Kun He 0008

dblp:59/1028-8 · DBLP profile ↗
← Back
93ranked-venue papers
5as first author
77since 2021 · last 2026
0000-0003-3472-419XORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 50 · 2 first-author · 45 since 2021Computer networks · 26 · 1 first-author · 20 since 2021Systems, architecture and hardware · 7 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Less is More: Persistent Low-Frequency Backdoor Injection in Federated Learning
abstract
Federated learning (FL) enables multiple clients to collaboratively train a machine learning model without sharing their local data. However, the distributed nature of FL makes it vulnerable to backdoor attacks from malicious clients. Most existing attack methods often assume that attackers can inject backdoors in every training round - a scenario that is both unrealistic and inefficient in real-world FL deployment. In this paper, we investigate why backdoor attacks become less effective under low-frequency injection and propose a novel attack paradigm for FL, called REinforced Memorization-based INterval backDoor attack (REMIND). REMIND optimizes the backdoor trigger via task alignment and feature alignment. Task alignment aligns backdoor and main task objectives to resist benign update suppression during non-attack rounds, while feature alignment guides poisoned samples to match the activation trajectory of target-class samples. This dual alignment enhances the backdoor's persistence and narrows the divergence between malicious and benign updates. With strong attack success rates established, we further analyze the advantages of low-frequency backdoor attacks, particularly their ability to improve robustness against defense mechanisms. Extensive evaluations on four benchmark datasets show that REMIND consistently outperforms eight state-of-the-art attack baselines under nine defense strategies.
Pei Ye, Yuqing Li 0001, Kun He 0008, Ruiying Du, Wei Wang 0030
INFOCOM3
2026 Formal Analysis of BLE Secure Connection Pairing and Revelation of the PE Confusion Attack
Yongkang Xiao, Jing Chen 0003, Kun He 0008, Ruiying Du
NDSS4
2026 CANDICE: An explainable and intelligent framework for network intrusion detection
Ruiying Du, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Yebo Feng
Future Gener. Comput. Syst.4
2026 CLAD: Robust audio deepfake detection against manipulation attacks with contrastive learning
Haolin Wu 0001, Jing Chen 0003, Ruiying Du, Cong Wu 0003, Kun He 0008, Xingcan Shang, Hao Ren 0001, Guowen Xu
Knowl. Based Syst.5
2026 Fully Private Shortest Path Computation With Single-Round Interaction
abstract
In real-world scenarios, computing the shortest path between given source and destination is widely prevalent, such as seeking the optimal route in a road network for navigation. However, in traditional non-private solutions, the user discloses its location information to the server in order to obtain the targeted shortest path, giving rise to a significant privacy leakage problem. Existing private shortest path computation schemes either provide limited privacy guarantees or require multiple interactions between the user and the server. In this paper, we introduce a fully private shortest path computation scheme, named Srchpa. This scheme ensures full privacy for both the location information provided by the user and the routing information held by the server. Furthermore, we propose a locally iterative computation method, achieving single-round interaction between the user and the server to obtain the targeted shortest path. Finally, we present the formal security analyses and comprehensive experiment evaluations. The security analyses demonstrate that our scheme achieves full privacy even if the server is malicious. The experiment evaluation results show that our scheme has lower computation, communication and storage costs on the user side, thus is practical for the lightweight user with limited resources.
Jing Chen 0003, Ruifeng Zhu, Kun He 0008, Chenbin Zhao, Ruiying Du
IEEE Trans. Dependable Secur. Comput.3
2026 Privacy-Preserving and Aggregated Proofs of Assets in Multiple Banks
abstract
Proof of reserves/assets is widely used for visa application, loan, and auction in practice, where provers display balance proofs generated by banks to verifiers to prove their balances. In real world, a prover usually deposits money in multiple banks and needs to prove her/his total balances in those banks. Based on existing technologies, a prover can either request those banks to interactively generate an aggregated proofs of assets or prove her/his balances one by one, and they are inefficient and have a low privacy protection effect. In this paper, we present privacy-preserving and aggregated proofs of assets in multiple banks. Specifically, we design a liability auditing and balance proving architecture that supports proofs of liabilities for banks and proofs of assets for provers. Then, we propose a generic construction of aggregated proofs of assets scheme, where provers can aggregate balances in multiple banks without the help of any bank and banks do not need to interact with each other. Moreover, the provers can prove the aggregated balance is more than a threshold without exposing the specific values or the bank information. We conduct experiments on our system and the results demonstrate that it is suitable in practice.
Jing Chen 0003, Kun He 0008, Erjun Zhou, Jielun Zeng, Ruiying Du
IEEE Trans. Dependable Secur. Comput.3
2026 MsgFilter: Proactive Anti-Harassment Sender-Anonymous Messaging System
abstract
Anonymous submissions inspire people to speak up since hiding their identities can protect them from negative influence by their own words. However, the abuse of anonymity may bring harassment to those public submission callers. Existing works only handle DoS attacks or block harassment senders in an active manner, which behave poorly in the early prevention of uncharacterized harassment. In this paper, we propose MsgFliter, a sender-anonymous messaging system with proactive anti-harassment mechanism. Our core idea is to prevent unanswered senders from sending messages continually while keeping their identities, messages, and sender types secret. To meet the functionality and security requirements of MsgFliter, we propose the Anti-Harassment Anonymous Authentication (AHAA) protocol. We associate messages from the same sender through linkable tags and invalidate linkability when a message is replied to. To achieve session indistinguishability, we further combine the proposed anonymous authentication with zero-knowledge proofs of disjunctive relations. We implement MsgFliter and compare its performance with related solutions. Experimental results show that our solution is practicable.
Siqin Li, Kun He 0008, Ruiying Du, Jing Chen 0003
IEEE Trans. Inf. Forensics Secur.2
2026 N Truths and a Lie: Consistency-Based Backdoor Defense for Vertical Federated Learning
Zijun Zhang 0003, Kun He 0008, Jing Chen 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.3
2026 MagLive: Robust Voice Liveness Detection on Smartphones Using Magnetic Pattern Changes
abstract
Voice authentication has been widely used on smartphones. However, it remains vulnerable to spoofing attacks, where the attacker replays recorded voice samples from authentic humans using loudspeakers to bypass the voice authentication system. In this paper, we present MagLive, a robust voice liveness detection scheme designed for smartphones to mitigate such spoofing attacks. MagLive leverages the differences in magnetic pattern changes generated by different speakers (i.e., humans or loudspeakers) when speaking for liveness detection, which are captured by the built-in magnetometer on smartphones. To extract effective and robust magnetic features, MagLive utilizes a TF-CNN-SAF model as the feature extractor, which includes a time-frequency convolutional neural network (TF-CNN) combined with a self-attention-based fusion (SAF) model. Supervised contrastive learning is then employed to achieve user-irrelevance, device-irrelevance, and content-irrelevance. MagLive imposes no additional burden on users and does not rely on active sensing or specialized hardware. We conducted comprehensive experiments with various settings to evaluate the security and robustness of MagLive. Our results demonstrate that MagLive effectively distinguishes between humans and attackers (i.e., loudspeakers), achieving an average balanced accuracy (BAC) of 99.01% and an equal error rate (EER) of 0.77%.
Xiping Sun, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Haozhe Xu, Yebo Feng, Ruiying Du, Xianhao Chen
IEEE Trans. Inf. Forensics Secur.4
2026 Realhybrid: A Hybrid Blockchain Consensus With Node-Level Switching
abstract
Blockchain consensus can be divided into synchronous consensus and asynchronous consensus according to the network status. In a real network environment, the network status of each node is constantly fluctuating. Hybrid consensus schemes adapt to network fluctuations through switching consensus protocol between asynchronous and synchronous. However, existing schemes are system-level switching, resulting in low efficiency. In this paper, we present Realhybrid, a hybrid consensus scheme with node-level switching, which enables every node to select appropriate consensus protocols based on their network status. We design corresponding protocols for each node to achieve efficient consensus under network fluctuations. Moreover, we establish a Realhybrid network model and quantify the relationship between its performance and system parameters. We conduct experiments on Realhybrid and the results show that it has 29% lower transaction waiting volume and 17% lower transaction confirmation latency compared to other hybrid consensus schemes.
Jing Chen 0003, Ruiying Du, Kun He 0008
IEEE Trans. Inf. Forensics Secur.6
2026 POWER: High-Throughput Blockchain Based on Computing Power Utilization
abstract
Proof-of-Work (PoW) based blockchain reaches consensus by solving computational puzzles, with only the winners generating blocks. In other words, most nodes waste their computing power, resulting in a mismatch between transaction throughput and system scale (i.e., the number of nodes). In this paper, we propose POWER, a high transaction throughput blockchain architecture that utilizes node computing power. Specifically, by introducing hook block and transaction block, we design a parallel structure to increase the utilization of the computing power of nodes that package and add transactions to the blockchain. In the parallel structure, the hook block hangs the transaction block and solves the problem of transaction redundancy. We also present a round interval confirmation mechanism to increase the utilization of the computing power of nodes that confirm transactions. We conduct experiments on POWER and the experiment results show that POWER has a 63% higher transaction throughput and a 51% lower transaction confirmation latency compared to other schemes. In particular, the transaction confirmation accuracy of POWER is 5.9 times better than that of OHIE.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Trans. Netw.3
2025 HARE Attack: Inaudible Harmony in Voice Enrollment
abstract
Speaker verification (SV) constitutes a prevalent biometric recognition technology safeguarding the security of sensitive data and regulating access to vital infrastructure. Current audio adversarial attack researches predominantly concentrate on deceiving systems through an touching on inference parameters of the underlying model architectures. This work introduces a pragmatic and formidable attack scenario wherein adversarial perturbations are introduced during the SV enrollment phase. These meticulously engineered distortions subtly alter voice embedding extraction, consequently influencing the verification outcome for the adversary. To enable this assault, we posit perturbations comprised of inaudible high-frequency noise and optimize them within an energy-based framework. Under black-box conditions, an evolutionary algorithm, differential evolution, resolves the intricate optimization challenge. Furthermore, we leverage a spectrum of realistic constraints, including absolute hearing thresholds, signal-to-noise ratios, and over-the-air propagation effects, to augment the robustness of our methodology. Rigorous experimentation across four voice identity datasets affirms the efficacy of our approach, demonstrating success rates exceeding 90% in digital environments and 78% in physical settings against four widely employed SV models.
