Yi Zhao 0011

dblp:51/4138-11 · DBLP profile ↗
← Back
51ranked-venue papers
18as first author
37since 2021 · last 2026
0000-0003-3632-3381ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 19 · 10 first-author · 11 since 2021Security and privacy · 19 · 4 first-author · 16 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 2 since 2021Systems, architecture and hardware · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Theory of computation · 1
YearPublicationVenuePosition
2026 AuEx: Automatic Exploration for Fresh Creative Ads via Large-Scale Deep Reinforcement Learning
Yi Zhao 0011, Qi Tan 0003, Liehuang Zhu
IWQoS1
2026 A Hard-Label Black-Box Evasion Attack against ML-based Malicious Traffic Detection Systems
Yi Zhao 0011, Zhuotao Liu, Qi Li 0002, Chuanpu Fu, Guangmeng Zhou, Ke Xu 0002
NDSS2
2026 Robust Fraud Transaction Detection: A Two-Player Game Approach
Qi Tan 0003, Yi Zhao 0011, Laizhong Cui, Qi Li 0002, Weiqiang Wang 0002, Ke Xu 0002
NDSS2
2026 Early-Stage Detection of Encrypted Malware Traffic via Multi-Flow Temporal Graph Learning
abstract
Malware widely adopts network traffic encryption techniques to conceal malicious activities. Recent research has demonstrated the effectiveness of machine learning (ML)-, deep learning (DL)-, and pre-training-based malware traffic detection methods. However, a vast majority of these methods rely on the collected complete traffic during the malware attack. While certain methods can operate on partial traffic, their detection accuracy often significantly decreases when the available data is restricted to the extreme early stage, where information is most sparse. In this paper, we proposeDawnGuard, an effective early-stage encrypted malware traffic detection framework through multi-flow temporal graph learning. Specifically, based on the temporal packet density distribution analysis,DawnGuardinnovatively proposes a self-adjusting data augmentation strategy for early-stage malware traffic, which can force the model to focus on the early-stage interaction phase with more distinguishable properties. Meanwhile, considering that temporal-topological correlations among multiple flows can provide more distinguishable properties in a malware attack, we further develop a temporal graph learning framework to extract features, which can formMulti-Flow Graph Features (MGF). By utilizingMGF,Dawn-Guardimplements a Vision Transformer-based detection mechanism, enabling accurate and precise encrypted malware traffic detection with early-stage traffic by capturing both local and global contextual relationships. Extensive experiments with two real-world datasets demonstrate thatDawnGuardoutperforms the state-of-the-art (SOTA) methods in three typical scenarios: varying early-stage time windows, imbalanced data, and unseen malware detection. Particularly,DawnGuardachieves an average F1 of 95.11%, 8.7% higher than the SOTA method, by only utilizing the first 20% loading ratio of complete traffic.
Jizhe Jia, Yi Zhao 0011, Meng Shen 0001, Susu Cui, Jing Wang 0150, Bufan Zhao 0001, Wei Wang 0012, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.2
2026 Byzantine-Robust Asynchronous Federated Learning via Feature Fingerprinting
abstract
Asynchronous federated learning (AFL) accelerates collaborative training across heterogeneous devices compared to synchronous federated learning, but increases vulnerability to Byzantine attacks due to its asynchronous aggregation. Existing defenses rely on parametric similarity between models and temporal consistency of updates, which are compromised by data and device heterogeneity, leading to ineffective robustness. To address this limitation, we propose Belisa, a Byzantine-robust AFL framework that enhances fidelity, robustness, and efficiency under heterogeneous scenarios. Belisa introduces novel discrepancies between feature representations of local models to distinguish malicious models from benign ones. By leveraging a reference model trained on publicly available data, Belisa quantifies these discrepancies, referred to as feature fingerprints, and filters out malicious models through clustering. Extensive experiments on six datasets from three types of tasks under five advanced Byzantine attacks demonstrate Belisa’s superiority. Notably, Belisa consistently outperforms existing approaches across both attack and non-attack settings. Under attack scenarios, it lowers the average test error rate to 0.42× that of baseline methods. Furthermore, Belisa accelerates the aggregation process by an average of 12.3× compared to other methods. To the best of our knowledge, Belisa is the first Byzantine-robust AFL framework, which provides a broadly applicable countermeasure in heterogeneous scenarios which are more prevalent in real-world settings.
Meng Shen 0001, Bohan Peng, Yi Zhao 0011, Ming Li 0049, Qi Li 0002, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2025 WisePIFinder: Efficient and Accurate Detection of Persistent and Infrequent Flows
abstract
In large-scale data stream analytics, accurate identification of Persistent and Infrequent (PI) flows is of great significance for monitoring and protecting against network attacks such as Advanced Persistent Threats (APT). However, existing research focuses mainly on detecting frequent flows or persistent flows, with insufficient studies on the characterization and detection methods for PI flows. Based on the analysis of sufficient APT flows, we propose a method that combines global and local features to effectively characterize PI flows. Further, we propose a novel sketch algorithm called WisePIFinder, which aims to detect PI flows more accurately and efficiently in realtime. The key idea is to continuously filter out non-PI flows while detecting flow persistence, to achieve accurate statistics on PI flows. Experimental results show that WisePIFinder improves the F1 Score by at least 20 % and insertion throughput by at least 60 % compared to the state-of-the-art solution for detecting PI flows. All related codes have been open-sourced on GitHub.
Zengxie Ma, Yao Xin, Zhuochen Fan, Tong Li 0014, Qing Liao 0001, Yi Zhao 0011, Feng Zhang 0007
IWQoS8
2025 Pegasus: A Universal Framework for Scalable Deep Learning Inference on the Dataplane
abstract
The paradigm of Intelligent DataPlane (IDP) embeds deep learning (DL) models on the network dataplane to enable intelligent traffic analysis at line-speed. However, the current use of the match-action table (MAT) abstraction on the dataplane is misaligned with DL inference, leading to several key limitations, including accuracy degradation, limited scale, and lack of generality. This paper proposes Pegasus to address these limitations. Pegasus translates DL operations into three dataplane-oriented primitives to achieve generality: Partition, Map, and SumReduce. Specifically, Partition "divides" high-dimensional features into multiple low-dimensional vectors, making them more suitable for the dataplane; Map "conquers" computations on the low-dimensional vectors in parallel with the technique of Fuzzy Matching, while SumReduce "combines" the computation results. Additionally, Pegasus employs Primitive Fusion to merge computations, improving scalability. Finally, Pegasus adopts full-precision weights with fixed-point activations to improve accuracy. Our implementation on a P4 switch demonstrates that Pegasus can effectively support various types of DL models, including Multi-Layer Perceptron (MLP), Recurrent Neural Network (RNN), Convolutional Neural Network (CNN), and AutoEncoder models on the dataplane. Meanwhile, Pegasus outperforms state-of-the-art approaches with an average accuracy improvement of up to 22.8%, along with up to 248× larger model size and 212× larger input scale.
