Beibei Li 0002

dblp:45/2422-2 · DBLP profile ↗
← Back
70ranked-venue papers
20as first author
58since 2021 · last 2026
0000-0002-0485-1975ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 27 · 8 first-author · 20 since 2021Artificial intelligence and machine learning · 11 · 11 since 2021Security and privacy · 11 · 2 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 5 first-author · 8 since 2021Systems, architecture and hardware · 6 · 4 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 5 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021
YearPublicationVenuePosition
2026 Beyond Class Boundaries: Federated Visual Primitive Sharing with Text-Guided Adaptation
abstract
Personalized Federated Learning (pFL) effectively addresses the challenge of statistical heterogeneity in traditional Federated Learning (FL), with feature alignment methods (e.g., FedProto) standing out due to their communication efficiency and model-agnostic design, making them practically viable in real-world non-IID scenarios. These methods directly align class-level features across clients without requiring model parameter transmission. However, they represent each class as a holistic prototype, which limits the diversity and expressiveness of shared features. This restriction hampers the model's ability to generalize across clients and impedes personalized adaptation, as clients lack sufficient semantic components to reconstruct discriminative features tailored to their local data distributions. To overcome these limitations, we propose Federated Visual Primitive Learning (FedVPL), a novel framework comprising two key components: (1) Visual Primitive Space Sharing, which decomposes class-level features into semantically meaningful and reusable visual primitives, enabling cross-client and cross-class sharing to enrich feature diversity and decouple communication cost from the number of classes, significantly improving efficiency; and (2) Text-Guided Semantic Alignment, a parameter-free personalization mechanism that leverages external language priors to align shared primitives with client-specific semantics, without requiring additional communication overhead. Extensive experiments across diverse non-IID benchmarks demonstrate that FedVPL substantially outperforms state-of-the-art baselines, achieving up to a 5.62% improvement in accuracy, reducing communication overhead by at least 12.5x, and effectively addressing generalization and personalization challenges in heterogeneous federated environments.
Yongqiang Huang 0003, Tao Wang 0167, Zerui Shao, Beibei Li 0002, Yi Zhang 0018
WWW6
2026 Distributed attack-mode-driven HT control for T-S fuzzy MASs under channel-dependent DoS attacks
Ruimei Zhang, Beibei Li 0002, Ju H. Park 0001, Mao Chen 0013
Fuzzy Sets Syst.3
2026 Secure stabilization and CRYSTALS-Kyber-based SIC application for memristive neural networks with RDCs and DoS attacks
Di Dong, Ruimei Zhang, Ju H. Park 0001, Deqiang Zeng, Beibei Li 0002
Neurocomputing5
2026 A feature selection method based on clonal selection with beneficial noise
Wenshan Li 0001, Chenyi Huang, Ao Liu 0005, Beibei Li 0002, Junjiang He, Wenbo Fang
Pattern Recognit.5
2026 Analysis on the Feasibility of D-FACTS Devices for Localizing FDI Attacks in Smart Grids
abstract
Proactive detection with distributed flexible AC transmission system (D-FACTS) devices has been extensively studied for identifying false data injection (FDI) attacks in smart grids, while their potential for localizing remains largely unexplored. To meet this gap, this paper systematically explores the feasibility of localizing FDI attacks with D-FACTS devices. Specifically, we first thoroughly study the rationale underlying FDI localization with D-FACTS devices. We prove that an activated D-FACTS device is capable of localizing FDI attacks targeted on its connected end buses once a bad data detection (BDD) alarm is triggered. In addition, we elaborately analyze the inherent localization limitations: (i) the unlocalizable adversary cases targeting one-degree buses or super-buses; (ii) the localization uncertainty introduced by the defender's blind spots, resulting in huge operational costs and insufficient precision. Following this, a data-prompting framework is designed to over-come the above limitations. This framework integrates a data driven injected error identifier for precise localization and cost reduction, followed by a perturbation strategy with D-FACTS devices that significantly lowers false positive rates. Extensive simulations validate our theoretical findings on the rationale and limitations, while also demonstrating the effectiveness of the proposed framework in addressing limitations and enhancing localization accuracy.
Qingyun Du, Mi Wen, Chonghua Wang, Beibei Li 0002, Yan Zhang 0002
IEEE Trans. Dependable Secur. Comput.4
2026 Beyond the Protocol: Unveiling Attack Vectors in the Model Context Protocol (MCP) Ecosystem
abstract
The Model Context Protocol (MCP) is an emerging standard designed to enable seamless interaction between Large Language Model (LLM) applications and external tools or resources. Within a short period, thousands of MCP services have been developed and deployed. However, the client-server integration architecture inherent in MCP may expand the attack surface against LLM Agent systems, introducing new vulnerabilities allowing attackers to exploit by malicious MCP servers.In this paper, we present thefirst end-to-end empirical evaluationof attack vectors targeting the MCP ecosystem. We provide the formal definitions, affected path, and exploited path based on the workflow for four malicious server attacks, i.e.,Tool Poisoning Attacks,Puppet Attacks,Rug Pull Attacks, andExploitation via Malicious External Resources. To evaluate their feasibility, we conduct experiments following the typical steps of launching an attack through malicious MCP servers: upload → download → attack. Specifically, we first construct malicious MCP servers and successfully upload them to three widely used MCP aggregation platforms. The results indicate that current audit mechanisms are insufficient to identify and prevent these threats. Next, through a user study and interview with 20 participants, we demonstrate that users struggle to identify malicious MCP servers and often unknowingly install them from aggregator platforms. Finally, we empirically demonstrate that these attacks can trigger harmful actions within the user’s local environment, such as accessing private files or controlling devices to transfer digital assets. Additionally, based on interview results, we discuss four key challenges faced by the current MCP security ecosystem. These findings underscore the urgent need for robust security mechanisms to defend against malicious MCP servers and ensure the safe deployment of increasingly autonomous LLM agents.
Wenxuan Luo, Leixin Guo, Ting Chen 0002, Jiashui Wang, Beibei Li 0002, Xiaosong Zhang 0001, Jiachi Chen
IEEE Trans. Software Eng.7
2025 Grimm: A Plug-and-Play Perturbation Rectifier for Graph Neural Networks Defending Against Poisoning Attacks
abstract
Recent studies have revealed the vulnerability of graph neural networks (GNNs) to adversarial poisoning attacks on node classification tasks. Current defensive methods require substituting the original GNNs with defense models, regardless of the original's type. This approach, while targeting adversarial robustness, compromises the enhancements developed in prior research to boost GNNs' practical performance. Here we introduce Grimm, the first plug-and-play defense model. With just a minimal interface requirement for extracting features from any layer of the protected GNNs, Grimm is thus enabled to seamlessly rectify perturbations. Specifically, we utilize the feature trajectories (FTs) generated by GNNs, as they evolve through epochs, to reflect the training status of the networks. We then theoretically prove that the FTs of victim nodes will inevitably exhibit discriminable anomalies. Consequently, inspired by the natural parallelism between the biological nervous and immune systems, we construct Grimm, a comprehensive artificial immune system for GNNs. Grimm not only detects abnormal FTs and rectifies adversarial edges during training but also operates efficiently in parallel, thereby mirroring the concurrent functionalities of its biological counterparts. We experimentally confirm that Grimm offers four empirically validated advantages: 1) Harmlessness, as it does not actively interfere with GNN training; 2) Parallelism, ensuring monitoring, detection, and rectification functions operate independently of the GNN training process; 3) Generalizability, demonstrating compatibility with mainstream GNNs such as GCN, GAT, and GraphSAGE; and 4) Transferability, as the detectors for abnormal FTs can be efficiently transferred across different systems for one-step rectification.
Ao Liu 0005, Wenshan Li 0001, Beibei Li 0002, Wengang Ma, Tao Li 0016, Pan Zhou 0001
AAAI3
2025 Multi-Pair Temporal Sentence Grounding via Multi-Thread Knowledge Transfer Network
abstract
Given some video-query pairs with untrimmed videos and sentence queries, temporal sentence grounding (TSG) aims to locate query-relevant segments in these videos. Although previous respectable TSG methods have achieved remarkable success, they train each video-query pair separately and ignore the relationship between different pairs. To this end, in this paper, we pose a brand-new setting: Multi-Pair TSG, which aims to co-train these pairs. We propose a novel video-query co-training approach, Multi-Thread Knowledge Transfer Network, to locate a variety of video-query pairs effectively and efficiently. Firstly, we mine the spatial and temporal semantics across different queries to cooperate with each other. To learn intra- and inter-modal representations simultaneously, we design a cross-modal contrast module to explore the semantic consistency by a self-supervised strategy. To fully align visual and textual representations between different pairs, we design a prototype alignment strategy to 1) match object prototypes and phrase prototypes for spatial alignment, and 2) align activity prototypes and sentence prototypes for temporal alignment. Finally, we develop an adaptive negative selection module to adaptively generate a threshold for cross-modal matching. Extensive experiments show the effectiveness and efficiency of our proposed method.