Xingcan Shang, Haolin Wu 0001, Kun He 0008, Jing Chen 0003
ICPADS3
2025 Lombard-VLD: Voice Liveness Detection Based on Human Auditory Feedback
abstract
Voice Liveness Detection (VLD) aims to protect speaker authentication from speech spoofing by determining whether speeches come from live speakers or loudspeakers. Previous methods mainly focus on their differences at the signal level. In this paper, we propose the first VLD that uses the human auditory feedback mechanism (i.e., the Lombard effect), called Lombard-VLD. The key idea is that live speakers can physiologically and involuntarily adjust their speaking patterns in a noisy background but loudspeakers cannot. Moreover, we design a reference-based dual input mode and a differential SE-ResBlock to model the acoustic differences caused by the Lombard effect. Experimental results show that Lombard-VLD achieves 0% and 0.24% EER in two datasets, outperforming the state-of-the-art methods. It is robust to various environmental factors, including different distances, postures of the speaker, and environmental noise, with an average accuracy of over 98.51%. It also has a good generalization to unseen speakers, genders, and datasets, with EER lower than 2.68%, 3.44%, and 7.32%, respectively. This work shows the advantages of the Lombard effect in VLD, which has fewer user limitations and better detection performance.
Hongcheng Zhu, Zongkun Sun, Yanzhen Ren, Kun He 0008, Yongpeng Yan, Wuyang Liu, Yuhong Yang 0001, Weiping Tu
SP4
2025 TrustMFA: A Privacy-Preserving Multi-Factor Authentication Scheme with Anonymous Credential
abstract
Multi-Factor Authentication (MFA) has emerged as a widely adopted and robust authentication mechanism across various scenarios. Whereas, existing methods suffer serious threats, because of their sacrifice of privacy protection, identity provider offline, or other critical features. In theorem, the above threats come from the technical challenge of the combination of biometric and secret key factors. To solve these problems and achieve a reliable access system, this paper introduces TrustMFA, a hybrid authentication framework that leverages anonymous credentials and fuzzy extractors to construct a unified and secure authentication scheme. TrustMFA transforms multiple factors, including biometric factors, into attributes in the anonymous credential, thereby fully guaranteeing the trust and privacy of user. To enhance the practicality, we propose ECC-LSH, an Error-Correcting Code compatible Locality-Sensitive Hashing, which ensures that Hamming distances between biometric features extracted from the same person remain within the error-correcting capability. Comprehensive security analysis and implementation results demonstrate TrustMFA’s effectiveness, showing acceptable computational and communication overhead while maintaining high security levels.
Jianan Hong, Kunling Li, Kun He 0008
TrustCom5
2025 EmbedX: Embedding-Based Cross-Trigger Backdoor Attack Against Large Language Models
Nan Yan 0001, Yuqing Li 0001, Xiong Wang 0006, Jing Chen 0003, Kun He 0008, Bo Li 0001
USENIX Security Symposium5
2025 When Translators Refuse to Translate: A Novel Attack to Speech Translation Systems
Haolin Wu 0001, Chang Liu 0089, Jing Chen 0003, Ruiying Du, Kun He 0008, Yu Zhang 0036, Cong Wu 0003, Tianwei Zhang 0004, Qing Guo 0005, Jie Zhang 0073
USENIX Security Symposium5
2025 EyeAuth: smartphone user authentication via reflexive eye movements
Zhixiang He, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Xiangyu Qu, Yangyang Gu, Xiping Sun, Ruiying Du
Frontiers Comput. Sci.3
2025 DynaShard: Secure and Adaptive Blockchain Sharding Protocol With Hybrid Consensus and Dynamic Shard Management
abstract
Blockchain sharding has emerged as a promising solution to the scalability challenges in traditional blockchain systems by partitioning the network into smaller, manageable subsets called shards. Despite its potential, existing sharding solutions face significant limitations in handling dynamic workloads, ensuring secure cross-shard transactions, and maintaining system integrity. To address these gaps, we propose DynaShard, a dynamic and secure cross-shard transaction processing mechanism designed to enhance blockchain sharding efficiency and security. DynaShard combines adaptive shard management, a hybrid consensus approach, plus an efficient state synchronization and dispute resolution protocol. Our performance evaluation, conducted using a robust experimental setup with real-world network conditions and transaction workloads, demonstrates DynaShard's superior throughput, reduced latency, and improved shard utilization compared to the fast transaction scheduling in blockchain sharding (FTSBS) method. Specifically, DynaShard achieves up to a 42.6% reduction in latency and a 78.77% improvement in shard utilization under high transaction volumes and varying cross-shard transaction ratios. These results highlight DynaShard's ability to outperform state-of-the-art sharding methods, ensuring scalable and resilient blockchain systems. We believe that DynaShard's innovative approach will significantly impact future developments in blockchain technology, paving the way for more efficient and secure distributed systems.
Jing Chen 0003, Kun He 0008, Ruiying Du, Jiahua Xu 0002, Cong Wu 0003, Yebo Feng, Teng Li 0003, Jianfeng Ma 0001
IEEE Internet Things J.3
2025 Formal Analyzing, Attacking, and Patching of Bluetooth Pairing Protocols
abstract
Bluetooth pairing is a protocol that authenticates two Bluetooth devices and derives a shared secret key between them. The Bluetooth standard consists of Bluetooth low energy (BLE) and Bluetooth classic (BC) and the latest pairing protocols in them are BLE secure connections (BLE-SCs) and secure simple pairing with secure connections (SSP-SCs), respectively. Although these two pairing protocols employ well-studied cryptographic primitives to guarantee their security, recent studies disclosed logic flaws in them. In this article, we develop the first comprehensive formal models of BLE-SC and SSP-SC pairing protocols. The models cover all pairing phases of the two protocols and all association models in the specification to discover attacks caused by the interplay between different association models. We also partly loosen the perfect cryptography assumption in traditional symbolic analysis approaches by designing a low-entropy key oracle to detect attacks caused by poorly derived keys. Our analysis confirms two existing attacks and discloses a new attack that we implemented on real-world devices. We propose a countermeasure to fix the flaws found in the BLE-SC and SSP-SC pairing protocols and discuss the backward compatibility. Moreover, we extend our models to verify the countermeasure, and the results demonstrate its effectiveness in our extended models.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Internet Things J.3
2025 A Formal Analysis of Bluetooth Mesh Provisioning Protocol
abstract
Bluetooth Mesh is a wireless mesh networking technology based on Bluetooth Low Energy, where new devices need to be provisioned to join an existing network. Currently, security research on the Bluetooth Mesh provisioning protocol primarily focuses on the manual analysis of potential vulnerabilities, while existing formal models are too simplistic to capture all the attacks present in the protocol. In this paper, we utilize Tamarin Prover to conduct a comprehensive formal analysis of the Bluetooth Mesh provisioning protocol. Our model encompasses all phases of the protocol from beaconing to data distribution, and includes the modeling of all public key exchanges and authentication methods specified in the Bluetooth Mesh specification. Additionally, we accurately model the AES-CMAC primitive used in the protocol, with the help of deconstruction rules and built-in message theories in Tamarin. This AES-CMAC model enables the analysis of subtle behaviors that were previously beyond the scope of symbolic analysis. Our model successfully reproduces reflection and primitive misuse attacks found in previous studies and identifies two new vulnerabilities. We propose countermeasures for the aforementioned attacks and extend our provisioning model to verify the effectiveness of these countermeasures.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Internet Things J.4
2025 Transferable and Robust Dynamic Adversarial Attack Against Object Detection Models
abstract
Object detection models have been widely deployed in physical world applications, and they are vulnerable to adversarial attacks. However, most adversarial attacks are implemented in a glass box setting, and under ideal shooting conditions, such as fixed distances and angles, and thus have limited attack success rate (ASR) in practice. In this article, we present a transferable and robust dynamic adversarial attack where the adversarial patches can be printed on or attached to nonrigid objects, such as clothes. We develop a cascade module with a momentum-based technique to optimize adversarial patches against various object detection models, achieving better transferability of the patches in a closed box setting. We also develop a strategy of distance-adaptive patch generation and employ perspective transformation to enhance the robustness of patches. To evaluate the attack performance, we conduct extensive experiments on seven mainstream object detection models at different distances and angles. The results show that our method can achieve an average ASR of 69.85%, which is 3.27 times that of the baseline method at 3 m.
Jing Chen 0003, Zijun Zhang 0003, Kun He 0008, Zongru Wu, Ruiying Du, Gongshen Liu
IEEE Internet Things J.4
2025 Universal and Efficient Adversarial Training Framework With Membership Inference Resistance
abstract
Adversarial training is an effective approach to enhance the robustness of machine learning models via adding adversarial examples into the training phase. However, existing adversarial training methods increase the advantage of membership inference attacks, which aim to determine from the model whether an example is in the training dataset. In this article, we propose an adversarial training framework that guarantees both robustness and membership privacy by introducing a tailor-made example called reverse-symmetry example. Moreover, our framework reduces the number of required adversarial examples compared with existing adversarial training methods. We implement our framework using four adversarial training methods on the FMNIST and CIFAR10 datasets and compare its performance with deep learning differential privacy. Our experimental findings demonstrate that our framework mitigates model overfitting and outperforms the original adversarial training with respect to the overall performance of accuracy, robustness, privacy, and runtime.
Ran Yan 0001, Ruiying Du, Kun He 0008, Jing Chen 0003, Cong Wu 0003
IEEE Internet Things J.3
2025 Efficient Verifiable Dynamic Searchable Symmetric Encryption With Forward and Backward Security
abstract
In the realm of secure data outsourcing, verifiable dynamic searchable symmetric encryption (VDSSE) enables a client to verify search results obtained from an untrusted server while protecting the data privacy. Nevertheless, the storage cost of verification structure in some schemes escalates linearly with the number of keywords, and the generation of proofs demands a substantial number of exponentiation operations. Moreover, some schemes overlook forward and backward security in the dynamic database. In this article, we introduce FB-VDSSE, an advanced VDSSE scheme that ensures both forward and backward security. Specifically, we introduce an efficient accumulation commitment verification structure (AC-VS) that attains a commitment verification value with a constant-size storage cost. Based on the AC-VS, we further propose a forward and backward secure VDSSE scheme. Within this scheme, the server exclusively generates a membership proof at the corresponding index of the vector, reducing the computation cost associated with the search operation. Finally, we provide the security proof and functional comparison, demonstrating that our scheme effectively ensures forward security, backward security, and verifiability. Additionally, the experimental evaluations underscore the efficiency of our scheme, showcasing its superior performance compared to relevant schemes in practical scenarios.
