VLDB 2026 Research / reviewers in the wild / expert
Bei Gong
dblp:45/10403
· DBLP profile ↗
61ranked-venue papers
11as first author
53since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 26 · 3 first-author · 20 since 2021Systems, architecture and hardware · 13 · 4 first-author · 12 since 2021Security and privacy · 12 · 3 first-author · 12 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Vulnerability-Type Correlation-Aware Smart Contract Multivulnerability Detection ModelabstractBlockchain technology has been widely used in the field of Internet of Things, providing effective support for solving security challenges in Internet of Things systems. However, due to the immature development language and deployment platform, smart contracts are prone to various vulnerabilities. Considering the immutability of smart contracts, efficient vulnerability detection before deployment is particularly critical. The existing detection methods have two main limitations: they can only identify a limited number of specific vulnerabilities, resulting in low coverage; the implicit correlation information between vulnerability types is ignored. In order to solve these problems, this paper proposes a smart contract multi-vulnerability detection model CorrelaScan (correlation-aware smart contract analyzer) that integrates vulnerability type correlation awareness. The model is based on a multi-task learning architecture, including a shared layer and a specific task layer. The shared layer uses BERT to extract shared features, while the specific task layer uses BiGRU to learn specific task features for vulnerability detection and type classification. In addition, a vulnerability type embedding module is integrated in the task-specific layer. The module mines potential associations by calculating the similarity between smart contract opcodes and vulnerability types, thereby enhancing detection guidance and improving model performance. Experimental verification on public datasets shows that the model can simultaneously detect 10 types of vulnerabilities such as integer overflow or underflow, reentrancy and timestamp dependence, with an average F1 value of 85.22%. Its detection performance exceeds the current state-of-the-art methods. Jing Huang 0003, Honggui Han, Bei Gong |
IEEE Internet Things J. | 4 |
| 2026 | LTRAA: Lightweight and transparent remote attestation with anonymity
Tao Shen 0004, Zikang Wang, Xianlin Yang, Fenhua Bai, Kai Zeng 0005, Chi Zhang 0121, Bei Gong |
J. Inf. Secur. Appl. | 7 |
| 2026 | Hela: A System Call Restriction Framework for Protecting the Entire Containers LifecycleabstractLimiting the number of system calls used by container processes can effectively reduce the kernel attack surface. Existing container system call restriction schemes only focus on the minimum system call set of applications in containers, and lack restrictions on the container runtime runc and other container components that create containers. To solve these problems, this paper proposes Hela, a system call restriction framework that can limit container runtimes and container applications. Hela introduces the Attack Surface Exposure Score (ASES), defined as the dot product of a container's system call usage vector and a risk-weight vector, to quantify exposure. Hela calculates and compares the ASES indicators of various partitioning schemes and selects the best partitioning boundary in the common hook nodes of runc. Hela divides the container creation phase into two phases and generates a minimum set of system calls for each phase. The advantage of Hela is that it combines seccomp with eBPF to achieve accurate parameter checking and efficient system call whitelist switching. Experimental results show that Hela can reduce the kernel attack surface of runc in container runtime compared to traditional schemes. Security experiments prove that our method can mitigate vulnerabilities involving runc and system call parameters. Shaohu Li 0001, Jin Zhou 0017, Weizhi Meng 0001, Bei Gong |
IEEE Trans. Cloud Comput. | 5 |
| 2026 | LAHENet: A Lightweight Additive Homomorphic Edge Neural Network Framework for Industrial IoTabstractEdge nodes in the Industrial Internet of Things (IIoT) often face a fundamental trade-off between limited computational resources and stringent real-time inference requirements. Moreover, sensitive data they generated are exposed to significant privacy and security threats during transmission and computation. To address these challenges, this paper proposes a lightweight additive homomorphic edge neural network framework called LAHENet. This framework achieves millisecond-level inference latency in real-world industrial environments through a combination of a dual-metric feature selection strategy, an efficient additive homomorphic signcryption protocol, and a lightweight linear computation layer with adaptive layer collapsing. It ensures end-to-end confidentiality, unforgeability, forward security, and verifiable computation correctness. Experimental results show that LAHENet maintains a constant communication overhead at a few kilobytes per inference while preserving high model accuracy. It significantly enhances inference efficiency and reduces bandwidth consumption in edge environments, offering a practical private inference solution for large-scale IIoT deployments. Mowei Gong, Zhe Li 0052, Xuepeng Lu, Bei Gong, Weizhi Meng 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | SUAD: A Secure Attribute-Based Data Sharing Framework with User-Controlled Key Management for Cloud-Assisted IoTabstractCloud computing supports the Internet of Things (IoT) in handling diverse and large-scale data. However, outsourcing data control to the cloud raises security concerns, particularly in key management. Although Ciphertext-Policy Attribute-Based Encryption (CP-ABE) preserves data confidentiality, it entrusts key management to a centralized attribute authority, resulting in the key escrow problem. Furthermore, existing CP-ABE schemes lack mechanisms for key verification and identity authentication, leaving IoT systems susceptible to key errors and impersonation attacks. To overcome these limitations, we propose Secure and User-autonomous Attribute-based Data Sharing (SUAD) for cloud-assisted IoT. The SUAD scheme transfers key management from the authority to data users themselves, thereby eliminating key escrow. Built on a data user-centric architecture, the SUAD scheme removes the decryption privilege of the attribute authority. To prevent key forgeries and operational errors, we design a correctness verification mechanism covering five critical keys and the decryption result, along with a two-way interactive authentication protocol based on the Schnorr scheme for reliable identity verification. The SUAD scheme further supports dynamic user management, enabling user logout, replacement, and joining while optimizing maintenance overhead through periodic updates. We formally prove that SUAD achieves selective IND-CCA security in the random oracle model. Both theoretical analysis and experimental evaluations demonstrate that SUAD enhances user autonomy and strengthens security without incurring additional encryption or decryption costs, confirming its practicality for IoT deployments. Bei Gong, Akhtar Badshah, Xin Ai 0009, Hisham Alasmary, Muhammad Waqas 0001, Muhammad Taimoor Khan 0001 |
ACM Trans. Priv. Secur. | 2 |
| 2026 | Efficient Privacy-Preserving Conjunctive Searchable Encryption for Cloud-IoT Healthcare SystemsabstractIn cloud-Internet of Things (IoT) healthcare systems, private medical data leakage is a serious concern as the cloud server is not fully trusted. Dynamic searchable symmetric encryption (DSSE), with necessary forward and backward privacy security properties, enables doctors to retrieve ciphertexts while guaranteeing data privacy. However, existing forward and backward private DSSE schemes are not well-suited for cloud-IoT healthcare systems with attribute-value type databases. To this end, we propose an efficient privacy-preserving conjunctive searchable encryption scheme for cloud-IoT healthcare systems, called PC-SE. It is the first conjunctive DSSE scheme designed for attribute-value type databases. Specifically, we design flexible search capabilities for PC-SE to address users’ various search requirements. It can not only achieve precise conjunctive search based on keywords but also realize broad attribute search. Moreover, our scheme achieves fine-grained search for attribute values while maintaining forward and Type-I - backward privacy. This approach reduces the communication burden and minimizes the risk of privacy exposure. To ensure that users with different authorities can only access the corresponding attribute values, we introduce an attribute access control mechanism in PC-SE. Finally, security analysis and experimental results demonstrate that PC-SE is secure and effective. Jiadi Ma, Tianqi Peng, Bei Gong, Muhammad Waqas 0001, Hisham Alasmary, Sheng Chen 0013 |