Wanlong Fang, Changshuo Wang 0001, Daizong Liu, Keke Tang, Jianfeng Dong, Pan Zhou 0001, Beibei Li 0002
AAAI8
2025 Graph Agent Network: Empowering Nodes with Inference Capabilities for Adversarial Resilience
abstract
End-to-end training with global optimization have popularized graph neural networks (GNNs) for node classification, yet inadvertently introduced vulnerabilities to adversarial edge-perturbing attacks. Adversaries can exploit the inherent opened interfaces of GNNs' input and output, perturbing critical edges and thus manipulating the classification results. Current defenses, due to their persistent utilization of global-optimization-based end-to-end training schemes, inherently encapsulate the vulnerabilities of GNNs. This is specifically evidenced in their inability to defend against targeted secondary attacks. In this paper, we propose the Graph Agent Network (GAgN) to address the aforementioned vulnerabilities of GNNs. GAgN is a graph-structured agent network in which each node is designed as an 1-hop-view agent. Through the decentralized interactions between agents, they can learn to infer global perceptions to perform tasks including inferring embeddings, degrees and neighbor relationships for given nodes. This empowers nodes to filtering adversarial edges while carrying out classification tasks. Furthermore, agents' limited view prevents malicious messages from propagating globally in GAgN, thereby resisting global-optimization-based secondary attacks. We prove that single-hidden-layer multilayer perceptrons (MLPs) are theoretically sufficient to achieve these functionalities. Experimental results show that GAgN effectively implements all its intended capabilities and, compared to state-of-the-art defenses, achieves optimal classification accuracy on the perturbed datasets.
Ao Liu 0005, Wenshan Li 0001, Tao Li 0016, Beibei Li 0002, Guangquan Xu, Pan Zhou 0001, Wengang Ma, Hanyuan Huang
AAAI4
2025 Enhancing the Open Network: Definition and Automated Detection of Smart Contract Defects
abstract
The Open Network (TON), designed to support Telegram's extensive user base of hundreds of millions, has garnered considerable attention since its launch in 2022. FunC is the most popular programming language for writing smart contracts on TON. It is distinguished by a unique syntax compared to other smart contract languages. Despite growing interest, research on the practical defects of TON smart contracts is still in its early stages. In this paper, we summarize eight smart contract defects identified from TON's official blogs and audit reports, each with detailed definitions and code examples. Furthermore, we propose a static analysis framework called TONScanner to facilitate the detection of these defects. Specifically, TONScanner reuses FunC compiler's frontend code to transform the FunC source code into FunC intermediate representation (IR) in the form of a directed acyclic graph (DAG). Based on this IR, TONScanner constructs a control flow graph (CFG), then transforms it into a static single assignment (SSA) form to simplify further analysis. TONScanner also integrates Data Dependency, Call Graph, Taint Analysis, and Cell Construct, which are specifically tailored for TON blockchain's unique data structures. These components finally facilitate the identification of the eight defects. We evaluate the effectiveness of TONScanner by applying it to 1,640 smart contracts and find a total of 14,995 defects. Through random sampling and manual labeling, we find that TONScanner achieves an overall precision of 97.49%. The results reveal that current TON contracts contain numerous defects, indicating that developers are prone to making errors. TONScanner has proven its ability to accurately identify these defects, thereby aiding in their correction.
Jiachi Chen, Ting Chen 0002, Beibei Li 0002, Zhangyan Lin, Xihan Zhou
ICSE5
2025 FedUFD: Personalized Edge Computing Using Federated Uncertainty-Driven Feature Distillation
abstract
Recently, federated learning (FL) has been considered a promising and well-suited technique for edge computing applications, such as intelligent traffic control, autonomous driving, and mobile crowdsensing. However, since each edge device may perform individual-specific tasks, they often have heterogeneous data distributions that impact the performance of collaborative training models. Personalized FL (PFL) has then received considerable attention to tackle this problem. Many existing PFL works often employ knowledge distillation to mitigate the negative effects of data heterogeneity. Nevertheless, these works often neglect the fact that the knowledge transferred from the teacher models is not completely correct, which limits the personalization performance of edge devices. In this work, we leverage the knowledge contained in global features to explore the potential of global models and propose a novel uncertainty-driven feature distillation framework called FedUFD. Specifically, we design an uncertainty estimation module in local models, by estimating the uncertainty of the personalized feature distribution, FedUFD can measure the difficulty of learning different personalized features, and then combine the global features to distill the corresponding personalized features. Extensive experiments show that FedUFD outperforms fourteen state-of-the-art PFL frameworks in edge computing, beating the best-performing traditional and personalized baselines by up to 45.45% and 3.55%, respectively.
Zerui Shao, Beibei Li 0002, Zhibo Wang 0001, Yanbing Yang 0001, Peiran Wang, Jun Luo 0001
INFOCOM2
2025 FracFace: Breaking the Visual Clues - Fractal-Based Privacy-Preserving Face Recognition
abstract
Face recognition is essential for identity authentication, but the rich visual clues in facial images pose significant privacy risks, highlighting the critical importance of privacy-preserving solutions. For instance, numerous studies have shown that generative models are capable of effectively performing reconstruction attacks that result in the restoration of original visual clues. To mitigate this threat, we introduce FracFace, a fractal-based privacy-preserving face recognition framework. This approach effectively weakens the visual clues that can be exploited by reconstruction attacks by disrupting the spatial structure in frequency domain features, while retaining the vital visual clues required for identity recognition. To achieve this, we craft a Frequency Channels Refining module that reduces sparsity in the frequency domain. It suppresses visual clues that could be exploited by reconstruction attacks, while preserving features indispensable for recognition, thus making these attacks more challenging. More significantly, we design a Frequency Fractal Mapping module that obfuscates deep representations by remapping refined frequency channels into a fractal-based privacy structure. By leveraging the self-similarity of fractals, this module preserves identity relevant features while enhancing defense capabilities, thereby improving the overall robustness of the protection scheme. Experiments conducted on multiple public face recognition benchmarks demonstrate that the proposed FracFace significantly reduces the visual recoverability of facial features, while maintaining high recognition accuracy, as well as the superiorities over state-of-the-art privacy protection approaches.
Wanying Dai, Beibei Li 0002, Naipeng Dong, Guangdong Bai, Jin Song Dong 0001
NeurIPS2
2025 Phone-to-EDU: A Smart Contract-Based Framework for Comprehensive Management of GAI-Assisted Programming Courses
abstract
Smartphones are widely used Internet of Things (IoT) devices in higher education, but relying on them alone does not sufficiently aid teachers in managing courses or improving student learning. For teachers, managing course progress through predefined rules and safeguarding student privacy at key stages is challenging. Likewise, students lack targeted learning assistance to enhance their capabilities. Therefore, a comprehensive scheme is essential to address these challenges effectively. In this paper, we propose a novel framework based on smart contracts and integrated with generative artificial intelligence (GAI) assistance. This framework manages programming courses and enhances student learning, with smartphones serving as access points. It leverages smart contracts to dynamically manage the entire course lifecycle, with contracts built upon access control policies to ensure that only authorized roles can access course resources via smartphone. The proposed framework is based on a consortium network. GAI model-ChatGPT-4o provides code generation and code explanation assistance in programming courses. We select the optimal prompt templates and store them on the blockchain, allowing GAI to provide more precise services using them. We implement and evaluate the proposed framework using the Hyperledger Fabric blockchain, demonstrating its effectiveness and scalability in real-world scenarios. Additionally, we evaluate the code-related content generated by the prompt templates using three criteria: pass rate, time spent, and number of votes. This evaluation confirms that the templates selected and recorded on the blockchain are optimal. The framework can be easily adapted to other scenarios such as course management, record management, and research collaboration.
Leixin Guo, Beibei Li 0002, Zhangyan Lin, Wenfei Ge
IEEE Internet Things J.4
2025 TAMT: Privacy-Preserving Task Assignment With Multi-Threshold Range Search for Spatial Crowdsourcing Applications
abstract
Spatial crowdsourcing is a distributed computing paradigm that utilizes the collective intelligence of workers to perform complex tasks. How to achieve privacy-preserving task assignment in spatial crowdsourcing applications has been a popular research area. However, most of the existing task assignment schemes may reveal private and sensitive information of tasks or workers. Few schemes can support task assignment based on different attributes simultaneously, such as spatial, interest, etc. To study the above themes, in this paper, we propose one privacy-preserving task assignment scheme with multi-threshold range search for spatial crowdsourcing applications (TAMT). Specifically, we first define Euclidean distance-based location search and Hamming distance-based interest search, which map the demands of the tasks and the interests of the workers into the binary vectors. Second, we deploy PKD-tree to index the task data leveraging the pivoting techniques and the triangular inequality of Euclidean distance, and propose an efficient multi-threshold range search algorithm based on matrix encryption and decomposition technology. Furthermore, based on DT-PKC, we introduce a ciphertext-based secure comparison protocol to support multi-threshold range search for spatial crowdsourcing applications. Finally, comprehensive security analysis proves that our proposed TAMT is privacy-preserving. Meanwhile, theoretical analysis and experimental evaluation demonstrate that TAMT is practical and efficient.
Haiyong Bao, Zhehong Wang, Rongxing Lu, Cheng Huang 0001, Beibei Li 0002
IEEE Trans. Big Data5
2025 A Bidirectional Differential Evolution-Based Unknown Cyberattack Detection System
abstract
The evolving unknown cyberattacks, compounded by the widespread emerging technologies (say 5G, Internet of Things, etc.), have rapidly expanded the cyber threat landscape. However, most existing intrusion detection systems (IDSs) are effective in detecting only known cyberattacks, because only known cyberattack samples are usually available for IDS training. Identifying unknown cyberattacks, therefore, remains a big challenging issue. To meet this gap, in this paper, motivated by artificial immunity (AIm) and differential evolution (DE), we propose a bidirectional differential evolution based unknown cyberattack detection system, coined BDE-IDS. Specifically, we first design a bidirectional differential evolution algorithm for known nonself antigens (abnormal data), where bidirectional evolutionary directions are considered for increasing or decreasing the differences between known nonself antigens and self antigens (normal data), to create new antigens possibly used for generating cyberattack detectors. Second, a novel tolerance training mechanism is developed to eliminate invalid newly-evolved antigens falling into the coverage of either known self or nonself antigens. Third, the remaining antigens are employed to generate detectors for unknown cyberattacks. Extensive experiments demonstrate that the proposed BDE-IDS achieves outperformance in detecting unknown cyberattacks (as well as known cyberattacks) compared to state-of-the-art studies, including those AIm-based, signature-based, and anomaly-based IDSs.