Yinchao Zhang, Su Yao, Kang Chen 0001, Tong Li 0014, Zhuotao Liu, Yi Zhao 0011, Lexuan Zhang, Qi Li 0002, Ke Xu 0002
SIGCOMM7
2025 Identity-Based Asymmetric Group Message Franking
abstract
In recent years, with the increasing prevalence of online group chat applications, malicious information has been more easily disseminated on the internet. Asymmetric group message franking (AGMF) allows users to report received malicious messages to moderators, achieving content moderation in large-scale online end-to-end messaging systems. However, the state-of-the-art construction is built upon traditional public key cryptosystems, resulting in the complex certificate management problem. This paper systematically explores identity-based AGMF (IB-AGMF) to resolve this issue. Specifically, we first introduce a novel primitive called hash proof system-based anonymous identity-based key encapsulation mechanism supporting sigma protocol (HPS-AIB-KEMΣ) and present a practical construction based on DBDH assumption. After formalizing the concept and security notions of IB-AGMF, we propose the generic construction of IB-AGMF based on HPS-AIB-KEMΣand non-interactive zero knowledge proof system. Finally, we conduct comprehensive performance evaluations and comparisons to demonstrate the feasibility of IB-AGMF in group communication scenarios.
Hang Liu 0008, Yang Ming 0001, Aotian Cai, Chenhao Wang 0005, Yi Zhao 0011
TrustCom5
2025 Pisces: In-Path Distributed Denial-of-Service Defense via Efficient Authentication Code Embedded in IP Address
abstract
High-volume brute-force distributed denial-of-service (DDoS) attack is among the top threats on the Internet. Existing widely deployed methods (e.g., BGP blackhole and scrubbing center) have difficulty achieving legitimate traffic friendliness, low cost, low latency, and high accuracy. We present an in-path DDoS defense mechanism, namelyPisces. Without requiring modifications to existing IP protocols,Piscesembeds authentication information into the IP address. Simultaneously, we design a QUIC-based extension to distribute authentication information.Piscesincorporates a translator module and a filter module, which accurately identifies malicious and legitimate traffic. These multi-dimensional compatibility advantages make it easy to deploy in the real world. We implementPisceson a high-end commercial router with service processing units. Even without hardware acceleration, a single CPU can achieve$ 20\,\text{Gbps}$throughput and the performance can scale linearly with the number of CPUs. The additional latency for the victim-related traffic and other traffic is around$27\,\text{us}$and$0.5\,\text{us}$, respectively, whose cost is far less than the scrubbing center. Remarkably,Pisceswithout false positives can provide high-quality datasets for intelligent approaches and form a prominent complementary effect.
Yi Zhao 0011, Bingyang Liu, Weiyu Jiang, Ke Xu 0002, Qi Li 0002, Chuang Wang 0012, Zongxin Dou
IEEE Trans. Dependable Secur. Comput.1
2025 Security-Enhanced Data Transmission With Fine-Grained and Flexible Revocation for DTWNs
abstract
The diverse properties of wireless networks are fulfilled with the assistance of digital twin (DT), which utilizes a virtual model of the physical object (PO) to provide predictions and control decisions. However, the open wireless channels and key leakage of compromised entities (including DT and PO) pose significant security issues, highlighting the need for secure data transmission schemes. Meanwhile, it is impractical to directly apply the existing works and cryptographic primitives to DT-empowered wireless networks (DTWNs) due to the absence of a solution to capture the security requirements comprehensively. Moreover, the essential characteristics for protecting historical data cannot be met. Therefore, this paper proposes a security-enhanced data transmission scheme with fine-grained and flexible revocation by customizing a novel cryptographic primitive named forward-secure puncturable signed encryption (FS-PSE). Our scheme enables confidential data dissemination/acquisition between the physical and virtual space while ensuring authentication of the real-time information and feedback results. In addition, three revocation modes are defined. Based on these modes, the entities can flexibly revoke any decryption-&-signature, decryption, and signature capability in a fine-grained approach, thereby providing security protections for the historically transmitted data even though the entity is compromised. Moreover, our scheme is instantiated with a concrete FS-PSE construction and extended to support outsourced computing to improve efficiency. Finally, the formal security proof and performance evaluation demonstrate the security and practicality of our scheme.
Chenhao Wang 0005, Yang Ming 0001, Hang Liu 0008, Yutong Deng, Yi Zhao 0011, Songnian Zhang
IEEE Trans. Inf. Forensics Secur.5
2025 Expediting Federated Learning on Non-IID Data by Maximizing Communication Channel Utilization
abstract
Federated learning (FL) is at the core of intelligent Internet architecture. It allows clients to jointly train a model without direct data sharing. In such a process, clients and the central server share information through communication channels formed by parameters. However, the non-iid training data in clients significantly impacts global model convergence and brings difficulties for the evaluation of local contributions. Most of existing studies try to expand the communication channel by improving consistency with variance reduction or regularization, but such methods neglect an important factor, i.e., channel utilization, hence their capability for sharing information is under-utilized. Moreover, the issue of contribution evaluation is still unsolved. In this paper, we simultaneously solve the former two challenges (i.e., model convergence and contribution evaluation) by modeling the indirect data sharing of FL as a problem of information communication. We prove that FL with non-iid data forms noisy communication channels, which have limited capability for information transmission, i.e., limited channel capacity. The main factor in deciding the channel capacity is the Gradient Signal to Noise Ratio (GSNR). Through analyzing GSNR, we further prove that channel capacity can be reached by optimal local updates and propose a method FedGSNR to calculate it, which allows us to maximize channel utilization in FL, leading to faster model convergence. Moreover, as the contribution of the local dataset depends on the amount of provided information, the derived GSNR allows the server to accurately evaluate the contributions of different clients (i.e., the quality of local datasets).
Qi Tan 0003, Yi Zhao 0011, Qi Li 0002, Ke Xu 0002
IEEE Trans. Netw.2
2025 Resource Allocation and Deep Learning-Based Joint Detection Scheme in Satellite NOMA Systems
abstract
To overcome the challenges of complex time-varying satellite channels and severe inter-user interference in non-orthogonal multiple access (NOMA), rational power allocation and accurate multi-user joint detection methods are essential. In this paper, a sparrow search algorithm-based resource allocation and deep learning-based joint detection scheme (SSA-DeepJD) in the satellite-terrestrial NOMA system is proposed. First, the NOMA-orthogonal frequency division multiplexing (OFDM) system model is constructed. Next, a convolutional neural network-based image super-resolution recovery network is proposed for offline training and online channel estimation, which incorporates densely connected convolutional layers and residual learning to model for handling complex non-linear channel fitting. Then, a multi-user signal detection based on an iterative deep neural network is proposed, which is iteratively retrained to improve the detection accuracy. Finally, due to the significant impact of the power allocation on the system error performance, the optimal power allocation is found within the power allocation factor threshold based on SSA. Simulation results show that the proposed SSA-DeepJD algorithm is well-suited for multi-user superposed NOMA systems and complex non-linear channel environments. Compared to the baseline algorithms, the SSA-DeepJD algorithm degrades the Bit Error Rate (BER) by 21.5 dB and 11.9 dB in the 2-user and 3-user NOMA systems, respectively.
