Jinwen Liang

dblp:218/8781 · DBLP profile ↗
← Back
29ranked-venue papers
8as first author
24since 2021 · last 2026
0000-0003-1306-3185ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 11 · 3 first-author · 8 since 2021Security and privacy · 9 · 3 first-author · 8 since 2021Systems, architecture and hardware · 5 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Epass: Efficient and Privacy-Preserving Asynchronous Payment on Blockchain
abstract
Buy Now Pay Later (BNPL) is a rapidly proliferating e-commerce model, offering consumers to get the product immediately and defer payments. Meanwhile, emerging blockchain technologies endow BNPL platforms with digital currency transactions, allowing BNPL platforms to integrate with digital wallets. However, the transparency of transactions causes critical privacy concerns because malicious participants may derive consumers' financial statuses from on-chain asynchronous payments. Furthermore, the newly created transactions for deferred payments introduce additional time overhead, which weakens the scalability of BNPL services. To address these issues, we propose an efficient and privacy-preserving blockchain-based asynchronous payment scheme (Epass), which has promising scalability while protecting the privacy of on-chain consumer transactions. Specifically, Epass leverages locally verifiable signatures to guarantee the privacy of consumer transactions against malicious acts. Then, a privacy-preserving asynchronous payment protocol is further constructed by leveraging time-release encryption to control trapdoors of the redactable blockchain, reducing time overhead by modifying transactions for deferred payment. We give formal definitions and security models, generic structures, and formal proofs for Epass. Extensive comparisons and experimental analysis show that Epass achieves KB-level communication costs, and reduces time overhead by more than four times in comparisons with locally verifiable signatures and Go-Ethereum private test networks.
Weijie Wang 0018, Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Liehuang Zhu, Song Guo 0001
IEEE Trans. Dependable Secur. Comput.2
2026 LASTS: Toward Scalable Access Control and Resilient Network Management of Mobile IoT on the Edge
abstract
Edge computing has recently emerged as a promising paradigm to support mobile access in Internet of Things (IoT) multinetworks, where heterogeneous wireless communication solutions coexist. Meanwhile, software-defined networking (SDN) presents a potential infrastructure to monitor and manage mobile edge computing. However, resilient access in the integrated IoT-Edge-SDN environment is a key challenge. In this article, we present location-aware spatio-temporal solution (LASTS) as an edge computing-empowered software-defined system to scalably control mobile IoT access and detect sequential anomaly. LASTS utilizes a Personal access point protocol to enable switching between multiple networks. In addition, it supports efficient control and transfer of the mobile device’s spatio-temporal context. This context information plays an important role in a deep learning model employed for sequential anomaly detection in the LASTS system. Realistic testbed experiments confirm that LASTS can successfully achieve scalable access control and sequential anomaly detection in mobile IoT.
Di Wu 0002, Jinhui Ouyang, Qinghua Guan, Xiang Nie, Jinwen Liang, Yanwen Wang 0001, Hanhui Deng
IEEE Trans. Ind. Informatics5
2025 Parallelizing Universal Atomic Swaps for Multi-Chain Cryptocurrency Exchanges
Danlei Xiao, Chuan Zhang 0003, Jinwen Liang, Licheng Wang 0004, Liehuang Zhu
USENIX Security Symposium4
2025 Pistis: A Decentralized Knowledge Graph Platform Enabling Ownership-Preserving SPARQL Querying
abstract
Decentralized Knowledge Graph (DKG) platforms allow the sharing of knowledge with multiple owners. While data owners can share their data with others by encrypting their data before sharing it, this naïve approach prevents data encrypted by different owners from being queried together, as it compromises query verifiability, an essential DKG platform feature. We propose Pistis, the first DKG platform capable of preserving ownership while also enabling verifiable SPARQL queries. Two novel techniques facilitate this: owner-managed end-to-end encryption and collaborative query verification. In Pistis, data owners thus encrypt their data individually and collaborate to construct an authenticated data structure (ADS) with a global key by means of secret sharing and secure multi-party computation. Then, by indexing KG data as ciphertext over the ADS, Pistis offers a cryptographic scheme called VO-SPARQL that facilitates verifiable queries on encrypted KG data with multiple owners. Pistis provides succinct proofs for two-stage SPARQL queries, including subgraph queries based on the ADS and aggregation on encrypted intermediate results based on a key-aggregate cryptographic primitive. A theoretical analysis and an empirical study provide detailed insight into the performance of Pistis while offering provable security.
