VLDB 2026 Research / reviewers in the wild / expert
Yunchuan Guo
dblp:22/7487
· DBLP profile ↗
53ranked-venue papers
6as first author
30since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 1 first-author · 11 since 2021Computer networks · 12 · 3 first-author · 6 since 2021Systems, architecture and hardware · 8 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Defense Response Time Window Optimization Against Coordinated Flooding Attacks in Space-Ground Integrated Networks
Dongbin Chen, Yunchuan Guo, Mengxiang Zhu, Zifu Li |
ICIC (11) | 2 |
| 2026 | HAS-B Tree: An Efficient Utility-Preserving Index for Anonymized Data Management
Haotian Yue, Fenghua Li 0001, Zifu Li, Yunchuan Guo, Shoukun Guo |
ICIC (2) | 4 |
| 2026 | How Far Are We from Automatically Identifying Violations of the Data Minimization Principle in Privacy Policies?abstractData protection laws and regulations require service providers to disclose data practices in privacy policies, specifying what personal information is processed and for what purposes. For compliance, these data practices must adhere to the data minimization principle, limiting the processing of personal information to what is directly relevant and necessary for the service purposes. However, data minimization is context-dependent, making violations difficult to define and quantify in privacy policies. Meanwhile, privacy policies are semantically complex and unstructured, hindering accurate extraction of fine-grained data practices and large-scale automated evaluation. To address these issues, we propose DataMini, a human--LLM collaborative evaluation framework for identifying violations of the data minimization principle in privacy policies. First, DataMini categorizes data minimization violations into two dimensions: inherent violations and contextual violations, establishing fine-grained evaluation criteria. Second, we construct a compliance baseline by mining high-frequency patterns from large-scale privacy policies and integrating expert knowledge to derive compliance mappings for human--LLM collaborative evaluation. Finally, the compliance baseline can automatically verify data practices that satisfy the data minimization principle, enabling the framework to focus exclusively on identifying suspected violations to improve efficiency and accuracy. Extensive evaluations demonstrate that DataMini exhibits superior data practice extraction accuracy of 83.46% and achieves an F1-score of 0.8180 for identifying data minimization violations in privacy policies, reducing manual evaluation effort by approximately 80%. Ziyan Zhou 0001, Yanru He, Yunchuan Guo, Liang Fang 0009, Fenghua Li 0001 |
SIGIR | 3 |
| 2025 | Automatic State Machine Inference for Binary Protocol Reverse EngineeringabstractProprietary protocols are widely used to ensure efficient data transmission, enhance privacy, and meet specific application requirements. However, the lack of public standards often leaves their security inadequately evaluated, posing significant challenges for network security. Protocol Reverse Engineering (PRE) is used to analyze protocols by inferring their structure and behavior. However, existing PRE methods primarily focus on protocol format analysis, neglecting Protocol State Machine (PSM) analysis, which can lead to insufficient detection of abnormal behaviors and potential vulnerabilities. To address this, we propose an automatic PSM inference framework for unknown protocols, incorporating a fuzzy membership-based auto-converging DBSCAN algorithm for protocol format clustering, followed by a session clustering algorithm based on Needleman-Wunsch and K-Medoids algorithm to classify sessions by protocol type. Finally, we refine a probabilistic PSM algorithm to infer protocol states and transitions. Experiments show that our method can infer PSMs while enabling precise protocol classification. Junhai Yang, Fenghua Li 0001, Liang Fang 0009, Yunchuan Guo, Zifu Li |
GLOBECOM | 5 |
| 2025 | SEHAP: Secure and Efficient Handover Authentication Protocol in LEO Satellite Non-Terrestrial NetworksabstractLEO satellite non-terrestrial networks (NTN) utilize satellites in Low Earth Orbit (LEO) to dynamically establish global communication service and own significant promise. The dynamic nature of LEO satellite NTN necessities efficient handover authentication protocols. However existing schemes cannot be directly applied in LEO satellite NTN because of their low efficiency and security. To address these problems, we propose a handover authentication protocol to quickly and securely authenticate the user’s identity during the handover process. In our scheme, we incorporate an implicit session-bound random challenge to facilitate mutual authentication and key agreement between the User Equipments (UEs) and satellites. To improve authentication efficiency, we propose a batch handover mechanism to transfer the necessary security contexts, largely reducing the handover authentication cost. We verify our protocol’s security using BAN logic and Tamarin prover. The performance evaluation shows that SEHAP outperforms other schemes in both communication and computational efficiency in LEO satellite NTN. Yunchuan Guo, Jing Wang 0174, Kui Geng, Zifu Li, Fenghua Li 0001, Liang Fang 0009 |
ICASSP | 1 |
| 2025 | Toward Forward-Secure End-to-End Data Sharing: An Attribute-Key-Free CP-ABE SchemeabstractIn end-to-end data sharing, data are directly distributed to data receivers and stored on their terminals, making it hard to ensure forward security because receivers whose permissions have been revoked may still access previously shared data. To address these challenges, we propose an attribute-key-free CP-ABE scheme, aimed at securely binding data with access policies while ensuring forward security. Specifically, the decryption process in our scheme is delegated to the attribute authorities, which adopt the user’s real-time attribute values to decrypt the ciphertext. To prevent the honest-but-curious attribute authorities from accessing the plaintext, the ciphertext is re-encrypted with a one-time key before being sent to the attribute authorities. Furthermore, to prevent sensitive information from being inferred through the policy, we design a policy-hiding mechanism to conceal attribute values. Through these mechanisms, it can be ensured that the data subject always has control over his or her personal data during the end-to-end data-sharing process. We evaluate the performance of our scheme through both theoretical analysis and comparative experiments, and the results show our scheme’s effectiveness. Xinyi Shi, Yunchuan Guo, Mingjie Yu, Daiyong Quan, Wenlong Kou, Fenghua Li 0001 |
