VLDB 2026 Research / reviewers in the wild / expert
Yubo Song
dblp:45/10757
· DBLP profile ↗
32ranked-venue papers
7as first author
24since 2021 · last 2027
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 3 first-author · 10 since 2021Security and privacy · 7 · 3 first-author · 7 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Structured evidence consolidation for reliable low-resource named entity recognition
Yubo Song, Boran Shao, Shang Gao 0006, Liquan Chen |
Expert Syst. Appl. | 1 |
| 2026 | Personalized differential privacy for high-dimensional data: A random sampling and pruning privacy tree approach
Zhongyuan Qin, Kefei Lu, Yuchuan Liu, Liquan Chen, Yubo Song |
Comput. Secur. | 5 |
| 2026 | Fine-Grained IoT Device Fingerprinting Using Active Probing
Yubo Song, Yuncong Ma, Guyue Li, Liquan Chen, Shang Gao 0006, Bin Xiao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Effective Sample Generation for Industrial Control Systems: A GAN-Based ApproachabstractIn industrial control systems (ICSs), safeguarding system security is vital, and intrusion detection is an effective protective measure. In real-world ICS environments, however, the training data for intrusion-detection models are dominated by normal traffic, with very few abnormal samples. This scarcity prevents the model from fully learning abnormal characteristics, thereby limiting anomaly-detection performance. ICS traffic is also noisy and often captured incompletely, which is especially problematic because it possesses strong temporal dependencies. Moreover, ICS operations tend to be highly regular and follow a strict logical order, causing data to cluster densely in certain regions while edge regions remain sparsely populated—an imbalance that easily leads to misclassification. To tackle data imbalance, missing temporal features, and edge-sample scarcity, we propose the DualCGAN-AE approach. It employs two conditional generative adversarial networks to perform dynamic learning on global and edge features and to enrich samples with temporal information; a multimodel discriminator is incorporated to enhance training stability. We validated the method on two datasets, assessing both the quality of the generated samples and their impact on intrusion detection performance. Experimental results show that the samples produced by DualCGAN-AE significantly boost detection accuracy. Zhongyuan Qin, Liquan Chen, Yubo Song |
IEEE Trans. Ind. Informatics | 5 |
| 2025 | Enhancing wircless channel authentication in industrial control: Attack-resistant CSI-based PUF
Yubo Song, Wenchang Liu, Jiyuan Huang, Yazhi Deng |
Ad Hoc Networks | 1 |
| 2025 | Hybrid authenticated key agreement utilizing CSI for enhanced wireless security
Yubo Song, Qingyue Yu, Yile Zhang, Dali Deng, Zhefu Deng |
Comput. Networks | 1 |
| 2025 | A multi-source log semantic analysis-based attack investigation approach
Yubo Song, Kanghui Wang, Zhongyuan Qin, Bang Lv |
Comput. Secur. | 1 |
| 2025 | PPCA: Privacy-Preserving Continuous Authentication Scheme With Consistency Proof for Zero-Trust Architecture NetworksabstractContinuous authentication (CA) has been widely applied by network service providers to verify user identities in finance, healthcare, and e-commerce fields. However, in next-generation networks, CA faces the risk of user privacy leakage due to its dependence on a verifier-centric authentication model, and verifiers may not always be trustworthy, particularly in zero-trust architecture networks. Existing privacy protection schemes face challenges in solving this problem because these schemes will weaken the linkability of context requests, leading to difficulties in consistency checks for fine-grained CA. To fill the gap, this article proposes a privacy-preserving CA (PPCA) scheme by incorporating anonymous self-sovereign identity and fine-grained CA. Specifically, PPCA exploits subset proof to enable users to reveal only the minimum necessary identity data for selective disclosure. To support fine-grained CA, we construct a new consistency proof for the anonymous user to prove that the different credentials are bound to the same attributes set, where the user is responsible for deciding whether to send the consistency proof. PPCA is formalized, defined, and constructed based on BLS signatures, Set Commitment, and Sigma Protocol. The security analysis shows that PPCA is correct and sound and supports user anonymity and credential consistency at the same time. The performance evaluation shows that PPCA requires only minimal additional time cost, achieving an optimal balance between security and efficiency. Guyue Li, Jiaheng Wang 0001, Bin Xiao 0001, Yubo Song |
IEEE Internet Things J. | 5 |
