Zeshun Shi

dblp:246/7190 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
8since 2021 · last 2024
0000-0001-9163-8023ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2024 A Secure and Trustworthy Biometric Data Ecosystem for Cross-border Suspect Identification
abstract
This paper introduces the Biometrics Data Space framework, which is a secure ecosystem built on Data Spaces technology and it is designed to address the challenges of suspect identification during cross-border crime investigation. Apart from Data Spaces technology, the proposed framework innovates by leveraging also Privacy Enhancing Technologies (PETs) and blockchain to enable secure, trustworthy, and sovereign data exchange between Law Enforcement Agencies (LEAs) across borders. Specifically, it utilizes advanced PETs, including Large-Scale Biometric Data Indexing based on deep hashing techniques and Homomorphic Encryption to allow for suspect identification without disclosing sensitive information of personal biometric data. Thus, it enables LEAs to securely compare and exchange encrypted sensitive biometric data, including facial images, fingerprints and voiceprints, while maintaining data privacy and data sovereignty. LEAs define the usage rules for the biometic data they own and these rules are enforced to and respected by the other LEAs participating in the Biometrics Data Space. The proposed architecture is designed to be scalable, allowing the incorporation of additional biometric modalitiies and the easy expansion and integration with new participant LEAs.
Katerina Kyriakou, Apostolos Apostolaras, Polychronis Velentzas, Georgios Benos, Konstantinos Koutsoukos, Chrysostomos Symvoulidis, Kaitai Liang, Zeshun Shi, Asterios Leonidis, Kyriaki Miniadou, Eleni Veroni, Spyridon Evangelatos, Georgios Th. Papadopoulos, Thanasis Korakis
IEEE Big Data8
2024 Inject Less, Recover More: Unlocking the Potential of Document Recovery in Injection Attacks Against SSE
abstract
Searchable symmetric encryption has been vulnerable to inference attacks that rely on uniqueness in leakage patterns. However, many keywords in datasets lack distinctive leakage patterns, limiting the effectiveness of such attacks. The file injection attacks, initially proposed by Cash et al. (CCS 2015), have shown impressive performance with 100% accuracy and no prior knowledge requirement. Nevertheless, this attack fails to recover queries with underlying keywords not present in the injected files. To address these limitations, our research introduces a novel attack strategy called LEAP-Hierarchical Fusion Attack (LHFA) that combines the strengths of both file injection attacks and inference attacks. Before initiating keyword injection, we introduce a new approach for inert/active keyword selection. In the phase of selecting injected keywords, we focus on keywords without unique leakage patterns and recover them, leveraging their presence for document recovery. Our goal is to achieve an amplified effect in query recovery. We demonstrate a minimum query recovery rate of 1.3 queries per injected keyword with a 10% data leakage of a real-life dataset, and initiate further research to overcome challenges associated with non-distinctive keywords.
Manning Zhang, Zeshun Shi, Huanhuan Chen 0003, Kaitai Liang
CSF2
2024 Similar Data is Powerful: Enhancing Inference Attacks on SSE with Volume Leakages
Björn Ho, Huanhuan Chen 0003, Zeshun Shi, Kaitai Liang
ESORICS (4)3
2022 A Bayesian game-enhanced auction model for federated cloud services using blockchain
abstract
Industrial applications often require federated cloud services from multiple providers to improve reliability and flexibility. Traditional selection methods through auctions usually involve a centralized auctioneer to coordinate the auction procedure. Blockchain and smart contracts provide a decentralized mechanism to automate the cloud auction process; however, existing solutions fail in the selection of the most suitable providers and the violation detection of the signed auction agreements, which are also known as service-level agreements (SLAs). To tackle these problems, we propose an integrated auction model using Bayesian game theory and blockchain techniques. The proposed model is enhanced with two Bayesian Nash Equilibriums (BNEs); the first BNE enables the selection of cost-effective providers to construct the federated cloud services, while the second BNE ensures consistent and trustworthy monitoring of federated SLAs. Moreover, a timed message submission (TMS) algorithm is proposed to protect the auction privacy during the message submission phase. This paper validates the equilibrium results of two BNEs and implements the proposed model on the Ethereum blockchain. The analytical and experimental results demonstrate the feasibility, trustworthiness, and cost-effectiveness of our model.