ACM Trans. Priv. Secur. | 3 |
| 2026 | TruChord: A Secure Communication Framework for Hybrid SDIoT Architecture Based on Chord Overlay
Bei Gong, Zahid Halim, Hisham Alasmary, Muhammad Waqas 0001, Iftekhar Ahmad |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | ROMA: Enhancing Container OOM Resilience via Reinforced Isolation and Adaptive Shared Resource ReclamationabstractContainer-based virtualization is a cornerstone of modern cloud orchestration, but the shared-kernel architecture also introduces subtle risks to memory isolation. Our study shows that Linux cgroups and the default Out-of-Memory (OOM) mechanism lack sufficient container context when selecting victim processes. As a result, a malicious container may disrupt critical co-located services and leave behind unreclaimed shared resources, such as POSIX/SysV shared memory, message queues, semaphores, and tmpfs files. These residual resources can accumulate over time and eventually lead to denial-of-service conditions. To address this problem, we propose ROMA, an adaptive memory-governance framework for containerized environments. ROMA introduces container awareness into the OOM handling path while maintaining low runtime overhead. It combines eBPF-based monitoring with two lightweight LSM hooks to confine OOM victim selection to the offending container and to proactively reclaim shared resources left behind after OOM events. Extensive experiments show that ROMA incurs only a 6.94% throughput overhead across eight workloads. Under up to eight concurrent attackers, ROMA preserves isolation, avoids collateral kills, reclaims all leaked resources, and keeps recovery time within 6.9 seconds. In 24-hour runs with up to 64 containers, ROMA remains stable with low CPU and memory overhead, negligible event loss, and limited impact on benign services. Shaohu Li 0001, Jin Zhou 0017, Weizhi Meng 0001, Bei Gong, Yong Wang 0028 |
IEEE Trans. Serv. Comput. | 6 |
| 2025 | ZKSA: Secure mutual Attestation against TOCTOU Zero-knowledge Proof based for IoT Devices
Fenhua Bai, Zikang Wang, Kai Zeng 0005, Chi Zhang 0121, Tao Shen 0004, Xiaohui Zhang 0019, Bei Gong |
Comput. Secur. | 7 |
| 2025 | GAPLG: Graph Augmented With Pseudolabels Generation for Blockchain Anomaly Transaction DetectionabstractCryptocurrencies, underpinned by blockchain technology, face persistent threats such as money laundering and extortion due to their decentralized and anonymous nature. Detecting fraudulent transactions is crucial for ensuring the security of block-chain systems. However, the existing detection methods face the following challenges: lack of labeled data, severe class imbalance in labeled data, complex network structure, numerous parameters, and long training time. To address these challenges, we propose a novel semisupervised learning framework that combines the graph augmented with pseudolabels generation (GAPLG) model and postprocessing technique. Our framework employs graph learning networks to elucidate relationships between transactions and users. By utilizing pseudolabels for unlabeled transaction data and embedding them onto diverse graph nodes, we achieve precise labels, enhancing prediction accuracy. Additionally, we employ specific post-processing technique, such as correction and smoothing (C&S) technology, to rectify residuals and refine labels, ensuring our framework rivals the best parameter and baseline models. Our method boasts high scalability and flexibility, aiding in optimizing various evaluation indicators. Experimental verification through multiple real transaction datasets under varying data segmentations, demonstrated its effectiveness when compared with other representative frameworks. The analysis validates the effectiveness and benefits of our method. Jing Huang 0003, Kuijian Bu, Honggui Han, Bei Gong, Ao Xiong, Wei Wang 0100, Qihui Wu 0001 |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2025 | Privacy-Preserving and Traceable Certificateless Anonymous Mutual Authentication Scheme for IoTabstractBy utilizing the sensing and perception capabilities of various devices, the Internet of Things (IoT) enables more precise awareness of the real world, thereby enhancing management and resource utilization efficiency. However, due to their open deployment environments and frequent message exchanges, IoT endpoints are highly vulnerable to a wide range of security threats and privacy breaches, including forgery, data theft, and information leakage. Therefore, to address these challenges and ensure device legitimacy verification and secure data exchange among IoT devices, we propose a privacy-preserving and traceable certificateless anonymous mutual authentication scheme (PPT-CLAMA). PPT-CLAMA not only eliminates the need for a secure channel during key generation but also prevents attackers from tracing the real identity of devices through their own identity or public keys while providing pseudonym and anonymous authentication to devices, demonstrating greater practicality. Furthermore, through security proofs and analysis, PPT-CLAMA satisfies various high-level security properties, including mutual authentication, key agreement, nonrepudiation, unlinkability, perfect forward secrecy, known session-specific temporary information security, traceability, anonymity, and privacy preservation. The simulation results indicate that, compared to authentication and key agreement schemes, PPT-CLAMA reduces the average computational overhead and average communication overhead during the authentication process by 6.73% and 3.31%, respectively, demonstrating higher computational and communication efficiency. Bei Gong, Akhtar Badshah, Muhammad Waqas 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | ECGSH: An Efficient Certificateless Group Signcryption-Based Homomorphic in Industrial IoTabstractWith the growth of the Industrial Internet of Things (IIoT), millions of smart devices are transmitting and processing data globally. However, this extensive interconnectivity also poses significant security challenges, particularly in data transmission. Traditional security mechanisms often incur high computational costs and long processing times, which are impractical for resource-constrained devices. In this paper, we propose an efficient and secure data processing and transmission scheme for the IIoT called ECGSH. This scheme combines certificateless signcryption and homomorphic encryption to enable homomorphic processing in an encrypted state, thus enhancing both security and flexibility. Moreover, it reduces the complexity of large-scale data processing by eliminating bilinear pair computations. The ECGSH scheme also supports homomorphic data transmission in the IIoT. A rigorous security analysis proves that the scheme has the properties of confidentiality, non-repudiation, and forward security under the random oracle model. An attack resistance analysis proves that the scheme can effectively resist man-in-the-middle (MITM) attacks, replay attacks, and eavesdropping attacks. The performance evaluation demonstrates that ECGSH excels in terms of security, computational efficiency, and communication overhead. It requires at most 31% CPU utilization, and less than 1.2% memory footprint on IIoT hardware, making it particularly suitable for IIoT environments with limited resources and high transmission costs. Bei Gong, Mowei Gong, Zhe Li 0052, Weizhi Meng 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Lightweight Continuous Authentication via IMU Fingerprinting for V2XabstractInertial measurement unit (IMU) fingerprinting is a promising physical authentication technique based on hardware imperfections produced during sensor manufacturing. This paper presents a two-stage feature extraction process that combines feature selection and mapping; the proposed approach is tailored for the lightweight vehicle-to-everything (V2X) application scenario. Specifically, the selected features are transformed into images via Gramian angular difference field (GADF), Gramian angular summation field (GASF), and Markov transition field (MTF) mappings, as well as feature extraction implemented via a convolutional neural network (CNN). Owing to the advances provided by the proposed scheme, a lightweight feature extraction system achieves satisfactory accuracy levels above 99.10% with fewer sample data and a short training time. The effectiveness and robustness of the developed approach were validated under various driving conditions via 20 IMU sensors, Arduino, and a Raspberry Pi across 20 vehicles. Additionally, tests conducted across different deep learning models demonstrated the generalizability of the proposed preprocessing and mapping methods. Bei Gong, Zhe Li 0052, Mowei Gong, Weizhi Meng 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Toward privacy-preserving verifiable DSSE for attribute-based cloud computing system
