ciphertext-policy attribute-based mechanism with keyword search and data sharing (CPAB-KSDS) for encrypted cloud data. The proposed solution not only supports attribute-based keyword search but also enables attribute-based data sharing at the same time, which is in contrast to the existing solutions that only support either one of two features. Additionally, the keyword in our scheme can be updated during the sharing phase without interacting with the PKG. In this article, we describe the notion of CPAB-KSDS as well as its security model. Besides, we propose a concrete scheme and prove that it is against chosen ciphertext attack and chosen keyword attack secure in the random oracle model. Finally, the proposed construction is demonstrated practical and efficient in the performance and property comparison.
Chunpeng Ge 0001, Willy Susilo, Zhe Liu 0001, Jinyue Xia, Pawel Szalachowski, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.1
2021 A Hybrid Fuzzy Convolutional Neural Network Based Mechanism for Photovoltaic Cell Defect Detection With Electroluminescence Images
abstract
In the intelligent manufacturing process of solar photovoltaic (PV) cells, the automatic defect detection system using the Industrial Internet of Things (IIoT) smart cameras and sensors cooperated in IIoT has become a promising solution. Many works have been devoted to defect detection of PV cells in a data-driven way. However, because of the subjectivity and fuzziness of human annotation, the data contains a high quantity of noise and unpredictable uncertainties, which creates great difficulties in automatic defect detection. To address this problem, we propose a novel architecture named fuzzy convolution, which integrates fuzzy logic and convolution operations at microscopic level. Combining the proposed fuzzy convolution with the regular convolution, we build a network called Hybrid Fuzzy Convolutional Neural Network (HFCNN). Compared with convolutional neural networks (CNNs), HFCNN can address the uncertainties of PV cell data to improve the accuracy with fewer parameters, making it possible to apply our method in smart cameras. Experimental results on a public dataset show the superiority of our proposed method compared with CNNs.
Chunpeng Ge 0001, Zhe Liu 0001, Liming Fang 0001, Huading Ling, Aiping Zhang, Changchun Yin
IEEE Trans. Parallel Distributed Syst.1
2020 A privacy preserving two-factor authentication protocol for the Bitcoin SPV nodes
Lu Zhou 0002, Chunpeng Ge 0001, Chunhua Su
Sci. China Inf. Sci.2
2020 A privacy preserve big data analysis system for wearable wireless sensor network
Chunpeng Ge 0001, Changchun Yin, Zhe Liu 0001, Liming Fang 0001, Juncen Zhu, Huading Ling
Comput. Secur.1
2020 A Secure and Fine-Grained Scheme for Data Security in Industrial IoT Platforms for Smart City
abstract
With the high popularity of IoT devices, industrial IoT platforms, such as smart factories and oilfield industrial control systems, have become a new trend in the development of smart city. Although various manufacturers pay wide attention to the different functional requirements of IoT platforms, they seldom consider security issues, especially in terms of data security, which has led to a large number of cases of privacy leakage. Some works have been made to provide secure and reliable communication solutions for industrial IoT platforms, unfortunately, as different communication protocols and interaction models are adopted in different scenarios, these solutions are mainly isolated and fragmented. Therefore, it is an urgent challenge to construct a universal cross-platform secure communication scheme for industrial IoT platforms. In this article, we analyze the logic and requirements of different industrial IoT scenarios to abstracts them into a universal model. We summarize the possible attacks on different industrial IoT platforms and design a security scheme to capture these attacks based on the conditional proxy re-encryption primitive. The proposed scheme ensures that data cannot be accessed by an unauthorized user. We also evaluate the security and performance of our scheme, and the experimental results show that our scheme can achieve the functionality and security requirements with low overhead.
Liming Fang 0001, Hanyi Zhang, Chunpeng Ge 0001, Liang Liu 0006, Zhe Liu 0001
IEEE Internet Things J.4
2020 Energy-Efficient and Privacy-Preserving Data Aggregation Algorithm for Wireless Sensor Networks
abstract
Privacy-preserving data aggregation is a kind of fundamental and essential algorithm for wireless sensor networks. However, the existing aggregation algorithms consume a large amount of energy to assure sensory data security. In this article, we propose an energy-efficient and privacy-preserving data aggregation algorithm (EPDA). We organize a sensor network into a tree and connect the leaf nodes of the tree to form many chains. EPDA requires only the data sensed by the tail nodes of the chains to be sliced to ensure privacy. Also, EPDA significantly decreases energy consumption and prolongs the lifetime of the network. We compare our scheme with the existing schemes through theoretical analysis and simulations. The analysis and simulation results show that EPDA outperforms the existing schemes.