Enyuan Zhou, Song Guo 0001, Zicong Hong, Christian S. Jensen, Yang Xiao 0014, Jinwen Liang, Dalin Zhang 0001
Proc. VLDB Endow.6
2025 Small-Signal Stability Region Analysis of Multi-Time Delay Wind Power System Considering Degenerate Hopf Bifurcation
abstract
From the perspective of nonlinear dynamics and bifurcation theory, this paper analyzes the impact of time delay on small-signal stability region of doubly-fed induction generator (DFIG) grid-connected power system. Firstly, the differential-algebraic equation model of the system is established. It is theoretically demonstrated that time delay will affect the bifurcation behavior of the system, especially the degenerate Hopf bifurcation (DHB) under a specific time delay. Then, the time delay, the injected DFIG mechanical power, and the load reactive power are chosen as the bifurcation variables. The bifurcation diagram is obtained through bifurcation analysis, which can determine the multi-parameter small-signal stability boundary of the system. Finally, the impact of single and multiple time delays on the stability region is analyzed through the stability boundary. It is found that the DHB due to the time delay variation induces a hole effect in the system stability region. Moreover, increasing the time delay may also improve the system stability margin. The findings of this study have significant guiding implications for multi-time delay system parameter adjustment.
Jinwen Liang, Yuheng Wan, Zesen Gui, Zehui Yuan, Ying Wang 0127, Xianyong Xiao
IEEE Trans. Circuits Syst. I Regul. Pap.2
2025 Robust Practical Stability Region Partition Considering Parameter Uncertainty and Volatility for Direct-Drive Wind Power System
abstract
A power system is a strongly nonlinear dynamic system, and traditional small disturbance stability analysis cannot reflect the dynamic characteristics of the system under uncertain disturbances. This paper proposes a robust practical stability region (RPSR) partitioning method that considers uncertain disturbances to address the uncertainty of wind power injections and load volatility in wind power systems. First, a disturbance model of the wind turbine generator access system is constructed on the basis of perturbation theory to investigate the effects of uncertainty disturbances on the dynamic characteristics of the system. Second, through bifurcation analysis and limit cycle (L-cycle) tracking, a comprehensive bifurcation diagram that considers the variation trend of the L-cycle amplitude is drawn. Combined with the variation trend of the L-cycle, the RPSR of the system under uncertain disturbances is partitioned. Case studies of dual-machine system and multimachine system explore the new concept of the RPSR. Last, numerical simulations are used to verify the effectiveness of the analysis results and the proposed method.
Maosheng Zhao, Jinwen Liang, Xianyong Xiao, Ying Wang 0127, Zehui Yuan, Yuheng Wan
IEEE Trans. Circuits Syst. I Regul. Pap.3
2025 ADA-FInfer: Inferring Face Representations From Adaptive Select Frames for High-Visual-Quality Deepfake Detection
abstract
Interpretable deepfake detection is gaining attention for providing explainable, trustworthy results, avoiding the limitations of ‘black-box’ models. Current interpretable methods focus on visible artifacts in low-visual-quality deepfakes, but these artifacts become less apparent in high-visual-quality deepfakes generated by advanced models. With advancements in deep generative models, producing high-visual-quality deepfakes has become a strategy to evade detection. To address this, we propose${\sf ADA-FInfer}$, an adaptive frame selection and interpretable face representation inference method for detecting high-visual-quality deepfakes.${\sf ADA-FInfer}$adaptively selects frames by analyzing optical flow to reveal manipulations. We also introduce an adaptive attack method that manipulates specific frames, and our adaptive selection strategy shows resistance to such attacks.${\sf ADA-FInfer}$uses an encoder to learn face representations from source and target faces, applying a representation-prediction loss to maximize the distinction between real and fake videos. To provide further insights, we employ the joint entropy, mutual information, and conditional entropy analyses to explain the method's effectiveness. Extensive experiments and ablation studies demonstrate that${\sf ADA-FInfer}$achieves promising performance in detecting high-visual-quality deepfakes.
Jinwen Liang, Zheng Qin 0001, Xin Liao 0001, Wenbo Zhou 0004, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.2
2025 SecPQ: Secure Prediction Queries on Encrypted Outsourced Databases
abstract
Prediction queries have revolutionized data search by integrating machine learning models and traditional data processing operations for advanced analytics. However, existing prediction query frameworks for outsourced databases face a critical security vulnerability: data flows are processed in plaintext on semi-honest servers, making them susceptible to data breaches. The main challenge in achieving secure prediction queries is that machine learning inference and data processing operations are distinct functionalities, while most current cryptographic frameworks support only a single type of operation on specific encrypted data. To bridge this crucial gap, we propose$\mathsf {SecPQ}$, the first framework tailored for secure prediction queries. Our approach unifies decision tree pipelines and data processing operations, such as selection, projection, and equality-joining, through equality matching on encrypted outsourced data. This enables the design of secure prediction queries with decision tree pipelines operating on encrypted data. We provide formal security definitions and proofs for$\mathsf {SecPQ}$. To further optimize the efficiency of secure prediction queries, we leverage order-preserving encryption to construct$\mathsf {SecPQ}_{{{ope}}}$, which offers improved query efficiency at the expense of weaker security properties compared with$\mathsf {SecPQ}$. Extensive experimental evaluations on billions of records demonstrate the feasibility and effectiveness of both$\mathsf {SecPQ}$and$\mathsf {SecPQ}_{{{ope}}}$.