Hanyuan Huang, Tao Li 0016, Beibei Li 0002, Wenhao Wang 0001, Yanan Sun 0001
IEEE Trans. Evol. Comput.3
2025 FedLoRE: Communication-Efficient and Personalized Edge Intelligence Framework via Federated Low-Rank Estimation
abstract
Federated learning (FL) has recently garnered significant attention in edge intelligence. However, FL faces two major challenges: First, statistical heterogeneity can adversely impact the performance of the global model on each client. Second, the model transmission between server and clients leads to substantial communication overhead. Previous works often suffer from the trade-off issue between these seemingly competing goals, yet we show that it is possible to address both challenges simultaneously. We propose a novel communication-efficient personalized FL framework for edge intelligence that estimates the low-rank component of the training model gradient and stores the residual component at each client. The low-rank components obtained across communication rounds have high similarity, and sharing these components with the server can significantly reduce communication overhead. Specifically, we highlight the importance of previously neglected residual components in tackling statistical heterogeneity, and retaining them locally for training model updates can effectively improve the personalization performance. Moreover, we provide a theoretical analysis of the convergence guarantee of our framework. Extensive experimental results demonstrate that our framework outperforms state-of-the-art approaches, achieving up to 89.18% reduction in communication overhead and 91.00% reduction in computation overhead while maintaining comparable personalization accuracy compared to previous works.
Zerui Shao, Beibei Li 0002, Peiran Wang, Yi Zhang 0018, Kim-Kwang Raymond Choo
IEEE Trans. Parallel Distributed Syst.2
2024 Towards Inductive Robustness: Distilling and Fostering Wave-Induced Resonance in Transductive GCNs against Graph Adversarial Attacks
abstract
Graph neural networks (GNNs) have recently been shown to be vulnerable to adversarial attacks, where slight perturbations in the graph structure can lead to erroneous predictions. However, current robust models for defending against such attacks inherit the transductive limitations of graph convolutional networks (GCNs). As a result, they are constrained by fixed structures and do not naturally generalize to unseen nodes. Here, we discover that transductive GCNs inherently possess a distillable robustness, achieved through a wave-induced resonance process. Based on this, we foster this resonance to facilitate inductive and robust learning. Specifically, we first prove that the signal formed by GCN-driven message passing (MP) is equivalent to the edge-based Laplacian wave, where, within a wave system, resonance can naturally emerge between the signal and its transmitting medium. This resonance provides inherent resistance to malicious perturbations inflicted on the signal system. We then prove that merely three MP iterations within GCNs can induce signal resonance between nodes and edges, manifesting as a coupling between nodes and their distillable surrounding local subgraph. Consequently, we present Graph Resonance-fostering Network (GRN) to foster this resonance via learning node representations from their distilled resonating subgraphs. By capturing the edge-transmitted signals within this subgraph and integrating them with the node signal, GRN embeds these combined signals into the central node's representation. This node-wise embedding approach allows for generalization to unseen nodes. We validate our theoretical findings with experiments, and demonstrate that GRN generalizes robustness to unseen nodes, whilst maintaining state-of-the-art classification accuracy on perturbed graphs. Appendices can be found on arXiv version: https://arxiv.org/abs/2312.08651
Ao Liu 0005, Wenshan Li 0001, Tao Li 0016, Beibei Li 0002, Hanyuan Huang, Pan Zhou 0001
AAAI4
2024 GraphCyber: Identifying IP Usage Scenarios for Cyberspace Mapping
abstract
Understanding the network characteristics of IP nodes and identifying their potential usage scenarios are crucial for cyberspace applications, such as asset evaluation, fraud prevention, and network attack prevention. However, many studies related to IP nodes primarily focused on IP geolocation and anomaly detection, with very little attention given to IP usage. Identifying the usage scenarios of IP node can facilitate network optimization, enhance security and improve resource allocation, which is crucial for network management and security. In this work, we propose a novel framework named GraphCyber based on graph neural network to identify street-level IP usage for cyberspace mapping. We first design a topology rule-based approach dividing a large number of IP nodes into regional blocks. Then we devise regional blocks to fuse the self-information of IP nodes and various neighborhood relationships into the graph. Last, based on an uncertainty-aware graph neural network, we identify the usage scenarios of IP nodes within regional blocks. Extensive experiments conducted on three large-scale real-world data sets demonstrate the superiority of GraphCyber over several state-of-the-art baselines in accurately identifying the IP usage scenarios.
Liang Liu 0009, Lei Zhang 0101, Beibei Li 0002
ICC5
2024 A Robust Malicious Traffic Detection Framework with Low-quality Labeled Data
abstract
Deep learning (DL) techniques have been widely applied in detecting malicious activities from network traffic. However, it is challenging to collect a traffic dataset with sufficient correct labels. The generalization ability of DL-based malicious traffic detection systems decreases when training with mislabeled data. Therefore, several methods have been proposed to detect malicious traffic from low-quality labeled training data. These methods divide noisy and clean samples based on the divergence of their prediction loss. However, this simple criterion is not effective on traffic data due to the obfuscation and redundancy nature of malicious traffic. In this paper, we propose a novel two-stage framework for malicious traffic detection from low-quality training data, which mainly consists of noisy sample filtering and label refinement. Firstly, with the help of the small loss criterion, we filter out most of the noisy samples from training data while ensuring that the filtered dataset covers sufficient clean samples. Next, we introduce a double-constrained similarity rule to provide a comprehensive measure of the similarity between samples and construct a topological graph. Lastly, we exploit the topological relations extracted from this graph to refine the labels based on the neighbor consistency criterion. We validate the effectiveness of our framework with a real-world malicious traffic dataset, achieving an accuracy of 90% even with 80% symmetric noise labels. Additionally, results from the publicly available BoT-IoT dataset demonstrate the adaptability of our framework to Internet of Things (IoT) environments.
Lingfeng Yao, Weina Niu, Qingjun Yuan, Beibei Li 0002, Xiaosong Zhang 0001
ICC4
2024 Enhanced Tensorial Self-representation Subspace Learning for Incomplete Multi-view Clustering
abstract
Incomplete Multi-View Clustering (IMVC) is a promising topic in multimedia as it breaks the data completeness assumption. Most existing methods solve IMVC from the perspective of graph learning. In contrast, self-representation learning enjoys a superior ability to explore relationships among samples. However, only a few works have explored the potentiality of self-representation learning in IMVC. These self-representation methods infer missing entries from the perspective of whole samples, resulting in redundant information. In addition, designing an effective strategy to retain salient features while eliminating noise is rarely considered in IMVC. To tackle these issues, we propose a novel self-representation learning method with missing sample recovery and enhanced low-rank tensor regularization. Specifically, the missing samples are inferred by leveraging the local structure of each view, which is constructed from available samples at the feature level. Then an enhanced tensor norm, referred to as Logarithm-p norm is devised, which can obtain an accurate cross-view description by adaptive weights. Our proposed method achieves exact subspace representation in IMVC by leveraging high-order correlations and inferring missing information at the feature level. Extensive experiments on several widely used multi-view datasets demonstrate the effectiveness of the proposed method.
Hangjun Che, Xinyu Pu, Deqiang Ouyang, Beibei Li 0002
ACM Multimedia4
2024 A Multi-Blockchain Based Anonymous Cross-Domain Authentication Scheme for Industrial Internet of Things
abstract
With the widespread adoption of the Industrial Internet of Things (IIoT) and the growing complexity of industrial production processes, data interactions between IIoT domains have become increasingly frequent. Ensuring security and privacy in cross-domain authentication has thus become a critical challenge. Traditional authentication schemes face several limitations, including high computation overhead, potential privacy leakage, and vulnerability to single point of failure, making it difficult to meet the cross-domain authentication needs. To address these challenges, we propose a distributed cross-domain authentication scheme in this paper. Specifically, we first design a novel IIoT cross-domain authentication architecture based on multi-blockchain. Unlike traditional single-blockchain based architecture, this approach enables fine-grained access control for on-chain device information and provides better performance and scalability. Building on this architecture, we propose an anonymous authentication scheme utilizing Certificate-Less Public Key Cryptography (CL-PKC), ensuring identity privacy for industrial devices while maintaining low authentication resource overhead. Additionally, we adopt the Merkle hash tree to construct a novel pseudonym management mechanism, which supports efficient batch pseudonym request, verification, and revocation. Finally, we demonstrate the scheme’s advantages in security and efficiency through comprehensive security analysis and performance evaluation.