Qi Zhang 0043, Haipeng Yao, Yi Zhao 0011, Mohsen Guizani
IEEE Trans. Wirel. Commun.5
2024 Adversarial Robust Safeguard for Evading Deep Facial Manipulation
abstract
The non-consensual exploitation of facial manipulation has emerged as a pressing societal concern. In tandem with the identification of such fake content, recent research endeavors have advocated countering manipulation techniques through proactive interventions, specifically the incorporation of adversarial noise to impede the manipulation in advance. Nevertheless, with insufficient consideration of robustness, we show that current methods falter in providing protection after simple perturbations, e.g., blur. In addition, traditional optimization-based methods face limitations in scalability as they struggle to accommodate the substantial expansion of data volume, a consequence of the time-intensive iterative pipeline. To solve these challenges, we propose a learning-based model, Adversarial Robust Safeguard (ARS), to generate desirable protection noise in a single forward process, concurrently exhibiting a heightened resistance against prevalent perturbations. Specifically, our method involves a two-way protection design, characterized by a basic protection component responsible for generating efficacious noise features, coupled with robust protection for further enhancement. In robust protection, we first fuse image features with spatially duplicated noise embedding, thereby accounting for inherent information redundancy. Subsequently, a combination comprising a differentiable perturbation module and an adversarial network is devised to simulate potential information degradation during the training process. To evaluate it, we conduct experiments on four manipulation methods and compare recent works comprehensively. The results of our method exhibit good visual effects with pronounced robustness against varied perturbations at different levels.
Jiazhi Guan, Yi Zhao 0011, Zhuoer Xu, Changhua Meng, Ke Xu 0002, Youjian Zhao
AAAI2
2024 Rethinking and Optimizing Workload Redistribution in Large-scale Internet Data Centers
abstract
Heuristic-based workload redistribution is the most commonly adopted solution to provide enhanced service performance in large-scale Internet Data Centers (IDCs). However, statistics show that they cannot perform as well as expected in real-world IDCs. In this paper, we rethink existing solutions based on real-world trace data and pinpoint two major pitfalls: (i) Sensitive to hand-tuning parameters; (ii) Reassigning only a few workloads locally at a time. The two of them jointly limit the universal applicability of existing solutions in optimizing multiple objectives fairly. To address such issues, we propose the matching-theory-based solution for workload redistribution, namely Themis. It is an efficient and universal solution for large-scale IDCs, which can avoid empirical parameters in optimization and reassign several workloads globally each time. Moreover, the newly proposed Themis can optimize multiple objectives (e.g., resource utilization balancing and communication efficiency improving) simultaneously and fairly. In addition to its own performance advantages, our proposed Themis is also compatible with existing methods, thus adapting to a wider range of deployment scenarios. Extensive evaluations based on the trace data from two real-world IDCs demonstrate that our proposed Themis outperforms multiple comparison solutions, as well as the compatibility of parameter changes (i.e., stability properties in terms of parameter configuration).
Yi Zhao 0011, Yusen Li, Meng Shen 0001, Liehuang Zhu, Ke Xu 0002
IWQoS1
2024 Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory Approach
Qi Tan 0003, Qi Li 0002, Yi Zhao 0011, Zhuotao Liu, Xiaobing Guo, Ke Xu 0002
USENIX Security Symposium3
2024 Blockchain-assisted verifiable certificate-based searchable encryption against untrusted cloud server for Industrial Internet of Things
Hang Liu 0008, Yang Ming 0001, Chenhao Wang 0005, Yi Zhao 0011, Songnian Zhang, Rongxing Lu
Future Gener. Comput. Syst.4
2024 VCSA: Verifiable and collusion-resistant secure aggregation for federated learning using symmetric homomorphic encryption
Yang Ming 0001, Chenhao Wang 0005, Hang Liu 0008, Yutong Deng, Yi Zhao 0011, Jie Feng 0004
J. Syst. Archit.6
2024 Generic Construction: Cryptographic Reverse Firewalls for Public Key Encryption With Keyword Search in Cloud Storage
abstract
The Snowden incident illustrates that an adversary may launch an algorithm substitution attack (ASA) by tampering with the algorithms of protocol participants to obtain users' secret information. A measure against ASA is to equip the protocol participants with cryptographic reverse firewalls (CRF). Public key encryption with keyword search (PEKS) as a cryptographic primitive allows users to search encrypted file in cloud servers while ensuring the security of the original file. The existing CRF constructions for PEKS does not consider the trust level of CRFs, leaving honest-but-curious CRF to deal with trapdoors that should be sent in the secure channels, which brings new security risks. This paper firstly introduces the notion of malleable designated tester public key encryption with keyword search (M-DPEKS). Based on M-DPEKS, we propose the generic construction of public key encryption with keyword search with cryptographic reverse firewalls to overcome the privacy leakage issue in cloud storage. Security proof indicates the generic construction is secure against ASA. Lastly, we instantiate the generic construction with a concrete M-DPEKS scheme and analyze the computation cost and communication overhead to evaluate the efficiency.
Yang Ming 0001, Hang Liu 0008, Chenhao Wang 0005, Yi Zhao 0011
IEEE Trans. Cloud Comput.4
2024 Comments on "Enabling Verifiable Privacy-Preserving Multi-Type Data Aggregation in Smart Grids"
abstract
Most recently, Zhang et al presented a verifiable data aggregation scheme for smart grids in IEEE Transactions on Dependable and Secure Computing (doi: 10.1109/TDSC.2021.3124546). The authors claim that the privacy of the user's electricity data is preserved, and the control center can check whether the aggregator honestly computes the aggregated ciphertext. However, we indicate that Zhang et al's scheme fails to provide the properties of data privacy and aggregate correctness guarantee. Specifically, by offering concrete attacks, we illustrate that the adversary who has the ability to obtain the decryption key of control center can decrypt any user's ciphertext to get the detailed electricity data, and a misbehaved aggregator will not be detected when it does have some malicious behavior.