Jinwen Liang, Song Guo 0001, Zicong Hong, Enyuan Zhou, Chuan Zhang 0003, Bin Xiao 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Publicly Verifiable and Secure SVM Classification for Cloud-Based Health Monitoring Services
abstract
In cloud-based health monitoring services, healthcare centers often outsource support vector machine (SVM)-based clinical decision models to provide remote users with clinical decisions. During service provisioning, authorized external organizations like insurance companies aim to verify decision correctness to prevent fraudulent medical reimbursements. However, existing verifiable and secure SVM classification schemes have predominantly focused on user self-verification, thereby introducing potential risks of privacy leakage (such as input data exposure) in publicly verifiable scenarios. To address the aforementioned limitation, we propose a publicly verifiable and secure SVM classification scheme (PVSSVM) for cloud-based health monitoring services in a malicious setting, which can accommodate the verification needs of users or authorized external organizations with respect to potential malicious results returned by cloud servers. Specifically, we utilize homomorphic encryption and secret sharing to protect the model and data confidentiality in the cloud server, respectively. Based on a multiserver verifiable computation framework, PVSSVM achieves public verification of predicted results. Additionally, we further investigate its performance. Experimental evaluations demonstrate that PVSSVM outperforms existing state-of-the-art solutions in terms of computation and communication overhead. Notably, in the verification scenario of large-scale predictions, the proposed scheme achieves a reduction of approximately 83.71% in computation overhead through batch verification, as compared to one-by-one verification.
Dian Lei, Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Daojing He, Liehuang Zhu, Song Guo 0001
IEEE Internet Things J.2
2024 VSpatial: Enabling Private and Verifiable Spatial Keyword-Based Positioning in 6G-Oriented IoT
abstract
For increasing Internet of Things (IoT) devices, 6G wireless technology aims for ubiquitous communications in which positioning services are necessary. Private spatial keyword-based positioning service is promising in 6G-oriented IoT since it positions users based on spatial locations and textual keywords while protecting user privacy. However, due to economic benefits or malicious attacks, positioning service providers may return erroneous or incomplete results, which cause tremendous economic damage and security threats, e.g., always assigning a selective driver for the specific car-hailing user. A technical challenge for extending existing private schemes to enable users to verify the correctness and completeness of positioning results is the distinctive positioning paradigm between compared spatial locations and matched textual keywords. This paper proposes a private and verifiable spatial keyword positioning scheme named VSpatial in 6G-oriented IoT. VSpatial enables users to verify the correctness and completeness of spatial keyword-based positioning results while preserving user privacy. The main inspiration for addressing the technical challenge is converting both spatial locations and textual keywords into an internal status, i.e., adapting comparison and matching to existence judging by multiple cryptographic tools, such as hierarchical cube and pseudorandom function. Based on this inspiration, we design a novel private authenticated data structure (named PVTree), and then propose two constructions of VSpatial, i.e., VSpatial-S and VSpatial-D, to suit static and dynamic environments, respectively. The core idea for adapting VSpatial-S to VSpatial-D is transferring one whole PVTree into multiple exponential-size partitions. Security analysis proves the security and verifiability of VSpatial. Theoretical and experimental evaluations show that VSpatial achieves faster-than-linear positioning efficiency and linear verification overhead.
