VLDB 2026 Research / reviewers in the wild / expert
Haiyong Bao
dblp:23/4271
· DBLP profile ↗
45ranked-venue papers
17as first author
32since 2021 · last 2026
0000-0002-6411-1338ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 6 first-author · 10 since 2021Systems, architecture and hardware · 9 · 3 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 4 since 2021Security and privacy · 5 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SpecGate: Spectral Decomposition and LOF-Gated Aggregation for Defending Against Backdoor Attacks in Federated Learning
Wenxiu Wu, Haiyong Bao, Menghong Guan, Jiaan Jiang, Hongning Dai, Cheng Huang 0001 |
ACISP (3) | 2 |
| 2026 | CQED: Secure and efficient composite query processing over encrypted healthcare data
Haiyong Bao, Yaotian Zhang, Xinqi Tu, Sunyu Tian, Cheng Huang 0001, Hongning Dai |
Inf. Sci. | 1 |
| 2026 | KMCS: Efficient and privacy-preserving k-core multi-attribute community search
Ziyang Zhong, Haiyong Bao, Ronghai Xie, Jiani Wu, Cheng Huang 0001, Hongning Dai |
Inf. Sci. | 2 |
| 2026 | LPSQ: Achieving Efficient and Privacy-Preserving Location-Point-Set Similarity Range Query for Cloud ComputingabstractLocation point set similarity range query aims to retrieve candidate point sets that are similar to the given point set in terms of location distribution patterns and geographical features, and it is vital in GIS (Geographic Information Systems), IoT (Internet of Things), and biometrics. Due to the economic and flexible advantages of cloud services, location data is frequently outsourced to cloud servers, which simultaneously increases the risk of privacy breaches. To address this, service providers choose to encrypt data before outsourcing. However, the existing schemes for similarity range query of encrypted location point sets have some problems, such as high computational complexity of measurements, which limit the query efficiency and security of schemes. To tackle these problems, this paper achieves the efficient and privacy-preserving location-point-set similarity range query for cloud computing (LPSQ). Firstly, we propose a lightweight similarity measurement called Geo-Jaccard similarity, to reduce the time complexity to$O(n)$. Secondly, to enhance the efficiency of the scheme, we integrate the kd-tree with pivot point technology to construct a pkd-tree, and design a corresponding filtering and verification algorithm. Thirdly, to enhance the security of our scheme, we encrypt the pkd-tree using a mix of matrix encryption and SHE (Symmetric Homomorphic Encryption), and design a series of protocols under SHE, such as SHE batch minimum value calculation protocol, SHE division protocol, and the approximation algorithm for computing Jaccard similarity securely. Finally, we prove that the security of our proposed LPSQ achieves CPA (Chosen Plaintext Attack) security. Furthermore, we conduct experiments to assess the performance, and the results demonstrate that LPSQ achieves sublinear search efficiency, while Geo-Jaccard similarity proves effective for similarity range queries on location point sets. Haiyong Bao, Daqi Li, Jing Wang 0239, Qinglei Kong, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Cloud Comput. | 2 |
| 2026 | KDCS: Achieving Efficient and Privacy-Preserving ($k,d$k,d)-Truss Community Search for Social NetworksabstractCommunity search is essential in social network analysis, with the ($k,d$)-truss model offering a robust framework to identify densely connected subgraphs that contain a query vertex and meet both$k$-truss and distance constraints. Despite the increasing reliance on cloud servers for processing large social network graph data, privacy concerns remain unaddressed. To fill this gap, we propose a novel privacy-preserving ($k,d$)-truss community search (KDCS) scheme based on weighted community graphs. Specifically, to enhance search efficiency, we introduce a$k$-truss-G (KTG) tree to index communities for efficient queries. Firstly, we develop a boundary vertex encoding mechanism for the social distance matrix. Then, we design a KTG tree construction algorithm and a ($k,d$)-truss community search algorithm based on the concept of segmentation and assembly. To ensure data security, we propose a secure community distance calculation (SCDC) algorithm, which utilizes mutually orthogonal matrices to preserve the privacy of the social distance matrix while accurately calculating the social distance. Furthermore, improved symmetric homomorphic encryption (iSHE) and matrix encryption are utilized to safeguard both dataset privacy and query privacy effectively. In addition, rigorous security analysis demonstrates that the proposed KDCS scheme is indeed privacy-preserving. Finally, extensive comparative experiments with real social network datasets show that KDCS exhibits outstanding performance at every stage, underscoring its practical significance. Haiyong Bao, Jiani Wu, Ziyang Zhong, Cheng Huang 0001, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | MPKS: Efficient and Privacy-Enhanced Multi-Party Keyword-Oriented Similarity Query in ehealthcare
Zian Zhang, Haiyong Bao, Jing Wang 0239, Cheng Huang 0001, Rongxing Lu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | EBS-CFL: Efficient and Byzantine-robust Secure Clustered Federated LearningabstractDespite federated learning (FL)'s potential in collaborative learning, its performance has deteriorated due to the data heterogeneity of distributed users. Recently, clustered federated learning (CFL) has emerged to address this challenge by partitioning users into clusters according to their similarity. However, CFL faces difficulties in training when users are unwilling to share their cluster identities due to privacy concerns. To address these issues, we present an innovative Efficient and Robust Secure Aggregation scheme for CFL, dubbed EBS-CFL. The proposed EBS-CFL supports effectively training CFL while maintaining users' cluster identity confidentially. Moreover, it detects potential poisonous attacks without compromising individual client gradients by discarding negatively correlated gradients and aggregating positively correlated ones using a weighted approach. The server also authenticates correct gradient encoding by clients. EBS-CFL has high efficiency with client-side overhead O(ml + m^2) for communication and O(m^2l) for computation, where m is the number of cluster identities, and l is the gradient size. When m = 1, EBS-CFL's computational efficiency of client is at least O(log(n)) times better than comparison schemes, where n is the number of clients. In addition, we validate the scheme through extensive experiments. Finally, we theoretically prove the scheme's security. Zhiqiang Li 0007, Haiyong Bao, Menghong Guan, Cheng Huang 0001, Hongning Dai |
