VLDB 2026 Research / reviewers in the wild / expert
Jinbo Xiong
dblp:31/7623
· DBLP profile ↗
87ranked-venue papers
10as first author
65since 2021 · last 2026
0000-0001-9985-1953ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 36 · 5 first-author · 27 since 2021Security and privacy · 16 · 12 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 2 first-author · 8 since 2021Systems, architecture and hardware · 10 · 3 first-author · 6 since 2021Databases, data management, data science and information retrieval · 6 · 6 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Optimal adversarial perturbation guided membership inference: Gradient-sensitive white-box and hybrid zeroth-order black-box strategies
Zehua Ding, Youliang Tian, Guorong Wang, Jinbo Xiong, Jianfeng Ma 0001 |
Expert Syst. Appl. | 4 |
| 2026 | PFNet: A face soft biometric privacy enhancement method based on attribute disentanglement and frequency compensation
Biao Jin 0004, Haowei Huang, Jinbo Xiong, Xuan Li 0007, Xing Wang 0005, Li Lin 0001 |
Expert Syst. Appl. | 4 |
| 2026 | Complex network evolution with node strategies driven by information entropy
Youliang Tian, Jinbo Xiong, Mengqian Li, Kun Niu, Die Zhou, Jianfeng Ma 0001 |
Inf. Sci. | 3 |
| 2026 | Security vulnerabilities and enhancement of a dynamic auditing scheme for regenerating code-based storage in cloud-fog-assisted IIoT
Guangjun Liu 0002, Jinbo Xiong, Ximeng Liu, Chenghu Ke, Zengfa Dou |
J. Parallel Distributed Comput. | 2 |
| 2026 | pDFL: Knowledge-aware adaptive aggregation for personalized decentralized federated learning
Shuai Wang 0056, Youliang Tian, Axin Xiang, Jinbo Xiong, Jianfeng Ma 0001 |
Knowl. Based Syst. | 4 |
| 2026 | Nagisa: A reversible privacy preservation scheme against facial soft-biometric attributes recognition
Biao Jin 0004, Jinbo Xiong, Xing Wang 0005, Zenghai Lu |
Pattern Recognit. | 4 |
| 2026 | PriDFL: Computation-Optimized Secure Aggregation With Byzantine-Resilient in Decentralized Federated LearningabstractPrivacy-preserving federated learning (PPFL) is a strong-privacy distributed learning paradigm, which typically employs secure aggregation (SA) protocols to protect the aggregation results of federated learning. However, the high computational cost of existing SA protocols is difficult to generalize to decentralized federated learning (DFL) with the large number of clients and fails to defend against model poisoning attacks launched by Byzantine adversaries. In this paper, we propose an efficient computational SA protocol compatible with DFL, referred to as PriDFL, and address the issue of Byzantine-robust aggregation. Specifically, we design an advanced secret-sharing protocol based on number-theoretic transformations to reduce the computational complexity from$O(n^{2})$to$\mathcal {O}(n\log n)$during data sharing. We employ a single-mask approach to provide lightweight gradient privacy protection for DFL. To mitigate the impact of poisoned gradients on model convergence, we develop a Byzantine resilience criterion grounded in model cross-updating. The proposed criterion efficiently detects poisoned gradients and non-independent identically distributed (non-IID) data with local computation. Security analysis shows that PriDFL satisfies the security requirements in an honest but curious setting. We evaluate PriDFL on typical datasets (e.g., MNIST and CIFAR-10) and the results show that PriDFL is computation-communication efficient and Byzantine resilient. In particular, PriDFL optimizes the computational efficiency by 6-10× compared to the well-utilized SA protocols while supporting Byzantine robustness. Shuai Wang 0056, Youliang Tian, Jinbo Xiong, Renwan Bi, Jianfeng Ma 0001, Yan Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Privacy-Preserving Multi-Modal Object Fusion for Connected Autonomous Vehicles: Resilience Against Malicious Third-Party AttacksabstractConnected autonomous vehicles (CAVs) utilize multi-modal sensors, such as LiDAR and high-definition cameras, to collect diverse types of sensing data. Fusing object detection information from these two modalities facilitates more accurate environmental perception. In this context, lightweight secret sharing techniques are employed to protect information privacy, enabling further calculation while effectively alleviating the computational resource constraints of CAVs. Meanwhile, such techniques require an additional third-party to generate some necessary random numbers. Addressing the challenges of privacy disclosure of multi-modal object information and the reliability of random numbers, we propose a malicious third-party-resistant privacy-preserving multi-modal object fusion model, termed MPOF. First, we develop a series of secure computation protocols that do not rely on time-consuming cryptographic primitives, including secure multiplication, secure sharing conversion, and secure comparison. Leveraging the idea of sacrificial verification, we can effectively detect malicious behavior by the third-party during the random number generation process. Second, we construct a secure object bounding-box matching module based on arithmetic secret sharing (ASS), enabling similarity calculation and matching of bounding-boxes between point cloud and image modalities. Additionally, we design a secure object score fusion module that achieves fusion and updating through secure implementations of convolution, ReLU, and Maxout operations. Detailed theoretical analysis and experimental results demonstrate that, compared to secure computation protocols using homomorphic encryption for random number generation, the proposed protocols reduce computational overhead by five orders of magnitude. Furthermore, the MPOF model constructed by integrating these protocols is secure, accurate, and efficient. Renwan Bi, Jinbo Xiong, Xu Yang 0002, Yuanyuan Zhang 0009, Zhiqiang Ruan, Xun Yi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Secure Rational Delegation Federated LearningabstractFederated learning (FL) allows multiple distributed clients with local datasets to train a global model collaboratively. Due to the potential privacy risk of the training process, differential privacy (DP) is introduced into FL to protect clients’ sensitive information by perturbing the model updates. However, the probability density function of the Laplace mechanism has a long-tail effect, which may generate large noise to induce the model to deviate from the normal result. Moreover, as the cloud is not fully trusted, there is no guarantee that the server follows the aggregation protocol correctly. To address these issues, in this paper, we propose a secure rational delegation FL scheme, namely SRDFL, and analyze its protection and convergence performance. Specifically, we first utilize the zero-determinant strategy to construct a FL rational model. It delegates tasks to multiple servers and encourages them to perform correct aggregation. Then, we design a bounded DP protection mechanism to achieve a fixed universe of perturbation outputs in a threshold-constrained manner. Finally, based on Shamir’s secret sharing, we propose a trusted verification algorithm of DP to validate servers for correct aggregation. Detailed theoretical analysis and extensive performance evaluations demonstrate that our proposed scheme is effective. Compared to existing works, SRDFL is able to improve 2.72% - 47.92% model accuracy. Mengqian Li, Youliang Tian, Jinbo Xiong, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Enhancing Federated Learning in Edge Computing With Secure Aggregation and Dynamic VerificationabstractFederated learning (FL) enables multiple clients to exchange gradients to facilitate collaborative training in edge computing without transferring private data to the cloud server. However, the malicious server may disrupt the model training process by obtaining gradients to infer client information or faking validation results. Considering these threats, we construct a dynamic, secure, and verifiable FL scheme, named DSVFL. Specifically, we propose the fine-grained top-$k$gradient selection algorithm to accelerate model convergence, which can improve model accuracy by up to 49.14%. Furthermore, we propose a single-cloud secure aggregation protocol that guarantees the server cannot access the real model parameters. We also design a trusted verification algorithm to validate the server's aggregation results while resisting collusion between the server and clients. For federation dynamics, we adopt the Shamir's secret sharing in both the aggregation and verification phases, which enables the correct aggregation and decryption of ciphertexts and the independent verification of client signatures, even in cases of client dropouts. Rigorous theoretical analysis demonstrates that DSVFL can protect data privacy and ensure correct training results. Experimental results indicate that DSVFL can reduce clients' computational cost by 48%-63% and communication overhead by 33%-49% compared with existing solutions. Mengqian Li, Youliang Tian, Jinbo Xiong, Xinhua Cui, Jianfeng Ma 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Enriching Complex Event Forecasting with Nested Patterns
Yuhui Chen, Ruihong Huang, Jinbo Xiong, Li Lin 0001, Jiayin Lin |
DASFAA (2) | 3 |
| 2025 | BDT-RVOC: Block Data Truncation for Verifiable and Private Multi-Cloud ComputationabstractReplication-based outsourced computation enables efficient correctness verification through cross-checking results from multiple non-colluding clouds, yet introduces critical privacy risks when clouds exchange intermediate data for interest alignment, especially in multi-user private data scenarios such as federated learning. To address this challenge, we propose BDT-RVOC, a novel framework integrating binary-segmentation data truncation with distributed multi-trapdoor public key cryptography (DMT-PKC). BDT-RVOC dynamically splits raw data into mutually exclusive blocks distributed to different clouds, ensuring that computations on truncated data preserve bit-level consistency with raw-data operations while preventing raw-data leakage during inter-cloud exchanges. Our framework designs secure interactive protocols for addition, multiplication, and equivalence testing under truncation, formally guaranteeing operational equivalence between block-level and raw-data computations. By extending Paillier encryption to a multi-key setting, DMT-PKC partitions strong private keys to resist collusion between the aggregator and up to n−2 agents. Applied to private aggregation, BDT-RVOC achieves a 1.8× speedup over federated learning baselines with 57% lower communication overhead. Theoretical analysis proves resilience against semi-honest adversaries compromising all communications and up to n−1 colluding parties, while experiments on real-world datasets confirm practical efficiency and scalability for real-world deployments. Youliang Tian, Ruixin Song, Kun Niu, Mengqian Li, Jinbo Xiong |
TrustCom | 6 |
