Hequn Xian

dblp:218/8830 · DBLP profile ↗
← Back
27ranked-venue papers
0as first author
19since 2021 · last 2026
0000-0002-7538-338XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 14 · 11 since 2021Security and privacy · 6 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Lightweight orthogonal perturbation for privacy-preserving federated learning against poisoning attacks
Chuanyu Peng, Hequn Xian
J. Inf. Secur. Appl.2
2025 Adaptive Selective Encryption for Surveillance Videos via Hierarchical Grading and YOLO Detection
Hequn Xian
ICCCN2
2025 A Gaussian Temporal Based Graph Convolutional Network for Traffic Operation Flow Forecasting
abstract
High-Quality traffic flow data may provide planners with a basis for designing road capacity, pavement and intersection control, etc., thus assisting in the construction of a more rational traffic network. This study developed a new Gaussian Temporal Network Module, which is a module based on a Gaussian process that utilizes a kernel Gaussian convolution kernel to assist in the extraction of temporal features. Which is aim to solve the common gradient vanishing and gradient explosion problems in temporal neural networks Further, this study combines the GTNM with the GCN module as a GT-GCN model and tests its performance on a publicly available dataset. Experiment results show that GT-GCN demonstrates superior performance, attaining state-of-the-art or second best outcomes across different test dataset. Several of these results surpass baseline benchmarks by more than 10%, which then well illustrates the effectiveness and stability of GT-GCN model.
Shulan Guo, Shangda Xiao, Mingxuan He, Hequn Xian, Zesheng Cheng
ICCCN5
2025 LFIoTDI: A lightweight and fine-grained device identification approach for IoT security enhancement
Zaiting Xu, Fei Chen 0014, Hequn Xian
Comput. Commun.4
2025 SLIoTDI: Scalable and Lightweight IoT Device Identification With Session-Level Grayscale Fingerprinting and Adversarial Training
abstract
The rapid expansion of the Internet of Things (IoT) has revolutionized various domains but also introduced critical security challenges, such as device spoofing and unauthorized access. These vulnerabilities underscore the urgent need for effective device identification to safeguard IoT networks and services. Despite ongoing research efforts, existing methods often fall short in scalability and lightweight design, which limits their deployment in real-world IoT environments. To address these challenges, we propose SLIoTDI, a novel scalable and lightweight IoT device identification approach. SLIoTDI uses session-level grayscale image-based fingerprinting and incorporates adversarial training with data augmentation to develop a robust and scalable feature extractor. Once trained, the extractor can generate fingerprints for unseen devices without retraining, ensuring adaptability to evolving IoT settings. Comprehensive experiments conducted on four public datasets and a real-world deployment validate the effectiveness of SLIoTDI, achieving the identification accuracies up to 99.98% and 99.16%, respectively. SLIoTDI is open-sourced to promote transparency and enable further research, offering a practical solution to enhance IoT security and device management in real-world applications.
Zaiting Xu, Hanlin Zhang 0001, Hequn Xian
IEEE Trans. Netw. Serv. Manag.4
2024 A Lossless Relational Data Watermarking Scheme Based on Uneven Partitioning
Hequn Xian
Inscrypt (1)2
2024 A Distortion Free Watermark Scheme for Relational Databases
abstract
Database watermark is an effective solution to the piracy and data leakage problems. It is recognized as the final defense line in zero-trust architecture. Most of the traditional watermark schemes are based on carrier modification, which is difficult to achieve robustness while maintaining data quality. A new distortion free relational data watermark scheme is proposed, which guarantees data quality. Firstly, a watermark encoding algorithm is applied to combine bits in the data with the watermark information to generate auxiliary data, which is then stored. In the watermark extraction stage, the watermark decoding algorithm extracts the watermark information from the auxiliary data. The watermark capacity is greatly increased by encoding at least one attribute of each tuple. This does not modify the original data in any way and avoids the data distortion problems associated with traditional schemes. The experimental results show that the proposed scheme is more robust than traditional robust watermark schemes.
