VLDB 2026 Research / reviewers in the wild / expert
Xueping Liang
dblp:201/4788
· DBLP profile ↗
30ranked-venue papers
10as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 7 first-author · 5 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Computer networks · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | An Agentic AI Control Plane for 6G Network Slice Orchestration, Monitoring, and Trading
Eranga Bandara, Ross Gore, Sachin Shetty, Ravi Mukkamala, Tharaka Mawanane Hewa, Abdul Rahman, Xueping Liang, Safdar Hussain Bouk, Peter Foytik, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 7 |
| 2026 | ASTRIDE: A Security Threat Modeling Platform for Agentic-AI ApplicationsabstractAI agent-based systems are becoming increasingly integral to modern software architectures, enabling autonomous decision-making, dynamic task execution, and multimodal interactions through large language models (LLMs). However, these systems introduce novel and evolving security challenges, including prompt injection attacks, context poisoning, model manipulation, and opaque agent-to-agent communication, that are not effectively captured by traditional threat modeling frameworks. In this paper, we introduce ASTRIDE, an automated threat modeling platform purpose-built for AI agent-based systems. ASTRIDE extends the classical STRIDE framework by introducing a new threat category, A for AI Agent-Specific Attacks, which encompasses emerging vulnerabilities such as prompt injection, unsafe tool invocation, and reasoning subversion, unique to agent-based applications. To automate threat modeling, ASTRIDE combines a consortium of fine-tuned vision-language models (VLMs) with the OpenAI-gpt-oss reasoning LLM to perform end-to-end analysis directly from visual agent architecture diagrams, such as data flow diagrams(DFDs). LLM agents orchestrate the end-to-end threat modeling automation process by coordinating interactions between the VLM consortium and the reasoning LLM. Our evaluations demonstrate that ASTRIDE provides accurate, scalable, and explainable threat modeling for next-generation intelligent systems. To the best of our knowledge, ASTRIDE is the first framework to both extend STRIDE with AI-specific threats and integrate fine-tuned VLMs with a reasoning LLM to fully automate diagram-driven threat modeling in AI agent-based applications. Eranga Bandara, Amin Hass, Sachin Shetty, Ravi Mukkamala, Ross Gore, Sachini Rajapakse, Xueping Liang, Safdar Hussain Bouk |
IWCMC | 7 |
| 2026 | Deep-RF - An Agentic AI Framework for RF Signal Classification and Real-Time 5G O-RAN Attack Detection
Eranga Bandara, Neda Moghim, Safdar Hussain Bouk, Sachin Shetty, Ross Gore, Ravi Mukkamala, Abdul Rahman, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 8 |
| 2025 | Llama-Recipe - Fine-Tuned Meta's Llama LLM, PBOM and NFT Enabled 5G Network-Slice Orchestration and End-to-End Supply-Chain Verification PlatformabstractModern 5G networks offer a network-sliced infrastructure where each network slice contains a dedicated 5G core software service layer. The 5G core software services in each slice shares common core network resources to meet specific customer needs. A primary challenge in 5G network slicing involves resource sharing and efficient network slice orchestration. Container-based methodologies, including tools like Docker and Kubernetes, have become popular for orchestrating 5G network slice services and managing configurations in microservices-based cloud-native service deployment. However, despite their utility, these tools present significant challenges. Their complexity often necessitates dedicated DevOps teams for effective management, while configuration management can prove arduous, and end-to-end supply chain oversight is lacking. To address these challenges, this paper introduces “Llama-Recipe,” a cloud-native 5G-core service deployment and orchestration platform integrating Generative AI, SBOM, PBOM and NFT. 5G-core service configurations across different network slices are represented as “HOCON (Human-Optimized Config Object Notation)” config objects adhering to the GitOps paradigm. Leveraging custom-trained Meta's Llama2 LLM, Llama-Recipe generates the Kubernetes manifests for network-sliced 5G-core services based on the defined HOCON configurations. The generated Kubernetes manifests of the 5G-core services are deployed in designated Kubernetes clusters utilizing GitOps tools (e.g., ArgoCD), ensuring seamless and