Chengqi Hou, Wei Yang 0015, Yu Wang 0243, Beibei Li 0002
TrustCom6
2024 FedRFC: Federated Learning with Recursive Fuzzy Clustering for improved non-IID data training
Yuxiao Deng, Anqi Wang 0008, Lei Zhang 0101, Beibei Li 0002
Future Gener. Comput. Syst.5
2024 FSMFLog: Discovering Anomalous Logs Combining Full Semantic Information and Multifeature Fusion
abstract
Industrial Internet of Things devices usually use log information to record their runtime status, so log-based anomaly detection can contribute to discovering device failures in time. The first step of log-based anomaly detection is log parsing. However, existing methods mainly extract log templates for analysis, which ignore some words that represent key semantics. Such omissions may cause semantic misunderstandings and further affect the performance of anomaly detection. On the other hand, existing deep learning-based log anomaly detection approaches only consider the sequential relations among log messages, ignoring the log time and type information. In this article, we propose an anomaly detection method called FSMFLog based on full semantic information and multifeature fusion. FSMFLog uses log word lists instead of log templates to represent semantic information. Specifically, the variable part is first removed through preprocessing, and then the log sentences are initially clustered using two heuristic strategies, after which the words in the log content are clustered through the prefix tree structure. By integrating semantic features, time features, and type features, FSMFLog also trains a bidirectional GRU model based on an attention mechanism. Evaluation on 16 real-word log data sets from LogHub shows that FSMFLog achieves a higher log parsing accuracy, outperforming other five state-of-the-art log parsing methods. We also evaluated FSMFLog on two most widely used public data sets (HDFS and BGL), and the results demonstrate the effectiveness of FSMFLog, outperforming the compared approaches using deep learning with an average increase of more than 10% in$F1$-score.
Weina Niu, Zimu Li, Zhaoxu He, Aduo Wang, Beibei Li 0002, Xiaosong Zhang 0001
IEEE Internet Things J.5
2024 KMSQ: Efficient and Privacy-Preserving Keyword-Oriented Multidimensional Similarity Query in eHealthcare
abstract
Extensive research has been conducted on efficient and privacy-preserving similarity queries in eHealthcare, aiming at disease diagnosis based on similar patients while protecting the outsourced sensitive healthcare data. In this article, a new secure similarity query scheme named keyword-oriented multidimensional similarity query (KMSQ) is proposed for eHealthcare. Different from the state-of-the-art similar works, our proposed scheme enables users to query historical similar patients’ records based on their multidimensional physiological characteristics and symptom keywords (two data types) at the same time. Although the query can be securely performed sequentially by formerly proposed schemes, we carefully tailor a binary-decision-PB (BD-PB) tree to index the two data types simultaneously for efficient queries. Furthermore, inspired by the Hilbert exclusion condition and the properties of the polynomial function, an efficient query algorithm based on the BD-PB tree is designed in a filtration–verification manner, which further greatly improves the computational efficiency of queries, especially on the server side. To ensure secure query on untrusted clouds, the BD-PB tree-based KMSQ is protected through multiple encryption techniques. Specifically, function-hiding inner product preserving encryption (FHIPPE) is modified and combined with a lightweight matrix encryption technique to achieve secure data filtration. In addition, a symmetric homomorphic encryption (SHE) scheme is utilized to ensure secure verification that each candidate record in the filtration result satisfies the query requirements. Security analysis demonstrates the modified FHIPPE (MFHIPPE) and our proposed scheme meet the necessary security properties under the honest-but-curious model. Finally, extensive experiments are also conducted to show that KMSQ is computationally efficient.
Zian Zhang, Haiyong Bao, Rongxing Lu, Cheng Huang 0001, Beibei Li 0002
IEEE Internet Things J.5
2024 Chaos-Based Index-of-Min Hashing Scheme for Cancellable Biometrics Security
abstract
Cancellable biometrics is essential for preserving sensitive biometric information from potential exposure. Existing studies usually convert real-valued biometric vectors into protected templates by randomly generated transformation keys. However, this way is realized by the built-in functions of the cancellable biometric system, which creates vulnerabilities for cancellable biometric schemes. In this paper, we propose a novel chaos-based Index-of-Min cancellable biometric scheme, named C-IoM, for privacy-preserving template updates in biometric technique. Specifically, we first design a chaos-based cancellable biometric framework to ensure the security and privacy of the biometric template. Second, we develop a secure random chaos seed generation algorithm, which non-linearly converts the biometric vectors into protected templates and conceals biometric dimensional information. Further, we craft a sliding window selection mechanism to choose the input biometric features, allowing each feature data to fully participate in the generation of protected templates through sliding intervals. Theoretical analysis confirms that the C-IoM satisfies the criteria of irreversibility, revocability, unlinkability, and performance preservation in cancellable biometrics. Extensive experiments on LFW, CFPW, and CASIA-V5 datasets demonstrate the security of the proposed framework in protecting biometric data as well as the superiorities over state-of-the-art schemes.
Wanying Dai, Beibei Li 0002, Qingyun Du, Ao Liu 0005
IEEE Trans. Inf. Forensics Secur.2
2024 HomeSentinel: Intelligent Anti-Fingerprinting for IoT Traffic in Smart Homes
abstract
Recent studies have demonstrated that malicious adversaries are capable of fingerprinting Internet of Things (IoT) devices in a smart home and further causing privacy breaches. However, many existing anti-fingerprinting schemes, either by traffic padding or traffic mutation, are less effective in defending against state-of-the-art fingerprinting methods. To meet this gap, we in this paper propose the HomeSentinel, an intelligent anti-fingerprinting scheme to counter IoT traffic fingerprinting in smart homes. Specifically, we first design a LightGBM-based IoT traffic extraction model to accurately distinguish IoT traffic from raw network traffic in a smart home without user operations. Second, we develop a dummy IoT traffic generation model to produce dummy IoT traffic in desired spatial-temporal patterns. Third, an IoT traffic mixing strategy is crafted to heuristically merge dummy IoT traffic with real IoT traffic in desired spatial-temporal patterns. Extensive experiments on three real-world datasets (i.e., two public and one custom) demonstrate that our proposed HomeSentinel scheme can effectively defend against state-of-the-art IoT traffic fingerprinting methods, and outperforms existing IoT traffic anti-fingerprinting schemes. Further, real-world experiments are conducted on a self-built testbed show that, reasonably low communication delays can be caused when implementing the HomeSentinel in smart homes.
Beibei Li 0002, Youtong Chen, Lei Zhang 0101, Licheng Wang 0004, Yanyu Cheng
IEEE Trans. Inf. Forensics Secur.1
2024 AN-GCN: An Anonymous Graph Convolutional Network Against Edge-Perturbing Attacks
abstract
Recent studies have revealed the vulnerability of graph convolutional networks (GCNs) to edge-perturbing attacks, such as maliciously inserting or deleting graph edges. However, theoretical proof of such vulnerability remains a big challenge, and effective defense schemes are still open issues. In this article, we first generalize the formulation of edge-perturbing attacks and strictly prove the vulnerability of GCNs to such attacks in node classification tasks. Following this, an anonymous GCN, named AN-GCN, is proposed to defend against edge-perturbing attacks. In particular, we present a node localization theorem to demonstrate how GCNs locate nodes during their training phase. In addition, we design a staggered Gaussian noise-based node position generator and a spectral graph convolution-based discriminator (in detecting the generated node positions). Furthermore, we provide an optimization method for the designed generator and discriminator. It is demonstrated that the AN-GCN is secure against edge-perturbing attacks in node classification tasks, as AN-GCN is developed to classify nodes without the edge information (making it impossible for attackers to perturb edges anymore). Extensive evaluations verify the effectiveness of the general edge-perturbing attack (G-EPA) model in manipulating the classification results of the target nodes. More importantly, the proposed AN-GCN can achieve 82.7% in node classification accuracy without the edge-reading permission, which outperforms the state-of-the-art GCN.
Ao Liu 0005, Beibei Li 0002, Tao Li 0016, Pan Zhou 0001, Rui Wang 0070
IEEE Trans. Neural Networks Learn. Syst.2
2023 A Lightweight Few-Shot Attack Detection Scheme for Industrial Cognitive Radio Networks
abstract
Industrial cognitive radio networks (ICRNs) have been a promising spectrum -sharing solution for massive resource-constrained wireless devices in the industrial Internet of things (1IoT). However, ICRNs are raising new opportunities for ma-licious users, wherein the threat landscape is compounded with few-shot attacks due to the insufficiency of high-quality examples. In this paper, we propose a novel lightweight intrusion detection system focusing on few-shot attacks for ICRNs, called KDFS-IDS. Specifically, we first develop a teacher-student model based hierarchical intrusion detection framework for ICRNs. Second, we design a convolutional neural network-based intrusion detection model as the fundamental model for identifying few-shot attacks. Third, a knowledge distillation strategy is crafted to obtain a lightweight but sufficiently accurate model for KDFS-IDS. Extensive experiments on three public datasets demonstrate the superiorities of our proposed scheme in detecting few-shot attacks for I CRN s, in terms of both effectiveness and accuracy.
Beibei Li 0002, Wanying Dai, Rongkuan Ma, Hanyuan Huang
GLOBECOM2
2023 Fuzzing Logical Bugs in eBPF Verifier with Bound-Violation Indicator
abstract
eBPF is widely used in Microsoft, Google, and Facebook because it is able to extend kernel without modifying the kernel source code. Nevertheless, vulnerabilities in kernel with eBPF will affect the stability and security of information system. Fuzzing has proven to be an effective approach for finding kernel bugs since it requires minimal knowledge about the target. However, two main challenges exist in discovering eBPF logical bugs: generating input that satisfies all eBPF instruction semantic requirements, and detecting the eBPF logical bug states. We remove highly semantically demanding and unnecessary instructions by analyzing the impact of the instructions to obtain a higher verification pass rate to address the first challenge. We also develop a bound-violation indicator to address the second challenge based on our analysis of eBPF logical bug patterns. We manually introduce 10 recently fixed logical bugs in eBPF for evaluation, and the experimental results show that we can effectively find 9 of them, while Syzkaller fails on all of them. In addition, 4 new bugs have been fixed for upstream Linux based on our work, and 3 functional issues have been reported.
