Qingkuan Dong

dblp:21/3558 · DBLP profile ↗
← Back
15ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0001-8034-9170ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 1 first-author · 2 since 2021Computer networks · 5 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 PDFL: A Privacy-Enhancing and Robust Poisoning Defense Federated Learning Scheme
abstract
This paper addresses the security and privacy issues of the global models in Federated Learning by proposing a new approach, called PDFL, which tackles the challenges of poisoning attacks and privacy leakage in FL rounds. PDFL is based on secure multi-party computation and performs privacy-preserving cluster analysis on encrypted data from participants in order to identify malicious poisoning attackers. This approach involves a two-server mechanism and integrates four privacy-preserving protocols based on two-party computation (2PC): SecJudge for normalizing gradients, SecCosine for computing the cosine similarity values among gradients, SecClu for countering poisoning attacks, and SecAgg for secure aggregation by the server. These protocols are designed to achieve low computational costs, preserve client data privacy, and mitigate poisoning attacks from the potentially malicious clients. We provide a theoretical proof that our four sub-protocols and the PDFL scheme are both safe and reliable, demonstrating that PDFL can ensure the privacy and security of the participating data. Additionally, we conduct extensive simulation experiments to evaluate the accuracy, efficiency, computational overhead, and communication overhead associated with the PDFL scheme. Experimental results show the potential of the PDFL scheme in significantly enhancing the ability to identify malicious poisoning attackers in federated learning systems accurately and efficiently, hence making PDFL a promising solution for addressing privacy and security concerns in this domain.
Huiwen Wu, Qingming Li, Ziyao Liu, Jun Zhao 0007, Kwok-Yan Lam, Qingkuan Dong
IEEE Trans. Inf. Forensics Secur.7
2025 VFGCN: A Vertical Federated Learning Framework With Privacy Preserving for Graph Convolutional Network
abstract
Due to the robust representational capabilities of graph data, employing graph neural networks for its processing has demonstrated superior performance over conventional deep learning algorithms. Graph data encompasses abundant features and structural information; however, its large-scale collection is often challenging in practice. This difficulty arises because data predominantly exists in isolated compartments, making it arduous to harmonize information across various organizations or to enable multiple organizations to collaborate effectively while safeguarding local data privacy. In light of an extreme data distribution scenario, where each client possesses distinct nodes with partially overlapping segments yet divergent data features, we introduce a dual-cloud server architecture. This framework encompasses the design of four secure subprotocols: ReEnc (secure re-encryption), SecPSI (secure outsourcing of PSI), SecWeight (secure weight calculation), and SecAgg (secure aggregation). Together, these components facilitate a vertical federated learning framework for graph convolutional networks, ensuring privacy preservation. We provide a security proof for the entire system and extensive evaluation on three benchmark datasets (Cora, Citeseer, and Pubmed) illustrates that our Vertical Federated Graph Convolutional Network (VFGCN) surpasses existing privacy-preserving methodologies.
Qingming Li, Ximeng Liu, Xiaoran Yan, Qingkuan Dong, Huiwen Wu, Xiangjie Kong 0001
IEEE Trans. Dependable Secur. Comput.5
2023 Hitting Moving Targets: Intelligent Prevention of IoT Intrusions on the Fly
abstract
Massive Internet of Things (IoT) devices have been playing a critical role in both the cyber and physical worlds. Various cyber attacks pose significant risks to IoT. Machine learning-based intrusion detection system (IDS) has earned much research attention. However, the intrusion prevention system (IPS) is rarely explored. Realtime intrusion prevention is quite challenging because the decision has to be made during a flow rather than after it finishes. Restricted by aligning with the shortest flows, existing IPSs generally inspect only the very first packets, leading to information loss for accurate detection. In this article, we first measure the information loss quantitatively. Then we devise Sniper, an IoT IPS scheme consisting of a flow length predictor, a novel feature space, and an enhanced ensemble learning algorithm. The flow length predictor guides a proper prevention time point to preserve as much information as possible. The proposed Markov matrix-based feature encoding method further saves more information than existing ones. The enhanced learning algorithm ensures a low-false positive rate (FPR), which is critical for IPSs. We benchmark Sniper with one closed-world and three open-world data sets. The results show that Sniper achieves a 99.89% prevention rate and 0.03% FPR, which is superior to the five state-of-the-art baseline models.