ICASSP | 2 |
| 2025 | Dynamically Optimize MTD Strategy in Satellite Computing Systems Using A2C Reinforcement LearningabstractThe Satellite Computing System (SCS) faces an increasing number of attacks. Although Moving Target Defense (MTD) can effectively mitigate attacks in ground networks, it is not well-suited for SCS due to the highly dynamic nature of both SCS traffic and attackers’ scanning behaviors. In this paper, we propose a dynamic MTD strategy optimization scheme using Advantage Actor-Critic (A2C) reinforcement learning. Specifically, we formulate the MTD strategy optimization for SCS as a Markov Decision Process (MDP). Furthermore, by accounting for the uncertainty in attack behavior changes, we apply A2C reinforcement learning to optimize the MTD strategy within the MDP framework. Experimental results demonstrate that our scheme effectively reduces the frequency of scanning hits, shortens the duration attackers can hold addresses, and minimizes the impact of MTD on quality of service. Yunchuan Guo, Shoukun Guo, Fenghua Li 0001, Faqun Jiang, Liang Fang 0009 |
ICASSP | 2 |
| 2025 | Accurate Hardware Trojan Detection for SGIN Device: A Prompt-Tuning and LangChain ApproachabstractSpace-Ground Integrated Networks (SGIN) devices are at risk of hardware Trojan attacks. Currently, existing detection schemes (e.g., deep learning) require a large amount of labeled samples. However, obtaining a high-quality labeled hardware Trojan dataset for SGIN devices is challenging due to the structural complexity of hardware, resulting in poor detection performance. To address this challenge, this paper combines prompt-tuning with LangChain to propose a hardware Trojan detection scheme for SGIN devices without requiring extensive training samples. In our scheme, we transform hardware Trojan detection into a mask prediction problem and design a two-phase prompt-based detection framework. In the first phase, we design 5 prompt patterns with masks and utilize Roberta-large as a large language model (LLM) to predict masks and their confidence. If their confidence is below a given threshold value, the second phase is initiated, where the corresponding original samples are fed into LangChain to optimize detection. To enhance the detection accuracy, we develop a Positional State Tree (PST) to extract the logical parallel structure of SGIN Trojan. Experiments show that our scheme achieves an accuracy of 91.3% in detecting the presence of Trojans and 96.3% in identifying the types of Trojans, respectively. Ming Mao, Yunchuan Guo, Fenghua Li 0001, Daiyong Quan |
ICASSP | 3 |
| 2025 | Rule Generation for Anomalous Behaviors Detection in Enterprises: A Few-Shot Learning Approach via Chain-of-Thoughts
Xin Bao, Yunchuan Guo, Xinyi Shi, Kui Geng, Wenlong Kou, Zifu Li |
ICIC (7) | 2 |
| 2025 | Accurate Classification for Government Data: A Tree-of-Thoughts-Driven Few-Shot Learning Approach
Mengxiang Zhu, Yunchuan Guo, Ziyan Zhou 0001, Lingcui Zhang |
ICIC (10) | 2 |
| 2025 | Circulation Control Model and Administration for Geospatial Data
Fenghua Li 0001, Yunchuan Guo, Lingcui Zhang, Ziyan Zhou 0001 |
ICICS (1) | 3 |
| 2025 | Contrastive Learning with Knowledge-Enhanced Prompts for Insider Threat DetectionabstractInsider threat detection is essential for protecting organizations from malicious or negligent insiders. This paper proposes a knowledge-enhanced self-contrastive learning framework for insider threat detection in multi-source user behavior graph scenarios. In the user behavior graph representation phase, a multi-head attention mechanism with relational encoding is used to explore user adjacency relations, with node connectivity guiding subgraph sampling. In the knowledge enhancement phase, self-contrastive learning aligns subgraph embeddings with behavior descriptions generated by a prompt template, enriching user behavior features. Finally, the dual-stage detection scheme filters anomalous users using a variational autoencoder and categorizes them through multi-class classification. Experimental results on the CERT insider threat dataset show that our scheme achieves 97.2% accuracy and an F1 score of 0.72, significantly outperforming existing schemes. Yunchuan Guo, Mengxiang Zhu, Yongqiang Xu, Zifu Li |
IJCNN | 2 |
| 2025 | An on-the-fly framework for usable access control policy mining
Yunchuan Guo, Mingjie Yu, Fenghua Li 0001, Zhen Pang, Liang Fang 0009 |
Comput. Secur. | 1 |
| 2025 | OPMonitor: Continuously monitoring residual over-granted permissions in verified access control policies
Yunchuan Guo, Zhe Sun 0005, Mingjie Yu, Fenghua Li 0001, Liang Fang 0009 |
Comput. Secur. | 2 |