| 2024 | EtherEditor: Bytecode Defense Framework for Unleashing Proactive Smart Contract SecurityabstractSmart contracts play a pivotal role in Ethereum by providing autonomous control functions and eliminating risks from third parties. However, there exists a current dearth of a universal automated solution to ensure contract security. In this paper, we propose EtherEditor, a bytecode-based framework to enhance smart contract security. EtherEditor operates independently of the source code, directly analyzing bytecode to automate the reconstruction of Control Flow Graphs (CFGs), vulnerability detection, and patching processes. The paper initiates with the development of a virtual execution engine for symbolic execution of bytecode, dynamically interpreting the effects of various opcodes on the stack. This approach culminates in the creation of a high-precision CFG at the bytecode level, capturing nuanced semantic information. This method lays a solid foundation for subsequent work. The paper then collects sensitive semantic information from the constructed CFG, including data flow and control flow characteristics, aiming to detect vulnerabilities by identifying risk instructions that contribute to vulnerabilities. Finally, the paper generates patch instances using preset patch templates based on the current contract’s context. These instances are then infused into the original bytecode via an advanced trampoline patch injection technique, ensuring the seamless operation of the amended contract. Extensive experiments demonstrate that our method achieves significant improvements in existing smart contract vulnerability detection and patch rewriting. Yadong Shi, Zhongyuan Qin, Yubo Song |
HPCC | 4 |
| 2024 | MoDID: Decentralized Identity Management for Multiple OwnersabstractIdentity management plays a critical role in Web3 applications. Decentralized Identity (DID) offers a privacy-preserving solution, giving users full control over their identity information. Existing research on DID primarily focuses on single-owner scenarios, where owners have complete privileges for owner management and credentials. However, in multi-owner cases, current coarse-grained identity management approaches lead to serious privacy and security problems, such as identity impersonation and high key recovery overhead. Little work has been done on identity management for multiple owners. In this paper, we propose MoDID, a fine-grained identity management scheme for multiple owners, which complies with the DID standard proposed by W3C. First, our solution allows multiple owners to control DID subjects flexibly and reliably through hierarchical owner management. Additionally, we design a secure key recovery scheme to reduce the risk of identity loss while introducing lower overhead. Finally, we implement MoDID on the Sepolia Ethereum Test Network to evaluate the effectiveness of our proposed scheme. The result demonstrates that our system allows multiple owners to manage a single identity with lower gas consumption and time consumption than the state-of-the-art. Huijiong Yang, Rui Song 0010, Yubo Song, Bin Xiao 0001 |
ICC | 4 |
| 2023 | Leaking Arbitrarily Many Secrets: Any-out-of-Many Proofs and Applications to RingCT ProtocolsabstractRing Confidential Transaction (RingCT) protocol is an effective cryptographic component for preserving the privacy of cryptocurrencies. However, existing RingCT protocols are instantiated from one-out-of-many proofs with only one secret, leading to low efficiency and weak anonymity when handling transactions with multiple inputs. Additionally, current partial knowledge proofs with multiple secrets are neither secure nor efficient to be applied in a RingCT protocol.In this paper, we propose a novel any-out-of-many proof, a logarithmic-sized zero-knowledge proof scheme for showing the knowledge of arbitrarily many secrets out of a public list. Unlike other partial knowledge proofs that have to reveal the number of secrets [ACF21], our approach proves the knowledge of multiple secrets without leaking the exact number of them. Furthermore, we improve the efficiency of our method with a generic inner-product transformation to adopt the Bulletproofs compression [BBB+18], which reduces the proof size to 2⌈log2(N)⌉+9.Based on our proposed proof scheme, we further construct a compact RingCT protocol for privacy cryptocurrencies, which can provide a logarithmic-sized communication complexity for transactions with multiple inputs. More importantly, as the only known RingCT protocol instantiated from the partial knowledge proofs, our protocol can achieve the highest anonymity level compared with other approaches like Omniring [LRR+19]. For other applications, such as multiple ring signatures, our protocol can also be applied with some modifications. We believe our techniques are also applicable in other privacy-preserving scenarios, such as multiple ring signatures and coin-mixing in the blockchain. Tianyu Zheng, Shang Gao 0006, Yubo Song, Bin Xiao 0001 |
SP | 3 |