AAAI | 2 |
| 2025 | PDMA: Efficient and privacy-preserving dynamic task assignment with multi-attribute search in crowdsourcing
Haiyong Bao, Ronghai Xie, Zhehong Wang, Hongning Dai |
Comput. Networks | 1 |
| 2025 | UEFL: Universal and Efficient Privacy-Preserving Federated LearningabstractFederated Learning (FL) is a distributed machine learning framework that allows for model training across multiple clients without requiring access to their local data. However, FL poses some risks, for example, curious clients might conduct inference attacks (e.g., membership inference attacks, model-inversion attacks) to extract sensitive information from other participants. Existing solutions typically fail to strike a good balance between performance and privacy, or are only applicable to specific FL scenarios. To address these challenges, we propose a universal and efficient privacy-preserving FL framework based on matrix theory. Specifically, we design the Improved Extended Hill Cryptosystem (IEHC), which efficiently encrypts model parameters while supporting the secure ReLU function. To accommodate different training tasks, we design the Secure Loss Function Computation (SLFC) protocol, which computes derivatives of various loss functions while maintaining data privacy of both client and server. And we implement SLFC specifically for three classic loss functions, including MSE, Cross Entropy, and L1. Extensive experimental results demonstrate that our approach robustly defends against various inference attacks. Furthermore, model training experiments conducted in various FL scenarios indicate that our method shows significant advantages across most metrics. Zhiqiang Li 0007, Haiyong Bao, Menghong Guan, Cheng Huang 0001, Hongning Dai |
IEEE Internet Things J. | 2 |
| 2025 | DualGuard: Obfuscated Federated Learning With Two-Party Secure Robust AggregationabstractFederated learning (FL) is a promising privacy-preserving distributed machine learning paradigm. However, data privacy leakage and Byzantine clients are common challenges in the FL aggregation phase. While extensive research has been conducted to explore defenses for these risks independently, there is a notable lack of scholarly work on integrated defense strategies to address both challenges simultaneously. To bridge this gap, we propose a novel two-party secure robust aggregation (TPSRA) framework. The critical insight of TPSRA is to couple client-side gradient obfuscation with server-side secure two-party computation to achieve robust and private FL aggregation. Specifically, clients obfuscate and split local gradients using matrix theory, while servers utilize a novel secure multiparty computation protocol based on mutually orthogonal matrices to preserve the privacy of local gradients. Additionally, TPSRA designs and integrates state-of-the-art robust aggregation algorithms into compatible subprotocols, enabling efficient parallel computation. This establishes a highly efficient and versatile secure robust aggregation framework for FL. Experiments demonstrate that our TPSRA framework not only effectively resists gradient leakage attacks and detects malicious gradients, but also exhibits superior computational and communication efficiency. We also prove theoretically that TPSRA is secure under the semi-honest adversary model. Haiyong Bao, Menghong Guan, Zhiqiang Li 0007, Cheng Huang 0001, Hongning Dai |
IEEE Internet Things J. | 2 |
| 2025 | TST-Trans: A Transformer Network for Urban Traffic Flow PredictionabstractA critical challenge for predicting urban traffic flows is to simultaneously process time series and spatial features from heterogeneous traffic data collected by diverse Internet of Things (IoT) devices. Despite the advent of Transformer-based models with an advanced network structure and excellent prediction performance, standard Transformer models are still struggling to combine both spatial information and temporal relations of traffic flows. To address these challenges, we design a novel Transformer network, namely temporal-spatial traffic-flow Transformer (TST-Trans), for traffic flow prediction with high accuracy. In particular, we use learnable position encoders to replace traditional fixed position encoders. Meanwhile, we introduce a spatiotemporal embedding method that integrates temporal relationships and spatial information with external inputs, thereby capturing the spatiotemporal dependencies of traffic flows. Experiments with the real-world datasets demonstrate that our proposed TST-Trans achieves better prediction accuracy than state-of-the-art methods while requiring fewer parameters. The research results increased by more than 10% compared with Transformer. Compared to spatiotemporal deep hybrid neural network, there is a 2% to 10% improvement in performance on different datasets. Ke Zhang 0022, Hongjin Ren, Jinbiao Kang, Cai Guo, Ming Tao 0001, Hongning Dai, Shaohua Wan 0001, Haiyong Bao |
IEEE Internet Things J. | 9 |
| 2025 | Mul_STK: Efficient and privacy-preserving query with spatio-temporal-keyword multiple attributes in cloud computing
Haiyong Bao, Menghong Guan, Jing Wang 0239, Qinglei Kong, Hongning Dai, Cheng Huang 0001 |
J. Syst. Archit. | 2 |
| 2025 | Security in data-driven satellite applications: An overview and new perspectives
