VLDB 2026 Research / reviewers in the wild / expert
Junsong Fu 0001
dblp:217/7590-1 · also Jun-Song Fu 0001
· DBLP profile ↗
36ranked-venue papers
5as first author
29since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 10 since 2021Computer networks · 9 · 1 first-author · 9 since 2021Systems, architecture and hardware · 7 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | VLMS: Verifiable Lattice-Based Encryption With Multi-Keyword Search in Cloud Storage
Na Wang 0003, Wen Zhou 0021, Jingjing Wang 0001, Junsong Fu 0001, Jianwei Liu 0001, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Adaptive Target Device Model Identification Attack in 5G Mobile NetworkabstractEnhanced system capacity is one of 5G goals. This will lead to massive heterogeneous devices in mobile networks. Mobile devices that lack basic security capability have chipset, operating system or software vulnerability. Attackers can perform Advanced Persistent Threat (APT) Attack for specific device models. In this paper, we propose an Adaptive Target Device Model Identification Attack (ATDMIA) that provides the prior knowledge for exploiting baseband vulnerability to perform targeted attacks. We discovered Globally Unique Temporary Identity (GUTI) Reuse in Evolved Packet Switching Fallback (EPSFB) and Leakage of User Equipment (UE) Capability vulnerability. Utilizing silent calls, an attacker can capture and correlate the signaling traces of the target subscriber from air interface within a specific geographic area. In addition, we design an adaptive identification algorithm which utilizes both invisible and explicit features of UE capability information to efficiently identify device models. We conducted an empirical study using 105 commercial devices, including network configuration, attack efficiency, time overhead and open-world evaluation experiments. The experimental results showed that ATDMIA can accurately correlate the EPSFB signaling traces of target victim and effectively identify the device model or manufacturer. Shaocong Feng, Baojiang Cui, Junsong Fu 0001, Meiyi Jiang, Shengjia Chang |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2026 | A Multi-Semantic Scheme to Verifiable EHRs Retrieval for Cloud-Based TelemedicineabstractAs the cornerstone of telemedicine, Electronic Health Records (EHRs) not only reduce clinical costs but also enable precision diagnostics. As medical institutions increasingly outsource EHRs to Cloud Service Providers (CSPs), dual challenges have emerged as critical issues: preserving patient privacy and enhancing the search experience for medical personnel. While multi-keyword searchable encryption has gained significant attention in the medical domain as a potential solution, existing schemes have significant limitations in both practicality and security. First, the growing number of medical institutions complicates the management of key and privileges. Second, the impoverished search semantics in existing query mechanisms severely degrades the clinical user experience, creating unacceptable operational bottlenecks in medical practice. Furthermore, excessive reliance on CSPs leads to ignoring situations where the returned results are incorrect, impacting the availability and security of the telemedicine system. To address these limitations, we propose a Verifiable Multi-Semantic Keyword Search scheme (VMSKS) for EHRs in cloud-based telemedicine. To resolve the security requirements arising from the increasing medical institutions, we innovatively design a more efficient dual Securek-Nearest Neighbor technique (SKNN) for key distribution. Meanwhile, fine-grained access control is implemented using access policy trees, ensuring the controllability of data access. This approach safeguards the privacy of EHRs. To support flexible EHR search for medical personnel, the prime Hadamard product encoding technique is exploited to provide queries that support multiple search semantics simultaneously. Given the potential unreliability of CSPs, VMSKS introduces a novel verification mechanism by constructing verification proofs during encryption, ensuring the authenticity and integrity of returned results. Theoretical analysis and experimental evaluation demonstrate the security and efficiency of VMSKS, respectively. Na Wang 0003, Guizhen Chen, Jianwei Liu 0001, Junsong Fu 0001 |
IEEE Trans. Netw. | 4 |
| 2025 | A Verifiable and Efficient Multi-Keyword Fuzzy Rank Search Scheme Over Encrypted Data With Privacy-PreservingabstractABSTRACT Searchable Encryption (SE) enables searching over encrypted data. Exact keyword search is supported in most SE schemes, which achieve higher search accuracy but suffer from lower completeness due to the inability to handle similar expressions. To realize fuzzy keyword search, some schemes employ Bloom Filters (BFs), but these may incur high false positive rates and risk exposing the Bloom Filter's internal values to cloud servers (CS). Besides, most existing schemes ignore the fact that CS may engage in malicious behaviors (e.g., undercounting parameters or forging results). To address these issues, we propose an efficient and verifiable ranked fuzzy multi‐keyword search scheme based on BFs. We propose a Twin Bloom Filter (TBF) to conceal insertion positions and introduce random numbers to obfuscate uninserted bits. Search results are ranked using Term Frequency‐Inverse Document Frequency (TF‐IDF) scores to improve relevance. To ensure correctness and integrity, we employ Real Homomorphic Message Authentication Codes (RealHomMAC) and a random challenge technique, respectively. Security analysis proves that our scheme remains secure under both the known‐ciphertext model and the known‐background model. Theoretical and experimental performance analysis confirms that our scheme achieves efficient and accurate keyword search. Fengyi Gao, Na Wang 0003, Jianwei Liu 0001, Zhiquan Liu 0001, Junsong Fu 0001, Lunzhi Deng |
Concurr. Comput. Pract. Exp. | 5 |
| 2025 | An Efficient and Privacy-Preserving Range Retrieval Scheme for Location-Based ServicesabstractWith the rapid development of positioning technology and mobile devices, location-based services (LBS) have witnessed extensive adoption. However, privacy leakage issues have become increasingly severe. Existing solutions often focus solely on protecting users’ location privacy while neglecting query privacy requirements, and further exhibit suboptimal retrieval efficiency when handling large-scale datasets. To comprehensively preserve user and server privacy while enhancing data retrieval efficiency, this paper proposes an efficient and privacy-preserving range retrieval scheme for location-based services (EPRL). The scheme proposes a Geohash-based query range generation algorithm, enabling users to generate query ranges according to their privacy requirements dynamically. To protect the user’s location privacy and query privacy, EPRL employs a ring signature policy. Furthermore, we innovatively design a Geohash-Trie Tree structure to store server data resources, effectively improving retrieval efficiency. Theoretical analysis and extensive experiments indicate that compared with other state-of-the-art LBS retrieval schemes, EPRL exhibits broader applicability, lower computational costs, and higher efficiency. When the number of ring signature users reaches 1,000, the total computational overhead of the scheme is approximately 5 seconds, merely one-fifth of that required by similar schemes. Haojia Qi, Guobiao He, Na Wang 0003, Jianwei Liu 0001, Junsong Fu 0001, Zhiquan Liu 0001 |
