Xuewen Dong

dblp:49/7488 · DBLP profile ↗
← Back
52ranked-venue papers
16as first author
41since 2021 · last 2026
0000-0001-5745-0545ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 10 first-author · 15 since 2021Security and privacy · 11 · 3 first-author · 7 since 2021Systems, architecture and hardware · 10 · 1 first-author · 9 since 2021Software engineering, systems software and programming languages · 7 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Communication-Aware Intelligent Cooperative Search for Multi-UAV Systems in Blocked Regions
Lingtao Xue, Xuewen Dong, Lingxiao Yang
ICIC (2)2
2026 PriFFT: Privacy-Preserving Federated Fine-Tuning of Large Language Models via Hybrid Secret Sharing
Zhichao You, Xuewen Dong, Ke Cheng 0001, Xutong Mu, Jiaxuan Fu, Shiyang Ma, Qiang Qu 0001, Yulong Shen 0001
IEEE Trans. Dependable Secur. Comput.2
2026 Blockchain-Based MIMO AAV-Aided Mobile Edge Computing
abstract
Unmanned aerial vehicle (UAV)-aided mobile edge computing (MEC) with a blockchain consensus algorithm is a promising solution for addressing mobile offloading of computation-intensive or latency-sensitive tasks with extensive service range, while ensuring the authenticity of the offloading. Existing UAV-aided MEC studies focus on task offloading or trajectory planning of single-antenna UAVs, missing multiple-input multiple-output (MIMO) UAV systems. In addition, most blockchain-based UAV-aided edge computing studies adopt energy-consuming proof-of-work-based consensus mechanisms, which are unsuitable for energy-limited UAV scenarios. To address the above issues, in this paper, we develop a joint deadline-aware task offloading and UAV trajectory planning scheme, utilizing the effects simulated through an energy-efficient consensus protocol. In order to prevent the exhaustion of UAVs' energy and ensure the authenticity of decision-making, we propose an energy-based Raft (E-Raft) consensus algorithm, enabling dynamic leader selection through a series of decreasing energy thresholds. Subsequently, we present a computational profit maximization problem to jointly optimize deadline-aware task offloading and the UAV swarm's trajectory planning. To address this NP-hard problem, we develop an online priority-based task offloading and trajectory selection algorithm, which is performed by the selected leader of the E-Raft consensus in each round. Simulation results demonstrate that our proposed scheme achieves up to 40% performance improvement over other approaches.
Xuewen Dong, Shuangrui Zhao, XinDi Ma, Qiang Qu 0001, Yulong Shen 0001
IEEE Trans. Mob. Comput.1
2026 MHCertChain: A Multi-CA Hierarchical Certificate Blockchain With Low Overhead
abstract
Blockchain-based certificate management schemes provide a distributed approach for Public Key Infrastructure through the integration of blockchain services, thereby enhancing transparency and security in identity authentication. However, existing schemes often suffer from limited scalability when accommodating new CAs, high overhead of blockchain systems, and a high false-positive rate in revocation status checks. To address above issues, we propose MHCertChain, a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure including the main chain and sub-chains is designed to enhance scalability, while the main chain stores trust paths between CAs and each automatically deployed sub-chain records user certificates issued by an end-entity CA. Then, we propose a lightweight dual-signature certificate format that contains certificate location information without requiring any external certificate location method outside the blockchain. Considering time characteristics of certificates, a time-partitioned cuckoo filter is proposed with a low false positive rate and accelerates revocation status query. Moreover, we deduce an optimal global performance parameter of such filter through mathematical modeling. We present a thorough security analysis of our MHCertChain utilizing the universally composable framework, and extensive experiments demonstrate that the CPU overhead and false positive rate are reduced by 70% and 95%, respectively, compared to state-of-the-art schemes. Blockchain-based certificate management schemes provide a distributed approach for Public Key Infrastructure through the integration of blockchain services, thereby enhancing transparency and security in identity authentication. However, existing schemes seldom discuss hierarchical CA architecture, and often suffer from limited scalability and high overhead when considering new CAs, frequent certificate authentication and revocation status verification. To address above issues, we propose MHCertChain, a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure including the main chain and sub-chains is designed, while the main chain stores trust paths between CAs and each automatically deployed sub-chain records user certificates issued by an end-entity CA. Then, we propose a lightweight dual-signature certificate format that contains certificate location information without requiring any external certificate location method outside the blockchain. Considering time characteristics of certificates, a time-partitioned cuckoo filter is proposed with a low false positive rate and accelerates revocation status query. Moreover, we deduce an optimal global performance parameter of such filter through mathematical modeling. We present a thorough security analysis of our MHCertChain utilizing the universally composable framework, and extensive experiments demonstrate that the CPU overhead and false positive rate are reduced by 70% and 95%, respectively, compared to state-of-the-art schemes. Blockchain-based certificate management schemes provide a distributed means to increase the transparency of PKI (Public Key Infrastructure) and prevent single point attacks in web communications. However, certificate management based on hierarchical multi-CA architecture often faces the problems of poor scalability and high CPU overhead in blockchain. In this article, we are the first to propose a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure of the main chain and sub-chain is adopted, with the main chain storing the trust paths and the sub-chain storing the user certificates. By monitoring to the CA transactions of the main chain, the sub-chain is automatically deployed. Then, in the certificate operation, we consider the high CPU overhead of traditional certificate query in blockchain and propose a dual-signature certificate format. combined with the time characteristics of the certificate, a time-partitioned cuckoo filter is proposed with a low false positive rate for the revocation status query speeding, and we find a global performance optimal parameter through mathematical modeling. Finally, we use a general composable framework to prove the security of HiCertChain, and the experiments show that the CPU overhead and false positive rate are reduced by 90% and 95%, respectively, compared with those of state-of-the-arts.
Xuewen Dong, Qingsong Yao, Lingxiao Yang, Zhiwei Zhang 0004, Ning Xi 0002, Yulong Shen 0001
IEEE Trans. Serv. Comput.2
2026 Non-Subjective Trust Mechanism for Online Ride-Hailing Services
abstract
Online ride-hailing services (ORHS) are changing the travel mode. The quality evaluation of ORHS is essential to regulate driver behavior and guide passengers in choosing good services. The existing quality evaluation methods of ORHS rely on subjective passenger feedback, while they are susceptible to malicious or paranoid feedback, resulting in untrustworthy evaluation results. This paper proposes a non-subjective trust mechanism for ORHS to supplement existing evaluation methods. Inspired by the trust machine, this mechanism defines the concept of non-subjective trust to measure the quality of ORHS. It uses trajectory data collected by infrastructure as a parameter to calculate the non-subjective trust value of ORHS, which can ensure the trustworthiness and authenticity of the calculation results. This mechanism also improves the CKKS homomorphic encryption algorithm to ensure both the privacy protection of the trajectory data and the effective calculation of non-subjective trust values. In addition, a blockchain is adopted to store trajectory data cipher text and trust values plaintext in the infrastructure. It promotes its flexible management and use and ensures the security of original data and traceability of evaluation results. Theoretical analysis and experiments show that the trust value calculated by this mechanism is trustworthy, and its time costs are feasible.