Weiting Zhang, Mingyang Zhao 0002, Zhuoyu Sun, Chuan Zhang 0003, Jinwen Liang, Liehuang Zhu, Song Guo 0001
IEEE J. Sel. Areas Commun.5
2024 FutureDID: A Fully Decentralized Identity System With Multi-Party Verification
abstract
Decentralized identity (DID) systems conforming to the World Wide Web Consortium (W3C) Decentralized Identifiers (DIDs) and Verifiable Credentials Data Model recommendations have recently attracted attention due to their better autonomy, interoperability, and openness design. However, those W3C recommendations lack a design for addressing the single point of failure (SPOF) and identity revocation, which could seriously compromise the robustness and practicality of DID systems. To remedy these limitations, we propose FutureDID, a DID system that enables multiple parties to jointly issue credentials and efficiently revoke DID identities, providing a robust and practical DID system. FutureDID is designed with a multi-party credential issuing mechanism based on distributed key generation technology, which transforms trust from a single entity to distributed committees and facilitates authentication between issuers, making it more resistant to SPOF. Moreover, the underlying blockchain system is built on a chameleon hash function to ensure tamper-proof and enable efficient identity revocation. We have implemented a prototype system using FISCO BCOS and conducted extensive evaluations to demonstrate the effectiveness and practicality of our system. Our evaluations have shown that FutureDID provides a significant improvement in efficiency, achieving at least a 60 × efficiency improvement in identity revocation compared to state-of-the-art systems.
Jinwen Liang, Chuan Zhang 0003, Ximeng Liu, Liehuang Zhu, Song Guo 0001
IEEE Trans. Computers2
2024 Achieving Efficient and Privacy-Preserving Location-Based Task Recommendation in Spatial Crowdsourcing
abstract
In spatial crowdsourcing, location-based task recommendation schemes are widely used to match appropriate workers in desired geographic areas with relevant tasks from data requesters. To ensure data confidentiality, various privacy-preserving location-based task recommendation schemes have been proposed, as cloud servers behave semi-honestly. However, existing schemes reveal access patterns, and the dimension of the geographic query increases significantly when additional information beyond locations is used to filter appropriate workers. To address the above challenges, this paper proposes two efficient and privacy-preserving location-based task recommendation (EPTR) schemes that support high-dimensional queries and access pattern privacy protection. First, we propose a basic EPTR scheme (EPTR-I) that utilizes randomizable matrix multiplication and public position intersection test (PPIT) to achieve linear search complexity and full access pattern privacy protection. Then, we explore the trade-off between efficiency and security and develop a tree-based EPTR scheme (EPTR-II) to achieve sub-linear search complexity. Security analysis demonstrates that both schemes protect the confidentiality of worker locations, requester queries, and query results and achieve different security properties on access pattern assurance. Extensive performance evaluation shows that both EPTR schemes are efficient in terms of computational cost, with EPTR-II being$10^{3}\times$faster than the state-of-the-art scheme in task recommendation.
Fuyuan Song, Jinwen Liang, Chuan Zhang 0003, Zhangjie Fu 0001, Zheng Qin 0001, Song Guo 0001
IEEE Trans. Dependable Secur. Comput.2
2024 NANO: Cryptographic Enforcement of Readability and Editability Governance in Blockchain Databases
abstract
Recently, increasing personal data has been stored in blockchain databases, ensuring data integrity by consensus. Although transparent and immutable blockchains are mainly adopted, the need to deploy preferences on which users canreadandeditthe data is growing in importance. Based on chameleon hashes, recent blockchains support editability governance but can hardly prevent data breaches because the data is readable to all participants in plaintexts. This motivates us to propose NANO, the first permissioned blockchain database that provides downward compatible readability and editability governance (i.e., users who caneditthe data can alsoreadthe data). Two challenges are protecting policy privacy and efficiently revoking malicious users (e.g., users who abuse their editability privileges). The punchline is leveraging Newton's interpolation formula-based secret sharing to hide policies into polynomial parameters and govern the distribution of data decryption keys and chameleon hash trapdoors. Inspired by proxy re-encryption, NANO integrates unique user symbols into user keys, achieving linear user revocation overhead. Security analysis proves that NANO provides comprehensive privacy preservation under the chosen-ciphertext attack. Experiments on the FISCO blockchain platform demonstrate that compared with state-of-the-art related solutions, NANO achieves a 7× improvement on average regarding computational costs, gas consumption, and communication overhead.
Chuan Zhang 0003, Mingyang Zhao 0002, Jinwen Liang, Liehuang Zhu, Song Guo 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Toward Collaborative Occlusion-Free Perception in Connected Autonomous Vehicles
abstract
In connected autonomous vehicles (CAVs), the driving safety can be greatly deteriorated, in the presence of occlusions which are adverse to CAVs' perception of region-of-interest (RoI). Collaborative perception on the basis the information sharing of occlusions among CAVs, in a real-time and accurate manner, provides a means of the occlusion-free RoI perception for safe driving. In this paper, we propose a novel framework ofCollaborativeOcclusion-freePerception (COFP) in CAVs, to regain the real-time and accurate occlusion awareness. The innovative COFP targets two goals: well-balanced computation resource allocation, as well as fast and high-quality RoI information fusion. Specifically, the resource allocation problem, with the objective of minimizing CAVs' completion delay, is formulated as a multi-player continuous potential game and solved by a better response dynamics (BRD) algorithm. The RoI information fusion, with the objective of maximizing the overall object depiction quality, is formulated as a combinatorial optimization problem, and solved by a modified discrete salp swarm (MDSSA) algorithm. Experimental results show that the proposed COFP with 5GHz computing power can achieve full occlusion awareness for CAVs with 69.61% completion time reduction and 19.03% fusion quality improvement, compared to the existing methods.