| 2025 | HT-ASAF: Automatic Sample Augmentation Framework for Hardware TrojanabstractHardware Trojans pose a significant security risk in space-ground integrated network (SGIN) devices. It is widely accepted in academia and industry that detecting hardware Trojans at an early stage, typically in register transfer-level (RTL) hardware design, can effectively protect the SGIN device. However, the few hardware Trojan samples dedicated to SGIN (called sHT) make it difficult to detect them using deep learning. To obtain more sHT samples automatically and quickly, this article proposes a lightweight automatic sample augmentation framework for hardware Trojan (HT-ASAF). In our scheme, we first designed a lightweight neural network called variational autoencoder for hardware Trojan (HT-VAE) to achieve high-generation quality without a large amount of training data. Further, we develop the positional state tree (PST) and introduce a node tuple representation for interconversion between PST and sequence to capture the intricate semantic features of concurrent operations in hardware design to enhance the performance of HT-VAE. To automatically verify the effectiveness of the augmented samples, we established an experimental platform incorporating cluster mapping (CLM), which can reduce the verification complexity. In our experiments, to obtain a small number of the training hardware Trojan samples for SGIN, we added activation mechanisms, such as velocity or altitude, to the existing RTL hardware Trojans samples to simulate the hardware Trojan threats faced by orbit devices. The set of the obtained samples is called sHT dataset. Experimental results on the obtained sHT dataset demonstrate that HT-ASAF can automatically and efficiently augment hardware trojan sample compared to existing augmentation schemes, and it performs well in the downstream task of hardware Trojan detection on SGIN devices. Fenghua Li 0001, Yunchuan Guo, Ming Mao, Zifu Li |
IEEE Internet Things J. | 3 |
| 2024 | Custominer: Mining Customized Access Control Policies under User-Defined ConstraintsabstractAccess control policies play a critical role in securing sensitive data and protecting personal rights in environments such as cloud computing and IoT. These policies, typically created by sysadmins, specify which users are authorized to access specific resources under certain conditions. However, the manual creation and revision of these policies to align with security objectives is often error-prone and labor-intensive. In this paper, we present Custominer, a policy mining tool designed to assist sysadmins in proactively generating and customizing access control policies that meet predefined security requirements. Custominer enables sysadmins to define security goals as constraints, and then automatically mines policies that satisfy these constraints from access logs. The policy mining task is framed as a local search optimization problem, utilizing a MaxSAT solver to efficiently eliminate suboptimal policy candidates. Our experiments, conducted on four real-world datasets, show that Custominer outperforms existing state-of-the-art methods in terms of both accuracy and efficiency. Yunchuan Guo, Mingjie Yu, Ziyan Zhou 0001, Liang Fang 0009, Fenghua Li 0001 |
HPCC | 2 |
| 2024 | Stochastic Game for Collaborative Defense in Multi-domain Networks: A MAPPO ApproachabstractAs cross-domain access constitutes a significant portion of network communication, multi-domain networks present both enhanced capabilities and increased cybersecurity risks. Traditional defense strategies often overlook the complexities of cross-domain collaboration, particularly the strategic interactions among domains that prioritize their own interests. In this paper, we introduce Macd, a multi-domain collaborative defense framework, which models the defense interactions as a multi-agent stochastic game. This enables Macd to consider long-term security performance across domains, mitigating multi-step attack threats. To promote effective collaboration, we propose a Shapley-value based reputation mechanism to ensure fair incentives for non-attacked domains that contributing Security Service Functions (SSFs). Additionally, we implement a MAPPO-based Macd-solver to dynamically compute optimal defense strategies. Simulations in a DDoS attack-defense scenario demonstrate that Macd significantly enhances cross-domain collaboration and improves the overall security of multi-domain networks. Yaobing Xu, Yunchuan Guo, Wenlong Kou, Ziyan Zhou 0001, Huimei Liao, Fenghua Li 0001 |
HPCC | 2 |
| 2024 | Online and Collaboratively Mitigating Multi-Vector DDoS Attacks for Cloud-Edge ComputingabstractEdge computing is witnessing a convergence of cloud data centers and edge clouds, thereby the large thereby intensifying the vulnerability of cloud services from multi-vector DDoS attacks. However, existing DDoS filtering approaches, characterized by independent offline decisions made by clouds, exhibit shortcomings in efficacy and real-time performance. This paper proposed an online collaborative mitigation framework for multi-vector DDoS attacks, which formulates the mitigation challenge as an Online Multi-dimensional Multiple-Choice Knap-sack Problem (O-MdMCKP). Further, the framework generates candidate filtering policies for each incoming attack flow and designs a policy selection algorithm by employing online analysis based on reservation functions, ensuring prompt and efficient filtering. Experimental results show the proposed algorithm outperforms other online benchmark methods. Siyuan Leng, Yunchuan Guo, Fanfan Hao, Xiaogang Cao, Fenghua Li 0001, Wenlong Kou |
ICC | 2 |
| 2024 | Orchestrating Security Protection Resource for Space-Ground Integrated NetworksabstractThe space-ground integrated networks (SGIN) is vulnerable to complex and evolving threats due to its open nature. However, the dynamic topology and limited resources of SGIN present significant challenges for security resource orchestration. Most existing studies focus on network function orchestration and resource allocation for service flows, overlooking the offensive and defensive characteristics of security resource orchestration. Moreover, they fail to adequately address the difficulties posed by the dynamic topology of SGIN. To address these gaps, we utilize a virtual node method and network structure characteristics to transform the dynamic network topology into a static scale-free network. The orchestration strategy generation problem is then modeled as a minimum spanning tree truncation game on the network. Given the NP-hard nature of the problem, we propose the OSG algorithm based on Benders decomposition to solve it. To further improve the OSG algorithm’s efficiency, we introduce an initial value algorithm and four cutting plane inequalities, culminating in the AOSG algorithm. Extensive experiments conducted on networks of varying scales demonstrate that the AOSG algorithm, incorporating the initial feasible solution and Hamming inequality, delivers superior performance and generates optimal orchestration strategies within a feasible time frame. Dongbin Chen, Yunchuan Guo, Fenghua Li 0001, Zifu Li |
