VLDB 2026 Research / reviewers in the wild / expert
Jianfei Sun
dblp:41/11196
· DBLP profile ↗
38ranked-venue papers
16as first author
30since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 8 first-author · 18 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 6 since 2021Computer networks · 5 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-authorTheory of computation · 2Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Unsupervised deformable image registration with local-global attention and image decomposition
Zhengyong Huang, Xingwen Sun, Xuting Chang, Jianfei Sun, Hongbin Han, Yao Sui |
Expert Syst. Appl. | 6 |
| 2026 | Blockchain-Based Privacy-Preserving Alternative Credit Data SharingabstractIn comparison to the lending data submitted by banks to credit bureaus under the traditional credit scoring paradigm, alternative credit data (such as social media activities and e-commerce consumption records) has increasingly demonstrated its significance in enhancing the accuracy of credit scores and addressing the issue of credit-invisible individuals in recent years. However, credit scoring model based on alternative credit data typically necessitates large-scale data circulation and may involve sensitive information, thereby raising concerns related to data security, user privacy, and data rights. Traditional cryptographic methods often encounter limitations in functionality, efficiency, flexibility, and traceability when addressing these issues. This article initially proposes a novel credit data sharing framework based on an alternative data cloud platform. Subsequently, based on this framework, a blockchain-based privacy-preserving alternative credit data sharing scheme is constructed. This scheme achieves efficient, privacy-preserving, and wildcard-supported attribute-based encryption (ABE) scheme through inner product operations, and implements a “two-level” access control by designing a keyword search mechanism in conjunction with the aforementioned scheme. Furthermore, a hybrid encryption mechanism is introduced to further enhance efficiency and security under high-frequency access scenarios. Security analysis and rigorous formal security reductions have been conducted to demonstrate the security of the proposed scheme. Comparative experimental results also indicate that the proposed scheme exhibits significant advantages in practicality compared with related schemes. Yangyang Bao, Jianfei Sun, Xiaochun Cheng, Weidong Qiu, Liming Nie |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2026 | HyperSiniel: Guaranteed Output Delivery Comes (Almost) Free in Private Delegation of zkSNARKsabstractZero-knowledge Succinct Non-interactive Argument of Knowledge (zkSNARK) is a powerful cryptographic primitive that enables a prover to convince a verifier that something is true without leaking the private witness. Current zkSNARKs face significant computational costs in generating proofs, which restricts their use in areas like private payments, confidential smart contracts, and anonymous credentials. Private delegation offers a practical solution by outsourcing the heavy computation to powerful external workers without leaking any private information. In this work, we propose HyperSiniel, an efficient private delegation framework for general zkSNARKs that achieves a new feature called guaranteed output delivery (GOD). HyperSiniel is designed to be compatible with any universal zkSNARKs constructed from a polynomial interactive oracle proof (PIOP) and a polynomial commitment scheme (PCS). It enables a computationally limited delegator to outsource proof generation to several workers in a fully non-interactive and privacy-preserving manner. Compared to the most state-of-the-art frameworks (e.g., Siniel [NDSS'25]), HyperSiniel ensures that the delegator always receives a correct proof, regardless of malicious worker behavior. We implement HyperSiniel and compare the performance with Siniel across varying bandwidths and circuit sizes. Under low-bandwidth conditions (10MBps), HyperSiniel incurs only an additional 25% overhead compared with Siniel, while the total running time of HyperSiniel is almost identical to Siniel under high-bandwidth settings (1000MBps). These results show that the strong robustness guarantee of GOD in HyperSiniel comes almost for free, making it a practical and secure solution for real-world zkSNARK delegation. Yunbo Yang, Yuejia Cheng, Junkai Liang, Kailun Wang, Xuanming Liu, Xiaoguo Li, Jianfei Sun, Xiaolei Dong, Zhenfu Cao, Meng Hao 0001, Guomin Yang, Robert H. Deng, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | Adaptive Batched K-out-of-N Oblivious Transfers Extension
Huijie Yang, Jianfei Sun |
Inscrypt (2) | 4 |
| 2025 | An Efficient Security-Enhanced Accountable Access Control for Named Data Networking
Jianfei Sun, Xuehuan Yang, Guomin Yang, Robert H. Deng |
ESORICS (4) | 1 |
| 2025 | Siniel: Distributed Privacy-Preserving zkSNARK
Yunbo Yang, Yuejia Cheng, Kailun Wang, Xiaoguo Li, Jianfei Sun, Xiaolei Dong, Zhenfu Cao, Guomin Yang, Robert H. Deng |
NDSS | 5 |
| 2025 | Privacy-Preserving Fine-Grained Data Sharing With Dynamic Service for the Cloud-Edge IoTabstractThe cloud-edge computing model has been expected to play a revolutionary role in promoting the quality of future generation large-scale Internet of Things (IoT) services. However, security and privacy in data sharing remain crucial issues hindering the success of cloud-edge IoT services. While some solutions based on attribute-based encryption (ABE) have been proposed to address these issues, they still face practical challenges such as attribute privacy leakage, resource-constrained devices, dynamic user groups, inflexible and inefficient service response. To address these challenges, this paper proposes a privacy-preserving fine-grained data sharing scheme with dynamic service (PF2DS), which implements access control by calculating the inner product between an attribute vector and an access vector. PF2DS is also capable of providing dynamic user group services through an efficient and indirect user revocation mechanism that periodically updates the key-embedded leaf nodes. Building on PF2DS, edge-assisted PF2DS (EPF2DS) delegates most of the operations to the edge device, which facilitates the performance of resource-constrained IoT devices. EPF2DS also supports efficient and asynchronous keyword search over the ciphertexts stored in the cloud. We demonstrate the security by the rigorous security proof. Both theoretical comparisons and experimental simulations demonstrate the practicality and superiority of our schemes over existing works. Jianfei Sun, Yangyang