automated deployment processes. Additionally, Llama-Recipe introduced a novel mechanism to handle end-to-end supply chain verification of 5G-core software services using Software-Bill of Materials (SBOM) and Pipeline-Bill of Materials (PBOM). SBOMs track all the dependencies and PBOMs facilitate the comprehensive tracking of end-to-end supply chain data for 5G-core software services, enhancing transparency and security. These PBOMs are also generated using the fine-tuned Meta's Llama-2 LLM and are encoded as NFT tokens with a novel NFT token schema. This schema enables easy verification and validation of supply-chain data during deployments, thus helping to prevent various supply-chain attacks. To fine-tune the Meta's Llama2 LLM, we've undertaken a meticulous training process, collaborating with Qlora to transform a 4-bit quantized pre-trained language model into Low-Rank Adapters(LoRA). The effectiveness of the Llama-Recipe is demonstrated through a real-world test-bed deployment in a sliced network scenario, utilizing multiple 5G cores (i.e., Open5GS) across Ericsson's new Radio Access Network (RAN). Eranga Bandara, Safdar Hussain Bouk, Sachin Shetty, Sandip Roy 0001, Ravi Mukkamala, Abdul Rahman, Peter Foytik, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
CCNC | 8 |
| 2025 | VindSec-Llama - Fine-Tuned Meta's Llama-3 LLM, Federated Learning, Blockchain and PBOM-enabled Data Security Architecture for Wind Energy Data PlatformsabstractCurrent wind energy data platforms face significant challenges in securing and managing extensive data from both offshore and onshore wind farms. These challenges include vulnerabilities to cyber-attacks, data tampering, breaches, complex data-sharing issues due to privacy concerns and regulatory compliance, and a lack of scalability and flexibility in analytical tools for real-time data processing. This paper proposes a novel multilayered data security architecture, termed "VindSec-Llama," to address these challenges. It integrates Generative AI, blockchain, federated learning, and Pipeline Bill of Materials (PBOM) to enhance data analytics, model development, and security across several layers, including Infrastructure, Data Lake, Federated Learning, MLOps, Data Provenance, and LLM. Each layer is designed to meet specific functional requirements, such as handling large datasets, facilitating secure federated learning, automating risk management, and ensuring data provenance and traceability. The platform, deployable in server environments (cloud or on-premises), complies with the Risk Management Framework (RMF) guidelines and security standards. It features a blockchain-enabled, coordinator-less federated learning system to enhance data privacy and security by enabling the development of privacy-preserving machine learning models with data from different wind farms. Automation plays a pivotal role throughout VindSec-Llama, with Meta’s custom-trained Llama-3 LLM used for generating remediation scripts in the Infrastructure Layer and for producing PPBOM in the MLOps Layer. The Llama-3 LLM has been quantized and fine-tuned using Qlora to ensure optimal performance on consumer-grade hardware. The MLOps pipeline setup, a critical functionality of VindSec-Llama, ensures seamless integration and deployment of machine learning models, embodying best practices in continuous integration and delivery. This setup is geared towards maximizing security, compliance, and operational efficiency. A prototype of the platform has been implemented within a wind-energy testbed with the collaboration of Department of Energy US, illustrating its practical applications and benefits. Eranga Bandara, Safdar Hussain Bouk, Sachin Shetty, Ross Gore, Sastry Kompella, Ravi Mukkamala, Abdul Rahman, Peter Foytik, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 9 |