IEEE Internet Things J. | 5 |
| 2025 | Privacy-Preserving IoT Data Retrieval Scheme With Lightweight Fine-Grained Access Control in Cloud ComputingabstractWith the rapid development of cloud computing technology, cloud services, represented by cloud storage and data retrieval, have been widely researched in Internet of Things (IoT). As a result, various data retrieval schemes have been proposed. The multikeyword Ranked Searchable Encryption Scheme (MRSE) was developed to improve the accuracy and experience of users searching data. However, MRSE has its drawbacks, such as the security risk of key leakage and limited functionality. Therefore, this article proposes a Privacy-preserving IoT Data Retrieval Scheme (PDRS) that supports lightweight fine-grained access control. We analyze the risk of key information leakage in MRSE, and perform permutation operations on encrypted indexes and trapdoors in PDRS to prevent key leakage and improve system security. Furthermore, in IoT scenarios with multiusers and multikeys, the secure user identity authentication mechanism ensures that only authorized users can acquire legitimate keys to generate search trapdoors, preventing malicious users from impersonating legitimate users and accessing private data. A novel polynomial-based access control is designed to realize attribute-based fine-grained access control, which enables resource-limited devices to limit data access to data users and achieves lightweight overhead. Finally, a formal theoretical analysis demonstrates that PDRS is secure. Simulation experiments verify that PDRS is efficient and lightweight. Wen Zhou 0021, Na Wang 0003, Zhiquan Liu 0001, Junsong Fu 0001, Lunzhi Deng, Qianhong Wu |
IEEE Internet Things J. | 4 |
| 2025 | Graph Learning on Instruction Stream-Augmented CFG for Malware Variant DetectionabstractAs malware as a service (MaaS) and organized attacks develop and drive a shift in malware variant generation mechanism, current variant detection, designed to counter conventional obfuscation and anti-detection strategies, falls short in facing new challenges, particularly in identifying variants that maintain core functionalities while altering local behaviors, or those sharing similar code logic but diverge in actual functionalities. To tackle the problems, we present ISCMVD, an Instruction Stream-augmented CFG-based Malware Variant Detection scheme, melding control flow structures with machine semantic information from instruction streams within blocks to build a comprehensive functional representation for variants’ basic and detailed behaviors. Leveraging a global-enhanced attentive graph neural network to integrate local and global functional features, we significantly boost the capture of representative stable primary behaviors’ similarity from variants within the same family identifying variants generated under attackers’ code rewriting, module modification, and other transformation means. Additionally, through cross-family associative analysis, we eliminate classification interference of variants’ logic similarities stemming from the same organization generating. Evaluation results on public and real-world datasets demonstrate the superiority and robustness of ISCMVD with an average of 99.29% in AC and 99.25% in F1 and perform well even in few-shot cases. What’s more important, we achieve a breakthrough in two special sample sets including variants related to MaaS and APT group, and outperform state-of-the-art methods under the current variant generation mechanism, proving its suitability for future trends. Jiaxin Mi, Qi Li 0057, Zewei Han, Weilue Liao, Junsong Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | An Efficient and Secure Spatial Keyword Ciphertext Retrieval Scheme Based on Cloud-Fog CollaborationabstractLocation-Based Services are increasingly common in our lives. In order to reduce user overhead, the data owner stores the location information and text data on the cloud server, and the user completes the retrieval task with the help of the fog server. To protect the privacy of outsourced data, many secure spatial keyword retrieval schemes have been proposed. Most schemes use R-tree indexes to improve the efficiency of ciphertext retrieval, but the encrypted R-tree index is hard to update. Moreover, some indexes based on order-preserving encryption are vulnerable to frequency-revealing attacks. So how to balance efficiency and security is a problem. To solve the above problems, we propose an efficient and secure spatial keyword ciphertext retrieval scheme based on cloud-fog collaboration. First, we innovatively design the SK-tree. The Geohash algorithm and Simhash algorithm are used in SK-tree to compress information, achieving efficient retrieval. Secondly, our retrieval tree has the function of fuzzy order preservation, which can better hide the correspondence between plaintext and ciphertext compared to traditional index-based order-preserving encryption schemes. In addition, we design a cloud-fog-user interaction scheme for attribute-based encryption that can hide access control policies, which reduces the computational overhead for the user side. Finally, we prove through theoretical analysis that our scheme ensures cloud data security and query trap information privacy. We compare our scheme with others through simulation experiments to demonstrate its superiority in efficiency. Na Wang 0003, Junsong Fu 0001, Lunzhi Deng, Jianwei Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | ReTrial: Robust Encrypted Malicious Traffic Detection via Discriminative Relation Incorporation and Misleading Relation CorrectionabstractEncryption techniques greatly ensure the confidentiality and integrity of network communications. However, they also allow attackers to conceal malicious activities within encrypted traffic, posing severe cybersecurity challenges. Current detection methods primarily rely on statistics and correlation analysis. However, both statistical features and inter-entity relations can be easily