Bao, Weidong Qiu, Rongxing Lu, Songnian Zhang, Yunguo Guan, Xiaochun Cheng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic AuthorizationabstractThe increasing demand for secure and efficient data sharing has underscored the importance of developing robust cryptographic schemes. However, many existing endeavors have overlooked the following critical issues: (1) unauthorized access resulting from malicious information leakage by senders; (2) absence of constraints on write and read permissions for participants; (3) and inflexibility of strategies to dynamically designate ciphertexts to multiple recipients. In this paper, we present SCPA, a cross-domain access control scheme imbued with sanitization features and propelled by policy-driven dynamic authorization, tailored for cloud-based data sharing. This scheme not only facilitates access controls, including regulations for no-read and no-write stipulations, governing the data permissible for senders to transmit and recipients to acquire but also enables the dynamic sharing of a data ciphertext subset with additional recipients beyond the originally sanctioned ones. We also provide comprehensive security proofs rigorously indicating the security of the invented SCPA. Moreover, to assess the efficacy of our SCPA, we undertake thorough theoretical and experimental analyses, showcasing its feasibility and superior performance. Jianfei Sun, Guowen Xu, Hongwei Li 0001, Tianwei Zhang 0004, Cong Wu 0003, Xuehuan Yang, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | AuditPCH: Auditable Payment Channel Hub With Privacy ProtectionabstractAnonymous Payment Channel Hub (PCH), one of the most promising layer-two solutions, settles the scalability issue in blockchain while guaranteeing the unlinkability of transacting parties. However, such developments bring conflicting requirements, i.e., hiding the sender-to-receiver relationships from any third party but opening the relationship to the auditor. Existing works do not support these requirements simultaneously since off-chain transactions are not recorded in the blockchain. Further, the privacy protection strategies hinder auditors from capturing the payment relationships. Thus, it is still a challenge to audit the finance activities of PCH transacting parties. This paper proposes a novel anonymous PCH solution called AuditPCH to achieve privacy and auditability. Concretely, we design a Linkable Randomizable Puzzle scheme for constructing conditional transactions, allowing a sender to pay for a receiver via the hub. As such, AuditPCH, with the new LRP scheme, ensures that 1) payment relationships can be protected from the hub and 2) an auditor with necessary trapdoors can associate the sender and receiver of a payment. We prove the security of AuditPCH under the Global Universal Composability framework. The extensive experimental evaluations on AuditPCH are established to demonstrate its functionality and flexibility. Jian Weng 0001, Junzuo Lai, Yingjiu Li, Jiahe Wu, Ming Li 0049, Jianfei Sun, Pengfei Wu 0003, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Forward-Secure Hierarchical Delegable Signature for Smart HomesabstractAiming to provide people with great convenience and comfort, smart home systems have been deployed in thousands of homes. In this paper, we focus on handling the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: 1) fine-grained, privacy-preserving authorization for smart home users and integrity protection of communication contents; 2) flexible self-sovereign permission delegation; 3) forward security of previous messages. To our knowledge, no previous system has been designed to consider these three security and privacy requirements simultaneously. To tackle these challenges, we put forward the first-ever efficient cryptographic primitive called the Forward-secure Hierarchical Delegable Signature (FS-HDS) scheme for smart homes. Specifically, we first propose a new primitive, efficient Hierarchical Delegable Signature (HDS) scheme, which is capable of supporting partial delegation capability while realizing privacy-preserving authorization and integrity guarantee. Then, we present an FS-HDS for smart homes with the efficient HDS as the underlying building block, which not only inherits all the desirable features of HDS but also ensures that the past content integrity is not affected even if the current secret key is compromised. We provide comprehensively strict security proofs to prove the security of our proposed solutions. Its performance is also validated via experimental simulations to showcase its practicability and effectiveness. Jianfei Sun, Guowen Xu, Yang Yang 0026, Xuehuan Yang, Xiaoguo Li, Cong Wu 0003, Zhen Liu 0008, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | $\mathsf{TCG}\text{-}\mathsf{IDS}$ : Robust Network Intrusion Detection via Temporal Contrastive Graph LearningabstractIn the era of zero trust security models and next-generation networks (NGN), the primary challenge is that network nodes may be untrusted, even if they have been verified, necessitating continuous validation and scrutiny. Effective intrusion detection systems (IDS) are crucial for continuously monitoring network traffic and identifying potential threats. However, traditional IDS approaches often struggle to keep pace with evolving threats, requiring extensive supervised training on labeled datasets. This limitation leads to high false positive rates, low detection accuracy, and a failure to provide real-time detection, thereby undermining the security of NGNs. This paper proposed the first self-supervised learning-based IDS, designed on temporal contrastive graph neural network (GNN), namely$\mathsf{TCG}\text{-}\mathsf{IDS}$. It innovatively integrates three contrastive learning strategies: temporal contrasting to capture temporal dependencies, asymmetric contrasting to account for the diverse interactions within network data, and masked contrasting to enhance the learning of node representations by masking parts of the data during training. Performance evaluation was conducted on two publicly available network traffic datasets, NF-CSE-CIC-IDS2018-V2 and NF-UNSW-NB15-V2.