Tianqi Peng, Bei Gong, Pengxuan Sun |
J. Supercomput. | 2 |
| 2025 | FORT: A Forward Secure and Threshold Authorized Multi-Authority Attribute-Based Signature Scheme for Multimedia IoTabstractAttribute-Based Signature (ABS) provides a critical solution for ensuring data integrity, fine-grained access control, and anonymous authentication in security-sensitive systems such as the Multimedia Internet of Things (MIoT) and multimedia streaming platforms. However, practical adoption of ABS faces three fundamental challenges: vulnerability to key exposure and escrow risks, linear growth of computational cost, and insufficient robustness in multi-authority environments. To address these issues, we propose a forward secure and threshold authorized multi-authority ABS scheme called FORT in this paper. By employing a binary tree structure to divide multiple time periods, historical signatures remain valid even in the event of key exposure. Furthermore, to balance robustness and resistance to corruption while mitigating the key escrow problem, we construct a threshold authorized multi-authority structure based on Lagrange interpolation. This structure effectively reduces the impact of a single authority on the MIoT. Additionally, through the adoption of outsourced computation technology, which offloads complex computations in the signature and verification phases to the edge server, the computational burden for both the signer and verifier is significantly reduced to a small constant. Rigorous security analysis demonstrates that the FORT scheme achieves forward security, collusion attack resistance, corrupt authority resistance and anonymity. Theoretical comparisons and simulation experiments demonstrate the lightweight nature of the FORT scheme in terms of computation and communication. Bei Gong, Zhe Li 0052, Mowei Gong |
IEEE Trans. Multim. | 2 |
| 2025 | Multi-User Oriented Data Sharing Scheme for Internet of Medical Things Based on Dual Cryptography MechanismabstractEncrypted sharing of Internet of Medical Things (IoMT) data is essential for facilitating collaboration, safeguarding patient privacy, and advancing clinical research. However, existing encryption schemes face numerous challenges in multi-user environments. Traditional proxy re-encryption requires exclusive ciphertext for each user, which is evidently unsuitable for IoMT's multi-user scenarios. Meanwhile, attribute-based encryption provides flexible data access control, but its complex computations and high resource demands limit its use in large-scale IoMT environments. Additionally, challenges like single-point failure and redundant backups emerge in ciphertext storage. To address these challenges, we propose a dual-cryptography mechanism integrating enhanced proxy re-encryption and attribute-based encryption. Our scheme enables unified ciphertext access for authorized users while applying attribute encryption exclusively to small data keys. To mitigate potential data loss from storage server failures, we propose a decentralized ciphertext storage and recovery mechanism with verifiable secret sharing. Furthermore, we implement decentralized ciphertext storage using verifiable secret sharing, ensuring recoverability from server failures. Formal analysis proves confidentiality under the random oracle model. Experimental results demonstrate high security strength, computational efficiency, and robustness. The solution prevents single-point failures, resists collusion attacks, and maintains traceability through blockchain-integrated audit trails. Guiping Zheng, Bei Gong, Muhammad Waqas 0001, Iftekhar Ahmad, Hisham Alasmary, Sheng Chen 0001 |
IEEE Trans. Sustain. Comput. | 2 |
| 2024 | A Sustainable Storage Compensation Method for Consortium Blockchain-based Computing Power TradingabstractThe consortium blockchain effectively ensures the trustworthiness of computing power transactions among resource owners. However, the substantial storage costs incurred by nodes have been overlooked, potentially diminishing their enthusiasm and affecting the platform’s security and sustainability. This paper proposes a sustainable storage compensation method to balance the storage profits between storage compensation providers and recipients. First, to mitigate the impact of malicious nodes, we propose a transaction storage pricing strategy based on reputation. Second, we develop a storage compensation pricing model based on Rubinstein’s game theory. We then conduct a Nash equilibrium analysis to determine the equilibrium storage compensation price for the computing power trading system. Finally, we demonstrate the effectiveness of our reputation-based unit price setting strategy through simulations and validate the feasibility of the game model. Compared with the two representative methods, our approach yields a higher time-average payoff and is more sustainable. Guangzhuo Zhu, Bei Gong |
TrustCom | 3 |
| 2024 | A federated semi-supervised automatic sleep staging method based on relationship knowledge sharing
Bian Ma, Lijuan Duan, Yuanhua Qiao, Bei Gong |
Expert Syst. Appl. | 5 |
| 2024 | Developing a reliable route protocol for mobile self-organization networksabstractMobile ad hoc networks (MANETs), which correspond to a novel wireless technology, are widely used in Internet of Things (IoT) systems such as drones, wireless sensor networks, and military or disaster relief communication. From the perspective of communication and data collection, the success rate of collaborations between nodes in mobile ad hoc networks and reliability of data collection mainly depend on whether the nodes in the network operate normally, namely, according to the established network rules. However, mobile ad hoc networks are vulnerable to attacks targeting transmission channels and nodes owing to their dynamic evolution, openness, and distributed characteristics. Therefore, during the network operation, it is necessary to classify and detect the behavior and characteristics of each node. However, most existing research only analyzes and considers responses against a single or small number of attacks. To address these issues, this article first systematically analyzed and classified common active attacks in MANETs. Then, a node trust model was proposed based on the characteristics of various attacks; subsequently, a new secure routing protocol, namely, TC-AODV, was proposed. This protocol has minimal effect on the original communication dynamics and can effectively deal with Packet drop, wormhole, Session hijacking, and other main attacks in MANETs. The NS3 simulation results show that the proposed routing protocol attains good transmission performance, can effectively identify various attacks and bypass malicious nodes, and securely complete the communication process. Shaohu Li 0001, Bei Gong |
High Confid. Comput. | 2 |
| 2024 | A Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for IIoTabstractThe Industrial Internet of Things (IIoT), through the extensive deployment of devices for sensing, transmitting, and analyzing production states, can provide users with more comprehensive services and enhance production and manufacturing efficiency. However, most IIoT devices are limited by software and hardware resources, and existing mature security mechanisms are no longer suitable due to high computing and communication costs. This weakness makes these devices highly susceptible to illegal attacks, such as counterfeiting, leading to a decline in service quality of IIoT. Therefore, to ensure the secure and efficient verification of the legitimacy of numerous IIoT devices, scholars have employed numerous viable solutions. However, many existing solutions have difficulty achieving a balance between the limited resources and security requirements of IIoT, resulting in certain shortcomings. To address this, we first propose a lightweight certificateless signature scheme without pairing, which can achieve unforgeability and reduce computation pressure by batch verification for multiple signatures. Furthermore, we propose a lightweight certificateless mutual authentication scheme (LCLMA-BS) for the IIoT. LCLMA-BS is capable of conducting key agreement for both authentication parties and batch authentication for multiple participants. Moreover, through analysis and proof, LCLMA-BS is shown to have various security properties, such as perfect forward and backward security and known session-specific temporary information security. Finally, the simulation results indicate that our signature and LCLMA-BS exhibit higher computational efficiency and communication efficiency, demonstrating better suitability for the IIoT. Deshuai Yin, Bei Gong |
IEEE Internet Things J. | 2 |