| 2025 | Bassa-Llama - Fine-Tuned Meta's Llama LLM, Blockchain and NFT Enabled Real-Time Network Attack Detection Platform for Wind Energy Power PlantsabstractLarge Language Models (LLMs) are widely recognized for their applications in natural language processing tasks, but their potential extends far beyond traditional use cases. This paper introduces "Bassa-Llama," a novel platform that harnesses LLMs for predictive tasks in the realm of network security. Specifically, we propose a platform for real-time network attack detection in Wind Power Plants, leveraging a fine-tuned version of Meta’s Llama-3 LLM alongside blockchain and NFT-based data storage. Using a network PCAP dataset containing both malicious and benign packets, we fine-tune the Llama-3 LLM, with Quantized Low-Rank Adapter (QLoRA), to detect anomalies in network traffic. This approach ensures optimal performance on consumer-grade hardware while significantly enhancing the model’s ability to accurately analyze PCAP data and identify attack patterns. The end-to-end orchestration of the real-time network attack detection flow for Wind Power Plants is fully automated through blockchain smart contracts, and NFTs for storing identified attack data from the PCAP. To the best of our knowledge, this research represents the first effort to utilize a fine-tuned LLM for real-time network attack detection tasks. The results highlight the transformative potential of combining fine-tuned LLMs with blockchain and NFTs to build robust and secure network defense systems for Wind Power Plants. A prototype of the proposed platform was developed in collaboration with the U.S. Department of Energy, utilizing a simulated Wind Power Plant as a testbed. Eranga Bandara, Safdar Hussain Bouk, Sachin Shetty, Ross Gore, Sastry Kompella, Ravi Mukkamala, Abdul Rahman, Peter Foytik, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
IWCMC | 9 |
| 2025 | A novel framework to identify cybersecurity challenges and opportunities for organizational digital transformation in the cloud
Xueping Liang |
Comput. Secur. | 1 |
| 2024 | SliceGPT - OpenAI GPT-3.5 LLM, Blockchain and Non-Fungible Token Enabled Intelligent 5G/6G Network Slice Broker and MarketplaceabstractThe main challenges in the 5G/6G network slicing are resource sharing, network slice orchestration, and network optimization in the 5G ecosystem. This paper proposes a novel architecture for a dynamic network slice broker and marketplace named “SliceGPT” that leverages Custom-Trained OpenAI GPT-3.5 LLM, blockchain and NFTs to enable collaboration between different stakeholders in the 5G ecosystem to address these challenges. The platform enables different stakeholders in 5G network slicing (e.g., cloud providers, network operators, RAN providers, and transport network providers) to share and rent their resources to create customized network slices that meet the specific requirements of 5G applications. The orchestration of network slices is managed through blockchain smart contracts, and the resulting network slices are encoded as NFT tokens and made available for purchase in a decentralized NFT marketplace. Customers can select and purchase the network slices that best meet their needs by paying either crypto or flat currency. Revenue generated through the sale of network slices is distributed among different providers, facilitating a fair and efficient marketplace. Intelligent network slice optimization is accomplished through the utilization of a custom-trained GPT-3.5 LLM(which powers the ChatGPT). This LLM can generate valuable insights and recommendations from extensive network datasets, contributing to the optimization of network slices for enhanced performance and efficiency. A prototype of SliceGPT has been implemented with FreedomFi 5G gateway, OpenAirInterface 5G core, OpenAI GPT-3.5-turbo model, LlamaIndex and Langchain. To the best of our knowledge, this is the very first research endeavor to incorporate the GPT LLMs for optimizing 5G/6G network slicing, Eranga Bandara, Peter Foytik, Sachin Shetty, Ravi Mukkamala, Abdul Rahman, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
CCNC | 6 |
| 2024 | WedaGPT - Generative-AI (with Custom-Trained Meta's Llama2 LLM), Blockchain, Self Sovereign Identity, NFT and Model Card Enabled Indigenous Medicine PlatformabstractTraditional and indigenous medicine, deeply rooted in ancient traditions and wisdom, plays a crucial role in global healthcare and cultural identity. These practices provide treatments for illnesses such as cancer and bone injuries, which often lack effective remedies in Western medicine. However, these valuable systems face challenges like potential knowledge loss, undervaluation of practitioners’ expertise, and the risk of fraud due to the absence of credential verification mechanisms. In this research, we introduce "WedaGPT," a Generative AI-enabled platform that utilizes a custom-trained Meta’s Llama2 Large Language Model (LLM), Blockchain, self-sovereign identity (SSI), Non-Fungible Tokens (NFTs), and model cards to share traditional medical knowledge and address these