Hang Liu 0008, Yang Ming 0001, Chenhao Wang 0005, Yi Zhao 0011, Yabin Li
IEEE Trans. Dependable Secur. Comput.4
2024 Flexible Selective Data Sharing With Fine-Grained Erasure in VANETs
abstract
Vehicular ad hoc networks (VANETs), an increasingly significant technology in intelligent transportation systems, achieve information sharing, intelligent traffic flow control, and road condition prediction through data sharing between vehicles and other devices, enhancing traffic efficiency and driving safety. Nevertheless, there are still challenges to data sharing with respect to efficiency, flexibility, and security. In this paper, we build a flexible selective data sharing with fine-grained erasure (FSDS-FE) scheme in VANETs by introducing the novel cryptographic primitive called puncturable identity-based fine-grained proxy re-encryption and employing identity-based signature. In FSDS-FE, with the support for ciphertext transformation, the vehicles are able to flexibly share the outsourced traffic data with others. Different sharing content can be customized for various entities through fine-grained re-encryption to protect sensitive information. Furthermore, the outsourced traffic data could be erased in a fine-grained way by the vehicles. In order to optimize the efficiency and practicality of FSDS-FE, we construct an improved FSDS-FE scheme by designing a novel puncturable identity-based fine-grained broadcast proxy re-encryption with verifiable outsourced decryption scheme. Rigorous security analysis demonstrates that FSDS-FE can achieve the desired security requirements. The comprehensive performance evaluation shows that our schemes are efficient and practical enough in VANETs.
Hang Liu 0008, Yang Ming 0001, Chenhao Wang 0005, Yi Zhao 0011
IEEE Trans. Inf. Forensics Secur.4
2024 FedPAGE: Pruning Adaptively Toward Global Efficiency of Heterogeneous Federated Learning
abstract
When workers are heterogeneous in computing and transmission capabilities, the global efficiency of federated learning suffers from the straggler issue, i.e., the slowest worker drags down the overall training process. We propose a novel and efficient federated learning framework named FedPAGE, where workers perform distributed pruning adaptively towards global efficiency, i.e., fast training and high accuracy. For fast training, we develop a pruning rate learning approach generating an adaptive pruning rate for each worker, making the overall update time approximate to the fastest worker’s update time, i.e., no stragglers. For high accuracy, we find that structural similarity between sub-models is essential to global model accuracy in the distributed pruning, and thus propose the CIG_X pruning scheme to ensure maximum similarity. Meanwhile, we adopt the sparse training and design model aggregating of different size sub-models to cope with distributed pruning. We prove the convergence of FedPAGE and demonstrate the effectiveness of FedPAGE on image classification and natural language inference tasks. Compared with the state-of-the-art, FedPAGE achieves higher accuracy with the same speedup ratio.
Guangmeng Zhou, Qi Li 0002, Yang Liu 0038, Yi Zhao 0011, Qi Tan 0003, Su Yao, Ke Xu 0002
IEEE/ACM Trans. Netw.4
2024 Server-Assisted Data Sharing System Supporting Conjunctive Keyword Search for Vehicular Social Networks
abstract
Vehicular social networks (VSNs), as the convergence of social networks and vehicular ad hoc networks, have brought many useful services to vehicle communication by collecting and sharing data between vehicles. In order to efficiently share data and satisfy the growing requirement of privacy protection, data owners typically encrypt and outsource the data to the cloud. Nevertheless, encryption undoubtedly reduces the availability of shared data, e.g., keyword search. Although a number of schemes supporting keyword search of shared data have been put forward, they still have issues with respect to security, functionality, and efficiency. In this paper, a server-assisted data sharing (SADS) system with support for conjunctive keyword search is presented. Specifically, to resist online keyword guessing attack, we devise an advanced keyword derivation mechanism to derive the keyword set, in which the conception of verifiable parallel oblivious unpredictable function is proposed to check whether the assisted server honestly responds to the derived keyword request. Moreover, the computation and communication costs of keyword trapdoor in SADS are constant. Concurrently, SADS achieves the anonymous data sharing and traceability of malicious vehicle data owner. The security of SADS is formally proved and analyzed. Performance evaluation also shows that our system is efficient and practical.
Hang Liu 0008, Yang Ming 0001, Chenhao Wang 0005, Yi Zhao 0011, Songnian Zhang, Rongxing Lu
IEEE Trans. Serv. Comput.4
2023 Identity-Based Proxy Re-encryption Based on SM9
Hang Liu 0008, Yang Ming 0001, Chenhao Wang 0005, Yi Zhao 0011
Inscrypt (1)4
2023 Improving Adversarial Transferability with Ghost Samples
abstract
Adversarial transferability presents an intriguing phenomenon, where adversarial examples designed for one model can effectively deceive other models. By exploiting this property, various transfer-based methods are proposed to conduct adversarial attacks without knowledge of target models, posing significant threats to practical black-box applications. However, these methods either have limited transferability or require high resource consumption. To bridge the gap, we investigate adversarial transferability from the optimization perspective and propose the ghost sample attack (GSA). GSA improves adversarial transferability by alleviating the overfitting issue of adversarial examples on the surrogate model. Based on the insight that a slight shift of the adversarial example is similar to a minor change in the decision boundary, we aggregate gradients of perturbed adversarial copies (named ghost samples) to efficiently achieve a similar effect to calculating gradients of multiple ensemble surrogate models. Extensive experiments demonstrate that GSA achieves state-of-the-art adversarial transferability with restricted resources. On average, GSA improves the attack success rate by 4.8% on normally trained models compared to state-of-the-art attacks. Additionally, GSA reduces the computational cost by 62% compared with TAIG-R. When combined with other methods, GSA further improves transferability to 96.9% on normally trained models and 82.7% on robust models.
Yi Zhao 0011, Ningping Mou, Yunjie Ge, Qian Wang 0002
ECAI1
2023 Towards real-time ML-based DDoS detection via cost-efficient window-based feature extraction
Yi Zhao 0011, Wenbing Yao, Ke Xu 0002, Qi Li 0002
Sci. China Inf. Sci.2
2023 PressPIN: Enabling Secure PIN Authentication on Mobile Devices via Structure-Borne Sounds
abstract
PIN authentication is widely used on mobile devices due to its usability and simplicity. However, it is known to be susceptible to shoulder surfing attacks, where an adversary spies the user’s PIN by direct human observation or camera-based recording. This paper proposes PressPIN, a novel enhanced PIN authenticator on mobile devices by sensing pressures from the user’s finger. Since pressure-sensitive touch screens are unavailable on most phones, we leverage the structure-borne propagation of sounds to estimate the pressure on the screen. When the user inputs the PINs, the pressure is extracted from each number to form the$n$-bit pressure code, where$n$corresponds to the length of the PIN sequence. The pressure code is difficult to be inferred by snooping or videotaping, and increases the entropy of passwords. In this way, PressPIN provides a low-cost, user-friendly, and more secure solution resistant to shoulder surfing attacks. Our extensive experiments with 30 participants and three types of smartphones demonstrate that PressPIN can authenticate legitimate users with high accuracy (e.g., as high as 96.7% within two trials), and is robust to various types of attacks (e.g., only 2.5% attack success rate even when the adversary can observe the legitimate user’s PIN sequence and finger pressing clearly). Additionally, PressPIN requires no additional hardware (e.g., the pressure sensor) and can be readily integrated into existing authentication systems of mobile devices.
