VLDB 2026 Research / reviewers in the wild / expert
Baojiang Cui
dblp:22/1154
· DBLP profile ↗
49ranked-venue papers
7as first author
29since 2021 · last 2026
0000-0001-6937-4068ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 1 first-author · 14 since 2021Computer networks · 11 · 9 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 1 first-author · 2 since 2021Systems, architecture and hardware · 5 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HeraClass: Towards Open-World Network Flow Classification via Traffic-Language Mapping
Ni Jin, Libin Liu 0001, Yukai Miao, Li Chen 0008, Dan Li 0001, Xizheng Wang, Xiuting Xu, Baojiang Cui |
IWQoS | 8 |
| 2026 | DeRed: Enhancing third-party library detection in binaries via deceptive reuse mitigation
Shengjia Chang, Shouguo Yang, Baojiang Cui, Shaocong Feng |
Comput. Secur. | 7 |
| 2026 | What-App? App Usage Detection Using Encrypted LTE/5G TrafficabstractCellular traffic fingerprinting attacks, in which an unprivileged adversary passively monitors encrypted wireless channels to infer user activities, introduce significant privacy risks by giving attackers the ability to track user behaviors, infer sensitive activities, and profile victims without authorization. Although such attacks have been discussed for LTE and 5G, many existing studies rely on idealized assumptions that fall short when faced with the complexities of real-world practical scenarios. In this paper, we present the first practical traffic fingerprinting attack leveraging a Man-in-the-Middle (MITM) Relay in an operational cellular network. Implemented with open-source software, our attack allows a passive adversary to identify user applications with up to 99.02% accuracy, even under noisy conditions. We evaluate our method using 40 applications across five categories on multiple COTS user equipment (UE). Our approach further demonstrates the ability to infer fine-grained user activities such as browsing, messaging, and video streaming under practical constraints, including partial traffic knowledge and app version drift. The attack also achieves cross-device and cross-network transferability, and it remains robust in open-world scenarios where only a subset of application traffic is known to the adversary. We additionally propose a novel traffic regularization-based defense tailored specifically for cellular networks. This defense operates as an optional, backward-compatible security layer integrated seamlessly into the existing cellular protocol stack, effectively balancing security strength with practical considerations such as latency and bandwidth overhead. Zishuai Cheng, Mihai Ordean, Baojiang Cui |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | Adaptive Target Device Model Identification Attack in 5G Mobile NetworkabstractEnhanced system capacity is one of 5G goals. This will lead to massive heterogeneous devices in mobile networks. Mobile devices that lack basic security capability have chipset, operating system or software vulnerability. Attackers can perform Advanced Persistent Threat (APT) Attack for specific device models. In this paper, we propose an Adaptive Target Device Model Identification Attack (ATDMIA) that provides the prior knowledge for exploiting baseband vulnerability to perform targeted attacks. We discovered Globally Unique Temporary Identity (GUTI) Reuse in Evolved Packet Switching Fallback (EPSFB) and Leakage of User Equipment (UE) Capability vulnerability. Utilizing silent calls, an attacker can capture and correlate the signaling traces of the target subscriber from air interface within a specific geographic area. In addition, we design an adaptive identification algorithm which utilizes both invisible and explicit features of UE capability information to efficiently identify device models. We conducted an empirical study using 105 commercial devices, including network configuration, attack efficiency, time overhead and open-world evaluation experiments. The experimental results showed that ATDMIA can accurately correlate the EPSFB signaling traces of target victim and effectively identify the device model or manufacturer. Shaocong Feng, Baojiang Cui, Junsong Fu 0001, Meiyi Jiang, Shengjia Chang |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | FeedbackFuzz: Fuzzing Processors via Intricate Program Generation with Feedback EngineabstractAs modern processor designs become increasingly complex, detecting hardware vulnerabilities has become more challenge. Recently, hardware fuzzing techniques have shown promising results in generating complex programs for processor testing. However, the complexity of processors continues to limit the speed of vulnerability detection and the ability to achieve sufficient coverage.This paper introduces FeedbackFuzz, a novel processor fuzzer aimed at significantly accelerating vulnerability detection. FeedbackFuzz enhances detection efficiency by generating more effective test programs and optimizing the process of identifying vulnerabilities in longer programs. It designs a feedback engine for processors with out-of-order execution capabilities. Additionally, we leverage large language models (LLMs) to handle the complexity of locating vulnerabilities in lengthy programs, greatly speeding up the detection process. We evaluated FeedbackFuzz on several open-source RISC-V processors. Our evaluation demonstrates that the efficiency of FeedbackFuzz has increased by 40% compared to Cascade, with a coverage acceleration of 16.7%. Jiashun Wang, Baojiang Cui, Renhai Dong, Rundi Zhai |
ICASSP | 2 |