| 2025 | Membership Feature Aggregation Attack Against Knowledge Reasoning Models in Internet of ThingsabstractThe rapid growth of Internet of Things (IoT) technology has heightened the requirement for effective data management and analysis. Knowledge graphs (KGs) and large pretrained language models (LLMs) play crucial roles in this scenario: KGs offer structured data management, while LLMs enhance data feature analysis. However, as data privacy concerns escalate, IoT machine learning models become more susceptible to membership inference attacks (MIAs). To tackle this challenge, we focus MIAs in knowledge reasoning models (KRMs) for IoT environments and propose two attack methods: 1) correlation attack (CA) and 2) feature aggregation attack (FAA). CA leverages the relational features of KGs to link member characteristics across different parameter spaces. It aggregates these features and maps them into a nonlinear space to identify linear relationships among members, thus improving membership recognition. In contrast, the FAA focuses on aggregating multiple member features, such as confidence scores, loss values, decision labels, and so on, within the KRM and projects them into a linear space. This method captures the interactions among different features, enhancing the differentiation between member and nonmember samples. The key difference is that CA explores correlations between features across member identities, while FAA aggregates various features to improve overall representation and identification. Experimental results show that both CA and FAA outperform existing methods, offering a more effective assessment of privacy risks in KRMs within IoT environments. Zehua Ding, Youliang Tian, Jinbo Xiong, Guorong Wang, Jianfeng Ma 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Achieving Efficient Privacy-Preserving Mixed Data Quality Assessment in Mobile CrowdsensingabstractIn mobile crowdsensing (MCS) applications, the single type data is inadequate to reflect the complexities of the real world and meet precise task requirements. Currently, there are few works that focus on mixed data in the context of MCS, and there is no work considering the credit issues of sensing platform. The privacy, fairness, and reliability of assessing the quality of mixed data remain unguaranteed. Therefore, we design a high-efficiency and privacy-preserving mixed data quality assessment scheme which adopts a dual-server architecture, designs secure k-prototype clustering for quality assessment, and conducts anomaly detection to eliminate anomalous data. Furthermore, we design a fair and reliable allocation mechanism to fairly allocate reward to users based on fixed and floating reward mechanisms for incentivizing rational users to submit high-quality mixed data. To prevent payment defaults by the sensing platform, we design verifiable credential to restrict them, ensuring payment fairness and transactional reliability. Finally, through theoretical analysis and experimental evaluation, we demonstrate the effectiveness and security of the proposed scheme. The results indicate that in terms of efficiency, the time overhead of mixed data quality assessment has been significantly reduced by three orders of magnitude compared to existing schemes. Chunpu Huang, Yuanyuan Zhang 0009, Jinbo Xiong, Renwan Bi, Youliang Tian |
IEEE Internet Things J. | 3 |
| 2025 | GeoFed: Geometry-Aware Byzantine Robust Federated Learning on SPD Manifolds in Heterogeneous EnvironmentsabstractFederated learning (FL) has been increasingly applied in the Internet of Things (IoT), leveraging its decentralized nature to facilitate collaboration among clients and enable resource-constrained clients to jointly train a globally optimal model based on consensus. However, it is difficult to confirm data authenticity and participant integrity due to the unobservability of local training procedures and the inaccessibility of local training data. As a result, FL is highly susceptible to Byzantine attacks, including data poisoning and model poisoning, which can manipulate the training process and degrade model performance. Moreover, IoT data is often highly heterogeneous and high-dimensional, rendering most existing Byzantine-robust FL approaches ineffective in practical scenarios. To address this challenge, we propose GeoFed, which iteratively filters out malicious clients based on the geodesic distance between clients. This geodesic distance is measured on the Riemannian manifold spanned by the covariance of local gradient update. To further mitigate the impact of data heterogeneity, GeoFed assigns a weight factor to each client after removing Byzantine attackers, optimizing the accuracy and flexibility of global model aggregation according to the quality of client data. We conduct extensive experimental evaluations of GeoFed under various Byzantine attack scenarios and highly heterogeneous data environments. To validate the efficacy of GeoFed, we provide a theoretical analysis of its convergence properties. The results demonstrate that GeoFed outperforms state-of-the-art Byzantine-robust FL approaches in heterogeneous IoT settings. Especially, under different Byzantine attacks, the accuracy of detecting malicious clients on the heterogeneous MNIST dataset approaches 100%. Qi Li 0011, Zhenzhen Wu, Jinbo Xiong, Anxiao Song, Tao Zhang 0029 |
IEEE Internet Things J. | 3 |
| 2025 | Incentivizing Resource Contribution for Video Analytics in Computing Power Networking: A Dual-Layer Stackelberg Game ApproachabstractThe explosion of cameras embedded in IoT devices—from mobile phones to autonomous vehicles—has positioned video analytics as a transformative AI tool across healthcare, smart cities, and beyond. Yet, the substantial computing and bandwidth demands of these applications outstrip what IoT devices alone can handle, particularly when low latency is required. Computing Power Networking (CPN) is an emerging solution that unifies cloud, edge, and device resources, enabling seamless, efficient task distribution for real-time analytics. While recent advances in cloud-edge frameworks show promise, current approaches often neglect the economic incentives that drive resource availability. To address this, we present a novel, privacy-enabled dual-layer Stackelberg game model that establishes a dynamic pricing strategy for video analytics in CPN. Our model introduces a two-stage negotiation: IoT devices contract with edge servers for computational and bandwidth resources, while edge servers may offload tasks to the cloud for enhanced service. Using game theory, we derive optimal pricing and offloading strategies under both complete and incomplete information, proving a Nash equilibrium. Comprehensive simulations validate our approach, showing improvements in resource efficiency, reduced latency, and incentivized resource-sharing across all CPN tiers. Specifically, our hybrid offloading strategy significantly reduces latency compared to edge-only and cloud-only computation models. For varying IoT device quantities, the average latency reduction across all scenarios is approximately 30.5%. This work provides an economically sustainable, privacy-conscious solution to the computational challenges of video analytics in an interconnected, resource-sharing ecosystem. Li Lin 0001, Jinbo Xiong, Peng Li 0017, Jiayin Lin, Xing Wang 0005, Limei Lin |
IEEE Internet Things J. | 3 |
| 2025 | THC-DL: Three-Party Homomorphic Computing Delegation Learning for Secure OptimizationabstractDelegation Learning(DL) flourishes data sharing, enabling agents to delegate data to the cloud for model training. To preserve privacy, homomorphic encryption (HE) offers an effective solution for privacy-preserving machine learning (PPML) in delegation learning, yet faces critical challenges in functionality (non-linear activation support), practicality (ciphertext blow-up from iterative computations), and security (data leakage risks caused by public knowledge of the mathematical principles applied in model training). To tackle these challenges, we propose THC-DL, a three-party HE framework addressing these challenges holistically for the first time. We elaborately design the ciphertext secure comparison (DL-CSC) protocol to satisfy secure comparison with private inputs, enabling efficient non-linear operations with O(1) communication complexity that reduces runtime to 12.5% of the DGK (Dolev-Greensmith-Kent protocol, the well-known comparison protocol). Second, we construct a Truncation-Mapping (Tru-Map) scheme, a mechanism that transforms input data by truncating and mapping it into a domain that facilitates more efficient processing, and the addition of truncated mapped data to resolve ciphertext blow-up by adaptively scaling ciphertexts during iterative training, ensuring correctness. Third, we formalize data leakage risks in HE-based quadratic convex optimization (standard in ML) and apply THC-DL to construct a secure optimization scheme. Theoretical analysis confirms THC-DL’s resilience against input recovery attacks, even when adversaries exploit public model parameters. Experiments on a real-world platform validate DL-CSC’s efficiency and scalability while reducing the computational complexity and communication complexity from O(n) to O(1) where n denotes the length of the input bits. Youliang Tian, Jinbo Xiong, Kun Niu, Mengqian Li, Jianfeng Ma 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Membership inference attacks via spatial projection-based relative information loss in MLaaS
Zehua Ding, Youliang Tian, Guorong Wang, Jinbo Xiong, Jinchuan Tang, Jianfeng Ma 0001 |
Inf. Process. Manag. | 4 |
| 2025 | DBFL: Dynamic Byzantine-Robust Privacy Preserving Federated Learning in Heterogeneous Data Scenario
Youliang Tian, Shuai Wang 0056, Kedi Yang, Jinbo Xiong |
Inf. Sci. | 6 |
| 2025 | FedRL-Hybrid: A federated hybrid reinforcement learning approach
Biao Jin 0004, Xuan Li 0007, Jinbo Xiong, Xing Wang 0005, Mingwei Lin |
Inf. Sci. | 5 |
| 2025 | Arithmetic consistency attack-resistant integrity verification for secure outsourced computing
Renwan Bi, Jinbo Xiong, Yuanyuan Zhang 0009, Youliang Tian |
J. Inf. Secur. Appl. | 3 |
| 2025 | VECO: A Digital Twin-Empowered Framework for Efficient Vehicular Edge Caching and Computation OffloadingabstractVehicular edge computing (VEC) tackles the escalating computational demands of intelligent transportation systems by offloading tasks to nearby roadside units (RSUs) for processing. However, in the dynamic vehicular network environment, where vehicles are constantly moving, effective VEC demands a sophisticated approach to managing computing, caching, and communication resources. This involves coordinating resource allocation and data caching across multiple vehicles and RSUs while making complex decisions about task placement. In this paper, we present VECO, a Vehicular Edge Caching and Offloading framework powered by digital twins (DTs). VECO leverages DTs for real-time monitoring of network conditions and resource states, enabling predictive analysis and intelligent decision-making. The framework incorporates a Dynamic Task Caching and Computation Offloading (DT2C) mechanism to optimize data caching and adapt task offloading based on task characteristics and dynamic resource availability. Specifically, we develop a utility-based caching algorithm for RSUs and a novel task offloading strategy using a Proximal Policy Optimization-based deep reinforcement learning algorithm. Extensive experiments demonstrate that VECO, augmented by the DT2C mechanism, significantly outperforms baseline approaches, achieving faster learning convergence and a 21% reduction in total costs, including system latency and energy consumption. Li Lin 0001, Qiang He 0001, Jinbo Xiong, Jiayin Lin, Limei Lin |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2024 | Towards Scalable and Secure IoTs Transactions: A New Bi-directional Payment Channel Without Third-Party Monitoring
Zuobin Ying, Qingao Ding, Shengmin Xu, Jinbo Xiong |
ACISP (3) | 5 |
| 2024 | Privacy Preservation Fully Homomorphic Encryption for Cloud-assisted Biometric Identification with Multi-keyabstractBiometrics is a technology that utilizes individual physiological or behavioral characteristics for identity authentication and identification, ensuring secure and accurate identity verification by comparing biometric information with samples in a database. However, traditional biometric technology raises concerns about privacy leakage, which has led to the emergence of privacy-preserving biometric technology. This study introduces a cloud-assisted privacy-preserving biometric authentication system based on multi-key full homomorphic encryption. Our scheme employs a TFHE encryption scheme to encrypt user biometrics and utilizes a cloud server to assist in computation. We design secure computing protocols based on multi-key TFHE and develop a privacy-preserving biometric system based on a single cloud server. Privacy analysis and performance evaluation demonstrate that the proposed solution is efficient and feasible. Our experimental findings indicate that the proposed scheme exhibits a superior accuracy rate to current schemes. Compared to the best solution, our method has increased the iris recognition accuracy by approximately 68.42%. Although the experimental results demonstrate high accuracy and feasibility, implementing TFHE in biometric models could be improved by its execution time, presenting challenges for broad adoption. Nevertheless, through optimization and technological advancements, this protocol is anticipated to elevate privacy protection standards in practical biometric recognition systems moving forward. Shenghui Peng, Peiheng Jia, Jinbo Xiong, Liehuang Zhu, Ximeng Liu |
GLOBECOM | 3 |