Chenbin Zhao, Ruiying Du, Kun He 0008, Jing Chen 0003, Jiguo Li 0001, Ximeng Liu, Jianting Ning
IEEE Internet Things J.3
2025 Fast Payment System in Cryptocurrencies Through Off-Chain Transaction Aggregation
abstract
Blockchain technology is widely used in the field of digital currency, however, the typical blockchain systems suffer from high transaction confirmation latency and expensive fees, which make it difficult to meet the needs of daily payment scenarios. Schemes such as state channel and payment center shift the on-chain payment confirmation process off-chain, thereby reducing latency. Yet these solutions require locking in additional funds or introducing a trusted third party, and seldom consider the issue of lowering transaction fees. In this paper, we propose a cryptocurrency fast payment scheme that organises off-chain participants through smart contracts to enable fast payments. The transaction parties update their state off-chain to ensure fast confirmation. At settlement, off-chain transactions between customer and multiple merchants or merchant and multiple customers are aggregated into a single on-chain transaction, effectively reducing overall transaction fees. We protect transaction privacy by hiding the transaction amount and balance through range proof. We conduct experiments on Ethereum platform, and the results show that the system latency meets the needs of real-world scenarios.
Ruiying Du, Jing Chen 0003, Kun He 0008, Yuanzheng Wang
IEEE Internet Things J.4
2025 An auditable and privacy-preserving user-controllable group signature scheme in blockchain
Jing Chen 0003, Shixiong Yao, Kun He 0008, Ruiying Du
J. Inf. Secur. Appl.4
2025 Efficient Single-Server Private Inference Outsourcing for Convolutional Neural Networks
abstract
Private inference outsourcing ensures the privacy of both clients and model owners when model owners deliver inference services to clients through third-party cloud servers. Existing solutions either reduce inference accuracy due to model approximations or rely on the unrealistic assumption of non-colluding servers. Moreover, their efficiency falls short of HELiKs, a solution focused solely on client privacy protection. In this paper, we propose Skybolt, a single-server private inference outsourcing framework without resorting to model approximations, achieving greater efficiency than HELiKs. Skybolt is built upon efficient secure two-party computation protocols that safeguard the privacy of both clients and model owners. For the linear calculation protocol, we devise a ciphertext packing algorithm for homomorphic matrix multiplication, effectively reducing both computational and communication overheads. Additionally, our nonlinear calculation protocol features a lightweight online phase, involving only the addition and multiplication on secret shares. This stands in contrast to existing protocols, which entail resource-intensive techniques such as oblivious transfer. Extensive experiments on popular models, including ResNet50 and DenseNet121, show that Skybolt achieves a 5.4 − 7.3× reduction in inference latency, accompanied by a 20.1 − 39.6× decrease in communication cost compared to HELiKs.
Xuanang Yang, Jing Chen 0003, Yuqing Li 0001, Kun He 0008, Zikuan Jiang, Ruiying Du
IEEE Trans. Circuits Syst. Video Technol.4
2025 GetFed: Accurate, Differentially Private Federated Learning With GAN-Based Data Generation
abstract
Federated Learning (FL) aims to train neural network models using distributed data resources from multiple clients without sharing raw data. One of the key challenges in FL is non-independent and identically distributed (non-IID) data, which may affect model accuracy. To address this issue, some schemes leverage Generative Adversarial Networks (GANs) to generate virtual data and combine it with the real data to achieve a balanced data distribution. However, there are risks of privacy leakage from the collected virtual data and aggregated gradients. In this paper, we propose GetFed, an accurate and differentially private FL framework with GAN-based Data Generation on non-IID Data. We integrate Differential Privacy (DP) into the GAN training and federated aggregation phases to prevent clients’ privacy leakage. To balance privacy and accuracy, we first design a privacy-preserving virtual sample generation algorithm for GAN training that dynamically reduces unnecessary noise as the quality of virtual samples improves. Additionally, we design an adaptive DP-based secure aggregation algorithm that decreases the added noise as the model approaches convergence. Furthermore, we implement a real-virtual ensemble training algorithm, employing an ensemble learning strategy to better mix virtual and real samples for enhanced global model accuracy. This approach ensures clients benefit from both the authenticity of real samples and the balanced data distribution provided by virtual samples, effectively mitigating the data heterogeneity inherent in non-IID scenarios. Extensive experiments demonstrate that compared with state-of-the-art schemes, GetFedimproves model accuracy by 6–47% and reduces training time by 50%.
Kun He 0008, Yuqing Li 0001, Jing Chen 0003, Zhongmou Liu, Xuanang Yang, Ruiying Du
IEEE Trans. Dependable Secur. Comput.2
2025 FedPHE: A Secure and Efficient Federated Learning via Packed Homomorphic Encryption
abstract
Cross-silo federated learning (FL) enables multiple institutions (clients) to collaboratively build a global model without sharing private data. To prevent privacy leakage during aggregation, homomorphic encryption (HE) is widely used to encrypt model updates, yet incurs high computation and communication overheads. To reduce these overheads,packedHE (PHE) has been proposed to encrypt multiple plaintexts into a single ciphertext. However, the original design of PHE assumes all clients share a single private key, making the system vulnerable to security threats of ciphertexts being intercepted and decrypted byhonest-but-curious clients. Also, it does not consider theheterogeneityamong different clients, resulting in undermined training efficiency with slow convergence and stragglers. To address these challenges, we propose FedPHE, a secure and efficient FL framework with PHE by jointly exploiting contribution-aware secure aggregation and straggler-resistant client selection. Using CKKS with sparsification and blinding, FedPHE achieves efficient secure aggregation that allows clients to only provideobscuredencrypted updates while the server can perform aggregation by accounting forcontributionsof local updates. To mitigate the straggler effect, we devise aperturbed sketch-based selection to cherry-pick representative clients withheterogeneous models and computing capabilitiesin a communication-efficient and privacy-preserving manner. We show, through rigorous security analysis and extensive experiments, that FedPHE can efficiently safeguard clients' privacy, achieve$2.45-6.56\times$training speedup, cut the communication overhead by$1.32-24.85\times$, and reduce straggler effects by$1.89-2.78\times$.
Yuqing Li 0001, Nan Yan 0001, Jing Chen 0003, Xiong Wang 0006, Jianan Hong, Kun He 0008, Wei Wang 0030, Bo Li 0001
IEEE Trans. Dependable Secur. Comput.6
2025 Practical Multi-User Dynamic Searchable Symmetric Encryption With Hierarchical Authorization
abstract
Searchable symmetric encryption (SSE) in the multi-user setting is designed for scenarios where data owners outsource their encrypted data to the cloud while allowing legitimate data users to search on it. However, existing multi-user SSE schemes are not practical in real scenarios with hierarchical user structure such as enterprises and hospitals. Specifically, most schemes require real-time participation of data owners in the authorization or search process, and are not efficient in authorization adjustment, placing a large computational burden on them. In this paper, we focus on hierarchical authorization in the multi-user setting and propose a forward secure scheme, called DSSEHA. In particular, we develop a hierarchical authorization mechanism where the data owner chooses to share her/his data with specific legitimate users who can continue to share with low-level users, thus reducing computational pressure on the data owner. Experiments show that the computation cost of DSSEHA in search is close to the state-of-the-art solution, while the computation cost in update and authorization (e.g., less than 0.1 ms per document for online authorization and less than 0.6 ms for offline authorization) and storage cost (e.g., less than 50.7 MB for Enron subset with 10,000 documents) are much smaller than existing schemes.
Beining Wang, Jing Chen 0003, Kun He 0008, Bei Shen, Sicheng Nian, Ruiying Du
IEEE Trans. Dependable Secur. Comput.3
2025 Forward Secure Similarity Search Over Encrypted Data for Hamming Distance
abstract
Similarity search on encrypted data can identify similar data and handle misspelled keywords in a privacy-preserving manner and thus has received a lot of attention. However, existing schemes suffer from imprecise or predefined distance thresholds, which means that they do not always return the expected search results. Moreover, these schemes either do not consider document addition or lack forward security in this dynamic setting. In this article, we present a Similar Keyword Matching (SKM) framework that accurately calculates the Hamming distance between keywords through a new keyword representation called uni-pos-gram. Based on our framework, we propose a basic scheme for similarity search over encrypted data called SimSE that offers adjustable Hamming distance thresholds and an enhanced scheme called SimSE-F that provides forward security. Security analysis demonstrates that our schemes effectively safeguard the privacy of documents, indexes, and searches. Empirical experiments using real-world datasets demonstrate the efficiency and practical applicability of our schemes.
Beining Wang, Kun He 0008, Jing Chen 0003, Chenbin Zhao, Ruiying Du
IEEE Trans. Dependable Secur. Comput.2
2025 WAFBooster: Automatic Boosting of WAF Security Against Mutated Malicious Payloads
abstract
Web application firewall (WAF) examines malicious traffic to and from a web application via a set of security rules. It plays a significant role in securing Web applications against web attacks. However, as web attacks grow in sophistication, it is becoming increasingly difficult for WAFs to block the mutated malicious payloads designed to bypass their defenses. In response to this critical security issue, we have developed a novel learning-based framework calledWAFBooster, designed to unveil potential bypasses in WAF detections and suggest rules to fortify their security. Using a combination of shadow models and payload generation techniques, we can identify malicious payloads and remove or modify them as needed.WAFBoostergenerates signatures for these malicious payloads using advanced clustering and regular expression matching techniques to repair any security gaps we uncover. In our comprehensive evaluation of eight real-world WAFs,WAFBoosterimproved the true rejection rate of mutated malicious payloads from 21% to 96%, with no false rejections.WAFBoosterachieves a false acceptance rate 3× lower than State-of-the-Art methods for generating malicious payloads. WithWAFBooster, we have taken a step forward in securing web applications against the ever-evolving threats.