Wei Tong 0003, Xuewen Dong, Jian Shen 0001, Yulong Shen 0001, Zesong Dong
IEEE Trans. Serv. Comput.2
2026 AC-BaaS: An Asynchronous Cross-Blockchain as a Service for the Internet of Things
abstract
Cross-chain techniques improve blockchain scalability and interoperability, providing decentralized exchange and cross-chain collaboration services for Internet of Things (IoT) data across various domains. However, current state-of-the-art (SOTA) solutions for cross-chain data exchange across multiple domains are constrained by synchronous networks, hindering efficient data exchange in intermittent network environments. Furthermore, there is a lack of research on asynchronous cross-chain transaction pool mechanisms, which are crucial for optimizing system utility. In this paper, we propose AC-BaaS, anasynchronouscross-blockchainasaservice framework tailored for the multi-domain IoT. Built upon a specially designed asynchronous sidechain architecture, the system leverages a committee to provide AC-BaaS for data exchange across multiple IoT domains. To fulfill the need for asynchronous and efficient data exchange, we combine the ideas of aggregate signatures and verifiable delay functions to devise a novel cryptographic primitive called delayed aggregate signature (DAS), which constructs asynchronous cross-chain proofs (ACPs) that ensure the security of cross-chain interactions. To ensure the consistency of asynchronous transactions, we propose a multilevel buffered transaction pool that guarantees the transaction sequencing. We further propose a heuristic for optimizing the utility of the buffer pool mechanism to strike a balance between performance and resource consumption. We also examine DAS delay size settings to trade-off security and efficiency. We analyze and prove the security of AC-BaaS, simulate asynchronous communication environments under various security levels, and conduct a comprehensive evaluation. The results show that AC-BaaS outperforms SOTA schemes, improving throughput by an average of 1.71 to 5.09 times, reducing transaction latency by 64.36% to 85.49%, and maintaining comparable resource overhead.
Lingxiao Yang, Xuewen Dong, Zhiguo Wan, Sheng Gao 0002, Wei Tong 0003, Yong Yu 0002, Yulong Shen 0001
IEEE Trans. Serv. Comput.2
2025 LBFT-DAG: A Swift, Leader-Driven, DAG-Based Consortium Blockchain with Byzantine Fault-Tolerance
Xuewen Dong, Teng Li 0003, Youliang Tian, Yulong Shen 0001, Xiaojiang Du
INFOCOM1
2025 AsyncSC: An Asynchronous Sidechain for Multi-Domain Data Exchange in Internet of Things
Lingxiao Yang, Xuewen Dong, Zhiguo Wan, Sheng Gao 0002, Wei Tong 0003, Di Lu 0001, Yulong Shen 0001, Xiaojiang Du
INFOCOM2
2025 HiCoCS: High Concurrency Cross-Sharding on Permissioned Blockchains
abstract
As the foundation of the Web3 trust system, blockchain technology faces increasing demands for scalability. Sharding emerges as a promising solution, but it struggles to handle highly concurrent cross-shard transactions (CSTxs), primarily due to simultaneous ledger operations on the same account. Hyperledger Fabric, a permissioned blockchain, employs multi-version concurrency control for parallel processing. Existing solutions use channels and intermediaries to achieve cross-sharding in Hyperledger Fabric. However, the conflict problem caused by highly concurrent CSTxs has not been adequately resolved. To fill this gap, we propose HiCoCS, a high concurrency cross-shard scheme for permissioned blockchains. HiCoCS creates a unique virtual sub-broker for each CSTx by introducing a composite key structure, enabling conflict-free concurrent transaction processing while reducing resource overhead. The challenge lies in managing large numbers of composite keys and mitigating intermediary privacy risks. HiCoCS utilizes virtual sub-brokers to receive and process CSTxs concurrently while maintaining a transaction pool. Batch processing is employed to merge multiple CSTxs in the pool, improving efficiency. We explore composite key reuse to reduce the number of virtual sub-brokers and lower system overhead. Privacy preservation is enhanced using homomorphic encryption. Evaluations show that HiCoCS improves cross-shard transaction throughput by 3.5-20.2 times compared to the baselines.
Lingxiao Yang, Xuewen Dong, Zhiguo Wan, Di Lu 0001, Yushu Zhang 0001, Yulong Shen 0001
IEEE Trans. Computers2
2025 Adaptive Backdoor Attacks With Reasonable Constraints on Graph Neural Networks
abstract
Recent studies show that graph neural networks (GNNs) are vulnerable to backdoor attacks. Existing backdoor attacks against GNNs use fixed-pattern triggers and lack reasonable trigger constraints, overlooking individual graph characteristics and rendering insufficient evasiveness. To tackle the above issues, we propose ABARC, the firstAdaptiveBackdoorAttack withReasonableConstraints, applying to both graph-level and node-level tasks in GNNs. For graph-level tasks, we propose a subgraph backdoor attack independent of the graph's topology. It dynamically selects trigger nodes for each target graph and modifies node features with constraints based on graph similarity, feature range, and feature type. For node-level tasks, our attack begins with an analysis of node features, followed by selecting and modifying trigger features, which are then constrained by node similarity, feature range, and feature type. Furthermore, an adaptive edge-pruning mechanism is designed to reduce the impact of neighbors on target nodes, ensuring a high attack success rate (ASR). Experimental results show that even with reasonable constraints for attack evasiveness, our attack achieves a high ASR while incurring a marginal clean accuracy drop (CAD). When combined with the state-of-the-art defense randomized smoothing (RS) method, our attack maintains an ASR over 94%, surpassing existing attacks by more than 7%.
Xuewen Dong, Shujun Li 0001, Zhichao You, Qiang Qu 0001, Yaroslav Kholodov, Yulong Shen 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Location Privacy Preservation Crowdsensing With Federated Reinforcement Learning
abstract
Crowdsensing has become a popular method of sensing data collection while facing the problem of protecting participants' location privacy. Existing location-privacy crowdsensing mechanisms focus on static tasks and participants without considering sensing tasks' time requirements and participants' mobility, which cannot achieve satisfactory collected data quality and task completion in crowdsensing with dynamic tasks and participants. Inspired by this, we proposed a location-preservation crowdsensing mechanism, FedSense, considering dynamic tasks and participants based on federated learning (FL) and reinforcement learning (RL). In FedSense, through RL's outstanding decision-making ability, participants select sensing tasks to perform by well-trained RL models without uploading location information to servers for task allocation. We propose an independent tasks selection environment that defines actions, states, and rewards of RL to enable FedSense to achieve satisfactory task completion and data quality while preserving location privacy. Besides, FedSense applies an asynchronous FL aggregation algorithm that reduces participants' network stabilization and device computing ability requirements. Analysis proves that participants' location information does not leave the local device during the model training and task selection process, effectively avoiding privacy leakage. Simulation shows that compared with existing location-preservation crowdsensing mechanisms, FedSense achieves the highest task completion and sensing accuracy for dynamic tasks and participants.
Zhichao You, Xuewen Dong, Ximeng Liu, Sheng Gao 0002, Yongzhi Wang 0001, Yulong Shen 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Local Differential Privacy Is Not Enough: A Sample Reconstruction Attack Against Federated Learning With Local Differential Privacy
abstract
Reconstruction attacks against federated learning (FL) aim to reconstruct users’ samples through users’ uploaded gradients. Local differential privacy (LDP) is regarded as an effective defense against various attacks, including sample reconstruction in FL, where gradients are clipped and perturbed. Existing attacks are ineffective in FL with LDP since clipped and perturbed gradients obliterate most sample information for reconstruction. Besides, existing attacks embed additional sample information into gradients to improve the attack effect and cause gradient expansion, leading to a more severe gradient clipping in FL with LDP. In this paper, we propose a sample reconstruction attack against LDP-based FL with any target models to reconstruct victims’ sensitive samples to illustrate that FL with LDP is not flawless. Considering gradient expansion in reconstruction attacks and noise in LDP, the core of the proposed attack is gradient compression and reconstructed sample denoising. For gradient compression, an inference structure based on sample characteristics is presented to reduce redundant gradients against LDP. For reconstructed sample denoising, we artificially introduce zero gradients to observe noise distribution and scale confidence interval to filter the noise. Theoretical proof guarantees the effectiveness of the proposed attack. Evaluations show that the proposed attack is the only attack that reconstructs victims’ training samples in LDP-based FL and has little impact on the target model’s accuracy. We conclude that LDP-based FL needs further improvements to defend against sample reconstruction attacks effectively.