$\mathsf{TCG}\text{-}\mathsf{IDS}$achieved a balanced accuracy of 99.48% and 91.48% on two datasets respectively, significantly outperforming state-of-the-art graph learning models. In multi-class detection,$\mathsf{TCG}\text{-}\mathsf{IDS}$attained a mean false positive rate of 4.15% and 3.34% on the two datasets respectively. Besides, it exhibits high efficiency with its running time of 0.37s and 0.51s on the two datasets to predict per batch of 100 samples. Results highlight the effectiveness and efficiency of$\mathsf{TCG}\text{-}\mathsf{IDS}$in accurately detecting various types of network intrusions. This work significantly advances the field of network intrusion detection via self-supervised temporal graph learning, offering a promising solution for future network security systems. Cong Wu 0003, Jianfei Sun, Jing Chen 0003, Mamoun Alazab, Yang Liu 0003, Yang Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Breaking the Trilemma: Toward Efficient, Privacy-Preserving, and Forward-Secure Data Sharing in the Post-Quantum EraabstractCloud-based data sharing has emerged as a prevailing solution for enterprises and end users, supporting various online services in our daily lives. However, the current cloud security solutions are vulnerable to the “harvest now, decrypt later” threat imposed by future quantum computers. To encounter the threat, lattice-based cryptographic solutions for supporting cloud data encryption and search have been extensively investigated by both academia and industry. Despite these efforts, existing lattice-based schemes fall into a trilemma: (1) lack of efficient access control for data retrieval; (2) inadequate protection of keyword privacy in both ciphertext and search token; and (3) difficulty in realizing forward secrecy to safeguard historical data. These limitations result in a substantial burden for lattice-based solutions to be adopted in real-world cloud data sharing. To our knowledge, no prior work has comprehensively addressed these issues at the same time, motivating us to design a more flexible, efficient, and secure lattice-based solution. In this paper, we propose an efficient, privacy-preserving, and forward-secure data sharing framework centered around a novel primitive called Forward-Secure Authenticated Searchable Encryption (FS-ASE). Specifically, we first construct an Authenticated Searchable Encryption (ASE) scheme based on ideal lattices, enabling efficient one-to-many search functionality and ensuring keyword privacy in both ciphertext and search token. On top of this primitive, we present the FS-ASE scheme, which achieves forward secrecy through a highly efficient key evolution mechanism, thereby keeping the confidentiality of historical data even if the current secret key is compromised. Finally, the security of our construction is proven under the Ring Learning With Errors (RLWE) assumption, and experimental results show that it achieves performance improvements of 158× in data retrieval and 350× in token generation over state-of-the-art approaches, indicating its practicality in real use. Jian Weng 0001, Pengfei Wu 0003, Shixin Chen, Jianfei Sun, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Towards Privacy-aware IoT Communications: Delegable, Revocable, and EfficientabstractThe Internet of Things (IoT) is widely recognized for its potential to enhance efficiency and productivity across various industries. However, its increasing prevalence has also made it a more attractive target for cybercriminals. While many advanced cryptographic solutions have been developed to secure IoT, some practical security and privacy issues such as self-sovereign delegation, flexible revocation, and lightweight access remain inadequately addressed in existing solutions. In this paper, we propose PLIC, a Privacy-aware Lightweight IoT Communication scheme, which not only enables any authorized user to flexibly delegate their lightweight access privileges to other delegatees, such that they can also access the authorized IoT targets in the same lightweight way, but also supports flexible revocation of access for specific users without affecting non-revoked users. Specifically, our solution leverages wildcard-based access control and tree-based encryption technologies to enable self-sovereign delegation, dynamic membership updates, and stably efficient decryption overhead in IoT. In addition, comprehensive security proofs are rendered to validate the robustness of our approach. Finally, experimental comparisons with similar methodologies demonstrate the practicality and superior performance of our solution, which indicates its effectiveness for practical IoT appli-cations. Pengfei Wu 0003, Jianfei Sun, Guomin Yang, Robert H. Deng |
TrustCom | 2 |
| 2024 | Shield-U: Safeguarding Traffic Sign Recognition Against Perturbation AttacksabstractTraffic sign recognition systems are crucial for the navigation and situation awareness of autonomous vehicles. They leverage deep learning technologies to swiftly and accurately identify traffic signs, even in the most challenging traffic environments. However, security researchers have uncovered a critical vulnerability in these systems: learning-based TSRs are particularly susceptible to physical-world perturbation attacks. Through subtle modifications (i.e., attaching well-designed patches on traffic signs), attackers can deceive the recognition system into making erroneous judgments, which can further lead to serious traffic accidents. Although several defense mechanisms have been proposed to enhance the security of sign recognition systems, these solutions generally target only specific types of malicious perturbations and thus lack robustness. To address this issue, we present a robust defense mechanism named Shield-U, which restores traffic sign images contaminated by physical patch perturbations, providing credible data for the recognition model. In the process of implementing Shield-U, we first design a feature difference-aware perturbation generator that outputs potential sign contamination patterns. Incorporating generated perturbations during the training phase enables our restoration model to gain sufficient understanding of diverse perturbation types, thus enhancing its ability to repair various perturbed signs. Following this, we build an attention-driven restoration network to repair sign images. Finally, we evaluate the effectiveness of Shield-U using widely used sign recognition models and public datasets. The results demonstrate that our defense mechanism excels in resisting potential perturbations, increasing the average sign recognition accuracy by 50.4%. Shengmin Xu, Jianfei Sun, Hangcheng Cao, Yulan Gao, Cong Wu 0003 |
TrustCom | 2 |