issues. WedaGPT creates a collaborative ecosystem connecting doctors, medicine providers, therapists, patients, and technology experts, all committed to preserving and advancing traditional healing practices. This platform enables secure and transparent contributions from all stakeholders to patient well-being. Ancient medical recipe books are translated into English and digitized into PDF formats to enrich the platform’s knowledge base. These texts are used to fine-tune the Llama2 LLM, which has been quantized and optimized with Qlora for performance on consumer-grade hardware. Through a chat-based interface in the SSI-enabled mobile wallet, users can interact with the LLM and access detailed information on treatments, recipes, prescriptions, and healing methods. Additionally, users can consult remotely with doctors who prescribe treatments through this wallet. A key feature of WedaGPT is transforming ancient medicinal recipes into NFT tokens for sale on NFT marketplaces, giving traditional knowledge digital authenticity and economic value. Revenue from these sales is distributed among platform contributors, promoting equitable ownership and recognition. Medical recipe data, including treatment histories and physician details, are encapsulated in Model Cards and securely stored on the blockchain. This system offers mechanisms to verify doctors and treatments in a privacy-preserving way, potentially reducing fraud and medication errors. Eranga Bandara, Peter Foytik, Sachin Shetty, Ravi Mukkamala, Abdul Rahman, Xueping Liang, Wee Keong Ng, Kasun De Zoysa |
ISCC | 6 |
| 2024 | LSD Attack: Exploiting Inconsistencies between Design and Implementation of Ethereum ProtocolsabstractIn the network layer of the Ethereum network, the Discv5 protocol is introduced to improve the node discovery process and enhance resistance to common P2P network attacks such as Sybil Attacks, Partition Attacks, and Eclipse Attacks. However, the practical effectiveness of the new security mechanisms introduced by the Discv5 protocol has not been evaluated through engineering assessments. In this paper, we identify inconsistencies between the design and implementation of the Discv5 protocol and propose a new attack pattern: the Leveraging Service Diversity (LSD) Attack. The LSD Attack targets networks where different services are indiscriminately mixed. Through detailed measurements of the Consensus Layer (CL) discovery network, we evaluate the impact of the LSD Attack on newly joined network nodes and on the services of honest nodes within the network. Our experiments demonstrate significant deviations between the Discv5 protocol’s current implementation and its original design, which can lead to a substantial reduction in the network’s security under the influence of service diversity. This study contributes to a deeper understanding of the security implications of the Discv5 protocol and highlights the need for further evaluation and improvement of the network layer protocols in Ethereum. Xueping Liang, Xiaorui Gong |
TrustCom | 3 |
| 2024 | Combating alert fatigue with AlertPro: Context-aware alert prioritization using reinforcement learning for multi-step attack detection
Xueping Liang, Xiaorui Gong |
Comput. Secur. | 3 |
| 2023 | Blockchain, NFT, Federated Learning and Model Cards enabled UAV Surveillance System for 5G/6G Network Sliced EnvironmentabstractIn recent years, the use of UAVs has expanded to various applications such as surveillance, disaster response, agriculture, and delivery. However, traditional UAV monitoring systems rely on direct communication between the UAV and the ground pilot, which has several limitations such as limited range, poor reliability, and susceptibility to interference. To overcome these limitations, there has been significant interest in integrating UAVs into cellular networks such as 5G/6G network slicing. The flexibility of network slicing allows UAVs to operate on different slices based on their communication needs, which can improve their performance and efficiency. However, integrating UAVs into network slicing also poses several challenges, such as managing communication and permissions of UAVs and base stations, access control of UAVs, and identity management of UAVs. To address these challenges, we propose a blockchain, Non-Fungible Token(NFT), Federated Learning(FL), and Zero-Trust(ZT) security-enabled UAV monitoring platform for 5G/6G network sliced environments. We propose a