Cong Wu 0003, Jing Chen 0003, Simeng Zhu, Wenqi Feng, Kun He 0008, Ruiying Du, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.5
2025 High Accuracy and Presentation Attack Resistant Hand Authentication via Acoustic Sensing for Commodity Mobile Devices
abstract
Biometric authentication schemes, i.e., fingerprint and face authentication, raise serious privacy concerns. To alleviate such concerns, hand authentication has been proposed recently. Existing hand authentication schemes, however, use dedicated hardware, such as infrared or depth cameras, which are not available on commodity mobile devices. In this paper, we presentEchoHand, a high accuracy and presentation attack resistant authentication scheme that complements camera-based 2-dimensional hand geometry recognition of one hand with an active acoustic sensing of the other hand. To this end,EchoHandplays an inaudible acoustic signal using the speaker to actively sense the holding hand and collects the echoes using the microphone.EchoHanddoes not rely on any specialized hardware but uses the built-in speaker, microphone and camera.EchoHanddoes not place more burdens on users than existing hand authentication methods. We conduct comprehensive experiments to evaluate the reliability, security, and usability ofEchoHand. The results show thatEchoHandhas a low equal error rate of 2.45% with as few as 10 training data points and it defeats presentation attacks. The results of the user study also suggest that the required hand gestures are easy to perform, andEchoHandis very user-friendly with low latency.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Ran Yan 0001, Ziming Zhao 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Multi-Authority Anonymous Credentials With Efficient and Decentralized Supervision
abstract
Anonymous credential is widely used in online services, where issuers in authorities issue credentials to users and then users can selectively and privately prove their identities and attributes. However, users may misbehave under anonymous settings. Therefore, we need to trace the credential proof to obtain the user’s identity and link credential proofs to achieve supervision. Existing solutions either have the single point of failure problem or require multiple supervisors perform threshold computations on all users’ identities, it is inefficient in practice especially when the number of users increases. In this paper, we present a credential management system in multiple authorities with efficient and decentralized supervision. Specifically, we design a multi-authority credential management architecture, where each issuer in authorities issues credentials to users and supervisors trace and link credential proofs in multiple authorities. Then, we present efficient and decentralized credential proof tracing and linking protocols, where more than threshold supervisors can trace credential proofs to obtain users’ identities and generate users’ linking keys. Verifiers can link each malicious user’s credential proofs efficiently with those linking keys. We conduct experiments on our system in the WAN and LAN settings and compare it with another threshold attribute-based credential scheme. The experimental results demonstrate that our solution is efficient in practice.
Jing Chen 0003, Yuanzheng Wang, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.4
2025 Vulseye: Detect Smart Contract Vulnerabilities via Stateful Directed Graybox Fuzzing
abstract
Smart contracts, the cornerstone of decentralized applications, have become increasingly prominent in revolutionizing the digital landscape. However, vulnerabilities in smart contracts pose great risks to user assets and undermine overall trust in decentralized systems. Fuzzing, a prominent security testing technique, is extensively explored to detect vulnerabilities. But current smart contract fuzzers fall short of expectations in testing efficiency for two primary reasons. Firstly, smart contracts are stateful programs, and existing approaches, primarily coverage-guided, lack effective feedback from the contract state. Consequently, they struggle to effectively explore the contract state space. Secondly, coverage-guided fuzzers, aiming for comprehensive program coverage, may lead to a wastage of testing resources on benign code areas. This wastage worsens in smart contract testing, as the mix of code and state spaces further complicates comprehensive testing. To address these challenges, we propose Vulseye, a stateful directed graybox fuzzer for smart contracts guided by vulnerabilities. Different from prior works, Vulseyeachieves stateful directed fuzzing by prioritizing testing resources to code areas and contract states that are more prone to vulnerabilities. We introduceCode TargetsandState Targetsinto fuzzing loops as the testing targets of Vulseye. We use static analysis and pattern matching to pinpointCode Targets, and propose a scalable backward analysis algorithm to specifyState Targets. We design a novel fitness metric that leverages feedback from both the contract code space and state space, directing fuzzing toward these targets. With the guidance of code and state targets, Vulseyealleviates the wastage of testing resources on benign code areas and achieves effective stateful fuzzing. In comparison with state-of-the-art fuzzers, Vulseyedemonstrated superior effectiveness and efficiency. Notably, it uncovered 4,845 vulnerabilities in 42,738 real-world smart contracts, outperforming existing approaches by up to$9.7\times $, and identified 11 previously unknown vulnerabilities within the top 50 Ethereum DApps, involving approximately 2,500,000 USD.
Ruichao Liang, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Yueming Wu 0001, Ruochen Cao, Ruiying Du, Ziming Zhao 0001, Yang Liu 0003
IEEE Trans. Inf. Forensics Secur.4
2025 SCR-Auth: Secure Call Receiver Authentication on Smartphones Using Outer Ear Echoes
abstract
Receiving calls is one of the most universal functions of smartphones, involving sensitive information and critical operations. Unfortunately, to prioritize convenience, the current call receiving process bypasses smartphone authentication mechanisms (e.g., passwords, fingerprint recognition, and face recognition), leaving a significant security gap. To address this issue, we propose SCR-Auth, a secure call receiver authentication scheme for smartphones that leverages outer ear echoes. It sends inaudible acoustic signals through the earpiece speaker to actively sense the call receiver’s outer ear structure and records the resulting echoes using the top microphone. These echoes are then analyzed to extract unique outer ear biometric information for authentication. It operates implicitly, without requiring extra hardware or imposing additional burden. Comprehensive experiments conducted under diverse conditions demonstrate SCR-Auth’s effectiveness and security, showing an average balanced accuracy of 96.95% and resilience against potential attacks.
Xiping Sun, Jing Chen 0003, Kun He 0008, Zhixiang He, Ruiying Du, Yebo Feng, Qingchuan Zhao, Cong Wu 0003
IEEE Trans. Inf. Forensics Secur.3
2025 Forward and Backward Private Conjunctive Dynamic Searchable Symmetric Encryption With Refined Leakage Function and Low Communication
abstract
Dynamic searchable symmetric encryption (DSSE) enables updates and keyword searches on outsourced encrypted data while minimizing the information revealed to the server. However, existing DSSE schemes that support conjunctive keyword searches disclose added documents or fail to filter deleted ones in certain circumstances, thus violating forward and backward privacy. Besides, the size of their search tokens increases with the number of documents, which incurs a heavy communication cost. In this paper, we develop a conjunctive DSSE scheme that has a search token size only related to the conjunction size and fully supports forward and backward privacy. Our scheme is based on a new three-dimensional chain structure called CUBE. We also rethink the leakage function of conjunctive queries and prove that our scheme satisfies the refined security definition. Experimental results demonstrate that compared with the state-of-the-art schemes, our scheme increases the computational cost by at most 9.62% but reduces the communication cost by 99.78% when searching six conjunctive keywords.
Beining Wang, Yinuo Li, Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.4
2025 Volia: An Efficient and Light Asynchronous BFT Protocol
abstract
Byzantine Fault Tolerance (BFT) protocols can be divided into synchronous BFT protocols, partially synchronous BFT protocols, and asynchronous BFT protocols according to communication delay. Asynchronous BFT protocols are widely used because they can tolerate uncertain communication delays in the real world. However, asynchronous BFT protocols need to perform many rounds of broadcasts to reach agreement on a transaction subset, which consumes a lot of communication, computing, and storage resources. In this paper, we present Volia, an asynchronous BFT protocol which resolves above problem.We design new broadcast protocol to reduce the number of broadcast rounds needed for agreement. It reduces the communication overhead. Voting broadcast is used to maintain the order of transaction subsets rather than threshold signature to reduce computation cost. Above mechanisms speeds up the agreement phase, reduces the accumulated transaction subsets waiting for agreement and thus saves storage resources. We conduct experiment on Volia and the results show that Volia exhibits about 2~65× throughput, 2~25% latency, and 30% storage cost compared to other asynchronous BFT protocols.
Jing Chen 0003, Kewen Pan, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.4
2025 Breaking the Illusion: A Critical Study of Backdoor Defense in Federated Learning With Non-IID Data
abstract
Existing backdoor defense methods for federated learning (FL) usually try to distinguish between benign and malicious clients. The key insight is that benign clients are densely distributed, whereas malicious clients tend to be outliers outside this distribution. However, this only holds when data is independent and identically distributed (IID), and the effectiveness of these methods under non-IID data has not been systematically examined. In this paper, we present a comprehensive systematization of FL backdoor defense by breaking down its overall pipeline into three key components, i.e., metrics for evaluating clients, techniques for amplifying the difference between benign and malicious clients, and mechanisms for identifying malicious clients. We conduct an empirical study of FL backdoor defense methods under non-IID data settings to explore whether benign and malicious clients can be fully distinguished. Experimental results show that the defense performance degrades significantly when data is non-IID. Our results also reveal how evaluation metrics, amplification techniques and identification mechanisms perform under diverse settings. Contrary to the established belief, we further conclude that these defenses have inherent shortcomings, due to lack of stability and robustness in detecting malicious clients. We believe that our findings can better facilitate the development of FL backdoor defenses.
Pei Ye, Yuqing Li 0001, Kun He 0008, Tianjie Qin, Xiong Wang 0006, Kaige Yang, Chujun Zhang, Jing Chen 0003
IEEE Trans. Inf. Forensics Secur.3
2025 Lightweight Dynamic Conjunctive Keyword Searchable Encryption With Result Pattern Hiding
abstract
With the rapid growth of cloud storage technology, the demand for efficient and secure search of outsourced encrypted data has become increasingly critical. However, existing conjunctive keyword dynamic searchable encryption schemes often expose the Keyword Pair Result Pattern (KPRP) during index matching, compromising privacy. Additionally, frequent index updates require expensive group exponentiations, leading to high client-side overhead. To tackle these challenges, we propose LRP-HDSE, a lightweight dynamic conjunctive keyword searchable encryption scheme that hides KPRP while minimizing client computation costs. To enhance privacy, we introduce the Vector Hidden Subset Predicate Encryption (VH-SPE) mechanism, which enables the server to implicitly detect cross-tag in the membership matching index, effectively mitigating KPRP leakage. For improved efficiency, the scheme designs a lightweight membership matching index structure, LSet, based on low-cost multiset hash operations, reducing reliance on costly exponentiations and lowering client overhead. Our security analysis confirms that LRP-HDSE provides robust KPRP hiding along with forward and backward security in dynamic environments. Asymptotic analysis, along with experiment evaluations on two real-world datasets, show that our scheme offers superior client-side computational efficiency compared to existing approaches, making it both practical and effective.