Qinglei Kong, Bo Chen 0015, Haiyong Bao, Lexi Xu |
Signal Process. | 5 |
| 2025 | TAMT: Privacy-Preserving Task Assignment With Multi-Threshold Range Search for Spatial Crowdsourcing ApplicationsabstractSpatial crowdsourcing is a distributed computing paradigm that utilizes the collective intelligence of workers to perform complex tasks. How to achieve privacy-preserving task assignment in spatial crowdsourcing applications has been a popular research area. However, most of the existing task assignment schemes may reveal private and sensitive information of tasks or workers. Few schemes can support task assignment based on different attributes simultaneously, such as spatial, interest, etc. To study the above themes, in this paper, we propose one privacy-preserving task assignment scheme with multi-threshold range search for spatial crowdsourcing applications (TAMT). Specifically, we first define Euclidean distance-based location search and Hamming distance-based interest search, which map the demands of the tasks and the interests of the workers into the binary vectors. Second, we deploy PKD-tree to index the task data leveraging the pivoting techniques and the triangular inequality of Euclidean distance, and propose an efficient multi-threshold range search algorithm based on matrix encryption and decomposition technology. Furthermore, based on DT-PKC, we introduce a ciphertext-based secure comparison protocol to support multi-threshold range search for spatial crowdsourcing applications. Finally, comprehensive security analysis proves that our proposed TAMT is privacy-preserving. Meanwhile, theoretical analysis and experimental evaluation demonstrate that TAMT is practical and efficient. Haiyong Bao, Zhehong Wang, Rongxing Lu, Cheng Huang 0001, Beibei Li 0002 |
IEEE Trans. Big Data | 1 |
| 2025 | PRRQ: Privacy-Preserving Resilient RkNN Query Over Encrypted Outsourced Multiattribute DataabstractTraditional reverse k-nearest neighbor (RkNN) query schemes typically assume that users are available online in real-time for interactive key reception, overlooking scenarios where users might be offline. Moreover, existing privacy-preserving RkNN query schemes primarily focus on user features or spatial data, neglecting the significance of user reputation values. To address these limitations, we propose a privacy-preserving resilient RkNN query scheme over encrypted outsourced multi-attribute data (PRRQ). Specifically, to mitigate the challenges posed by resilient online presence (i.e., non-real-time online) of users for interactive key reception, we incorporate a non-interactive key exchange (NIKE) protocol and the Diffie-Hellman two-party key exchange algorithm to propose a multi-party NIKE algorithm (2K-NIKE), facilitating non-interactive key reception for multiple users. Considering the privacy leakage issues, PRRQ encodes original multi-attribute data (i.e., spatial, feature, and reputation values) alongside query requests based on formalized criteria. Additionally, we integrate the proposed 2K-NIKE and the improved symmetric homomorphic encryption (iSHE) algorithms to encrypt them. Furthermore, catering to the requirements of ciphertext-based RkNN queries, we propose a private RkNN query eligibility-checking (PREC) algorithm and a private reputation-verifying (PRRV) algorithm, which validate the compliance of encrypted outsourced multi-attribute data with query requests. Security analysis demonstrates that PRRQ achieves simulation-based security under anhonest-but-curiousmodel. Experimental results show that PRRQ offers superior computational efficiency compared to comparative schemes. Jing Wang 0239, Haiyong Bao, Na Ruan, Qinglei Kong, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Computers | 2 |
| 2025 | MKAC: Efficient and Privacy-Preserving Multi- Keyword Ranked Query With Ciphertext Access Control in Cloud EnvironmentsabstractWith the explosion of big data in cloud environments, data owners tend to delegate the storage and computation to cloud servers. Since cloud servers are generally untrustworthy, data owners often encrypt data before outsourcing it to the cloud. Numerous privacy-preserving schemes for the multi-keyword ranked query have been proposed, but most of these schemes do not support ciphertext access control, which can easily lead to malicious access by unauthorized users, causing serious damage to personal privacy and commercial secrets. To address the above challenges, we propose an efficient and privacy-preserving multi-keyword ranked query scheme (MKAC) that supports ciphertext access control. Specifically, in order to enhance the efficiency of the multi-keyword ranked query, we employ a vantage point (VP) tree to organize the keyword index. Additionally, we develop a VP tree-based multi-keyword ranked query algorithm, which utilizes the pruning strategy to minimize the number of nodes to search. Next, we propose a privacy-preserving multi-keyword ranked query scheme that combines asymmetric scalar-product-preserving encryption with the VP tree. Furthermore, attribute-based encryption mechanism is used to generate the decryption key based on the query user's attributes, which is then employed to decrypt the query results and trace any malicious query user who may leak the secret key. Finally, a rigorous analysis of the security of MKAC is conducted. The extensive experimental evaluation shows that the proposed scheme is efficient and practical. Haiyong Bao, Menghong Guan, Na Ruan, Cheng Huang 0001, Hongning Dai |
IEEE Trans. Cloud Comput. | 1 |