| 2024 | An Efficient Privacy-Aware Split Learning Framework for Satellite CommunicationsabstractIn the rapidly evolving domain of satellite communications, integrating advanced machine learning techniques, particularly split learning, is crucial for enhancing data processing and model training efficiency across satellites, space stations, and ground stations. Traditional ML approaches often face significant challenges within satellite networks due to constraints such as limited bandwidth and computational resources. To address this gap, we propose a novel framework for more efficient SL in satellite communications. Our approach, Dynamic Topology-Informed Pruning, namely DTIP, combines differential privacy with graph and model pruning to optimize graph neural networks for distributed learning. DTIP strategically applies differential privacy to raw graph data and prunes GNNs, thereby optimizing both model size and communication load across network tiers. Extensive experiments across diverse datasets demonstrate DTIP’s efficacy in enhancing privacy, accuracy, and computational efficiency. Specifically, on Amazon2M dataset, DTIP maintains an accuracy of 0.82 while achieving a 50% reduction in floating-point operations per second. Similarly, on ArXiv dataset, DTIP achieves an accuracy of 0.85 under comparable conditions. Our framework not only significantly improves the operational efficiency of satellite communications but also establishes a new benchmark in privacy-aware distributed learning, potentially revolutionizing data handling in space-based networks. Jianfei Sun, Cong Wu 0003, Shahid Mumtaz, Junyi Tao, Mingsheng Cao 0001, Mei Wang 0003, Valerio Frascolla |
IEEE J. Sel. Areas Commun. | 1 |
| 2024 | OpenVFL: A Vertical Federated Learning Framework With Stronger Privacy-PreservingabstractFederated learning (FL) allows multiple parties, each holding a dataset, to jointly train a model without leaking any information about their own datasets. In this paper, we focus on vertical FL (VFL). In VFL, each party holds a dataset with the same sample space and different feature spaces. All parties should first agree on the training dataset in the ID alignment phase. However, existing works may leak some information about the training dataset and cause privacy leakage. To address this issue, this paper proposes OpenVFL, a vertical federated learning framework with stronger privacy-preserving. We first propose NCLPSI, a new variant of labeled PSI, in which both parties can invoke this protocol to get the encrypted training dataset without leaking any additional information. After that, both parties train the model over the encrypted training dataset. We also formally analyze the security of OpenVFL. In addition, the experimental results show that OpenVFL achieves the best trade-offs between accuracy, performance, and privacy among the most state-of-the-art works. Yunbo Yang, Yuhao Pan, Zhenfu Cao, Xiaolei Dong, Xiaoguo Li, Jianfei Sun, Guomin Yang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2024 | PkT-SIN: A Secure Communication Protocol for Space Information Networks With Periodic k-Time Anonymous AuthenticationabstractSpace Information Network (SIN) enables universal Internet connectivity for any object, even in remote and extreme environments where deploying a cellular network is difficult. Access authentication is crucial for ensuring user access control in SIN and preventing unauthorized entities from gaining access to network services. However, due to the complex communication environment in SIN, including exposed links and higher signal delay, designing a secure and efficient authentication scheme presents a significant challenge. In this paper, we propose a secure communication protocol for SIN with periodick-time anonymous authentication (named PkT-SIN) that allows satellite users to anonymously authenticate to ground stations at mostktimes in each single time period. An efficient handover mechanism is designed to ensure seamless communication for satellite users to communicate with different satellites and ground stations, taking into account the dynamic topology of SIN. As a core component of PkT-SIN, we propose a novel primitive, periodick-time keyed-verification anonymous credential (PkT-KVAC), that enables users to derivektokens from a credential for anonymous and unlinkable authentication. On the other hand, a verifier can always recognize a reused token from a dishonest user. PkT-KVAC is of independent contribution to anonymous authentication in pay-per-use business scenarios. Formal security proofs confirm that PkT-SIN and PkT-KVAC have desired security features. The supremacy of their computing features is demonstrated through comprehensive comparison and rigorous performance analysis. Yang Yang 0026, Wenyi Xue, Jianfei Sun, Guomin Yang, Yingjiu Li, HweeHwa Pang, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | A Tamper-Resistant Broadcasting Scheme for Secure Communication in Internet of Autonomous VehiclesabstractAs increasingly prevalent technologies in autonomous driving, 5G and the Internet of Things (IoT), Internet of autonomous vehicle (IoAV) technology is recognized as a technique that is capable of disruptively changing the way people travel and greatly improving the travel experience. In the IoAV scenarios, information dissemination is inseparable from the interaction between autonomous vehicles and smart infrastructure. However, existing efforts rarely focus on the secrecy, authenticity of interactive data and flexible one-to-many communication between autonomous vehicles. In this paper, we propose a tamper-resistant broadcasting (TRBS) scheme for secure communication, which handles the inefficiencies and insecurity of existing identity-based broadcast signcryption solutions. Not only can our TRBS protect communication data from being illegally accessed, forged, or tampered with by malicious vehicles, but it can also enable efficient and flexible secure information dissemination between autonomous vehicles. We also exhibit strict security proofs and experimental evaluations to demonstrate our TRBS is secure and efficient for real-world applications. Jianfei Sun, Junyi Tao, Yanan Zhao 0002, Liming Nie, Xiaochun Cheng, Tianwei Zhang 0004 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | Secure Source Identification Scheme for Revocable Instruction Sharing in Vehicle PlatoonabstractThe secure transmission of instructions among vehicles in a platoon is one of the most essential needs for a vehicle platoon. Despite the existence of cryptographic methods to securely share instructions, instruction sharing is still subject to forgery, tampering, and denial-of-service attacks. Therefore, it is urgent to find a solution to perform data source identification to filter out irrelevant information (not instructions) while ensuring the authenticity of encrypted instructions is urgent to address. In addition, immediate revocation of credentials is also a crucial requirement for a vehicle platoon when an authorized vehicle member misbehaves. In this paper, we propose the