Zhichao You, Xuewen Dong, Shujun Li 0001, Ximeng Liu, Siqi Ma 0001, Yulong Shen 0001
IEEE Trans. Inf. Forensics Secur.2
2025 Joint Trajectory Planning and Task Offloading for MIMO AAV-Aided Mobile Edge Computing
abstract
Edge computing is conducive to reducing service response time and improving service quality by pushing cloud functions to a network's edges. Most existing works in edge computing focus on utility maximization of task offloading on static edges with a single antenna. Besides, trajectory planning of mobile edges, e.g., autonomous aerial vehicles (AAVs) is also rarely discussed. In this paper, we are the first to jointly discuss the deadline-ware task offloading and AAV trajectory planning problem in a multi-input multi-output (MIMO) AAV-aided mobile edge computing system. Due to discrete variables and highly coupling nonconvex constraints, we equivalently convert the original problem into a more solvable form by introducing auxiliary variables. Next, a penalty dual decomposition-based algorithm is developed to achieve a global optimal solution to the problem. Besides, we proposed a profit-based fireworks algorithm in a relatively lower time to reduce the execution time for large-scale networks. Extensive evaluation results reveal that our proposed optimal algorithms could significantly outperform static offloading algorithms and other algorithms by 25% on average.
Xuewen Dong, Shuangrui Zhao, Ximeng Liu, Zijie Di, Yulong Shen 0001
IEEE Trans. Mob. Comput.1
2024 Watch the Rhythm: Breaking Privacy with Accelerometer at the Extremely-Low Sampling Rate of 5Hz
abstract
Considering the threat from on-board eavesdropping with smartphone motion sensors, Android 12 has limited the maximum sampling rate of motion sensors to 200Hz for zero-privilege access to prevent potential wiretapping.Unfortunately, there have been some attacks targeting 200Hz, making it not a safe sampling rate any more.Smartphone manufacturers may further reduce the maximum sampling rate of the accelerometer in response to this privacy concern.It can be expected that, the maximum sampling rate will gradually decrease to a very low level, as the battle between manufacturers and adversaries continues.Existing on-board eavesdropping approaches, utilizing spectral features, cannot provide acceptable accuracy at very low sampling rates, not even at 50Hz.Therefore, this paper explores the feasibility of using the onboard accelerometer for privacy breaking with an extremely-low sampling rate, specifically, 5Hz.5Hz is a minimum sampling rate to meet normal use, otherwise the applications can only choose to work without the accelerometer.Since the lowest fundamental frequency for humans is around 85Hz, such a low sampling rate poses a significant challenge for sound recognition.According to Nyquist's law, it seems impossible to capture 85Hz with the sampling rate of 5Hz.Fortunately, we observe that the rhythm features, including pause rhythm and intensity rhythm, of accelerometer data are relatively stable at various sampling rates.On this basis, we propose an eavesdropping approach with the accelerometer at an extremely-low sampling rate.Introducing the rhythm features, we * He completed his work on this paper as a graduate student at Xidian University, unrelated to his current institution.
Qingsong Yao, Xiongjia Sun, Xuewen Dong, Xiaoyu Ji 0001, Jianfeng Ma 0001
CCS4
2024 FedADDP: Privacy-Preserving Personalized Federated Learning with Adaptive Dimensional Differential Privacy
Tao Zhang 0029, Xutong Mu, Haoshuo Li, Xuewen Dong, Qi Li 0011
ICA3PP (5)5
2024 Non-Subjective Trust Mechanism for Online Ride-Hailing Services
abstract
Online ride-hailing services (ORHS) are changing the travel mode. The quality evaluation of ORHS is essential to regulate driver behavior and guide passengers in choosing good services. The existing quality evaluation methods of ORHS rely on subjective passenger feedback, while they are susceptible to malicious or paranoid feedback, resulting in untrustworthy evaluation results. This paper proposes a non-subjective trust mechanism for ORHS to supplement existing evaluation methods. Inspired by the trust machine, this mechanism defines the concept of non-subjective trust to measure the quality of ORHS. It uses trajectory data collected by infrastructure as a parameter to calculate the non-subjective trust value of ORHS, which can ensure the trustworthiness and authenticity of the calculation results. In addition, a blockchain is adopted to store trajectory data and trust values in the infrastructure. It promotes its flexible management and use and ensures the security of data and traceability of evaluation results. Security analysis and extensive experiments show that the trust value calculated by this mechanism is resistant to attacks and trustworthy.
Wei Tong 0003, Xuewen Dong, Weidong Yang 0003, Yulong Shen 0001, Chao Yang 0016, Zesong Dong
ICWS2
2024 PhantomPatch: Easy-ignoring Attacks on Object Detectors Using Ghosting Artifacts
abstract
Current patches used to attack object detectors are easily noticeable as abnormal. To mitigate this shortcoming, we devise an innovative technique named PhantomPatch, which leverages lens flare phenomena to attack object detectors, particularly in autonomous driving systems. Leveraging transfer-based adversarial examples, this method fools object detectors by projecting deceptive lens flares or ghost images, which are meaningless to people, while the light source looks like nearby light for people. Thus, it is easy to ignore.In this way, we enable a cost-effective approach to manipulate the perception of the vehicle remotely. This strategy harmonizes adversarial patches with projecting image integrity correcting. Firstly, we propose to train a black-box transfer-based adversarial patch to fool the object-detecting system behind the camera. Then, the patch is printed and attached in front of a flashlight, which casts the patch onto the camera, resulting in a ghost image. We maintain the integrity of the image captured by the camera while casting the patch with image loss correction and optical distortion modeling.Our experimental results validate the effectiveness of PhantomPatch in evading existing object detectors such as YOLO V3/V5 and Faster R-CNN. Notably, during nocturnal scenarios, the technique achieves a success rate of 98.2%. Furthermore, our approach addresses limitations of existing methods, like conspicuousness and positional constraints, offering a low-cost and effective technique for adversarial attacks, especially for autonomous vehicles. Code and demo are available at https://github.com/rufus0803/PhantomPatch.
Qingsong Yao, Jingwei Li 0001, Xuewen Dong, Jianfeng Ma 0001
ISPA4
2024 Federated and Online Dynamic Spectrum Access for Mobile Secondary Users
abstract
Users in dynamic spectrum access (DSA) with federated reinforcement learning (FRL) autonomously access channels, avoiding centralized coordination and protecting users’ privacy. However, existing FRL-based DSA mechanisms are limited to ideal network states, i.e., assuming that channel states and users’ interference relationships are unchanged. Besides, users should upload intermediate results simultaneously for federated aggregation. The above conditions are impractical for mobile users since their network states and locations are unstable. Meanwhile, newly connected users have to train their models through local data with numerous computing resources since global models are unsuitable for them. We propose FRDSA, an FRL-based secure and lightweight channel selection mechanism in DSA for mobile users under dynamic network states. An independent channel selection environment with a virtual group strategy is presented to avoid interference between users under unstable channel states. Furthermore, an asynchronous parameter aggregation method in FRDSA dynamically adjusts the aggregation factors without users simultaneously uploading intermediate results. Simulations based on real trajectory data show that FRDSA significantly reduces approximately 60% interference between mobile users under unstable network states. Newly connected users can directly apply the well-trained global model to access channels autonomously instead of retraining a model, effectively reducing mobile users’ computing resource requirements.