novel approach in which UAVs are represented as NFT tokens within the platform. This innovative representation allows for enhanced security and trust in the system, aligning with the principles of the Zero-Trust security model, which assumes no implicit trust in any network component or user. Furthermore, we propose a FL system that operates on top of the blockchain, which can analyze data from multiple UAVs across different network slices. Our proposed FL system uses coordinator-less models, which eliminates the attacks of a centralized coordinator. As a use case, we consider a scenario where our proposed system detects anomaly communications of UAVs and identifies attack surfaces via analyzing network traffic data of UAVs using FL. The 5G system testbed implemented with FreedomFi 5G gateway and Indoor Radio Cell. Eranga Bandara, Sachin Shetty, Peter Foytik, Abdul Rahman, Ravi Mukkamala, Xueping Liang, Nadini Sahabandu |
ISNCC | 6 |
| 2023 | Decentralizing Cyber Physical Systems for Resilience: An Innovative Case Study from A Cybersecurity Perspective
Xueping Liang, Charalambos Konstantinou, Sachin Shetty, Eranga Bandara, Ruimin Sun |
Comput. Secur. | 1 |
| 2022 | Bassa-ML - A Blockchain and Model Card Integrated Federated Learning Provenance PlatformabstractFederated learning is a collaborative/distributed machine learning system which is designed to address the privacy issues in centralized machine learning systems. The transparency and provenance of a machine learning model are important aspects of federated learning systems since they impact peoples’ lives in various domains (e.g., from healthcare to personal finance to employment). However, most of the existing federated learning systems deal with centralized coordinators which are vulnerable to attacks and privacy breaches. Also, they do not provide any standard transparency and provenance mechanisms for the resulting models. In this paper, we propose a blockchain and Model Card-based integrated federated learning system "Bassa-ML" providing enhanced transparency and trust for the models. Model parameter sharing, local model generation, model averaging, and model sharing functions are implemented using smart contracts. The generated models, model training information, and model reports are stored in the blockchain ledger as Model Card Objects. This results in enhanced transparency and auditability to the federated learning process. Eranga Bandara, Sachin Shetty, Abdul Rahman, Ravi Mukkamala, Juan Zhao 0003, Xueping Liang |
CCNC | 6 |
| 2022 | Skunk - A Blockchain and Zero Trust Security Enabled Federated Learning Platform for 5G/6G Network SlicingabstractThe network slicing in 5G/6G mobile networks enables billions of connected devices to transmit data at higher rates than ever before. The high number of devices and the huge data rates result in configuration complexities and complex security management. Machine learning techniques could play a key role in managing these system complexities. While feder-ated learning (FL) has recently been proposed as an emerging paradigm to build privacy-preserving machine learning models, many of the existing systems involve centralized coordinators which are known to be vulnerable to attacks and privacy breaches. In addition, current FL models have weak support for transparency and provenance mechanisms. In this paper, we propose a Blockchain-based, Zero-trust Security-enabled Federated Learning system “Skunk” to address privacy and data provenance requirements. The proposed federated learning system also supports the requirements of 5G/6G networks. The sharding-based architecture in the blockchain enables the deployment of Skunk in 5G/6G network slice environments. As a use case of Skunk, we have considered a scenario with IoT device attacks in a 5G/6G network. The proposed FL models detect such attacks in the 5G/6G network sliced environment. Eranga Bandara, Xueping Liang, Sachin Shetty, Ravi Mukkamala, Abdul Rahman, Wee Keong Ng |
SECON | 2 |