| 2025 | BinFuse: Binary Code Similarity Detection via Lightweight Fused Semantic EmbeddingabstractBinary code similarity detection (BCSD) is critical for ensuring software security and reliability; however, current approaches often fall short in capturing comprehensive program semantics. Existing methods typically rely on isolated code or structural embeddings; others apply naive strategies to combine these embeddings, which limits their effectiveness—particularly in complex scenarios such as cross-architecture and cross-optimization binary comparisons. To address these limitations, we propose BinFuse, a lightweight framework designed for high-performance BCSD through the efficient fusion of code and structural semantics. BinFuse introduces a novel Markov matrix construction for fine-grained code feature extraction and employs an enhanced concrete autoencoder (CAE) for optimal feature selection. These extracted features are then assigned as node attributes to construct a fused semantic control flow graph (FSCFG), which is then jointly modeled by a Siamese network to enable accurate and efficient code similarity detection. Experimental results show that BinFuse achieves an impressive accuracy of 96.3% in complex scenarios, significantly outperforming established baselines such as Asm2Vec and Gemini in multiple evaluation metrics. Notably, BinFuse achieves accuracy comparable to the state-of-the-art IoTSim while reducing the detection time by 15%. The favorable balance between accuracy and efficiency achieved by BinFuse underscores its potential as a practical and scalable solution for BCSD in complex scenarios, thereby contributing to the development of more secure and trustworthy software systems. Shengjia Chang, Baojiang Cui, Shaocong Feng |
TrustCom | 2 |
| 2025 | A combined side-channel and transient execution attack scheme on RISC-V processors
Renhai Dong, Baojiang Cui |
Comput. Secur. | 2 |
| 2025 | Who are querying for me? Measuring the dependency and centralization in recursive resolution
Qiuyun Wang, Jianrong Zhang, Baojiang Cui, Zhengwei Jiang |
Comput. Secur. | 6 |
| 2025 | NGAP Feature Fusion Hybrid Network Attack Detection for 5G Edge SecurityabstractThe fifth-generation (5G) mobile network is a critical infrastructure for cellular communication, requiring the confidentiality, integrity and availability of services. However, the inherent vulnerabilities of Radio Access Network (RAN) allow the attacker to exploit vulnerabilities in 3GPP specifications or implementation to compromise user privacy and disrupt services. Existing defense methods are limited by the reliance on manual analysis and rule-based detection, which fails to detect novel and evolving threats. We propose NGAPAD, the first system designed to automatically monitor and analyze 5G edge attack based on Next Generation Application Protocol (NGAP). NGAPAD provides a feasible solution to overcome challenges of threat pattern universality, protocol specificity and data efficiency in 5G edge security. We design a new NGAP telemetry format and a dual-branch hybrid network to achieve precise and efficient attack detection. We constructed a high-quality dataset and evaluated it experimentally on 5G simulation network. NGAPAD achieved the optimal performance metrics by sequence length tuning, achieving 99.31% F1 Score with the length of 12. The system successfully detected 18 out of 22 known edge attacks and achieved 98.3% Accuracy against unknown attacks generated by fuzzing of NGAP protocol. Shaocong Feng, Baojiang Cui, Shengjia Chang, Yuqi Huo |
IEEE Internet Things J. | 2 |
| 2025 | Fed-RWM: A Robust Watermarking Approach for Federated Learning Model Ownership ProtectionabstractThe interconnected nature of the Internet of Things (IoT) significantly enhances the efficiency of industries such as smart manufacturing, but it also raises concerns about data privacy. Federated learning (FL) utilizes an edge-cloud collaborative mode that shares models in the cloud instead of data, effectively mitigating data privacy leakage in edge IoT devices. However, FL suffers from the risk of model leakage, and both the cloud and the edge may illegally copy and sell the model, infringing on model ownership. To prevent such misbehavior, it is essential to design a robust method for verifying the model ownership. In this paper, we propose Fed-RWM, a novel watermarking method for FL models that provides robust ownership verification and avoids both edge and cloud leakage of watermark information. Fed-RWM trains the watermark by sharing parameters with an additional model and incorporates a watermark recovery method during verification to counter complex watermark removal attacks, which enhances the verification robustness. Fed-RWM introduces a new training paradigm that performs continuous watermarking training at the FL task initiator, preventing access to watermark information at both the edge and the cloud. The experimental results demonstrate that Fed-RWM performs well in model ownership verification and fidelity, is robust to different watermark removal attacks, and can provide reliable protection for federated learning models. Shike Li, Ni Jin, Baojiang Cui |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | ArchSentry: Enhanced Android Malware Detection via Hierarchical Semantic ExtractionabstractAndroid malware poses a significant challenge for mobile platforms. To evade detection, contemporary malware variants use API substitution or obfuscation techniques to hide malicious activities and mask their shallow semantic characteristics. However, existing research lacks analysis of the hierarchical semantic associated with Android apps. To address this problem, we propose ArchSentry, an enhanced Android malware