| 2025 | EPPQ: Efficient and Privacy-Preserving $k$NN Query Processing for Outsourced High-Dimensional DataabstractExtensive schemes have been conducted on the development of efficient and privacy-preserving$k$NN query algorithms in data outsourcing scenarios. However, existing researches primarily address low-dimensional data, posing scalability challenges in higher dimensions. To tackle this issue, we propose an efficient and privacy-preserving$k$NN query scheme for outsourced high-dimensional data (EPPQ), emphasizing the complete lifecycle from secure dimensionality reduction of high-dimensional data to secure$k$NN query on the reduced-dimensional data. Specifically,in the secure dimensionality reduction phase: on the one hand, EPPQ integrates principal component analysis (PCA) for dimensionality reduction to minimize computational overhead. On the other hand, to address privacy concerns during the process of PCA, by incorporating differential privacy (DP), we propose the Privacy-Preserving Data Dimensionality Reduction Algorithm based on PCA (PDDRP).In the secure$k$NN query phase: for one thing, EPPQ facilitates the index of the reduced-dimensional data by k-d tree. To enhance index efficiency, we innovatively propose plaintexts-based distance calculation definitions (PDC definitions) and construct an efficient variant of k-d tree (Ek-d tree), for the first time. For another, the Paillier homomorphic encryption (PHE) technique is leveraged to safeguard privacy when outsourcing Ek-d tree to untrusted cloud servers. Additionally, for ciphertexts-based distance calculations and comparisons, we design the Secure Precomputed Distance protocol (SPCD) and Secure Comparison protocol (SCOM). Finally, we creatively present the Privacy-Preserving$k$NN Query Algorithm based on Ek-d tree (PKQKT) for efficient and secure$k$NN query. Comprehensive security analysis demonstrates that the EPPQ scheme meets the required security properties under thehonest-but-curiousmodel. Extensive experiments confirms that EPPQ achieves high computational efficiency and query accuracy. Jing Wang 0239, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Menghong Guan |
IEEE Trans. Serv. Comput. | 2 |
| 2024 | Achieving Secure On-Orbit Comparison in LEO-Satellite-Enabled Offshore Wind Farm SurveillanceabstractThe low-Earth orbit (LEO) satellite constellation holds immense potential for offshore wind farm surveillance since it can provide all-day and all-weather monitoring capabilities facilitated by satellite collaboration. However, it faces significant challenges. First, limited downlink transmission bandwidth constrained by ground stations and constraint on-orbit resources necessitate selective data downloads, focusing only on differences between consecutive data sets. Second, a passively injected satellite in open space poses a risk of unauthorized data extraction from neighboring satellites. Third, onboard energy constraints limit the feasibility of computationally intensive cryptographic operations. To tackle these challenges for the first time, we propose a novel secure and efficient on-orbit comparison (SEOC) scheme. Our solution begins with introducing a lightweight matrix encryption-based secure inner product (MSIP) technique tailored for secure on-orbit comparison. We further enhance communication efficiency by integrating a Cuckoo filter to reduce costs, complementing a novel difference comparison tree (DCTree) structure to manage false positives. Through comprehensive security analysis, the$\textsf {MSIP}$technique achieves selective security, and the$\textsf {SEOC}$scheme is secure under the universally composable (UC) framework. At last, performance evaluations demonstrate the high efficiency of our approach in terms of computational costs and communication overheads, which adapts to the limited on-orbit resources. Qinglei Kong, Songnian Zhang, Bo Chen 0015, Sudong Xiao, Haiyong Bao, Jun Shao 0001 |
IEEE Internet Things J. | 6 |
| 2024 | PMRK: Privacy-Preserving Multidimensional Range Query With Keyword Search Over Spatial DataabstractWith the intensification of mobile devices, vast amounts of spatial data have been outsourced to cloud servers to provide query services. However, existing privacy-preserving schemes for spatial data only support spatial range queries and keyword searches and do not scale well in the scenario of multidimensional range queries. To address the above challenges, we propose a privacy-preserving scheme for the multidimensional range query with keyword search over spatial data (PMRK). Specifically, based on the encoding technique, we design data comparison and text matching algorithms, which can convert range queries and keyword searches into Hadamard-product-based operations. To improve the search efficiency, we index the spatial data by R-tree and propose the range intersection algorithm to implement the multidimensional range query with keyword search on R-tree simultaneously. Furthermore, the homomorphic encryption and matrix encryption techniques are leveraged to design the intersection predicate encryption (IPE) and subset predicate encryption (SPE) schemes, which preserve the privacy of range queries and keyword searches. Then, we propose our PMRK scheme, which not only supports efficient and secure multidimensional range queries and keyword searches at the same time but also preserves the single-dimensional privacy for multidimensional queries, and the path pattern privacy of the R-tree. In addition, the security of IPE and SPE is formally proved, and the security of PMRK is analyzed. In the experimental part, the feasibility and efficiency of PMRK are demonstrated by conducting experiments on real data sets. Xinqi Tu, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Hongning Dai |
IEEE Internet Things J. | 2 |