Zeshun Shi, Huan Zhou 0006, Cees T. A. M. de Laat, Zhiming Zhao
Future Gener. Comput. Syst.1
2022 Featured Cover
abstract
The cover image is based on the Research Article Notebook-as-a-VRE (NaaVRE): From private notebooks to a collaborative cloud virtual research environment by Zhiming Zhao et al., https://doi.org/10.1002/spe.3098.
Zhiming Zhao, Spiros Koulouzis, Riccardo Bianchi, Siamak Farshidi, Zeshun Shi, Ruyue Xin, Yuandou Wang, Yifang Shi 0002, Joris Timmermans, W. Daniel Kissling
Softw. Pract. Exp.5
2022 Notebook-as-a-VRE (NaaVRE): From private notebooks to a collaborative cloud virtual research environment
abstract
Abstract Virtual research environments (VREs) provide user‐centric support in the lifecycle of research activities, for example, discovering and accessing research assets or composing and executing application workflows. A typical VRE is often implemented as an integrated environment, including a catalog of research assets, a workflow management system, a data management framework, and tools for enabling user collaboration. In contrast, notebook environments like Jupyter allow researchers to rapidly prototype scientific code and share their experiments as online accessible notebooks. Jupyter can support several popular languages used by data scientists, such as Python, R, and Julia. However, such notebook environments do not have seamless support for running heavy computations on remote infrastructure or finding and accessing collaborative software code inside notebooks. This article investigates the gap between a notebook environment and a VRE and proposes an embedded VRE solution for the Jupyter environment called Notebook‐as‐a‐VRE (NaaVRE). The NaaVRE solution provides functional components via a component marketplace and allows users to create a customized VRE on top of the Jupyter environment. From the VRE, a user can search research assets (data, software, and algorithms), compose workflows, manage the lifecycle of an experiment, and share the results among users in the community. We demonstrate how such a solution can enhance a legacy workflow that uses Light Detection and Ranging (LiDAR) data from country‐wide airborne laser scanning surveys for deriving geospatial data products of ecosystem structure at high resolution over broad spatial extents. This enables users to scale out the processing of multi‐terabyte LiDAR point clouds for ecological applications to more data sources in a distributed cloud environment. Similar applications could be developed for workflows producing other essential biodiversity variables.
Zhiming Zhao, Spiros Koulouzis, Riccardo Bianchi, Siamak Farshidi, Zeshun Shi, Ruyue Xin, Yuandou Wang, Yifang Shi 0002, Joris Timmermans, W. Daniel Kissling
Softw. Pract. Exp.5
2021 Distributed service-level agreement management with smart contracts and blockchain
abstract
Summary The current cloud market is dominated by a few providers, which offer cloud services in a take‐it‐or‐leave‐it manner. However, the dynamism and uncertainty of cloud environments may require the change over time of both application requirements and service capabilities. The current service‐level agreement (SLA) management solutions cannot easily guarantee a trustworthy, distributed SLA adaptation due to the centralized authority of the cloud provider who could also misbehave to pursue individual goals. To address the above issues, we propose a novel SLA management framework, which facilitates the specification and enforcement of dynamic SLAs that enable one to describe how, and under which conditions, the offered service level can change over time. The proposed framework relies on a two‐level blockchain architecture. At the first level, the smart SLA is transformed into a smart contract that dynamically guides service provisioning. At the second level, a permissioned blockchain is built through a federation of monitoring entities to generate objective measurements for the smart SLA/contract assessment. The scalability of this permissioned blockchain is also thoroughly evaluated. The proposed framework enables creating open distributed clouds, which offer manageable and dynamic services, and facilitates cost reduction for cloud consumers, while it increases flexibility in resource management and trust in the offered cloud services.