| 2024 | Privacy-Preserving Traceable Encrypted Traffic Inspection in Blockchain-Based Industrial IoTabstractBlockchain-based Industrial Internet of Things (IIoT) integrates the blockchain technology into the traditional IIoT infrastructure to provide secure and collaborative services. In IIoT, the traffic is usually encrypted using a cipher suite (SSL/TLS) for secure communication, which makes it hard for middleboxes (MBs) to detect malicious activity in the traffic. To address this problem, secure MBs that directly perform encrypted traffic inspection have been presented. Recently, a new privacypreserving deep packet inspection (DPI) system on MB for IoT scenarios was proposed, but it suffered from the following two limitations: 1) no support for fast token detection and 2) no support for tracing abnormal sources. To address the two limitations, we propose BTDPI, a privacy-preserving traceable DPI system that efficiently performs inspection over encrypted traffic in blockchain-based IIoT. Technically, we adopt a two-layer filter architecture to improve the efficiency of detection and moreover introduce a new online–offline certificateless aggregate signature with smart contract to design an identity traceability mechanism. The experiment result shows that BTDPI runs$26.7\times $faster for token detection with 3000 tokens and 3000 rules than the state-of-the-art work. Kai Zhang 0016, Minjun Deng, Bei Gong, Yinbin Miao, Jianting Ning |
IEEE Internet Things J. | 3 |
| 2024 | An Intelligent Edge Dual-Structure Ensemble Method for Data Stream Detection and ReleasingabstractEdge intelligence is a critical enabler of intelligent application services in the Internet of Things (IoT). However, due to complex environmental factors, edge devices are subject to constant dynamic changes, which can result in security threats and sensitive information leakage. Therefore, it is essential to investigate data stream online analysis and detection strategies and implement an online releasing mechanism to ensure sensitive information is not leaked. Existing work rarely addresses these issues simultaneously or has poor performance, which poses a challenge. To address this challenge, we propose an intelligent edge dual-structure ensemble method (IEDSEM), consisting of three key components: 1) data preprocessing; 2) drift detection data analytics (IEDSEM-DDDA); and 3) privacy-preserving data releasing (IEDSEM-PPDR). Data preprocessing is used primarily to enhance the quality of data streams to improve the performance of model learning. IEDSEM-DDDA involves three sequential operations: 1) dynamic feature selection; 2) model learning and selection and 3) online model ensemble deployment to achieve anomaly detection of online data streams. Meanwhile, IEDSEM-PPDR uses differential privacy and online optimization operations to achieve intelligent hierarchical protection of edge data. To validate the performance of our proposed IEDSEM method, we conducted two comprehensive simulation experiments on real data machines, verifying the accuracy of the concept drift component detection and the privacy optimization performance of the privacy-preserving component, respectively. Simulation results show that compared with several other advanced high-performance algorithms, our algorithm has over 99% accuracy in data stream analysis detection and more outstanding privacy-preserving ability. Jiangjiang Zhang, Bei Gong, Qian Wang 0015, Guiping Zheng |
IEEE Internet Things J. | 2 |
| 2024 | MalFox: Camouflaged Adversarial Malware Example Generation Based on Conv-GANs Against Black-Box DetectorsabstractDeep learning is a thriving field currently stuffed with many practical applications and active research topics. It allows computers to learn from experience and to understand the world in terms of a hierarchy of concepts, with each being defined through its relations to simpler concepts. Relying on the strong capabilities of deep learning, we propose a convolutional generative adversarial network-based (Conv-GAN) framework titled MalFox, targeting adversarial malware example generation against third-party black-box malware detectors. Motivated by the rival game between malware authors and malware detectors, MalFox adopts a confrontational approach to produce perturbation paths, with each formed by up to three methods (namely Obfusmal, Stealmal, and Hollowmal) to generate adversarial malware examples. To demonstrate the effectiveness of MalFox, we collect a large dataset consisting of both malware and benignware programs, and investigate the performance of MalFox in terms of accuracy, detection rate, and evasive rate of the generated adversarial malware examples. Our evaluation indicates that the accuracy can be as high as 99.0% which significantly outperforms the other 12 well-known learning models. Furthermore, the detection rate is dramatically decreased by 56.8% on average, and the average evasive rate is noticeably improved by up to 56.2%. Fangtian Zhong, Xiuzhen Cheng, Dongxiao Yu, Bei Gong, Shuaiwen Song, Jiguo Yu |
IEEE Trans. Computers | 4 |
| 2024 | SLIM: A Secure and Lightweight Multi-Authority Attribute-Based Signcryption Scheme for IoTabstractAlthough attribute-based signcryption (ABSC) offers a promising technology to ensure the security of IoT data sharing, it faces a two-fold challenge in practical implementation, namely, the linearly increasing computation and communication costs and the heavy load of single authority based key management. To this end, we propose a Secure and Lightweight Multi-authority ABSC scheme called SLIM in this paper. The signcryption and de-signcryption costs of devices are reduced to a small constant by offloading most of the computation to the edge server. To minimize communication and storage costs, a short and constant-size ciphertext is designed. Moreover, we adopt a hierarchical multi-authority architecture, setting up multiple attribute authorities that manage keys independently to prevent the bottleneck. Rigorous security analysis proves that the SLIM scheme can resist adaptive chosen ciphertext attacks and adaptive chosen message attacks under the standard model. Simulation experiments demonstrate the correctness of our theoretical derivations and the cost reduction of the SLIM scheme in computation, communication and storage. Bei Gong, Yao Sun 0002, Muhammad Waqas 0001, Sheng Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | TBAC: A Tokoin-Based Accountable Access Control Scheme for the Internet of ThingsabstractOverprivilege Attack, a widely reported phenomenon in IoT that accesses unauthorized or excessive resources, is notoriously hard to prevent, trace and mitigate. In this paper, we propose TBAC, a Tokoin-Based Access Control model enabled by blockchain and Trusted Execution Environment (TEE) technologies, to offer fine-grained access control and strong auditability for IoT. TBAC materializes the virtual access power into a definite-amount, secure and accountable cryptographic coin, termed “tokoin” (token+coin), and manages it using atomic and accountable state-transition functions in a blockchain. A tokoin carries a fine-grained policy defined by the resource owner to specify the requirements to be satisfied before an access is granted, and the behavioral constraints that describe the correct procedure to follow during access. The strong-auditability is achieved with blockchain and a TEE-enabled trusted access control object (TACO) to ensure that all access activities are securely monitored and auditable. We prototype TBAC by implementing all its functions with well-studied cryptographic primitives over different blockchain platforms, building a TACO on top of the ARM Cortex-M33 TEE microcontroller, and constructing a user-friendly APP for regular users. A case study is finally presented to demonstrate how TBAC is employed to enable autonomous and secure in-home cargo delivery. Chun-Chi Liu, Minghui Xu 0001, Hechuan Guo, Xiuzhen Cheng, Yinhao Xiao, Dongxiao Yu, Bei Gong, Arkady Yerukhimovich, Shengling Wang 0001, Weifeng Lyu |
IEEE Trans. Mob. Comput. | 7 |
| 2024 | VSSB-Raft: A Secure and Efficient Zero Trust Consensus Algorithm for BlockchainabstractTo solve the problems of vote forgery and malicious election of candidate nodes in the Raft consensus algorithm, we combine zero trust with the Raft consensus algorithm and propose a secure and efficient consensus algorithm -Verifiable Secret Sharing Byzantine Fault Tolerance Raft Consensus Algorithm (VSSB-Raft). The VSSB-Raft consensus algorithm realizes zero trust through the supervisor node and secret sharing algorithm without the invisible trust between nodes required by the algorithm. Meanwhile, the VSSB-Raft consensus algorithm uses the SM2 signature algorithm to realize the characteristics of zero trust requiring authentication before data use. In addition, by introducing the NDN network, we redesign the communication between nodes and guarantee the communication quality among nodes. The VSSB-Raft consensus algorithm proposed in this paper can make the algorithm Byzantine fault tolerant by setting a threshold for secret sharing while maintaining the algorithm’s complexity to be O(n). Experiments show that the VSSB-Raft consensus algorithm is secure and efficient with high throughput and low consensus latency. Siben Tian, Fenhua Bai, Tao Shen 0004, Chi Zhang 0121, Bei Gong |