TrustCom | 2 |
| 2024 | Efficiently Detecting DDoS in Heterogeneous Networks: A Parameter-Compressed Vertical Federated Learning approach
Cao Chen, Fenghua Li 0001, Yunchuan Guo, Zifu Li, Wenlong Kou |
TrustCom | 3 |
| 2024 | D3IR: Securing Multi-Domain Networks via Extending Depth-in-Defense Strategies Across Nested Management DomainsabstractIn an increasingly interconnected world, multi-domain networks serve as vital infrastructure, enabling seamless communication and resource sharing across diverse sectors, but also leading to increasingly frequent cyberattacks. Defense-in-depth (DiD) is widely regarded as a necessary strategy for mitigating these threats through layered security measures. However, current DiD strategies often fall short due to their single-domain focus, reliance on centralized control, and inability to adapt to dynamic threats. This paper proposes a novel framework to extend DiD strategies for multi-domain networks. It progressively defines key elements of multi-domain networks, culminating in a detailed hierarchical framework that clarifies the roles and interactions of management domains. Furthermore, cross-domain intrusion response is modeled as a multi-agent stochastic game, accounting for self-interested behavior and interactions between domains. The Independent Q-Learning (IQL) algorithm is employed to solve this game, with experimental results demonstrating substantial improvements in security across multi-domain environments. Yaobing Xu, Yunchuan Guo, Wenlong Kou, Junhai Yang, Ziyan Zhou 0001, Fenghua Li 0001 |
TrustCom | 2 |
| 2024 | Correcting the Bound Estimation of Mohawk
Mingjie Yu, Fenghua Li 0001, Yunchuan Guo, Zheng Yan 0002, Nenghai Yu |
TrustCom | 4 |
| 2024 | Toward Personal Data Sharing Autonomy: A Task-Driven Data Capsule Sharing SystemabstractPersonal data custodian services enable data owners to share their data with data consumers in a convenient manner, anytime and anywhere. However, with data hosted in these services being beyond the control of the data owners, it raises significant concerns about privacy in personal data sharing. Many schemes have been proposed to realize fine-grained access control and privacy protection in data sharing. However, they fail to protect the rights of data owners to their data under the law, since their designs focus on the management of system administrators rather than enhancing the data owners’ privacy. In this paper, we introduce a novel task-driven personal data sharing system based on the data capsule paradigm realizing personal data sharing autonomy. It enables data owners in our system to fully control their data, and share it autonomously. Specifically, we present a tamper-resistant data capsule encapsulation method, where the data capsule is the minimal unit for independent and secure personal data storage and sharing. Additionally, to realize selective sharing and informed-consent based authorization, we propose a task-driven data sharing mechanism that is resistant to collusion and EDoS attacks. Furthermore, by updating parts of the data capsules, the permissions granted to data consumers can be immediately revoked. Finally, we conduct a security and performance analysis, proving that our scheme is correct, sound, and secure, as well as revealing more advantageous features in practicality, compared with the state-of-the-art schemes. Qiuyun Lyu, Yilong Zhou, Yizhi Ren, Zhen Wang 0013, Yunchuan Guo |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Efficient and Privacy-Preserving Byzantine-Robust Federated LearningabstractFederated learning (FL) is a distributed machine learning paradigm, which allows the training of machine learning models to be completed without leaving the local area. However, due to the distributed architecture of FL, it is vulnerable to reconstruction attacks and Byzantine attacks, in which reconstruction attacks are prone to make attackers recover original data from shared gradients while Byzantine attacks are able to dramatically drop the accuracy of the federated model by uploading manipulated local model update. To address these problems, some privacy-preserving robust FL schemes have been proposed. But these schemes are still unpractical in terms of heavy cryptographic operations and complex secure aggregation rules without optimization. Therefore, we proposed an efficient, privacy preserving and Byzantine-robust scheme EP-FLTrust to maintain robustness while preventing information leakage during FL process with lower latency and bandwidth than previous works. Specifically, we introduce a trust third party to customize several two party computation (2PC) protocols with optimizations and design a clipping function DReLU with only 1 bit storage, which help simplify the computation and communication complexity from$O$(dn2) to$O$(dn). We give the security proof of our scheme, and establish a performance evaluation test-bed. Our results shows that EP-FLTrust has the same robustness with state-of-the-art schemes, the computation time cost of EP-FLTrust is around 50X times less than state-of-the-art privacy-preserving schemes and the communication cost is around 10X times less than state-of-the-art privacy-preserving schemes. Shijie Luan, Guangsheng Chang, Yunchuan Guo |
GLOBECOM | 5 |