Chenbin Zhao, Ruiying Du, Jing Chen 0003, Kun He 0008, Ximeng Liu, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.4
2025 Boreas: Fully Anonymous Sealed-Bid Auction
abstract
With the rise of e-commerce, sealed-bid auctions are widely used in various online scenarios. In auctions, bidders’ bids and participants’ identities are considered critical private information. However, existing works either only achieve bid privacy or fail to provide complete protection of identity. In this work, we propose the first sealed-bid auction scheme that achieves both bid privacy and identity privacy, calledBoreas. We propose three fundamental protocols as the building blocks. In particular,anonymous submissionenables sellers to submit items anonymously,oblivious biddingandlocker transactionenable the seller and the winner to confirm the auction results and complete the transaction without knowing each other’s identity. Meanwhile, we formally define the security goal of identity privacy and formalize a new security property called:fully anonymous. We prove the security of our scheme in the semi-honest adversary model. We implement Boreas and run experiments comparing its performance against existing schemes. Our experiments show that Boreas improves computation time by 12.6% and reduces communication costs by 103× in handling a large-scale auction, while offering stronger security guarantee.
Erjun Zhou, Jing Chen 0003, Zhengdi Huang, Kun He 0008, Ruiying Du
IEEE Trans. Inf. Forensics Secur.6
2025 CSIPose: Unveiling Human Poses Using Commodity WiFi Devices Through the Wall
abstract
The popularity of WiFi devices and the development of WiFi sensing have alerted people to the threat of WiFi sensing-based privacy leakage, especially the privacy of human poses. Existing work on human pose estimation is deployed in indoor scenarios or simple occlusion (e.g., a wooden screen) scenarios, which are less privacy-threatening in attack scenarios. To reveal the risk of leakage of the pose privacy to users from commodity WiFi devices, we propose CSIPose, a privacy-acquisition attack that passively estimates dynamic and static human poses in through-the-wall scenarios. We design a three-branch network based on transfer learning, auto-encoder, and self-attention mechanisms to realize the supervision of video frames over CSI frames to generate human pose skeleton frames. Notably, we designAveCSI, a unified framework for preprocessing and feature extraction of CSI data corresponding to dynamic and static poses. This framework uses the average of CSI measurements to generate CSI frames to mitigate the instability of passively collected CSI data, and utilizes a self-attention mechanism to enhance key features. We evaluate the performance of CSIPose across different room layouts, subjects, devices, subject locations, and device locations. Evaluation results emphasize the generalizability of CSIPose. Finally, we discuss measures to mitigate this attack.
Yangyang Gu, Jing Chen 0003, Congrui Chen, Kun He 0008, Ju Jia, Yebo Feng, Ruiying Du, Cong Wu 0003
IEEE Trans. Mob. Comput.4
2025 HeadSonic: Usable Bone Conduction Earphone Authentication via Head-Conducted Sounds
abstract
Earables (ear wearables) are rapidly emerging as a new platform encompassing a diverse of personal applications, prompting the development of authentication schemes to protect user privacy. Existing earable authentication methods are all specifically designed for air-conduction earphones, which are not suited for bone conduction earphones (BCEs) that rely on bone conduction mechanisms. In this paper, we propose HeadSonic, a usable BCE authentication system based on the unique head-conducted sounds, which can be acquired when the user wears the BCE device. Specifically, the system emits a millisecond-level sound to initiate the authentication session. The signal captured by the BCE microphone is propagated through the user's head, which is unique in density, geometry, and bone-tissue ratio. It operates implicitly, while maintaining robustness across different behaviors. Extensive experiments involving 60 subjects demonstrate that HeadSonic achieves a commendable balanced accuracy of 96.59%, proving its efficacy and resilience against replay and synthesis attacks. Our dataset and source codes are available athttps://anonymous.4open.science/r/HeadSonic-1CE4.
Zhixiang He, Jing Chen 0003, Kun He 0008, Yangyang Gu, Qiyi Deng, Zijian Zhang 0001, Ruiying Du, Qingchuan Zhao, Cong Wu 0003
IEEE Trans. Mob. Comput.3
2025 EP-GSPR: An Efficient Privacy-Preserving Graph Shortest Path Retrieval Scheme
abstract
The continuous development of mobile terminal applications, online maps, and other navigation services have become widely used, simultaneously giving rise to significant security risks. To address the issues of privacy leakage and low efficiency in traditional graph shortest path retrieval schemes, an efficient privacy-preserving graph shortest path retrieval scheme is proposed, called EP-GSPR. Specifically, this scheme addresses the privacy security problems in the existing graph shortest path retrieval solutions by ensuring the bilateral privacy protection of the user's query location and the database privacy of the cloud server. Throughout the retrieval process, the cloud server cannot obtain the user's location information, and the user cannot access any database information other than the retrieval results. To overcome the performance bottlenecks in existing schemes, a progressive iterative retrieval framework is designed as the fundamental modular, called Pirf, achieving sub-linear retrieval costs and low storage overhead on the cloud server side. Finally, the security analyses demonstrate the EP-GSPR scheme achieves the bilateral privacy-preserving in terms of user and server sides. The comprehensive experiment evaluations also state the efficiency and practicality of the proposed scheme
Chenbin Zhao, Ruifeng Zhu, Jing Chen 0003, Ruiying Du, Kun He 0008, Jianting Ning, Yang Xiang 0001
IEEE Trans. Mob. Comput.5
2025 ACE-pFL: Accurate, Efficient Personalized Federated Learning With Knowledge Distillation
abstract
Personalized Federated Learning (pFL) can collaboratively personalize models for multiple clients without sharing their private data. However, many pFL methods rely on server-side model parameters aggregation, which requires all models to have the same structure and size. One promising approach is leveraging knowledge distillation (KD) to transfer knowledge between models by exchanging soft predictions rather than model parameters, thus training heterogeneous models. Nevertheless, existing KD-based pFL solutions suffer from accuracy loss due to inadequate knowledge extraction as well as huge computing and communication overheads. In this paper, we present an accurate and efficient KD-based pFL framework, called ACE-pFL. Specifically, we first propose a privacy-preserving client clustering to reduce the impact of non-independent and identically distributed (non-IID) data on model accuracy and convergence, grouping clients with similar data distributions into the same cluster. Since the distillation temperature of traditional KD is fixed, which does not consider the dynamic model training process, we design a dynamic distillation temperature adjustment to accommodate this process, where clients incrementally increase the distillation temperature as training proceeds to facilitate model generalization to new data. Finally, we employ the triple distillation strategy to provide diverse and abundant knowledge, including explicit global knowledge, implicit local knowledge, and implicit global knowledge. Experiments on multiple datasets and tasks show that compared with existing schemes, ACE-pFL can significantly improve the test accuracy by 17.18%, reduce the training time by 57% and the communication overhead by$59.12\times $on average.
Kun He 0008, Yuqing Li 0001, Jing Chen 0003, Ruiying Du
IEEE Trans. Netw.1
2025 A Formal Analysis of 5G EAP-TLS Protocol
abstract
The emergence of private 5G networks has garnered significant attention from enterprises. To ensure the security of communication devices within these networks, the 3GPP group proposed the 5G Extensible Authentication Protocol-Transport Layer Security (EAP-TLS). Despite its critical role, the security of 5G EAP-TLS has not been systematically studied. In this paper, we present the first comprehensive formal model of the 5G EAP-TLS protocol, detailing its flow and incorporating all parties and the certificate distribution mechanism as defined by the 5G specification. Additionally, we extract and interpret the security requirements outlined in the specification. Using the automated symbolic tool Tamarin, we analyze the protocol’s security goals and identify potential vulnerabilities. We propose and verify solutions to these issues, enhancing the protocol’s security. This work provides a foundational understanding and improvements for securing private 5G networks.
Jing Chen 0003, Kun He 0008, Ruiying Du
IEEE Trans. Netw.4
2025 Towards Effective Detection of Ponzi Schemes on Ethereum with Contract Runtime Behavior Graph
abstract
Ponzi schemes, a form of scam, have been discovered in Ethereum smart contracts in recent years, causing massive financial losses. Existing detection methods primarily focus on rule-based approaches and machine learning techniques that utilize static information as features. However, these methods have significant limitations. Rule-based approaches rely on pre-defined rules with limited capabilities and domain knowledge dependency. Using static information like opcodes for machine learning fails to effectively characterize Ponzi contracts, resulting in poor reliability and interpretability. Our research shows no significant difference between Ponzi and non-Ponzi contracts at the opcode level. Moreover, relying on static information like transactions for machine learning requires a certain number of transactions to achieve detection, which limits the scalability of detection and hinders the identification of 0-day Ponzi schemes. In this article, we propose PonziGuard , an efficient Ponzi scheme detection approach based on contract runtime behavior. Inspired by the observation that a contract’s runtime behavior is more effective in disguising Ponzi contracts from the innocent contracts, PonziGuard establishes a comprehensive graph representation called contract runtime behavior graph (CRBG), to accurately depict the behavior of Ponzi contracts. Furthermore, it formulates the detection process as a graph classification task on CRBG, enhancing its overall effectiveness. The experiment results show that PonziGuard surpasses the current state-of-the-art approaches in the ground-truth dataset, achieving a precision of 96.9%, recall of 98.2%, and F1-score of 97.5%. It also exhibits the highest level of interpretability among the current tools. We applied PonziGuard to Ethereum Mainnet and demonstrated its effectiveness in real-world scenarios. Using PonziGuard , we identified 805 Ponzi contracts on Ethereum Mainnet, which have resulted in an estimated economic loss of 281,700 Ether or approximately \($\) 500 million USD. We also found 0-day Ponzi schemes in the recently deployed 10,000 smart contracts.