| 2024 | KMSQ: Efficient and Privacy-Preserving Keyword-Oriented Multidimensional Similarity Query in eHealthcareabstractExtensive research has been conducted on efficient and privacy-preserving similarity queries in eHealthcare, aiming at disease diagnosis based on similar patients while protecting the outsourced sensitive healthcare data. In this article, a new secure similarity query scheme named keyword-oriented multidimensional similarity query (KMSQ) is proposed for eHealthcare. Different from the state-of-the-art similar works, our proposed scheme enables users to query historical similar patients’ records based on their multidimensional physiological characteristics and symptom keywords (two data types) at the same time. Although the query can be securely performed sequentially by formerly proposed schemes, we carefully tailor a binary-decision-PB (BD-PB) tree to index the two data types simultaneously for efficient queries. Furthermore, inspired by the Hilbert exclusion condition and the properties of the polynomial function, an efficient query algorithm based on the BD-PB tree is designed in a filtration–verification manner, which further greatly improves the computational efficiency of queries, especially on the server side. To ensure secure query on untrusted clouds, the BD-PB tree-based KMSQ is protected through multiple encryption techniques. Specifically, function-hiding inner product preserving encryption (FHIPPE) is modified and combined with a lightweight matrix encryption technique to achieve secure data filtration. In addition, a symmetric homomorphic encryption (SHE) scheme is utilized to ensure secure verification that each candidate record in the filtration result satisfies the query requirements. Security analysis demonstrates the modified FHIPPE (MFHIPPE) and our proposed scheme meet the necessary security properties under the honest-but-curious model. Finally, extensive experiments are also conducted to show that KMSQ is computationally efficient. Zian Zhang, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Beibei Li 0002 |
IEEE Internet Things J. | 2 |
| 2024 | SAMFL: Secure Aggregation Mechanism for Federated Learning with Byzantine-robustness by functional encryption
Menghong Guan, Haiyong Bao, Zhiqiang Li 0007, Cheng Huang 0001, Hongning Dai |
J. Syst. Archit. | 2 |
| 2024 | A secure location management scheme in an LEO-satellite network with dual-mobility
Qinglei Kong, Maode Ma, Haiyong Bao |
Peer Peer Netw. Appl. | 5 |
| 2024 | Efficient and Privacy-Preserving Cloud-Assisted Two-Party Computation Scheme in Heterogeneous NetworksabstractPrevailing smart devices collect individual or industrial sensitive data for collaborative computation to provide convenient service in heterogeneous networks. Nowadays, protecting privacy and security is a significant issue and raises increasing concerns in academia and industry. But diverse smart devices are equipped with unequal resources and some devices with limited resources cannot afford expensive privacy-preserving computation. In this article, we propose a generic efficient and privacy-preserving cloud-assisted two-party computation scheme for smart devices in heterogeneous networks. We adopt the cloud server to assist the collaborative computation and reduce the overhead of smart devices. Besides, we apply preprocessing and online phases to guarantee different devices to operate with a lower burden online. What is more, the work is, to our best knowledge, the first to resist the malicious cloud server and computing parties simultaneously by adopting authenticated masked bits to strengthen the garbled circuit scheme. At the same time, our scheme can guarantee correctness and fairness, as shown in security analysis. The performance comparison result shows that this work is efficient and surpasses the previous best counterpart scheme while maintaining nearly identical computation cost. It outperforms in terms of total communication cost by 49% and total execution time by 32%, even though it takes extra and acceptable cost in the online phase for stronger security against the malicious server. Zhusen Liu, Haiyong Bao, Zhenfu Cao, Lu Zhou 0002, Zhe Liu 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2024 | Achieving Privacy-Preserving Trajectory Query in Geospatial Information Systems With Outsourced CloudabstractGeographic information system (GIS) enables operations for capturing, manipulating, analyzing, and displaying the spatial characteristics of objects on Earth's surface. As the objects in GISs are mostly location-dependent, various location privacy-preserving schemes are proposed to support the secure spatial query and analysis. However, existing location privacy-preserving mechanisms mainly focus on the$k$-nearest neighbor ($k$NN) queries and range queries and fail to consider the practical geographic implementation with quad-trees. We propose an efficient and privacy-preserving point-of-interest (POI) query scheme along the movement trajectory under the quad-tree setup in a two-server mode. Specifically, we first convert the secure identification of the target lowest-level tile into a series of private information retrieval (PIR) processes and securely derive the target POIs along the movement trajectory within the identified tile by constructing a linear polynomial passing through the origin and destination for secure distance comparison. Our scheme also supports the efficient loading of POIs contained in the adjacent tiles with privacy preservation. Security analysis demonstrates that ours can achieve the security goals of privacy preservation and confidentiality. We execute performance evaluations to show and validate the system efficiency, i.e., computational costs and communication overheads. Qinglei Kong, Songnian Zhang, Rongxing Lu, Haiyong Bao, Bo Chen 0015, Shiwu Xu |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | NLSP: A novel lattice-based secure primitive for privacy-preserving smart grid communicationsabstractSummary As the new generation of power scheme, smart grid is proposed to overcome the shortcomings of traditional systems, such as low efficiency and reliability. In this article, a novel lattice‐based secure primitive for privacy‐preserving smart grid communications is proposed, which has the remarkable characteristics, such as scalable multi‐dimensional fine‐grained power data structure and differential privacy security. First, combining with the lattice‐based data encryption technology, while effectively resisting quantum attacks, the method of simultaneous processing of multi‐dimensional data is innovated. Second, through combining the additive homomorphism of the lattice‐based cryptosystem and the Chinese remainder theorem, the data aggregation mechanism that can directly perform homomorphic operations on compressed ciphertext is constructed. Thanks to the above innovative design ideas, the proposed scheme not only significantly improves the efficiency of data communication and processing, greatly reduces the computational cost of the intermediate entity, but also realizes the data confidentiality and information privacy. Finally, observing the decentralized topology of communication nodes in the typical cyber‐physical system of smart grid, the localized differential privacy technology is leveraged to optimize and balance the utility, security, and efficiency of differential privacy. Extensive performance evaluations are conducted to illustrate that the proposed scheme outperforms the state‐of‐the‐art similar schemes in terms of computation complexity and communication cost. Haiyong Bao, Haibo Hong, Qinglei Kong, Haifeng Qian |