| 2023 | A Survey of Blockchain-Based Schemes for Data Sharing and ExchangeabstractData immutability, transparency and decentralization of blockchain make it widely used in various fields, such as Internet of things, finance, energy and healthcare. With the advent of the Big Data era, various companies and organizations urgently need data from other parties for data analysis and mining to provide better services. Therefore, data sharing and data exchange have become an enormous industry. Traditional centralized data platforms face many problems, such as privacy leakage, high transaction costs and lack of interoperability. Introducing blockchain into this field can address these problems, while providing decentralized data storage and exchange, access control, identity authentication and copyright protection. Although many impressive blockchain-based schemes for data sharing or data exchange scenarios have been presented in recent years, there is still a lack of review and summary of work in this area. In this paper, we conduct a detailed survey of blockchain-based data sharing and data exchange platforms, discussing the latest technical architectures and research results in this field. In particular, we first survey the current blockchain-based data sharing solutions and provide a detailed analysis of system architecture, access control, interoperability, and security. We then review blockchain-based data exchange systems and data marketplaces, discussing trading process, monetization, copyright protection and other related topics. Rui Song 0010, Bin Xiao 0001, Yubo Song, Songtao Guo, Yuanyuan Yang 0001 |
IEEE Trans. Big Data | 3 |
| 2022 | : A Traceable and Privacy-Preserving Data Exchange Scheme based on Non-Fungible Token and Zero-KnowledgeabstractWith the advent of the Big Data era, industry, business and academia have developed various data exchange schemes to make data more economically beneficial. Unfortunately, most of the existing systems provide only one-time data exchanges without the ability to track the provenance and transformations of datasets. In addition, existing systems encrypt the data to protect data privacy, which hinders demanders from verifying the correctness of the data and evaluating its value.To provide data traceability and privacy while ensuring fairness during data exchanges, we design and implement ZKDET, a traceable data exchange scheme based on non-fungible token and zero-knowledge, which is able to (i) track all transformations of data during their lifecycle and record them on the blockchain; (ii) provide zero-knowledge proofs to securely guarantee that all complex transformations and data contents are correct and meet specific requirements; and (iii) warrant exchange fairness and data privacy in public storage platforms. Security analysis and evaluations on ZKDET show that it can support traceable data exchange while preserving data privacy and maintaining high throughput despite large data volumes. Rui Song 0010, Shang Gao 0006, Yubo Song, Bin Xiao 0001 |
ICDCS | 3 |
| 2022 | VecSeeds: Generate fuzzing testcases from latent vectors based on VAE-GANabstractIn fuzzing, the generative adversarial network learns from the training set and generates test-cases with similar formats, so as to provide inputs conforming to the input format for programs tested. However, problems of the unstable training process, single generation method, and monotonic sample types generated exist in general generative adversarial networks. This paper proposes a fuzzing input generation technique based on VAE-GAN, which introduces the representation learning process of variational auto-encoder for traditional generative adversarial networks, so that it can learn and utilize the character information of testcases, improving the stability of training and generate various testcases. It is shown that testcases generated by VAE-GAN trigger more unique tuples than other existing generative adversarial networks on 3 among 4 selected target programs. Moreover, compared with the AFL mutation training set, testcases generated by VAE-GAN can improve code coverage by up to 11.87%, and the discovery rate of 15.74% and 5.36% in the unique crashes and hangs respectively. Xujian Liu, Jiarong Fan, Zeru Li, Yubo Song, Zhongyuan Qin |
TrustCom | 6 |
| 2022 | Smart Grid Data Aggregation Scheme Based on Local Differential PrivacyabstractWith the development of IoT technology, smart grid has gradually replaced the traditional grid. Smart grid is convenient and fast. It can provide real-time residential electricity monitoring and forecasting, give users better electricity guidance and save a lot of labor costs. Smart meters send customers’ electricity consumption data to the gateway, which aggregates the data and then sends it to the electricity consumption control center. But in this process, there will be a security problem of leakage of customer’s electricity consumption data. Most of the current user data privacy protection collection schemes use homomorphic encryption and randomization techniques. However, some of these schemes require a trusted third-party entity, and some may cause significant computational overhead. Due to the limited computational resources of smart meters, these techniques may be impractical. In this paper, we propose a local differential privacy data aggregation protection scheme based on the idea of grouping perturbation of electricity consumption data according to data domains. Experiments show that our scheme can provide statistical estimates of electricity in the region while satisfying the privacy protection of customers’ electricity consumption data. Moreover, our scheme has small computational and communication overheads, which can meet the application requirements in practical scenarios. Dong Mao, Zuge Chen, Yubo Song, Liquan Chen, Zhongyuan Qin |
