VLDB 2026 Research / reviewers in the wild / expert
Gaopan Hou
dblp:294/5633
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-6043-4167ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Security-Driven SFC Deployment and Migration in Dynamic SAGIN Using Deception and Moving Target DefenseabstractAs the mainstream architecture for 6G networks, the Space-Air-Ground Integrated Network (SAGIN) faces dual challenges of security threats introduced by Network Function Virtualization and inherent topology dynamics, necessitating a secure and flexible Service Function Chain (SFC) deployment paradigm. This paper proposes a novel SFC security framework integrating Deception Defense (DD) and Moving Target Defense (MTD). A security assessment model is introduced to quantify virtualization risks, complemented by a DD-driven deployment strategy that incorporates security awareness and load balancing to enhance attack obfuscation. Furthermore, to mitigate the impact of topology dynamics, a link-stability-aware migration algorithm is designed with MTD, effectively balancing security and service continuity. Extensive simulations demonstrate that compared to conventional methods, the framework improves SFC security by approximately 102%, optimizes network load balancing by 23%, and reduces migration frequency by 31%, thereby ensuring service stability in highly dynamic scenarios. This work effectively bridges the critical gap between proactive security enforcement and adaptive resource orchestration in SAGIN environments. Changsong Li, Hao Wu 0005, Gaopan Hou |
IEEE Internet Things J. | 4 |
| 2026 | Deceptive VM Deployment Strategy Based on Deep Reinforcement Learning Against Co-Resident AttacksabstractWith the development and popularization of virtualization technology, it offers efficient, flexible services in cloud computing, data centers, etc. However, the sharing of underlying physical devices makes the isolation between different virtual machines (VMs) relatively fragile, leading to new security challenges. Co-resident attack is one of the most representative types. In order to facilitate the construction of side channels to achieve sensitive data theft and other malicious operations, attackers try to co-locate their VMs with target VMs on the same physical device. This paper proposes a VM placement method for virtualization cloud platforms to mitigate the risks posed by co-resident attacks. This study model the VM placement process in the virtualization cloud platform as a Markov Decision Process (MDP) and construct an objective function to minimize co-resident attacks under various constraints. Furthermore, it is believe that after the co-residence occurs, it is equally important to prevent attackers from constructing side channels against the co-resident targets. Therefore, the concept of deceptive defense is introduced to mislead attackers. In addition, this study introduces reinforcement learning and designs a deceptive VM deployment strategy generation method based on PPO (DD-PPO), considering platform security, load balance, and power consumption. Finally, CloudSim is used to build the simulation environment, and the performance of the proposed algorithm is evaluated through experiments. Simulation results show that the proposed algorithm effectively mitigates the threats of co-resident attacks compared to baselines. Changsong Li, Hao Wu 0005, Gaopan Hou, Zhibin Zheng |
IEEE Internet Things J. | 4 |
| 2026 | PPCDA: A Privacy-Preserving Cross-Domain Authentication Scheme for Vehicular PlatoonsabstractThe rapid advancement of intelligent transportation systems has significantly improved vehicular networks, particularly in applications such as vehicular platoons, which enhance fuel efficiency, road capacity, and traffic safety. However, vehicular platoons require frequent cross-domain communication across different administrative jurisdictions, which poses significant challenges to cross-domain authentication and privacy preservation. Existing cross-domain authentication schemes often suffer from high computation overhead, insufficient privacy protection, and limited support for dynamic platoon membership, making them difficult to scale to large-scale and highly dynamic cross-domain vehicular platoon scenarios. To overcome these challenges, in this paper, we propose a novel privacy-preserving cross-domain authentication (PPCDA) scheme for vehicular platoons. The PPCDA scheme ensures both vehicle identity legitimacy and message integrity, while preserving privacy for vehicles. Additionally, we introduce a batch authentication mechanism to process multiple cross-domain requests from various vehicular platoons simultaneously, alongside a scalable dynamic authentication mechanism to accommodate the dynamic nature of vehicular platooning. Compared with existing cross-domain authentication schemes, the proposed PPCDA scheme achieves improved security and authentication efficiency for vehicular platoons, with average reductions of 56.4% in authentication latency and 8.8% in communication overhead, which makes it particularly suitable for large-scale and dynamic cross-domain vehicular platoon scenarios. Nuo Xu 0007, Zhiquan Liu 0001, Jian Weng 0001, Gaopan Hou, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Cross-Cloud Associated Multireplica Auditing for Lightweight Devices in the IoTabstractCloud storage has become prevalent in Internet of Things (IoT) systems, attributed to its robust storage capabilities and user convenience. However, the cloud-based storage model, which separates data ownership from management, introduces integrity challenges due to the vulnerability of data to tampering. To address the risk of data loss and ensure recoverability, the implementation