Concurr. Comput. Pract. Exp. | 1 |
| 2023 | Reinforcement learning-driven deep question generation with rich semantics
Menghong Guan, Subrota K. Mondal, Hongning Dai, Haiyong Bao |
Inf. Process. Manag. | 4 |
| 2022 | Non-homogeneous haze data synthesis based real-world image dehazing with enhancement-and-restoration fused CNNs
Shuangshuang Ye, Lideng Zhang, Haiyong Bao, Xun Wang 0007, Fanding Wu |
Comput. Graph. | 4 |
| 2022 | A verifiable privacy-preserving data collection scheme supporting multi-party computation in fog-based smart grid
Zhusen Liu, Zhenfu Cao, Xiaolei Dong, Haiyong Bao |
Frontiers Comput. Sci. | 5 |
| 2022 | BBNP: A Blockchain-Based Novel Paradigm for Fair and Secure Smart Grid CommunicationsabstractAs the future energy infrastructure, smart grid aims to overcome the disadvantages of traditional power grid, e.g., low efficiency and unstable service. However, the frequent collection and analysis of the user’s electricity data may bring various security and privacy threats. Besides, the traditional centralized data storage model in the smart grid is prone to the single point of failure. To address these challenges, in this article, for fair and secure smart grid communication, a blockchain-based novel paradigm, named BBNP, is proposed. Specifically, based on the pseudorandom function and auxiliary information generation and sharing technology, a lightweight data aggregation protocol is designed first to protect the user’s data privacy and ensure communication confidentiality. Then, a novel efficient authentication mechanism is proposed to generate and share session keys in a noninteractive way, which is leveraged for MAC authentication to achieve data integrity of the transmitted data. After that, based on the subjective logic reputation model, a blockchain node consensus mechanism is studied to efficiently store smart grid big data and effectively solve the single point failure problem. By constructing the long-term reputation model for consensus nodes (CNs) and integrating batch verification technology, the problems of CN fair selection and scalability of large-scale nodes are solved simultaneously. Finally, the performance evaluation indicates that BBNP outperforms the state-of-the-art similar schemes in computing complexity, communication cost, system availability, and fairness of block generation. Haiyong Bao, Binbin Ren, Beibei Li 0002, Qinglei Kong |
IEEE Internet Things J. | 1 |
| 2022 | EPMDA-FED: Efficient and Privacy-Preserving Multidimensional Data Aggregation Scheme With Fast Error Detection in Smart GridabstractSmart grids bring advantages of reliability and high efficiency by real-time communication technologies in contrast to the traditional grids. However, smart grids also raise concerns about privacy and security for the individual fine-grained information collection. In order to guarantee privacy and security in the grids, we propose an efficient and privacy-preserving multidimensional data aggregation scheme without a third trusted party and supporting fast error detection, named EPMDA-FED, in the article. First, we adopt a Chinese Remainder Theorem (CRT) to pack multidimensional data and encrypt the processed data using the keys generated by the negotiation among users and the control center (CC). Second, our scheme is efficient for encryption without high-cost additive homomorphic public-key encryption (PKE) scheme, such as the Paillier cryptosystem and supporting batch verification with fast error detection. Our proposed error detection algorithm is quite efficient with sublinear computational complexity. Besides, through security analysis, EPMDA-FED is semantically secure against collusion attack and the consistency of negotiated key, authenticity, and data integrity of the users’ reports are guaranteed. Finally, performance evaluation shows EPMDA-FED is more efficient than the existing competing approaches in terms of computational and communication overheads. Zhusen Liu, Zhenfu Cao, Xiaolei Dong, Tian Liu 0005, Haiyong Bao |
IEEE Internet Things J. | 6 |
| 2021 | A novel privacy preserving data aggregation scheme with data integrity and fault tolerance for smart grid communications
Haiyong Bao, Beibei Li 0002 |
Frontiers Comput. Sci. | 1 |
| 2021 | Smart and Practical Privacy-Preserving Data Aggregation for Fog-Based Smart GridsabstractWith the increasingly powerful and extensive deployment of edge devices, edge/fog computing enables customers to manage and analyze data locally, and extends computing power and data analysis applications to network edges. Meanwhile, as the next generation of the power grid, the smart grid can achieve the goal of efficiency, economy, security, reliability, use safety and environmental friendliness for the power grid. However, privacy and secure issues in fog-based smart grid communications are challenging. Without proper protection, customers’ privacy will be readily violated. This article presents a smart and practical Privacy-preserving Data Aggregation (PDA) scheme with smart pricing and packing method for fog-based smart grids, which achieves diversified tariffs, multifunctional statistics and efficiency. Especially, we