obfuscated. Moreover, issues with low-quality data and fixed feature sets limit the generalizability and adaptability to defend against various evasion techniques. Robustifying encrypted malicious traffic detection in adverse conditions is still an open problem. In this paper, we propose ReTrial, a robust encrypted malicious traffic detection system via discriminative relation incorporation and misleading relation correction. The key motivations behind ReTrialare to accurately leverage the rich relations among flows for contextual analysis, and correct misleading ones for robust threat detection. Specifically, we construct a relational multigraph and develop a tailored Graph Attention Network (GAT) to selectively incorporate contextual information. Then we retrieve multi-order neighborhood similarity graphs as observations for adaptive relation correction. Following an iterative scheme, both detector performance and graph topology mutually optimize. To validate the robustness of ReTrial, we simulate various adverse conditions by randomly dropping packets and greedily injecting perturbation edges. The experimental results show that ReTrialis competitive in ideal condition. Under adverse conditions, though the performances of other state-of-the-art methods degrade significantly, ReTrialconsistently exhibits superior performance with a maximum reduction of only 5.88% in F1, highlighting its robustness in threat detection. Jianjin Zhao, Qi Li 0057, Zewei Han, Junsong Fu 0001, Guoshun Nan, Meng Shen 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | A Privacy-Preserving IoT Data Access Control Scheme for Cloud-Edge ComputingabstractIn Internet of Things(IoT), the combination of cloud computing and edge computing becomes a new computing paradigm to provide users with low-latency data services. However, for the limited resource, high dynamic, and wide distributed characteristics of IoT devices, it becomes a great challenge to realize the universal application of edge servers and the cloud-edge computing allocation. Meanwhile, most of the schemes ignore the leakage of data access pattern privacy when accessing data. Therefore, in this paper, we propose a privacy-preserving access control scheme for IoT data. Based on the cloud-edge-end framework, we design a pervasive edge computing protocol, which allows well-resourced devices to become edge servers at suitable geographic locations and users to outsource and access IoT data through the nearest edge server. It increases the flexibility of the cloud-edge collaborative system as well as the efficiency of data processing. Users do not need to interact beyond the network edge to enjoy the data services. Furthermore, a novel attribute-based encryption scheme is designed based on a modified Lightweight Secret Sharing Scheme to optimize computing task allocation and reduce the computation burden on end devices, without attribute information leakage. In addition, we also design a Transform algorithm and a Cloud-edge Interaction protocol to hide access pattern privacy efficiently. We analyze the feasibility of the scheme and demonstrate that the scheme is semantically secure and conceals access pattern privacy. Simulation experiments based on real IoT data show that the scheme is efficient and suitable for IoT scenarios. Jingjing Wang 0001, Na Wang 0003, Wen Zhou 0021, Jianwei Liu 0001, Junsong Fu 0001, Lunzhi Deng |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2025 | A Lightweight and Fine-Grained Ciphertext Search Scheme for Big Data Assisted by Proxy ServersabstractIn big data scenarios, the data volume is enormous. Data computation and storage in distributed manner with more efficient algorithms is promising. However, most current ciphertext search schemes are designed for the centralized cloud computing platforms and they are inefficient and inapplicable in big data scenarios. A proxy server based system is a cloud computing extension. This new pattern moves some of the data storage and computation burden from end users to the edge servers and it greatly decrease the resource costs of data users. In this paper, we propose a searchable encryption scheme assisted by cloud computing and proxy servers for big data, which can accomplish Lightweight Fine-grained access control and Efficient multi-keyword top-k ciphertext Search synchronously (LFES). To cope with all types of data, we design an innovative fine-grained access control mechanism based on attribute-based encryption and key distribution protocol. Thus, the scheme only allows users with licensed attributes to access data efficiently. Then, a public key searchable encryption scheme is proposed based on privacy Protection Set Intersection (PSI) and the proxy server model. Our scheme greatly reduces the computation burden on end-users and improves retrieval efficiency. Meanwhile, to prevent tampering with stored ciphertexts, a practical data integrity audit mechanism is also designed. Security analysis illustrates that the LFES can resist Chosen Keyword Attack (CKA) and Keyword Guessing Attack (KGA). Finally, the simulation shows that the LFES is efficient and feasible in practice. Na Wang 0003, Kaifa Zheng, Wen Zhou 0021, Jianwei Liu 0001, Lunzhi Deng, Junsong Fu 0001 |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2024 | The blockchain-based privacy-preserving searchable attribute-based encryption scheme for federated learning model in IoMTabstractAbstract Federated learning enables training healthcare diagnostic models across multiple decentralized devices containing local private health data samples, without transferring data to a central server, providing privacy‐preserving services for healthcare professionals. However, for a model of a specific field, some medical data from non‐target participants may be included in model training, compromising model accuracy. Moreover, diagnostic queries for healthcare models stored in cloud servers may result in the leakage of the privacy of healthcare participants and the parameters of models. Furthermore, the records of model searching and usage could be tracked causing privacy disclosure risk. To address these issues, we propose a blockchain‐based privacy‐preserving searchable attribute‐based encryption scheme for the diagnostic model federated learning in the Internet of Medical Things (BSAEM‐FL). We first adopt fine‐grained model trainer participation policies for federated learning, using the attribute‐based encryption (ABE) mechanism, to realize model accuracy and local data privacy. Then, We employ searchable encryption technology for model training and usage to protect the security of models stored in the cloud server. Blockchain is utilized to implement distributed healthcare models' keyword‐based search and model users' attribute‐based authentication. Lastly, we transfer most of the computational overhead of user terminals in model searching and decryption to edge nodes, achieving lightweight computation of IoMT terminals. The security analysis proves the security of the proposed healthcare scheme. The performance evaluation indicates our scheme is of better feasibility, efficiency, and decentralization. Ziyu Zhou 0002, Na Wang 0003, Jianwei Liu 0001, Junsong Fu 0001, Lunzhi Deng |