ACM Trans. Sens. Networks | 5 |
| 2024 | An Anonymous and Supervisory Cross-chain Privacy Protection Protocol for Zero-trust IoT ApplicationabstractInternet of things (IoT) development tends to reduce the reliance on centralized servers. The zero-trust distributed system combined with blockchain technology has become a hot topic in IoT research. However, distribution data storage services and different blockchain protocols make network interoperability and cross-platform more complex. Relay chain is a promising cross-chain technology that solves the complexity and compatibility issues associated with blockchain cross-chain transactions by utilizing relay blockchains as cross-chain connectors. Yet relay chain cross-chain transactions need to collect asset information and implement asset transactions via two-way peg. Due to the release of user transaction information, there is the issue of privacy leakage. In this article, we propose a cross-chain privacy protection protocol based on the Groth16 zero-knowledge proof algorithm and coin-mixing technology, which changes the authentication mechanism and uses a combination of generating functions to map virtual external addresses in transactions. It allows fast cross-chain anonymous transactions while hiding the genuine user’s address. The experiment shows that, in a zero-trust IoT context, our scheme can effectively protect user privacy information, accomplish controlled transaction traceability operations, and guarantee cross-chain transaction security. Yinghong Yang, Fenhua Bai, Tao Shen 0004, Yingli Liu, Bei Gong |
ACM Trans. Sens. Networks | 6 |
| 2024 | Blockchain-Enhanced Time-Variant Mean Field-Optimized Dynamic Computation Sharing in Mobile NetworkabstractAlthough 5G and beyond communication technology empower a large number of edge heterogeneous devices and applications, the stringent security remains a major concern when dealing with the millions of edge computing tasks in the highly dynamic heterogeneous networks (HDHNs). Blockchains contribute significantly to addressing security challenges by guaranteeing the reliability of data and information. Since the node’s mobility, there are risks of exiting the network and leaving the remaining tasks noncomputed. Therefore, we model the cost function of offloaded computing tasks as a dynamic stochastic game. To reduce the computational complexity, the Time-Variant Mean-Field term (TVMF) is adopted to solve the cost-optimized problem. What’s more, we design an Adaptivity-Aware Practical byzantine fault tolerance consensus Protocol (AAPP) to dynamically formulate domains, execute leader node selection with regard to task completion and quickly verify computational results. In addition, a Dynamic Multi-domain Fractional Repetition uncoded repair storage (DMFR) scheme with variant redundancy is proposed to reduce the storage pressure and repair overhead. The simulation is implemented to demonstrate our scheme outperforms the benchmarks in terms of cost and time overhead. Fenhua Bai, Tao Shen 0004, Jian Song 0011, Bei Gong, Muhammad Waqas 0001, Hisham Alasmary |
IEEE Trans. Wirel. Commun. | 5 |
| 2023 | A Fine-Grained Cross-Chain Spectrum Sharing Mechanism Based on OracleabstractThe dramatically increased wireless communication needs make non-renewable spectrum resources extremely scarce and costly. Consortium blockchain realizes trusted spectrum sharing among untrusted spectrum owners. Yet, most existing studies ignore spectrum sharing among blockchains, which greatly reduce spectrum utilization. In the paper, we focus on cross-chain spectrum sharing. We propose a Fine-grained Cross-chain Spectrum Sharing mechanism based on Oracle (FCSSO) to realize trusted and efficient cross-chain spectrum transactions. To guarantee benefits of spectrum owners, we design a fine-grained time partition method to decide spectrum renting time in transactions. The method reduces the waste of owners' available spectrum time caused by spectrum handoff. Extensive simulation proves the positive impact of the proposed fine-grained time partition method, and FCSSO outperforms two representative cross-chain mechanisms from two aspects: spectrum owners' benefits and spectrum utilization. Mengjie Cao, Qian Wang 0015, Xiaojiang Du, Juan Fang 0004, Bei Gong, Mohsen Guizani |
GLOBECOM | 5 |
| 2023 | MSKNP: Multistage Key Negotiation Protocol for IoT-Blockchain EnvironmentabstractWith the development of the Internet, the technical framework that integrates Internet of Things (IoT) and blockchain has gradually developed. However, how to ensure the secure with balanced performance of devices becomes a key issue. In this article, we design a new multistage session key negotiation protocols for the Internet of Things-blockchain environment by using “Agents.” We transfer bilinear operations to Agents, which has strong computing capabilities. Based on this, the resource of IoT devices in the key negotiation process is reduced without simplifying bilinear pairing compute and making them more secure. The simplified BPR model and the random oracle model ID-BJM are used to test the security of requirements in different stages of the scheme, furthermore, theoretically analyze its performance overhead. This protocol can reduce the computing overhead of IoT devices in the key negotiation process under the premise of ensuring security. Zipeng Diao, Qian Wang 0015, Bei Gong |
IEEE Internet Things J. | 3 |
| 2023 | LCDMA: Lightweight Cross-Domain Mutual Identity Authentication Scheme for Internet of ThingsabstractWith the widespread popularity of mobile terminals in the Internet of Things (IoT), the demand for cross-domain access of mobile terminals between different regions has also increased significantly. The nature of wireless communication media makes mobile terminals vulnerable to security threats in cross-domain access. Identity authentication is a prerequisite for secure data transmission in the cross-domain, and it is also the first step to guarantee the credibility of data sources. Most existing authentication schemes are based on bilinear pairing or public-key encryption and decryption with high computation overhead, which are not suitable for the resource-limited mobile IoT terminals. Moreover, these schemes have some security drawbacks and cannot meet the security requirements of cross-domain access. In this article, we propose a lightweight cross-domain mutual identity authentication (LCDMA) for the mobile IoT environment. LCDMA uses a symmetric polynomial instead of high-complexity bilinear pairing in the traditional schemes. We theoretically analyze the security performance under the random oracle model. Our results show that LCDMA not only resists common attacks but also preserves secure traceability while guaranteeing anonymity. Performance evaluation further demonstrates that our scheme has better performance in terms of computation and communication overhead, compared with other existing representative schemes. Bei Gong, Guiping Zheng, Muhammad Waqas 0001, Shanshan Tu, Sheng Chen 0001 |
IEEE Internet Things J. | 1 |
| 2023 | Smart contracts vulnerability detection model based on adversarial multi-task learning
Kuo Zhou, Jing Huang 0003, Honggui Han, Bei Gong, Ao Xiong, Wei Wang 0100, Qihui Wu 0001 |
J. Inf. Secur. Appl. | 4 |
| 2023 | Sandbox Computing: A Data Privacy Trusted Sharing Paradigm Via Blockchain and Federated LearningabstractAs a new trusted data sharing pattern with privacy protection, the integration mechanism of blockchain and Federated Learning has attracted extensive attention. Generally, this mechanism uses blockchain technology to supervise the original data and calculation results, which ignores the supervision of the Federated Learning model and computing process. Therefore, we introduce the concepts of the sandbox and state channel to construct a new data privacy sharing paradigm via Blockchain and Federated Learning. Under this paradigm, we use state channel to connect Blockchain and Federated Learning. And state channel is used to create a “trusted sandbox” to instantiate Federated Learning tasks in the trustless edge computing environment. Meanwhile, we also mainly solve problems about data privacy sharing in Federated Learning and system performance degradation caused by data quality. The simulation results show that the proposed method has better performance and efficiency than the traditional data sharing method. Shao-Yong Guo 0001, Keqin Zhang, Bei Gong, Liandong Chen, Yinlin Ren, Feng Qi 0004, Xuesong Qiu 0001 |