| 2022 | Moose: A Scalable Blockchain Architecture for 5G Enabled IoT with Sharding and Network Slicingabstract5G network slicing enables IoT networks to connect billions of heterogeneous objects providing high quality of service, high network capacity, and enhanced system throughput. Despite all these advantages, there are some major challenges to be addressed including decentralization, transparency, data interoperability, network privacy and security, and network slice orchestration, data provenance, and management. Blockchain technologies have the potential to offer innovative solutions to overcome these challenges. However, in the context of 5G enabled scalable IoT applications, integrating 5G with blockchain platforms could pose challenges to 5G’s goals such as high transaction throughput, high scalability, and real-time transaction processing, sharding-based consensus, network slice management and provenance. In this paper, "Moose," a blockchain platform, to overcome these challenges is proposed. It supports sharding based consensus in the blockchain network. It integrates a network slice orchestration library with smart contracts to manage and schedule network slices. As a use-case, Moose is integrated with a 5G-supported IoT device identity monitoring system on a network sliced environment. The performance results from the implemented system indicate that the proposed system indeed overcomes the aforementioned challenges. Eranga Bandara, Sachin Shetty, Abdul Rahman, Ravi Mukkamala, Xueping Liang |
WCNC | 5 |
| 2021 | A Blockchain and Self-Sovereign Identity Empowered Digital Identity PlatformabstractMost of the existing identity systems are built on top of centralized storage systems. Storing identity data on these types of centralized storage platforms(e.g cloud storage, central servers) becomes a major privacy concern since various types of attacks and data breaches can happen. With this research, we are proposing blockchain and self-sovereign identity based digital identity (KYC - Know Your Customer) platform “Casper” to address the issues on centralized identity systems. “Casper ” is an Android/iOS based mobile identity wallet application that combines the integration of blockchain and a self-sovereign identity-based approach. Unlike centralized identity systems, the actual identities of the customer/users are stored in the customers’ mobile wallet application. The proof of these identities is stored in the blockchain-based decentralized storage as a self-sovereign identity proof. Casper platforms’ Self-Sovereign Identity(SSI)-based system provides a Zero Knowledge Proof(ZKP) mechanism to verify the identity information. Casper platform can be adopted in various domains such as healthcare, banking, government organization etc. As a use case, we have discussed building a digital identity wallet for banking customers with the Casper platform. Casper provides a secure, decentralized and ZKP verifiable identity by using blockchain and SSI based approach. It addresses the common issues in centralized/cloud-based identity systems platforms such as the lack of data immutability, lack of traceability, centralized control etc. Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty, Kasun De Zoysa |
ICCCN | 2 |
| 2021 | Blockchain and Self-Sovereign Identity Empowered Cyber Threat Information Sharing PlatformabstractCyber threat information (CTI) sharing involves processes of the collection, analysis and sharing of cyber threat information among multiple organizations. CTI is highly sensitive and inadvertent access can harm an organisation’s reputation. Moreover, CTI sharing may also inadvertently advertise a vulnerability that may be present in the organisation’s infrastructure. Therefore, preserving the privacy and anonymity of the CTI participants is critical. This paper proposes "Siddhi", a blockchain and Self-Sovereign Identity(SSI) enabled CTI platform that will realize traceability, anonymization and data provenance in a scalable fashion. Siddhi is equipped with SSI-enabled mobile wallet to ensure anonymous reporting of threat information and supports TAXII and STIX standards for exchanging the threat information between participants in the blockchain network. Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty |
SMARTCOMP | 2 |
| 2021 | Leveraging Intel SGX to enable trusted and privacy preserving membership service in distributed ledgers
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Peter Foytik, Lingchen Zhang |
Int. J. Inf. Comput. Secur. | 1 |
| 2021 | A blockchain empowered and privacy preserving digital contact tracing platform
Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty, Crissie Hall, Daniel Bowden, Nalin Ranasinghe, Kasun De Zoysa |
Inf. Process. Manag. | 2 |
| 2021 | Rahasak - Scalable blockchain architecture for enterprise applications
Eranga Bandara, Xueping Liang, Peter Foytik, Sachin Shetty, Nalin Ranasinghe, Kasun De Zoysa |