Youlin Li, Weina Niu, Yukun Zhu, Jiacheng Gong, Beibei Li 0002, Xiaosong Zhang 0001
ICC5
2023 A Novel Generation Method for Diverse Privacy Image Based on Machine Learning
abstract
Abstract In recent years, deep neural networks have been extensively applied in various fields, and face recognition is one of the most important applications. Artificial intelligence has reached or even surpassed human capabilities in many fields. However, while artificial intelligence application provides convenience to the human lives, it also leads to the risk of privacy leaking. At present, the privacy protection technology for human faces has received extensive attention. Research goals of face privacy protection technology mainly include providing face anonymization and data availability protection. Existing methods usually have insufficient anonymity and they are not easy to control the degree of image distortion, which makes it difficult to achieve the purpose of privacy protection. Moreover, they do not explicitly perform diversity preservation of attributes such as emotions, expressions and ethnicities, so they cannot perform data analysis tasks on non-identity attributes. This paper proposes a diverse privacy face image generation algorithm based on machine learning, called DIVFGEN. This algorithm comprehensively considers image distortion, identity mapping distance loss and emotion classification loss; transforms the privacy protection target into the problem of generating adversarial examples based on the recognition model; and uses an adaptive optimization algorithm to generate anonymity and diversity of privacy images. The experimental results show that on the Cohn-Kanade+ dataset, our algorithm can reduce the probability of facial recognition by the neural network when it accurately classifies sentiment, from 98.6% to 4.8%.
Weina Niu, Yuheng Luo, Kangyi Ding, Xiaosong Zhang 0001, Beibei Li 0002
Comput. J.6
2023 Defending Byzantine attacks in ensemble federated learning: A reputation-based phishing approach
Beibei Li 0002, Peiran Wang, Zerui Shao, Ao Liu 0005, Yukun Jiang 0001
Future Gener. Comput. Syst.1
2023 Artificial immunity based distributed and fast anomaly detection for Industrial Internet of Things
Beibei Li 0002, Yujie Chang, Hanyuan Huang, Wenshan Li 0001, Tao Li 0016, Wen Chen 0025
Future Gener. Comput. Syst.1
2023 EPPSQ: Achieving efficient and privacy-preserving statistics queries over encrypted data in smart grids
Beibei Li 0002, Linghao Zhang, Zhengwei Chang, Liang Zhao 0020, Arun Kumar 0006
Future Gener. Comput. Syst.1
2023 Incentive-Based Federated Learning for Digital-Twin-Driven Industrial Mobile Crowdsensing
abstract
Mobile crowdsensing has empowered the Industrial Internet of Things (IIoT) in many ways, such as vehicle-aided traffic flow scheduling, drone-aided visual inspections, etc. However, dynamic perception and cooperative decision making among these heterogeneous and resource-constrained mobile clients in IIoT remains a big challenge. In this article, we propose an incentive-based federated learning scheme for digital twin (DT)-driven industrial mobile crowdsensing. Specifically, we first design a DT-driven industrial mobile crowdsensing architecture to achieve dynamic perception of the complex IIoT environment, among heterogeneous and resource-constrained mobile clients. Second, we develop a novel incentive-based federated learning framework incorporated with a contract-based reputation mechanism and a Stackelberg-based interclient incentive mechanism, to optimize the model accuracy. Third, we devise a knowledge distillation algorithm for the federated learning framework, to address the heterogeneity of nonindependent and identically distributed (Non-IID) data. Extensive experiments on both MNIST/FEMNIST and CIFAR10/100 data sets demonstrate the outperformance of our proposed scheme, in terms of model accuracy, incentive fairness, and data compatibility, compared to state-of-the-art studies.
Beibei Li 0002, Yaxin Shi, Qinglei Kong, Qingyun Du, Rongxing Lu
IEEE Internet Things J.1
2023 $\bm {P}^{\bm {3}}$: Privacy-Preserving Prediction of Real-Time Energy Demands in EV Charging Networks
abstract
Real-time and accurate prediction of charging pile energy demands in electric vehicle (EV) charging networks contributes significantly to load shedding and energy conservation. However, existing methods usually suffer from either data privacy leakage problems or heavy communication overheads. In this article, we propose a novel blockchain-based personalized federated deep learning scheme, coined $P^{3}$ , for privacy-preserving energy demands prediction in EV charging networks. Specifically, we first design an accurate deep learning-based energy demands prediction model for charging piles, by making use of the CNN, BiLSTM, and attention mechanism. Second, we develop a blockchain-based hierarchical and personalized federated learning framework with a consensus committee, allowing charging piles to collectively establish a comprehensive energy demands prediction model in a low-latency and privacy-preserving way. Last, a CKKS cryptosystem based secure communication protocol is crafted to guarantee the confidentiality of model parameters while model training. Extensive experiments on two real-world datasets demonstrate the superiorities of the proposed $P^{3}$ scheme in accurately predicting real-time energy demands over state-of-the-art schemes. Further, the $P^{3}$ scheme can achieve reasonably low computational costs, compared with other homomorphic-based schemes, such as Paillier and BFV.
Beibei Li 0002, Qingyun Du, Rongxing Lu
IEEE Trans. Ind. Informatics1
2022 LogTracer: Efficient Anomaly Tracing Combining System Log Detection and Provenance Graph
abstract
Information systems have penetrated into all areas of social life, however, unknown threats represented by APT attacks pose serious challenges to their security. In recent years, approaches based on log analysis and provenance graph have been extensively used in the anomaly detection and tracing of malicious attacks. However, traditional method has low detection accuracy, high complexity and low efficiency. To address those shortcomings, we propose an efficient anomaly tracing approach (LogTracer), which combines system log detection and provenance graph together. The proposed LogTracer extracts the attack path from provenance graph, which is constructed with the anomaly degrees of the system logs anomaly detection results. Compar-ative experiments with OmegaLog, NoDoze and ALchemist are conducted on a simulated dataset with 16 attack types totaling 290 million logs. The experimental results show that our method approximately 5.4x, 0.2x and 7.2x faster than these three methods in processing efficiency, and its malicious node coverage rate reaches 98.1%.
Weina Niu, Zhenqi Yu, Zimu Li, Beibei Li 0002, Runzi Zhang, Xiaosong Zhang 0001
GLOBECOM4
2022 User Behavior Simulation in ICS Cyber Ranges
abstract
Cyber ranges, built to simulate the topologies, configurations, and runtime status of the real network, can be employed to test and verify the security and/or privacy issues of user behaviors in newly developed systems and networks in a virtual but extremely similar environment. However, most of the existing user behavior simulation methods usually suffer from low authenticity and trust in real-world user behaviors, especially for large-scale and complex industrial control systems (ICSs). To meet this gap, this paper proposes a novel user behavior simulation method for ICS cyber ranges. Specifically, we first generate coarse-grained group user behaviors and choose specific nodes to generate fine-grained individual user behaviors to fit the same software under different levels of subsystems. Then, we accelerate and replay the generated traffic by compressing the time interval to balance the packet loss rate and distortion rate. Importantly, to build a multi-granularity ICS cyber range that can simulate different types of user behaviors, we use the cloud platform to create protocol stacks, dockers, virtual machines, and physical devices. Experiment results show that the simulated user behaviors in ICS cyber ranges are highly similar to the actual network environments.
Chuhan Liu, Fengkai Xu, Beibei Li 0002
PST5
2022 IDROP: Intelligently detecting Return-Oriented Programming using real-time execution flow and LSTM
abstract
Return-Oriented Programming (ROP) has become one of the most widely used attack techniques for software vulnerability exploitation. Existing ROP detection methods fall into two types: hardware-based methods and software-based methods. The former is strongly dependent on specific hardware architectures and difficult to deploy. Although the latter can alleviate these problems, limited by the selection of features and thresholds, it cannot effectively discover neither variant ROP nor delayed ROP. In this work, we propose an intelligent detection method at runtime and implement the corresponding prototype system, IDROP, which uses real-time execution flow and LSTM to discovery ROP and its variants. Specifically, IDROP analyzes the differences between program execution flows that are independent of the ROP feature thresholds. Firstly, the Aspect Oriented Programming (AOP) is utilized to instrument the tested program, and the sliding window mechanism is applied to screen out suspicious program execution flow snapshots. Then, these suspicious execution flow snapshots are vectorized through data representation techniques. Finally, we build and train an LSTM model to discover ROP. Furthermore, we evaluate the performance of IDROP on a dataset consisting of 6000+ samples. The experimental results show that IDROP is effective in detecting ROP attacks, variant ROP and delayed ROP with an accuracy of 98%, 93% and 80%, respectively. In addition, IDROP has negligible space overhead and low performance overhead, which is similar to that of only using Pin for detection (about additional 2.5 times the program execution time before instrumentation).
Weina Niu, Zhiqin Duan, Beibei Li 0002, Xiaosong Zhang 0001
TrustCom5
2022 MSCCS: A Monero-based security-enhanced covert communication system
Liang Liu 0009, Beibei Li 0002, Shan Liao, Lei Zhang 0101
Comput. Networks3
2022 MEMBER: A multi-task learning model with hybrid deep features for network intrusion detection
Jinghong Lan, Xudong Liu 0001, Bo Li 0005, Jie Sun 0035, Beibei Li 0002, Jun Zhao 0017
Comput. Secur.5
2022 BBNP: A Blockchain-Based Novel Paradigm for Fair and Secure Smart Grid Communications
abstract
As the future energy infrastructure, smart grid aims to overcome the disadvantages of traditional power grid, e.g., low efficiency and unstable service. However, the frequent collection and analysis of the user’s electricity data may bring various security and privacy threats. Besides, the traditional centralized data storage model in the smart grid is prone to the single point of failure. To address these challenges, in this article, for fair and secure smart grid communication, a blockchain-based novel paradigm, named BBNP, is proposed. Specifically, based on the pseudorandom function and auxiliary information generation and sharing technology, a lightweight data aggregation protocol is designed first to protect the user’s data privacy and ensure communication confidentiality. Then, a novel efficient authentication mechanism is proposed to generate and share session keys in a noninteractive way, which is leveraged for MAC authentication to achieve data integrity of the transmitted data. After that, based on the subjective logic reputation model, a blockchain node consensus mechanism is studied to efficiently store smart grid big data and effectively solve the single point failure problem. By constructing the long-term reputation model for consensus nodes (CNs) and integrating batch verification technology, the problems of CN fair selection and scalability of large-scale nodes are solved simultaneously. Finally, the performance evaluation indicates that BBNP outperforms the state-of-the-art similar schemes in computing complexity, communication cost, system availability, and fairness of block generation.