Jiang Han, Xiaowei Peng, Hequn Xian, Dalin Yang
ICCCN3
2024 Location Privacy Protection Method with Route Constraints
abstract
A location privacy protection method based on route constraints is proposed for the use of location-based services in vehicular networks. This scheme proposes a system architecture based on semi trusted third-party services, which stores user private information separately on three parties. Even if attackers acquire some information, they still cannot obtain the complete private information of the user, thus effective resists single point attacks from attackers. In addition, a dummy location selection algorithm based on route constraints and query history is proposed, which improves the privacy protection by maximizing physical dispersion, and location difference. The proposed method does not require any reliable third-party server, which can protect vehicle location privacy against inference attacks using route information, service record, and other auxiliary information. Security and cost analysis was conducted on the proposed method. The experimental results showed that this method can ensure the uncertainty and physical dispersion of dummy locations, improving the effectiveness of dummy locations, and effectively protect vehicle location privacy.
Jiang Han, Hequn Xian, Dalin Yang
ICCCN2
2024 ADG-Dedup: Adaptive Dynamic Grained Deduplication Scheme for IoT Data in Cloud Storage
Hequn Xian
SecureComm (4)2
2024 Mal-POBM: A Genetic Algorithm for Malware Adversarial Sample Generation
Hequn Xian, Xiaowei Peng
SecureComm (3)2
2024 MRFE: A Deep-Learning-Based Multidimensional Radio Frequency Fingerprinting Enhancement Approach for IoT Device Identification
abstract
Nowadays, wireless networks have been widely deployed in our daily lives, providing people with convenient Internet of Things (IoT) services in healthcare, smart cities, transportation, etc. However, the open nature of communication mediums leaves IoT devices susceptible to unauthorized access by rogue devices, leading to significant privacy breaches and property damage. Among various security measures, radio frequency (RF) fingerprinting stands out as a promising device identification technique, owing to RF fingerprints’ uniqueness and forgery-resistant nature. Existing methods, however, overlook the structural relationship of a transmitter’s internal hardware paths, affecting the performance and efficiency of RF fingerprint identification. Inspired by the internal hardware paths, this article introduces a novel deep-learning-based RF fingerprinting approach, multidimensional RF fingerprinting enhancement (MRFE). MRFE enhances RF fingerprinting by dissecting raw IQ signals into multiple dimensions and proposing a novel fingerprint strengthen layer (FSL) to extract multidimensional fingerprints from the separate hardware paths, then leveraging attention mechanisms to fuse them into an enhanced RF fingerprint. The enhanced fingerprint captures more detailed physical hardware characteristics, effectively enhancing device identification accuracy. Our MRFE’s open-source implementation has been validated on the public ORACLE RF fingerprinting data set, achieving an impressive 99.33% accuracy in identifying 16 high-end bit-similar transmitters with identical configurations.
Zaikai Yang, Hanlin Zhang 0001, Fei Chen 0014, Hequn Xian
IEEE Internet Things J.5
2024 Eliminating Rogue Access Point Attacks in IoT: A Deep Learning Approach With Physical-Layer Feature Purification and Device Identification
abstract
Wi-Fi plays an essential role in various emerging Internet of Things (IoT) services and applications in smart cities and communities, such as IoT access, data transmission, and intelligent control. However, the openness of such wireless communication medium makes IoT extremely vulnerable to conventional Wi-Fi attacks, of which one is rouge access point (RAP) attacks. This attack brings about serious privacy leakage and property damage to IoT users, motivating in-depth research on RAP attack detection in both academic and industrial communities. Recently, the phase error extracted from channel state information (CSI) has been extensively explored as a physical-layer hardware fingerprint to realize RAP detection. However, in this article, we discover that the phase error suffers from an fingerprint fracture phenomenon (FFP), leading to the complete failure of environment noise filters applied in state-of-the-art approaches and resulting in unsatisfactory detection accuracy. Inspired by our significant discovery, we propose a deep-learning RAP detection method named DL-PEDR. It innovatively offers an Auto-NRK network to effectively remove the environment interference on phase error drift range and inputs it into a Self-ACC network as a reconstructed device fingerprint to accurately authenticate the access point (AP) identity. Through comprehensive evaluation experiments with 30 commonly used Wi-Fi routers, we demonstrate that DL-PEDR achieves a 100% device distinction rate and a 96.6% RAP detection rate under dynamic environments. Moreover, we collect and share more than 1.5 million pieces of CSI data to alleviate the need for large-scale public CSI data sets.