Zhu Xiao, Jinmei Shu, Hongbo Jiang 0001, Geyong Min, Jinwen Liang, Arun Iyengar
IEEE Trans. Mob. Comput.5
2024 POTA: Privacy-Preserving Online Multi-Task Assignment With Path Planning
abstract
Privacy-preserving online multi-task assignment is a crucial aspect of spatial crowdsensing on untrusted platforms, where multiple real-time tasks are allocated to appropriate workers in a privacy-preserving manner. While existing schemes ensure the privacy of tasks and users, they seldom focus on minimizing the total moving distances for crowdsensing workers when assigning multiple tasks in real time, which adversely impacts the efficiency of online multi-task assignments. To address this issue, we propose POTA, the first privacy-preserving online multi-task assignment scheme with path planning that minimizes the total moving distances for crowdsensing workers without additional noise. POTA cryptographically implements the extended minimum-cost flow model, which models the encrypted data of workers and tasks in a graph and later produces optimized routing. With such a secure path-planning component, POTA reduces the total moving distances by$25.19\%-52.78\%$in the tested dataset compared with the state-of-the-art schemes with obfuscated path planning. Security analysis proves that POTA guarantees the confidentiality of sensitive data, a stronger security property than introducing obfuscation to sensitive data. Experimental evaluations on real-world datasets demonstrate the feasibility of POTA in terms of running time and its ability to achieve minimized total moving distances.
Chuan Zhang 0003, Xingqi Luo, Jinwen Liang, Ximeng Liu, Liehuang Zhu, Song Guo 0001
IEEE Trans. Mob. Comput.3
2023 Prophet: Conflict-Free Sharding Blockchain via Byzantine-Tolerant Deterministic Ordering
abstract
Sharding scales throughput by splitting blockchain nodes into parallel groups. However, different shards’ independent and random scheduling for cross-shard transactions results in numerous conflicts and aborts, since cross-shard transactions from different shards may access the same account. A deterministic ordering can eliminate conflicts by determining a global order for transactions before processing, as proved in the database field. Unfortunately, due to the intertwining of the Byzantine environment and information isolation among shards, there is no trusted party able to predetermine such an order for cross-shard transactions. To tackle this challenge, this paper proposes Prophet, a conflict-free sharding blockchain based on Byzantine-tolerant deterministic ordering. It first depends on untrusted self-organizing coalitions of nodes from different shards to pre-execute cross-shard transactions for prerequisite information about ordering. It then determines a trusted global order based on stateless ordering and post-verification for pre-executed results, through shard cooperation. Following the order, the shards thus orderly execute and commit transactions without conflicts. Prophet orchestrates the pre-execution, ordering, and execution processes in the sharding consensus for minimal overhead. We rigorously prove the determinism and serializability of transactions under the Byzantine and sharded environment. An evaluation of our prototype shows that Prophet improves the throughput by 3.11× and achieves nearly no aborts on 1 million Ethereum transactions compared with state-of-the-art sharding.
Zicong Hong, Song Guo 0001, Enyuan Zhou, Wuhui Chen, Jinwen Liang, Jie Zhang 0076, Albert Y. Zomaya
INFOCOM6
2023 VeriDKG: A Verifiable SPARQL Query Engine for Decentralized Knowledge Graphs
abstract
The ability to decentralize knowledge graphs (KG) is important to exploit the full potential of the Semantic Web and realize the Web 3.0 vision. However, decentralization also renders KGs more prone to attacks with adverse effects on data integrity and query verifiability. While existing studies focus on ensuring data integrity, how to ensure query verifiability - thus guarding against incorrect, incomplete, or outdated query results - remains unsolved. We propose VeriDKG, the first SPARQL query engine for decentralized knowledge graphs (DKG) that offers both data integrity and query verifiability guarantees. The core of VeriDKG is the RGB-Trie, a new blockchain-maintained authenticated data structure (ADS) facilitating correctness proofs for SPARQL query results. VeriDKG enables verifiability of subqueries by gathering global index information on subgraphs using the RGB-Trie, which is implemented as a new variant of the Merkle prefix tree with an RGB color model. To enable verifiability of the final query result, the RGB-Trie is integrated with a cryptographic accumulator to support verifiable aggregation operations. A rigorous analysis of query verifiability in VeriDKG is presented, along with evidence from an extensive experimental study demonstrating its state-of-the-art query performance on the largeRDFbench benchmark.