| 2024 | FPIM: Fair and Privacy-Preserving Incentive Mechanism in Mobile Crowdsensing
Ruonan Lin, Yuanyuan Zhang 0009, Renwan Bi, Ruihong Huang, Jinbo Xiong |
ICA3PP (5) | 5 |
| 2024 | CPAKE: Dynamic Batch Authenticated Key Exchange with Conditional Privacy
Axin Xiang, Youliang Tian, Jinbo Xiong, Zuobin Ying, Changgen Peng |
ICA3PP (1) | 3 |
| 2024 | LSTN: A Lightweight Secure Three-Party Inference Framework for Deep Neural NetworksabstractSecure inference in a deep-learning-as-a-service setting (DLaaS) can effectively protect sensitive data of the client and server model parameters. However, various nonlinear computations heavily hinder its efficiency. To address this issue, we propose a secure three-party inference framework, called LSTN, to ensure the privacy of client input data and meanwhile achieve prediction accuracy close to the plaintext setting. Specifically, we leverage replicated secret sharing to design a novel secure three-party comparison protocol that will be employed to develop a secure ReLU function. Our developed protocol can achieve high communication efficiency in the scenario of having a majority of honest parties. The experimental result shows that the inference time is 6× faster than the prevailing computing framework, CrypTen. Dalong Guo, Changqing Luo, Yuanyuan Zhang 0009, Renwan Bi, Jinbo Xiong |
ICC | 5 |
| 2024 | Knowledge Distillation Enables Federated Learning: A Data-free Federated Aggregation SchemeabstractApplying knowledge distillation (KD) in federated learning (FL) can transfer model knowledge between clients’ local models and global model, which helps to improve the generalization of the global model. However, this requires both the clients and the server to have public data sets, which may lead to potential privacy disclosure issues. In this paper, we propose a federated data-free knowledge distillation framework, namely FedDFKD, which does not rely on any public data sets. There is a lightweight delivery model we design to learn and transfer model knowledge in different clients. During local training, the local model is jointly trained with delivery model using local data sets, and the local model feeds back its knowledge to the delivery model after it has finished its training phase in this communication round. Afterwards, the server performs global model aggregation and knowledge distillation of the delivery model. Finally, the server returns global model and distillation result to clients. We compare FedDFKD with the most representative aggregation algorithms in FL, and the results show that our method is feasible and outperforms the compared methods by between 0.1 and 3.96 percent of the global model on the MNIST dataset. Yuanyuan Zhang 0009, Renwan Bi, Jiayin Lin, Jinbo Xiong |
IJCNN | 5 |
| 2024 | Optimizing Resource Allocation in the Internet of Vehicles: An Intelligent Vehicle-Edge-Cloud Collaboration Approach
Li Lin 0001, Jinbo Xiong, Jiayin Lin, Ruihong Huang, Xing Wang 0005 |
NPC (2) | 3 |
| 2024 | Membership Inference Attacks via Dynamic Adversarial Perturbations ReductionabstractExisting membership inference attacks (MIAs) based on adversarial attacks typically introduce excessively large adversarial perturbations to change the model predictions. However, such methods are not only likely to obscure the characteristic memory of the model regarding member data but also blur the subtle characteristic differences between member and non-member data. To address this issue, we propose a novel dynamic adversarial perturbation reduction MIA (DAPR-MIA), which aims to enhance the ability to identify the membership of samples by reducing the perturbation strength. Specifically, DAPR-MIA first conducts a fine-grained analysis of the gradient components of conventional adversarial examples, assessing the impact of each element on the model decision to generate a sensitivity mask. This mask identifies dimensions within adversarial examples that significantly influence model predictions, referred to as sensitive dimensions. Then, by dynamically reducing the perturbation size in these sensitive dimensions, DAPR-MIA gradually approaches the minimum perturbation required to change the prediction result of samples, maximizing the retention of membership features within the sample. Finally, the deviation of the prediction results between the original sample and the adversarial example after perturbation attenuation on the target model is measured to infer whether the sample belongs to a member data. Experimental results show that DAPR-MIA significantly outperforms existing methods on multiple datasets and deep models, demonstrating state-of-the-art attack accuracy. Zehua Ding, Youliang Tian, Guorong Wang, Jinbo Xiong, Jianfeng Ma 0001 |
TrustCom | 4 |
| 2024 | Attribute-based key management for patient-centric and trusted data access in blockchain-enabled IoMT
Axin Xiang, Hongfeng Gao, Youliang Tian, Jinbo Xiong |
Comput. Networks | 5 |
| 2024 | A literature review on V2X communications security: Foundation, solutions, status, and futureabstractAbstract With the refinement and development of the Vehicle to Everything (V2X) concept, its security issues have gradually come to the fore, revealing many security risks and increasing security requirements for V2X, and many protective measures have likewise emerged. The article first introduces the development history of the past Internet of Vehicles(IoV), summarizes some common V2X security threats, surveys the security technologies used for V2X communication, and outlines the development of each technology and the proposed security protocols in the last 3 years. Due to the different advantages and disadvantages of previous protection schemes, the idea of using National Cryptography to supplement the security scheme or designing a new security scheme article based on the National Cryptography Algorithms((AKA SM algorithms) is proposed. The survey then introduces the SM2, SM3, SM9, and ZUC algorithms, describes the development and application of the SM commercial algorithm in recent years, and finally, statistics and introduces the part of the development process of the security protocols currently used in IoV regarding the SM algorithms and gives some application prospects. Zuobin Ying, Kaichao Wang, Jinbo Xiong, Maode Ma |
IET Commun. | 3 |
| 2024 | Decentralized Access Control for Privacy-Preserving Cloud-Based Personal Health Record With Verifiable Policy UpdateabstractWith the advancement of cloud computing technology, cloud-based personal health record (CB-PHR) has become an increasingly popular way for modern patients to flexibly manage and share their health records with doctors. However, the confidentiality of CB-PHR privacy is vulnerable to threats due to unauthorized users and untrusted cloud service provider (CSP). Additionally, patients and doctors may be constrained by changes in access permissions and limited device resources. To address these challenges, we propose an efficient decentralized privacy-preserving attribute-based access control scheme with verifiable policy update (DPVPU) for CB-PHR systems. DPVPU supports large attribute universe and safeguards the privacy of both the access policy and the doctor’s identity through partially hiding the access policy and employing a one-way anonymous key agreement technique. Unlike re-encrypting ciphertext, it can dynamically update policy by fully utilizing the previous policy and outsourcing the computation of ciphertext update to the CSP. Also, we design an efficient verification algorithm enabling patients to check the correctness of updated ciphertext. For devices with limited resources, we use online/offline and outsourced decryption techniques to reduce system costs. Finally, we provide formal security proofs and performance analysis to demonstrate the security and practicality of DPVPU. Haoyuan Fan, Qi Li 0011, Jinbo Xiong, Rui Li 0047, Wei Chen 0006, Haiping Huang |
IEEE Internet Things J. | 3 |
| 2024 | PSFL: Ensuring Data Privacy and Model Security for Federated LearningabstractThe integration of blockchain-based federated learning (BFL) and Industry 4.0 utilizes intermediate models to execute task deployment and result acceptance, effectively solving the problems of data barriers and data resource waste in Industry 4.0. However, the BFL ecosystem is susceptible to poisoning and inference attacks that undermine data privacy and model security. In this paper, we propose PSFL, a robust FL framework that guarantees both data privacy and model security. Specifically, we design a cross-validation algorithm where numerous participants conduct a thorough assessment of the user’s contribution growth rate in the current round. This approach proves effective in identifying Byzantine attackers engaged in malicious activities within the system. Furthermore, we propose a lightweight multi-receiver signcryption mechanism employing secure key distribution, which significantly minimizes resource overhead. Finally, the security of PSFL is proved based on the random oracle model. Empirical assessment affirms the effectiveness and practicality of PSFL, even with different proportions of malicious users, PSFL’s performance is 10%20% higher than Trimmed Mean and M-Krum. In summary, PSFL improves the model accuracy and the security of the model transmission process in scenarios involving edge node poisoning, which demonstrates that PSFL can be well adapted to Industry 4.0. Jing Li 0155, Youliang Tian, Zhou Zhou 0005, Axin Xiang, Shuai Wang 0056, Jinbo Xiong |
IEEE Internet Things J. | 6 |
| 2024 | Computing Power Networking Meets Blockchain: A Reputation-Enhanced Trading Framework for Decentralized IoT Cloud ServicesabstractComputing Power Networking (CPN) represents a transformative paradigm in distributed computing, harnessing the collective capabilities of edge servers dispersed across diverse geographical locations. CPN’s core strengths lie in its ability to accelerate data processing, diminish latency, and scale efficiently, rendering it particularly apt for real-time applications and the Internet of Things. When coupled with blockchain technology, CPN extends its potential by facilitating secure and transparent allocation and trading of computing resources, bolstering data integrity and reliability. However, current research at the intersection of CPN and blockchain primarily focuses on framework development and technology integration, often overlooking the challenge of delivering dependable computing services, especially in the presence of potentially unreliable nodes. To tackle this issue, we introduce a reputation-enhanced resource trading framework, designed to ensure equitable and trustworthy computing power transactions. We establish a decentralized reputation model, capable of accurately assessing node behavior over extended periods. Additionally, we present three optimization mechanisms for reputation updates, accounting for transaction history, quality of service, and transaction amount. Furthermore, our work introduces a reputation-enhanced consensus mechanism within the trading system, strategically employing incentives to motivate participants to deliver high-quality services, thereby increasing their rewards. Simultaneously, it effectively mitigates wealth inequality among resource providers of varying sizes. To validate our approach, we develop a prototype system and conduct performance evaluations, which affirm the superiority of our system in enhancing reputation and delivering robust economic features. Li Lin 0001, Jiapeng Wu, Zhi Zhou 0006, Jin Zhao 0003, Peng Li 0017, Jinbo Xiong |
IEEE Internet Things J. | 6 |