| 2023 | Dynamic threshold strategy optimization for security protection in Internet of Things: An adversarial deep learning-based game-theoretical approachabstractAbstract As mobile communications, the Internet, databases, distributed computing, and other technologies continue to develop, the Internet of Things (IoT) has emerged as prevalent technique. However, attacks on security and sensitive data in IoT occur frequently, and these attacks often evade intrusion detection systems strategically by mutating their traffic. To prevent security threats and sensitive data leakage, we propose a game approach based on adversarial deep learning to optimize a dynamic security threshold strategy. We introduce a mobile edge computing framework and utilize a game model to describe the adversarial interaction between the two participants. To solve the complexity of the game problem to gain dynamically randomized adversarial attacks, we present a column generation (CG) framework, which uses a feedforward neural network to quantify data flowing through IoT devices. Considering the limited resources of IoT devices, we calculate an optimal response to cyberattacks via a particle swarm optimization algorithm, aiming to reduce the false alarm rate. The adversarial dynamic threshold (ADT)‐based column generation (CG‐ADT) algorithm generates the set of detection threshold and the probability. Finally, we present the results of experiments conducted to demonstrate the effectiveness and robustness of the proposed dynamic threshold scheme for sensitive data security protection in IoT and its suitability for implementation in production systems. Zhen Wang 0013, Yunchuan Guo, Fenghua Li 0001, Zifu Li |
Concurr. Comput. Pract. Exp. | 4 |
| 2022 | Insider Threat Detection Using Generative Adversarial Graph Attention NetworksabstractInsiders cause serious security threats to organizations. Existing insider threat detection methods mainly mine the users' behaviors or psychological features by analyzing the users' operation logs, and they ignore the associations of behaviors among users and get unappealing performance on the imbalanced samples. In this paper, considering attention mechanism, we propose Generative Adversarial Graph Attention Networks (GAGAN) to detect insider threats. First, we design association rules to construct a graph to associate users' behaviors. Second, to address the imbalanced samples, we adopt graph generator to generate abnormal nodes; A discriminator with graph attention networks is designed to further mine the potential associations of behaviors among users and discriminate real nodes from the generated nodes, also adopted to discriminate anomaly nodes from normal nodes. Experimental results on CERT data set demonstrate that our method can accurately detect abnormal insiders and outperforms several state-of-the-art baseline methods. Chaoyang Li 0011, Fenghua Li 0001, Mingjie Yu, Yunchuan Guo, Yitong Wen, Zifu Li |
GLOBECOM | 4 |
| 2022 | DICOF: A Distributed and Collaborative Framework for Hybrid DDoS Attack DetectionabstractHybrid distributed denial-of-service (DDoS) attack, which utilizes multiple types of DDoS attack to launch one attack event, has become more rampant. However, existing researches for DDoS attack detection mainly focus on the single attack scene and ignore the hybrid attack incident. To deal with the hybrid DDoS attack detect problem, we propose a distributed and collaborative DDoS detection framework(DICOF) to detect and classify multiple DDoS attack simultaneously. Firstly, we propose an entropy-based method to quickly identify the DDoS attack events by measuring the distribution of the total length of inbound and outbound packets for network traffics. Then, we adopt a GRU(Gated Recurrent Unit) based classification method to distinguish the type of different DDoS attacks contained in one attack event. Experiment results show that the DICOF is able to detect hybrid DDoS attack events at millisecond level and classify different DDoS attacks precisely. Siyuan Leng, Yingke Xie, Yunchuan Guo, Liang Fang 0009, Fenghua Li 0001 |
ISCC | 4 |
| 2022 | Efficiently Constructing Topology of Dynamic NetworksabstractAccurately constructing dynamic network topology is one of the core tasks to provide on-demand security services to the ubiquitous network. Existing schemes cannot accurately construct dynamic network topologies in time. In this paper, we propose a novel scheme to construct the ubiquitous network topology. Firstly, ubiquitous network nodes are divided into three categories: terminal node, sink node, and control node. On this basis, we propose two operation primitives (i.e., addition and subtraction) and three atomic operations (i.e., intersection, union, and fusion), and design a series of algorithms to describe the network change and construct the network topology. We further use our scheme to depict the specific time-varying network topologies, including Satellite Internet and Internet of things. It demonstrates that their communication and security protection modes can be efficiently and accurately constructed on our scheme. The simulation and theoretical analysis also prove that the efficiency of our scheme, and effectively support the orchestration of protection capabilities. Fenghua Li 0001, Cao Chen, Yunchuan Guo, Liang Fang 0009, Chao Guo 0002, Zifu Li |
TrustCom | 3 |
| 2022 | Privacy-Preserving Robust Federated Learning with Distributed Differential PrivacyabstractFederated Learning (FL) has attracted significant interest, as it provides a distributed machine learning paradigm to share data resources during model training process. However, sharing the gradients or model weights uploaded by clients or the final model aggregated by the server can lead to privacy disclosures and executing correctness issues. Specifically, the original data can be easily inferred through analyzing the shared gradients, and malicious users can disrupt the model aggregation to result in a destruction of the model accuracy. To address these issues, we propose a novel FL scheme with providing both privacy protection and robust aggregation. By using the distributed differential privacy and range proof technologies, the proposed scheme resists semi-honest servers and malicious users, while protecting the global model and providing the high accuracy. Both privacy analysis and experiments are given to demonstrate the effectiveness of our scheme. Fayao Wang, Yuanyuan He 0002, Yunchuan Guo, Peizhi Li |
TrustCom | 3 |