IEEE Trans. Computers | 3 |
| 2023 | CommandFence: A Novel Digital-Twin-Based Preventive Framework for Securing Smart Home SystemsabstractSmart home systems are both technologically and economically advancing rapidly. As people become gradually inalienable to smart home infrastructures, their security conditions are getting more and more closely tied to everyone's privacy and safety. In this paper, we consider smart apps, either malicious ones with evil intentions or benign ones with logic errors, that can cause property loss or even physical sufferings to the user when being executed in a smart home environment and interacting with human activities and environmental changes. Unfortunately, current preventive measures rely on permission-based access control, failing to provide ideal protections against such threats due to the nature of their rigid designs. In this paper, we propose CommandFence, a novel digital-twin-based security framework that adopts a fundamentally new concept of protecting the smart home system by letting any sequence of app commands to be executed in a virtual smart home system, in which a deep-q network (DQN) is used to predict if the sequence could lead to a risky consequence. CommandFence is composed of an Interposition Layer to interpose app commands and an Emulation Layer to figure out whether they can cause any risky smart home state if correlating with possible human activities and environmental changes. We fully implemented our CommandFence implementation and tested against 553 official SmartApps on the Samsung SmartThings platform and successfully identified 34 potentially dangerous ones, with 31 of them reported to be problematicAuthor: Please provide index terms/keywords for your article. To download the IEEE Taxonomy go tohttp://www.ieee.org/documents/taxonomy_v101.pdf?> the first time to our best knowledge. Moreover, We tested our CommandFence on the 10 malicious SmartApps created by Jiaet al.2017, and successfully identified 7 of them as risky, with the missed ones actually only causing smartphone information leak (not harmful to the smart home system). We also tested CommandFence against the 17 benign SmartApps with logic errors developed by Celiket al.2017, and achieved a 100% accuracy. Our experimental studies indicate that adopting CommandFence incurs a neglectable overhead of 0.1675 seconds. Yinhao Xiao, Qin Hu 0001, Xiuzhen Cheng, Bei Gong, Jiguo Yu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Many-Objective Optimization Based Intrusion Detection for in-Vehicle Network SecurityabstractIn-vehicle network security plays a vital role in ensuring the secure information transfer between vehicle and Internet. The existing research is still facing great difficulties in balancing the conflicting factors for the in-vehicle network security and hence to improve intrusion detection performance. To challenge this issue, we construct a many-objective intrusion detection model by including information entropy, accuracy, false positive rate and response time of anomaly detection as the four objectives, which represent the key factors influencing intrusion detection performance. We then design an improved intrusion detection algorithm based on many-objective optimization to optimize the detection model parameters. The designed algorithm has double evolutionary selections. Specifically, an improved differential evolutionary operator produces new offspring of the internal population, and a spherical pruning mechanism selects the excellent internal solutions to form the selected pool of the external archive. The second evolutionary selection then produces new offspring of the archive, and an archive selection mechanism of the external archive selects and stores the optimal solutions in the whole detection process. An experiment is performed using a real-world in-vehicle network data set to verify the performance of our proposed model and algorithm. Experimental results obtained demonstrate that our algorithm can respond quickly to attacks and achieve high entropy and detection accuracy as well as very low false positive rate with a good trade-off in the conflicting objective landscape. Jiangjiang Zhang, Bei Gong, Muhammad Waqas 0001, Shanshan Tu, Sheng Chen 0001 |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2023 | Applications of Differential Privacy in Social Network Analysis: A SurveyabstractDifferential privacy provides strong privacy preservation guarantee in information sharing. As social network analysis has been enjoying many applications, it opens a new arena for applications of differential privacy. This article presents a comprehensive survey connecting the basic principles of differential privacy and applications in social network analysis. We concisely review the foundations of differential privacy and the major variants. Then, we discuss how differential privacy is applied to social network analysis, including privacy attacks in social networks, models of differential privacy in social network analysis, and a series of popular tasks, such as analyzing degree distribution, counting subgraphs and assigning weights to edges. We also discuss a series of challenges for future work. Honglu Jiang, Jian Pei 0001, Dongxiao Yu, Jiguo Yu, Bei Gong, Xiuzhen Cheng |
IEEE Trans. Knowl. Data Eng. | 5 |
| 2023 | A Hybrid Many-Objective Optimization Algorithm for Task Offloading and Resource Allocation in Multi-Server Mobile Edge Computing NetworksabstractMobile edge computing (MEC) is an effective computing tool to cope with the explosive growth of data traffic. It plays a vital role in improving the quality of service for user task computing. However, the existing solutions rarely address all the significant factors that impact the quality of service. To challenge this problem, a trusted many-objective model is built by comprehensively considering the task time delay, server energy consumption, trust metrics between task and server, and user experience utility factors in multi-server MEC networks. We decompose the original problem into task offloading (TO) and resource allocation (RA) to address the model. Then a novel hybrid many-objective optimization algorithm based on cascading clustering and incremental learning is designed to optimize the TO decision solutions. A low-complexity heuristic method is adopted based on the optimal TO decision solutions to optimize the RA problem continuously. To verify the model's validity and the optimisation algorithm's superiority, five other advanced many-objective algorithms are used for comparison. The results show that our algorithm has more than half the number of the superior values for the benchmark problem. And the obtained model solution shows good performance on different indicators metrics for the decomposition problem. Jiangjiang Zhang, Bei Gong, Muhammad Waqas 0001, Shanshan Tu, Zhu Han 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | An identity privacy scheme for blockchain-based on edge computingabstractAbstract Blockchain has decentralization characteristics and requires more targeted security schemes to protect user privacy. In contrast, existing signature schemes have many high‐complexity operations and impose an enormous computational burden on wireless nodes. This article proposes a light‐weighted identity privacy scheme for blockchain‐based on edge computing. We construct linkable identity privacy and non‐linkable identity privacy, which can resist collusion attacks while virtually guaranteeing blockchain nodes' identity privacy. Since edge computing offloads heavily, the proposed scheme has lower computational complexity than the existing techniques. Bei Gong, Jiangjiang Zhang, Yang Cao 0022, Zheng Li 0033 |
Concurr. Comput. Pract. Exp. | 2 |
| 2022 | Anonymous Traceability protocol based on Group Signature for Blockchain
Bei Gong, Chi Cui, Xiaochong Li, Yuheng Ren |
Future Gener. Comput. Syst. | 1 |
| 2022 | A secure and lightweight certificateless hybrid signcryption scheme for Internet of Things
Bei Gong, Qian Wang 0015, Yuheng Ren |
Future Gener. Comput. Syst. | 1 |
| 2022 | A trusted proof mechanism of data source for smart city
Bei Gong, Qian Wang 0015 |
Future Gener. Comput. Syst. | 2 |