Xuewen Dong, Zhichao You, Ximeng Liu, Yuanxiong Guo, Yulong Shen 0001, Yanmin Gong 0001
IEEE Trans. Wirel. Commun.1
2023 Optimal Hub Placement and Deadlock-Free Routing for Payment Channel Network Scalability
abstract
As a promising implementation model of payment channel network (PCN), payment channel hub (PCH) could achieve high throughput by providing stable off-chain transactions through powerful hubs. However, existing PCH schemes assume hubs are preplaced in advance, not considering payment requests' distribution and may affect network scalability, especially network load balancing. In addition, current source routing protocols with PCH allow each sender to make routing decision on his/her own request, which may have a bad effect on performance scalability (e.g., deadlock) for not considering other senders' requests. This paper proposes a novel multi-PCHs solution with high scalability. First, we are the first to study the PCH placement problem and propose optimal/approximation solutions with load balancing for small-scale and large-scale scenarios, by trading off communication costs among participants and turning the original NP-hard problem into a mixed-integer linear programming (MILP) problem solving by supermodular techniques. Then, on global network states and local directly connected clients' requests, a routing protocol is designed for each PCH with a dynamic adjustment strategy on request processing rates, enabling high-performance deadlock-free routing. Extensive experiments show that our work can effectively balance the network load, and improve the performance on throughput by 29.3% on average compared with state-of-the-arts.
Lingxiao Yang, Xuewen Dong, Sheng Gao 0002, Qiang Qu 0001, Xiaodong Zhang 0036, Wensheng Tian, Yulong Shen 0001
ICDCS2
2023 Testing Automated Driving Systems by Breaking Many Laws Efficiently
abstract
An automated driving system (ADS), as the brain of an autonomous vehicle (AV), should be tested thoroughly ahead of deployment. ADS must satisfy a complex set of rules to ensure road safety, e.g., the existing traffic laws and possibly future laws that are dedicated to AVs. To comprehensively test an ADS, we would like to systematically discover diverse scenarios in which certain traffic law is violated. The challenge is that (1) there are many traffic laws (e.g., 13 testable articles in Chinese traffic laws and 16 testable articles in Singapore traffic laws, with 81 and 43 violation situations respectively); and (2) many of traffic laws are only relevant in complicated specific scenarios.
Xiaodong Zhang 0036, Yang Sun 0008, Jun Sun 0001, Yulong Shen 0001, Xuewen Dong, Zijiang Yang 0004
ISSTA6
2023 Anonymous Lightweight Authenticated Key Agreement Protocol for Fog-Assisted Healthcare IoT System
abstract
The impact of fog-assisted healthcare Internet of Things (H-IoT) system is immense. The smart H-IoT equipments can upload healthcare information to fog nodes with low latency and high mobility. To facilitate secure interactions among three parties, including smart H-IoT equipments, fog nodes, and a cloud server, over the public and insecure channels, a few authenticated key agreement (AKA) protocols are proposed. However, existing works are constructed based on expensive cryptographic primitives (e.g., bilinear pairing), which lead to high computation costs. Besides, the anonymity of H-IoT users is failed to be provided. To tackle these issues, an anonymous and lightweight three-party AKA protocol (ALAKAP) is proposed, which leverages an efficient cryptographic primitive (i.e., Chebyshev chaotic map operation) to generate a shared session key among three parties and achieve security (anonymity and other six properties) and efficiency simultaneously. It then formally proves the security of ALAKAP under the broadly accepted Burrows–Abadi–Needham (BAN) logic model and demonstrates how the proposed protocol satisfies the desired requirements in the fog-assisted H-IoT system. Finally, the performance of ALAKAP is validated by conducting the experiments on Amazon EC2 and Raspberry Pi. The results show that our work can achieve at least 44% higher improvement than the state-of-the-art works.
Xuewen Dong, Qi Jiang 0001, Siqi Ma 0001, Chao Liu 0039, Ning Xi 0002, Yulong Shen 0001
IEEE Internet Things J.2
2023 TI-BIoV: Traffic Information Interaction for Blockchain-Based IoV With Trust and Incentive
abstract
Recent Blockchain-based Internet of Vehicles (BIoV) solutions are proposed to provide the capabilities of trust management and incentive distribution for traffic information interaction in decentralized trustless Internet of Vehicles (IoV). However, existing trust management methods in BIoV are designed based on subjective user feedback, which is vulnerable to bad-mouthing and collusion attacks. Besides, these incentive strategies achieve accurate information interaction based on the game theory, yet it is challenging for the practical IoV scenario without completely explicit parameters. To address these issues, we propose TI-BIoV, a traffic information interaction system based on three blockchains for IoV with the nonsubjective trust evaluation and optimal incentive with partial inexplicit parameters. Specifically, a nonsubjective trust mechanism is designed based on the traffic information offset calculated by other related traffic information, which ensures the change of vehicle trust value without any subjective factors. On this basis, a trust-based consensus protocol, which selects entities with high trust values as participants, is given to realize the reliable public audit of transactions. According to traffic information accuracy measurements, we develop a$Q$-learning-based algorithm to encourage vehicles continuously submit accurate traffic information and optimally schedule the incentive for both platform and vehicle via training with incompletely explicit parameters of TI-BIoV. Finally, we analyze the security properties and common attacks of TI-BIoV and implement a prototype. The experimental results show that TI-BIoV achieves reliable consensus with nonsubjective trust evaluation and runs stably for a long time with two-sided incentive strategies.
Wei Tong 0003, Xuewen Dong, Yushu Zhang 0001, Zongyang Zhang, Lingxiao Yang, Weidong Yang 0003, Yulong Shen 0001
IEEE Internet Things J.2
2023 Personalized Location Privacy Trading in Double Auction for Mobile Crowdsensing
abstract
Mobile crowdsensing systems (MCSs) are widely used in data collection due to their flexible deployment and comprehensive coverage in many IoT scenarios (e.g., road condition monitoring). Recently, the difference between workers’ perception on location privacy has drawn researchers’ attention. The only privacy trading mechanism in MCSs has been designed, however, in a single auction and single-minded way. Realizing task requesters’ competition requirement and workers’ task preference variance, in this article, we are the first to propose a double MCS auction mechanism with a personalized location privacy incentive. Specifically, this article introduces the concept of privacy budget, allowing workers to decide how much location information to disclose to the platform to realize personalized location privacy protection. Besides, considering the heterogeneity of sensing tasks and the diversity of task selection, each worker is allowed to offer several bids for interested tasks and to perform a subset of tasks in a bid if wins. In addition, our auction mechanism enables the platform to select winning requesters and workers and achieve ideal sensing service accuracy. Extensive theoretical analysis and experiment results validate that the proposed mechanism satisfies budget balance, individual rationality, and 2-D-truthfulness.