first propose a smart PDA scheme with Smart Pricing (PDA-SP). With PDA-SP, the Control Center (CC) can compute more complex and higher-order aggregation statistics to provide various services, provide diversiform pricing strategies and choose a double-winning strategy. Subsequently, we put forward a practical PDA scheme with Packing Method (PDA-PM), which is able to reduce the size of encrypted data and improve performance in performing various secure computations. Moreover, we extend our original packing method and present a more useful packing method, which can handle general vectors with large entries. The security analysis shows that our proposed scheme is secure against many threats. The performance evaluation reveals that the computation and communication overheads of our proposed scheme are effectively reduced by employing the Somewhat Homomorphic Encryption (SHE), and our packing method can further significantly reduce these overheads. Fenghua Li 0001, Hongwei Li 0001, Rongxing Lu, Siqi Ren, Haiyong Bao, Jianhong Lin, Song Han 0006 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2020 | On Feasibility and Limitations of Detecting False Data Injection Attacks on Power Grid State Estimation Using D-FACTS DevicesabstractRecent studies have investigated the possibilities of proactively detecting the high-profile false data injection (FDI) attacks on power grid state estimation by using the distributed flexible ac transmission system (D-FACTS) devices, termed as proactive false data detection (PFDD) approach. However, the feasibility and limitations of such an approach have not been systematically studied in the existing literature. In this paper, we explore the feasibility and limitations of adopting the PFDD approach to thwart FDI attacks on power grid state estimation. Specifically, we thoroughly study the feasibility of using PFDD to detect FDI attacks by considering single-bus, uncoordinated multiple-bus, and coordinated multiple-bus FDI attacks, respectively. We prove that PFDD can detect all these three types of FDI attacks targeted on buses or super-buses with degrees larger than 1, if and only if the deployment of D-FACTS devices covers branches at least containing a spanning tree of the grid graph. The minimum efforts required for activating D-FACTS devices to detect each type of FDI attacks are, respectively, evaluated. In addition, we also discuss the limitations of this approach; it is strictly proved that PFDD is not able to detect FDI attacks targeted on buses or super-buses with degrees equalling 1. Beibei Li 0002, Gaoxi Xiao, Rongxing Lu, Ruilong Deng, Haiyong Bao |
IEEE Trans. Ind. Informatics | 5 |
| 2019 | A privacy-preserving sensory data sharing scheme in Internet of Vehicles
Qinglei Kong, Rongxing Lu, Maode Ma, Haiyong Bao |
Future Gener. Comput. Syst. | 4 |
| 2019 | Towards insider threats detection in smart grid communication systemsabstractIn today's communication systems, the most damaging security threats are not originating from the outsiders but from the trusted insiders – both malicious insiders and negligent insiders. Always endowed with high privileges, insiders are significantly prone to conduct acts that can cause catastrophic damages to the whole system either intentionally or unintentionally. Characterised by the full and rapid integration of information and communication technologies, smart grid – arguably the largest national critical engineering infrastructure – is suffering from a multitude of security threats initiated from both outsiders and insiders. Without security guarantee, the promising benefits of achieving an efficient, green, and reliable power grid would not be a success. In this study, the authors investigate the insider threats and summarise the existing threats detection solutions in smart grid communication systems. In addition, a novel hybrid insider threats modelling, analysis, and detection framework, which is based on stochastic Petri net and behaviour rule specifications, is proposed to contain insider threats in smart grid communication systems. Beibei Li 0002, Rongxing Lu, Gaoxi Xiao, Haiyong Bao, Ali A. Ghorbani 0001 |
IET Commun. | 4 |
| 2017 | A lightweight data aggregation scheme achieving privacy preservation and data integrity with differential privacy and fault tolerance
Haiyong Bao, Rongxing Lu |
Peer-to-Peer Netw. Appl. | 1 |
| 2016 | A lightweight privacy-preserving scheme with data integrity for smart grid communicationsabstractSummary Smart grid, deemed as the next generation of power grid, can efficiently monitor, control, and predicate energy generation and consumption. However, the frequent collection of users' consumption information in smart grid may reveal user's privacy, and the tampering of smart grid communication may also impair the data integrity, subsequently affecting the precise monitoring and controlling at the control center. In this paper, to address the aforementioned challenges, we propose a lightweight data report scheme for smart grid communications, which can achieve privacy preservation and data integrity simultaneously. Specifically, an efficient pseudonym identity‐based privacy‐preserving report approach is proposed for the control center to obtain the fine‐grained usage data of all the users while protecting user's privacy. An online/off‐line hash tree‐based mechanism is also designed to check and assure data integrity of communications. Because of the shifting of most time‐consuming computations to off‐line phase, the online process is very fast and efficient by performing merely the lightweight bottom‐up hash tree verifications to check all users' data integrity concurrently. Furthermore, a topology‐independent data report architecture is also structured, which is adaptable for dynamic residential users to spontaneously form clusters and efficiently report data in flocks. Extensive performance evaluation demonstrates that the proposed scheme can achieve less communication overhead and dramatically reduce computational cost in comparison with the existing schemes. Copyright © 2015 John Wiley & Sons, Ltd. Haiyong Bao |