detection via hierarchical semantic extraction. First, we select entities and their relationships relevant to Android software behavior through the software architecture and represent them using a heterogeneous graph. Then, we structure meta-paths to represent rich semantic information to achieve semantic enhancement and improve efficiency. Next, we design a meta-path semantic selection method based on KL Divergence to identify and eliminate redundant features. To achieve a comprehensive representation of the overall software semantics and improve performance, we construct a feature fusion approach based on Restricted Boltzmann Machines (RBM) and AutoEncoder (AE) during the pre-training phase, while preserving the probability distribution characteristics of various meta-paths. Finally, Deep Neural Networks (DNN) process fusion features for comprehensive feature sets. Experimental results on real-world application samples indicate that ArchSentry achieves a remarkable 99.2% detection rate for Android malware, with a low false positive rate below 1%. These results surpass the performance of current state-of-the-art approaches. Tianbo Wang 0001, Mengyao Liu 0001, Huacheng Li, Lei Zhao 0012, Changnan Jiang, Chunhe Xia, Baojiang Cui |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2024 | EvilPromptFuzzer: generating inappropriate content based on text-to-image modelsabstractAbstract Text-to-image (TTI) models provide huge innovation ability for many industries, while the content security triggered by them has also attracted wide attention. Considerable research has focused on content security threats of large language models (LLMs), yet comprehensive studies on the content security of TTI models are notably scarce. This paper introduces a systematic tool, named EvilPromptFuzzer, designed to fuzz evil prompts in TTI models. For 15 kinds of fine-grained risks, EvilPromptFuzzer employs the strong knowledge-mining ability of LLMs to construct seed banks, in which the seeds cover various types of characters, interrelations, actions, objects, expressions, body parts, locations, surroundings, etc. Subsequently, these seeds are fed into the LLMs to build scene-diverse prompts, which can weaken the semantic sensitivity related to the fine-grained risks. Hence, the prompts can bypass the content audit mechanism of the TTI model, and ultimately help to generate images with inappropriate content. For the risks of violence, horrible, disgusting, animal cruelty, religious bias, political symbol, and extremism, the efficiency of EvilPromptFuzzer for generating inappropriate images based on DALL.E 3 are greater than 30%, namely, more than 30 generated images are malicious among 100 prompts. Specifically, the efficiency of horrible, disgusting, political symbols, and extremism up to 58%, 64%, 71%, and 50%, respectively. Additionally, we analyzed the vulnerability of existing popular content audit platforms, including Amazon, Google, Azure, and Baidu. Even the most effective Google SafeSearch cloud platform identifies only 33.85% of malicious images across three distinct categories. Juntao He, Runqi Sui, Xuejing Yuan, Dun Liu, Wenchuan Yang, Baojiang Cui, Kedan Li |
Cybersecur. | 9 |
| 2024 | Enhanced anomaly traffic detection framework using BiGAN and contrastive learningabstractAbstract Abnormal traffic detection is a crucial topic in the field of network security. However, existing methods face many challenges when processing complex high-dimensional traffic data. Especially in dealing with redundant features, data sparsity and nonlinear features, traditional methods often suffer from high computational complexity and low detection efficiency. It is challenging to capture potential patterns in complex data effectively and cannot fully meet the needs of practical applications. To address these challenges, this paper proposes an enhanced anomaly traffic detection framework using bidirectional generative adversarial networks (BiGAN) and contrastive learning. This method preprocesses high-dimensional data through steps such as data cleaning, normalization, and clustering to improve data quality. It uses BiGAN and contrastive learning technology to enhance the model's feature representation capabilities. Experimental results show that the method proposed in this paper performs well on multiple traffic data sets and significantly improves the accuracy and efficiency of anomaly detection. Overall, the solution proposed in this paper effectively overcomes the limitations of existing methods in high-dimensional data processing and provides a more advanced abnormal traffic detection strategy. Haoran Yu 0003, Wenchuan Yang, Baojiang Cui, Runqi Sui, Xuedong Wu |
Cybersecur. | 3 |
| 2024 | Renyi entropy-driven network traffic anomaly detection with dynamic thresholdabstractAbstract Network traffic anomaly detection is a critical issue in network security. Existing Abnormal traffic detection methods rely on statistical-based or anomaly-based approaches, and these detection methods all require a full understanding of traffic characteristics and attack patterns. Information entropy has been widely studied in abnormal traffic detection because it can describe the distribution characteristics of network traffic. However, this method makes it difficult to cope with the timing and variability of network traffic. To address these challenges, this paper proposes a network traffic anomaly detection method based on Renyi entropy. Simultaneously, we introduce a fixed time window and utilize an improved EWMA model within this window to dynamically set thresholds for anomaly detection. Experimental results show that the method proposed in this paper is superior to popular abnormal traffic detection methods in terms of effectiveness and efficiency, it is better adapted to the dynamic changes of network traffic and provides a more reliable solution for anomaly detection. Haoran Yu 0003, Wenchuan Yang, Baojiang Cui, Runqi Sui, Xuedong Wu |