TrustCom | 4 |
| 2022 | An Adaptive BSCO Algorithm of Solid Color Optimization for 3D Reconstruction System with PIFuHD
Chao-Hsien Hsieh, Yubo Song, Changfeng Li |
WASA (2) | 2 |
| 2022 | Computer-Aided Recognition Based on Decision-Level Multimodal Fusion for DepressionabstractAiming at the problem of depression recognition, this paper proposes a computer-aided recognition framework based on decision-level multimodal fusion. In Song Dynasty of China, the idea of multimodal fusion was contained in "one gets different impressions of a mountain when viewing it from the front or sideways, at a close range or from afar" poetry. Objective and comprehensive analysis of depression can more accurately restore its essence, and multimodal can represent more information about depression compared to single modal. Linear electroencephalography (EEG) features based on adaptive auto regression (AR) model and typical nonlinear EEG features are extracted. EEG features related to depression and graph metric features in depression related brain regions are selected as the data basis of multimodal fusion to ensure data diversity. Based on the theory of multi-agent cooperation, the computer-aided depression recognition model of decision-level is realized. The experimental data comes from 24 depressed patients and 29 healthy controls (HC). The results of multi-group controlled trials show that compared with single modal or independent classifiers, the decision-level multimodal fusion method has a stronger ability to recognize depression, and the highest accuracy rate 92.13% was obtained. In addition, our results suggest that improving the brain region associated with information processing can help alleviate and treat depression. In the field of classification and recognition, our results clarify that there is no universal classifier suitable for any condition. Hanshu Cai, Yubo Song, Tao Lei 0003 |
IEEE J. Biomed. Health Informatics | 3 |
| 2022 | Griffin: Real-Time Network Intrusion Detection System via Ensemble of Autoencoder in SDNabstractMany efforts have been devoted to the development of efficient Network Intrusion Detection System (NIDS) using machine learning approaches in Software-defined Network (SDN). Unfortunately, existing solutions failed to detect real-time and zero-day attacks due to their limited throughput and prior knowledge-based detection. To this end, we propose Griffin, a NIDS that uses unsupervised machine learning expertise to detect both known and zero-day intrusion attacks in real-time with high accuracy. Specifically, Griffin uses an efficient feature extraction framework to capture the sequential features of the traffic packets. Then, it utilizes cluster analysis to reduce the feature scale to achieve low throughput. Moreover, an ensemble autoencoder is built automatically to further extract features with low complexity and high precision to train the model. We evaluate the accuracy, robustness, and complexity of the system using open datasets. The result shows that Griffin’s complexity is about 40% lower, and its accuracy is at most 19% higher than existing NIDS.Additionally, even in the situation with evasion, the Griffin has at most 9% decrease of AUC, which is a good performance compared with other solutions. Furthermore, this paper also utilizes the differential privacy framework during training autoencoders to protect datasets’ privacy which is inherent in machine learning approaches. Liyan Yang, Yubo Song, Shang Gao 0006, Aiqun Hu, Bin Xiao 0001 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | IoT-ID: Robust IoT Device Identification Based on Feature Drift AdaptationabstractInternet of Things (IoT) devices deployed in publicly accessible locations increasingly encounter security threats from device replacement and impersonation attacks. Unfortunately, the limited memory and poor computing capability on such devices make solutions involving complex algorithms or enhanced authentication protocols untenable. To address this issue, device identification technologies based on traffic characteristics finger-printing have been proposed to prevent illegal device intrusion and impersonation. However, because of time-dependent distribution of traffic characteristics, these approaches often become less accurate over time. Meanwhile insufficient attention has been paid to the impact of possible changes on the accuracy of device identification. Therefore, we propose a novel feature selection method based on degree of feature drift and genetic algorithm to keep high accuracy and stability of device identification. The degree of feature drift— relevance of features through time and gain ratio are combined as a composite metric to filter out stable features. Furthermore, in order to perform equally well in device identification, we use the genetic algorithm to select the most discriminate feature subset. Experiments show that the accuracy of device recognition compared with other methods is increased from 86.4% to 94.5%, and the robustness of recognition is also improved. Yubo Song, Brendan Jennings, Fan Zhang 0077, Bin Xiao 0001, Shang Gao 0006 |