Ruichao Liang, Jing Chen 0003, Cong Wu 0003, Kun He 0008, Yueming Wu 0001, Weisong Sun, Ruiying Du, Qingchuan Zhao, Yang Liu 0003
ACM Trans. Softw. Eng. Methodol.4
2025 Practical Multiuser Dynamic Searchable Symmetric Encryption With Collusion Resistance
abstract
As data sharing becomes more prevalent, there is growing interest in multiuser dynamic searchable symmetric encryption (MU-DSSE). It enables multiple authorized users to search the encrypted database while safeguarding data privacy. However, most existing schemes are inefficient due to complex computation operations and unaffordable storage burdens. In addition, some are susceptible to collusion attacks between cloud server and compromised users, leading to the leakage of search privacy from other legitimate users. To overcome these challenges, we propose a practical MU-DSSE scheme featuring an unlinkable key derivation mechanism to thwart collusion attacks. Moreover, the MU-DSSE scheme ensures both forward and backward securities in the dynamic setting. To enhance efficiency, we introduce an innovative identity-based key encapsulation mechanism for distributing authorization information to multiple users, significantly optimizing computation and storage costs on user sides and the data owner. Furthermore, we provide the formal security proof and performance analyses. The experimental results demonstrate that MU-DSSE incurs the constant-size storage cost on user sides and the data owner, and outperforms the existing schemes in practice.
Chenbin Zhao, Ruiying Du, Jing Chen 0003, Kun He 0008, Li Xu 0002, Jiguo Li 0001
IEEE Trans. Reliab.4
2024 TokenScout: Early Detection of Ethereum Scam Tokens via Temporal Graph Learning
abstract
Decentralized finance has experienced phenomenal growth, revolutionizing the landscape of financial transactions and asset management via blockchain. Yet, this swift growth brings with it substantial challenges, notably the surge in scam tokens, imposing significant security threats on cryptocurrency investments and trading. Existing detection methods of scam token, primarily relying on analyzing contract codes or transaction patterns, struggle to catch increasingly sophisticated tactics employed by scammers. For example, contract-based analysis are unable to identify scams lacking overt malicious code, e.g., most rugpulls, while transaction-based methods generally lack the foresight to early-detect potential risks.
Cong Wu 0003, Jing Chen 0003, Ziming Zhao 0001, Kun He 0008, Guowen Xu, Yueming Wu 0001, Haijun Wang 0002, Hongwei Li 0001, Yang Liu 0003, Yang Xiang 0001
CCS4
2024 PonziGuard: Detecting Ponzi Schemes on Ethereum with Contract Runtime Behavior Graph (CRBG)
abstract
Ponzi schemes, a form of scam, have been discovered in Ethereum smart contracts in recent years, causing massive financial losses. Rule-based detection approaches rely on pre-defined rules with limited capabilities and domain knowledge dependency. Additionally, using static information like opcodes and transactions for machine learning models fails to effectively characterize the Ponzi contracts, resulting in poor reliability and interpretability.
Ruichao Liang, Jing Chen 0003, Kun He 0008, Yueming Wu 0001, Gelei Deng, Ruiying Du, Cong Wu 0003
ICSE3
2024 Efficient and Straggler-Resistant Homomorphic Encryption for Heterogeneous Federated Learning
abstract
Cross-silo federated learning (FL) enables multiple institutions (clients) to collaboratively build a global model without sharing their private data. To prevent privacy leakage during aggregation, homomorphic encryption (HE) is widely used to encrypt model updates, yet incurs high computation and communication overheads. To reduce these overheads, packed HE (PHE) has been proposed to encrypt multiple plaintexts into a single ciphertext. However, the original design of PHE does not consider the heterogeneity among different clients, an intrinsic problem in cross-silo FL, often resulting in undermined training efficiency with slow convergence and stragglers. In this work, we propose FedPHE, an efficiently packed homomorphically encrypted FL framework with secure weighted aggregation and client selection to tackle the heterogeneity problem. Specifically, using CKKS with sparsification, FedPHE can achieve efficient encrypted weighted aggregation by accounting for contributions of local updates to the global model. To mitigate the straggler effect, we devise a sketching-based client selection scheme to cherry-pick representative clients with heterogeneous models and computing capabilities. We show, through rigorous security analysis and extensive experiments, that FedPHE can efficiently safeguard clients’ privacy, achieve a training speedup of 1.85 − 4.44×, cut the communication overhead by 1.24 − 22.62× , and reduce the straggler effect by up to 1.71 − 2.39×.
Nan Yan 0001, Yuqing Li 0001, Jing Chen 0003, Xiong Wang 0006, Jianan Hong, Kun He 0008, Wei Wang 0030
INFOCOM6
2024 Model-agnostic adversarial example detection via high-frequency amplification
Jing Chen 0003, Kun He 0008, Zijun Zhang 0003, Ruiying Du, Jisi She
Comput. Secur.3
2024 Corrigendum to "Model-agnostic Adversarial Example Detection via High-Frequency Amplification" [Computers & Security, Volume 141, June 2024, 103791]
Jing Chen 0003, Kun He 0008, Zijun Zhang 0003, Ruiying Du, Jisi She
Comput. Secur.3
2024 Generic Construction of Threshold Credential Management With User-Autonomy Aggregation
abstract
Credential management is widely used in online services such as electronic identity cards, e-health, and e-voting, in which users prove their identity or attributes with credentials issued by authorities. Under some circumstances, a user needs to prove her/his identity or attributes in multiple credentials to a verifier. In existing credential management systems, a user either proves her/his credentials one by one or requests new credentials from authorities with the original ones, and they are inefficient in practice. Moreover, existing decentralized credential management systems either rely on multiple single parties or do not support attribute revocation. In this paper, we present a threshold credential management system with threshold issuance and revocation and user-autonomy aggregation. Specifically, we design a decentralized credential management architecture where multiple authorities form an alliance and manage credentials collaboratively. Then, we propose a threshold credential management scheme, where user issuance and revocation must be approved by multiple credential managers, and a user can aggregate her/his credentials and prove them to a verifier simultaneously. We conduct experiments on our system and the results demonstrate that it is suitable in practice.
Jing Chen 0003, Kun He 0008, Yuanzheng Wang, Ruiying Du
IEEE Trans. Inf. Forensics Secur.3
2024 MaskAuct: Seller-Autonomous Auction With Bidder Anonymity and Bidding Confidentiality
abstract
Electronic auctions, popular in the digital era, raise great privacy concerns that may impact participant interests. However, traditional privacy-preserving auction systems fall short in facilitating seller autonomy, particularly in identifying and excluding previously mischievous anonymous bidders. In this paper, we propose MaskAuct, a seller-autonomous auction system with the privacy of bidder identity and bidding price. To enable seller autonomy without compromising bidder privacy, we present a new cryptographic primitive, called Zero-Knowledge Blacklistable Group Signature (ZKBGS), which can invalidate signatures from users in the blacklist without opening user identity. We construct MaskAuct from fully homomorphic encryption and ZKBGS, and introduce the distributed privacy server provider to address the collusion problem. The experimental results show ZKBGS has a smaller signature size (8320 bytes) and running time (635 ms for signing and 24 ms for verification) than the linkable ring signature, even when the length of the blacklist is$2^{9}$. In contrast to the sealed-bid auction scheme SEAL, MaskAuct provides better communication complexity, and is$27\times $faster on bidder computation.
Siqin Li, Kun He 0008, Jing Chen 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.2
2024 Rethinking Membership Inference Attacks Against Transfer Learning
abstract
Transfer learning, successful in knowledge translation across related tasks, faces a substantial privacy threat from membership inference attacks (MIAs). These attacks, despite posing significant risk to ML model’s training data, remain limited-explored in transfer learning. The interaction between teacher and student models in transfer learning has not been thoroughly explored in MIAs, potentially resulting in an under-examined aspect of privacy vulnerabilities within transfer learning. In this paper, we propose a new MIA vector against transfer learning, to determine whether a specific data point was used to train the teacher model while only accessing the student model in a white-box setting. Our method delves into the intricate relationship between teacher and student models, analyzing the discrepancies in hidden layer representations between the student model and its shadow counterpart. These identified differences are then adeptly utilized to refine the shadow model’s training process and to inform membership inference decisions effectively. Our method, evaluated across four datasets in diverse transfer learning tasks, reveals that even when an attacker only has access to the student model, the teacher model’s training data remains susceptible to MIAs. We believe our work unveils the unexplored risk of membership inference in transfer learning.
Cong Wu 0003, Jing Chen 0003, Qianru Fang, Kun He 0008, Ziming Zhao 0001, Hao Ren 0001, Guowen Xu, Yang Liu 0003, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.4
2024 Fregata: Fast Private Inference With Unified Secure Two-Party Protocols
abstract
Private Inference (PI) safeguards client and server privacy when the client utilizes the server’s model to make predictions. Existing PI solutions for Convolutional Neural Networks (CNNs) employ distinct cryptographic primitives to customize secure two-party protocols for linear and non-linear layers. This requires data to be converted into a specific form to switch between protocols, thus leading to a significant increase in inference latency. In this paper, we present Fregata, a fast PI scheme for CNNs by leveraging identical cryptographic primitives to calculate both linear and nonlinear layers. Specifically, our protocols utilize homomorphic encryption to obtain additive secret shares of matrix products during the offline phase, followed by lightweight multiplication and addition operations on these shares in the latency-sensitive online phase. Benefiting from uniformity, we accelerate inference from a holistic perspective by decoupling certain procedures of our protocols and executing them asynchronously. Moreover, to improve the efficiency of the offline phase, we elaborate a homomorphic matrix multiplication calculation method with reduced computation and communication complexity compared to existing approaches. Furthermore, we minimize inference latency by employing graphics processing units to parallelize the operations on the shares during the online phase. Experimental evaluations on popular CNN models such as SqueezeNet, ResNet, and DenseNet demonstrate that Fregata reduces 35-45 times inference latency over the state-of-the-art counterparts, accompanied by a 1.6-2.8 times decrease in communication overhead. In terms of total runtime, Fregata maintains a reduction of approximately 3 times.