Enyuan Zhou, Song Guo 0001, Zicong Hong, Christian S. Jensen, Yang Xiao 0014, Dalin Zhang 0001, Jinwen Liang, Qingqi Pei
Proc. VLDB Endow.7
2022 FInfer: Frame Inference-Based Deepfake Detection for High-Visual-Quality Videos
abstract
Deepfake has ignited hot research interests in both academia and industry due to its potential security threats. Many countermeasures have been proposed to mitigate such risks. Current Deepfake detection methods achieve superior performances in dealing with low-visual-quality Deepfake media which can be distinguished by the obvious visual artifacts. However, with the development of deep generative models, the realism of Deepfake media has been significantly improved and becomes tough challenging to current detection models. In this paper, we propose a frame inference-based detection framework (FInfer) to solve the problem of high-visual-quality Deepfake detection. Specifically, we first learn the referenced representations of the current and future frames’ faces. Then, the current frames’ facial representations are utilized to predict the future frames’ facial representations by using an autoregressive model. Finally, a representation-prediction loss is devised to maximize the discriminability of real videos and fake videos. We demonstrate the effectiveness of our FInfer framework through information theory analyses. The entropy and mutual information analyses indicate the correlation between the predicted representations and referenced representations in real videos is higher than that of high-visual-quality Deepfake videos. Extensive experiments demonstrate the performance of our method is promising in terms of in-dataset detection performance, detection efficiency, and cross-dataset detection performance in high-visual-quality Deepfake videos.
Xin Liao 0001, Jinwen Liang, Wenbo Zhou 0004, Zheng Qin 0001
AAAI3
2021 An Efficient and Privacy-Preserving Multi-User Multi-Keyword Search Scheme without Key Sharing
abstract
Multi-keyword search, aiming to search the objects by a query request that consists of multiple keywords, has wide applications in personalized recommendation services. Mean-while, the fast development of cloud technology has given rise to a new trend that data are encrypted before being outsourced to a public cloud for users to enjoy pay-as-you-go services. However, most of the existing works primarily focus on the single keyword search, and consider a general scenario with a single owner and a single user. In this paper, we propose an efficient and Privacy-preserving Multi-user Multi-keyword Search (PMMS) scheme, which can support user scalability without key sharing. In particular, based on the matrix decomposition, a key derivation approach is integrated into our PMMS to generate secret keys and re-encryption keys. Furthermore, by employing threshold predicate encryption and leveraging the techniques of matrix transformation and proxy re-encryption, PMMS guarantees that only the comparison result of an inner product of two vectors and a pre-defined threshold is revealed, and enables the cloud server to perform multi-keyword search in an efficient and privacy-preserving manner. Security analysis shows that the confidentiality of owners’ data and users’ queries can be guaranteed. Extensive experiments on a real-world dataset demonstrate that PMMS is efficient in terms of multi-keyword search.
Fuyuan Song, Zheng Qin 0001, Jinwen Liang, Xiaodong Lin 0001
ICC3
2021 Traceable and Privacy-Preserving Non-Interactive Data Sharing in Mobile Crowdsensing
abstract
Data sharing is one of the key technologies, which provides the practice of making data collected from a crowd of mobile devices available to others using a cloud infrastructure, known as mobile crowdsensing (MCS). However, the collected data may contain sensitive information, and sharing them in public clouds without proper protection could cause serious security problems, such as privacy leakage, unauthorized access, and secret key abuse. To address the above issues, in this paper, we propose a Traceable and privacy-preserving non-Interactive Data Sharing (TIDS) scheme in mobile crowdsensing. Specifically, to achieve privacy-preserving fine-grained data sharing, an attribute-based access policy is generated by a data owner without interacting with data users in the TIDS. Furthermore, we design a ciphertext conversion mechanism to support flexible data sharing. Also, by utilizing traceable Ciphertext-Policy Attribute-Based Encryption (CP-ABE), TIDS supports a trusted authority to trace malicious users who abuse their secret keys without incurring additional computational overhead. Security analysis demonstrates that TIDS can protect the confidentiality of the outsourced data. Experimental results show that TIDS can achieve efficient data sharing in mobile crowdsensing applications.