Man Zhou 0004, Qian Wang 0002, Xiu Lin, Yi Zhao 0011, Peipei Jiang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001
IEEE Trans. Dependable Secur. Comput.4
2023 FedDef: Defense Against Gradient Leakage in Federated Learning-Based Network Intrusion Detection Systems
abstract
Deep learning (DL) methods have been widely applied to anomaly-based network intrusion detection system (NIDS) to detect malicious traffic. To expand the usage scenarios of DL-based methods, federated learning (FL) allows multiple users to train a global model on the basis of respecting individual data privacy. However, it has not yet been systematically evaluated how robust FL-based NIDSs are against existing privacy attacks under existing defenses. To address this issue, we propose two privacy evaluation metrics designed for FL-based NIDSs, including (1) privacy score that evaluates the similarity between the original and recovered traffic features using reconstruction attacks, and (2) evasion rate against NIDSs using adversarial attack with the recovered traffic. We conduct experiments to illustrate that existing defenses provide little protection and the corresponding adversarial traffic can even evade the SOTA NIDS Kitsune. To defend against such attacks and build a more robust FL-based NIDS, we further propose FedDef, a novel optimization-based input perturbation defense strategy with theoretical guarantee. It achieves both high utility by minimizing the gradient distance and strong privacy protection by maximizing the input distance. We experimentally evaluate four existing defenses on four datasets and show that our defense outperforms all the baselines in terms of privacy protection with up to 7 times higher privacy score, while maintaining model accuracy loss within 3% under optimal parameter combination.
Jiahui Chen 0009, Yi Zhao 0011, Qi Li 0002, Xuewei Feng, Ke Xu 0002
IEEE Trans. Inf. Forensics Secur.2
2023 Where Are the Dots: Hardening Face Authentication on Smartphones With Unforgeable Eye Movement Patterns
abstract
With the ubiquitous adoption, mobile face authentication systems have been facing constant security challenges, particularly the spoofing risks. Except for those using specialized hardware, existing proposals for face anti-spoofing on mainstream smartphones either leverage people’s 3D face characteristics or various facial expressions. While showing progress towards more resilient face authentication, they are still vulnerable to recent advanced attacks (e.g., 3D mask attacks, video attacks, etc.). This paper presents GazeGuard, an on-device face anti-spoofing system that leverages unpredictable and unforgeable eye movement patterns to provide strong security guarantees against all known attacks. Targeting mainstream smartphones, GazeGuard is designed to conduct eye movement-based authentication using only 2D front cameras. Specifically, by presenting a series of short-lasting random dots on the screen (named gazecode), GazeGuard simultaneously captures a user’s gaze responses and the corresponding deformed periocular features to ensure both the freshness and correctness for the anti-spoofing face authentication. We have extensively tested GazeGuard’s performance over 50 volunteers. Using a 4-digit gazecode (just four random dots), GazeGuard achieves an average 90.39% authentication accuracy and 81.57 out of 100 System Usability Scale (SUS) scores. Under the same settings, GazeGuard achieves detection accuracy of 95.72% for image attack, 95.59% for video attack, 99.73% for 3D mask attack, and 100% for physical adversarial attack.
Qian Wang 0002, Cong Wang 0001, Man Zhou 0004, Yi Zhao 0011, Qi Li 0002, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2023 Friendship Inference in Mobile Social Networks: Exploiting Multi-Source Information With Two-Stage Deep Learning Framework
abstract
With the tremendous growth of mobile social networks (MSNs), people are highly relying on it to connect with friends and further expand their social circles. However, the conventional friendship inference techniques have issues handling such a large yet sparse multi-source data. The related friend recommendation systems are therefore suffering from reduced accuracy and limited scalability. To address this issue, we propose a Two-stage Deep learning framework for Friendship Inference, namely TDFI. This approach enables MSNs to exploit multi-source information simultaneously, rather than hierarchically. Therefore, there is no need to manually set which information is more important and the order in which the various information is applied. In details, we apply an Extended Adjacency Matrix (EAM) to represent the multi-source information. We then adopt an improved Deep Auto-Encoder Network (iDAEN) to extract the fused feature vector for each user. Our framework also provides an improved Deep Siamese Network (iDSN) to measure user similarity. To provide a substantial description and evaluation of the proposed methodology, we evaluate the effectiveness and robustness on three large-scale real-world datasets. Trace-driven evaluation results demonstrate that TDFI can effectively handle the sparse multi-source data while providing better accuracy for friendship inference. Through the comparison with numerous state-of-the-art methods, we find that TDFI can achieve superior performance via real-world multi-source information. Meanwhile, it demonstrates that the proposed pipeline can not only integrate structural information and attribute information, but also be compatible with different attribute information, which further enhances the overall applicability of friend-recommendation systems under information-rich MSNs.
Yi Zhao 0011, Meina Qiao, Rui Zhang 0017, Dan Wang 0002, Ke Xu 0002
IEEE/ACM Trans. Netw.1
2022 Congestion-Aware Modeling and Analysis of Sponsored Data Plan from End User Perspective
abstract
The past decade has witnessed the rapid expansion of demands for mobile traffic, while the traditional mobile traffic pricing schemes cannot accommodate such demands. Sponsored data plan (SDP), which can increase the revenue of all stakeholders in the market through transferring some of the revenue from content providers (CPs) to end users (EUs), is more suitable. However, existing studies have focused more on Internet service providers (ISPs) and CPs, ignoring the influence of EUs (e.g., the inherent attribute differences of EUs and the interaction among EUs) on the market under SDP. Regarding the difficulty of modeling the abstract property about interaction among EUs, we utilize network congestion as the medium and construct the congestion-aware SDP model based on Stackelberg game. The newly proposed model can not only analyze how network congestion affects SDP mechanism, but also elucidate the impact of interactions among EUs. More specifically, through theoretical analysis, we prove that there is a unique dynamic equilibrium in the interaction among EUs (i.e., the traffic consumption of different EUs). By taking into account network congestion, the newly proposed model also more accurately and realistically describes the optimal strategies and computation methods of all stakeholders in the market. Moreover, simulation experiments demonstrate that the positive effect brought by SDP is not as obvious as before, and EUs influence each other instead of being independent of each other. Overall, this paper emphasizes the non-negligible influence of EUs and promotes a deeper understanding of SDP mechanism, which can guide the relevant stakeholders to optimize their own decision-making details.