GLOBECOM | 2 |
| 2021 | You Can Hear But You Cannot Record: Privacy Protection by Jamming Audio RecordingabstractUnauthorized voice recording via smartphones can leak the talking content stealthily. This would be a serious security threat to those individuals, enterprises and the government who need to keep the conversation confidential. Furthermore, due to the size miniaturization of smartphones, it is hard to find the covert recording from malicious attendees. Existing solutions usually jam the recording with audible noise or electromagnetic emitting. However, the audible noise will seriously interfere with conversation and the effect of electromagnetic emitting will be limited by the distance. In this paper, we propose UltraArray, a pioneering silent ultrasonic anti-recording jammer, which can covertly block recording for a long distance. The principle of covert blocking is inspired by acoustic parametric array theory, which suggests that the audible frequency wave can be spread through the air silently while it is modulated to an inaudible ultrasonic frequency. The modulation used in this paper is double sideband (DSB) modulation. The microphone on the phone will record the audible frequency and filtering out the ultrasonic frequency. The jammer we developed uses an acoustics array to form a beam to spread the signal further. The evaluation shows that the device has a good jamming effect on more than 5 meters for most Android smartphones. It will also work well with more than 2.5 meters effective distance on iPhone XR, which has the active noise control (ANC) function. Those results achieve ten times the interference ability of existing solutions. Xiaosong Ma, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
ICC | 2 |
| 2021 | My Site Knows Where You Are: A Novel Browser Fingerprint to Track User PositionabstractUtilizing browsers to identify and track users has become a routine on the Web in recent years. It is easy for the browser to collect sensitive information and construct comprehensive user profiles while the users are still unaware. As the problem mentioned above, several anti-fingerprint mechanisms have been adopted to protect user privacy. However, our research finds a novel method based on localization fingerprints that may still threaten user privacy. The location fingerprint obtains the response delay of data transmission over the link between the users and the third-party sites. Since the physical link state information between the host and the remote website is distinct and steady, it can be used to extract statistical features and construct user profiles. We implement a multilateration cross-site image resource request scheme to collect link-state information of users and develop a prototype called PingLoc to evaluate the effectiveness. About 1,093 users from all over the world are involved in our experiment. The evaluation shows that the delay features collected are stable, and the accuracy of the localization fingerprint is up to 98%. Pressure testing shows that the PingLoc is robust against various anti-fingerprint mechanisms and achieves 93.5% accuracy for browser switching, 80.6% accuracy for virtual machine disguising, and 88.2% accuracy for IP rotation. Yubo Song, Fan Zhang 0077, Shang Gao 0006, Bin Chen 0007 |
ICC | 2 |
| 2021 | Data desensitization mechanism of Android application based on differential privacyabstractIn recent years, the mining and analysis of user data by Android applications have posed the risk of privacy breaches. However excessive permission control can affect the usability of applications. A mechanism that balances security and usability is urgently needed. In this paper, a data desensitization mechanism for Android applications based on differential privacy techniques is proposed. The mechanism can address the privacy protection of data flows generated by the interaction between users and Android applications. In order to solve the problem of constraints on the basic functions of the application caused by privacy security technique, this paper introduces a differential privacy mechanism based on Gaussian process. The mechanism performs hyperparametric optimization methods that combine sparse approximations and classification results. Also, by specifying the global sensitivity of the differential privacy budget specific randomization algorithm, the mechanism selects parameters with a specific probability to obtain the most effective parameter combination. Experimental results show that the differential privacy technique based on Gaussian process further enhances the availability of Android application data while obtaining the same privacy protection effect compared with ordinary differential privacy mechanisms. Xinzao Jiang, Yubo Song, Rui Song 0010, Aiqun Hu |