Cybersecur. | 3 |
| 2024 | A formal security analysis of the fast authentication procedure based on the security context in 5G networks
Baojiang Cui, Haitao Du, Jie Xu 0038, Junsong Fu 0001 |
Soft Comput. | 2 |
| 2024 | RUDOLF: An Efficient and Adaptive Defense Approach Against Website Fingerprinting Attacks Based on Soft Actor-Critic AlgorithmabstractAlthough Tor is designed to provide anonymity, website fingerprinting (WF) attacks have posed significant threats to user privacy. In response, various defense approaches have been developed. Randomization and regularization-based defenses are criticized to be inefficient due to their bandwidth-consuming nature. Some adversarial learning-based defenses are impractical because the generation of perturbation depends on the complete traffic traces. Other adversarial learning-based defenses have weaknesses of lacking adaptability because their perturbations are input-agnostic. To overcome these shortcomings, we propose RUDOLF, an efficient and adaptive WF defense based on the soft actor-critic (SAC) algorithm of reinforcement learning (RL). We train the agent that can incrementally output perturbations synchronously following each burst of real-time traffic. Different from previous defenses, RUDOLF’s perturbation does not depend on the integrity of the traffic and concerns the actual real-time traffic, which ensures the practicality of implementation and adaptability. Besides, we take advantage of the exploratory characteristics of the SAC algorithm to obtain the optimal policy of adding perturbations that can efficiently balance defense effects and bandwidth consumption. Experiments on synthetic datasets show that with less than 30% bandwidth overhead (BWO), RUDOLF can reduce the average attack accuracy to around 15%–20%, which is superior to previous works. We also have implemented RUDOLF as a Tor pluggable transport. The performance in the real Tor network shows that RUDOLF can reduce the average accuracy of WF classifier to around 24% with about 25% BWO and almost no time delay. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | KimeraPAD: A Novel Low-Overhead Real-Time Defense Against Website Fingerprinting Attacks Based on Deep Reinforcement LearningabstractThe onion router (Tor) is a network system for anonymous communication. However, website fingerprinting (WF) attacks have threatened the anonymity of Tor. WF attackers can passively monitor and collect traffic, classify the victims’ traffic based on machine learning or deep learning, and identify the websites the victims visit. In recent years, there has been some research on WF defense, but most of the works have high bandwidth and latency overhead. Besides, some defenses are criticized as being unrealistic to implement in real-time due to the need for prior knowledge of the traffic’s exact packet sequences, and the lengths of sequences. In this paper, we propose KimeraPAD, a defense against WF attacks based on deep reinforcement learning. Specifically, our method first trains an agent to generate perturbations confusing the attacker’s classifier. To overcome the weak point of WF defense based on adversarial learning, we then design the implementation method and incur randomness so that it can inject dummy packets in real time and resist adversarial training. Experimental results demonstrate that our method can greatly reduce attack accuracy with a low bandwidth overhead. Besides, KimeraPAD can also be implemented on the client side, which simplifies the implementation a lot while achieving excellent performance. Meiyi Jiang, Baojiang Cui, Junsong Fu 0001, Tao Wang 0012 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | A Vulnerability Detection Method for SDN with Optimized Fuzzing
Xiaofeng Chi, Jingling Zhao, Baojiang Cui |
AINA (2) | 4 |
| 2023 | Static vulnerability mining of IoT devices based on control flow graph construction and graph embedding network
Baojiang Cui, Chen Chen 0061, Thar Baker |
Comput. Commun. | 2 |
| 2023 | Watching your call: Breaking VoLTE Privacy in LTE/5G NetworksabstractVoice over LTE (VoLTE) and Voice over NR (VoNR), are two similar technologies that have been widely deployed by operators to provide a better calling experience in LTE and 5G networks, respectively. The VoLTE/NR protocols rely on the security features of the underlying LTE/5G network to protect users' privacy such that nobody can monitor calls and learn details about call times, duration, and direction. In this paper, we introduce a new privacy attack which enables adversaries to analyse encrypted LTE/5G traffic and recover any VoLTE/NR call details. We achieve this by implementing a novel mobile-relay adversary which is able to remain undetected by using an improved physical layer parameter guessing procedure. This adversary facilitates the recovery of encrypted configuration messages exchanged between victim devices and the mobile network. We further propose an identity mapping method which enables our mobile-relay adversary to link a victim's network identifiers to the phone number efficiently, requiring a single VoLTE protocol message. We evaluate the real-world performance of our attacks using four modern commercial off-the-shelf phones and two representative, commercial network carriers. We collect over 60 hours of traffic between the phones