J. Syst. Archit. | 2 |
| 2018 | Blockchain and IoT Data Analytics for Fine-Grained Transportation InsuranceabstractInnovations such as the Cloud, Internet of Things (IoT) and data analytics have already dramatically altered the customer experience in many, if not all, industries. Blockchain, as another emerging technology, is expected to be the next generation infrastructure to established trusted multiparty collaborations. In this paper, we investigated the convergence of aforementioned technologies, by presenting a prototype of fine-grained transportation insurance. Insurance premium were assessed based on vehicles usage and driver's behavior, which were deduced from streaming IoT data collected from mobile sensors. This incentive mechanism promotes fairness among drivers and encourages safer driving style. The prototype takes advantage of both private blockchain (e.g., high transaction rate in Hyperledger) and public blockchain (e.g., inbuilt cryptocurrency). Besides system architecture and implementation details, preliminary performance evaluations are presented and discussed. Zengxiang Li, Quanqing Xu, Ekanut Sotthiwat, Rick Siow Mong Goh, Xueping Liang |
ICPADS | 6 |
| 2018 | Towards a Reliable and Accountable Cyber Supply Chain in Energy Delivery System Using Blockchain
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Yafei Ji, Danyi Li |
SecureComm (2) | 1 |
| 2018 | A Reliable Data Provenance and Privacy Preservation Architecture for Business-Driven Cyber-Physical Systems Using BlockchainabstractCyber-physical systems (CPS) including power systems, transportation, industrial control systems, etc. support both advanced control and communications among system components. Frequent data operations could introduce random failures and malicious attacks or even bring down the whole system. The dependency on a central authority increases the risk of single point of failure. To establish an immutable data provenance scheme for CPS, the authors adopt blockchain and propose a decentralized architecture to assure data integrity. In business-driven CPS, end users are required to share their personal information with multiple third parties. To prevent data leakage and preserve user privacy, the authors isolate and feed different information retrieval requests using tokens specifically generated for each type of request. Providing both traceability of data operations, and unlinkability of end user activities, a robust blockchain-based CPS is prototyped. Evaluation indicates the architecture is capable of assured data provenance validation and user privacy preservation at a low overhead. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Juan Zhao 0003, Danyi Li, Jihong Liu |
Int. J. Inf. Secur. Priv. | 1 |
| 2017 | Man in the Cloud (MITC) Defender: SGX-Based User Credential Protection for Synchronization Applications in Cloud Computing PlatformabstractIn cloud environment, client user credential protection is a critical security capability that is target of adversarial attacks, especially, in cloud file synchronization applications. Among the various adversarial attacks, MITC (Man in the Cloud) attack on commercial cloud storage applications has emerged as a critical threat because it is easy to launch and hard to detect. In this paper, we propose MITC Defender, a hardware-based defense system capable of protecting client user credentials using Intel Software Guard Extensions (SGX) and preventing against four different types of MITC attack in cloud environment. By adopting Intel SGX security features such as sealing and attestation, MITC Defender can securely seal user credentials locally and easily unseal user credentials, when verifications are needed, in a Trusted Execution Environment (TEE). We implement MITC Defender on an open source platform OpenSGX and evaluate the performance and potential overhead. Our evaluation results show that MITC Defender is effective on defense against MITC attack and other security threats with a low cost. Xueping Liang, Sachin Shetty, Lingchen Zhang, Charles A. Kamhoua, Kevin A. Kwiat |
CLOUD | 1 |