Yi Zhao 0011, Qi Tan 0003, Xiaohua Xu 0002, Hui Su, Dan Wang 0002, Ke Xu 0002
IWQoS1
2022 Intelligent networking in adversarial environment: challenges and opportunities
Yi Zhao 0011, Ke Xu 0002, Qi Li 0002, Dan Wang 0002
Sci. China Inf. Sci.1
2022 Practical algorithm substitution attack on extractable signatures
Yi Zhao 0011, Kaitai Liang, Yanqi Zhao, Bo Yang 0003, Yang Ming 0001, Emmanouil A. Panaousis
Des. Codes Cryptogr.1
2022 Blockchain-Enabled Efficient Dynamic Cross-Domain Deduplication in Edge Computing
abstract
As the rapid proliferation of Internet of Things (IoT) and edge computing, large amounts of data are needed to be stored and transmitted in the online storage system. Data deduplication can be adopted to improve communication efficiency and minimize storage space. However, in edge computing, data deduplication brings security and functionality requirements that are still unsatisfied. Most existing schemes are vulnerable to brute-force attacks and single-point attacks. Moreover, they impose a heavy burden on resource-constrained edge nodes and do not support cross-domain deduplication. Blockchain is a promising technology because the programmable smart contract can be utilized to perform cross-domain deduplication and guarantee the traceability of data. In this article, an efficient dynamic cross-domain deduplication scheme in blockchain-enabled edge computing is proposed to solve the above problems. Specifically, the smart contract is employed to assist cross-domain deduplication, which also can reduce the storage pressure of edge nodes. Meanwhile, a hash proof system-based oblivious pseudorandom function is created to reduce the time cost of key generation and achieve the security requirements of resistance to brute-force attacks and single-point attacks. The technology of accumulators is adopted to achieve Proofs of Ownership (PoO), which can prevent duplicate-faking attacks. The security analysis demonstrates that the proposed scheme has a higher security level. The performance evaluation shows that the proposed scheme significantly reduces computation cost and communication overhead, compared with other existing schemes. The smart contract is implemented in the Ethereum test network (i.e., Rinkeby), which shows acceptable gas cost even the functions are called frequently.
Yang Ming 0001, Chenhao Wang 0005, Hang Liu 0008, Yi Zhao 0011, Jie Feng 0004, Ning Zhang 0007, Weisong Shi
IEEE Internet Things J.4
2022 Efficient Privacy-Preserving Data Aggregation Scheme with Fault Tolerance in Smart Grid
abstract
As the traditional grid produces a large amount of greenhouse gas and cannot adapt to such new demands as dynamic electricity prices, data analysis, and early warning, smart grid with high efficiency and reliability is increasingly valued. It plays a key role in achieving carbon neutrality. Nonetheless, smart grid requires the collection of real-time power data, and personal privacy may be leaked through the frequent electricity measurement reports. With the requirements of data analysis and prediction while preserving users’ personal privacy, data aggregation schemes have emerged. However, existing schemes cannot resolve all the troubles well. Some schemes do not consider the failures for smart meters, and most of the schemes have expensive computation cost. In view of this, an efficient privacy-preserving data aggregation scheme with fault tolerance in smart grid is put forward in this paper. To be specific, the proposed scheme is lightweight due to the application of the symmetric homomorphic encryption technology and the elliptic curve cryptography. Even if some smart meters are destroyed, the proposed scheme can still successfully obtain aggregated data. Moreover, the proposed data aggregation scheme is proved to be secure, and all security requirements can be satisfied. Performance evaluation illustrates the relatively low computation cost and communication overhead of the proposed scheme compared to other related schemes.
Yang Ming 0001, Yabin Li, Yi Zhao 0011
Secur. Commun. Networks3
2021 FedPrune: Personalized and Communication-Efficient Federated Learning on Non-IID Data
Yang Liu 0038, Yi Zhao 0011, Guangmeng Zhou, Ke Xu 0002
ICONIP (5)2
2021 MEC-Enabled Hierarchical Emotion Recognition and Perturbation-Aware Defense in Smart Cities
abstract
With the explosive growth of Internet of Things (IoT) devices and various emerging network technologies, IoT-enabled smart cities are further refined into health smart cities. For example, IoT devices can automatically recognize emotional states through collected facial expressions, which can further serve mental health assessment, human–computer interaction, etc. On the other hand, existing facial expression recognition algorithms emphasize the application of deep neural networks (DNNs), and it is difficult for resource-constrained IoT devices to provide sufficient computing resources to optimize parameters for DNN-based structures. To solve the challenge of resource constraints, we propose the hierarchical emotion recognition system enabled by mobile edge computing (MEC). Specifically, MEC nodes provide IoT devices with short-delay and high-performance computing services, satisfying the requirements of training DNN-based algorithms. Moreover, our proposed emotion recognition system leverages a pretrained feature extraction module on the remote cloud to accelerate optimization and provides a localization module for specific tasks of IoT devices. In addition to evaluating the accuracy and efficiency, we also clarify that the DNN-based emotion recognition system exposes obvious vulnerability to perturbation. Due to the uncertainty of the environment, it is common for facial expressions collected by IoT devices to be accompanied by perturbation. To address this issue, we propose the proactive perturbation-aware defense mechanism. It has been demonstrated that the newly proposed defense mechanism can maintain state-of-the-art performance on the publicly available LIRIS-CSE dataset while defending against known and unknown perturbation. This can promote the deployment of our proposed MEC-enabled hierarchical emotion recognition system and defense mechanism in real-world scenarios.
Yi Zhao 0011, Ke Xu 0002, Bo Li 0026, Meina Qiao, Haobin Shi
IEEE Internet Things J.1
2021 Data Clustering via Uncorrelated Ridge Regression
abstract
Ridge regression is frequently utilized by both supervised and semisupervised learnings. However, the trivial solution might occur, when ridge regression is directly applied for clustering. To address this issue, an uncorrelated constraint is introduced to the ridge regression with embedding the manifold structure. In particular, we choose uncorrelated constraint over orthogonal constraint, since the closed-form solution can be obtained correspondingly. In addition to the proposed uncorrelated ridge regression, a soft pseudo label is utilized with ℓ1ball constraint for clustering. Moreover, a brand new strategy, i.e., a rescaled technique, is proposed such that optimal scaling within the uncorrelated constraint can be achieved automatically to avoid the inconvenience of tuning it manually. Equipped with the rescaled uncorrelated ridge regression with the soft label, a novel clustering method can be developed based on solving the related clustering model. Consequently, extensive experiments are provided to illustrate the effectiveness of the proposed method.
Rui Zhang 0017, Xuelong Li 0001, Tong Wu 0006, Yi Zhao 0011
IEEE Trans. Neural Networks Learn. Syst.4
2020 Auction-based High Timeliness Data Pricing under Mobile and Wireless Networks
abstract
Data is the cornerstone of intelligent algorithms such as deep learning, and the explosive development of mobile and wireless networks has prompted more devices to share data in time via the Internet. Meanwhile, data is highly time sensitive. It has been found that the value of data is becoming more and more critical to any application areas, significantly highlighting the importance of data pricing mechanisms in data transactions. Although traditional auction mechanisms for ordinary commodities are gradually becoming matures, they fail in the high timeliness data pricing market due to the following key challenges: Firstly, the value and price of the high timeliness data is ever changing with time, making existing mechanisms with fixed prices expired. Secondly, the price changing of such data is uncertain and dynamic, requiring the auction mechanisms to work stably under different price variations of the high timeliness data. To address these challenges, we for the first time innovatively propose an efficient auction mechanism for High Timeliness Data Pricing, namely HTDP. The newly proposed HTDP can maximize the profit of auctioneer in the high timeliness data transactions. And the key factor for HTDP's success is the consideration of the price changing in the high timeliness data, which fills the blank of traditional auction mechanisms in this area. We further evaluate the newly proposed HTDP on the overall auction profit, and compare the results with the benchmark. Experimental results demonstrate that HTDP not only achieves high profit under proper settings, but also is stable and efficient.