VTC Fall | 2 |
| 2021 | Permission Sensitivity-Based Malicious Application Detection for AndroidabstractSince a growing number of malicious applications attempt to steal users’ private data by illegally invoking permissions, application stores have carried out many malware detection methods based on application permissions. However, most of them ignore specific permission combinations and application categories that affect the detection accuracy. The features they extracted are neither representative enough to distinguish benign and malicious applications. For these problems, an Android malware detection method based on permission sensitivity is proposed. First, for each kind of application categories, the permission features and permission combination features are extracted. The sensitive permission feature set corresponding to each category label is then obtained by the feature selection method based on permission sensitivity. In the following step, the permission call situation of the application to be detected is compared with the sensitive permission feature set, and the weight allocation method is used to quantify this information into numerical features. In the proposed method of malicious application detection, three machine-learning algorithms are selected to construct the classifier model and optimize the parameters. Compared with traditional methods, the proposed method consumed 60.94% less time while still achieving high accuracy of up to 92.17%. Yubo Song, Yijin Geng, Shang Gao 0006 |
Secur. Commun. Networks | 1 |
| 2021 | Just Shake Them Together: Imitation-Resistant Secure Pairing of Smart Devices via ShakingabstractIn traditional device‐to‐device (D2D) communication based on wireless channel, identity authentication and spontaneous secure connections between smart devices are essential requirements. In this paper, we propose an imitation‐resistant secure pairing framework including authentication and key generation for smart devices, by shaking these devices together. Based on the data collected by multiple sensors of smart devices, these devices can authenticate each other and generate a unique and consistent symmetric key only when they are shaken together. We have conducted comprehensive experimental study on shaking various devices. Based on this study, we have listed several novel observations and extracted important clues for key generation. We propose a series of innovative technologies to generate highly unique and completely randomized symmetric keys among these devices, and the generation process is robust to noise and protects privacy. Our experimental results show that our system can accurately and efficiently generate keys and authenticate each other. Congcong Shi, Lei Xie 0004, Peicheng Yang, Yubo Song, Sanglu Lu |
Wirel. Commun. Mob. Comput. | 5 |
| 2020 | Griffin: An Ensemble of AutoEncoders for Anomaly Traffic Detection in SDNabstractThe Network Intrusion Detection Systems (NIDS) with machine learning in SDN become increasingly popular solutions. NIDS uses abnormal traffic detection to identify unknown network attacks. Most of today's abnormal traffic detection systems are supposed to continuously update the recognition model in time based on the features from newly collected packets to accurately identify unknown network attack behaviors. However, those existing solutions always require a large number of packets to train the recognition model offline. That means it is impossible to accurately detect the emergence of new cyber-attacks immediately. This paper proposes Griffin, a per-packet anomaly detection system that can dynamically update the training model based on neural networks. The Griffin is executed in SDN environment, utilizing a novel ensemble of autoencoders to collectively filter out abnormal traffic from normal traffic. Meanwhile, the autoencoders are updated based on the root mean square error to adjust the training model. The adjustment is done in an unsupervised manner, which needs no expert to label the network traffic or update the model from time to time. Our evaluations, with the open Datasets provided by Yisroel Mirsky, show that Griffin's time delay is around 0. 1s and its accuracy is 98%. Moreover, we also compare Griffin with other four similar NIDSs and find that Griffin performs the best in terms of Matthews Correlation Coefficient and complexity. Liyan Yang, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 2 |