| 2017 | ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and AvailabilityabstractCloud data provenance is metadata that records the history of the creation and operations performed on a cloud data object. Secure data provenance is crucial for data accountability, forensics and privacy. In this paper, we propose a decentralized and trusted cloud data provenance architecture using blockchain technology. Blockchain-based data provenance can provide tamper-proof records, enable the transparency of data accountability in the cloud, and help to enhance the privacy and availability of the provenance data. We make use of the cloud storage scenario and choose the cloud file as a data unit to detect user operations for collecting provenance data. We design and implement ProvChain, an architecture to collect and verify cloud data provenance, by embedding the provenance data into blockchain transactions. ProvChain operates mainly in three phases: (1) provenance data collection, (2) provenance data storage, and (3) provenance data validation. Results from performance evaluation demonstrate that ProvChain provides security features including tamper-proof provenance, user privacy and reliability with low overhead for the cloud storage applications. Xueping Liang, Sachin Shetty, Deepak K. Tosh, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 1 |
| 2017 | Security Implications of Blockchain Cloud with Analysis of Block Withholding AttackabstractThe blockchain technology has emerged as an attractive solution to address performance and security issues in distributed systems. Blockchain's public and distributed peer-to-peer ledger capability benefits cloud computing services which require functions such as, assured data provenance, auditing, management of digital assets, and distributed consensus. Blockchain's underlying consensus mechanism allows to build a tamper-proof environment, where transactions on any digital assets are verified by set of authentic participants or miners. With use of strong cryptographic methods, blocks of transactions are chained together to enable immutability on the records. However, achieving consensus demands computational power from the miners in exchange of handsome reward. Therefore, greedy miners always try to exploit the system by augmenting their mining power. In this paper, we first discuss blockchain's capability in providing assured data provenance in cloud and present vulnerabilities in blockchain cloud. We model the block withholding (BWH) attack in a blockchain cloud considering distinct pool reward mechanisms. BWH attack provides rogue miner ample resources in the blockchain cloud for disrupting honest miners' mining efforts, which was verified through simulations. Deepak K. Tosh, Sachin Shetty, Xueping Liang, Charles A. Kamhoua, Kevin A. Kwiat, Laurent Njilla |
CCGrid | 3 |
| 2017 | Towards a Trusted and Privacy Preserving Membership Service in Distributed Ledger Using Intel Software Guard Extensions
Xueping Liang, Sachin Shetty, Deepak K. Tosh, Peter Foytik, Lingchen Zhang |
ICICS | 1 |
| 2017 | Towards Decentralized Accountability and Self-sovereignty in Healthcare Systems
Xueping Liang, Sachin Shetty, Juan Zhao 0003, Daniel Bowden, Danyi Li, Jihong Liu |
ICICS | 1 |
| 2017 | Integrating blockchain for data sharing and collaboration in mobile healthcare applicationsabstractEnabled by mobile and wearable technology, personal health data delivers immense and increasing value for healthcare, benefiting both care providers and medical research. The secure and convenient sharing of personal health data is crucial to the improvement of the interaction and collaboration of the healthcare industry. Faced with the potential privacy issues and vulnerabilities existing in current personal health data storage and sharing systems, as well as the concept of self-sovereign data ownership, we propose an innovative user-centric health data sharing solution by utilizing a decentralized and permissioned blockchain to protect privacy using channel formation scheme and enhance the identity management using the membership service supported by the blockchain. A mobile application is deployed to collect health data from personal wearable devices, manual input, and medical devices, and synchronize data to the cloud for data sharing with healthcare providers and health insurance companies. To preserve the integrity of health data, within each record, a proof of integrity and validation is permanently retrievable from cloud database and is anchored to the blockchain network. Moreover, for scalable and performance considerations, we adopt a tree-based data processing and batching method to handle large data sets of personal health data collected and uploaded by the mobile platform. Xueping Liang, Juan Zhao 0003, Sachin Shetty, Jihong Liu, Danyi Li |
PIMRC | 1 |