Xuanang Yang, Jing Chen 0003, Yuqing Li 0001, Kun He 0008, Zikuan Jiang, Ruiying Du
IEEE Trans. Inf. Forensics Secur.4
2024 WiFiLeaks: Exposing Stationary Human Presence Through a Wall With Commodity Mobile Devices
abstract
WiFi devices are ubiquitous and may leak user and household privacy. In this paper, we report an attack, namely WiFiLeaks, which uses a commodity mobile device to passively detect stationary human presence through a wall by analyzing the channel state information of wireless signals transmitted by indoor WiFi devices. In our adversarial scenario, attackers cannot control the WiFi transmitter or use advanced radio devices. The main challenge of this attack is how to extract robust features from non-customized signals for stationary human presence. To address this challenge, we first combine methods based on outliers and wavelet denoising to enhance the low-frequency information related to human presence. Then we propose a novel feature extraction method based on the correlation among subcarriers since stationary human presence can enhance their correlations. We evaluate WiFiLeaks using nine different WiFi transmitter and one commodity smartphone in four different settings. The evaluations show WiFiLeaks can still achieve accuracy rates of 83.33% and 100% for human presence and absence at 20 meters between the monitor device and the transmitter in through-the-wall scenarios.
Yangyang Gu, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Ziming Zhao 0001, Ruiying Du
IEEE Trans. Mob. Comput.3
2024 UFinAKA: Fingerprint-Based Authentication and Key Agreement With Updatable Blind Credentials
abstract
Authentication and key agreement are two basic functionalities to guarantee secure network communications, which are naturally integrated as an Authentication and Key Agreement (AKA) protocol. AKAs usually either need a dedicated device to store a cryptographic key or require the user to remember a password. In recent years, AKAs built on biometrics, e.g., human fingerprints, have gained research attention since they avoid these issues. Unlike keys or passwords that can be updated, biometrics are at greater risk that cannot be reused once disclosed. However, existing mechanisms either explicitly expose the biometrics to the server or consume a massive amount of resources. This paper proposes UFinAKA, a privacy-preserving fingerprint-based authentication and key agreement system with updatable blind credentials. UFinAKA explores a fingerprint-based blind credential authentication scheme as a building block such that the server has no access to the fingerprint data hidden within the credential. Furthermore, UFinAKA provides an updatable fingerprint-based credentials AKA protocol, which allows the server to update the blind credentials and guarantees anonymous fingerprint authentication to mitigate further leakage when the server is corrupted. We perform security analysis and experimental evaluation on UFinAKA. The evaluation results show that UFinAKA requires only linear computation overhead for the client, a single round of interaction, and roughly linear computation and storage cost for the server. The running time of UFinAKA is at least 4 times faster than the state-of-the-art solutions, and the storage cost of these solutions is at least 100 times more than UFinAKA.
Mei Wang 0003, Jing Chen 0003, Kun He 0008, Ruozhou Yu, Ruiying Du
IEEE/ACM Trans. Netw.3
2024 Incentive Mechanisms for Online Task Offloading With Privacy-Preserving in UAV-Assisted Mobile Edge Computing
abstract
Unmanned aerial vehicles (UAVs) have emerged as a promising technology to provide low-latency mobile edge computing (MEC) services. To fully utilize the potential of UAV-assisted MEC in practice, both technical and economic challenges need to be addressed: how to optimize UAV trajectory for online task offloading and incentivize the participation of UAVs without compromising the privacy of user equipment (UE). In this work, we consider unique features of UAVs,i.e.,high mobility as well as limited energy and computing capacity, and propose privacy-preserving auction frameworks, Ptero, to schedule offloading tasks on the fly and incentivize UAVs’ participation. Specifically, Ptero first decomposes the online task offloading problem into a series of one-round problems by scaling the UAV’s energy constraint into the objective. To protect UE’s privacy, Ptero calculates UAV’s coverage based on subset-anonymity. At each round, Ptero schedules UAVs greedily, computes remuneration for working UAVs, and processes unserved tasks in the cloud to maximize the system’s utility ( i.e., minimize social cost). Theoretical analysis proves that Ptero achieves truthfulness, individual rationality, computational efficiency, privacy-preserving and a nontrivial competitive ratio. Trace-driven evaluations further verify that Ptero can reduce the social cost by up to$116\%$compared with four state-of-the-art algorithms.
Renli Zhang, Ruiting Zhou, Haisheng Tan, Kun He 0008
IEEE/ACM Trans. Netw.5
2024 FACT: Sealed-Bid Auction With Full Privacy via Threshold Fully Homomorphic Encryption
abstract
Sealed-bid auction is a common mechanism for selling and buying commodities. However, existing auction schemes to protect bids require at least squared computation and communication complexity for the bidders or rely on trusted auctioneers or third parties. To address the above problems, we propose a secure and efficient sealed-bid auction framework, called FACT. We design a lightweight threshold fully homomorphic encryption scheme as the building block. Our framework does not rely on any trusted auctioneer and fulfills a stronger security guarantee, called full privacy, i.e., only the seller and the winning bidder can determine the auction result. While our framework applies to first-price sealed-bid, it can easily be extended to support second-price sealed-bid (i.e., Vickrey auction) with the same security guaranteed. Our framework also supports the dynamic joining and exiting of sellers and bidders. Meanwhile, our framework reduces the bidders’ overhead and the number of interactions to a constant level. We formally prove the security of our framework in the semi-honest adversary model. We implement FACT and run experiments comparing its performance against existing schemes. We find that our framework not only achieves a stronger security guarantee but also shows significant performance improvement compared to existing schemes.
Erjun Zhou, Jing Chen 0003, Kun He 0008, Ruiying Du, Mei Wang 0003, Yunyu Yao
IEEE Trans. Serv. Comput.3
2023 Efficient Adversarial Training with Membership Inference Resistance
Ran Yan 0001, Ruiying Du, Kun He 0008, Jing Chen 0003
PRCV (1)3
2023 Formal Analysis and Patching of BLE-SC Pairing
Jing Chen 0003, Kun He 0008, Ruiying Du
USENIX Security Symposium3
2023 Efficient Privacy-Preserving Inference Outsourcing for Convolutional Neural Networks
abstract
Inference outsourcing enables model owners to deploy their machine learning models on cloud servers to serve users. In this paradigm, the privacy of model owners and users should be considered. Existing solutions focus on Convolutional Neural Networks (CNNs) but their efficiency is much lower than GALA, which is a solution that only protects user privacy. Furthermore, these solutions adopt approximations that reduce the model accuracy and thus require model owners to retrain the models. In this paper, we present an efficient CNN inference outsourcing solution that protects the privacy of both model owners and users. Specifically, we design secure two-party computation protocols based on two non-colluding cloud servers, which calculate with additive secret shares of the model and the user’s input. Our protocols avoid the expensive permutation operations in linear calculations and approximations in non-linear calculations. We implement our solution on realistic CNNs and experimental results show that our solution is even 2–4 times faster than GALA.
Xuanang Yang, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.3
2022 EchoHand: High Accuracy and Presentation Attack Resistant Hand Authentication on Commodity Mobile Devices
abstract
Biometric authentication schemes, i.e., fingerprint and face authentication, raise serious privacy concerns. To alleviate such concerns, hand authentication has been proposed recently. However, existing hand authentication schemes use dedicated hardware, such as infrared or depth cameras, which are not available on commodity mobile devices. In this paper, we present EchoHand, a high accuracy and presentation attack resistant authentication scheme that complements camera-based 2-dimensional hand geometry recognition of one hand with active acoustic sensing of the other holding hand. EchoHand plays an inaudible acoustic signal using the speaker to actively sense the holding hand and collects the echoes using the microphone. EchoHand does not rely on any specialized hardware but uses the built-in speaker, microphone and camera. Moreover, EchoHand does not place more burdens on users than existing hand authentication methods. We conduct comprehensive experiments to evaluate the reliability and security of EchoHand. The results show that EchoHand has a low equal error rate of 2.45% with as few as 10 training data points and it defeats presentation attacks.
Cong Wu 0003, Jing Chen 0003, Kun He 0008, Ziming Zhao 0001, Ruiying Du
CCS3
2022 Online incentive mechanism for task offloading with privacy-preserving in UAV-assisted mobile edge computing
abstract
Unmanned aerial vehicles (UAVs) have emerged as a promising technology to provide low-latency mobile edge computing (MEC) services. To fully utilize the potential of UAV-assisted MEC in practice, both technical and economic challenges need to be addressed: how to optimize UAV trajectory for online task offloading and incentivize the participation of UAVs without compromising the privacy of user equipment (UE). In this work, we consider unique features of UAVs, i.e., high mobility as well as limited energy and computing capacity, and propose a privacy-preserving auction framework, Ptero, to schedule offloading tasks on the fly and incentivize UAVs' participation. Specifically, Ptero first decomposes the online task offloading problem into a series of one-round problems by scaling the UAV's energy constraint into the objective. To protect UE's privacy, Ptero calculates UAV's coverage based on subset-anonymity. At each round, Ptero schedules UAVs greedily, computes remuneration for working UAVs, and processes unserved tasks in the cloud to maximize the system's utility (i.e., minimize social cost). Theoretical analysis proves that Ptero achieves truthfulness, individual rationality, computational efficiency, privacy preserving and a non-trivial competitive ratio. Trace-driven evaluations further verify that Ptero can reduce the social cost by up to 116% compared with four state-of-the-art algorithms.
Ruiting Zhou, Renli Zhang, Haisheng Tan, Kun He 0008
MobiHoc5
2022 PANDA: Lightweight non-interactive privacy-preserving data aggregation for constrained devices
Mei Wang 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Bingsheng Zhang, Zengpeng Li 0001
Future Gener. Comput. Syst.2
2022 DELIA: Distributed Efficient Log Integrity Audit Based on Hierarchal Multi-Party State Channel
abstract
Audit log contains the trace of different activities in computing systems, which makes it critical for security management, censorship, and forensics. However, experienced attackers may delete or modify the audit log after their attacks, which makes the audit log unavailable in attack investigation. In this article, we focus on the log integrity audit in the same domain, in which a number of servers update audit logs for a single or several organizations as an alliance. We propose a distributed efficient log integrity audit framework, called DELIA, which employs the distributed ledger technique to protect audit information, and utilizes the idea of state channel to improve the throughput of distributed ledger. To generate stable state from the rapidly-updated logs in the domain, we propose a log state generation scheme, which not only generates state suitable for audit logs, but also enables mutual supervision within the domain. To overcome the high latency in existing state channel schemes, we propose a hierarchal multi-party state channel scheme, which makes the latency in our framework independent of the number of servers in the domain. We implement DELIA on Ethereum and evaluate its performance. The results show that our framework is efficient and secure in practice.