| 2024 | DScPA: A Dynamic Subcluster Privacy-Preserving Aggregation Scheme for Mobile Crowdsourcing in Industrial IoTabstractMobile crowdsourcing (MCS) is a promising new paradigm for intelligent data perception in large-scale sensor applications such as the Industrial Internet of Things (IIoT). This approach assigns industrial perception tasks to mobile devices for data collection and sharing, creating a bright outlook for building strong industrial systems and improving industrial services. However, the particular IIoT network environment is vulnerable to a range of malicious attacks, including the manipulation or deletion of data. Moreover, industry-aware nodes, which have limited energy resources, are susceptible to various failures that can result in distorted data and inaccurate trend analysis. To tackle the above issues, we propose a dynamic sub-cluster privacy-preserving aggregation (DScPA) scheme for the crowdsourced industrial virtual areas, by exploring the equilibrium between privacy security and data benefits for industrial users. Specifically, we propose joining and exiting the virtual area aggregation system protocol, and design low-cost privacy-preserving aggregation algorithm to achieve flexible and dynamic construction of virtual areas. Additionally, we propose a supervised mechanism-based subset aggregation protocol that takes into account the remaining energy of the nodes in the virtual areas aggregation system and their distance from the base station. We employ the relevant characteristics of polynomial functions and binary data to achieve data privacy protection and integrity verification at a lower computational cost. Furthermore, we develop an asymmetric information iterative static non-cooperative game model to verify the soundness of DScPA. Finally, security analysis demonstrates that the DScPA scheme meets the security objectives. Simulations show that implementing DScPA in the industrial virtual area can improve the network lifetime by about 16.7% compared to existing solutions, while also increasing the average remaining energy of industry-aware nodes. Tao Feng 0007, Jinbo Xiong, Qi Li 0011, Youliang Tian |
IEEE Internet Things J. | 3 |
| 2024 | RVFL: Rational Verifiable Federated Learning Secure Aggregation ProtocolabstractUsing federated learning (FL) to train global models in IoT improves computational efficiency and protects users’ data privacy. However, FL still faces privacy threats. Driven by interests, servers reduce their computational cost or induce wrong decisions in IoT devices by returning wrong global model gradients. Although the verifiability of aggregation results is achieved in previous research, it is difficult to defend against collusion attacks launched by servers and users. Therefore, we construct a rational verifiable federated learning secure aggregation protocol based on the dual-server framework and game theory, which achieves verifiable aggregation results, and effectively defends against collusion attacks. Firstly, we propose a new model verification code based on the property of irreversible matrices, which allows users to verify the correctness of the aggregation results by matrix products. This model validation code is computationally efficient and resistant to the adversary’s backward inference. Secondly, we adopt a dual-server architecture and improve the prisoner contract and betrayal contract according to the actual application scenarios of IoT, converting the previous collusion attacks between servers and users to collusion attacks between servers and making the rational servers not launch collusion attacks to destroy the verification mechanism of the aggregation results through the incentive mechanism. Finally, we demonstrate through security analysis that RVFL is secure and effective against collusion and reverse inference attacks. In addition, we show through experimental results that RVFL can improve its efficiency by three orders of magnitude in the verification phase and 88% in the masking phase. Xianyu Mu, Youliang Tian, Zhou Zhou 0005, Shuai Wang 0056, Jinbo Xiong |
IEEE Internet Things J. | 5 |
| 2024 | H²CT: Asynchronous Distributed Key Generation With High-Computational Efficiency and Threshold Security in Blockchain NetworkabstractAsynchronous distributed key generation (ADKG) is a strong-robustness key management technology to bootstrap threshold cryptosystems without a global clock, which can enable decentralized security management for threshold digital wallets in blockchain network. However, the high-computational cost of existing ADKG protocols makes it difficult to remove the “slow” connotation from the word “asynchronous” in a high-threshold security context. In this article, we propose a simpler “two-high” ADKG protocol (H2CT) for blockchain to improve the computational efficiency of asynchronous communications while balancing it with threshold security. Concretely, we first construct a computationally efficient asynchronous complete secret sharing (ACSS) scheme using number theory transformation, reducing the computational complexity of share evaluation from$O(n^{2})$to$O(n\log n)$in the dealing phase. To eliminate the negative impact of up to t biased secrets brought by the implicate messages in the agreement phase, we extend the verifiable ACSS scheme to a publicly verifiable ACSS scheme (pvACSS) using Feldman polynomial commitment. Leveraging this enhanced randomness, the matrix computation cost and message size in the remaining phases are reduced to about half that of the existing works, i.e.,$O(2n^{2})$. Finally, considering the high-scalability requirements, the network size n is increased to up to 1024 nodes and the results show that our pvACSS and the derived H2CT reduce the runtime by approximately 33.96 s and 824.46 s, respectively, over the state-of-the-art. Moreover, we perform simulations on an open-source blockchain testbed, fully demonstrating the efficiency advantages of our H2CT protocol. Axin Xiang, Hongfeng Gao, Youliang Tian, Jinbo Xiong, Changgen Peng |
IEEE Internet Things J. | 4 |
| 2024 | CEC-DL: Cloud-Edge Collaborative Delegation Learning Against Covert AdversariesabstractDelegation learning is indeed a prevalent approach in privacy-preserving machine learning (PPML), especially when dealing with big data. It specifically involves data owners delegating their data to servers with computational capabilities for training and inference. These servers provide services on a pay-per-use basis. The essence of delegation learning lies in maintaining the integrity of the server’s training while ensuring the privacy of the delegator’s data. However, existing delegation learning schemes struggle to balance security and efficiency, and they cannot guarantee correctness. To tackle these challenges, we propose a cloud-edge collaborative delegation learning framework (CEC-DL) against covert adversaries, which is verifiable and satisfies the guaranteed output delivery (GOD) in security. This is the first time that the covert security assumption is used in a PPML scenario. Furthermore, we design probabilistic verifiable secure addition and subtraction computation protocol (PVS-AaS) and probabilistic verifiable secure multiplication computation protocol (PVS-MUL), which can be used to realize secure addition and multiplication computations in delegation learning without expensive message authentication code (MAC) verification. At the same time, we develop a malicious adversary detection protocol (MADP) that could prevent the malicious actions of potential covert adversaries while ensuring the correct output. Finally, we apply the CEC-DL to the linear regression model to construct privacy preserving linear regression protocol (PP-LRP). Through theoretical analysis and experiments, CEC-DL improves the security, and is more efficient than the verifiable computation of malicious adversaries. Youliang Tian, Zerui Chen, Xinhua Cui, Jinbo Xiong, Jianfeng Ma 0001 |
IEEE Internet Things J. | 5 |
| 2024 | Achieving lightweight, efficient, privacy-preserving user recruitment in mobile crowdsensing
Ruonan Lin, Yikun Huang, Yuanyuan Zhang 0009, Renwan Bi, Jinbo Xiong |
J. Inf. Secur. Appl. | 5 |
| 2024 | Robust and Privacy-Preserving Decentralized Deep Federated Learning Training: Focusing on Digital Healthcare ApplicationsabstractFederated learning of deep neural networks has emerged as an evolving paradigm for distributed machine learning, gaining widespread attention due to its ability to update parameters without collecting raw data from users, especially in digital healthcare applications. However, the traditional centralized architecture of federated learning suffers from several problems (e.g., single point of failure, communication bottlenecks, etc.), especially malicious servers inferring gradients and causing gradient leakage. To tackle the above issues, we propose a robust and privacy-preserving decentralized deep federated learning (RPDFL) training scheme. Specifically, we design a novel ring FL structure and a Ring-Allreduce-based data sharing scheme to improve the communication efficiency in RPDFL training. Furthermore, we improve the process of distributing parameters of the Chinese residual theorem to update the execution process of the threshold secret sharing, supporting healthcare edge to drop out during the training process without causing data leakage, and ensuring the robustness of the RPDFL training under the Ring-Allreduce-based data sharing scheme. Security analysis indicates that RPDFL is provable secure. Experiment results show that RPDFL is significantly superior to standard FL methods in terms of model accuracy and convergence, and is suitable for digital healthcare applications. Youliang Tian, Shuai Wang 0056, Jinbo Xiong, Renwan Bi, Zhou Zhou 0005, Md. Zakirul Alam Bhuiyan |
IEEE Trans. Comput. Biol. Bioinform. | 3 |
| 2024 | Communication-Efficient Privacy-Preserving Neural Network Inference via Arithmetic Secret SharingabstractWell-trained neural network models are deployed on edge servers to provide valuable inference services for clients. To protect data privacy, a promising way is to exploit various types of secret sharing to implement privacy-preserving neural network inference. However, existing schemes suffer high communication rounds and overhead, making them hardly practical. In this paper, we propose Cenia, a new communication-efficient privacy-preserving neural network inference model. Specifically, we exploit arithmetic secret sharing to develop low-interaction secure comparison protocols, that can be used to realize secure activation layers (e.g., ReLU) and secure pooling layers (e.g., max pooling) without expensive garbled circuit and oblivious transfer primitives. Besides, we also design secure exponent and division protocols to realize secure normalization layers (e.g., Sigmoid). Theoretical analysis demonstrates the security and low complexity of Cenia. Extensive experiments have also been conducted on benchmark datasets and classical models, and experimental results show that Cenia achieves privacy-preserving, accurate, and efficient neural network inference. Particularly, Cenia can achieve 37.5% and 60.76% of Sonic’s communication rounds and overhead, respectively, compared to Sonic (i.e., the state-of-the-art scheme). Renwan Bi, Jinbo Xiong, Changqing Luo, Jianting Ning, Ximeng Liu, Youliang Tian, Yan Zhang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | A Verifiable Privacy-Preserving Outsourced Prediction Scheme Based on Blockchain in Smart HealthcareabstractThe swift progression of the Internet of Things and the extensive integration of machine learning have spurred the growth of intelligent healthcare. Many intelligent healthcare devices, limited by their own computing and storage resources, require outsourcing data analysis tasks to cloud platforms for efficient and accurate results. Unfortunately, malicious cloud services lead to privacy breaches in outsourced data and untrustworthiness in learning models. To address these challenges, this paper proposes a verifiable privacy-preserving outsourced prediction scheme based on blockchain in smart healthcare (VPOL). Specifically, by incorporating blockchain technology into VPOL, we build a robust and scalable framework to prevent falsification of outsourced data and learning models in a decentralized and transparent manner. Then, we design a training committee approach to ensure the reliability of outsourced prediction and employ homomorphic encryption and commitment scheme to protect the privacy and integrity of the data. Finally, theoretical analysis proves the effectiveness and security of VPOL. Sufficient experiments demonstrate that VPOL achieves the approximate accuracy of the plaintext. Ta Li, Youliang Tian, Jinbo Xiong |
HealthCom | 3 |