Shuaishuai Tan, Wenyin Liu, Qingkuan Dong, Sammy Chan, Shui Yu 0001, Xiaoxiong Zhong, Daojing He
IEEE Internet Things J.3
2022 A new RFID ultra-lightweight authentication protocol for medical privacy protection in smart living
Xingmiao Wang, Kai Fan 0001, Kan Yang 0001, Xiaochun Cheng, Qingkuan Dong, Hui Li 0006, Yintang Yang
Comput. Commun.5
2022 Sneaking Through Security: Mutating Live Network Traffic to Evade Learning-Based NIDS
abstract
Machine learning based network intrusion system (NIDS) is known to be vulnerable to evasions. Attackers conceal intrusion activities to make them undetected. Researching evasion techniques contributes to evaluating and increasing the robustness of NIDS. Previous evasion approaches modify feature values or packets of an offline network trace as a whole. However, in real scenarios, attackers are constrained to manipulate only outbound packets on the fly. To bridge this assumption gap, we present the first evasion solution for live network traffic against learning based NIDSs. The solution consists of three components: a devised Kalman filter based algorithm to predicate the feature values of live flows, a set of formally constructed atomic packet mutation operators, and a proposed Strength Enhanced Deep Q-learning (SE-DQN) to determine effective mutation operators on outbound packets according to the predicted features. A defense scheme based on adaptive decision threshold adjustment is also provided. Experimental evaluation is presented on various NIDS classifiers and cyber attacks. Results show that SE-DQN achieves an evasion rate of at least 64.2% on most classifiers and even more than 90% on certain ones, and it is three times faster than DQN on learning mutation policy. The defense scheme shows an improvement of at least 76.4% on recall measurement.
Shuaishuai Tan, Xiaoxiong Zhong, Zhiyi Tian, Qingkuan Dong
IEEE Trans. Netw. Serv. Manag.4
2020 Energy-Efficient Neighbor Discovery for the Internet of Things
abstract
Internet of Things (IoT) networks are usually distributed in nature. Due to the possible mobility of IoT devices, it is common and critical for each IoT device to keep discovering who is in its neighborhood, referred to as neighbor discovery. Due to the limited battery capacity of IoT devices, it is challenging to design a neighbor discovery protocol (NDP) that can achieve both low duty cycle and low discovery latency. In this article, we build a model called Circle to characterize the process of neighbor discovery in IoT networks. Then, we give a necessary and sufficient condition for neighbor discovery and theoretically prove its correctness. This is the first time in the research community that a necessary and sufficient condition is given for neighbor discovery. According to the necessary and sufficient condition, we analytically derive a lower bound of the worst case discovery latency and demonstrate when the lower bound can be achieved. The analytical model is generic as it can be used to analyze existing NDPs. Based on the Circle model and the analysis, we propose an NDP, which is also called Circle. We compare Circle with the state-of-the-art NDPs in a real testbed, and experimental results show that Circle is superior to the existing state-of-the-art NDPs.
Zhong Shen, Hai Jiang 0001, Qingkuan Dong, Baocang Wang
IEEE Internet Things J.3
2017 Natural sd-RCCA Secure Public-Key Encryptions
Yuan Chen 0008, Qingkuan Dong, Qiqi Lai
ProvSec2
2016 A similarity-based indirect trust model with anti-spoofing capability
abstract
Abstract Trust management has become an emerging security paradigm in various areas such as ad hoc networks and cloud computing. One core element of trust management is the indirect trust model that evaluates the trustworthiness of a target based on others' recommendations. The research on indirect trust is still at an early stage, and some problems are not addressed yet. Because of the subjectivity of trust, entities would have different views on a same target. Consequently, after receiving recommendations, the evaluating entity should first measure their credibility. Existing methods often distort recommendations. We propose a more reasonable method based on the similarity between recommenders and evaluating entities. Furthermore, considering the characteristics of one‐hop and multi‐hop recommendations, the similarity calculation methods for them were developed individually. Another problem is the spoofed recommendations aiming at tarnishing someone or harboring conspirators. We design a simple but efficient algorithm to detect and remove them. The proposed methods and algorithms constitute the integrated indirect trust model. This model is not bound to any specific domain, and thus it can be widely applied. Simulation results show that the model is effective in obtaining an objective indirect trust value with the existence of personalized and dishonest recommenders. Copyright © 2017 John Wiley & Sons, Ltd.
Shuaishuai Tan, Yanming Liu 0001, Xiaoping Li 0004, Qingkuan Dong
Secur. Commun. Networks4
2015 Trust based routing mechanism for securing OSLR-based MANET
Shuaishuai Tan, Qingkuan Dong
Ad Hoc Networks3
2015 Achieving CCA security from DCCA security more efficiently by using the KEM+DEM hybrid paradigm
abstract
Abstract Detectable Chosen Ciphertext (DCCA) security is a useful notion to achieve CCA security for public‐key encryptions (PKE). An “inner‐outer” structure can transform a DCCA‐secure PKE into a CCA‐secure one. In the structure, the “inner” layer encrypts both the message and the two embedded randomness, so a key encapsulated mechanism (KEM) + data encapsulation mechanism (DEM) hybrid paradigm helps to gain time efficiency. Nevertheless, the long “inner” ciphertext still makes the “outer” encryption less efficient. We show that the structure can be applied solely on the KEM part, and even the embedded randomness can be encrypted outside the structure by introducing a CCA‐secure DEM. These reduce the length of the “inner” ciphertext, thus avoiding some redundant re‐encryptions in the “outer” layer and offload as much of the work as possible from KEMs to faster DEMs. Combined with a recent improvement made on the “outer” layer, we can gain better time and space efficiency. Additionally, we prove that when a DCCA‐secure KEM satisfies the so‐called “translatability”, a proper related‐key secure DEM helps to achieve CCA security directly by applying the hybrid paradigm without any use of the less efficient “inner‐outer” structure. Copyright © 2015 John Wiley & Sons, Ltd.