and the mobile networks and execute 160 VoLTE calls, which we use to successfully identify patterns in the physical layer parameter allocation and in VoLTE traffic, respectively. Our real-world experiments show that our mobile-relay works as expected in all test cases, and the VoLTE activity logs recovered describe the actual communication with 100% accuracy. Finally, we show that we can link network identifiers such as International Mobile Subscriber Identities (IMSI), Subscriber Concealed Identifiers (SUCI) and/or Globally Unique Temporary Identifiers (GUTI) to phone numbers while remaining undetected by the victim. Zishuai Cheng, Mihai Ordean, Flavio D. Garcia, Baojiang Cui, Dominik Rys |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | An Attack to One-Tap Authentication Services in Cellular NetworksabstractThe One-Tap Authentication (OTAuth) based on the cellular network is a password-less login service provided by Mobile Network Operator (MNO) through the unique communication gateway access technique. The service allows app users to quickly sign up or log in with their mobile phone numbers without entering a password. Due to its convenience, OTAuth has been widely used by various apps. However, some studies have elaborated that OTAuth services are of great drawbacks from the perspective of mobile security and identified several flawed designs, which make the MNO cannot distinguish malicious apps from normal ones and cause impersonation attacks. In this paper, we further analyze OTAuth services from the perspective of 4G and 5G cellular networks and focus on two important procedures in which the cellular network plays an important role in OTAuth services. Not surprisingly, we discover a new fundamental design flaw in determining whether the runtime environment supports OTAuth services. Moreover, we propose a mature attack paradigm by exploiting this flaw, which allows an attacker to login or register one app as a victim. To evaluate the impact of the attack, we have examined 100/90/100 Android/iOS/HarmonyOS apps for OTAuth services of 3 main-stream MNOs in China. The experimental results show that our proposed attack is applicable to almost all the apps that support OTAuth services, and affects more apps than the attacks that have been reported before. Finally, we propose several counter-measures to defend against the attack. Note that, for security’s sake, we have already reported our findings to authorized parties and received their confirmations. Baojiang Cui, Junsong Fu 0001, Bharat K. Bhargava |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Intelligent Fuzzing Algorithm for 5G NAS Protocol Based on Predefined RulesabstractThe fifth-generation mobile communication network (5G) is a significant infrastructure with the support of enhanced mobile broadband, ultra-reliable and low latency communication, and massive machine type communication. Due to the large-scale application of 5G in industrial control field, the security of 5G network has become an important issue. In order to efficiently perform security detection on 5G radio access network protocols, we propose an intelligent fuzzing algorithm for 5G NAS protocol based on predefined rules. Through the analysis of the 3GPP NAS protocol technical specification and captured packets, a message structure table is extracted based on the NAS message format and field properties. Different mutation strategies are then dynamically assigned to different key fields to realize the intelligence of the message mutation process. Furthermore, in order to evaluate the performance of the algorithm, we implement a fuzzing prototype system based on this intelligent mutation algorithm, and then conduct practical security detection on 5G NAS protocol in OAI, an open-source software radio simulation environment. Experimental results show that our proposed intelligent mutation algorithm has better performance in terms of protocol state coverage and the scale of test cases. In addition, five types of security vulnerabilities in OAI are also exposed in this paper, namely buffer overflow, use-after-free, infinite loop, memory access for uninitialized address, and memory access for NULL pointers. These vulnerabilities could result in denial of registration services to users. Fengjiao He, Wenchuan Yang, Baojiang Cui, Jia Cui |
ICCCN | 3 |
| 2022 | A novel privacy-aware model for nonparametric decentralized detection
Baojiang Cui, Cong Sun 0002 |
Comput. Secur. | 2 |
| 2022 | Defending Trace-Back Attack in 3D Wireless Internet of ThingsabstractWith the development of 5G, it is unsurprising that most of the smart devices in the Internet of Things (IoT) will be wirelessly connected with each other in the near future. This kind of lightweight, scalable and green network architecture will be well-received. In a wide variety of IoT application scenarios, sensor nodes deployed in a local space, such as a multistory building, automatically form a distributed 3D wireless IoT and it can be employed to collect and analyze environmental information. Source-location privacy protection is of great importance in these networks and however, most existing schemes focus on only planar distributed networks which are not suitable for the 3D networks. In this paper, we consider a novel trace-back attack for 3D wireless IoT and then design a source-location privacy protection scheme, named DMR-3D, to defend this kind of novel attacks. In DMR-3D, the source node first selects a set of virtual locations to indirectly choose a set of agent nodes based on the cold start sphere structure and the ellipsoid communication pipeline. Then, a sophisticated mechanism