| 2023 | DFedXGB: An XGB Vertical Federated Learning Framework with Data DesensitizationabstractThe emergence of Vertical Federated Learning (VFL) addresses the issue of data isolation and enhances edge intelligence. However, the high computational costs pose a significant challenge when employing Homomorphic Encryption (HE) for privacy protection in VFL. To address this challenge, we present DFedXGB, a secure and reliable framework for Federated XGBoost (FedXGB). DFedXGB incorporates an innovative data desensitization scheme to safeguard raw data and model parameters against privacy disclosure. Furthermore, We also designed a secure aggregation algorithm based on XGBoost to mitigate server collusion. Theoretical analysis confirms the correctness of DFedXGB, and security analysis establishes its provable security. Experimental results on real datasets demonstrate that DFedXGB achieves lossless accuracy comparable to non-privacy-preserving centralized methods. Moreover, DFedXGB reduces computational costs by an average of 85% compared to SecureBoost. Qing Yang 0003, Youliang Tian, Jinbo Xiong |
TrustCom | 3 |
| 2023 | The dummy-based trajectory privacy protection method to resist correlation attacks in Internet of VehiclesabstractSummary Existing dummy‐based trajectory privacy protection schemes do not take into account the correlation of multiple locations and whether the generated trajectory based on dummies matches the user's movement mode, which enables the adversary to identify some dummies. Aiming at this problem, to ensure that the generated trajectories match the movement modes of users, historical query trajectories of users are selected. In this way, the generated dummies on the selected historical query trajectories are based on the location relationship of adjacent time and the background information constraint of the dummy, namely, they should meet the time reachability, the similarity of historical query probability and the maximum in‐degree. Security analysis shows that the proposed scheme effectively perturbs the spatiotemporal correlation between the real location and dummies. Furthermore, the proposed scheme is compared with the existing schemes in terms of single‐point location exposure risk and trajectory exposure risk, and the experimental results indicate that the proposal has significant improvement in location privacy protection of the user. Qiuling Chen, Ayong Ye, Jinbo Xiong |
Concurr. Comput. Pract. Exp. | 4 |
| 2023 | Outsourced and Privacy-Preserving Collaborative k-Prototype Clustering for Mixed Data via Additive Secret SharingabstractOutsourced cloud computing can be considered as an effective way to overcome the data island among users and relieve the pressure of limited resources. However, due to the concerns about trust in cloud servers, outsourcing the users’ data and model training task has considerable privacy disclosure risks. This article presents a PriKPM scheme by using additive secret sharing (ASS), so as to implement the privacy-preserving${k}$-prototype clustering for mixed data (i.e., including numerical and categorical attributes). In PriKPM, data samples are randomly split into two shares and delivered offline to two collaborative servers. We design a secure initialization method for determining the location and number of cluster centers. Then, both servers securely calculate the mixed distance between samples and cluster centers, and execute the samples partion and cluster updating operations. An efficient and secure comparison protocol is developed to offer flexibly the “less than or equal” and “equal” functions during the entire clustering process. Furthermore, theoretical analysis proves the effectiveness and security of PriKPM. Sufficient experiments demonstrate that PriKPM is computationally more efficient than existing secure clustering works. PriKPM can achieve the approximate accuracy of the plaintext${k}$-prototype clustering scheme. Renwan Bi, Dalong Guo, Yuanyuan Zhang 0009, Ruihong Huang, Li Lin 0001, Jinbo Xiong |
IEEE Internet Things J. | 6 |
| 2023 | Achieving Lightweight and Privacy-Preserving Object Detection for Connected Autonomous VehiclesabstractConnected autonomous vehicles (CAVs) are capable of capturing high-definition images from onboard sensors, which can be used to facilitate the detection of objects in the vicinity. Such images may, however, contain sensitive information (e.g., human faces and license plates) as well as the indirect location of CAVs. To protect the object privacy of images shared by CAVs, this article proposes a privacy-preserving object detection (P2OD) framework. Specifically, we propose multiple secure computing protocols designed to construct a privacy-preserving Faster$R$-convolutional neural network (CNN) model to securely extract features and bounding-boxes of objects in an image. By leveraging edge computing (with higher performance computation and lower latency, in comparison to cloud-based solutions), CAVs randomly split the captured images and upload them to two noncollusive edge servers. Both servers will then perform the P2OD framework cooperatively to directly detect objects over random image shares without exposing sensitive information. The theoretical analysis demonstrates the security, correctness, and efficiency of the P2OD framework, and the experimental findings show that the P2OD framework can effectively protect the classification and location privacy of image objects for CAVs. Compared with the original Faster R-CNN model, the classification and regression errors of the P2OD framework can be controlled within 10−12 and 10−14, respectively. Renwan Bi, Jinbo Xiong, Youliang Tian, Qi Li 0011, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 2 |
| 2023 | Blockchain-assisted multi-keyword fuzzy search encryption for secure data sharing
Yipeng Zou, Tao Peng 0011, Guojun Wang 0001, Jinbo Xiong |
J. Syst. Archit. | 5 |
| 2023 | EPMA: Edge-Assisted Hierarchical Privacy-Preserving Multidimensional Data Aggregation Mechanism
Tao Feng 0007, Youliang Tian, Jinbo Xiong |
Mob. Networks Appl. | 4 |
| 2023 | FVP-EOC: Fair, Verifiable, and Privacy-Preserving Edge Outsourcing Computing in 5G-Enabled IIoTabstractThe 5G-enabled Industrial Internet of Things tilts the data processing model from the cloud to the edge. Users are more inclined to get feedback and data analysis of outsourcing computing results timely from the edge. However, the existing solutions undermine the fairness of multitask outsourcing in edge environment and cannot guarantee the correctness of results. To tackle these challenges, in this article, we propose a fair, verifiable, and privacy-preserving edge outsourcing computing scheme based on blockchain (FVP-EOC). Initially, we propose a task bidding method in the same round of task outsourcing, which improves the utilization of resources and the fairness of the FVP-EOC by dividing tasks into blocks. Furthermore, we design a result verification algorithm and a consensus algorithm to ensure the correctness of the results without a trusted third party. Finally, theoretical analysis and ample simulations indicate that the FVP-EOC is secure and verifiable and ensure the benefits of all the participants in edge outsourcing computing. Ta Li, Youliang Tian, Jinbo Xiong, Md. Zakirul Alam Bhuiyan |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Blockchain-Enabled Secure and Trusted Federated Data Sharing in IIoTabstractFederated learning breaks down data silos and promotes the intelligence of the Industrial Internet of Things (IIoT). However, the principal–agent architecture commonly used in federated learning not only increases the cost but also fails to take into account the privacy protection and trustworthiness of flexible on-demand data sharing. To tackle the above challenges, we propose a secure and trusted federated data sharing (STFS) based on blockchain. Initially, we construct an autonomous and reliable federated extreme gradient boosting learning algorithm to crack the data isolation problem, providing privacy protection and verifiability. Furthermore, we design a secure and trusted data sharing and trading mechanism to ensure secure on-demand controlled data sharing and fair trading. Finally, the security of STFS is proved based on the universal composable theory. The results of ample experimental simulations demonstrate the good effectiveness and performance of STFS for IIoT applications. Zhou Zhou 0005, Youliang Tian, Jinbo Xiong, Jianfeng Ma 0001, Changgen Peng |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Blockchain-enabled Secure Distributed Data Aggregation and Verification Mechanism for IIoTabstractThe traditional Industrial Internet of Things (IIoT) is a centralized system that fully trusts and relies on a central cloud server to process and store the data collected by the equipments. As the number of devices increases, this centralized model not only faces severe network load issues and single point of failure crises, but also raises various security and privacy concerns. Fortunately, blockchain can provide decentral-ization, high trustworthiness and security. Therefore, to design a distributed IIoT system, a blockchain-based IIoT would be a reasonable choice. This paper combines the consortium chain and the homomorphic Paillier algorithm, and proposes a secure distributed data aggregation and verfication (SDAV) mechanism based on the consortium chain. This mechanism combines edge computing and blockchain technology to build a distributed data aggregation framework, which effectively supports the secure collection and storage of data, and avoids single point of failure and tampering crisis. Secondly, based on the (k, t)-threshold Paillier algorithm, a secure cryptographic verification mechanism is designed to protect the privacy and confidentiality of data on the blockchain. Finally, the analysis proves the security of the proposed mechanism and demonstrates the efficiency advantage through simulation experiments. Tao Feng 0007, Qi Li 0011, Jinbo Xiong |
GLOBECOM | 4 |
| 2022 | Outsourced and Practical Privacy-Preserving K-Prototype Clustering supporting Mixed DataabstractAiming to the data and model privacy issue in outsourced clustering tasks, this paper proposes an practical privacy-preserving k-prototype clustering scheme (referred to PriKPM) supporting mixed numerical and categorical attributes data. In PriKPM scheme, the users only randomly split the data sample into two shares and send them to two non-collusive servers, without interacting with the servers online. The two servers can cooperate to perform secure sample distance calculation, cluster center selection, and in-cluster sample update operations over two randomness data shares, and finally obtain the clustering distribution of samples. Specifically, we design an efficient secure comparison protocol based on additive/arithmetic secret sharing, which can switch freely between "greater than or equal" and "equal" functions, providing two comparison forms for PriKPM scheme. Theoretical analysis indicates the security and efficiency of our PriKPM scheme. Experimental results further show that compared to prior work, the clustering time of PriKPM scheme is reduced by 3 orders of magnitude. Renwan Bi, Jinbo Xiong, Youliang Tian |
ICC | 2 |
| 2022 | Achieving Graph Clustering Privacy Preservation Based on Structure Entropy in Social IoTabstractDecoding the real structure from the Social Internet-of-Things (SIoT) network with a large-scale noise structure plays a fundamental role in data mining. Protecting private information from leakage in the mining process and obtaining accurate mining results is a significant challenge. To tackle this issue, we present a graph clustering privacy-preserving method based on structure entropy, which combines data mining with the structural information theory. Specially, user private information in SIoT is encrypted by Brakerski–Gentry–Vaikuntanathan (BGV) homomorphism to generate a graph structure in the ciphertext state, the ciphertext graph structure is then divided into different modules by applying a 2-D structural information solution algorithm and a entropy reduction principle node module partition algorithm, and the$K$-dimensional structural information solution algorithm is utilized to further cluster the internal nodes of the partition module. Moreover, normalized structural information and network node partition similarity are introduced to analyze the correctness and similarity degree of clustering results. Finally, security analysis and theoretical analysis indicate that this scheme not only guarantees the correctness of the clustering results but also improves the security of private information in SIoT. Experimental evaluation and analysis shows that the clustering results of this scheme have higher efficiency and reliability. Youliang Tian, Jinbo Xiong, Lei Chen 0029, Jianfeng Ma 0001, Changgen Peng |