| 2022 | Trustworthy Blockchain-Empowered Collaborative Edge Computing-as-a-Service Scheduling and Data Sharing in the IIoEabstractOwing to the technology of 5G and beyond, collaborative edge computing-as-a-service has enabled trillions of interconnected edge applications. It has also become a prospective paradigm for providing computing services by offloading computationally intensive assignments to mobile-edge servers or fog nodes due to terminals constrained computing and caching resources. Nevertheless, in this process, trust of computing-as-a-service scheduling and edge data sharing in heterogeneous systems is an unavoidable challenge of paramount importance. As a powerful tool that addresses security issues, blockchains can ensure the trustworthiness and irreversibility of computing data by consensus mechanisms. However, in the Industrial Internet of Energy (IIoE), the storage burden of a single blockchain has increased. Therefore, from the perspective of a stable real-time operation, we propose a multiedgechain structure that accommodates thousands of edge data and promotes on-chain data efficiency to achieve cross-chain edge data sharing for heterogeneous blockchain systems. Moreover, aiming at the profits of computing resource scheduling in the IIoE, a two-stage Stackelberg game strategy with an optimal scheduling demand and reward is provided considering the edge user’s preferences and risk factors. Finally, the simulation results verify the superiority of the proposed scheme, regarding the game equilibrium, utility optimization, and data sharing efficiency of cloud–edge collaboration. Fenhua Bai, Tao Shen 0004, Kai Zeng 0005, Bei Gong |
IEEE Internet Things J. | 5 |
| 2022 | SCCA: A slicing-and coding-based consensus algorithm for optimizing storage in blockchain-based IoT data sharing
Pengge Chen, Fenhua Bai, Tao Shen 0004, Bei Gong, Lei Zhang 0110, Zhengyuan An, Talha Mir, Shanshan Tu, Muhammad Waqas 0001 |
Peer-to-Peer Netw. Appl. | 4 |
| 2022 | Structure-Attribute-Based Social Network Deanonymization With Spectral Graph PartitioningabstractOnline social networks have gained tremendous popularity and have dramatically changed the way we communicate in recent years. However, the publishing of social network data raises more and more privacy concerns. To protect user privacy, social networking data are usually anonymized before being released. Nevertheless, existing anonymization techniques do not have sufficient protection effects. A large number of deanonymization attacks have arisen, and they mainly make use of either network topology or node attribute information to successfully reidentify anonymized users. In this article, we model a social network as a structure-attribute network (SAN) integrating the structural characteristics and the attribute information associated with social network users. A novel similarity measurement of social network nodes is proposed by considering the structural similarity and attribute similarity. A two-phase scheme is then designed to perform deanonymization by first dividing a social network (graph) into smaller subgraphs based on spectral graph partitioning and then applying the proposed deanonymization algorithm on each matched subgraph pair. We simulate the deanonymization attack with extensive experiments on three real-world datasets, and the experimental results demonstrate that our approach can improve the accuracy and time complexity of deanonymization compared with the state of the art. Honglu Jiang, Jiguo Yu, Xiuzhen Cheng, Cheng Zhang 0018, Bei Gong, Haotian Yu |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2021 | A delay-sensitive resource allocation algorithm for container cluster in edge computing environment
Shao-Yong Guo 0001, Keqin Zhang, Bei Gong, Wenchen He, Xuesong Qiu 0001 |
Comput. Commun. | 3 |
| 2021 | A threshold group signature scheme suitable for the Internet of ThingsabstractSummary With the development of information technology, the Internet of Things terminals are vulnerable to threats such as eavesdropping, tampering, and counterfeiting. The application of threshold group signature technology can effectively ensure the security of the system in applications such as battlefield intelligent decision‐making, connected vehicles, and intelligent manufacturing. However, the existing threshold group signature schemes lack the two‐way trusted authentication mechanism between group members and group manager, and group manager can easily become a security risk for the entire signature system. To solve this problem, this paper proposes a threshold group signature scheme based on elliptic curve that achieves mutual authentication of group members and group manager. The security analysis proves that the proposed scheme is anonymous, traceable, and can resist collusion attacks and frame attacks. The results of performance analysis and comparison also show that under the same security strength, the scheme proposed has shorter signature length, lower calculation amount for signature generation and signature verification, which can effectively reduce the communication and calculation overhead of the IoT terminal, and can be better applied to the Internet of Things application scenarios. Bei Gong, Yang Cao 0022, Zheng Li 0033 |
Concurr. Comput. Pract. Exp. | 1 |
| 2021 | Trusted data collection for Internet of ThingsabstractSummary Trusted date collection is the precondition of the security of Internet of Things (IOT). Recently, compressed sensing technology, which can enable the reduction of the energy consumption and time delay of data collection, has been extensively studied in IOT; However, the security of compressed sensing technology in IOT has not been sufficiently considered. Since compressed sensing depends the cooperation between IOT nodes and then sensing data is transparent for all IOT nodes, which is subjected to malicious nodes attack. Therefore, we propose a trusted data collection scheme based on compressed sensing oriented to the IOT. When data collection is tampered with, the scheme can detect malicious nodes. Experiments demonstrate that the proposed scheme can ensure data security with a low energy consumption. Bei Gong, Caiqiu Zhou |
Concurr. Comput. Pract. Exp. | 2 |
| 2021 | Privacy-Preserving Collaborative Learning for Multiarmed Bandits in IoTabstractThis article studies privacy-preserving collaborative learning in decentralized Internet-of-Things (IoT) networks, where the agents exchange information constantly to improve the learnability, and meanwhile make the privacy of agents protected during communications. However, the harsh constraints in IoT make executing collaborative learning much more difficult than well-connected systems composed by servers with strong computation power, due to the weak capacity of devices, limited bandwidth for exchanging information, the asynchronous communication environment, and the necessity of privacy preserving. We show that even if with the harsh constraints in IoT, it still can devise efficient privacy-preserving collaborative learning algorithms, by proposing the first known decentralized collaborative learning algorithm for the fundamental multiarmed bandits problem under the framework of local differential privacy. Rigorous analysis shows that the proposed learning algorithm can make every agent learn the best arm with a high probability and keep the privacy preserved meanwhile. Extensive experiments illustrate that our learning algorithm performs well in real settings. Shuzhen Chen 0001, Youming Tao 0001, Dongxiao Yu, Feng Li 0002, Bei Gong, Xiuzhen Cheng |
IEEE Internet Things J. | 5 |
| 2021 | A Trusted Attestation Scheme for Data Source of Internet of Things in Smart City Based on Dynamic Trust ClassificationabstractThe Internet of Things (IoT) in smart cities collects and transmits a large amount of time–space-sensitive information to realize feedback control. It bridges the gap between the information world and the real world. With the data-based feature, the security and credibility of the IoT mainly depend on whether the source of the data is trusted. Therefore, as the data collection and transmission entity, sensing nodes should be classified and proved the trustworthiness. However, the existing works failed to classify and measure the credibility of sensing nodes multidimensional in real time. The previous trust-proof methods also cannot effectively protect the key information. To address these problems, this article first proposes a multidimensional and fine-grained dynamic measurement method in a trusted computing environment. Then, a trust classification model of sensing nodes is presented, and a grouping mechanism of different trust levels is designed to identify malicious nodes. Finally, a threshold ring signature-based trust certification scheme is proposed for data source authentication. It can adequately protect the privacy information of the attestation node and has complete anonymity and traceability. Besides, the scheme has a shorter signature and high computational efficiency, which makes it also suitable for sensing nodes with limited computing resources. The simulation results show that the scheme has better dynamic adaptability and can effectively ensure the credibility of data sources under the premise of various attacks with accessible impact on the system. Bei Gong, Shao-Yong Guo 0001 |
IEEE Internet Things J. | 1 |