Concurr. Comput. Pract. Exp. | 4 |
| 2024 | A formal security analysis of the fast authentication procedure based on the security context in 5G networks
Baojiang Cui, Haitao Du, Jie Xu 0038, Junsong Fu 0001 |
Soft Comput. | 6 |
| 2024 | A Lightweight Privacy-Preserving Ciphertext Retrieval Scheme Based on Edge ComputingabstractWith the rapid development of cloud computing and Internet of Things (IoT) technologies, large amounts of data collected from IoT devices are encrypted and outsourced to cloud servers for storage and sharing. However, traditional ciphertext retrieval schemes impose high computation and storage overhead on end users. Meanwhile, IoT devices with limited resources are difficult to adapt to large amounts of data computation and transmission, which leads to transmission delay and poor user experience. In this article, we propose a lightweight privacy-preserving ciphertext retrieval scheme based on edge computing (LPCR) by extending searchable encryption (SE) and ciphertext policy attribute-based encryption (CP-ABE) techniques. First, to avoid network delay and paralysis, we introduce edge servers into LPCR and design a collaboration mechanism between the user side and the edge servers. The user side only needs to accomplish lightweight computation and storage tasks, which greatly reduces their resource consumption. Second, we extend the basic ciphertext policy attribute-based keyword search (CP-ABKS) technique and design the Linear Secret Sharing Scheme (LSSS) access control algorithm with attribute values to hide access policies and attributes. In addition, to improve the retrieval accuracy, the document indexes and query trapdoors are set up by conjunctive keywords to help the cloud server locate exactly the data that the user wishes to query. Formal security analysis verifies that LPCR can achieve the security of chosen plaintext attack (CPA) and chosen keyword attack (CKA), and resist collusion attack. Simulation experiments prove that LPCR is lightweight and feasible. Na Wang 0003, Wen Zhou 0021, Qingyun Han, Jianwei Liu 0001, Weilue Liao, Junsong Fu 0001 |
IEEE Trans. Cloud Comput. | 6 |
| 2024 | A Framework of High-Speed Network Protocol Fuzzing Based on Shared MemoryabstractIn recent years, security test of network protocols based on fuzzing has been attracting more and more attentions. This is very challenging compared with the stateless software fuzzing and most early network protocol fuzzers are of low speed and poor test effect. Since the first greybox and stateful fuzzer named AFLNET was proposed, several new schemes have been designed to improve its performance from different aspects. During the research, a great challenge is how to greatly improve the fuzzing efficiency. Based on the basic analysis in SNPSFuzzer, this paper provides a more thorough analysis about the time consumption in a fuzzing iteration for 13 network protocols and then we design a High-speed Network Protocol Fuzzer named HNPFuzzer. In HNPFuzzer, the test cases and response messages between the client and server are transmitted through the shared memory, guided by a precise synchronizer, rather than the socket interfaces. This greatly shorten the period of an iteration. Moreover, we design a persistent mode attempting to fuzz the service instances in the memory more than one time based on analyzing the side effect information. This mode further improves the speed of fuzzing. Experiment results illustrate that our scheme can improve the fuzzing throughput by about 39.66 times in average and triggers a large number of crashes including 2 new vulnerabilities which cannot discovered by existing fuzzers. Note that, the existing network protocol fuzzing schemes proposed in different directions do not compete with each other and on the contrary, they can collaborate with each other to improve the overall fuzzing effect and efficiency. Consequently, more existing tools can be integrated into our framework to get better network protocol fuzzing effect. Junsong Fu 0001, Shuai Xiong, Na Wang 0003, Ruiping Ren, Ang Zhou, Bharat K. Bhargava |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic AlgorithmabstractAlthough Tor is designed to provide anonymity, website fingerprinting (WF) attacks have posed significant threats to user privacy. In response, various defense approaches have been developed. Randomization and regularization-based defenses are criticized to be inefficient due to their bandwidth-consuming nature. Some adversarial learning-based defenses are impractical because the generation of perturbation depends on the complete traffic traces. Other adversarial learning-based defenses have weaknesses of lacking adaptability because their perturbations are input-agnostic. To overcome these shortcomings, we propose RUDOLF, an efficient and adaptive WF defense based on the soft actor-critic (SAC) algorithm of reinforcement learning (RL). We train the agent that can incrementally output perturbations synchronously following each burst of real-time traffic. Different from previous defenses, RUDOLF’s perturbation does not depend on the integrity of the traffic and concerns the actual real-time traffic, which ensures the practicality of implementation and adaptability. Besides, we take advantage of the exploratory characteristics of the SAC algorithm to obtain the optimal policy of adding perturbations that can efficiently balance defense effects and bandwidth consumption. Experiments on synthetic datasets show that with less than 30% bandwidth overhead (BWO), RUDOLF can reduce the average attack accuracy to around 15%–20%, which is superior to previous works. We also have implemented RUDOLF as a Tor pluggable transport. The performance in the real Tor network shows that RUDOLF can reduce the average accuracy of WF classifier to around 24% with about 25% BWO and almost no time delay. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Secure and Efficient Similarity Retrieval in Cloud Computing Based on Homomorphic EncryptionabstractWith the rapid development of cloud computing, massive amounts of data are uploaded to cloud servers for storage. For privacy protection, sensitive data should be encrypted before outsourcing, and ciphertext retrieval technologies based on similarity come into being. In cloud computing with massive data, the efficiency and accuracy of retrieval are crucial. However, most of the current similarity retrieval schemes do not perform well in these two aspects. Therefore, we propose SESR scheme, a secure and efficient similarity retrieval scheme based on homomorphic encryption. Firstly, we use Hamming distance to calculate the similarity between the feature vector of the data and query vector from the data user. Secondly, the homomorphic encryption algorithm is used to encrypt data to protect data privacy. Furthermore, we creatively design a BK-KD tree structure that hierarchically implements similarity search and fine-grained access control, thereby speeding up the retrieval efficiency. In addition, we design a two-cloud-server cooperative retrieval model and a message authentication scheme, which ensure access pattern privacy security and the integrity of the transmitted data simultaneously. We also propose an improved SESR scheme. In this scheme, we use Simhash algorithm to generate feature vectors and query vectors, which reduces storage overhead. Finally, the security of SESR is formally proved and the simulation results show the efficiency and accuracy of the retrieval scheme. Na Wang 0003, Wen Zhou 0021, Jingjing Wang 0001, Junsong Fu 0001, Jianwei Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | KimeraPAD: A Novel Low-Overhead Real-Time Defense Against Website Fingerprinting Attacks Based on Deep Reinforcement LearningabstractThe onion router (Tor) is a network system for anonymous communication. However, website fingerprinting (WF) attacks have threatened the anonymity of Tor. WF attackers can passively monitor and collect traffic, classify the victims’ traffic based on machine learning or deep learning, and identify the websites the victims visit. In recent years, there has been some research on WF defense, but most of the works have high bandwidth and latency overhead. Besides, some defenses are criticized as being unrealistic to implement in real-time due to the need for prior knowledge of the traffic’s exact packet sequences, and the lengths of sequences. In this paper, we propose KimeraPAD, a defense against WF attacks based on deep reinforcement learning. Specifically, our method first trains an agent to generate perturbations confusing the attacker’s classifier. To overcome the weak point of WF defense based on adversarial learning, we then design the implementation method and incur randomness so that it can inject dummy packets in real time and resist adversarial training. Experimental results demonstrate that our method can greatly reduce attack accuracy with a low bandwidth overhead. Besides, KimeraPAD can also be implemented on the client side, which simplifies the implementation a lot while achieving excellent performance. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | 3D-IDS: Doubly Disentangled Dynamic Intrusion DetectionabstractNetwork-based intrusion detection system (NIDS) monitors network traffic for malicious activities, forming the frontline defense against increasing attacks over information infrastructures. Although promising, our quantitative analysis shows that existing methods perform inconsistently in declaring various unknown attacks (e.g., 9% and 35% F1 respectively for two distinct unknown threats for an SVM-based method) or detecting diverse known attacks (e.g., 31% F1 for the Backdoor and 93% F1 for DDoS for a GCN-based state-of-the-art method), and reveals that the underlying cause is entangled distributions of flow features. This motivates us to propose 3D-IDS, a novel method that aims to tackle the above issues through two-step feature disentanglements and a dynamic graph diffusion scheme. Specifically, we first disentangle traffic features by a non-parameterized optimization based on mutual information, automatically differentiating tens and hundreds of complex features of various attacks. Such differentiated features will be fed into a memory model to generate representations, which are further disentangled to highlight the attack-specific features. Finally, we use a novel graph diffusion method that dynamically fuses the network topology for spatial-temporal aggregation in evolving data streams. By doing so, we can effectively identify various attacks in encrypted traffics, including unknown threats and known ones that are not easily detected. Experiments show the superiority of our 3D-IDS. We also demonstrate that our two-step feature disentanglements benefit the explainability of NIDS. Chenyang Qiu 0001, Yingsheng Geng, Junrui Lu, Kaida Chen, Shitong Zhu, Ya Su, Guoshun Nan, Junsong Fu 0001, Qimei Cui, Xiaofeng Tao 0001 |
KDD | 9 |
| 2023 | Multiuser Personalized Ciphertext Retrieval Scheme Based on Deep LearningabstractWith the rapid development of cloud computing technology and Internet of Things (IoT), enterprises and organizations tend to outsource local data to cloud servers and use searchable encryption (SE) technology to access and search encrypted data. However, the existing symmetric SE (SSE) schemes pay less attention to multiuser environments and users’ interest, which cause poor experience to users. In this article, we propose a multiuser personalized ciphertext search scheme (MPCS) by extending deep learning technology and SSE technology, which can achieve personalized retrieval and multiuser retrieval at the same time. MPCS achieves secure transmission of document keys and fine-grained access control by combining matrix decomposition and ciphertext policy attribute-based encryption (CP-ABE) technology, which assigns different private keys to each authorized user in the system and allows setting different access rights for different users. Second, we build an interest model for different users and design a user query update algorithm based on the attention mechanism to provide personalized ranking results, which improves the retrieval experience of users. In addition, the computation overhead of MPCS is lightweight, the size of ciphertext and key will not increase linearly with the number of attribute values, and MPCS supports lightweight document updates, which greatly reduces the computation overhead of the system. Formal security analysis verifies the security of MPCS, and simulation experiments on real data sets show that MPCS is feasible and efficient in practice. Na Wang 0003, Qingyun Han, Junsong Fu 0001, Jianwei Liu 0001 |
IEEE Internet Things J. | 3 |