Hao Liu 0110, Xuewen Dong, Yulong Shen 0001, Bin Wang 0062
IEEE Internet Things J.3
2023 Performance-Power Tradeoff in Heterogeneous SaaS Clouds With Trustworthiness Guarantee
abstract
Software-as-a-service (SaaS) clouds grow dramatically due to cost-effectiveness, availability, and flexibility. Quality of service (QoS) and power, which represent performance and cost, respectively, are conflicting yet critical issues in the service scheduling of SaaS clouds, and some researchers have investigated the tradeoff between them. However, existing works do not involve QoS attacks in which untrusted service providers provide fake QoS values to absorb service requests, resulting in lower user experience and system profits. In this paper, we jointly consider the QoS performance, queue congestion, and energy consumption to formulate the performance-power tradeoff while considering QoS attacks. To address this NP scheduling problem, we propose a Lyapunov-based decomposition strategy that converts the original problem into three equivalent subproblems. By aggregating the solving strategies for the three subproblems, we develop the online service selection and trustworthiness management algorithm that optimizes the performance–power tradeoff while resisting QoS attacks. In addition, a light-weighted trustworthiness management strategy is designed to update trustworthiness values without storing large amounts of past information. Mathematical analyses and simulations demonstrate that our proposed control framework realizes detection and resistance of QoS attacks and a$[O(1 / V), O(V)]$tradeoff between performance and power with a performance-power tradeoff parameter V.
Zijie Di, Qingsong Yao, Xuewen Dong, Yulong Shen 0001
IEEE Trans. Computers4
2023 Joint Controller Placement and Control-Service Connection in Hybrid-Band Control
abstract
By separating the forwarding and control planes, Software-Defined Networking (SDN) facilitates flexible traffic routing and network management for a service network. Because of the impact of controller deployment on message transmission distances and network latency, controller placement problems have drawn many researchers’ attention. However, assumptions in most existing research that all control packets are either transmitted in the service network (i.e., in-band control) or through predetermined control-service connection (i.e., out-of-band control) are not reasonable due to bandwidth resources occupation on the service network or high construction costs. In this paper, we are the first to jointly discuss the controller placement and control-service connection problem for latency minimization in the hybrid-band control mode, which is essentially a bi-level programming optimization problem. Specifically, we introduce auxiliary variables to simplify the above NP-hard problem. Next, Generalized Benders decomposition is used to obtain an optimal solution in theory. In addition, we propose a time-efficient fireworks algorithm with a little latency increment for large-scale networks. Extensive evaluations show that the two proposed algorithms accomplish the desired objectives and respectively achieve up to 35% and 25% latency decrement than greedy algorithms.
Xuewen Dong, Lingtao Xue, Zhiwei Zhang 0004, Yushu Zhang 0001, Teng Li 0003, Zhichao You, Yulong Shen 0001
IEEE Trans. Cloud Comput.1
2023 BeDCV: Blockchain-Enabled Decentralized Consistency Verification for Cross-Chain Calculation
abstract
With the increase of data stored on the blockchain, the efficiency of storage and calculation of blockchain has gradually become a bottleneck restricting the development of blockchain. By storing data on multiple chains, blockchains can request data from other chains for calculation and the storage pressure can be alleviated. But the transfer of a large amount of data between chains suffers from low transfer efficiency and poor security. A reasonable design is to perform the calculation on the data storage chain and only transfer the results across chains. However, since the calculation process is invisible, blockchains cannot judge the consistency of calculation results from other chains. In this paper, we provide a blockchain-enabled decentralized consistency verification scheme for cross-chain calculation (BeDCV). Considering the decentralized characteristic of blockchain, we adopt the blockchain calledsupervision chainfor decentralized auditing. We modify paillier homomorphic encryption to encrypt data involved in the calculation for correctness verification. Then, we aggregate the ciphertexts of data to generate the audit proof for integrity verification. Besides, we verify whether the data involved in the calculation are real-time by leveraging a counting bloom filter. The supervision chain can check the correctness, integrity, and real-time performance of cross-chain data calculation without revealing any original information about the data. The theoretical and experimental analysis demonstrates that BeDCV can verify the consistency of cross-chain data calculation result effectively, realizing secure and reliable expansion of blockchain.
Yushu Zhang 0001, Xuewen Dong, Liangmin Wang 0001, Yong Xiang 0001
IEEE Trans. Cloud Comput.3
2023 Smaug: A TEE-Assisted Secured SQLite for Embedded Systems
abstract
As one of the most popular relational databases for embedded devices, SQLite is lightweight to be embedded into applications without installing a specific database management system. However, simplicity and easy-to-use are double-edged swords; while bringing convenience, they also make data processing and storage risky. For example, an attacker can obtain data from a database file or memory and tamper with it once he has gained higher privileges, threatening the database's confidentiality and integrity. To address such security issues, based on a trusted execution environment (TEE) and a trusted platform module (TPM), we have proposed Smaug, a general secure scheme to ensure the confidentiality and integrity of SQLite and similar databases. With Smaug, all the critical data is stored in ciphertext, and data integrity protection is also provided. Besides, with TEE, all the sensitive operations are isolated from the untrusted environment, which can effectively resist attacks against memory. In addition, we use TPM to provide a solid root-of-trust (RoT) for the system. Finally, we have implemented a prototype system, and the performance evaluations have clarified the dominant factors that affect the system availability, providing a reference to the design and implementation of similar systems.
Di Lu 0001, Minqiang Shi, XinDi Ma, Ximeng Liu, Tianfang Zheng, Yulong Shen 0001, Xuewen Dong, Jianfeng Ma 0001
IEEE Trans. Dependable Secur. Comput.8
2023 VCD-FL: Verifiable, Collusion-Resistant, and Dynamic Federated Learning
abstract
Federated learning (FL) is essentially a distributed machine learning paradigm that enables the joint training of a global model by aggregating gradients from participating clients without exchanging raw data. However, a malicious aggregation server may deliberately return designed results without any operation to save computation overhead, or even launch privacy inference attacks using crafted gradients. There are only a few schemes focusing on verifiable FL, and yet they cannot achieve collusion-resistant verification. In this paper, we propose the first Verifiable, Collusion-resistant, and Dynamic FL (VCD-FL) to tackle this issue. Specifically, we first optimize Lagrange interpolation by gradient grouping and compression for achieving efficient verifiability of FL. To protect clients’ data privacy against collusion attacks, we propose a lightweight commitment scheme using irreversible gradient transformation. By integrating the proposed efficient verification mechanism with the novel commitment scheme, our VCD-FL can detect whether or not the aggregation server is involved in collusion attacks. Moreover, considering that clients might go offline due to some reason such as network anomaly and client crash, we adopt the secret sharing technique to eliminate the effect of federation dynamics on FL. To the best of our knowledge, this is the first work to achieve collusion-resistant verification and collusion attack detection with supporting the correctness, privacy, and dynamics. Finally, we theoretically prove the effectiveness of our VCD-FL, make comprehensive comparisons, and conduct a series of experiments on MNIST dataset with MLP and CNN models. The theoretical proof and experimental analysis demonstrate that our VCD-FL is computationally efficient, robust against collusion attacks, and able to support the dynamics of FL.
Sheng Gao 0002, Jingjie Luo, Jianming Zhu 0002, Xuewen Dong, Weisong Shi
IEEE Trans. Inf. Forensics Secur.4
2023 A Two-Dimensional Sybil-Proof Mechanism for Dynamic Spectrum Access
abstract
Achieving higher spectrum utilization, auction-based mechanisms has been regarded as a popular tool in dynamic spectrum access (DSA). Recently, Sybil attacks in auction-based DSA mechanisms have been investigated, where a cheating bidder can manipulate an auction by submitting bids under multiple fake identities. Existing Sybil-proof mechanisms in DSA are limited to prevent Sybil attacks from primary users (PUs) or secondary users (SUs). However, both of PUs and SUs may perform Sybil attacks in DSA, i.e., double Sybil attacks. The challenge of solving the double Sybil attacks is that fictitious identities and fake bids can directly affect allocation results, but the malicious bidders cannot be straightforwardly distinguished from all bidders. To resist the double Sybil attacks, we propose STEAM, the first double Sybil-proof and two-dimensional Truthful spEctrum Auction Mechanism for DSA. Specifically, STEAM merges suspicious buyers based on geographic characteristics and sorts sellers by a bid-independent sorting method to minimize the impact of untruthful bids and Sybil attacks on the allocation results. Theoretical analysis and extensive evaluations prove that STEAM is double Sybil-proof, two-dimensional truthful, individual rational and budget-balanced, while the performance loss in various metrics within 8% compared to the existing auction-based mechanisms.