| 2021 | Competitive Age of Information in Dynamic IoT NetworksabstractIn the past decades, Dynamic Internet of Things (D-IoT) networks have played a conspicuously more important role in many real-life areas, including disaster relief, environment monitoring, public safety, and so on, to rapidly collect information from the environment and help people to make the decision. Meanwhile, due to the widespread implementation of dynamic IoT networks, there exists an enormous demand on designing suitable models and efficient algorithms for fundamental operations in dynamic IoT networks, to achieve the high throughput and reliable low-latency communication demands in 6G networks. In this article, we first present a general dynamic model to comprehensively depict most of the dynamic phenomena in IoT networks. Then, based on the proposed dynamic model, a distributed scheduling algorithm is proposed to competitively optimize the Age-of-Information (AoI) problem in the context of a D-IoT network. We say our scheduling algorithm is competitive: the throughput of the base station approximates the optimal solution with constant competitive ratio; and, the latency for a packet received by the base station is only constant times larger than the optimal latency. Rigorous theoretical analysis and extensive simulations are presented to verify the high throughput and reliable low-latency communications in our proposed algorithm. Dongxiao Yu, Yifei Zou, Minghui Xu 0001, Yong Zhang 0001, Bei Gong, Xiaoshuang Xing |
IEEE Internet Things J. | 6 |
| 2021 | Distributed learning dynamics of Multi-Armed Bandits for edge intelligence
Shuzhen Chen 0001, Youming Tao 0001, Dongxiao Yu, Feng Li 0002, Bei Gong |
J. Syst. Archit. | 5 |
| 2021 | Construction of Trusted Routing Based on Trust ComputationabstractIn the field of applied IoT, a large number of wireless sensor devices are tasked with data production and collection, providing IoT subjects with a large amount of basic data to support top‐level IoT applications. However, there is a considerable risk of being attacked on such sensor networks that are organized in a wireless form. These relatively independent network devices have extremely limited performance and lifetime, a problem that can be supplemented in a centralized network with base stations by relying on the performance of the core nodes of the network, but in a decentralized self‐organizing network, they can have a serious adverse impact on the implementation of security solutions. Considering the fundamental nature of the data generated by such end devices in IoT application services, the protection of their security is also directly related to the quality of upper layer services provided. The main research result of this paper is the design of a trust routing scheme for self‐organizing networks. The scheme is based on a comprehensive evaluation of data transmission rate, transmission delay, and other factors related to the operation status of the self‐organized network and improves the efficiency of the overall work of the self‐organized network by reducing the performance consumption of individual nodes of the self‐organized network and balancing the network load. Bei Gong, Jingxuan Zhu, Yubo Wang 0013 |
Wirel. Commun. Mob. Comput. | 1 |
| 2021 | Dynamic Network Security Mechanism Based on Trust Management in Wireless Sensor NetworksabstractWireless sensor network is a key technology in Internet of Things. However, due to the large number of sensor nodes and limited security capability, aging nodes and malicious nodes increase. In order to detect the untrusted nodes in the network quickly and effectively and ensure the reliable operation of the network, this paper proposes a dynamic network security mechanism. Firstly, the direct trust value of the node is established based on its behavior in the regional information interaction. Then, the comprehensive trust value is calculated according to the trust recommendation value and energy evaluation value of other high‐trust nodes. Finally, node reliability and management nodes are updated periodically. Malicious nodes are detected and isolated according to the credibility to ensure the dynamic, safe, and reliable operation of the network. Simulation results and analysis show that the node trust value calculated by this mechanism can reflect its credibility truly and accurately. In terms of reliable network operation, the mechanism can effectively detect malicious nodes, with higher detection rate, avoid the risk of malicious nodes as management nodes, reduce the energy consumption of nodes, and also play a defensive role in DOS attacks in wireless sensor networks. Guiping Zheng, Bei Gong, Yu Zhang 0138 |
Wirel. Commun. Mob. Comput. | 2 |
| 2020 | Distributed Data Aggregation in Dynamic Sensor Networks
Yifei Zou, Minghui Xu 0001, Yong Zhang 0001, Bei Gong, Xiaoshuang Xing |
WASA (1) | 5 |
| 2020 | Research on CLPKC-IDPKC cross-domain identity authentication for IoT environment
Bei Gong |
Comput. Commun. | 2 |
| 2020 | FlowGuard: An Intelligent Edge Defense Mechanism Against IoT DDoS AttacksabstractInternet-of-Things (IoT) devices are getting more and more popular in recent years and IoT networks play an important role in the industry as well as people's activities. On the one hand, they bring convenience to every aspect of our daily life; on the other hand, they are vulnerable to various attacks that in turn cancels out their benefits to a certain degree. In this article, we target the defense techniques against IoT Distributed Denial-of-Service (DDoS) attacks and propose an edge-centric IoT defense scheme termed FlowGuard for the detection, identification, classification, and mitigation of IoT DDoS attacks. We present a new DDoS attack detection algorithm based on traffic variations and design two machine learning models for DDoS identification and classification. To demonstrate the effectiveness of the two machine learning models, we generate a large data set by DDoS simulators BoNeSi and SlowHTTPTest, and combine it with the CICDDoS2019 data set, to test the identification and classification accuracy as well as the model efficiency. Our results indicate that the identification accuracy of the proposed long short-term memory is as high as 98.9%, which significantly outperforms the other four well-known learning models mentioned in the most related work. The classification accuracy of the proposed convolutional neural network is up to 99.9%. Besides, our models satisfactorily meet the delay requirements of IoT when deployed in edge servers with computational powers higher than a personal computer. Fangtian Zhong, Arwa Alrawais, Bei Gong, Xiuzhen Cheng |
IEEE Internet Things J. | 4 |
| 2020 | RJCC: Reinforcement-Learning-Based Joint Communicational-and-Computational Resource Allocation Mechanism for Smart City IoTabstractWith the fast development of smart cities and 5G, the amount of mobile data is growing exponentially. The centralized cloud computing mode is hard to support the continuous exchanging and processing of information generated by millions of the Internet-of-Things (IoT) devices. Therefore, mobile-edge computing (MEC) and software-defined networking (SDN) are introduced to form a cloud-edge-terminal collaboration network (CETCN) architecture to jointly utilize the communicational and computational resources. Although the CETCN brings many benefits, there still exist some challenges, such as the unclear operation mode, low utilization of edge resources, as well as the limited energy of terminals. To address these problems, a reinforcement learning-based joint communicational-and-computational resource allocation mechanism (RJCC) is proposed to optimize overall processing delay under energy limits. In RJCC, a Q -learning-based online offloading algorithm and a Lagrange-based migration algorithm are designed to jointly optimize computation offloading across multisegments and on edge platform, respectively. The simulation results show that the proposed RJCC outperforms the delay-optimal, energy-optimal, and edge-to-terminal offloading algorithm by 42%-74% in long-term average energy consumption while maintaining relatively low delay. Siya Xu, Qingchuan Liu, Bei Gong, Feng Qi 0004, Shao-Yong Guo 0001, Xuesong Qiu 0001 |
IEEE Internet Things J. | 3 |
| 2020 | An efficient privacy-preserving data query and dissemination scheme in vehicular cloud
Yongli Wang 0002, Gang Xiao 0003, Junlong Zhou, Bei Gong |
Pervasive Mob. Comput. | 5 |
| 2020 | A secure and lightweight privacy-preserving data aggregation scheme for internet of vehicles
Yongli Wang 0002, Bei Gong, Yanchao Li 0001, Ruxin Zhao, Hao Li 0050 |
Peer-to-Peer Netw. Appl. | 3 |
| 2018 | A remote attestation mechanism for the sensing layer nodes of the Internet of Things
Bei Gong, Yu Zhang 0138 |
Future Gener. Comput. Syst. | 1 |
| 2018 | The Model Design of Mobile Resource Scheduling in Large Scale Activities
Cai-Qiu Zhou, Yuwang Yang, Bei Gong, Mengkun Li, Renqiang Wen |
Mob. Networks Appl. | 3 |