| 2023 | An Attack to One-Tap Authentication Services in Cellular NetworksabstractThe One-Tap Authentication (OTAuth) based on the cellular network is a password-less login service provided by Mobile Network Operator (MNO) through the unique communication gateway access technique. The service allows app users to quickly sign up or log in with their mobile phone numbers without entering a password. Due to its convenience, OTAuth has been widely used by various apps. However, some studies have elaborated that OTAuth services are of great drawbacks from the perspective of mobile security and identified several flawed designs, which make the MNO cannot distinguish malicious apps from normal ones and cause impersonation attacks. In this paper, we further analyze OTAuth services from the perspective of 4G and 5G cellular networks and focus on two important procedures in which the cellular network plays an important role in OTAuth services. Not surprisingly, we discover a new fundamental design flaw in determining whether the runtime environment supports OTAuth services. Moreover, we propose a mature attack paradigm by exploiting this flaw, which allows an attacker to login or register one app as a victim. To evaluate the impact of the attack, we have examined 100/90/100 Android/iOS/HarmonyOS apps for OTAuth services of 3 main-stream MNOs in China. The experimental results show that our proposed attack is applicable to almost all the apps that support OTAuth services, and affects more apps than the attacks that have been reported before. Finally, we propose several counter-measures to defend against the attack. Note that, for security’s sake, we have already reported our findings to authorized parties and received their confirmations. Baojiang Cui, Junsong Fu 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Lightweight and Secure Data Transmission Scheme Against Malicious Nodes in Heterogeneous Wireless Sensor NetworksabstractWith the continuous development of sensor technology, more and more users hope to monitor and collect information in a certain area safely and efficiently by deploying heterogeneous wireless sensor networks (HWSNs). However, nodes in HWSNs have limited capabilities, which leads to many security challenges. Existing data transmission schemes in HWSNs take measures to resist these security threats, which aggravate the node computation overhead and increase the network energy consumption. This paper proposes a Lightweight and Secure Data Transmission (LSDT) scheme against malicious nodes in heterogeneous wireless sensor networks. Firstly, considering node capabilities limitations in HWSNs, we design a lightweight secret sharing scheme based on XOR operation, which maps data to multiple shares and makes it convenient to transmit shares separately to the sink node via multiple paths. While guaranteeing data security, this scheme can greatly reduce the computation overhead of nodes compared with traditional secret sharing schemes. Further, during the delivery of shares, the network may be attacked by malicious nodes, causing the interruption of message transmission. Therefore, we design a malicious node detection and feedback mechanism, which can quickly respond to malicious node attacks and update the reputation degree of malicious nodes. Finally, we propose a routing selection scheme based on reference path which comprehensively considers the energy and reputation degree of heterogeneous nodes. It makes message transmission bypass malicious nodes while achieving network energy load balance, significantly extending the network lifetime. The security analysis proves that our scheme guarantees the security of data transmission. Theoretical analysis and experiments show that our scheme has significant advantages over the existing HWSNs data transmission schemes in terms of network lifetime extension and malicious node resistance. Na Wang 0003, Shancheng Zhang, Jiawen Qiao, Junsong Fu 0001, Jianwei Liu 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Block-Based Privacy-Preserving Healthcare Data Ranked Retrieval in Encrypted Cloud File SystemsabstractThe Internet of Medical Things (IoMT) is an important application of the Internet of Things in health care. In IoMT, efficiency and user privacy are crucial for cloud storage and retrieval of healthcare data documents. Existing schemes, however, often suffer from inefficient retrieval and increased risk of privacy disclosure when dealing with massive data. We propose here a new Efficient Encrypted Parallel Ranking (EEPR) search system, block-based and privacy-preserved, for encrypted cloud healthcare data. We design a parallel binary search tree structure in block and propose a parallel retrieval algorithm adaptable to such a structure. A quantitative analysis through the information retention index shows that our scheme demonstrates better search performance. In addition, feature vectors generated from our scheme are difficult to be reversely analyzed due to unexplainability, enhancing privacy protection for patients and researchers. A formal security analysis shows that our EEPR scheme is resistable to known background attack, and yields a lower time complexity and significantly improves search efficiency as well as accuracy over existing schemes. Na Wang 0003, Shancheng Zhang, Junsong Fu 0001, Jianwei Liu 0001, Ruijin Wang |
IEEE J. Biomed. Health Informatics | 4 |
| 2023 | Secure and Distributed IoT Data Storage in Clouds Based on Secret Sharing and Collaborative BlockchainabstractWith the rapid development of 5G/6G, most Internet of Things (IoT) devices will embrace wireless connection in the near future. A public concern is how to securely organize, store and retrieve data generated from IoT devices. Many cloud-based IoT data storage schemes have been proposed recently. However, for an untrusted or vulnerable cloud server, the stored IoT data can be easily accessed, modified and even destroyed given that the IoT data are stored in total centralization. Moreover, the servers in a cloud are generally homogeneous and thus vulnerable to attacks. For improvements, we design a novel framework for secure and efficient IoT data storage based on secret sharing and a collaborative blockchain. First, an ultra-lightweight secret sharing algorithm is designed to map original messages generated by IoT devices to a set of shorter message shares. Second, all the shares of IoT messages are separately delivered to different clouds for storage. To guarantee the security of shares, the delivery is notarized on a proposed blockchain. Specifically, both hash values of the shares and their information of location are embedded in blocks which are then chained to form a blockchain. Third, we create a balanced index structure about the shares for each cloud storage node based on the information in the blockchain, and we also propose a depth-first data search algorithm to improve IoT data retrieval efficiency. Theoretical analysis and simulation results illustrate that our scheme can store and retrieve the IoT data securely and efficiently. Na Wang 0003, Junsong Fu 0001, Shancheng Zhang, Jiawen Qiao, Jianwei Liu 0001, Bharat K. Bhargava |