Haiyong Bao, Binbin Ren, Beibei Li 0002, Qinglei Kong
IEEE Internet Things J.3
2022 Resource Provisioning for Mitigating Edge DDoS Attacks in MEC-Enabled SDVN
abstract
Vehicular ad hoc network (VANET) has become an accessible technology for improving road safety and driving experience, the problems of heterogeneity and lack of resources it faces have also attracted widespread attention. With the development of software-defined networking (SDN) and multiaccess edge computing (MEC), a variety of resource allocation strategies in MEC-enabled software-defined networking-based VANET (SDVN) have been proposed to solve these problems. However, we note that few of these work involves the situation where SDVN is under Distributed Denial of Service (DDoS) attacks. Actually, Internet of Things (IoT) devices are extremely easy to be compromised by malicious users, and compromised IoT devices may be used to launch edge DDoS attacks against the MEC servers in MEC-enabled SDVN at any time. In this article, we propose a graph neural network (GNN)-based collaborative deep reinforcement learning (GCDRL) model to generate the resource provisioning and mitigating strategy. The model evaluates the trust value of the vehicles, formulates mitigation of edge DDoS attacks and resource provisioning strategies to ensure that the MEC servers can work normally under edge DDoS attacks. In addition, GNN is adopted in the DRL model to extract the structure feature of the graph composed of MEC servers, and help transfer computing tasks between MEC servers to alleviate the problem of resources imbalance between them. Experimental results show that the method of estimating the vehicular trust value is effective, and our method can make the average throughput of edge nodes more stable and lower down the average delay and the average energy consumption under the edge DDoS attack. Also, a real-world case study is conducted to verify our conclusion.
Yuchuan Deng, Hao Jiang 0010, Peijing Cai, Tong Wu 0014, Pan Zhou 0001, Beibei Li 0002, Jing Wu 0016, Xin Chen 0032, Kehao Wang 0001
IEEE Internet Things J.6
2022 Attacker Traceability on Ethereum through Graph Analysis
abstract
Since the Ethereum virtual machine is Turing complete, Ethereum can implement various complex logics such as mutual calls and nested calls between functions. Therefore, Ethereum has suffered a lot of attacks since its birth, and there are still many attackers active in Ethereum transactions. To this end, we propose a traceability method on Ethereum, using graph analysis to track attackers. We collected complete user transaction data to construct the graph and analyzed data on several harmful attacks, including reentry attacks, short address attacks, DDoS attacks, and Ponzi contracts. Through graph analysis, we found accounts that are strongly associated with these attacks and are still active. We have done a systematic analysis of these accounts to analyze their threats. Finally, we also analyzed the correlation between the information collected through RPC and these accounts and finally found that some accounts can find their IP addresses.
Weina Niu, Xuhan Liao, Xiaosong Zhang 0001, Beibei Li 0002, Zheyuan He
Secur. Commun. Networks6
2022 FEEL: Federated End-to-End Learning With Non-IID Data for Vehicular Ad Hoc Networks
abstract
Recent studies have demonstrated the potentials of federated learning (FL) in achieving cooperative and privacy-preserving data analytics. It would also be promising if FL can be employed in vehicular ad hoc networks (VANETs) for cooperative learning tasks, such as steering angle prediction, trajectory prediction, drivable road detection, etc., among integrated vehicles. However, since VANETs are characterized by ad hoc cooperating vehicles with non-independent and identically distributed (Non-IID) data, directly employing existing FL frameworks to VANETs may cause extensive communication overhead and compromised model performance. Further, most of the existing deep learning models incorporated in FL frameworks rely heavily on data with manual annotations, leading to a huge labor cost. To address these issues, in this paper we propose an efficient and effective Federated End-to-End Learning framework for cooperative learning tasks in VANETs, named FEEL. Specifically, we first formulate a distributed optimization problem for cooperative deep learning tasks with Non-IID data in multi-hop cluster VANETs. Second, two algorithms for inter-cluster learning and inner-cluster learning are respectively designed, to reduce the communication overhead and fit Non-IID data. Third, a Paillier-based communication protocol is crafted, allowing secure model parameter updates at the central server without knowing the real updates at each cooperating base station. Extensive experiments on two real-world datasets are conducted by considering various data distributions and VANET topologies, demonstrating the high efficiency and effectiveness of the proposed FEEL framework in both regression and classification tasks.
Beibei Li 0002, Yukun Jiang 0001, Qingqi Pei, Tao Li 0016, Liang Liu 0009, Rongxing Lu
IEEE Trans. Intell. Transp. Syst.1
2022 Federated Anomaly Detection on System Logs for the Internet of Things: A Customizable and Communication-Efficient Approach
abstract
Runtime log-based anomaly detection is one of several key building blocks in ensuring system security, as well as post-incident forensic investigations. However, existing log-based anomaly detection approaches that are implemented on large-scale Internet of Things (IoT) systems generally upload local data from edge devices to a centralized (cloud) server for processing and analysis. Such a workflow incurs significant communication and computation overheads, with potential privacy implications. Hence, in this paper, we propose a customizable and communication-efficient federated anomaly detection scheme (hereafter referred to as FedLog), designed to facilitate the identification of abnormal log patterns in large-scale IoT systems. Specifically, we first craft a Temporal Convolutional Network-Attention Mechanism-based Convolutional Neural Network (TCN-ACNN) model, to effectively extract fine-grained features from system logs. Second, we develop a new federated learning framework to support IoT devices in establishing a comprehensive anomaly detection model in a collaborative and privacy-preserving manner. Third, a lottery ticket hypothesis based masking strategy is designed to achieve customizable and communication-efficient federated learning in handling non-Independent and Identically Distributed (non-IID) log datasets. We then evaluate the performance of our proposed scheme with those of DeepLog (published in CCS, 2017) and Loganomaly (published in IJCAI, 2019) in both centralized learning and federated learning settings, using two publicly available and widely used real-world datasets (i.e., HDFS and BGL). The findings demonstrate the utility of the proposed FedLog scheme, in terms of log-based anomaly detection.
Beibei Li 0002, Shang Ma, Ruilong Deng, Kim-Kwang Raymond Choo
IEEE Trans. Netw. Serv. Manag.1
2021 FedVANET: Efficient Federated Learning with Non-IID Data for Vehicular Ad Hoc Networks
abstract
The vehicular ad hoc networks (VANETs) play a significant role in intelligent transportation systems (ITS). In recent years, federated learning (FL) has been widely used in VANETs to preserve the privacy-sensitive data, such as vehicle locations, drivers' driving patterns, on-board camera data, etc. However, conventional FL faces the challenges of non-independent and identically distributed (Non-IID) data and high communication overheads in VANETs. To address these challenges, we propose a novel FL framework for VANETs, named FedVANET, where a hierarchical inner-cluster FL model and a weighted inter-cluster cycling update algorithm are, respectively, developed. Extensive experiments demonstrate the high efficiency of the FedVANET in inner-cluster communications, effectiveness in handling Non-IID data, and robustness in dynamic VANET topologies.
Beibei Li 0002, Yukun Jiang 0001, Weina Niu, Peiran Wang
GLOBECOM1
2021 Honeypot-Enabled Optimal Defense Strategy Selection for Smart Grids
abstract
Smart grids have been increasingly spotted as high-profile targets of cyber assaults over the years. To better understand the cyber threat landscape, honeypots have been widely used in the smart grid security community, i.e., identifying unauthorized penetration attempts and observing the behaviors in such activities. In this paper, we propose a honeypot-enabled optimal defense strategy selection approach for smart grids, based on a novel stochastic game. Specifically, the interactions between the attacker and smart grid defender are captured using our designed stochastic game, a non-cooperative two-player game with incomplete information. We take into account various possible defenses from a smart grid defender and offensive strate-gies from the attacker. Then the Nash equilibrium is calculated by the stochastic game model, which is derived exhibiting an optimal defense strategy for the smart grid defender. Extensive simulation experiments demonstrate the effectiveness of the proposed scheme.
Beibei Li 0002, Yaxin Shi, Qinglei Kong, Chao Zhai 0002, Yuankai Ouyang
GLOBECOM1
2021 Achieving Blockchain-based Privacy-Preserving Location Proofs under Federated Learning
abstract
Federated learning-based navigation has received much attention in vehicular IoT. The intention is to employ a big number of end-users for data collection along different trajectories and perform local training of a global learning model to substitute the global positioning system (GPS) in urban areas. The prerequisites for its commercialization, however, lie in the location-dependent input data trustworthiness and participants’ privacy preservation. In this paper, we propose a privacy-preserving proof-of-location mechanism using blockchain to meet these conditions. Specifically, the proposed scheme utilizes a Threshold Identity-Based Encryption (TIBE) system for the generation of secret shares, such that each anonymous location proof can only be verified with at least a threshold number of participants. In addition, the proposed scheme exploits a cuckoo filter for the secure and efficient maintenance and dissemination of location proofs. Systematic security analysis is conducted to demonstrate the fulfillment of harsh security requirements. Performance evaluations are carried out to validate the computation efficiency in comparison with an oblivious transfer (OT) protocol, which has been widely adopted for secure data acquisition.