Xuewen Dong, Zhichao You, Yulong Shen 0001, Di Lu 0001, Yang Xu 0012, Jia Liu 0009
IEEE Trans. Mob. Comput.1
2023 PRAM: A Practical Sybil-Proof Auction Mechanism for Dynamic Spectrum Access With Untruthful Attackers
abstract
Auction is becoming increasingly popular for dynamic spectrum access (DSA), while it is extremely vulnerable to sybil attacks. Existing studies on sybil-proof DSA auction impractically assume that attackers bid truthfully based on true appraisals. This paper, for the first time, considers untruthful attackers and investigates the sybil-proof auction design in such more hazardous scenarios. To justify the new assumption, we first show that attackers obtain higher utilities by bidding untruthfully, especially in networks with inadequate channels. Based on this novel finding, we then design a practical sybil attack model named EqualSumBid Sybil, where attackers follow an equal-sum rule (i.e., the sum bid value of the multiple identities of an attacker equals the bid value when it bids with only one identity) instead of their true appraisals. To ensure efficient DSA under the new attack, we finally propose the PRAM, a Practical sybil-pRoof Auction Mechanism, where suspicious identity merging and bid-independent bidder sorting methods are introduced to alleviate the effect of untruthfulness on spectrum auction. Furthermore, winner selection and payment methods are designed to resist the EqualSumBid Sybil attack. Theoretical analyses and numerical results show that PRAM not only resists the EqualSumBid Sybil attack but also achieves individual rationality and truthfulness.
Xuewen Dong, Yuanyu Zhang 0001, Yuanxiong Guo, Yanmin Gong 0001, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Mob. Comput.1
2023 Fair Outsourcing Paid in Fiat Money Using Blockchain
abstract
Seeking outsourcing from cloud service providers is common for resource-constrained users to complete complex computing. Conventional cloud computing outsourcing solutions focus on guiding users to verify the returned results, which is unfair since malicious users can refuse to pay by falsely claiming that the results are wrong. To address this problem, fair payment schemes, both blockchain-free and blockchain-based, have been proposed. However, the former is usually inefficient and the latter only supports payment through cryptocurrencies. The use of cryptocurrencies faces hurdles as it exposes cloud service providers to a significant risk of sharp currency price fluctuations, as well as vulnerability to government bans due to regulatory concerns. In contrast, fiat money payment is not only more in line with the business norm, but also naturally avoids the above troubles. Motivated by this, a blockchain-based fair outsourcing scheme to support payment in fiat money is proposed in this paper. The proposed scheme has broad compatibility and, as an example, is subsequently instantiated with a conventional outsourcing solution of eigen-decomposition. The performance of the scheme in fairness, privacy, and efficiency is verified by both theoretical and experimental evaluations.
Xiangli Xiao, Yushu Zhang 0001, Xuewen Dong, Liangmin Wang 0001, Yong Xiang 0001, Xiaochun Cao
IEEE Trans. Serv. Comput.3
2023 Load Balancing of Double Queues and Utility-Workload Tradeoff in Heterogeneous Mobile Edge Computing
abstract
Mobile edge computing (MEC) is a popular service paradigm by which mobile devices can offload their latency-sensitive and computation-intensive workloads to edge servers. The MEC service scheduling problem has been investigated in recent years. However, most MEC service scheduling mechanisms only consider workloads on homogeneous edge servers, causing servers’ queue backlogs to be too large when innumerable user requests arrive concurrently. In this paper, we are the first to propose a double-queue workloads scheduling model innovatively, and formulate a system (including user ends and edge server ends) utility into a scheduling optimization problem. To tackle such an NP scheduling problem, we present a Lyapunov-based decomposition strategy to convert the original problem into three equivalent subproblems. By aggregating three subproblem solving strategies, we propose the Lyapunov-based online matching algorithm for edge service scheduling, named LOMES, to obtain an optimal system utility while guaranteeing the load balancing of mobile devices and heterogeneous edge servers. Simulations further validate that LOMES realizes the load balancing of two queue lengths and a$[O(1/V); O(V)]$tradeoff between the system’s utility and workloads with a utility-workload tradeoff parameter${V}$.
Xuewen Dong, Zijie Di, Liangmin Wang 0001, Qingsong Yao, Guangxia Li, Yulong Shen 0001
IEEE Trans. Wirel. Commun.1
2022 Dual Adversarial Federated Learning on Non-IID Data
Tao Zhang 0029, Shaojing Yang, Anxiao Song, Guangxia Li, Xuewen Dong
KSEM (3)5
2022 A blockchain-driven data exchange model in multi-domain IoT with controllability and parallelity
Wei Tong 0003, Xuewen Dong, Yulong Shen 0001, Xiaohong Jiang 0001, Zhiwei Zhang 0004
Future Gener. Comput. Syst.2
2022 CHChain: Secure and parallel crowdsourcing driven by hybrid blockchain
Wei Tong 0003, Xuewen Dong, Yulong Shen 0001, Yuanyu Zhang 0001, Xiaohong Jiang 0001, Wensheng Tian
Future Gener. Comput. Syst.2
2022 Privacy-Preserving Asynchronous Grouped Federated Learning for IoT
abstract
Federated learning (FL), a cooperative distributed learning framework, has been employed in various intelligent Internet of Things (IoT) applications (e.g., smart health-care, smart home, and smart industry). However, there may be malicious devices in these IoT applications inferring other devices’ privacy or destroying the uploaded model parameters. Besides, due to the heterogeneity of IoT devices, it is difficult for the existing synchronized FL to effectively train models through non-identical independently distributed (non-IID) local data sets. To address these issues, we propose an asynchronous grouped federated learning framework (PAG-FL) for IoT, enabling multiple devices and the server to collaboratively and efficiently train models without revealing privacy. PAG-FL framework consists of an adaptive Rényi Differential Privacy-based privacy budget allocation (ARB) protocol and an asynchronous weight-based grouped update (AWGU) algorithm. In particular, our ARB protocol applies Rényi Differential Privacy and adaptively adjusts the privacy budget to obtain an efficient local model. The AWGU algorithm can defend against the poisoning attack on non-IID data set by weighing grouped local models to generate a global model. Meanwhile, it also realizes the asynchronous optimized update by adopting a lazy loading strategy. Theoretically, the proposed framework has a convergence guarantee and a privacy guarantee when training over the non-IID data set in an asynchronous FL. Our empirical experiments validate the effectiveness of the theoretical design and demonstrate the improved utility and robustness of PAG-FL in heterogeneous IoT.
Tao Zhang 0029, Anxiao Song, Xuewen Dong, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Internet Things J.3
2022 Optimizing Task Location Privacy in Mobile Crowdsensing Systems
abstract
The location information for tasks may expose sensitive information, which impedes the practical use of mobile crowdsensing in the industrial Internet. In this article, to our knowledge, we are the first to discuss the privacy protection of task locations and propose a codebook-based task allocation mechanism to protect it. Considering the cost of system utility caused by privacy protection technology, the tradeoff between local privacy and system utility is formalized a multiobjective optimization problem. The optimal solution is theoretically derived, and the optimal task allocation scheme is obtained. In addition, the selected allocation codebook (SAC) method is introduced to solve the problem of high computational resource consumption in the task allocation process and protect the task location privacy to some extent. The experimental results show that the SAC method sacrifices system utility but improves the privacy protection for task locations by 60% on average.