Yuan Chen 0008, Qingkuan Dong
Secur. Commun. Networks2
2015 Improvement and optimized implementation of cryptoGPS protocol for low-cost radio-frequency identification authentication
abstract
Abstract In radio‐frequency identification (RFID) authentication technology, the authentication schemes between reader and tag based on public‐key cryptography (PKC) are much better than those based on symmetric‐key cryptography in terms of expanding the scale of RFID applications and the style of providing service, while the limitation of resource consumption and computation capability of RFID tags makes it difficult to apply traditional PKC to RFID authentications. The cryptoGPS protocol based on PKC proposed by Mcloone and Robshaw suits low‐cost RFID system well, but it just achieves one‐way authentication, and the authentication times are very limited, which makes it vulnerable to coupons‐exhausted DoS attacks. To solve these problems, cryptoGPS protocol is greatly improved to realize the mutual authentication between RFID reader and the tag. In the improved protocol, a readers' public key distribution scheme is proposed to support the mutual authentication and a coupons updating algorithm is presented to resist the aforementioned DoS attack. Moreover, a modified Rabin encryption algorithm and a parameter generation method based on Low Hamming Weight technology are proposed to optimize the implementation of the proposed authentication protocol. And a feasible hardware structure of the protocol is also given. The protocol's simulation results show that the scheme just needs 3232 equivalent gates, and the maximum time of single step is 3.3 ms (500 k clock). The scheme is suitable for the low‐cost tags. Copyright © 2014 John Wiley & Sons, Ltd.
Qingkuan Dong, Wenxiu Ding
Secur. Commun. Networks1
2014 RCCA security for KEM+DEM style hybrid encryptions and a general hybrid paradigm from RCCA-secure KEMs to CCA-secure encryptions
abstract
ABSTRACT Replayable chosen‐ciphertext attack (RCCA) security is a weaker notion than chosen‐ciphertext attack (CCA) security and has been proven to be sufficient for several cryptographic tasks. However, it is open to construct RCCA‐secure schemes more efficient than CCA‐secure ones. This paper adapts RCCA security to the most popular hybrid paradigms, KEM+DEM and Tag‐KEM/DEM. For KEM+DEM paradigm, we show RCCA security is consistent with the CCA case, just as desired. But for Tag‐KEM/DEM paradigm, we find some different status. Natural RCCA‐secure Tag‐KEM schemes can be easily constructed, which are more efficient than all existing CCA‐secure ones. But unfortunately, passive security of DEM is not sufficient to obtain RCCA hybrid encryptions. In spite of this and for completeness, we show RCCA‐secure DEMs are still sufficient. On the other hand, for passive secure DEMs, we prove that a stronger notion of RCCA security for Tag‐KEM, named as tRCCA security, suffices for RCCA‐secure hybrid encryptions. This somewhat suggests that a benign RCCA security for tag‐based schemes should be tRCCA security. Finally, to show RCCA‐secure KEM is sufficient for achieving CCA‐secure hybrid encryptions, we introduce a new hybrid paradigm, named as KEM/Tag‐DEM, where the ciphertext of KEM is used as a tag for Tag‐DEM scheme rather than reversely in Tag‐KEM/DEM, so that the security of KEM can be weakened to RCCA one. KEM/Tag‐DEM shows the diversity of hybrid encryptions and has additional practical values. We also show Tag‐DEMs can be constructed as efficiently as DEMs. Copyright © 2013 John Wiley & Sons, Ltd.
Yuan Chen 0008, Qingkuan Dong
Secur. Commun. Networks2
2012 RCCA Security for KEM+DEM Style Hybrid Encryptions
Yuan Chen 0008, Qingkuan Dong
Inscrypt2
2012 Two extensions of the ring signature scheme of Rivest-Shamir-Taumann
Qingkuan Dong, Xiaoping Li 0004, Yanming Liu 0001
Inf. Sci.1
2009 A Dynamic Layering Scheme of Multicast Key Management
abstract
Group key management is a difficult task in implementing large and dynamic secure multicast. In this paper, a new scheme is proposed in the basis of in-depth analysis of the requirements of the secure multicast and group key management. The scheme is based on the multicast group security architecture and multicast security group key management architecture proposed by IETF. This scheme constructs group key based on pairings and distributes the group key using HSAH function polynomial, and manages group key making use of the dynamic layering GCKS. The scheme is better in security, lower in computation cost and communication cost. The analysis comparison proves that the scheme has strong scalability and efficiency.
Xiaoping Li 0004, Qingkuan Dong, Yanming Liu 0001
IAS3