Qinglei Kong, Feng Yin 0001, Beibei Li 0002, Xuejia Yang, Shuguang Cui
ICC4
2021 On Secure and Efficient Data Sharing for Smart Grids: An Anti-Collusion Scheme
abstract
High volumes of real-time energy consumption data are generated by smart meters each day, which may create tremendous values if shared to third parties, e.g., government agencies, real estate agents, and travel agencies, etc. However, significant security and privacy challenges are always in place in case these sensitive digital assets are directly shared outside the grid utilities without any protection. It is, therefore, vital to guarantee the data security and privacy while maintaining its values. To meet this gap, in this paper we propose a secure and efficient data sharing scheme with anti-collusion for smart grids. In this scheme, we devise a privacy-preserving data acquisition algorithm for smart meters based on a modified Paillier cryptosystem, and also an anti-collusion proxy re-encryption algorithm for the control center & cloud server to achieve secure energy consumption data sharing of its mean and variance. Importantly, the proposed scheme is also designed to support customer identity preservation while requesting data sharing services. Security analysis strictly demonstrate the security of the proposed scheme, and extensive experiments validate the high efficiency of the proposed scheme.
Xiaoxia Ma, Beibei Li 0002, Qinglei Kong, Yuankai Ouyang, Rongxing Lu
ICC2
2021 FS-IDS: A Novel Few-Shot Learning Based Intrusion Detection System for SCADA Networks
abstract
Supervisory control and data acquisition (SCADA) networks provide high situational awareness and automation control for industrial control systems, whilst introducing a wide range of access points for cyber attackers. To address these issues, a line of machine learning or deep learning based intrusion detection systems (IDSs) have been presented in the literature, where a large number of attack examples are usually demanded. However, in real-world SCADA networks, attack examples are not always sufficient, having only a few shots in many cases. In this paper, we propose a novel few-shot learning based IDS, named FS-IDS, to detect cyber attacks against SCADA networks, especially when having only a few attack examples in the defenders’ hands. Specifically, a new method by orchestrating one-hot encoding and principal component analysis is developed, to preprocess SCADA datasets containing sufficient examples for frequent cyber attacks. Then, a few-shot learning based preliminary IDS model is designed and trained using the preprocessed data. Last, a complete FS-IDS model for SCADA networks is established by further training the preliminary IDS model with a few examples for cyber attacks of interest. The high effectiveness of the proposed FS-IDS, in detecting cyber attacks against SCADA networks with only a few examples, is demonstrated by extensive experiments on a real SCADA dataset.
Yuankai Ouyang, Beibei Li 0002, Qinglei Kong, Han Song, Tao Li 0016
ICC2
2021 Locating False Data Injection Attacks on Smart Grids Using D-FACTS Devices
Beibei Li 0002, Qingyun Du, Aohan Li, Xiaoxia Ma
ICSOC1
2021 FLPhish: Reputation-based Phishing Byzantine Defense in Ensemble Federated Learning
abstract
The increasing demand for privacy protection facilitates growing interests in Federated Learning (FL). Nevertheless, most of existing FL schemes are susceptible to malicious participating clients compromised by Byzantine attacks, which remains a challenging issue. In this paper, we propose a novel Byzantine-robust FL scheme, coined FLPhish. Specifically, we first design a ensemble learning-based FL architecture, named Ensemble Federated Learning (Ensemble FL). Second, a phishing mechanism is crafted for the FL architecture to detect abnormal client behaviors. Third, a reputation mechanism is developed to further identify malicious participating clients compromised by Byzantine attackers. We evaluate the performance of FLPhish by considering various fractions of Byzantine clients and various imbalance degrees of the data distribution. Extensive experiments demonstrate the high effectiveness of the proposed FLPhish scheme in resisting Byzantine attacks in Ensemble FL.
Beibei Li 0002, Peiran Wang, Hanyuan Huang, Shang Ma, Yukun Jiang 0001
ISCC1
2021 An immune-based risk assessment method for digital virtual assets
Junjiang He, Tao Li 0016, Beibei Li 0002, Xiaolong Lan
Comput. Secur.3
2021 JSContana: Malicious JavaScript detection using adaptable context analysis and key feature extraction
Yunhua Huang, Tao Li 0016, Lijia Zhang, Beibei Li 0002
Comput. Secur.4
2021 A novel privacy preserving data aggregation scheme with data integrity and fault tolerance for smart grid communications
Haiyong Bao, Beibei Li 0002
Frontiers Comput. Sci.2
2021 SP-SMOTE: A novel space partitioning based synthetic minority oversampling technique
Tao Li 0016, Beibei Li 0002, Xiaolong Lan
Knowl. Based Syst.4
2021 Privacy-Preserving Aggregation for Federated Learning-Based Navigation in Vehicular Fog
abstract
Federated learning-based automotive navigation has recently received considerable attention, as it can potentially address the issue of weak global positioning system (GPS) signals under severe blockages, such as in downtowns and tunnels. Specifically, the data-driven navigation framework combines the position estimation offered by the high-sampling inertial measurement units and the position calibration provided by the low-sampling GPS signals. Despite its promise, the privacy preservation and flexibility of the participating users in the federated learning process are still problematic. To address these challenges, in this article, we propose an efficient, flexible, and privacy-preserving model aggregation scheme under a federated learning-based navigation framework named FedLoc. Specifically, our proposed scheme efficiently protects the locally trained model updates, flexibly supports the fluctuation of participants, and is robust against unregistered malicious users by exploiting a homomorphic threshold cryptosystem, together with the bounded Laplace mechanism and the skip list. We perform a detailed security analysis to demonstrate the security properties in terms of privacy preservation and dishonest user detection. In addition, we evaluate and compare the computational efficiency with two traditional schemes, and the simulation results show that our scheme greatly improves the computational efficiency during participant fluctuation. To validate the effectiveness of our scheme, we also show that only part of the model update is excluded from aggregation in the case of a dishonest user.
Qinglei Kong, Feng Yin 0001, Rongxing Lu, Beibei Li 0002, Shuguang Cui, Ping Zhang 0003
IEEE Trans. Ind. Informatics4
2021 DeepFed: Federated Deep Learning for Intrusion Detection in Industrial Cyber-Physical Systems
abstract
The rapid convergence of legacy industrial infrastructures with intelligent networking and computing technologies (e.g., 5G, software-defined networking, and artificial intelligence), have dramatically increased the attack surface of industrial cyber-physical systems (CPSs). However, withstanding cyber threats to such large-scale, complex, and heterogeneous industrial CPSs has been extremely challenging, due to the insufficiency of high-quality attack examples. In this article, we propose a novel federated deep learning scheme, named DeepFed, to detect cyber threats against industrial CPSs. Specifically, we first design a new deep learning-based intrusion detection model for industrial CPSs, by making use of a convolutional neural network and a gated recurrent unit. Second, we develop a federated learning framework, allowing multiple industrial CPSs to collectively build a comprehensive intrusion detection model in a privacy-preserving way. Further, a Paillier cryptosystem-based secure communication protocol is crafted to preserve the security and privacy of model parameters through the training process. Extensive experiments on a real industrial CPS dataset demonstrate the high effectiveness of the proposed DeepFed scheme in detecting various types of cyber threats to industrial CPSs and the superiorities over state-of-the-art schemes.
Beibei Li 0002, Yuhao Wu 0006, Rongxing Lu, Tao Li 0016, Liang Zhao 0020
IEEE Trans. Ind. Informatics1
2020 ReAL: A New ResNet-ALSTM Based Intrusion Detection System for the Internet of Energy
abstract
The Internet of energy (IoE), envisioned to be a promising paradigm of the Internet of things (IoT), is characterized by the deep integration of various distributed energy systems. However, the fusion of heterogeneous IoE communication networks creates a new threat landscape. To thwart and mitigate various types of cyber threats to IoE networks, this paper proposes a novel intrusion detection system (IDS) based on a designed residual network with attention long short term memory (ReAL). Specifically, we design a light gradient boosting machine (LightGBM)-based feature selection method to identify the most useful features. Then, a residual network (ResNet) and a long short term memory neural network with an attention mechanism (ALSTM) are employed, to extract temporal patterns of network traffic events. After that, these patterns are orchestrated to identify the anomalies in IoE networks. The high effectiveness of the proposed IDS is validated on a real IoE dataset.
Beibei Li 0002, Yuhao Wu 0006, Yaxin Shi, Aohan Li
LCN2
2020 Toward efficient and effective bullying detection in online social network
Mi Wen, Rongxing Lu, Beibei Li 0002, Jinguo Li
Peer-to-Peer Netw. Appl.4
2020 On Feasibility and Limitations of Detecting False Data Injection Attacks on Power Grid State Estimation Using D-FACTS Devices
abstract
Recent studies have investigated the possibilities of proactively detecting the high-profile false data injection (FDI) attacks on power grid state estimation by using the distributed flexible ac transmission system (D-FACTS) devices, termed as proactive false data detection (PFDD) approach. However, the feasibility and limitations of such an approach have not been systematically studied in the existing literature. In this paper, we explore the feasibility and limitations of adopting the PFDD approach to thwart FDI attacks on power grid state estimation. Specifically, we thoroughly study the feasibility of using PFDD to detect FDI attacks by considering single-bus, uncoordinated multiple-bus, and coordinated multiple-bus FDI attacks, respectively. We prove that PFDD can detect all these three types of FDI attacks targeted on buses or super-buses with degrees larger than 1, if and only if the deployment of D-FACTS devices covers branches at least containing a spanning tree of the grid graph. The minimum efforts required for activating D-FACTS devices to detect each type of FDI attacks are, respectively, evaluated. In addition, we also discuss the limitations of this approach; it is strictly proved that PFDD is not able to detect FDI attacks targeted on buses or super-buses with degrees equalling 1.