Lu Zhou 0002, Chunpeng Ge 0001, Chunhua Su
IEEE Internet Things J.2
2020 A blockchain based decentralized data security mechanism for the Internet of Things
Chunpeng Ge 0001, Zhe Liu 0001, Liming Fang 0001
J. Parallel Distributed Comput.1
2020 A semi-autonomous distributed blockchain-based framework for UAVs system
Chunpeng Ge 0001, Xinshu Ma, Zhe Liu 0001
J. Syst. Archit.1
2020 Achieving reliable timestamp in the bitcoin platform
Guangkai Ma, Chunpeng Ge 0001, Lu Zhou 0002
Peer-to-Peer Netw. Appl.2
2020 Privacy Protection for Medical Data Sharing in Smart Healthcare
abstract
In virtue of advances in smart networks and the cloud computing paradigm, smart healthcare is transforming. However, there are still challenges, such as storing sensitive data in untrusted and controlled infrastructure and ensuring the secure transmission of medical data, among others. The rapid development of watermarking provides opportunities for smart healthcare. In this article, we propose a new data-sharing framework and a data access control mechanism. The applications are submitted by the doctors, and the data is processed in the medical data center of the hospital, stored in semi-trusted servers to support the selective sharing of electronic medical records from different medical institutions between different doctors. Our approach ensures that privacy concerns are taken into account when processing requests for access to patients’ medical information. For accountability, after data is modified or leaked, both patients and doctors must add digital watermarks associated with their identification when uploading data. Extensive analytical and experimental results are presented that show the security and efficiency of our proposed scheme.
Liming Fang 0001, Changchun Yin, Juncen Zhu, Chunpeng Ge 0001, Muhammad Tanveer 0001, Alireza Jolfaei, Zehong Cao
ACM Trans. Multim. Comput. Commun. Appl.4
2019 Blockchain-Enabled Privacy-Preserving Internet of Vehicles: Decentralized and Reputation-Based Network Architecture
Xinshu Ma, Chunpeng Ge 0001, Zhe Liu 0001
NSS2
2019 A CCA-secure multi-conditional proxy broadcast re-encryption scheme for cloud storage system
Yepeng Liu 0004, Yongjun Ren, Chunpeng Ge 0001, Jinyue Xia, Qirun Wang
J. Inf. Secur. Appl.3
2018 A CCA-secure key-policy attribute-based proxy re-encryption in the adaptive corruption model for dropbox data sharing system
Chunpeng Ge 0001, Willy Susilo, Liming Fang 0001, Yun Q. Shi 0001
Des. Codes Cryptogr.1
2018 A proxy broadcast re-encryption for cloud data sharing
Maosheng Sun, Chunpeng Ge 0001, Liming Fang 0001
Multim. Tools Appl.2
2016 A Key-Policy Attribute-Based Proxy Re-Encryption Without Random Oracles
abstract
A conditional proxy re-encryption (CPRE) scheme enables the proxy to convert a ciphertext from Alice to Bob, if the ciphertext satisfies one condition set by Alice. To improve the issue of more fine-grained on the condition set, Fang, Wang, Ge and Ren proposed a new primitive named Interactive conditional PRE with fine grain policy (ICPRE-FG) in 2011, and left an open problem on how to construct CCA-secure ICPRE-FG without random oracles. In this paper, we answer this open problem affirmatively by presenting a new construction of CCA-secure key-policy attribute-based PRE (KP-ABPRE) without random oracles. In this paper, we enhance the security model of Fang's ICPRE-FG scheme by allowing the adversary to make some extra queries, which do not help them win the game trivially. Finally, we present a CCA-secure KP-ABPRE without random oracles under the 3-weak decisional bilinear Diffie–Hellman inversion(3-wDBDHI) assumption.
Chunpeng Ge 0001, Willy Susilo, Liming Fang 0001, Yongjun Ren
Comput. J.1
2013 Fuzzy conditional proxy re-encryption
Liming Fang 0001, Chunpeng Ge 0001, Yongjun Ren
Sci. China Inf. Sci.3
2013 Public key encryption with keyword search secure against keyword guessing attacks without random oracle
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
Inf. Sci.3
2012 Chosen-ciphertext secure anonymous conditional proxy re-encryption with keyword search
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
Theor. Comput. Sci.3
2011 Interactive conditional proxy re-encryption with fine grain policy
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
J. Syst. Softw.3
2009 A Secure Channel Free Public Key Encryption with Keyword Search Scheme without Random Oracle
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
CANS3