| 2022 | Truthfully Negotiating Usage Policy for Data SovereigntyabstractTo realize data sovereignty, the International Data Space (IDS), adopting usage policies to determine how, when and where other enterprises or individuals may use data, has been proposed by the IDS association and widely received attention from academia and industry. However, because data in the IDS are transferred across domains, existing policy creation approaches for a single domain cannot be applied in the IDS. To address this problem, in this paper, we propose a negotiation scheme to create usage policies in the IDS. In detail, we formulate usage policy negotiation as a combinatorial auction problem and adopt the Vickrey-Clarke-Groves (VCG) mechanism to incentivize potential data providers to truthfully negotiate usage policies. Both theoretical and simulation results show that our scheme maintains truthfulness on data providers and is cost-efficient. Chunlei Yang, Yunchuan Guo, Mingjie Yu, Lingcui Zhang |
TrustCom | 2 |
| 2020 | The Linear Geometry Structure of Label Matrix for Multi-label Learning
Tianzhu Chen, Fenghua Li 0001, Fuzhen Zhuang, Yunchuan Guo, Liang Fang 0009 |
DEXA (2) | 4 |
| 2020 | Decision-Making for Intrusion Response: Which, Where, in What Order, and How Long?abstractGenerating fine-grained response policies is a fundamental problem for Intrusion Response Systems (IRSs). Although existing schemes determine countermeasures and defense points efficiently, they ignore the deployment orders and execution durations of the selected countermeasures, which may impact response performance. To address this problem, by considering four attributes (i.e., attack damage, deployment cost, negative impact on QoS, and security benefit), we propose a decisionmaking framework for IRSs to reach fine-grained decisions to balance attack damage and response cost. We formulate decisionmaking as a single-objective optimization problem. To efficiently solve this problem, a Genetic Algorithm with Three-dimensional Encoding (GATE) is proposed to not only select countermeasures and defense points, but also determine deployment orders and execution durations. Simulation results demonstrate the efficiency of our approach. Yunchuan Guo, Zifu Li, Fenghua Li 0001, Liang Fang 0009, Lihua Yin, Jin Cao 0001 |
ICC | 1 |
| 2020 | Dynamic countermeasures selection for multi-path attacks
Fenghua Li 0001, Siyuan Leng, Yunchuan Guo, Kui Geng, Zhen Wang 0013, Liang Fang 0009 |
Comput. Secur. | 4 |
| 2020 | A topic-centric access control model for the publish/subscribe paradigmabstractSummary The publish/subscribe paradigm provides loosely coupled and scalable communication for the Internet of Things (IoT). In this paradigm, access control is an efficient approach to guaranteeing security. However, existing access control methods are not suitable for the publish/subscribe paradigm in the sensing layer of the IoT due to their coarse‐grained controls and lack of self‐configuration. To address these problems, in this paper, we propose a topic‐centric access control model (TCAC) to realize fine‐grained authorization for the sensing layer of the IoT. First, we use topics, a fundamental concept for the publish/subscribe paradigm, as the basic access control unit to dynamically authorize access according to the attributes of devices, users, and topics. Second, an administration model for TCAC is proposed to manage these attributes and configure access policies to effectively implement user‐driven access controls. Finally, a healthcare case is used to demonstrate the security of the proposed TCAC. The results show that our model is dynamic, fine‐grained, and user driven. Rongna Xie, Guozhen Shi, Yunchuan Guo, Fenghua Li 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2020 | Incentive mechanism for cooperative authentication: An evolutionary game approach
Liang Fang 0009, Guozhen Shi, Lianhai Wang, Shujiang Xu, Yunchuan Guo |
Inf. Sci. | 6 |
| 2020 | Securing instruction interaction for hierarchical management
Fenghua Li 0001, Zifu Li, Liang Fang 0009, Yaobing Xu, Yunchuan Guo |
J. Parallel Distributed Comput. | 6 |
| 2019 | Cyberspace-Oriented Access Control: A Cyberspace Characteristics-Based Model and its PoliciesabstractWith wide development of various information technologies, our daily activities are becoming deeply dependent on cyberspace. People often use handheld devices (e.g., mobile phones or laptops) to publish social messages, facilitate remote e-health diagnosis, or monitor a variety of surveillance. However, security insurance for these activities remains as a significant challenge. Representation of security purposes and their enforcement are two main issues in security of cyberspace. To address these challenging issues, we propose a cyberspace-oriented access control model (CoAC) for cyberspace whose typical usage scenario is as follows. Users leverage devices via network of networks to access sensitive objects with temporal and spatial limitations. We generalize subjects and objects in cyberspace and propose scene-based access control. To enforce security purposes, we argue that all operations on information in cyberspace are combinations of atomic operations. If every single atomic operation is secure, then the cyberspace is secure. Taking applications in the browser-server architecture as an example, we present seven atomic operations for these applications. A number of cases demonstrate that operations in these applications are combinations of introduced atomic operations. We also design a series of security policies for each atomic operation. Finally, we demonstrate both feasibility and flexibility of our CoAC model by examples. Fenghua Li 0001, Zifu Li, Weili Han, Ting Wu 0001, Yunchuan Guo, Jinjun Chen |
IEEE Internet Things J. | 6 |