IEEE/ACM Trans. Netw. | 2 |
| 2022 | An efficient multikeyword fuzzy ciphertext retrieval scheme based on distributed transmission for Internet of ThingsabstractAs traditional computing and cloud computing integrate, the Internet of Things (IoT) has evolved into a layered and cloud-network-edge-end architecture. However, most searchable encryption models still use triples, in which hierarchical structures are neglected, and insecure intermediate nodes are exposed to external environment. Meanwhile, mainstream schemes adopting accurate retrieval are incompatible with IoT end users' features of differentiation. To address these issues, we innovatively design an efficient and credible search model with an accurate multikeyword fuzzy ciphertext retrieval scheme in the context of IoT. First, based on network coding and key sharing, data are grouped, encoded, and transmitted in parallel to the receiver node through middle-layer nodes, with high efficiency and reliability. Second, to realize fuzzy retrieval of IoT, edit distance is selected as the standard of difference between keywords, and then document index vector and query vector are created based on locality sensitive hashing (LSH) and Bloom Filter. Furthermore, to improve the traditional scheme, query keywords are split into multiple single-word forms, inner products between each trapdoor of single word and encryption index vector are calculated, respectively, for the sum of each inner product and thus top $\mathrm{top}$ - k $k$ sorting search. Ultimately, feasibility, safety, and efficiency of our improved scheme are verified by security analysis, while simulation results support that our scheme has better accuracy and efficiency. Kaifa Zheng, Na Wang 0003, Jianwei Liu 0001, Shancheng Zhang, Qingyun Han, Ruijin Wang, Junsong Fu 0001 |
Int. J. Intell. Syst. | 8 |
| 2022 | Defending Trace-Back Attack in 3D Wireless Internet of ThingsabstractWith the development of 5G, it is unsurprising that most of the smart devices in the Internet of Things (IoT) will be wirelessly connected with each other in the near future. This kind of lightweight, scalable and green network architecture will be well-received. In a wide variety of IoT application scenarios, sensor nodes deployed in a local space, such as a multistory building, automatically form a distributed 3D wireless IoT and it can be employed to collect and analyze environmental information. Source-location privacy protection is of great importance in these networks and however, most existing schemes focus on only planar distributed networks which are not suitable for the 3D networks. In this paper, we consider a novel trace-back attack for 3D wireless IoT and then design a source-location privacy protection scheme, named DMR-3D, to defend this kind of novel attacks. In DMR-3D, the source node first selects a set of virtual locations to indirectly choose a set of agent nodes based on the cold start sphere structure and the ellipsoid communication pipeline. Then, a sophisticated mechanism is designed based on both the connected graph and Multiple Delaunay Triangulation (MDT) structure of the network to deliver packets from the source node to the destination node via these agent nodes in a relay manner. Analysis and simulation results illustrate that the proposed scheme can effectively protect source-location privacy with a moderate increment of path stretch, time delay and data transmission amount. Junsong Fu 0001, Na Wang 0003, Leyao Nie, Baojiang Cui, Bharat K. Bhargava |
IEEE/ACM Trans. Netw. | 1 |
| 2022 | A Practical Framework for Secure Document Retrieval in Encrypted Cloud File SystemsabstractWith the development of cloud computing, more and more data owners are motivated to outsource their documents to the cloud and share them with the authorized data users securely and flexibly. To protect data privacy, the documents are generally encrypted before being outsourced to the cloud and hence their searchability decreases. Though many privacy-preserving document search schemes have been proposed, they cannot reach a proper balance among functionality, flexibility, security and efficiency. In this paper, a new encrypted document retrieval system is designed and a proxy server is integrated into the system to alleviate data owner's workload and improve the whole system's security level. In this process, we consider a more practical and stronger threat model in which the cloud server can collude with a small number of data users. To support multiple document search patterns, we construct two AVL trees for the filenames and authors, and a Hierarchical Retrieval Features tree (HRF tree) for the document vectors. A depth-first search algorithm is designed for the HRF tree and the Enhanced Asymmetric Scalar-Product-Preserving Encryption (Enhanced ASPE) algorithm is utilized to encrypt the HRF tree. All the three index trees are linked with each other to efficiently support the search requests with multiple parameters. Theoretical analysis and simulation results illustrate the security and efficiency of the proposed framework. Junsong Fu 0001, Na Wang 0003, Baojiang Cui, Bharat K. Bhargava |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2021 | Privacy-Preserving Top-k Location-based Services Retrieval in Mobile Internet
Na Wang 0003, Jian Li 0035, Junsong Fu 0001 |
Mob. Networks Appl. | 3 |
| 2021 | An Improved Feature Extraction Approach for Web Anomaly Detection Based on Semantic StructureabstractAnomaly-based Web application firewalls (WAFs) are vital for providing early reactions to novel Web attacks. In recent years, various machine learning, deep learning, and transfer learning-based anomaly detection approaches have been developed to protect against Web attacks. Most of them directly treat the request URL as a general string that consists of letters and roughly use natural language processing (NLP) methods (i.e., Word2Vec and Doc2Vec) or domain knowledge to extract features. In this paper, we proposed an improved feature extraction approach which leveraged the advantage of the semantic structure of URLs. Semantic structure is an inherent interpretative property of the URL that identifies the function and vulnerability of each part in the URL. The evaluations on CSIC-2020 show that our feature extraction method has better performance than conventional feature extraction routine by more than average dramatic 5% improvement in accuracy, recall, and F1-score. Zishuai Cheng, Baojiang Cui, Wenchuan Yang, Junsong Fu 0001 |
Secur. Commun. Networks | 5 |
| 2020 | HFuzz: Towards automatic fuzzing testing of NB-IoT core network protocols implementations
Xinyao Liu, Baojiang Cui, Junsong Fu 0001, Jinxin Ma |
Future Gener. Comput. Syst. | 3 |