Concurr. Comput. Pract. Exp. | 1 |
| 2016 | Efficient and privacy-preserving skyline computation framework across domains
Ximeng Liu, Rongxing Lu, Jianfeng Ma 0001, Haiyong Bao |
Future Gener. Comput. Syst. | 5 |
| 2016 | BLITHE: Behavior Rule-Based Insider Threat Detection for Smart GridabstractIn this paper, we propose a behavior rule-based methodology for insider threat (BLITHE) detection of data monitor devices in smart grid, where the continuity and accuracy of operations are of vital importance. Based on the dc power flow model and state estimation model, three behavior rules are extracted to depict the behavior norms of each device, such that a device (trustee) that is being monitored on its behavior can be easily checked on the deviation from the behavior specification. Specifically, a rule-weight and compliance-distance-based grading strategy is designed, which greatly improves the effectiveness of the traditional grading strategy for evaluation of trustees. The statistical property, i.e., the mathematical expectation of compliance degree of each trustee, is particularly analyzed from both theoretical and practical perspectives, which achieves satisfactory tradeoff between detection accuracy and false alarms to detect more sophisticated and hidden attackers. In addition, based on real data run in POWER WORLD for IEEE benchmark power systems, and through comparative analysis, we demonstrate that BLITHE outperforms the state of arts for detecting abnormal behaviors in pervasive smart grid applications. Haiyong Bao, Rongxing Lu, Beibei Li 0002, Ruilong Deng |
IEEE Internet Things J. | 1 |
| 2016 | Comment on "Privacy-Enhanced Data Aggregation Scheme Against Internal Attackers in Smart Grid"abstractQuite recently, Fanet al.(IEEE Trans. Ind. Informat., vol. 10, no. 1, pp. 666–675, 2014) proposed a new data aggregation scheme for smart grid communications, and claimed that it can achieve not only user’s privacy-preservation, but also data integrity requirement. However, in this paper, we show that Fanet al.’s scheme has a serious security flaw and cannot meet data integrity requirement at all. Specifically, by observing the user registration procedure in Fanet al.’s scheme, we find that each user’s private key can be easily derived from the information published by the aggregator. Then, with the derived private key, an attacker can inject polluted data to user’s real data without being detected. As a result, data integrity will be completely violated. We hope that with our comment, similar mistakes can be avoided in future design of privacy-preserving data aggregation with data integrity protection. Haiyong Bao, Rongxing Lu |
IEEE Trans. Ind. Informatics | 1 |
| 2015 | DDPFT: Secure data aggregation scheme with differential privacy and fault toleranceabstractPrivacy-preserving data aggregation has been widely researched to meet the requirement of timely monitoring electricity consumption of users while protecting individual's data privacy in smart grid communications. In this paper, we propose a new secure data aggregation scheme, named DDPFT, for achieving differential privacy and fault tolerance simultaneously. Specifically, by introducing auxiliary ciphertexts subtly, a novel distributed approach for fault tolerance of data aggregation is put forward to be able to aggregate the functioning smart meter measurements flexibly and efficiently. Furthermore, DDPFT also achieves a good trade-off of accuracy and security of differential privacy for arbitrary number of malfunctioning smart meters. Moreover, through decentralizing the computational overhead and the power of the hub-like entity of the gateway, the security of our proposed scheme is enhanced and the efficiency is improved significantly. Extensive performance evaluations are conducted to illustrate that DDPFT outperforms the state-of-the-art data aggregation schemes in terms of computation complexity, communication cost, robustness of fault tolerance, and utility of differential privacy. Haiyong Bao, Rongxing Lu |
ICC | 1 |
| 2015 | A New Differentially Private Data Aggregation With Fault Tolerance for Smart Grid CommunicationsabstractPrivacy-preserving data aggregation has been widely studied to meet the requirement of timely monitoring measurements of users while protecting individual's privacy in smart grid communications. In this paper, a new secure data aggregation scheme, named differentially private data aggregation with fault tolerance (DPAFT), is proposed, which can achieve differential privacy and fault tolerance simultaneously. Specifically, inspired by the idea of Diffie-Hellman key exchange protocol, an artful constraint relation is constructed for data aggregation. With this novel constraint, DPAFT can support fault tolerance of malfunctioning smart meters efficiently and flexibly. In addition, DPAFT is also enhanced to resist against differential attacks, which are suffered in most of the existing data aggregation schemes. By improving the basic Boneh-Goh-Nissim cryptosystem to be more applicable to the practical scenarios, DPAFT can resist much stronger adversaries, i.e., user's privacy can be protected in the honest-but-curious model. Extensive performance evaluations are further conducted to illustrate that DPAFT outperforms the state-of-the-art data aggregation schemes in terms of storage cost, computation complexity, utility of differential privacy, robustness of fault tolerance, and the efficiency of user addition and removal. Haiyong Bao, Rongxing Lu |
IEEE Internet Things J. | 1 |
| 2006 | Identity-Based Threshold Proxy Signature Scheme with Known Signers
Haiyong Bao, Zhenfu Cao, Shengbao Wang |
TAMC | 1 |
| 2005 | On the Security of a Group Signcryption Scheme from Distributed Signcryption Scheme
Haiyong Bao, Zhenfu Cao, Haifeng Qian |
CANS | 1 |
| 2005 | Remarks on Wu-Hsu's threshold signature scheme using self-certified public keys
Haiyong Bao, Zhenfu Cao, Shengbao Wang |
J. Syst. Softw. | 1 |