| 2018 | Real-Time Data Incentives for IoT SearchesabstractEffectively collecting real-time data is a fundamental problem in IoT (Internet of Things) searches. In the IoT, most data are linked with the owner's private information and cannot be publicly released on the Internet. This invalidates the use of crawlers to collect data in IoT searches. As a result, effectively motivating potential data providers (PDPs) to provide real-time on demand data becomes a key requirement for the development of an IoT search service. To address this problem, we acknowledge the realistic assumption of incomplete information, and propose a buyout-auction framework, with the constraint of QoD (Quality of Data), to collect real-time data and maximize bidders' payoff. Simulation results demonstrate that our approach can drive PDPs to participate in bidding in a timely manner and provide data under the constraints of QoD to IoT search service providers. Yunchuan Guo, Liang Fang 0009, Kui Geng, Lihua Yin, Fenghua Li 0001 |
ICC | 1 |
| 2018 | Selecting Combined Countermeasures for Multi-Attack Paths in Intrusion Response SystemabstractCountermeasure selection is a key process of the Intrusion Response System (IRS). Many cost-sensitive schemes have been proposed to select the optimal countermeasure to maximize security utility by attuning attack damage and response cost. However, existing schemes ignore the interaction between different countermeasures for different attack paths, and neglect the uncertainty between alerts and attacks, which may lead to excessive or insufficient responses. ignore the interaction between different countermeasures for multiple attack paths. To address this problem, in this paper, we propose a combined countermeasures selection scheme based on probabilistic attack tree (PAT). First, we employ Bayesian networks to calculate the probability of each atomic attack in the PAT. Next, the exploitation probability of each attack path is evaluated and multiple possible attack paths are identified. In addition, we quantify the damage of each identified attack path and formulate the countermeasure selection for single attack path as a multi-objective optimization problem. Finally, by considering the security utilities of the countermeasures for different attack paths, we use a greedy strategy to select the combined countermeasures and maximize overall security utility. The experimental results demonstrate the effectiveness of the proposed scheme. Fenghua Li 0001, Zhengkun Yang, Yunchuan Guo, Lihua Yin, Zhen Wang 0013 |
ICCCN | 4 |
| 2018 | HAC: Hybrid Access Control for Online Social NetworksabstractThe rapid development of communication and network technologies including mobile networks and GPS presents new characteristics of OSNs. These new characteristics pose extra requirements on the access control schemes of OSNs, which cannot be satisfied by relationship-based access control currently. In this paper, we propose a hybrid access control model (HAC) which leverages attributes and relationships to control access to resources. A new policy specification language is developed to define policies considering the relationships and attributes of users. A path checking algorithm is proposed to figure out whether paths between two users can fit in with the hybrid policy. We develop a prototype system and demonstrate the feasibility of the proposed model. Fangfang Shan, Hui Li 0006, Fenghua Li 0001, Yunchuan Guo, Ben Niu 0001 |
Secur. Commun. Networks | 4 |
| 2018 | Security Measurement for Unknown Threats Based on Attack PreferencesabstractSecurity measurement matters to every stakeholder in network security. It provides security practitioners the exact security awareness. However, most of the works are not applicable to the unknown threat. What is more, existing efforts on security metric mainly focus on the ease of certain attack from a theoretical point of view, ignoring the “likelihood of exploitation.” To help administrator have a better understanding, we analyze the behavior of attackers who exploit the zero-day vulnerabilities and predict their attack timing. Based on the prediction, we propose a method of security measurement. In detail, we compute the optimal attack timing from the perspective of attacker, using a long-term game to estimate the risk of being found and then choose the optimal timing based on the risk and profit. We design a learning strategy to model the information sharing mechanism among multiattackers and use spatial structure to model the long-term process. After calculating the Nash equilibrium for each subgame, we consider the likelihood of being attacked for each node as the security metric result. The experiment results show the efficiency of our approach. Lihua Yin, Zhen Wang 0013, Yunchuan Guo, Fenghua Li 0001, Binxing Fang |
Secur. Commun. Networks | 4 |
| 2018 | A game-theoretic approach to advertisement dissemination in ephemeral networks
Lihua Yin, Yunchuan Guo, Fenghua Li 0001, Junyan Qian, Athanasios V. Vasilakos |
World Wide Web | 2 |
| 2017 | Optimally Selecting the Timing of Zero-Day Attack via Spatial Evolutionary Game
Lihua Yin, Yunchuan Guo, Fenghua Li 0001, Binxing Fang |
ICA3PP | 3 |
| 2017 | A Novel Threat-Driven Data Collection Method for Resource-Constrained Networks
Lihua Yin, Yunchuan Guo, Chao Li 0027, Fenghua Li 0001 |
NSS | 3 |
| 2015 | Ad Dissemination Game in Ephemeral Networks
Lihua Yin, Yunchuan Guo, Junyan Qian, Athanasios V. Vasilakos |
APWeb | 2 |
| 2015 | Assessing the Disclosure of User Profile in Mobile-Aware Services
Daiyong Quan, Lihua Yin, Yunchuan Guo |
Inscrypt | 3 |
| 2014 | Utility-based cooperative decision in cooperative authenticationabstractIn mobile networks, cooperative authentication is an efficient way to recognize false identities and messages. However, an attacker can track the location of cooperative mobile nodes by monitoring their communications. Moreover, mobile nodes consume their own resources when cooperating with other nodes in the process of authentication. These two factors cause selfish mobile nodes not to actively participate in authentication. In this paper, a bargaining-based game for cooperative authentication is proposed to help nodes decide whether to participate in authentication or not, and our strategy guarantees that mobile nodes participating in cooperative authentication can obtain the maximum utility, all at an acceptable cost. We obtain Nash equilibrium in static complete information games. To address the problem of nodes not knowing the utility of other nodes, incomplete information games for cooperative authentication are established. We also develop an algorithm based on incomplete information games to maximize every node's utility. The simulation results demonstrate that our strategy has the ability to guarantee authentication probability and increase the number of successful authentications. Yunchuan Guo, Lihua Yin, Licai Liu, Binxing Fang |