is designed based on both the connected graph and Multiple Delaunay Triangulation (MDT) structure of the network to deliver packets from the source node to the destination node via these agent nodes in a relay manner. Analysis and simulation results illustrate that the proposed scheme can effectively protect source-location privacy with a moderate increment of path stretch, time delay and data transmission amount. Junsong Fu 0001, Na Wang 0003, Leyao Nie, Baojiang Cui, Bharat K. Bhargava |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | A Practical Framework for Secure Document Retrieval in Encrypted Cloud File SystemsabstractWith the development of cloud computing, more and more data owners are motivated to outsource their documents to the cloud and share them with the authorized data users securely and flexibly. To protect data privacy, the documents are generally encrypted before being outsourced to the cloud and hence their searchability decreases. Though many privacy-preserving document search schemes have been proposed, they cannot reach a proper balance among functionality, flexibility, security and efficiency. In this paper, a new encrypted document retrieval system is designed and a proxy server is integrated into the system to alleviate data owner's workload and improve the whole system's security level. In this process, we consider a more practical and stronger threat model in which the cloud server can collude with a small number of data users. To support multiple document search patterns, we construct two AVL trees for the filenames and authors, and a Hierarchical Retrieval Features tree (HRF tree) for the document vectors. A depth-first search algorithm is designed for the HRF tree and the Enhanced Asymmetric Scalar-Product-Preserving Encryption (Enhanced ASPE) algorithm is utilized to encrypt the HRF tree. All the three index trees are linked with each other to efficiently support the search requests with multiple parameters. Theoretical analysis and simulation results illustrate the security and efficiency of the proposed framework. Junsong Fu 0001, Na Wang 0003, Baojiang Cui, Bharat K. Bhargava |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2021 | A novel model for anomaly detection in network traffic based on kernel support vector machine
Cong Sun 0002, Baojiang Cui, Xiaohui Jin |
Comput. Secur. | 3 |
| 2021 | An Improved Feature Extraction Approach for Web Anomaly Detection Based on Semantic StructureabstractAnomaly-based Web application firewalls (WAFs) are vital for providing early reactions to novel Web attacks. In recent years, various machine learning, deep learning, and transfer learning-based anomaly detection approaches have been developed to protect against Web attacks. Most of them directly treat the request URL as a general string that consists of letters and roughly use natural language processing (NLP) methods (i.e., Word2Vec and Doc2Vec) or domain knowledge to extract features. In this paper, we proposed an improved feature extraction approach which leveraged the advantage of the semantic structure of URLs. Semantic structure is an inherent interpretative property of the URL that identifies the function and vulnerability of each part in the URL. The evaluations on CSIC-2020 show that our feature extraction method has better performance than conventional feature extraction routine by more than average dramatic 5% improvement in accuracy, recall, and F1-score. Zishuai Cheng, Baojiang Cui, Wenchuan Yang, Junsong Fu 0001 |
Secur. Commun. Networks | 2 |
| 2021 | A Method of Information Protection for Collaborative Deep Learning under GAN Model AttackabstractDeep learning is widely used in the medical field owing to its high accuracy in medical image classification and biological applications. However, under collaborative deep learning, there is a serious risk of information leakage based on the deep convolutional generation against the network's privacy protection method. Moreover, the risk of such information leakage is greater in the medical field. This paper proposes a deep convolution generative adversarial networks (DCGAN) based privacy protection method to protect the information of collaborative deep learning training and enhance its stability. The proposed method adopts encrypted transmission in the process of deep network parameter transmission. By setting the buried point to detect a generative adversarial network (GAN) attack in the network and adjusting the training parameters, training based on the GAN model attack is forced to be invalid, and the information is effectively protected. Xiaodan Yan, Baojiang Cui, Yang Xu 0013, Peilin Shi |
IEEE ACM Trans. Comput. Biol. Bioinform. | 2 |
| 2021 | Firmware code instrumentation technology for internet of things-based servicesabstractAbstract With the rapid development of electronic and information technology, Internet of Things (IoT) devices have become extensively utilised in various fields. Increasing attention has been paid to the performance and security analysis of IoT-based services. Dynamic instrumentation is a common process in software analysis for acquiring runtime information. However, due to the limited software and hardware resources in IoT devices, most dynamic instrumentation tools do not support IoT-based services. In this paper, we provide an analysis tool, IoTDIT, to solve the current problem of runtime detection in IoT-based services. IoTDIT employs static analysis andptracesystem calls to obtain dynamic firmware information, which can aid in firmware performance analysis and security detection. We perform experiments to verify the performance and effectiveness of the proposed instrumentation tool. Chen Chen 0061, Jinxin Ma, Baojiang Cui, Weikong Qi, Zhaolei Zhang |