IEEE Internet Things J. | 3 |
| 2022 | Special Issue on Knowledge- and Service-Oriented Industrial Internet of Things: Architectures, Challenges, and MethodologiesabstractThe Ever-Increasing evolution of technologies in communication, artificial intelligence (AI), manufacturing, etc., is promoting a new wave of industrial revolution. Industrial Internet of Things (IIoT) has been considered as a critical stimulator for both science and economics by amounts of countries. Dapeng Wu 0002, Shaoen Wu, Danda B. Rawat, Paulo Roberto de Lira Gondim, Periklis Chatzimisios, Jinbo Xiong |
IEEE Internet Things J. | 6 |
| 2022 | Toward Lightweight, Privacy-Preserving Cooperative Object Classification for Connected Autonomous VehiclesabstractCollaborative perception enables autonomous vehicles to exchange sensor data among each other to achieve cooperative object classification, which is considered an effective means to improve the perception accuracy of connected autonomous vehicles (CAVs). To protect information privacy in cooperative perception, we propose a lightweight, privacy-preserving cooperative object classification framework that allows CAVs to exchange raw sensor data (e.g., images captured by HD camera), without leaking private information. Leveraging chaotic encryption and additive secret sharing technique, image data are first encrypted into two ciphertexts and processed, in the encrypted format, by two separate edge servers. The use of chaotic mapping can avoid information leakage during data uploading. The encrypted images are then processed by the proposed privacy-preserving convolutional neural network (P-CNN) model embedded in the designed secure computing protocols. Finally, the processed results are combined/decrypted on the receiving vehicles to realize cooperative object classification. We formally prove the correctness and security of the proposed framework and carry out intensive experiments to evaluate its performance. The experimental results indicate that P-CNN offers exactly almost the same object classification results as the original CNN model, while offering great privacy protection of shared data and lightweight execution efficiency. Jinbo Xiong, Renwan Bi, Youliang Tian, Ximeng Liu, Dapeng Wu 0002 |
IEEE Internet Things J. | 1 |
| 2022 | Privacy-Preserving Traffic Violation Image Filtering and Searching via Crowdsensing
Yuanyuan Zhang 0009, Jinbo Xiong, Ximeng Liu |
Mob. Networks Appl. | 2 |
| 2022 | POISIDD: privacy-preserving outsourced image sharing scheme with illegal distributor detection in cloud computing
Tianpeng Deng, Xuan Li 0007, Jinbo Xiong |
Multim. Tools Appl. | 3 |
| 2022 | A Blockchain-Based Machine Learning Framework for Edge Services in IIoTabstractEdge services provide an effective and superior means of real-time transmissions and rapid processing of information in the Industrial Internet of Things (IIoT). However, the continuous increase of the number of smart devices results in privacy leakage and insufficient model accuracy of edge services. To tackle these challenges, in this article, we propose a blockchain-based machine learning framework for edge services (BML-ES) in IIoT. Specifically, we construct novel smart contracts to encourage multiparty participation of edge services to improve the efficiency of data processing. Moreover, we propose an aggregation strategy to verify and aggregate model parameters to ensure the accuracy of decision tree models. Finally, based on the SM2 public key cryptosystem, we protect data security and prevent data privacy leakage in edge services. Theoretical analysis and simulation experiments indicate that the BML-ES framework is secure, effective, and efficient, and is better suitable to improve the accuracy of edge services in IIoT. Youliang Tian, Ta Li, Jinbo Xiong, Md. Zakirul Alam Bhuiyan, Jianfeng Ma 0001, Changgen Peng |
IEEE Trans. Ind. Informatics | 3 |
| 2022 | Edge-Cooperative Privacy-Preserving Object Detection Over Random Point Cloud Shares for Connected Autonomous VehiclesabstractConnected autonomous vehicles (CAVs) employ the point cloud data captured by LiDAR to enhance the capability of object recognition and detection. Edge computing with its inherent advantages can help CAVs alleviate resource constraints and enable faster situational awareness and data processing. However, the point cloud data contains private information, such as vehicle identity, location and trajectory, directly uploading the raw point cloud to the edge nodes or other vehicle will lead to serious privacy leakage. To the best of our knowledge, we are the first to try to tackle this challenge and propose a privacy-preserving object detection framework over random point cloud shares for CAVs (referred to SecPCV), aiming to guarantee the privacy of both point cloud and object detection results. In SecPCV, CAVs split point cloud into two random shares based on additive secret sharing (ASS) and upload them to two competing edge nodes, respectively, which greatly compress the computational load of CAVs. Without changing the object detection network in plaintext environment, the edge nodes can cooperatively and securely extract, regress, and classify over point cloud shares. Theoretical analysis ensure the efficiency and security of the SecPCV framework. Experimental results with the real KITTI point cloud dataset indicate that SecPCV can achieve the consistent object detection accuracy as that in plaintext environment, and provide a feasible solution for CAVs secure sharing of point cloud data. Renwan Bi, Jinbo Xiong, Youliang Tian, Qi Li 0011, Ximeng Liu |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2021 | Towards reducing delegation overhead in replication-based verification: An incentive-compatible rational delegation computing scheme
Zerui Chen, Youliang Tian, Jinbo Xiong, Changgen Peng, Jianfeng Ma 0001 |
Inf. Sci. | 3 |
| 2021 | Security Analysis and Improvements on a Remote Integrity Checking Scheme for Regenerating-Coding-Based Distributed StorageabstractEnabling remote data integrity checking with failure recovery becomes exceedingly critical in distributed cloud systems. With the properties of a lower repair bandwidth while preserving fault tolerance, regenerating coding and network coding (NC) have received much attention in the coding-based storage field. Recently, an outstanding outsourced auditing scheme named NC-Audit was proposed for regenerating-coding-based distributed storage. The scheme claimed that it can effectively achieve lightweight privacy-preserving data verification remotely for these networked distributed systems. However, our algebraic analysis shows that NC-Audit can be easily broken due to a potential defect existing in its schematic design. That is, an adversarial cloud server can forge some illegal blocks to cheat the auditor with a high probability when the coding field is large. From the perspective of algebraic security, we propose a remote data integrity checking scheme RNC-Audit by resorting to hiding partial critical information to the server without compromising system performance. Our evaluation shows that the proposed scheme has significantly lower overhead compared to the state-of-the-art schemes for distributed remote data auditing. Guangjun Liu 0002, Wangmei Guo, Ximeng Liu, Jinbo Xiong |
Secur. Commun. Networks | 4 |
| 2021 | CP-ABE-Based Secure and Verifiable Data Deletion in CloudabstractCloud data, the ownership of which is separated from their administration, usually contain users’ private information, especially in the fifth-generation mobile communication (5G) environment, because of collecting data from various smart mobile devices inevitably containing personal information. If it is not securely deleted in time or the result of data deletion cannot be verified after their expiration, this will lead to serious issues, such as unauthorized access and data privacy disclosure. Therefore, this affects the security of cloud data and hinders the development of cloud computing services seriously. In this paper, we propose a novel secure data deletion and verification (SDVC) scheme based on CP-ABE to achieve fine-grained secure data deletion and deletion verification for cloud data. Based on the idea of access policy in CP-ABE, we construct an attribute association tree to implement fast revoking attribute and reencrypting key to achieve fine-grained control of secure key deletion. Furthermore, we build a rule transposition algorithm to generate random data blocks and combine the overwriting technology with the Merkle hash tree to implement secure ciphertext deletion and generate a validator, which is then used to verify the result of data deletion. We prove the security of the SDVC scheme under the standard model and verify the correctness and effectiveness of the SDVC scheme through theoretical analysis and ample simulation experiment results. Jun Ma 0026, Minshen Wang, Jinbo Xiong, Yongjin Hu |
Secur. Commun. Networks | 3 |
| 2021 | An AI-Enabled Three-Party Game Framework for Guaranteed Data Privacy in Mobile Edge Crowdsensing of IoTabstractThe mobile crowdsensing (MCS) technology with a large number of Internet of Things (IoT) devices provides an economic and efficient solution to participation in coordinated large-scale sensing tasks. Edge computing powers MCS to form the mobile edge crowdsensing (MECS) framework. Privacy disclosure of sensing data in multiple stages is a significant challenge in the MECS. To tackle this issue, combining machine learning with game theory, in this article, we propose an artificial intelligence (AI)-enabled three-party game (ATG) framework for guaranteed data privacy in the MECS of IoT. Specifically, based on the random forest classifier and the k-anonymity algorithm, we propose a classification-anonymity model that effectively guarantees the privacy of sensitive data. Moreover, we construct a three-party game model for analyzing the data privacy leakage in different phases in the MECS. Finally, we conduct numerical and theoretical analyses and ample simulations. The results indicate that the ATG framework is effective and efficient, and better suited to the MECS of IoT. Jinbo Xiong, Mingfeng Zhao, Md. Zakirul Alam Bhuiyan, Lei Chen 0029, Youliang Tian |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | Location Privacy Protection Scheme for LBS in IoTabstractThe widespread use of Internet of Things (IoT) technology has promoted location‐based service (LBS) applications. Users can enjoy various conveniences brought by LBS by providing location information to LBS. However, it also brings potential privacy threats to location information. Location data that contains private information is often transmitted among IoT networks in LBS, and such privacy information should be protected. In order to solve the problem of location privacy leakage in LBS, a location privacy protection scheme based on k‐anonymity is proposed in this paper, in which the Geohash coding model and Voronoi graph are used as grid division principles. We adopt the client‐server‐to‐user (CS2U) model to protect the user’s location data on the client side and the server side, respectively. On the client side, the Geohash algorithm is proposed, which converts the user’s location coordinates into a Geohash code of the corresponding length. On the server side, the Geohash code generated by the user is inserted into the prefix tree, the prefix tree is used to find the nearest neighbors according to the characteristics of the coded similar prefixes, and the Voronoi diagram is used to divide the area units to complete the pruning. Then, using the Geohash coding model and the Voronoi diagram grid division principle, the G‐V anonymity algorithm is proposed to find k neighbors in an anonymous area so that the user’s location data meets the k‐anonymity requirement in the area unit, thereby achieving anonymity protection of location privacy. Theoretical analysis and experimental results show that our method is effective in terms of privacy and data quality while reducing the time of data anonymity. Hongtao Li 0002, Xingsi Xue, Long Li 0005, Jinbo Xiong |
Wirel. Commun. Mob. Comput. | 5 |