Xuewen Dong, Yushu Zhang 0001, Zhichao You, Sheng Gao 0002, Yulong Shen 0001, Chao Wang 0028
IEEE Trans. Ind. Informatics1
2022 TrustWorker: A Trustworthy and Privacy-Preserving Worker Selection Scheme for Blockchain-Based Crowdsensing
abstract
Worker selection in crowdsensing plays an important role in the quality control of sensing services. The majority of existing studies on worker selection were largely dependent on a trusted centralized server, which might suffer from single point of failure, the lack of transparency and so on. Some works recently proposed blockchain-based crowdsensing, which utilized reputation values stored on blockchains to select trusted workers. However, the transparency of blockchains enables attackers to effectively infer private information about workers by the disclosure of their reputation values. In this article, we proposed the TrustWorker, a trustworthy and privacy-preserving worker selection scheme for blockchain-based crowdsensing. By taking the advantages of blockchains such as decentralization, transparency and immutability, our TrustWorker could make the worker selection process trustworthy. To protect workers’ reputation privacy in our TrustWorker, we adopted a deterministic encryption algorithm to encrypt reputation values and then selected the top$N$workers in the light of secret minimum heapsort scheme. Finally, we theoretically analyzed the effectiveness and efficiency of our TrustWorker, and then conducted a series of experiments. The theoretical analysis and experiment results demonstrate that our TrustWorker can achieve trustworthy worker selection, while ensuring the workers’ privacy and the high quality of sensing services.
Sheng Gao 0002, Xiuhua Chen, Jianming Zhu 0002, Xuewen Dong, Jianfeng Ma 0001
IEEE Trans. Serv. Comput.4
2021 On Strategic Interactions in Blockchain Markets: A Three-stage Stackelberg Game Approach
abstract
Blockchain technology is a promising approach for solving the security and personal privacy problems in Internet applications. The successful commercial deployment of Blockchain markets relies on a comprehensive understanding of the economic and strategic interactions among different entities involved. In this paper, we focus on a blockchain market consisting of a blockchain platform (BP), multiple miners, and blockchain users (BUs), and formulate their interactions as a three-stage Stackelberg game. In Stage I, the BP strategizes the rewards granted to the miners, so as to attract the miners to contribute more computing power used for improving the security and privacy of the blockchain. In Stage II, each miner strategizes its computing power individually for winning the mining compe-tition, which is modeled as a non-cooperative game. In Stage III, the BUs strategize the transaction fee to acquire a corresponding service experience. With the objective of utility maximization, we develop a theoretical framework to analyze the hierarchical interactive behaviors among the entities in a backward inductive way. By solving the Stackelberg equilibrium, we determine the optimal strategies of entities in closed-form. Numerical results are provided to demonstrate the performance of the strategic interactions in the blockchain market.
Jianbo Shao, Yang Xu 0012, Jia Liu 0009, Hiroki Takakura, Zhao Li 0005, Xuewen Dong
GLOBECOM6
2021 Optimal Mobile Crowdsensing Incentive Under Sensing Inaccuracy
abstract
Due to the pervasive adoption of sensor-embedded mobile devices yet increasing demand on data and computing resources, mobile crowdsensing is a promising paradigm with rapid growth. One of the most challenging issues is how to maximize the utilities of crowdsensing platforms under inaccurate distributed sensing. The nature of such inaccuracy is due to the fact that energy-based sensing can be greatly impacted by thermal and environmental noise, which significantly affects task allocation strategies of crowdsensing platforms. Because of the allocation efficiency and fairness concerns, auction-based mechanisms have been extensively used in crowdsensing systems. However, the existing auction-based mechanisms for crowdsensing do not take sensing inaccuracy into consideration, while guaranteeing that each participator obtains her maximal utility by bidding with her true cost for tasks. To tackle this issue, in this article, we propose OSIER, an optimal mobile crowdsensing incentive under sensing inaccuracy. Specifically, a quantitative analytical framework on characterizing the impact of sensing inaccuracy on a crowdsensing platform is presented, and an optimization problem involving sensing inaccuracy is solved to achieve a maximum utility of the platform. Furthermore, depending on whether a user needs to perform all tasks simultaneously or not, indivisible tasks and divisible tasks are discussed, and OSIER-I and OSIER-D are presented for these two kinds of tasks. Simulation results verify the truthfulness of OSIER, and given a sample set with 5%-20% noise in spectrum sensing, OSIER can achieve 10% higher utilities than the existing crowdsensing mechanisms on average.
Xuewen Dong, Zhichao You, Tom H. Luan, Qingsong Yao, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Internet Things J.1
2021 xTSeH: A Trusted Platform Module Sharing Scheme Towards Smart IoT-eHealth Devices
abstract
IoT based eHealth system brings a revolution to healthcare industry, with which the old healthcare systems can be updated into smarter and more personalized ones. The practitioners can continue monitoring the physical status of the patients at anytime and anywhere, and develop more precise treatment plans by analyzing the collected data, such as heart rate, blood pressure, blood glucose. Actually, these smart sensors used in eHealth system are smart embedded devices (SED). Due to the limitations on hardware capabilities, these inter-connected SEDs lack of security considerations in design and implementation, and face the threats from the network. To prevent the malicious users (or programs) from tampering with the SEDs, trusted platform module (TPM) is adopted, which can guarantee the system integrity via detecting unauthorized modifications to data and system environment. However, due to the limited scalability and insufficient system resources, not all SEDs can be deployed with TPM chips. To address this issue, in this paper, a TPM extension scheme (xTSeH) is proposed. In xTSeH, we have extended the functions of a TPM deployed in a SED (TSED) to those non-TPM-protected SEDs (N-TSED) via network. A shadow TPM in the form of a kernel module is designed as the trust base for the N-TSED, which is the representative of the TPM in TSED. Then, three protocols are proposed to implement the integrity verification and inter-SED authentication. Finally, a Raspberry Pi based prototype system is designed and implemented. The feasibility and usability of our scheme are proved by the analysis of the experimental results of system performance.
Di Lu 0001, Ruidong Han, Yulong Shen 0001, Xuewen Dong, Jianfeng Ma 0001, Xiaojiang Du, Mohsen Guizani
IEEE J. Sel. Areas Commun.4
2020 Towards Primary User Sybil-proofness for Online Spectrum Auction in Dynamic Spectrum Access
abstract
Dynamic spectrum access (DSA) is a promising platform to solve the spectrum shortage problem, in which auction based mechanisms have been extensively studied due to good spectrum allocation efficiency and fairness. Recently, Sybil attacks were introduced in DSA, and Sybil-proof spectrum auction mechanisms have been proposed, which guarantee that each single secondary user (SU) cannot obtain a higher utility under more than one fictitious identities. However, existing Sybil-poof spectrum auction mechanisms achieve only Sybil-proofness for SUs, but not for primary users (PUs), and simulations show that a cheating PU in those mechanisms can obtain a higher utility by Sybil attacks. In this paper, we propose TSUNAMI, the first Truthful and primary user Sybil-proof aUctioN mechAnisM for onlIne spectrum allocation. Specifically, we compute the opportunity cost of each SU and screen out cost-efficient SUs to participate in spectrum allocation. In addition, we present a bid-independent sorting method and a sequential matching approach to achieve primary user Sybil-proofness and 2-D truthfulness, which means that each SU or PU can gain her maximal utility by bidding with her true valuation of spectrum. We evaluate the performance and validate the desired properties of our proposed mechanism through extensive simulations.