World Wide Web | 4 |
| 2020 | Greybox Fuzzing Based on Ant Colony Algorithm
Baojiang Cui, Yeqi Fu |
AINA | 3 |
| 2020 | HFuzz: Towards automatic fuzzing testing of NB-IoT core network protocols implementations
Xinyao Liu, Baojiang Cui, Junsong Fu 0001, Jinxin Ma |
Future Gener. Comput. Syst. | 2 |
| 2020 | Outsourced privacy-aware task allocation with flexible expressions in crowdsourcing
Jie Xu 0038, Baojiang Cui, Ruisheng Shi, Qingling Feng |
Future Gener. Comput. Syst. | 2 |
| 2020 | Learning URL Embedding for Malicious Website DetectionabstractThe emergence of artificial intelligence technology has promoted the development of the Internet of Things. However, this promising cyber technology can encounter serious security problems while accessing the internet. A malicious website can disguise itself as a normal website, and obtain users' private information. Thus, it is very important to detect malicious websites using tools such as machine learning (ML) algorithms, as these algorithms can help us to identify abnormal information hidden in the mass traffic more easily. Accordingly, many feature engineering tasks must be performed from memory, as a strong machine learning model is greatly improved with good features. In this article, we propose an unsupervised learning algorithm that learns URL embedding. We also explore some key parameters regarding a domain embedding model to obtain a good effect on domain features. Xiaodan Yan, Yang Xu 0013, Baojiang Cui, Taibiao Guo, Chaoliang Li |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | Trustworthy Network Anomaly Detection Based on an Adaptive Learning Rate and Momentum in IIoTabstractWhile the industrial Internet of Things (IIoT) brings convenience to the industry, it also brings security problems. Due to the massive amount of data generated by the surge of IIoT devices, it is impossible to ensure whether these data contain an attack or untrustworthy data, therefore, how to ensure the security and trustworthiness of IIoT devices has become an urgent problem to solve. In this article, we design a new hinge classification algorithm based on mini-batch gradient descent with an adaptive learning rate and momentum (HCA-MBGDALRM) to minimize the effects of security attacks. The algorithm significantly improves the performance of deep network training compared with traditional neural networks, decision trees and logistic regression in terms of scale and speed. In addition, we have solved the data skew problem in the shuffle phase, and we implement a parallel framework for HCA-MBGDALRM to accelerate the processing speed of very large traffic data sets. Xiaodan Yan, Yang Xu 0013, Xiaofei Xing, Baojiang Cui, Taibiao Guo |
IEEE Trans. Ind. Informatics | 4 |
| 2019 | Terminal Access Data Anomaly Detection Based on Random Forest for Power User Electric Energy Data Acquisition System
Xiaobing Liang, Bing Zhao 0001, Bang Sun, Baojiang Cui |
AINA | 5 |
| 2019 | Ontology-based services for software vulnerability detection: a survey
Baojiang Cui |
Serv. Oriented Comput. Appl. | 2 |
| 2019 | A Distributed Position-Based Routing Algorithm in 3-D Wireless Industrial Internet of ThingsabstractSmart factory is a typical application scene of Internet of Things and wireless terminal devices naturally compose a three-dimensional (3-D) industrial wireless network. A primary requirement in the network is delivering packets from source node to destination node. Most geographic routing algorithms are designed for planar networks and they do not suit 3-D networks. In this paper, we extend a greedy perimeter stateless routing algorithm (GPSR) into three dimensions named GPSR-3D. In GPSR-3D, each node decides next hop of a packet by cooperating with only local neighbors and hence this algorithm is totally distributed. GPSR-3D comprises two packet forwarding patterns named greedy forwarding pattern (GFP) and surface forwarding pattern (SFP). In GFP, a node always sends the packet to a neighbor closest to destination and when it fails, SFP is employed for recovery. In SFP, we first divide the whole network space into a set of subspaces based on a novel 3-D geometric structure. Then, a parallel polyhedron traverse algorithm is proposed to recover local minima. A flowchart of GPSR-3D is given to clearly present the process of delivering a packet based on GFP and SFP. Simulation results show that GPSR-3D is of great reliability, energy efficiency and storage efficiency. Specifically, data transmission amount in GPSR-3D is about 67% and 71% to that of multihop Delaunay triangulation (MDT) and GDSTR-3D on average. Moreover, GPSR-3D performs much better than MDT and GDSTR-3D in terms of average storage cost and the average storage space in GPSR-3D is about 48% and 26% to that of MDT and GDSTR-3D, respectively. Junsong Fu 0001, Baojiang Cui, Na Wang 0003, Xinyao Liu |
IEEE Trans. Ind. Informatics | 2 |