Zaikai Yang, Hanlin Zhang 0001, Fei Chen 0014, Hequn Xian
IEEE Internet Things J.5
2024 Biometric identification on the cloud: A more secure and faster construction
Duo Wu, Leibo Li, Weizhong Tian, Hequn Xian, Chengliang Tian
Inf. Sci.4
2024 AF-Dedup: Secure Encrypted Data Deduplication Based on Adaptive Dynamic Merkle Hash Forest PoW for Cloud Storage
abstract
For encrypted data deduplication, proof of ownership (PoW) verifies a client's ownership of an entire file, preventing malicious users from exploiting a single segment of information to gain access to the file. By establishing the identity of two users who possess the same file, cloud service provider (CSP) can maintain a single copy for the file, enabling deduplication. However, existing PoW schemes based on Merkle hash tree (MHT) cannot guarantee the security of small files. Therefore, we propose a novel data structure namedadaptivedynamicMerklehashforest (ADMHF) for PoW, and present an encrypted data deduplication scheme called AF-Dedup. It reduces the risks of data content exposure resulting from multiple ownership verification attempts in traditional schemes. Specifically, we first construct the file tag as a unique identifier of the file. Second, different encryption schemes are employed depending on the popularity of the data. Then, the corresponding ADMHF is generated for subsequent ownership verifications. After security analysis and simulation experiments, our scheme is proven to significantly enhance the security of small files. In a given situation for files with only two blocks, our scheme achieves the same level of security as the existing scheme for a file with 91 blocks.
Hequn Xian
IEEE Trans. Ind. Informatics2
2023 VDCNet: A Vulnerability Detection and Classification System in Cross-Project Scenarios
Hequn Xian, Jiyang Chen
ICANN (1)2
2023 Query on the cloud: improved privacy-preserving k-nearest neighbor classification over the outsourced database
Chengliang Tian, Hequn Xian, Weizhong Tian, Yan Zhang 0037
World Wide Web (WWW)3
2022 Privacy-Preserving and Verifiable Cloud-Aided Disease Diagnosis and Prediction With Hyperplane Decision-Based Classifier
abstract
With the vigorous development and gradual maturity of machine learning (ML) technologies, the AI-assisted disease diagnosis and prediction ($\mathcal {AADP}$) system has been extensively studied and can be expected to be intensively deployed in the real world. However, as the scale of ML data increases exponentially, the training and application of ML models impose a great burden on resource-constrained terminals. Designing cloud/edge server-aided$\mathcal {AADP}$protocols is becoming a popular topic. Whereas, the sensitivity of ML data, the intellectual property of ML models, and the uncontrollability of servers bring great security challenges to this promising computing paradigm. In this article, we initialize a new four-party framework for the$\mathcal {AADP}$system which consists of users, third-party test institution, AI doctor, and cloud/edge server. With this framework, we design two high-efficiency and secure outsourcing$\mathcal {AADP}$protocols under two different security models. By comprehensively employing secure hash functions, Householder transformations, and random permutations, we realize the following design objectives: 1) user’s actual identification is invisible to the other parties; 2) user’s feature vector is blinded to the AI doctor and the server; 3) the ML model of the AI doctor is confidential to the server; 4) AI doctor can obtain decent computational savings compared with achieving the diagnosis task by itself; and 5) AI doctor can verify the server’s misbehaviors with a nonnegligible probability under the security model with a fully malicious server. We argue these claims with rigid theoretical proofs and corroborate them with extensive experimental analysis.