| 2020 | ms-PoSW: A multi-server aided proof of shared ownership scheme for secure deduplication in cloudabstractSummary Collaborative cloud applications have become the dominant application mode in the big data era. These applications usually generate plenty of cooperative files, which share their ownerships with all collaborative participants. Data deduplication is a promising solution to improve the storage efficiency and save the user expenditure. However, it remains an open issue on how to securely prove the shared ownerships for the shared files and address the attacks on account of using data deduplication. To tackle the above issue, in this paper, we introduce a novel concept of the Proof of Shared oWnership (PoSW) and construct a secure multi‐server‐aided PoSW (ms‐PoSW) scheme for securing client‐side deduplication for the shared files, which is based on the convergent encryption, secret sharing, and bloom filter. In the ms‐PoSW scheme, we employ a sharing convergent key to avoid the single point of failure, introduce the secret sharing algorithm to implement the shared ownership, and construct a novel interaction protocol between the shared owners and the cloud server to prove the shared ownership. Furthermore, a hybrid PoSW scheme is constructed to address the secure proof of hybrid cloud architectures. Finally, security analysis and performance evaluation show the security and efficiency of the proposed schemes. Jinbo Xiong, Yuanyuan Zhang 0009, Li Lin 0001, Jian Shen 0001, Xuan Li 0007, Mingwei Lin |
Concurr. Comput. Pract. Exp. | 1 |
| 2020 | A secure data deletion scheme for IoT devices through key derivation encryption and data analysis
Jinbo Xiong, Lei Chen 0029, Md. Zakirul Alam Bhuiyan, Chunjie Cao, Minshen Wang, Ximeng Liu |
Future Gener. Comput. Syst. | 1 |
| 2020 | A Blockchain-Based Secure Key Management Scheme With Trustworthiness in DWSNsabstractDynamic wireless sensor networks (DWSNs) as an important means of industrial data collection are a key part of industrial Internet of Things (IIoT), where security and reliability are important characteristics of trustworthiness. However, due to dynamics, the security of key management is caused by a nontrusted base station (BS) that is easily targeted. For the distribution key management scheme, the avianized BS also causes additional and heavy overhead on sensors. To tackle these issues, in this article, we propose a blockchain-based secure key management scheme (BC-EKM). First, stake blockchain is constructed based on the hybrid sensor network. In addition, we design a secure cluster formation algorithm and a secure node movement algorithm to implement key management, where stake blockchain as a trust machine replaces the majority functions of the BS. Finally, we conduct the security analysis and ample simulations. The results indicate that that the BC-EKM scheme is effective and efficient, and better suited to improve the trustworthiness of DWSNs in the IIoT. Youliang Tian, Zuan Wang, Jinbo Xiong, Jianfeng Ma 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2020 | A Personalized Privacy Protection Framework for Mobile Crowdsensing in IIoTabstractWith the rapid digitalization of various industries, mobile crowdsensing (MCS), an intelligent data collection and processing paradigm of the industrial Internet of Things, has provided a promising opportunity to construct powerful industrial systems and provide industrial services. The existing unified privacy strategy for all sensing data results in excessive or insufficient protection and low quality of crowdsensing services (QoCS) in MCS. To tackle this issue, in this article we propose a personalized privacy protection (PERIO) framework based on game theory and data encryption. Initially, we design a personalized privacy measurement algorithm to calculate users' privacy level, which is then combined with game theory to construct a rational uploading strategy. Furthermore, we propose a privacy-preserving data aggregation scheme to ensure data confidentiality, integrity, and real-timeness. Theoretical analysis and ample simulations with real trajectory dataset indicate that the PERIO scheme is effective and makes a reasonable balance between retaining high QoCS and privacy. Jinbo Xiong, Lei Chen 0029, Youliang Tian, Qi Li 0011, Ximeng Liu |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | A Privacy-Preserving Personalized Service Framework through Bayesian Game in Social IoTabstractIt is enormously challenging to achieve a satisfactory balance between quality of service (QoS) and users’ privacy protection along with measuring privacy disclosure in social Internet of Things (IoT). We propose a privacy-preserving personalized service framework (Persian) based on static Bayesian game to provide privacy protection according to users’ individual security requirements in social IoT. Our approach quantifies users’ individual privacy preferences and uses fuzzy uncertainty reasoning to classify users. These classification results facilitate trustworthy cloud service providers (CSPs) in providing users with corresponding levels of services. Furthermore, the CSP makes a strategic choice with the goal of maximizing reputation through playing a decision-making game with potential adversaries. Our approach uses Shannon information entropy to measure the degree of privacy disclosure according to the probability of game mixed strategy equilibrium. Experimental results show that Persian guarantees QoS and effectively protects user privacy despite the existence of adversaries. Renwan Bi, Qianxin Chen, Lei Chen 0029, Jinbo Xiong, Dapeng Wu 0002 |
Wirel. Commun. Mob. Comput. | 4 |
| 2019 | Privacy-preserving edge-assisted image retrieval and classification in IoT
Xuan Li 0007, Jin Li 0002, Siu-Ming Yiu, Chong-zhi Gao, Jinbo Xiong |
Frontiers Comput. Sci. | 5 |
| 2019 | Enhancing Privacy and Availability for Data Clustering in Intelligent Electrical Service of IoTabstractThe ever-growing demand for electrical energy of sensing devices in the Internet of Things (IoT) has led to generating large amounts of electricity consumption data. Electricity service providers often use wireless sensor networks to collect sensing devices' electricity consumption data for statistical analysis, so as to provide sensing devices with improved electrical services. As an important data mining technique, while data clustering excels in dealing with such massive data, it imposes the risk of privacy disclosure in the process of data clustering. In an effort of solving this problem, Blum et al. proposed a differential privacy k-means algorithm, effectively preventing privacy disclosure. However, the availability of data clustering results is reduced due to the data distortion in Blum's algorithm. In this paper, we propose a privacy and availability data clustering (PADC) scheme based on k -means algorithm and differential privacy, which enhances the selection of the initial center points and the distance calculation method from other points to center point. Moreover, PADC attempts to reduce the outlier effect through detecting outliers during the clustering process. Security analysis indicates that our scheme satisfies the goal of differential privacy and prevents privacy information disclosure. Meanwhile, performance evaluation shows that our scheme, at the same privacy level, improves the availability of clustering results compared to the existing differential privacy k-means algorithms, suggesting that our proposed PADC scheme outperforms others for intelligent electrical service in IoT. Jinbo Xiong, Lei Chen 0029, Mingwei Lin, Dapeng Wu 0002, Ben Niu 0001 |
IEEE Internet Things J. | 1 |
| 2018 | A Novel Data Secure Deletion Scheme for Mobile DevicesabstractWith the widespread adoption of mobile devices, an increasingly number of personal data are stored in mobile devices that using flash memory as storage medium. Personal data privacy may also be leaked because of unauthorized access or resale of mobile devices. How to effectively protect users' data privacy and securely delete invalid data, which brings a great challenge to the data secure deletion in flash memory. In order to tackle these problems, we propose a novel data secure deletion scheme based on key derivation encryption algorithm for mobile devices. Firstly, we construct a node key tree based on flash hierarchical structure, and propose a key derivation encryption algorithm to generate data key to encrypt user data. Furthermore, we combine partial block erasure with partial key deletion method to delete both the ciphertext data and the partial key component after expired. The security analysis shows that the proposed scheme is able to implement data privacy protect and secure deletion of invalid data. Performance analysis and experimental results indicate that the proposed scheme is effective and efficient. Minshen Wang, Jinbo Xiong, Qi Li 0011, Biao Jin 0004 |
ICCCN | 2 |
| 2018 | Distributed and Application-Aware Task Scheduling in Edge-CloudsabstractEdge computing is an emerging technology which places computing at the edge of the network to provide an ultra-low latency. Computation offloading, a paradigm that migrates computing from mobile devices to remote servers, can now use the power of edge computing by offloading computation to cloudlets in edge-clouds. However, the task scheduling of computation offloading in edge-clouds faces a two-fold challenge. First, as cloudlets are geographically distributed, it is difficult for each cloudlet to perform load balancing without centralized control. Second, as tasks of computation offloading have a wide variety of types, to guarantee the user quality of experience (QoE) in terms of task types is challenging. In this paper, we present Petrel, a distributed and application-aware task scheduling framework for edge-clouds. Petrel implements a sample-based load balancing technology and further adopts adaptive scheduling policies according to task types. This application-aware scheduling not only provides QoE guarantee but also improves the overall scheduling performance. Trace-driven simulations show that Petrel achieves a significant improvement over existing scheduling strategies. Li Lin 0001, Peng Li 0017, Jinbo Xiong, Mingwei Lin |
MSN | 3 |
| 2018 | Local HMM for indoor positioning based on fingerprinting and displacement rangingabstractReceived signal strength (RSS) in wireless networks is widely adopted for indoor positioning purpose because of its low cost and open access properties. However due to the sophisticated propagation of radio signals, the RSS shows a significant variation during pedestrian walking, which introduces critical errors in deterministic indoor positioning. To solve this problem, the authors present a novel method to improve the indoor pedestrian positioning accuracy by modelling fingerprinting and information on the movement into a hidden Markov models (HMMs). They divide the whole continuous positioning process into specified‐size sub‐processes, which could efficiently reduce the accumulative and resonance error caused by iterative estimation. They use an accelerometer sensor to provide the information on the movement distance to calculate the transition probability of the HMMs. In their experiments, they demonstrate that, compared with the deterministic pattern matching algorithm, the proposed method greatly improves the positioning accuracy and shows robust environmental adaptability. Ayong Ye, Jianfei Shao, Li Xu 0002, Jinbo Xiong |
IET Commun. | 5 |
| 2018 | RSE-PoW: a Role Symmetric Encryption PoW Scheme with Authorized Deduplication for Multimedia Data
Jinbo Xiong, Yuanyuan Zhang 0009, Xuan Li 0007, Mingwei Lin, Guangjun Liu 0002 |
Mob. Networks Appl. | 1 |