Fuyuan Song, Zheng Qin 0001, Jinwen Liang, Pulei Xiong, Xiaodong Lin 0001
PST3
2021 Efficient and Privacy-Preserving Decision Tree Classification for Health Monitoring Systems
abstract
Due to the increasing healthcare costs and the advance of wireless technology, health monitoring systems have been widely adopted recently. In health monitoring systems, a hospital outsources a clinical decision model to a cloud service provider, which receives biomedical data from remote clients and produces clinical decisions based on the outsourced model. Due to critical privacy concerns, both the clinical decision model and biomedical data should be protected. In this article, we propose an efficient and privacy-preserving decision tree (PPDT) classification scheme for health monitoring systems. Specifically, we first transform a decision tree classifier (i.e., the clinical decision model) into the Boolean vectors. Then, we leverage symmetric key encryption to encrypt the Boolean vectors as encrypted indices. The PPDT classification is achieved by searching the encrypted indices with encrypted tokens. We formulate a leakage function and provide the security definition and simulation-based proof for PPDT. The performance analyses demonstrate that PPDT is very efficient in terms of computation, communication, and storage. Experimental evaluations show that PPDT only requires microsecond-level execution time, kilobyte-level communication costs, and kilobyte-level storage costs on the test data set.
Jinwen Liang, Zheng Qin 0001, Xiaodong Lin 0001, Xuemin Shen
IEEE Internet Things J.1
2021 Verifiable and Secure SVM Classification for Cloud-Based Health Monitoring Services
abstract
In cloud-based health monitoring services, support vector machine (SVM) classification techniques are often utilized by medical institutes to build medical decision models, which can be outsourced to a cloud server for producing medical decisions based on medical features from remote clients. In this article, we propose a verifiable and secure SVM classification scheme ($\mathsf {VSSVMC}$) for cloud-based health monitoring services in a malicious setting, where the cloud server may return invalid decisions. By constructing verifiable indices,$\mathsf {VSSVMC}$ensures the verifiability of medical decisions, which enables clients to detect whether the cloud server returns incorrect or incomplete medical decisions. Symmetric key encryption is leveraged to ensure the confidentiality of the medical decision model and medical data with computational efficiency. We give security and verifiability definitions and provide formal security and verifiability proofs for$\mathsf {VSSVMC}$. Performance analyses show that$\mathsf {VSSVMC}$is extremely efficient in terms of computation, communication, and storage. Experimental evaluations demonstrate that$\mathsf {VSSVMC}$achieves microsecond-level execution time with kilobyte-level communication and storage overheads on the tested data set.
Jinwen Liang, Zheng Qin 0001, Xiaodong Lin 0001, Xuemin Shen
IEEE Internet Things J.1
2021 Practical and Secure SVM Classification for Cloud-Based Remote Clinical Decision Services
abstract
Support vector machine (SVM) classification techniques have been widely adopted for building clinical decision models. In cloud-based remote clinical decision services, a healthcare center outsources the clinical decision model to a cloud server, which then provides remote clinical decision services to end users. In this article, we propose a practical and secure SVM classification scheme (${\sf SSVMC}$) for cloud-based remote clinical decision services. Specifically, we first extract SVM decision rules from an SVM classifier. Then, we leverage symmetric key encryption to protect the confidentiality of medical data and prevent the cloud service provider from misusing intellectual property of the outsourced clinical model. Finally, we build encrypted indexes to achieve efficient SVM classification. We define a leakage function, formulate a security definition, and provide a simulation-based security proof for${\sf SSVMC}$. The performance analysis demonstrates that${\sf SSVMC}$achieves linear computational complexity when an SVM classifier (a.k.a., the clinical decision model) is pre-trained. The simulations evaluate the impact of several parameters on time costs. The experimental evaluations show the performance differences between${\sf SSVMC}$and several existing schemes in terms of time costs, storage costs, communication costs, and precisions in a real-world clinical dataset, which demonstrate that${\sf SSVMC}$is computationally efficient with high decision accuracy.
Jinwen Liang, Zheng Qin 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen
IEEE Trans. Computers1
2021 Efficient and Secure Decision Tree Classification for Cloud-Assisted Online Diagnosis Services
abstract
Decision tree classification has become a prevailing technique for online diagnosis services. By outsourcing computation intensive tasks to a cloud server, cloud-assisted online diagnosis services are better ways for cases that the storage and computation requirements exceed the capability of medical institutions. With privacy concerns as well as intellectual property protection issues, the valuable diagnosis classifier and the sensitive user data should be protected against the cloud server. In this paper, we identify a work-flow for cloud-assisted online diagnosis services. We propose an efficient and secure decision tree classification scheme in the proposed work-flow. Specifically, the medical institution transforms a locally pre-trained decision tree classifier to a decision table, and later uses searchable symmetric encryption to encrypt the decision table. Then, the encrypted table is outsourced to the cloud server, and a user can submit encrypted physiological features to the cloud server and obtain an encrypted diagnosis prediction back. We provide formal security proofs to demonstrate that our scheme protects the confidentiality of the decision tree classifier and the user's data. The performance analysis shows that our scheme achieves faster-than-linear classification speed. Experimental evaluations show that our scheme requires several micro-seconds to process a diagnosis request in the tested datasets.