Rafael Brundo Uriarte, Huan Zhou 0006, Kyriakos Kritikos, Zeshun Shi, Zhiming Zhao, Rocco De Nicola
Concurr. Comput. Pract. Exp.4
2021 Building a blockchain-based decentralized ecosystem for cloud and edge computing: an ALLSTAR approach and empirical study
Huan Zhou 0006, Zeshun Shi, Xue Ouyang 0003, Zhiming Zhao
Peer-to-Peer Netw. Appl.2
2019 An Automated Customization and Performance Profiling Framework for Permissioned Blockchains in a Virtualized Environment
abstract
The permissioned blockchains have demonstrated their potential to provide trustworthy and security services in various industrial scenarios, especially in the Cloud-based virtualized environments. To customize the configuration of a blockchain application, an operator needs the performance characteristics of a blockchain network in different Cloud environments. However, manually profiling the performance characteristics of a blockchain network is very time-consuming. Therefore, in this paper, we propose a BlockchaIn-infRAstructure CustomIzation and Auto-profiLing (BIRACIAL) framework to automate the whole process of blockchain deployment and performance profiling. Based on the profile and performance requirements of a blockchain application, the framework aims to plan the virtual infrastructure for permissioned blockchain, to automate the provision of the required infrastructure, to deploy the customized permissioned blockchain, and to enable continuous monitoring of blockchain performance. Our evaluation results show that the proposed framework can achieve automated deployment of different permissioned blockchain networks under certain overheads. The performance profiling results can be used to compare and select the appropriate blockchain platforms and consensus algorithms.
Zeshun Shi, Huan Zhou 0006, Jayachander Surbiryala, Yang Hu 0013, Cees T. A. M. de Laat, Zhiming Zhao
CloudCom1
2019 Teaching DevOps and Cloud Based Software Engineering in University Curricula
abstract
This paper presents recommendations on the design and pilot implementation of the DevOps and Cloud based Software Development curricula for Computer Science and Software Engineering masters. The central part of proposed approach is the Body of Knowledge in the DevOps technologies for Software Engineering (DevOpsSE BoK) that defines a set Knowledge Areas and Knowledge Units required for SE professionals to work efficiently as DevOps engineer or application developer. Defining DevOpsSE-BoK provides a basis for defining required professional competences and skills and allows consistent curricula structuring and profiling. The paper also reports on the experience of the first course run on 2018/2019 academic year at the University of Amsterdam. The paper presents the structure of the course and explains what instructional methodologies have been used for course development, such as project based learning that facilitates the students' team based skills both in mastering Agile development process and skills sharing. The paper provides a short summary of the generally used DevOps definitions, concepts, models and tools, specifically focusing on the cloud based DevOps tools for software development, deployment and operation that allows the main DevOps principle of continuous development and continuous improvement which are critical for modern agile data driven companies.
Yuri Demchenko, Zhiming Zhao, Jayachander Surbiryala, Spiros Koulouzis, Zeshun Shi, Jelena Gordiyenko
eScience5
2019 Operating Permissioned Blockchain in Clouds: A Performance Study of Hyperledger Sawtooth
abstract
With ever more IoT (Internet of Things) and bigdata applications, the emerging blockchain techniques provide fundamental supports to credibly track the transactions of digital assets. Public blockchains, e.g., bitcoin, are often energy-consuming and low efficient. Therefore, an empirical study of operating permissioned blockchains in clouds is urgently needed. In this paper, we study the performance of Sawtooth, a well-known permissioned blockchain platforms from Hyperledger, in cloud environments. Our results provide insights for blockchain operators to optimize the performance of Sawtooth through adjusting the two configuration parameters, i.e., Scheduler and Maximum Batches Per Block. Our approach can be used to test other blockchain platforms.
Zeshun Shi, Huan Zhou 0006, Yang Hu 0013, Jayachander Surbiryala, Cees T. A. M. de Laat, Zhiming Zhao
ISPDC1