first Secure Source Identification Scheme for Revocable Instruction Sharing (SI-RIS) to securely simultaneously achieve bilateral fine-grained access control, data source identification, immediate vehicle user revocation, and efficient encryption in vehicle platoons. Specifically, our SI-RIS solution supports fine-grained access control for both the sender and receiver over the encrypted instructions. As a result, only authorized correspondents are able to access the commands. Furthermore, upon identification of malicious members in the platoon, our SI-RIS provides an efficient direct vehicle user revocation mechanism capable of immediate revocation credentials without affecting other vehicles. We prove the security of our SI-RIS via rigorous mathematical security proof. Moreover, performance evaluation and comparisons illustrate the feasibility and practicability of SI-RIS for vehicle platoon. Yanan Zhao 0002, Haiyang Yu 0002, Yuhao Liang, Alessandro Brighente, Mauro Conti, Jianfei Sun, Yilong Ren |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2024 | Joint Client-and-Sample Selection for Federated Learning via Bi-Level OptimizationabstractFederated Learning (FL) enables massive local data owners to collaboratively train a deep learning model without disclosing their private data. The importance of local data samples from various data owners to FL models varies widely. This is exacerbated by the presence of noisy data that exhibit large losses similar to important (hard) samples. Currently, there lacks an FL approach that can effectively distinguish hard samples (which are beneficial) from noisy samples (which are harmful). To bridge this gap, we propose the joint Federated Meta-Weighting based Client and Sample Selection (FedMW-CSS) approach to simultaneously mitigate label noise and hard sample selection. It is a bilevel optimization approach for FL client-and-sample selection and global model construction to achieve hard sample-aware noise-robust learning in a privacy preserving manner. It performs meta-learning based online approximation to iteratively update global FL models, select the most positively influential samples and deal with training data noise. To utilize both the instance-level information and class-level information for better performance improvements, FedMW-CSS efficiently learns a class-level weight by manipulating gradients at the class level, e.g., it performs a gradient descent step on class-level weights, which only relies on intermediate gradients. Theoretically, we analyze the privacy guarantees and convergence of FedMW-CSS. Extensive experiments comparison against eight state-of-the-art baselines on six real-world datasets in the presence of data noise and heterogeneity shows that FedMW-CSS achieves up to 28.5% higher test accuracy, while saving communication and computation costs by at least 49.3% and 1.2%, respectively. Anran Li 0001, Guangjing Wang 0001, Ming Hu 0003, Jianfei Sun, Lan Zhang 0002, Anh Tuan Luu, Han Yu 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | It's All in the Touch: Authenticating Users With HOST Gestures on Multi-Touch Screen DevicesabstractAs smartphones proliferate, secure and user-friendly authentication methods are increasingly critical. Existing behavioral biometrics, however, are often compromised by behavior variability, leading to poor authentication accuracy and an unsatisfactory user experience. To fill this gap, we proposeBioHold, a new robust and reliable user authentication method, fusing finger behavior and hand geometry, captured via a smartphone's multitouch screen during natural holding gestures. It synergistically fuses behavioral and physiological biometrics. In contrast to traditional methods that require restrictive, unnatural user patterns, our approach utilizes a stable, natural gesture for authentication, effectively mitigating behavior variability. It enables one-handed authentication through familiar smartphone-holding and unlocking gestures. During this interaction, hand geometry and behavioral characteristics are recorded for subsequent authentication. We evaluate our method using a dataset collected from 20 subjects, demonstrating its resilience against behavioral variability over time while maintaining a high level of distinctiveness. With only 10 training samples, our method achieves an equal error rate of 3.59%, which improves to 1.25% with 40 training samples. Importantly, our method is resistant to common security threats such as zero-effort attacks, smudge attacks, and shoulder surfing attacks. A usability study confirms the method's high user acceptance, as measured by the system usability score. Cong Wu 0003, Hangcheng Cao, Guowen Xu, Jianfei Sun, Ran Yan 0001, Yang Liu 0003, Hongbo Jiang 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | Share Your Data Carefree: An Efficient, Scalable and Privacy-Preserving Data Sharing Service in Cloud ComputingabstractBenefiting from the powerful computing and storage capabilities of cloud services, data sharing in the cloud has been permeated across various applications including social networks, e-health and crowdsourcing transportation system. Intuitively, outsourcing data to untrusted cloud commonly raises concerns about data privacy breaches. To combat this, one approach is exploiting Broadcast Based Searchable Encryption (BBSE) for secure data sharing. Nevertheless, the latest proposed BBSE is still defective in either security or efficiency. In this article, we propose ESPD, an Efficient, Scalable and Privacy-preserving Data sharing framework over encrypted cloud dataset. Different from previous works, ESPD supports sharing target data to multiple users with distinct secret keys, and keeps a constant ciphertext length with the changes of the amount of system users. This feature significantly improves search efficiency and makes ESPD scalable in real-world scenarios. We show a formal analysis to prove the security of ESPD in terms of file privacy, keyword privacy and trapdoor privacy. Also, extensive experiments on real-world dataset are conducted to indicate the desirable performance of ESPD compared to other similar schemes. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Hu Xiong, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Cloud Comput. | 1 |