Yi Zhao 0011, Ke Xu 0002, Yuchao Zhang 0004
ICC1
2020 Analysis, Modeling, and Implementation of Publisher-side Ad Request Filtering
abstract
Online advertising has been a great driving force for the Internet industry. To maintain a steady growth of advertising revenue, advertisement (ad) publishers have made great efforts to increase the impressions as well as the conversion rate. However, we notice that the results of these efforts are not as good as expected. In detail, to show more ads to the consumers, publishers have to waste a significant amount of server resources to process the ad requests that do not result in consumers' clicks. On the other hand, the increasing ads are also impacting the browsing experience of the consumers. In this paper, we explore the opportunity to improve publishers' overall utility by handling a selective number of requests on ad servers. Particularly, we propose a publisher-side proactive ad request filtration solution Win2. Upon receiving an ad request, Win2 estimates the probability that the consumer will click if serving it. The ad request will be served if the clicking probability is above a dynamic threshold. Otherwise, it will be filtered to reduce the publisher's resource cost and improve consumer experience. We implement Win2 in a large-scale ad serving system and the evaluation results confirm its effectiveness.
Ke Xu 0002, Meng Shen 0001, Yi Zhao 0011, Guanhui Geng
INFOCOM5
2020 I Know If the Journey Changes: Flexible Source and Path Validation
abstract
No matter from the perspective of detection or defense, source and path validations are fundamentally primitive in constructing security mechanisms to greatly enhance network immunity in the face of malicious attacks, such as injection, traffic hijacking and hidden threats. However, existing works for source and path verification still impose a non-trivial operational overhead and lack adjustment capability for path dynamic changes. In this paper, we propose a flexible and convenient source and path validation protocol called PSVM, which uses an authentication structure PIC composed of ordered pieces to carry out packet verification. Specifically, in the basic PSVM protocol, PIC (related to cryptographic computation) in the packet header does not require any update during packet verification, which thus enables a lower processing overhead in routers. To cope with the challenge of path policy changes in the running protocol, the dynamic PSVM protocol supports controllable adjustment and migration, especially in the case of avoiding a malicious node or region. Our evaluation of a prototype experiment on Click demonstrates that the verification efficiency of PSVM is barely influenced by payload size or path length. Compared to the baseline of normal IP routing, the throughput reduction ratio of the basic PSVM is about 13%, which is much better than 28% of existing best solution Origin and Path Trace (OPT). In addition, for a 35-hop path with 30 pieces of PIC needed to be adjusted in dynamic PSVM, the throughput reduction ratio of routing cross node performing the adjustment operation after normal verification is only 2.4 %.
Ke Xu 0002, Qi Li 0002, Rongxing Lu, Bo Wu 0002, Yi Zhao 0011, Meng Shen 0001
IWQoS7
2020 Incentive mechanisms for mobile data offloading through operator-owned WiFi access points
Yi Zhao 0011, Ke Xu 0002, Yifeng Zhong, Xiang-Yang Li 0001, Ning Wang 0001, Hui Su, Meng Shen 0001
Comput. Networks1
2020 Privacy preserving search services against online attack
Yi Zhao 0011, Jianting Ning, Kaitai Liang, Yanqi Zhao, Liqun Chen 0002, Bo Yang 0003
Comput. Secur.1
2020 A generic construction of CCA-secure deterministic encryption
Meijuan Huang, Bo Yang 0003, Yi Zhao 0011, Xin Wang 0058, Yanwei Zhou, Zhe Xia
Inf. Process. Lett.3
2020 Understand Love of Variety in Wireless Data Market Under Sponsored Data Plans
abstract
Sponsored Data Plan (SDP) is an emerging pricing model for the wireless data market where the Content Provider (CP) can sponsor the data usage for specific content on behalf of the users. This strategy sheds new light on the data pricing model and receives significant attention from the Internet Service Provider (ISP). However, the existing SDP studies consider traffic price (e.g., sponsorship) as the only factor that affects user decision. The impact of other classic market features, such as the demand for a variety of contents (i.e., love of variety), remains largely unclear. In this paper, we develop a new model to understand the love of variety in the wireless data market under SDPs. Our model has demonstrated that, such variety is important to understand the complex gaming between ISPs, CPs, and users in both short-run and long-run markets. For example, the analysis indicates that the advantage of CPs with higher revenue will be significantly reduced when users have a greater love of variety. Moreover, to help the ISP better adopt the proposed model in the real market, we also develop a practical method to calibrate the related parameters, which can also be applied to quantity the love of variety.
Yi Zhao 0011, Hui Su, Liang Zhang 0042, Rui Zhang 0017, Dan Wang 0002, Ke Xu 0002
IEEE J. Sel. Areas Commun.1
2020 Deep Learning-Based Gait Recognition Using Smartphones in the Wild
abstract
Compared to other biometrics, gait is difficult to conceal and has the advantage of being unobtrusive. Inertial sensors, such as accelerometers and gyroscopes, are often used to capture gait dynamics. These inertial sensors are commonly integrated into smartphones and are widely used by the average person, which makes gait data convenient and inexpensive to collect. In this paper, we study gait recognition using smartphones in the wild. In contrast to traditional methods, which often require a person to walk along a specified road and/or at a normal walking speed, the proposed method collects inertial gait data under unconstrained conditions without knowing when, where, and how the user walks. To obtain good person identification and authentication performance, deep-learning techniques are presented to learn and model the gait biometrics based on walking data. Specifically, a hybrid deep neural network is proposed for robust gait feature representation, where features in the space and time domains are successively abstracted by a convolutional neural network and a recurrent neural network. In the experiments, two datasets collected by smartphones for a total of 118 subjects are used for evaluations. The experiments show that the proposed method achieves higher than 93.5% and 93.7% accuracies in person identification and authentication, respectively.