| 2020 | ClickGuard: Exposing Hidden Click Fraud via Mobile Sensor Side-channel AnalysisabstractAdvertising income depends on the amount of clicks by users of websites and mobile applications. However, the emergence of click fraud greatly reduces the real benefits of the advertisement. Most existing researches focus on detecting click fraud by analyzing properties and patterns of click data streams, but attackers can construct data that looks legitimate by replaying former data streams. In this paper, we propose a novel system called ClickGuard to detect click fraud attacks. ClickGuard takes advantage of motion sensor signals from mobile devices, since the pattern of motion signals is completely different under real click events and fraud events. To prevent attackers from bypassing the system by faking the time-domain statistical characteristics of original signals, we introduce the MFCC algorithm in feature extraction phase. MFCC algorithm can extract frequency-domain features of original signals in specific frequency bands which are hardly constructed out of thin air. Classifiers are finally constructed using these features and several machine learning algorithms. Experiments show that ClickGuard can achieve the accuracy of 96.71% in general environment and 84.16% when attackers modify the time-domain statistical characteristics of raw data. Congcong Shi, Rui Song 0010, Xinyu Qi, Yubo Song, Bin Xiao 0001, Sanglu Lu |
ICC | 4 |
| 2020 | Detection and Mitigation of DoS Attacks in Software Defined NetworksabstractThe introduction of software-defined networking (SDN) has emerged as a new network paradigm for network innovations. By decoupling the control plane from the data plane in traditional networks, SDN provides high programmability to control and manage networks. However, the communication between the two planes can be a bottleneck of the whole network. SDN-aimed DoS attacks can cause long packet delay and high packet loss rate by using massive table-miss packets to jam links between the two planes. To detect and mitigate SDN-aimed DoS attacks, this paper presents FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks. FloodDefender stands between the controller platform and other controller apps, and conforms to the OpenFlow policy without additional devices. The detection module in FloodDefender utilizes new frequency features to precisely identify SDN-aimed DoS attacks. The mitigation module uses three new techniques to efficiently mitigate attack traffic: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to filter out attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. Our evaluation on a prototype implementation of FloodDefender shows that the defense framework can precisely identify and efficiently mitigate the SDN-aimed DoS attacks with very little overhead. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Aiqun Hu, Yubo Song, Kui Ren 0001 |
IEEE/ACM Trans. Netw. | 5 |
| 2019 | iShake: Imitation-Resistant Secure Pairing of Smart Devices via ShakingabstractIn conventional device-to-device (D2D) communication through wireless channels, it is an essential demand to authenticate with each other and establish spontaneous secure connections among the smart devices. In this paper, we propose an imitation-resistant mutual authentication and key generation framework for smart devices, by shaking these devices together. According to the multi-sensor data collected from smart devices, these devices are able to authenticate each other and generate a unique and consistent symmetric key if and only if they are shaken together. We have conducted comprehensive experimental study on shaking various devices, illustrated several novel observations and extracted some important clues for efficient key generation. We propose a series of novel techniques to make the key generation robust to noise and privacy-preserving, and generate highly distinctive and fully randomized symmetric keys among these devices. Realistic experiment results indicate that our solution is able to authenticate with each other and generate the symmetric keys with high accuracy and time-efficiency. Congcong Shi, Lei Xie 0004, Peicheng Yang, Yubo Song, Sanglu Lu |
ICPADS | 5 |
| 2018 | I Know What You Type: Leaking User Privacy via Novel Frequency-Based Side-Channel AttacksabstractSmartphone sensors have been applied to record the movement of users for healthy use. However, the motion sensor readings recorded by malicious applications can be utilized as a side-channel to leak user privacy by keystroke inference. Most existing approaches use time-domain statistical characteristics for keystroke inference. Their systems are poor to show the subtle changes in short time period, since the time- domain statistical features can only reflect the characteristics in a long-time interval. In this paper, we propose a novel framework to perform keystroke inference on smartphones. This framework introduces an improved MFCC algorithm to extract frequency- domain features for more comprehensive use of raw data. Since the frequency-domain energy distribution of motion signals is concentrated, and the specificity of signals is strong, MFCC can improve the inference accuracies under complex scenarios. Based on this framework, we present a prototype called FreqKey, which is an inference system to leak user privacy such as PINs and passwords. FreqKey collects motion sensor readings during keystroke events and constructs classification models with machine learning algorithms. Experimental results show that FreqKey improves the performance in a variety of complex scenarios. Especially, even in web platform whose sampling rate is lower than 80Hz, FreqKey can achieve relatively high accuracy of 74.6%. To mitigate the frequency-based side-channel attack and protect user privacy, we propose a defense solution which contains sensor- activity monitoring, malicious program identification and interference signal injection. Rui Song 0010, Yubo Song, Shang Gao 0006, Bin Xiao 0001, Aiqun Hu |