| 2023 | Verifiable, Fair and Privacy-Preserving Broadcast Authorization for Flexible Data Sharing in CloudsabstractThe cloud-based data sharing technology with cryptographic primitives enables data owners to outsource data into paradigms and privately share information with arbitrary recipients without geographic barriers. However, we argue that most of existing efforts for outsourced data sharing are either inefficient, inflexible, or incompletely secure due to the following problems: (1) lack of efficient strategies for dynamically designating target ciphertexts to multiple recipients; (2) how to hide the identity of the recipient and (3) how to verify the correctness of outsourced ciphertext transformation without any denial. To the best of our knowledge, no previous work has thoroughly explored the above three issues, motivating us to design such an efficient and comprehensively secure outsourced data sharing mechanism. We design VF-PPBA, the first Verifiable, Fair and Privacy-preserving Broadcast Authorization framework for flexible data sharing in clouds. In more detail, we first invent a new primitive, privacy-preserving multi-recipient broadcast proxy re-encryption (PPMR-BPRE), which enables the authorization of a given ciphertext to different recipients with efficient ciphertext transformation, and further guarantees that any malicious adversary deduces nothing about the identity of the recipient. Then, we present VF-PPBA for flexible data sharing with PPMR-BPRE as the underlying structure, which in addition to inheriting all the functionalities of PPMR-BPRE, is capable of supporting the verifiability of the outcome correctness of the outsourced conversion task, and being immune to the malicious accusation if the outsourcing outcome is correctly completed. We formalize the adversarial models and render comprehensively strict security proofs to prove the security of our proposed solutions. Its performance is also validated via experimental simulations to showcase the practicability and effectiveness. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Xuehuan Yang, Mamoun Alazab, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Privacy-Aware and Security-Enhanced Efficient Matchmaking EncryptionabstractData sharing technologies enable users to outsource data and privately share information with arbitrary recipients without geographic barriers. However, existing efforts for secure data sharing are either inflexible, insufficiently-secure or inefficient. In this paper, we invent PS-ME, the first Privacy-aware and Security-enhanced efficient Matchmaking Encryption (ME) for flexible data sharing. To be more specific, we first formulate an identity-based broadcast matchmaking encryption (IB-BME) for one-to-many data sharing, which enables both participants to specify respective access policies to the encrypted data, such that the data can be revealed by multiple recipients in the case that both access policies are satisfied. In IB-BME, a general matchmaking transformation solution realizing one-to-many sharing is initialized. We also formulate the PS-ME with the general matchmaking transformation solution of IB-BME as the underlying approach, which in addition to featuring IB-BME’s all desirable properties, enables efficient decryption, identity anonymity and CCA-security, where we address the open problem of ME regarding CCA-security (raised in CRYPTO’2019). Finally, the comprehensively rigorous security proofs indicate the security of the suggested methodologies. The experimental results are also shown to demonstrate their practicability and effectiveness. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Xuehuan Yang, Mamoun Alazab, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Fine-Grained Data Sharing With Enhanced Privacy Protection and Dynamic Users Group Service for the IoVabstractThe Internet of Vehicles (IoV) is expected to play a revolutionary role in improving users’ driving experience and urban traffic governance. By widely absorbing emerging technologies including cloud computing, the future IoV evolution is leading towards providing more flexible and diversified data services. However, the publicly accessible IoV environment arouses the user’s concerns about the leakage of data and personal privacy. Despite some cryptographic solutions have been proposed, they still raise challenges on privacy, efficiency and usability. To cope with these challenges, this paper first presents an efficient scheme PH-ABE-DS, which attains the full policy hiding by implementing the access control with the inner product. Besides, we design an efficient indirect revocation mechanism, to enable the cloud and users to update the ciphertext and user secret key with slight storage and computational overheads. On this basis, we then present the EA-PH-ABE-DS scheme, by resorting to edge computing, it further reduces the overheads of resource-constrained devices. We design a deployment model for EA-PH-ABE-DS in IoV to discuss its usability. Rigorous security proof and security properties analysis show that our proposal is secure and reliable. Finally, through detailed comparisons on theoretical and experimental, both our two schemes show their superiority over the latest related works in terms of functionality and performance. The simulation evaluates and demonstrates the practicality of our solutions in practical IoT scenarios. Yangyang Bao, Weidong Qiu, Xiaochun Cheng, Jianfei Sun |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2023 | Secure Data Sharing With Flexible Cross-Domain Authorization in Autonomous Vehicle SystemsabstractAs an increasingly prevalent technology in intelligent autonomous transportation systems, autonomous vehicle platoon has been indicated the ability to significantly reduce fuel consumption as well as heighten highway safety and throughput. However, existing efforts rarely focus on protecting data confidentiality and authenticity in autonomous vehicle platoons. How to ensure secure and high-fidelity platoon-level communication is still in its infancy. This paper makes the first attempt for efficient and secure communication across autonomous vehicle platoons. Specifically, we presentPDSM-FC, the first privacy-preserving data share mechanism with flexible cross-domain authorization over distinctive platoons. The key insight ofPDSM-FCis the design of a new ciphertext conversion technique, which allows a ciphertext to be easily converted into another type of ciphertext, facilitating efficient access by all entities holding the legitimate authorization. As a result,PDSM-FCcan achieve high-fidelity data communication between two unique platoons in ciphertext, so as to complete specific tasks including platoon integration. Rigorous security analysis shows thatPDSM-FCis secure against various attacks such as collusion, forgery and chosen-plaintext attacks. Moreover, theoretical evaluation and extensive experiments demonstrate the practicability ofPDSM-FCin terms of functionality, storage and computation overheads. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Xiaochun Cheng, Xingshuo Han, MingJian Tang 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | A Practical Fog-Based Privacy-Preserving Online Car-Hailing Service SystemabstractAiming for minimizing passengers waiting time and vehicles vacancy rate, online car-hailing service systems with fog computing has been deployed in various scenarios. In this paper, we focus on addressing the security and privacy issues in such a promising system by customizing a new cryptographic primitive to provide the following security guarantees: (1) private, fine-grained and bilateral order matching between passengers and drivers; (2) authenticity verification of passengers orders in the form of ciphertext, and (3) temporal assurance of passengers’ ciphertext orders. To the best of our knowledge, no previous system has been designed to meet all three requirements. Existing cryptographic primitives (including forward/puncturable encryption (FE/PE) and attribute based matchmaking encryption (AB-ME)) may be leveraged to partially address some of challenges, but there lacks a comprehensive solution. Moreover, the integration of existing works is hampered by the heterogeneity and the weak coupling between distinct cryptographic primitives. As a result, it is infeasible to directly exploit them for the online car-hailing service. To tackle that, we put forward a new cryptographic primitive called Fine-grained Puncturable Matchmaking Encryption (FP-ME) by modifying AB-ME and incorporating PE technology. FP-ME can simultaneously implement fine-grained and bilateral order matching, the authenticity of passengers orders, and meeting the time constraint of passengers orders. We formalize the adversarial models for the proposed FP-ME and then present rigorous security analysis to prove the security of the proposed system. Additionally, we study performance of the system via simulations to demonstrate its practicability and effectiveness in the real-world applications. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Mamoun Alazab, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Privacy-Preserving Bilateral Fine-Grained Access Control for Cloud-Enabled Industrial IoT HealthcareabstractThe expeditious development in cloud-enabled industrial Internet of Things (IIoT) healthcare has significantly reduced the costs to monitor and protect people at home while notably improving the quality of human healthcare. Despite its considerable convenience and benefits, it confronts some security and privacy challenges in the aspects of bilateral fine-grained access control, the authenticity and tamper resistance of shared health data. To tackle these constraints, a secure privacy-preserving bilateral access control scheme with fine granularity (PBAC-FG) is proposed in this article. Our PBAC-FG exploits fine-grained access control and matchmaking encryption technologies to ensure both participants (e.g., patients and healthcare providers) can specify their respective fine-grained access control over the encrypted health data, such that only authorized counterparts can efficiently access the health data. Besides, the correct rigorous security proofs are indicated to verify that our PBAC-FG is indeed secure. We carry out comprehensive performance evaluations and comparisons to demonstrate the efficiency and practicality of the PBAC-FG for IIoT healthcare applications. Jianfei Sun, MingJian Tang 0001, Xiaochun Cheng, Xuyun Nie, Muhammad Umar Aftab |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | A Privacy-Aware and Traceable Fine-Grained Data Delivery System in Cloud-Assisted Healthcare IIoTabstractThe emerging of healthcare Industrial Internet of Things (HealthIIoT) cannot only facilitate high-quality care services for patients but also enable efficient telemedicine platform for healthcare practitioners. However, it faces several fundamental security and privacy challenges, such as secure fine-grained data delivery, privacy preserving keyword-based ciphertext retrieval, malicious key delegation, and efficiency of the system. To combat these issues, we propose a privacy-aware and traceable fine-grained system (PTFS) for secure data delivery in cloud-assisted HealthIIoT. Compared to the existing solutions that only implement some of the preceding features, the proposed solution enables secure fine-grained data delivery, privacy-preserving data retrieval, efficient encryption and decryption operations, and trace of malicious key delegation simultaneously. For security analysis, rigorous proofs of the proposed scheme are provided to prove its security. In addition, extensive simulations and experiments are conducted for performance evaluation, which demonstrate the feasibility and effectiveness of PTFS. Jianfei Sun, Dajiang Chen, Ning Zhang 0007, Guowen Xu, MingJian Tang 0001, Xuyun Nie, Mingsheng Cao 0001 |
IEEE Internet Things J. | 1 |
| 2021 | On the Security of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-Owner SettingabstractRecently in the IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2019.28976752019), Miao et al. proposed a novel construction of Privacy-Preserving Attribute-Based Keyword Search in Shared Multi-owner Setting (ABKS-SM), which can delegate keyword search tasks to cloud server provider (CSP) without revealing any useful information. Although the authors claimed that the offline keyword guessing attacks can be resisted in ABKS-SM scheme, we show that this scheme indeed suffers from four types of offline keyword guessing attacks and hence fails to gain the claimed security property, which is an important goal to be achieved in searchable encryption schemes. Specifically, given the concrete attacks, we demonstrate that the underlying keyword information can be extracted from both encrypted keyword indexes and trapdoors by any malicious user and any adversarial CSP. We hope that the similar security vulnerabilities could be avoided in the future design of related searchable encryption schemes. Jianfei Sun, Hu Xiong, Xuyun Nie, Yinghui Zhang 0002, Pengfei Wu 0003 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Secure and Verifiable Inference in Deep Neural NetworksabstractOutsourced inference service has enormously promoted the popularity of deep learning, and helped users to customize a range of personalized applications. However, it also entails a variety of security and privacy issues brought by untrusted service providers. Particularly, a malicious adversary may violate user privacy during the inference process, or worse, return incorrect results to the client through compromising the integrity of the outsourced model. To address these problems, we propose SecureDL to protect the model’s integrity and user’s privacy in Deep Neural Networks (DNNs) inference process. In SecureDL, we first transform complicated non-linear activation functions of DNNs to low-degree polynomials. Then, we give a novel method to generate sensitive-samples, which can verify the integrity of a model’s parameters outsourced to the server with high accuracy. Finally, We exploit Leveled Homomorphic Encryption (LHE) to achieve the privacy-preserving inference. We shown that our sensitive-samples are indeed very sensitive to model changes, such that even a small change in parameters can be reflected in the model outputs. Based on the experiments conducted on real data and different types of attacks, we demonstrate the superior performance of SecureDL in terms of detection accuracy, inference accuracy, computation, and communication overheads. Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Jianfei Sun, Shengmin Xu, Jianting Ning, Haomiao Yang, Kan Yang 0001, Robert H. Deng |
ACSAC | 4 |
| 2020 | Catch You If You Deceive Me: Verifiable and Privacy-Aware Truth Discovery in Crowdsensing SystemsabstractTruth Discovery (TD) is to infer truthful information by estimating the reliability of users in crowdsensing systems. To protect data privacy, many Privacy-Preserving Truth Discovery (PPTD) approaches have been proposed. However, all existing PPTD solutions do not consider a fundamental issue of trust. That is, if the data aggregator (e.g., the cloud server) is not trustworthy, how can an entity be convinced that the data aggregator has correctly performed the PPTD? A "lazy" cloud server may partially follow the deployed protocols to save its computing and communication resources, or worse, maliciously forge the results for some shady deals. In this paper, we propose V-PATD, the first Verifiable and Privacy-Aware Truth Discovery protocol in crowdsensing systems. In V-PATD, a publicly verifiable approach is designed enabling any entity to verify the correctness of aggregated results returned from the server. Since most of the computation burdens are carried by the cloud server, our verification approach is efficient and scalable. Moreover, users' data is perturbed with the principles of local differential privacy. Security analysis shows that the proposed perturbation mechanism guarantees a high aggregation accuracy even if large noises are added. Compared to existing solutions, extensive experiments conducted on real crowdsensing systems demonstrate the superior performance of V-PATD in terms of accuracy, computation and communication overheads. Guowen Xu, Hongwei Li 0001, Shengmin Xu, Hao Ren 0001, Yinghui Zhang 0002, Jianfei Sun, Robert H. Deng |
AsiaCCS | 6 |
| 2020 | Lightweight and Privacy-Aware Fine-Grained Access Control for IoT-Oriented Smart HealthabstractWith the booming of Internet of Things (IoT), smart health (s-health) is becoming an emerging and attractive paradigm. It can provide an accurate prediction of various diseases and improve the quality of healthcare. Nevertheless, data security and user privacy concerns still remain issues to be addressed. As a high potential and prospective solution to secure IoT-oriented s-health applications, ciphertext policy attribute-based encryption (CP-ABE) schemes raise challenges, such as heavy overhead and attribute privacy of the end users. To resolve these drawbacks, an optimized vector transformation approach is first proposed to efficiently transform the access policy and user attribute set into respective vectors of shorter length while other approaches result in redundant and longer vectors. Our transformation approach can greatly relieve the costly overheard of key generation, encryption, and decryption phases. Then, based on the transformation approach and the offline/online computation technology, we propose a lightweight policy-hiding CP-ABE scheme for the IoT-oriented s-health application. With our proposed scheme, data users in the s-health system can perform lightweight encryption and decryption without leaking any sensitive privacy about the attributes of the user. Finally, the formal security analysis, the theoretic performance evaluation and experiment results indicate that the solution is secure and efficient. Jianfei Sun, Hu Xiong, Ximeng Liu, Yinghui Zhang 0002, Xuyun Nie, Robert H. Deng |
IEEE Internet Things J. | 1 |
| 2020 | Mobile access and flexible search over encrypted cloud data in heterogeneous systems
Jianfei Sun, Hu Xiong |
Inf. Sci. | 1 |
| 2018 | Comments on "A secure anti-collusion data sharing scheme for dynamic groups in the cloud"
Jianfei Sun, Hu Xiong, Zhiguang Qin |
Inf. Process. Lett. | 3 |
| 2017 | Comments on "Circuit ciphertext-policy attribute-based hybrid encryption with verifiable delegation"
Hu Xiong, Jianfei Sun |
Inf. Process. Lett. | 3 |
| 2017 | Comments on "Verifiable and Exculpable Outsourced Attribute-Based Encryption for Access Control in Cloud Computing"abstractRecently in IEEE Transactions on Dependable and Secure Computing (TDSC) (doi: 10.1109/TDSC.2015.2499755), Ma et al. proposed a new construction of attribute-based encryption (ABE) which can outsource the complicated encryption task to Encryption Service Provider (ESP) in a verifiable manner. Despite the authors claimed that the results of the outsourced encryption can be checked by the user, we show that Ma et al.'s proposal fails to provide the verifiability property for outsourced encryption, the most essential security goal that a verifiable computation scheme should achieve. Specifically, by giving concrete attacks, we demonstrate that the ESP can return forged intermediate ciphertext to the user without being detected. Hu Xiong, Jianfei Sun |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | Improvement of Virtual View Rendering Based on Depth ImageabstractVirtual view rendering has great importance in 3-D display. In order to get high-quality image of an arbitrary view from 2-D source image, improvement on depth-image based rendering (DIBR) is studied in this paper. By analyzing the process of virtual view rendering of DIBR, an improved method is proposed, which generates new view by modifying parallax of two views and incorporating image in painting. The parallax is deduced from depth information, and modified afterwards according to parallax gradient, so as to reduce hole regions before generating new view by 3-D image warping. To further remove the remaining holes, image in painting combining texture and depth information is incorporated. Experimental results show the superiority of the proposed method. Jianfei Sun |
ICIG | 2 |