Yuhang Shao, Chengliang Tian, Lidong Han, Hequn Xian, Jia Yu 0003
IEEE Internet Things J.4
2021 Secure Encrypted Data Deduplication Based on Data Popularity
Hequn Xian, Liming Wang 0001
Mob. Networks Appl.2
2021 A Graded Reversible Watermarking Scheme for Relational Data
Ruitao Hou, Hequn Xian
Mob. Networks Appl.2
2020 An integrity verification scheme of cloud storage for internet-of-things mobile terminal devices
Xiuqing Lu, Zhenkuan Pan 0001, Hequn Xian
Comput. Secur.3
2020 SoProtector: Safeguard Privacy for Native SO Files in Evolving Mobile IoT Applications
abstract
Android Apps have become the most important mobile applications in the evolving mobile IoT systems, whose security and privacy are confronted with ever more challenges, since such mobile devices as smartphones involve too much personal privacy information. Meanwhile, the developers prefer to put core functions (e.g., encryption function and T9 search function) of Android applications in the native layer for execution efficiency. However, there are no automated security analysis tools to protect the security and privacy of the Android native layer, especially for those dynamically loaded third-party SO libraries. In order to solve the previous problem, which is confusing, we propose a novel and scalable system, called SoProtector, to prevent privacy from leaking via the analysis of data flow between the Java and native layers. For detection of the malicious function implanted in the SO libraries, SoProtector realizes a real-time engine. We derive the malware features via three steps: 1) present binary files in native family as a grayscale image; 2) with use of the ARM instructions set reversely obtain the code of the SO file and using Python to obtain the opcode sequence; and 3) each file is transformed as the form of assembly language by IDA Pro, which includes a gdl file as an accompaniment. Our experiment, which involved 3400 applications, demonstrates that SoProtector is able to detect more sinks, sources, and smudges. It effectively inspects and blocks at least 82% of the applications that are loading malicious third-party SO dynamically, and it has relatively low overhead in the meantime, compared to most of the existing static analysis tools (e.g., FlowDroid and AndroidLeaks).
Guangquan Xu, Wei Wang 0012, Litao Jiao, Kaitai Liang, James Xi Zheng, Wenjuan Lian, Hequn Xian, Honghao Gao
IEEE Internet Things J.8
2020 Privacy-preserving categorization of mobile applications based on large-scale usage data
Guangquan Xu, Wenjuan Lian, Hequn Xian, Wei Wang 0012
Inf. Sci.5
2020 Blockchain-based two-party fair contract signing scheme
Hanlin Zhang 0001, Jia Yu 0003, Hequn Xian
Inf. Sci.4
2020 CSNN: Password guessing method based on Chinese syllables and neural network
Hequn Xian
Peer-to-Peer Netw. Appl.2
2020 A Secure Random Key Distribution Scheme Against Node Replication Attacks in Industrial Wireless Sensor Systems
abstract
With the wide deployment of wireless sensor networks in smart industrial systems, lots of unauthorized attacking from the adversary are greatly threatening the security and privacy of the entire industrial systems, of which node replication attacks can hardly be defended, since it is conducted in the physical layer. To solve this problem, we propose a secure random key distribution (SRKD) scheme, which provides a new method for the defense against the attack. Specifically, we combine a localized algorithm with a voting mechanism to support the detection and revocation of malicious nodes. We further change the meaning of the parameter s to help prevent the replication attack. Furthermore, the experimental results show that the detection ratio of replicate nodes exceeds 90% when the number of network nodes reaches 200, which demonstrates the security and effectiveness of our scheme. Compared with existing state-of-the-art schemes, the SRKD scheme also has good storage and communication efficiency.
Longpeng Li, Guangquan Xu, Litao Jiao, Hao Wang 0003, Jing Hu 0007, Hequn Xian, Wenjuan Lian, Honghao Gao
IEEE Trans. Ind. Informatics7
2020 SSL-SVD: Semi-supervised Learning-based Sparse Trust Recommendation
abstract
Recommendation systems have been widely used in large e-commerce websites, but cold start and data sparsity seriously affect the accuracy of recommendation. To solve these problems, we propose SSL-SVD, which works to mine the sparse trust between users and improve the performance of the recommendation system. Specifically, we mine sparse trust relationships by decomposing trust impact into fine-grained factors and employing the Transductive Support Vector Machine algorithm to combine these factors. Then, we incorporate both social trust and sparse trust information into the SVD++ model, which can effectively utilize the explicit and implicit influence of trust for rating prediction in the recommendation system. Experiments show that our SSL-SVD increases the trust density degree of each dataset by more than 65% and improves the recommendation accuracy by up to 4.3%.
Zhengdi Hu, Guangquan Xu, James Xi Zheng, Zhangbing Li, Quan Z. Sheng, Wenjuan Lian, Hequn Xian
ACM Trans. Internet Techn.8
2017 BKI: Towards Accountable and Decentralized Public-Key Infrastructure with Blockchain
Zhiguo Wan, Zhangshuang Guan, Feng Zhuo, Hequn Xian
SecureComm4