GLOBECOM | 2 |
| 2017 | Novel attacks in OSPF networks to poison routing tableabstractLink State Advertisement (LSA) reflects the current status of all incident links of a router in an Autonomous System (AS). A fake LSA with false link status information will pollute the view of the network topology on routers. In this paper, we present two novel attacks that inject malicious Link State Advertisements (LSAs) to modify the routing tables: adjacency spoofing and single path injection. Adjacency spoofing attack makes attacker access to routing networks by disguising as a legitimate router. Single path injection attack evades the “fight-back” mechanism and affects routing advertisements of routers. Unlike existing LSA injection attacks, which need to be launched by malicious routers, a common host can launch these attacks and control the transmission path of data traffic in an AS. Simulation and real-world experiment results show that these two attacks can efficiently modify the routing tables of routers, and further lead to DNS spoofing, phishing Website, eavesdropping, and manin-the-middle attacks. Furthermore, we also implement a security vulnerability detection system to detect the existing vulnerabilities of routing protocol deployed in real-world routers. Yubo Song, Shang Gao 0006, Aiqun Hu, Bin Xiao 0001 |
ICC | 1 |
| 2017 | SCoP: Smartphone energy saving by merging push services in Fog computingabstractEnergy saving solutions on smartphone devices can greatly extend a smartphone's lasting time. However, today's push services require keep-alive connections to notify users of incoming messages, which cause costly energy consuming and drain a smartphone's battery quickly in cellular communications. Most keep-alive connections force smartphones to frequently send heartbeat packets that create additional energy-consuming radio-tails. No previous work has addressed the high-energy consumption of keep-alive connections in smartphones push services. In this paper, we propose Single Connection Proxy (SCoP) system based on fog computing to merge multiple keep-alive connections into one, and push messages in an energy-saving way. The new design of SCoP can satisfy a predefined message delay constraint and minimize the smartphone energy consumption for both real-time and delay-tolerant apps. SCoP is transparent to both smartphones and push servers, which does not need any changes on today's push service framework. Theoretical analysis shows that, given the Poisson distribution of incoming messages, SCoP can reduce the energy consumption by up to 50%. We implement SCoP system, including both the local proxy on the smartphone and remote proxy on the “Fog”. Experimental results show that the proposed system consumes 30% less energy than the current push service for real-time apps, and 60% less energy for delay-tolerant apps. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Qingjun Xiao, Yubo Song |
IWQoS | 5 |
| 2016 | Secure and energy efficient prefetching design for smartphonesabstractEnergy efficient prefetching systems for smart-phones can greatly reduce energy consumption and data transmission, and maintain the timely response when information is prefetched. However, the proxy structure of the system can cause security problem to reveal private information to the third party. The end-to-end encryption (SSL) in traditional prefetching systems cannot solve the security problem in this new, complex energy efficient prefetching system. In this paper, we propose Secure and Energy Efficient Prefetching (SEEP) to meet the security requirement of HTTPS connections and to save smartphone's energy consumption and data transmission. The new design of SEEP includes two parts: the local proxy on the smartphone to verify the validity of prefetched responses, and the remote proxy (e.g. on the cloudlet) to store encrypted prefetched responses. SEEP is transparent to both smartphones and web servers, which does not need to change today's Browser/Server framework. Security analysis shows that SEEP protects the confidentiality of requests and responses, and is able to resist replay attack from malicious proxy. Experimental results show that the proposed system consumes 25% less energy and 95% less data when prefetching 10 outbound webpages than the traditional prefetching system in Wi-Fi networks. Shang Gao 0006, Zhe Peng, Bin Xiao 0001, Yubo Song |
ICC | 4 |