of multiple replicas is a common strategy. Nonetheless, traditional multireplica auditing schemes are not well suited for IoT environments that employ lightweight devices with limited computational capabilities. In response to the aforementioned challenges, we propose a novel multireplica auditing scheme named CCMR, aimed at alleviating the heavy computation cost on the device side. Our scheme leverages an efficient aggregated multisignature algorithm, offloading computationally intensive tasks associated with data tags from lightweight devices to cloud service providers (CSPs) equipped with advanced computational power. The innovative cross-cloud multireplica hash tree structure, named CC-MHT, facilitates the secure and efficient verification of data block structures and ensures consistency of replicas across multicloud environments. Furthermore, by utilizing blockchain as a public random source, a robust challenge-response protocol is established to guard against potential audit failures that could arise from collusion between the third-party auditor and CSPs. The experimental results indicate the high efficiency of the proposed scheme in terms of computation cost. Gaopan Hou, Zhiquan Liu 0001, Yinbin Miao, Jianfeng Ma 0001, Guisheng Liao |
IEEE Internet Things J. | 1 |
| 2025 | SCRM: Secure and Controllable Similarity Retrieval in Multiuser SettingsabstractCloud computing has become an essential paradigm for facilitating large-scale and privacy-preserving encrypted image retrieval in Internet of Things (IoT) environments. However, existing encrypted image retrieval schemes face challenges in balancing retrieval efficiency and data security, which hinders their practical adoption. On one hand, retrieval-efficient schemes based on secure k-Nearest Neighbor (kNN) are prone to known-plaintext attacks; on the other hand, highly secure schemes based on homomorphic encryption often suffer from excessive computational and storage overhead. Furthermore, supporting multi-user environments and enforcing fine-grained access control over query users are critical challenges in IoT-based retrieval systems. To tackle these issues, we propose a Secure and Controllable similarity Retrieval scheme in Multi-user settings (SCRM), which achieves a practical trade-off between efficiency and security while enabling multi-user management. First, we design an efficient and privacy-preserving similarity computation method that is resilient against known-plaintext attacks. Second, we introduce a key conversion protocol that enables similarity retrieval in multi-user settings without requiring key sharing. Third, we integrate attribute-based encryption to enforce fine-grained access control and trace query users who may leak decryption keys. A correctness analysis confirms that SCRM ensures accurate similarity retrieval while supporting access control. Furthermore, a formal security analysis demonstrates that SCRM effectively protects data privacy against known-plaintext attacks. Finally, extensive experiments on real-world image dataset validate the efficiency and effectiveness of SCRM. Yingying Li 0001, Feng Li 0041, Gaopan Hou, Yu Guan 0003, Zhiquan Liu 0001, Qi Xie 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Secure and Traceable Multikey Image Retrieval in Cloud-Assisted Internet of ThingsabstractThe privacy-preserving image retrieval technology permits users to retrieve outsourced images in a secure manner in cloud-assisted Internet of Things (IoT) environment. However, most of the existing schemes still have some blemishes, such as low performance, shared key, and untraceable malicious users. To this end, we present a secure and traceable multikey image retrieval, named as secure and traceable multikey image retrieval (STMIR). First, we design a novel privacy-preserving Mahalanobis distance comparison method (PPMDC) based on the learning with errors technology and Mahalanobis distance. And STMIR extracts image features utilizing the convolutional neural network (CNN) model to improve retrieval accuracy. Then, STMIR employs extracted image features, PPMDC and key conversion technology to achieve secure image retrieval that supports the multikey setting. Meanwhile, STMIR uses encrypted image watermarking technology to protect the content of images and track malicious users who redistribute images. Formal security analysis shows that STMIR can resist both ciphertext only attack and known background attack, and extensive experiments in the real-world image data sets demonstrate effectiveness of STMIR in terms of retrieval accuracy, retrieval efficiency, and traceability to malicious query users. Zhiquan Liu 0001, Gaopan Hou |
IEEE Internet Things J. | 7 |
| 2021 | Audit Outsourced Data in Internet of ThingsabstractWith the increase in network transmission rates, the Internet of Things (IoT) has gradually become a trend. Users can upload the data generated by the device to the cloud database to save local storage space, thereby reducing local storage costs. Because uploading data to the cloud loses physical control of the data, an audit is required. Traditional audit protocols are not completely suitable for lightweight devices in the IoT. This paper proposes a new type of audit protocol suitable for lightweight devices with weak computing power. This protocol transfers part of the computation of data tags to a cloud storage provider (CSP) with strong computing power, thereby reducing the introduction of computing entities. Our scheme supports the dynamic operation of data and guarantees the effectiveness of challenge response by blockchain. Compared with existing schemes, our scheme is more secure and effective. Gaopan Hou, Jianfeng Ma 0001 |
Secur. Commun. Networks | 1 |