| 2018 | Achieving Incentive, Security, and Scalable Privacy Protection in Mobile Crowdsensing ServicesabstractMobile crowdsensing as a novel service schema of the Internet of Things (IoT) provides an innovative way to implement ubiquitous social sensing. How to establish an effective mechanism to improve the participation of sensing users and the authenticity of sensing data, protect the users’ data privacy, and prevent malicious users from providing false data are among the urgent problems in mobile crowdsensing services in IoT. These issues raise a gargantuan challenge hindering the further development of mobile crowdsensing. In order to tackle the above issues, in this paper, we propose a reliable hybrid incentive mechanism for enhancing crowdsensing participations by encouraging and stimulating sensing users with both reputation and service returns in mobile crowdsensing tasks. Moreover, we propose a privacy preserving data aggregation scheme, where the mediator and/or sensing users may not be fully trusted. In this scheme, differential privacy mechanism is utilized through allowing different sensing users to add noise data, then employing homomorphic encryption for protecting the sensing data, and finally uploading ciphertext to the mediator, who is able to obtain the collection of ciphertext of the sensing data without actual decryption. Even in the case of partial sensing data leakage, differential privacy mechanism can still ensure the security of the sensing user’s privacy. Finally, we introduce a novel secure multiparty auction mechanism based on the auction game theory and secure multiparty computation, which effectively solves the problem of prisoners’ dilemma incurred in the sensing data transaction between the service provider and mediator. Security analysis and performance evaluation demonstrate that the proposed scheme is secure and efficient. Jinbo Xiong, Lei Chen 0029, Youliang Tian, Li Lin 0001, Biao Jin 0004 |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | A Multi-replica Associated Deleting Scheme in CloudabstractRapid development of cloud storage services produces a tremendous amount of user data outsourcing to cloud servers. Therefore, it is easy to generate data multi-replica, which is able to improve data availability and users' experience. However, when the management of data is poor, the sensitive information will be disclosed more easily. This may bring serious security and privacy challenges for both user's data and its multi-replica in cloud environment. In order to tackle the above issues, in this paper, we propose a multi-replica associated deleting scheme (MADS) in cloud environment. We first introduce a replica associated model to organize all of data replicas among different cloud servers. Furthermore, we propose the MADS scheme which is consists of data storage algorithm, replica generation algorithm, replica deletion and feedback algorithm. Finally, we employ Amazon S3 to implement MADS and the results indicate that the proposed scheme is available and effective. Yuanyuan Zhang 0009, Jinbo Xiong, Xuan Li 0007, Biao Jin 0004, Suping Li, Xu An Wang 0014 |
CISIS | 2 |
| 2016 | A Secure Data Deduplication Scheme Based on Differential PrivacyabstractIn cloud computing environment, especially in big data era, adversary may use data deduplication service supported by the cloud service provider as a side channel to eavesdrop users' privacy or sensitive information. In order to tackle this serious issue, in this paper, we propose a secure data deduplication scheme based on differential privacy. The highlights of the proposed scheme lie in constructing a hybrid cloud framework, using convergent encryption algorithm to encrypt original files, and introducing differential privacy mechanism to resist against the side channel attack. Performance evaluation shows that our scheme is able to effectively save network bandwidth and disk storage space during the processes of data deduplication. Meanwhile, security analysis indicates that our scheme can resist against the side channel attack and related files attack, and prevent the disclosure of privacy information. Jinbo Xiong, Yuanyuan Zhang 0009, Ayong Ye |
ICPADS | 3 |
| 2016 | An efficient CGA algorithm against DoS attack on duplicate address detection processabstractNeighbor Discovery Protocol (NDP) is significant in mobile network, which enables mobile node randomly access to foreign network by Stateless Link Address Autoconfiguration (SLAAC). However, the NDP initially offers no protection mechanism and is prone to address spoofing and Denial of Service (DoS). Secure Neighbor Discovery Protocol (SeNDP) is proposed to solve these NDP threats. Recently there are many solutions presented in SeNDP which relies on special IPv6 addresses named Cryptographically Generated Address (CGA). But there is little work to defend DoS attack on Duplicate Address Detection (DAD). In our paper, we focus on the problems of CGA and propose a novel time-based monitoring DoS attack. The conventional DoS defense mechanisms are realized by monitoring the packet rating and observing connection delay to analyze various DoS attack. Hence, we adopt a delay as an indication to distinct the DoS attack. We set a timer to control the address generation for monitoring abnormal attack to protect each address configuration. In addition, we adopt SHA-224 hash function instead of SHA-1 to improve the security of address generation. Considering the computation overhead, we decrease the hash matching factor from 16 bits to 8 bits. We develop our scheme using the Network Simulator (NS2) and the OpenSSL library. Finally, experiment results prove our scheme can provide more efficient IP generation. Compared with the CGA algorithm in SeNDP, our time consumption decreases to 10%. From the view of defense attack, our scheme can control DoS attack. Jinbo Xiong, Qiong Wu 0002 |
WCNC | 2 |
| 2016 | Secure, efficient and revocable multi-authority access control system in cloud storage
Qi Li 0011, Jianfeng Ma 0001, Rui Li 0047, Ximeng Liu, Jinbo Xiong, Danwei Chen |
Comput. Secur. | 5 |
| 2015 | A full lifecycle privacy protection scheme for sensitive data in cloud computing
Jinbo Xiong, Fenghua Li 0001, Jianfeng Ma 0001, Ximeng Liu, Patrick S. Chen |
Peer-to-Peer Netw. Appl. | 1 |
| 2015 | Large universe decentralized key-policy attribute-based encryptionabstractAbstract In multi‐authority attribute‐based encryption (ABE) systems, each authority manages a different attribute universe and issues the private keys to users. However, the previous multi‐authority ABE schemes are subject to such restrictions during initializing the systems: either the attribute universe is polynomially sized and the attributes have to be enumerated or the attribute universe can be exponentially large, but the size of the set of attributes, which will be used in encryption, is not more than a predefined fixed value. These restrictions prevent multi‐authority ABE schemes from being deployed in dynamic practice applications. In this paper, we present a large universe decentralized key‐policy ABE scheme without such additional limitation. In our scheme, there is no requirement of any central authority. Each attribute authority executes independently from the others and can join or depart the system allodiality. Our system supports any monotone access policy. The proposed scheme is constructed on prime order groups and proved selectively secure in the standard model. To the best of our knowledge, our scheme is the first large universe decentralized key‐policy ABE system in the standard model. Copyright © 2014 John Wiley & Sons, Ltd. Qi Li 0011, Jianfeng Ma 0001, Rui Li 0047, Jinbo Xiong, Ximeng Liu |
Secur. Commun. Networks | 4 |
| 2015 | Provably secure unbounded multi-authority ciphertext-policy attribute-based encryptionabstractAbstract Multi‐authority attribute‐based encryption (ABE) is a generation of ABE where the descriptive attributes are managed by different authorities. In current multi‐authority ABE schemes, the scale of attribute universe employed in encryption is restricted by various predefined thresholds. In this paper, we propose an unbounded multi‐authority ciphertext‐policy ABE system without such restriction. Our scheme consists of multiple attribute authorities (AAs), one central authority (CA), and users labeled by the set of attributes. Each AA governs a different universe of attributes and operates separately. Moreover, there is no cooperation between the CA and AAs. To provide the private keys for a user, the AAs first issue partial attribute‐related keys according to the attributes; the CA then issues identity‐related keys and links these attribute‐keys with the user's global identifier. Both the identity‐related and the linked attribute‐related keys will be used in decryption. The proposed multi‐authority ciphertext‐policy ABE scheme can support arbitrary linear secret sharing scheme as the access policy. Performance analysis and security proof indicate that our scheme is efficient and secure. Copyright © 2015 John Wiley & Sons, Ltd. Qi Li 0011, Jianfeng Ma 0001, Rui Li 0047, Jinbo Xiong, Ximeng Liu |
Secur. Commun. Networks | 4 |
| 2014 | Trustworthy Service Composition in Service-Oriented Mobile Social NetworksabstractIn service-oriented mobile social networks (S-MSN), many location-based services are developed to provide various applications to social participants. Services can in turn be composed with the help of these participants. However, the composite structure, the subjective interpretation of trust demand, and the opportunistic connectivity make service composition a challenging task in S-MSN. In this paper, we propose a novel approach to enable trustworthy service evaluation and invocation during the process of composition. By analyzing dependency relationships, our approach can decentralizedly evaluate the trust degree of each service based on a lattice-based trust model to prevent data from being transmitted to untrustworthy counterparts. Besides, service consumers and vendors are able to specify their global and local constraints on the trust degree of service components on demand for more effective composition. Finally, by introducing acquaintances to the neighbors iteratively, social participants form a trust-aware acquaintance graph to forward invocation messages. Tao Zhang 0029, Jianfeng Ma 0001, Ning Xi 0002, Ximeng Liu, Zhiquan Liu 0001, Jinbo Xiong |
ICWS | 6 |
| 2014 | Threshold attribute-based encryption with attribute hierarchy for lattices in the standard modelabstractAttribute‐based encryption (ABE) has been considered as a promising cryptographic primitive for realising information security and flexible access control. However, the characteristic of attributes is treated as the identical level in most proposed schemes. Lattice‐based cryptography has been attracted much attention because of that it can resist to quantum cryptanalysis. In this study, lattice‐based threshold hierarchical ABE (lattice‐based t ‐HABE) scheme without random oracles is constructed and proved to be secure against selective attribute set and chosen plaintext attacks under the standard hardness assumption of the learning with errors problem. The notion of the HABE scheme can be considered as the generalisation of traditional ABE scheme where all attributes have the same level. Ximeng Liu, Jianfeng Ma 0001, Jinbo Xiong, Qi Li 0011, Tao Zhang 0029, Hui Zhu 0001 |
IET Inf. Secur. | 3 |
| 2014 | A Secure Data Self-Destructing Scheme in Cloud ComputingabstractWith the rapid development of versatile cloud services, it becomes increasingly susceptible to use cloud services to share data in a friend circle in the cloud computing environment. Since it is not feasible to implement full lifecycle privacy security, access control becomes a challenging task, especially when we share sensitive data on cloud servers. In order to tackle this problem, we propose a key-policy attribute-based encryption with time-specified attributes (KP-TSABE), a novel secure data self-destructing scheme in cloud computing. In the KP-TSABE scheme, every ciphertext is labeled with a time interval while private key is associated with a time instant. The ciphertext can only be decrypted if both the time instant is in the allowed time interval and the attributes associated with the ciphertext satisfy the key's access structure. The KP-TSABE is able to solve some important security problems by supporting user-defined authorization period and by providing fine-grained access control during the period. The sensitive data will be securely self-destructed after a user-specified expiration time. The KP-TSABE scheme is proved to be secure under the decision l-bilinear Diffie-Hellman inversion (l-Expanded BDHI) assumption. Comprehensive comparisons of the security properties indicate that the KP-TSABE scheme proposed by us satisfies the security requirements and is superior to other existing schemes. Jinbo Xiong, Ximeng Liu, Jianfeng Ma 0001, Qi Li 0011, Kui Geng, Patrick S. Chen |
IEEE Trans. Cloud Comput. | 1 |