Beibei Li 0002, Gaoxi Xiao, Rongxing Lu, Ruilong Deng, Haiyong Bao
IEEE Trans. Ind. Informatics1
2019 Towards insider threats detection in smart grid communication systems
abstract
In today's communication systems, the most damaging security threats are not originating from the outsiders but from the trusted insiders – both malicious insiders and negligent insiders. Always endowed with high privileges, insiders are significantly prone to conduct acts that can cause catastrophic damages to the whole system either intentionally or unintentionally. Characterised by the full and rapid integration of information and communication technologies, smart grid – arguably the largest national critical engineering infrastructure – is suffering from a multitude of security threats initiated from both outsiders and insiders. Without security guarantee, the promising benefits of achieving an efficient, green, and reliable power grid would not be a success. In this study, the authors investigate the insider threats and summarise the existing threats detection solutions in smart grid communication systems. In addition, a novel hybrid insider threats modelling, analysis, and detection framework, which is based on stochastic Petri net and behaviour rule specifications, is proposed to contain insider threats in smart grid communication systems.
Beibei Li 0002, Rongxing Lu, Gaoxi Xiao, Haiyong Bao, Ali A. Ghorbani 0001
IET Commun.1
2019 Efficient privacy-preserving data merging and skyline computation over multi-source encrypted data
Yandong Zheng, Rongxing Lu, Beibei Li 0002, Jun Shao 0001, Haomiao Yang, Kim-Kwang Raymond Choo
Inf. Sci.3
2019 On Reliability Analysis of Smart Grids under Topology Attacks: A Stochastic Petri Net Approach
abstract
Building an efficient, smart, and multifunctional power grid while maintaining high reliability and security is an extremely challenging task, particularly in the ever-evolving cyber threat landscape. The challenge is also compounded by the increasing complexity of power grids in both cyber and physical domains. In this article, we develop a stochastic Petri net based analytical model to assess and analyze the system reliability of smart grids, specifically against topology attacks under system countermeasures (i.e., intrusion detection systems and malfunction recovery techniques). Topology attacks, evolving from false data injection attacks, are growing security threats to smart grids. In our analytical model, we define and consider both conservative and aggressive topology attacks, and two types of unreliable consequences (i.e., system disturbances and failures). The IEEE 14-bus power system is employed as a case study to clearly explain the model construction and parameterization process. The benefit of having this analytical model is the capability to measure the system reliability from both transient and steady-state analysis. Finally, intensive simulation experiments are conducted to demonstrate the feasibility and effectiveness of our proposed model.
Beibei Li 0002, Rongxing Lu, Kim-Kwang Raymond Choo, Wei Wang 0100, Sheng Luo 0001
ACM Trans. Cyber Phys. Syst.1
2018 PAMA: A Proactive Approach to Mitigate False Data Injection Attacks in Smart Grids
abstract
The pervasiveness of information and communications technologies as well as intelligent electronic devices leads to an expanded attack surface in smart grids, making it increasingly challenging to withstand the high-profile false data injection (FDI) attacks. In this paper, we propose a Proactive Approach to Mitigate FDI Attacks (PAMA) in smart grids. With PAMA scheme, the critical information - power grid connections and configurations as well as the original measurement data - used for constructing FDI attacks is well protected from leakage or theft, so that FDI attacks are effectively mitigated. Specifically, we transform the state estimation and FDI detection application into a distributed one equipped with converted information from the critical information provided by the control center. In addition, the original measurement data is also protected by using a secure hybrid Paillier cryptosystem. Our PAMA scheme is proved to be secure and effective in mitigating FDI attacks on smart grids. The computational complexity and the communication overhead are evaluated on the standard IEEE 14-bus test system. Keywords__Smart grids, false data injection (FDI) attack, Paillier cryptosystem, state estimation.
Beibei Li 0002, Rongxing Lu, Gaoxi Xiao, Zhou Su 0001, Ali A. Ghorbani 0001
GLOBECOM1
2018 State Estimation Based Energy Theft Detection Scheme with Privacy Preservation in Smart Grid
abstract
The increasing deployment of smart meters at individual households has significantly improved people's experience in electricity bill payments and energy savings. It is, however, still challenging to guarantee the accurate detection of attacked meters' behaviors as well as the effective preservation of users'privacy information. In addition, rare existing research studies jointly consider both these two aspects. In this paper, we propose a Privacy-Preserving energy Theft Detection scheme (PPTD) to address the energy theft behaviors and information privacy issues in smart grid. Specifically, we use a recursive filter based on state estimation to estimate the user's energy consumption, and detect the abnormal data. During data transmission, we use the lightweight NTRU algorithm to encrypt the user's data to achieve privacy preservation. Security analysis demonstrates that in the PPTD scheme, only authorized units can transmit/receive data, and data privacy are also preserved. The performance evaluation results illustrate that our PPTD scheme can significantly reduce the communication and computation costs, and effectively detect abnormal users.
Mi Wen, Donghuan Yao, Beibei Li 0002, Rongxing Lu
ICC3
2017 HMM-Based Fast Detection of False Data Injections in Advanced Metering Infrastructure
abstract
Smart grids not only provide "intelligence" to the next generation power systems, but also potentially introduce vital security and privacy issues. Particularly, as a core part of the smart grids, advanced metering infrastructure (AMI) is suffering widespread disputes in terms of security and privacy concerns. This paper proposes a novel hidden Markov model (HMM) based method to detect false data injection attacks in AMI. In this method, a global-state HMM of the whole-house appliances is built and trained by sufficient historical meter data in an offline mode. Then, a new fast Viterbi algorithm is devised to decode the hidden states of the HMM. The decoded states are then verified via the partial sub-meter data in an online mode, by which false data can be detected. The effectiveness and efficiency of our method are verified by a public dataset AMPds with one- year real-time meter data.
Beibei Li 0002, Rongxing Lu, Gaoxi Xiao
GLOBECOM1
2017 Distributed host-based collaborative detection for false data injection attacks in smart grid cyber-physical system
abstract
False data injection (FDI) attacks are crucial security threats to smart grid cyber-physical system (CPS), and could result in cataclysmic consequences to the entire power system . However, due to the high dependence on open information networking , countering FDI attacks is challenging in smart grid CPS. Most existing solutions are based on state estimation (SE) at the highly centralized control center; thus, computationally expensive. In addition, these solutions generally do not provide a high level of security assurance, as evidenced by recent work that smart FDI attackers with knowledge of system configurations can easily circumvent conventional SE-based false data detection mechanisms. In this paper, in order to address these challenges, a novel distributed host-based collaborative detection method is proposed. Specifically, in our approach, we use a conjunctive rule based majority voting algorithm to collaboratively detect false measurement data inserted by compromised phasor measurement units (PMUs). In addition, an innovative reputation system with an adaptive reputation updating algorithm is also designed to evaluate the overall running status of PMUs, by which FDI attacks can be distinctly observed. Extensive simulation experiments are conducted with real-time measurement data obtained from the PowerWorld simulator, and the numerical results fully demonstrate the effectiveness of our proposal.
Beibei Li 0002, Rongxing Lu, Wei Wang 0100, Kim-Kwang Raymond Choo
J. Parallel Distributed Comput.1
2016 BLITHE: Behavior Rule-Based Insider Threat Detection for Smart Grid
abstract
In this paper, we propose a behavior rule-based methodology for insider threat (BLITHE) detection of data monitor devices in smart grid, where the continuity and accuracy of operations are of vital importance. Based on the dc power flow model and state estimation model, three behavior rules are extracted to depict the behavior norms of each device, such that a device (trustee) that is being monitored on its behavior can be easily checked on the deviation from the behavior specification. Specifically, a rule-weight and compliance-distance-based grading strategy is designed, which greatly improves the effectiveness of the traditional grading strategy for evaluation of trustees. The statistical property, i.e., the mathematical expectation of compliance degree of each trustee, is particularly analyzed from both theoretical and practical perspectives, which achieves satisfactory tradeoff between detection accuracy and false alarms to detect more sophisticated and hidden attackers. In addition, based on real data run in POWER WORLD for IEEE benchmark power systems, and through comparative analysis, we demonstrate that BLITHE outperforms the state of arts for detecting abnormal behaviors in pervasive smart grid applications.
Haiyong Bao, Rongxing Lu, Beibei Li 0002, Ruilong Deng
IEEE Internet Things J.3
2016 DDOA: A Dirichlet-Based Detection Scheme for Opportunistic Attacks in Smart Grid Cyber-Physical System
abstract
In the hierarchical control paradigm of a smart grid cyber-physical system, decentralized local agents (LAs) can potentially be compromised by opportunistic attackers to manipulate electricity prices for illicit financial gains. In this paper, to address such opportunistic attacks, we propose a Dirichlet-based detection scheme, where a Dirichlet-based probabilistic model is built to assess the reputation levels of LAs. Initial reputation levels of the LAs are first trained using the proposed model, based on their historical operating observations. An adaptive detection algorithm with reputation incentive mechanism is then employed to detect opportunistic attackers. We demonstrate the utility of our proposed scheme using data collected from the IEEE 39-bus power system with the PowerWorld simulator.
Beibei Li 0002, Rongxing Lu, Wei Wang 0100, Kim-Kwang Raymond Choo
IEEE Trans. Inf. Forensics Secur.1