INFOCOM | 1 |
| 2014 | Bargaining-Based Dynamic Decision for Cooperative Authentication in MANETsabstractIn MANETs, cooperative authentication, requiring cooperation of neighbor nodes, is a significant authenticate technique. However, when nodes participate in cooperation, their location may easily be tracked by misbehaving nodes, meanwhile, their resources will be consumed. These two factors lead selfish nodes reluctant participate in cooperation and decrease the probability of correct authentication. To encourage nodes to take part in cooperation, we proposed a bargaining-based dynamic game model for cooperative authentication to analyze dynamic behaviors of nodes and help nodes decide whether to participate in cooperation or not. Further, to analyze the dynamic decision-making of nodes, we discussed two situations - complete information and incomplete information, respectively. Under complete information, Sub game Perfect Nash Equilibriums are obtained to guide nodes to choose its optimal strategy to maximize its utility. In reality, nodes often do not have good knowledge about others' utility (this case is often called incomplete information). To dealt with this case, Perfect Bayesian Nash Equilibrium is established to eliminate the implausible Equilibriums. Based on the model, we designed two algorithms for complete information and incomplete information,, and the simulation results demonstrate that in our model nodes participating in cooperation will maximize their location privacy and minimize their resources consumption with ensuing the probability of correct authentication. Both of algorithms can improve the success rate of cooperative authentication and extend the network lifetime to 160%-360.6%. Licai Liu, Lihua Yin, Yunchuan Guo, Binxing Fang |
TrustCom | 3 |
| 2013 | Balancing authentication and location privacy in cooperative authenticationabstractIn MANET, the cooperative authentication mechanism requires the cooperation of the neighbor nodes and significantly enhances the authentication probability. However, it exposes location privacy of neighbor nodes and is costly. How to balance the authentication and location privacy is a key issue. In this paper, we use game theory to analyze the behavior of neighbor nodes in cooperative authentication and gain the optimal strategy. Every node seeks to obtain most reward at least location privacy loss and cost. We first build the static game with complete information and obtain two pure-strategy and one mixed-strategy Nash equilibria. These equilibria can be used efficiently to balance authentication and location privacy. Then, we build the static game with incomplete information and obtain the Bayesian Nash equilibria. Licai Liu, Yunchuan Guo, Lihua Yin, Yan Sun 0004 |
ANCS | 2 |
| 2012 | Cyber Attacks Prediction Model Based on Bayesian NetworkabstractCyber attacks prediction is an important part of risk management. Existing cyber attacks prediction methods did not fully consider the specific environment factors of the target network, which may make the results deviate from the true situation. In this paper, we propose a cyber attacks prediction model based on Bayesian network. We use attack graphs to represent all the vulnerabilities and possible attack paths. Then we capture the using environment factors using Bayesian network model. Cyber attacks predictions are performed on the constructed Bayesian network. Experimental analysis shows that our method gets more accurate results. Lihua Yin, Yunchuan Guo |
ICPADS | 3 |
| 2010 | Information content security on the Internet: the control model and its evaluation
Binxing Fang, Yunchuan Guo, Yuan Zhou 0008 |
Sci. China Inf. Sci. | 2 |
| 2009 | Research on Quantitative Evaluation for IntegrityabstractIntegrity is one of essential properties of information security. It is necessary to analyze integrity of system quantitatively in order to protect the system security. For the purpose, we present formal definitions of integrity based on probabilistic computation tree logic (PCTL) and quantitative evaluation model of integrity. In the model, we model interoperations of system and environment by probabilistic automata and evaluate integrity quantitatively by probabilistic model checking algorithm. Analysis results show that the formal description of integrity is of great significance and evaluation results are different with different integrity goals even for the same system. Lihua Yin, Yunchuan Guo |
IAS | 2 |
| 2009 | Simulation Analysis of Probabilistic Timing Covert ChannelsabstractIt is very important to analyze the bandwidth and transmission error rate in the study of probabilistic timing covert channels. For the purpose, a simulation system of probabilistic timing covert channels has been set up in the paper. The simulation results show that (1) the bandwidth and the transmission error rate of probabilistic timing covert channels are closely related to the hardware/software environment, probability factor, time factor and/or coding methods as well as scheduling times; (2) the approximate transmission error rate can be measured with the central limit theorem; (3) it is not accurate to estimate the amount of information leakage based on weak probabilistic bisimulation; and (4) in probabilistic timing covert channels, there exist some characteristics which are different from non-deterministic covert channels. Yunchuan Guo, Lihua Yin, Yuan Zhou 0008, Chao Li 0027, Li Guo 0001 |
NAS | 1 |