| 2020 | Source-Location Privacy Protection Based on Anonymity Cloud in Wireless Sensor NetworksabstractAn adversary can deploy parasitic sensor nodes into wireless sensor networks to collect radio traffic distributions and trace back messages to their source nodes. Then, he can locate the monitored targets around the source nodes with a high probability. In this paper, a Source-location privacy Protection scheme based on Anonymity Cloud (SPAC) is proposed. We first design a light-weight (t, n)-threshold message sharing scheme and map the original message to a set of message shares which are shorter in length and can be processed and delivered with minimal energy consumption. Based on the shares, the source node constructs an anonymity cloud with an irregular shape around itself to protect its location privacy. Specifically, an anonymity cloud is a set of active nodes with similar radio actions and they are statistically indistinguishable from each other. The size of the cloud is controlled by the preset number of hops that the shares can walk in the cloud. At the border of the cloud, the fake source nodes independently send the shares to the sink node through proper routing algorithms. At last, the original message can be recovered by the sink node once at least t shares are received. The simulation results demonstrate that the SPAC can strongly protect the source-location privacy in an efficient manner. Moreover, the message sharing mechanism of SPAC increases the confidentiality of network data and it also brings high tolerance for the failures of sensor nodes to the data transmission process. Na Wang 0003, Junsong Fu 0001, Jian Li 0035, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | A Distributed Position-Based Routing Algorithm in 3-D Wireless Industrial Internet of ThingsabstractSmart factory is a typical application scene of Internet of Things and wireless terminal devices naturally compose a three-dimensional (3-D) industrial wireless network. A primary requirement in the network is delivering packets from source node to destination node. Most geographic routing algorithms are designed for planar networks and they do not suit 3-D networks. In this paper, we extend a greedy perimeter stateless routing algorithm (GPSR) into three dimensions named GPSR-3D. In GPSR-3D, each node decides next hop of a packet by cooperating with only local neighbors and hence this algorithm is totally distributed. GPSR-3D comprises two packet forwarding patterns named greedy forwarding pattern (GFP) and surface forwarding pattern (SFP). In GFP, a node always sends the packet to a neighbor closest to destination and when it fails, SFP is employed for recovery. In SFP, we first divide the whole network space into a set of subspaces based on a novel 3-D geometric structure. Then, a parallel polyhedron traverse algorithm is proposed to recover local minima. A flowchart of GPSR-3D is given to clearly present the process of delivering a packet based on GFP and SFP. Simulation results show that GPSR-3D is of great reliability, energy efficiency and storage efficiency. Specifically, data transmission amount in GPSR-3D is about 67% and 71% to that of multihop Delaunay triangulation (MDT) and GDSTR-3D on average. Moreover, GPSR-3D performs much better than MDT and GDSTR-3D in terms of average storage cost and the average storage space in GPSR-3D is about 48% and 26% to that of MDT and GDSTR-3D, respectively. Junsong Fu 0001, Baojiang Cui, Na Wang 0003, Xinyao Liu |
IEEE Trans. Ind. Informatics | 1 |
| 2018 | Source-location privacy full protection in wireless sensor networks
Na Wang 0003, Junsong Fu 0001, Jiwen Zeng, Bharat K. Bhargava |
Inf. Sci. | 2 |
| 2018 | Efficient Retrieval Over Documents Encrypted by Attributes in Cloud ComputingabstractSecure document storage and retrieval is one of the hottest research directions in cloud computing. Though many searchable encryption schemes have been proposed, few of them support efficient retrieval over the documents which are encrypted based on their attributes. In this paper, a hierarchical attribute-based encryption scheme is first designed for a document collection. A set of documents can be encrypted together if they share an integrated access structure. Compared with the ciphertext-policy attribute-based encryption schemes, both the ciphertext storage space and time costs of encryption/decryption are saved. Then, an index structure named attribute-based retrieval features (ARF) tree is constructed for the document collection based on the TF-IDF model and the documents' attributes. A depth-first search algorithm for the ARF tree is designed to improve the search efficiency which can be further improved by parallel computing. Except for the document collections, our scheme can be also applied to other datasets by modifying the ARF tree slightly. A thorough analysis and a series of experiments are performed to illustrate the security and efficiency of the proposed scheme. Na Wang 0003, Junsong Fu 0001, Bharat K. Bhargava, Jiwen Zeng |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | Secure Data Storage and Searching for Industrial IoT by Integrating Fog Computing and Cloud ComputingabstractWith the fast development of industrial Internet of things (IIoT), a large amount of data is being generated continuously by different sources. Storing all the raw data in the IIoT devices locally is unwise considering that the end devices' energy and storage spaces are strictly limited. In addition, the devices are unreliable and vulnerable to many threats because the networks may be deployed in remote and unattended areas. In this paper, we discuss the emerging challenges in the aspects of data processing, secure data storage, efficient data retrieval and dynamic data collection in IIoT. Then, we design a flexible and economical framework to solve the problems above by integrating the fog computing and cloud computing. Based on the time latency requirements, the collected data are processed and stored by the edge server or the cloud server. Specifically, all the raw data are first preprocessed by the edge server and then the time-sensitive data (e.g., control information) are used and stored locally. The non-time-sensitive data (e.g., monitored data) are transmitted to the cloud server to support data retrieval and mining in the future. A series of experiments and simulation are conducted to evaluate the performance of our scheme. The results illustrate that the proposed framework can greatly improve the efficiency and security of data storage and retrieval in IIoT. Junsong Fu 0001, Yun Liu 0001, Han-Chieh Chao, Bharat K. Bhargava, Zhenjiang Zhang |
IEEE Trans. Ind. Informatics | 1 |
| 2016 | k-Nearest neighbors tracking in wireless sensor networks with coverage holes
Yun Liu 0001, Junsong Fu 0001, Zhenjiang Zhang |
Pers. Ubiquitous Comput. | 2 |