Xuewen Dong, Qiao Kang, Qingsong Yao, Di Lu 0001, Yang Xu 0012, Jia Liu 0009
INFOCOM1
2020 BC-RAN: Cloud radio access network enabled by blockchain for 5G
Wei Tong 0003, Xuewen Dong, Yulong Shen 0001
Comput. Commun.2
2020 A secured TPM integration scheme towards smart embedded system based collaboration network
Di Lu 0001, Ruidong Han, Yue Wang 0063, Yongzhi Wang 0001, Xuewen Dong, XinDi Ma, Teng Li 0003, Jianfeng Ma 0001
Comput. Secur.5
2020 CryptSQLite: SQLite With High Data Security
abstract
SQLite, one of the most popular light-weighted database system, has been widely used in various systems. However, the compact design of SQLite did not make enough consideration on user data security. Specifically, anyone who has obtained the access to the database file will be able to read or tamper the data. Existing encryption-based solutions can only protect data on storage, while still exposing data when in computation. In this article, we combine the Trusted Execution Environment(TEE) technology and the authenticated encryption scheme, proposed and developed the CryptSQLite, a high security SQLite database system, which protects both the confidentiality and integrity of users' data. Our security analysis proves that CryptSQLite can protect data confidentiality and integrity. Our implementation and experiments indicate that CryptSQLite incurs an average of 21 percent of extra time for SQL statement executions, compared with traditional encryption-based solutions that failed to offer rigorous security guarantees.
Yongzhi Wang 0001, Yulong Shen 0001, Cuicui Su, Jiawen Ma, Lingtong Liu, Xuewen Dong
IEEE Trans. Computers6
2020 A Truthful Online Incentive Mechanism for Nondeterministic Spectrum Allocation
abstract
Dynamic spectrum access (DSA) is a promising platform to solve the problem of spectrum shortage for which the most challenging issue is spectrum allocation under uncertain availability information, which is referred as a nondeterministic spectrum allocation problem. The nature of such a problem is due to inaccurate spectrum sensing results, which are induced by that power or energy based sensing can be greatly impacted by thermal and environmental noise. For spectrum allocation, auction-based mechanisms have been extensively studied because of channel allocation efficiency, and its potential to achieve bidding truthfulness for secondary uses (SUs). However, most existing spectrum auction mechanisms focus on realizing the truthfulness under certain spectrum availability information. In this paper, we propose FORTUNE, the first truthful online auction mechanism for nondeterministic spectrum allocation by considering uncertain spectrum availability and dynamic spectrum requests. Specifically, we take limited information to compute expected income and losses when interference between primary users (PUs) and SUs occurs, and present a virtual request method for changing of spectrum's actual state. Thorough theoretical analysis proves the truthfulness of FORTUNE. Furthermore, given a sample set with 5%-30% noise in spectrum sensing, FORTUNE achieves not only truthfulness, but also up to 50% higher channel utilization than existing spectrum auction mechanisms.
Xuewen Dong, Zhichao You, Liangmin Wang 0001, Sheng Gao 0002, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Trans. Wirel. Commun.1
2020 An incentive mechanism with bid privacy protection on multi-bid crowdsourced spectrum sensing
Xuewen Dong, Guangxia Li, Tao Zhang 0029, Di Lu 0001, Yulong Shen 0001, Jianfeng Ma 0001
World Wide Web1
2019 Blockchain-based secure digital asset exchange scheme with QoS-aware incentive mechanism
abstract
As the Internet of things (IoT) is increasingly popular, the number of IoT devices such as sensors and smart equipments are growing at an astonishing rate and data generated by these devices is exploding. However, these massive IoT data, stored in the form of isolated data centers, can not be shared by others who also need it. Moreover, data exchange is now needing a secure and fair mechanism to guarantee the data provider's rights and data security. Data providers also lack the motivation to share their data, as no effective mechanism exists to reward this behavior. To solve these problems, we propose a digital asset exchange mechanism based on blockchain technology, in which we record the behavior of data publishing and exchanging into the blockchain, which can ensure the reliability and transparency of data exchange without the restriction of trusted third-party payment institutions. Especially, to inspire the data providers to share their high-quality data, we design an incentive mechanism based on QoS, which gives higher rewards to those who provide high-quality data. Experimental results of this prototype demonstrate that this mechanism is appropriate to be applied in practice.
Xuewen Dong, Qihang Liu, Wei Tong 0003
HPSR2
2019 A Hierarchical Sharding Protocol for Multi-Domain IoT Blockchains
abstract
Internet of Things (IoT), an significant support for strategic emerging industries, is re-building industrial systems, such as transportation, healthcare and energy, while a number of new features and requirements like data cross-industry sharding appear in recent years. The emerging Blockchain technology has provided a promising opportunity to break information island and single-domain management in multi-domain IoT systems by leveraging distributed storage. On the other hand, the transaction consensus throughput in the mainstream blockchain systems, such as Ethereum and Fabric, is far from meeting the demand for massive data storage in time in multi-domain IoT systems. In this paper, we design a sharding protocol called MDIoTSP. The protocol first partitions the overall blockchains into many small shards, each of which generally recognized as a micro-blockchain according to the multiple domains, and then make the final consensus by merging the hash digests of the sub-blocks which generated from the shards for the multi-domain IoT blockchains ecosystem specifically. We also develop MicrothingsChains to run MDIoTSP in multi-domain IoT blockchains to prove our assumption that MDIoTSP scales up the transaction consensus throughput near linearly with the number of shards.
Wei Tong 0003, Xuewen Dong, Yulong Shen 0001, Xiaohong Jiang 0001
ICC2
2019 Selfholding: A combined attack model using selfish mining with block withholding attack
Xuewen Dong, Anter Faree, Deke Guo, Yulong Shen 0001, Jianfeng Ma 0001
Comput. Secur.1
2016 A new method to deduce counterexamples in secure routing protocols based on strand space model
abstract
Abstract Strand space model, an excellent formal analysis method, is still not effective enough when it is used to analyze ad hoc routing protocols. Counterexamples cannot be deduced directly if a protocol is proved insecure by strand space model. Based on backward reasoning and strand space model, an attack analysis method is proposed to find all possible attacks that cause nonexistent routes to be accepted. To begin with, a nonexistent route is assumed to be accepted by a routing protocol. Then, to decrease the complexity of analysis, an adversarial node abstraction process is carried out to make all the intermediate nodes in the nonexistent route turn into normal nodes. Furthermore, a combined analysis of strand space model and cross‐route attack is carried on the route reply phase of the routing protocol. Finally, all possible attacks that lead to the nonexistent route can be deduced after combined analyzing of the route request phase. Then, we take endairA—a classic secure routing protocol in ad hoc networks—as an example to verify the correctness and effectiveness of the new method. Copyright © 2017 John Wiley & Sons, Ltd.
Xuewen Dong, Chao Yang 0016, Lijie Sheng, Chao Wang 0085, Jianfeng Ma 0001
Secur. Commun. Networks1
2009 Towards Provably Secure On-demand Source Routing in MANET
abstract
Based on the simulation paradigm, Acs et al proposed a formal model tailored to the security analysis of on-demand source routing protocols in MANET, and a new routing protocol, called endairA, was proven secure in the model. We indicate the improper manipulations such as mergence of the adjacent adversarial nodes, the improper definition of secure route in the model, and the flaw in the proof for endairA. A new hidden channel attack to endairA is presented, which shows that endairA is not provably secure even in their model.
Liqiang Mao, Jianfeng Ma 0001, Xuewen Dong
IAS3