| 2018 | An Adaptive Analysis Framework for Correlating Cyber-Security-Related DataabstractIn recent years, due to the rise of APT attacks and the failure of traditional security facilities, organizations have to collect a large amount of cyber-security-related data and try to unveil the previously unknown attacks by analyzing them. Additionally, a report from Gartner claims, "Information security is becoming a big data analytics problem, where massive amounts of data will be correlated, analyzed and mined for meaningful patterns". Generally, the research work of big data analytics for cyber security mainly includes building big data systems, designing efficient processing algorithms and exploring specific analysis methods and applications, such as detecting DDoS attacks, identifying malicious URLs, correlating IDS alert incidents and extracting threat intelligence from certain unstructured data. Of all these work, most is the extension of previous methods in the big data context, by employing big data techniques to improve the storage capacity, accelerate the calculation or carry out correlation analysis in a much longer time window. Instead, only a few cares about the real coordination of these multi-source, heterogeneous data. In this paper, we propose an adaptive analysis framework for correlating different kinds of cyber-security-related data, such as network traffic, alert incidents and external threat intelligence. This framework can help to improve the pertinence of analysis and better discover potential threats. Xiaohui Jin, Baojiang Cui, Jun Yang 0035, Zishuai Cheng |
AINA | 2 |
| 2018 | Fuzzing Test Method Based on Constraint-Conditions Priority for LTE-EPC Protocol
Jingling Zhao, Jinxin Ma, Baojiang Cui |
CISIS | 4 |
| 2018 | Malware Detection Using Machine Learning Based on the Combination of Dynamic and Static FeaturesabstractAs millions of new malware samples emerge every day, traditional malware detection techniques are no longer adequate. Static analysis methods, such as file signature, fail to detect unknown programs. Dynamic analysis methods have low efficiency and high false positive rate. We need a detection technique that can adapt to the rapidly changing malware ecosystem. The paper presented a new malware detection method using machine learning based on the combination of dynamic and static features. The characteristic of this experiment involved in many fields of knowledge, including binary program instrumentation, static analysis, assembly instruction analysis, machine learning, etc. Finally, we achieved a good result over a substantial number of malwares. Jingling Zhao, Suoxing Zhang, Baojiang Cui |
ICCCN | 4 |
| 2018 | A systematic review of fuzzing techniques
Chen Chen 0061, Baojiang Cui, Jinxin Ma, Runpu Wu, Jianchao Guo, Wenqian Liu |
Comput. Secur. | 2 |
| 2018 | An improved payload-based anomaly detector for web applications
Xiaohui Jin, Baojiang Cui, Zishuai Cheng, Congxian Yin |
J. Netw. Comput. Appl. | 2 |
| 2017 | Uploading multiply deferrable big data to the cloud platform using cost-effective online algorithms
Baojiang Cui, Peilin Shi, Weikong Qi |
Future Gener. Comput. Syst. | 1 |
| 2017 | WhirlingFuzzwork: a taint-analysis-based API in-memory fuzzing framework
Baojiang Cui, Yongle Hao, Xiaofeng Chen 0001 |
Soft Comput. | 1 |
| 2016 | A taint based approach for automatic reverse engineering of gray-box file formats
Baojiang Cui, Yongle Hao, Lingyu Wang 0001 |
Soft Comput. | 1 |
| 2016 | Key-Aggregate Searchable Encryption (KASE) for Group Data Sharing via Cloud StorageabstractThe capability of selectively sharing encrypted data with different users via public cloud storage may greatly ease security concerns over inadvertent data leaks in the cloud. A key challenge to designing such encryption schemes lies in the efficient management of encryption keys. The desired flexibility of sharing any group of selected documents with any group of users demands different encryption keys to be used for different documents. However, this also implies the necessity of securely distributing to users a large number of keys for both encryption and search, and those users will have to securely store the received keys, and submit an equally large number of keyword trapdoors to the cloud in order to perform search over the shared data. The implied need for secure communication, storage, and complexity clearly renders the approach impractical. In this paper, we address this practical problem, which is largely neglected in the literature, by proposing the novel concept of key-aggregate searchable encryption and instantiating the concept through a concrete KASE scheme, in which a data owner only needs to distribute a single key to a user for sharing a large number of documents, and the user only needs to submit a single trapdoor to the cloud for querying the shared documents. The security analysis and performance evaluation both confirm that our proposed schemes are provably secure and practically efficient. Baojiang Cui, Zheli Liu, Lingyu Wang 0001 |
IEEE Trans. Computers | 1 |
| 2015 | A practical off-line taint analysis framework and its application in reverse engineering of file format
Baojiang Cui, Tao Guo 0001, Guowei Dong |
Comput. Secur. | 1 |
| 2015 | Service-oriented mobile malware detection system based on mining strategies
Baojiang Cui, Haifeng Jin, Giuliana Carullo, Zheli Liu |
Pervasive Mob. Comput. | 1 |
| 2004 | Study on Performance of IP-SWAN Based on Distributed NS-RAIDabstractPrevious work on performance of network storage system has been mostly qualitative. This work proposes a quantitative analytical method based on closed queueing networks in order to analyze the performance bounds of IP-SWAN (storage wide area network) based on distributed network software RAID (NS-RAID). Experimental results show that testing results are within the bounds predicted by the performance analysis model and the bounds reflect the dynamic trend of the actual testing performance. Furthermore, the bottleneck and the potential bottleneck that affect the IP-SWAN performance can be derived from the performance analysis model. Meanwhile the model provides us with the criteria for distinguishing the key performance factors and non-key performance factors. Baojiang Cui, Gang Wang 0001, Jing Liu 0010 |
COMPSAC | 1 |