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Lu Ou, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.1
2020 Efficient and Privacy-preserving Outsourced Image Retrieval in Public Clouds
abstract
With the proliferation of cloud services, cloud-based image retrieval services enable large-scale image outsourcing and ubiquitous image searching. While enjoying the benefits of the cloud-based image retrieval services, critical privacy concerns may arise in such services since they may contain sensitive personal information. In this paper, we propose an efficient and Privacy-Preserving Image Retrieval scheme with Key Switching Technique (PPIRS). PPIRS utilizes the inner product encryption for measuring Euclidean distances between image feature vectors and query vectors in a privacy-preserving manner. Due to the high dimension of the image feature vectors and the large scale of the image databases, traditional secure Euclidean distance comparison methods provide insufficient search efficiency. To prune the search space of image retrieval, PPIRS tailors key switching technique (KST) for reducing the dimension of the encrypted image feature vectors and further achieves low communication overhead. Meanwhile, by introducing locality sensitive hashing (LSH), PPIRS builds efficient searchable indexes for image retrieval by organizing similar images into a bucket. Security analysis shows that the privacy of both outsourced images and queries are guaranteed. Extensive experiments on a real-world dataset demonstrate that PPIRS achieves efficient image retrieval in terms of computational cost.
Fuyuan Song, Zheng Qin 0001, Jixin Zhang, Jinwen Liang, Xuemin Shen
GLOBECOM5
2020 Privacy-preserving range query over multi-source electronic health records in public clouds
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Jixin Zhang, Hui Yin 0001, Keqin Li 0001
J. Parallel Distributed Comput.1
2019 Efficient and Privacy-Preserving Outsourced SVM Classification in Public Cloud
abstract
Data classification has become an important and prevailing technique for big data analytics. Typically, a data classifier is designed and outsourced to a public cloud. A service provider then can easily provide various services and handle frequent and massive classification requests from users. With privacy concerns as well as Intellectual Property(IP) protection issues, the valuable classifier and the sensitive user data cannot be directly exposed to the public cloud. In this paper, we focus on the Support Vector Machine (SVM), one of the most popular classifiers, and propose an efficient and privacy-preserving outsourcing scheme for SVM classification in public clouds. Specifically, the service provider is allowed to transform the traditional SVM classifier to fixed hyper-rectangles and the order-preserving encryption is utilized to encrypt these hyper-rectangles as the encrypted classifier. Afterwards, the encrypted classifier is outsourced to the public cloud, and a user can submit an encrypted range query to the cloud and obtain the classification results back. Security analysis and extensive experimental evaluation demonstrate that our scheme can protect the confidentiality of classifier and users' data and achieves efficient SVM classification in terms of computational cost.
Jinwen Liang, Zheng Qin 0001, Jianbing Ni, Xiaodong Lin 0001, Xuemin Shen
ICC1
2019 Efficient and Secure k-Nearest Neighbor Search Over Encrypted Data in Public Cloud
abstract
Cloud computing has become an important and popular infrastructure for data storage and sharing. Typically, data owners outsource their massive data to a public cloud that will provide search services to authorized data users. With privacy concerns, the valuable outsourced data cannot be exposed directly, and should be encrypted before outsourcing to the public cloud. In this paper, we focus on k-Nearest Neighbor (k-NN) search over encrypted data. We propose efficient and secure k-NN search schemes based on matrix similarity to achieve efficient and secure query services in public cloud. In our basic scheme, we construct the traces of two diagonal multiplication matrices to denote the Euclidean distance of two data points, and perform secure k-NN search by comparing traces of corresponding similar matrices. In our enhanced scheme, we strengthen the security property by decomposing matrices based on our basic scheme. Security analysis shows that our schemes protect the data privacy and query privacy under attacking with different levels of background knowledge. Experimental evaluations show that both schemes are efficient in terms of computation complexity as well as computational cost.
Fuyuan Song, Zheng Qin 0001, Jinwen Liang, Lu Ou
ICC4
2017 MPOPE: Multi-provider Order-Preserving Encryption for Cloud Data Privacy
Jinwen Liang, Zheng Qin 0001, Sheng Xiao, Jixin Zhang, Hui Yin 0001, Keqin Li 0001
SecureComm1