Qin Zou 0001, Qian Wang 0002, Yi Zhao 0011, Qingquan Li 0001
IEEE Trans. Inf. Forensics Secur.4
2019 TDFI: Two-stage Deep Learning Framework for Friendship Inference via Multi-source Information
abstract
Due to the explosive growth of social network services, friendship inference has been widely adopted by Online Social Service Providers (OSSPs) for friend recommendation. The conventional techniques, however, have limitations in accuracy or scalability to handle such a large yet sparse multi-source data. For example, the OSSPs will be required to manually give the order in which the various information is applied. This unavoidably reduces the applicability of existing friend recommendation systems. To address this issue, we propose a Two-stage Deep learning framework for Friendship Inference (TDFI). This approach can utilize multi-source information simultaneously with low complexity. In particular, we apply an Extended Adjacency Matrix (EAM) to represent the multi-source information. We then adopt an improved Deep AutoEncoder Network (iDAEN) to extract the fused feature vector for each user. The TDFI framework also provides an improved Deep Siamese Network (iDSN) to measure user similarity from iDAEN. Finally, we evaluate the effectiveness and robustness of TDFI on three large-scale real-world datasets. It shows that TDFI can effectively handle the sparse multi-source data while providing better accuracy for friend recommendation.
Yi Zhao 0011, Meina Qiao, Rui Zhang 0017, Dan Wang 0002, Ke Xu 0002, Qi Tan 0003
INFOCOM1
2019 Variety matters: a new model for the wireless data market under sponsored data plans
abstract
In this paper, we develop a new model to study the competition among Content Providers (CPs) under Sponsored Data Plans (SDPs). SDP is an emerging pricing model for the wireless data market where Internet Service Providers (ISPs) allow a CP to compensate the traffic volume of users when users access the contents of this CP. Studies have shown that SDPs create a triple-win situation, where users consume more contents and the revenue of both CPs and ISPs increases. Currently, a main concern of SDPs is on whether SDPs may bring about unfair competition among CPs. Studies have shown that big CPs have an advantage over small CPs. We observe that such conclusions are derived because in all previous models, traffic price is the only factor that affects user decisions. We argue that it is not precise. Nowadays, people conduct a large variety of activities online, and users have an intrinsic demand for a variety of contents. To reflect this, we for the first time characterize the variety demand as an intrinsic parameter of users, and integrate such variety into a new model to help us drive some novel insights into SDPs, especially the competition among CPs. Our model shows that variety matters for understanding SDPs more thoroughly and comprehensively. For example, under SDPs, the advantage of CPs with higher revenue will be significantly reduced if users have a greater love for variety. Overall, our new model leads to a set of completely new results and rectifies some past conclusions.
Yi Zhao 0011, Hui Su, Liang Zhang 0042, Dan Wang 0002, Ke Xu 0002
IWQoS1
2019 Leakage Resilient CCA Security in Stronger Model: Branch Hidden ABO-LTFs and Their Applications
abstract
Lossy trapdoor functions (LTFs) have already found various applications in cryptography with many priorities. But constructing leakage resilient (LR) CCA secure PKE schemes through this way received less attention. Existing works could only be proven secure in a weakened model due to the power of leakage attack. To address this problem, we introduce a new variant of ABO-LTF which is called branch hidden ABO-LTF (BHABO-LTF) in this paper. This primitive provides protection for the information of evaluated branches rather than lossy branches, which means even an adversary knows the information of the set of lossy branches, it can still not determine whether the output is evaluated on an injective or a lossy branch as long as the inversion key is kept secret. We observe that if this primitive has Chameleon property, we could present a generic construction of CCA secure PKE schemes. Due to the transparency of lossy branches of the primitive, we find that our construction can naturally be extended to accommodate leakage resilience. We give a generic construction with a realization of LR-BHABO-LTFs under the decisional composite residuosity assumption. This construction can be proved secure in a well-accepted security model rather than existing LTF-based ones in weak key-leakage model. Besides, without the need to hide the information of lossy branches, a Chameleon BHABO-LTF can be constructed by additively homomorphic CPA secure PKE alone. So our work can also be viewed as an interesting progress to give a construction of CCA secure PKE from additively homomorphic CPA secure PKE with certain properties as well as their LR counterparts, which has been a longstanding problem.
Yi Zhao 0011, Yong Yu 0002, Bo Yang 0003
Comput. J.1
2019 LRCoin: Leakage-Resilient Cryptocurrency Based on Bitcoin for Data Trading in IoT
abstract
Currently, the number of Internet of Things (IoT) devices making up the IoT is more than 11 billion and this number has been continuously increasing. The prevalence of these devices leads to an emerging IoT business model called Device-as-a-service, which enables sensor devices to collect data disseminated to all interested devices. The devices sharing data with other devices could receive some financial reward, such as Bitcoin. However, side-channel attacks, which aim to exploit some information leaked from the IoT devices during data trade execution, are possible since most of the IoT devices are vulnerable to be hacked or compromised. Thus, it is challenging to securely realize data trading in IoT environment due to the information leakage, such as leaking the private key for signing a Bitcoin transaction in Bitcoin system. In this paper, we propose LRCoin, a kind of leakage-resilient cryptocurrency based on bitcoin in which the signature algorithm used for authenticating bitcoin transactions is leakage-resilient. LRCoin is suitable for the scenarios where information leakage is inevitable, such as IoT applications. Our core contribution is proposing an efficient bilinear-based continual-leakage-resilient ECDSA signature. We prove the proposed signature algorithm is unforgeable against adaptively chosen messages attack in the generic bilinear group model under the continual leakage setting. Both the theoretical analysis and the implementation demonstrate the practicability of the proposed scheme.
Yong Yu 0002, Yujie Ding, Yanqi Zhao, Yannan Li 0001, Yi Zhao 0011, Xiaojiang Du, Mohsen Guizani
IEEE Internet Things J.5
2019 CCA Secure Public Key Encryption against After-the-Fact Leakage without NIZK Proofs
abstract
In leakage resilient cryptography, there is a seemingly inherent restraint on the ability of the adversary that it cannot get access to the leakage oracle after the challenge. Recently, a series of works made a breakthrough to consider a postchallenge leakage. They presented achievable public key encryption (PKE) schemes which are semantically secure against after-the-fact leakage in the split-state model. This model puts a more acceptable constraint on adversary’s ability that the adversary cannot query the leakage of secret states as a whole but the functions of several parts separately instead of prechallenge query only. To obtain security against chosen ciphertext attack (CCA) for PKE schemes against after-the-fact leakage attack (AFL), existing works followed the paradigm of “double encryption” which needs noninteractive zero knowledge (NIZK) proofs in the encryption algorithm. We present an alternative way to achieve AFL-CCA security via lossy trapdoor functions (LTFs) without NIZK proofs. First, we formalize the definition of LTFs secure against AFL (AFLR-LTFs) and all-but-one variants (ABO). Then, we show how to realize this primitive in the split-state model. This primitive can be used to construct AFLR-CCA secure PKE scheme in the same way as the method of “CCA from LTFs” in traditional sense.
Yi Zhao 0011, Kaitai Liang, Bo Yang 0003, Liqun Chen 0002
Secur. Commun. Networks1
2017 Direct constructions and proofs for CCA secure (LR)IBE with dual system encryption
Yi Zhao 0011, Bo Yang 0003
Sci. China Inf. Sci.1