Jing Chen 0003, Kun He 0008, Ruiying Du, Weihang Chen, Yang Xiang 0001
IEEE Trans. Dependable Secur. Comput.3
2022 XAuth: Efficient Privacy-Preserving Cross-Domain Authentication
abstract
It is well known that each Public Key Infrastructure (PKI) system forms a closed security domain and only recognizes certificates in its own domain (such as medical systems, financial systems, and 5G networks). When users need to access services in other domains, their identities often cannot be recognized or PKI systems require extremely complex operations to authenticate the users’ identities. This is the cross-domain authentication problem. The distributed consensus feature of blockchain provides a technical approach to solve this problem. However, there are some unresolved problems in existing blockchain-based schemes. On one hand, due to the low throughput of blockchain systems, the response speed may be insufferable when the number of cross-domain authentication requirements becomes enormous. On the other hand, these schemes insufficiently consider the privacy risk in the cross-domain scenario. In this article, we propose an efficient privacy-preserving cross-domain authentication scheme called XAuth that is integrated naturally with the existing PKI and Certificate Transparency (CT) systems. Specifically, we design a lightweight correctness verification protocol based on Multiple Merkle Hash Tree for rapid response. To protect users’ privacy, we present an anonymous authentication protocol for cross-domain authentication. The security analysis and experimental results demonstrate that XAuth is secure and efficient.
Jing Chen 0003, Zeyi Zhan, Kun He 0008, Ruiying Du
IEEE Trans. Dependable Secur. Comput.3
2022 Toward Robust Detection of Puppet Attacks via Characterizing Fingertip-Touch Behaviors
abstract
Fingerprint authentication has gained increasing popularity on mobile devices in recent years. However, it is vulnerable to presentation attacks, which include that an attacker spoofs with an artificial replica. Many liveness detection solutions have been proposed to defeat such presentation attacks; however, they all fail to defend against a particular type of presentation attack, namelypuppet attack, in which an attacker places an unwilling victim's finger on the fingerprint sensor. In this article, we proposeFinAuth, an effective and efficient software-only solution, to complement fingerprint authentication by defeating both synthetic spoofs and puppet attacks usingfingertip-touchcharacteristics.FinAuthcharacterizes intrinsic fingertip-touch behaviors including the acceleration and the rotation angle of mobile devices when a legitimate user authenticates.FinAuthonly utilizes common sensors equipped on mobile devices and does not introduce extra usability burdens on users. To evaluate the effectiveness ofFinAuth, we carried out experiments on datasets collected from 90 subjects after the IRB approval. The results show thatFinAuthcan achieve the average balanced accuracy of 96.04% with 5 training data points and 99.28% with 100 training data points. Security experiments also demonstrate thatFinAuthis resilient against possible attacks. In addition, we report the usability analysis results ofFinAuth, including user authentication delay and overhead.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ziming Zhao 0001, Ruiying Du
IEEE Trans. Dependable Secur. Comput.2
2022 Redactable Blockchain From Decentralized Chameleon Hash Functions
abstract
Blockchain is a technology with decentralization and immutability features and has been employed for auditing by many applications. However, immutability sometimes limits the application of blockchain technology. For example, vulnerable smart contracts on blockchain cannot be redacted due to immutability. The existing redactable blockchain solutions either have a low efficiency or violate the decentralization feature. Moreover, those solutions lack mechanisms for tracing redaction history and checking block consistency. In this paper, we present an efficient redactable blockchain with traceability in the decentralized setting. Specifically, we propose a decentralized chameleon hash function for redactable blockchain that every redaction must be approved by multiple blockchain nodes. We also design a redactable blockchain structure that maintains all redactions of a block and encodes the redacted blocks into an RSA accumulator. Then, we propose an efficient block consistency check protocol based on the RSA accumulator. Finally, we conduct experiments and compare our scheme with another decentralized redactable blockchain to demonstrate that our solution is efficient in practice.
Jing Chen 0003, Kun He 0008, Ruiying Du, Mingxi Lai
IEEE Trans. Inf. Forensics Secur.3
2021 Biometrics-Authenticated Key Exchange for Secure Messaging
abstract
Secure messaging heavily relies on a session key negotiated by an Authenticated Key Exchange (AKE) protocol. However, existing AKE protocols only verify the existence of a random secret key (corresponding to a certificated public key) stored in the terminal, rather than a legal user who uses the messaging application. In this paper, we propose a Biometrics-Authenticated Key Exchange (BAKE) framework, in which a secret key is derived from a user's biometric characteristics that are not necessary to be stored. To protect the privacy of users' biometric characteristics and realize one-round key exchange, we present an Asymmetric Fuzzy Encapsulation Mechanism (AFEM) to encapsulate messages with a public key derived from a biometric secret key, such that only a similar secret key can decapsulate them. To manifest the practicality, we present two AFEM constructions for two types of biometric secret keys and instantiate them with irises and fingerprints, respectively. We perform security analysis of BAKE and show its performance through extensive experiments.
Mei Wang 0003, Kun He 0008, Jing Chen 0003, Zengpeng Li 0001, Wei Zhao 0054, Ruiying Du
CCS2
2021 HIAWare: Speculate Handwriting on Mobile Devices with Built-In Sensors
Jing Chen 0003, Peidong Jiang, Kun He 0008, Ruiying Du
ICICS (1)3
2021 PROCESS: Privacy-Preserving On-Chain Certificate Status Service
abstract
Clients (e.g., browsers) and servers require public key certificates to establish secure connections. When a client accesses a server, it needs to check the signature, expiration time, and revocation status of the certificate to determine whether the server is reliable. The existing solutions for checking certificate status either have a long update cycle (e.g., CRL, CRLite) or violate clients' privacy (e.g., OCSP, CCSP), and these solutions also have the problem of trust concentration. In this paper, we present PROCESS, an online privacy-preserving on-chain certificate status service based on the blockchain architecture, which can ensure decentralized trust and provide privacy protection for clients. Specifically, we design Counting Garbled Bloom Filter (CGBF) that supports efficient queries and BlockOriented Revocation List (BORL) to update CGBF timely in the blockchain. With CGBF, we design a privacy-preserving protocol to protect clients' privacy when they check the certificate statuses from the blockchain nodes. Finally, we conduct experiments and compare PROCESS with another blockchain-based solution to demonstrate that PROCESS is suitable in practice.
Kun He 0008, Jing Chen 0003, Ruiying Du, Weihang Chen, Zhihong Tian 0001, Shouling Ji
INFOCOM2
2021 SeCrowd: Efficient secure interactive crowdsourcing via permission-based signatures
Jing Chen 0003, Kun He 0008, Ruiying Du
Future Gener. Comput. Syst.3
2021 Semantics-Aware Privacy Risk Assessment Using Self-Learning Weight Assignment for Mobile Apps
abstract
Most of the existing mobile application (app) vetting mechanisms only estimate risks at a coarse-grained level by analyzing app syntax but not semantics. We propose a semantics-aware privacy risk assessment framework (SPRisk), which considers the sensitivity discrepancy of privacy-related factors at semantic level. Our framework can provide qualitative (i.e., risk level) and quantitative (i.e., risk score) assessment results, both of which help users make decisions to install an app or not. Furthermore, to find the reasonable weight distribution of each factor automatically, we exploit a self-learning weight assignment method, which is based on fuzzy clustering and knowledge dependency theory. We implement a prototype system and evaluate the effectiveness of SPRisk with 192,445 normal apps and 7,111 malicious apps. A measurement study further reveals some interesting findings, such as the privacy risk distribution of Google Play Store, the diversity of official and unofficial marketplaces, which provide insights into understanding the seriousness of privacy threat in the Android ecosystem.
Jing Chen 0003, Chiheng Wang, Kun He 0008, Ziming Zhao 0001, Min Chen 0003, Ruiying Du, Gail-Joon Ahn
IEEE Trans. Dependable Secur. Comput.3
2021 Dynamic Group-Oriented Provable Data Possession in the Cloud
abstract
As an important security property of cloud storage, data integrity has not been sufficiently studied under the multi-writer model, where a group of users work on shared files collaboratively and any group member can update the data by modification, insertion, and deletion operations. Existing works under such multi-writer model would bring large storage cost to the third-party verifiers. Furthermore, to the best of our knowledge, none of the existing works for shared files supports fully dynamic operations, which implies that users cannot freely perform the update operations. In this paper, we propose the first public auditing scheme for shared data that supports fully dynamic operations and achieves constant storage cost for the verifiers. Our scheme, named PRAYS, is boosted by a new paradigm for remote data integrity checking. To implement the new paradigm, we proposed a specially designed authenticated structure, called blockless Merkle tree, and a novel cryptographic primitive, called permission-based signature. Extensive evaluation demonstrates that PRAYS is as efficient as the existing less-functional solutions. We believe that PRAYS is an important step towards designing practical multi-writer cloud storage systems.
Kun He 0008, Jing Chen 0003, Quan Yuan 0003, Shouling Ji, Debiao He, Ruiying Du
IEEE Trans. Dependable Secur. Comput.1
2021 Secure Dynamic Searchable Symmetric Encryption With Constant Client Storage Cost
abstract
Dynamic Searchable Symmetric Encryption (DSSE) enables users to search on the encrypted database stored on a semi-trusted server while keeping the search and update information under acceptable leakage. However, most existing DSSE schemes are not efficient enough in practice due to the complex structures and cryptographic primitives. Moreover, the storage cost on the client side grows linearly with the number of keywords in the database, which induces unaffordable storage cost when the size of keyword set is large. In this article, we focus on secure dynamic searchable symmetric encryption with constant client storage cost. Our framework is boosted by fish-bone chain, a novel two-level structure which consists of Logical Keyword Index Chain (LoKIC) and Document Index Chain (DIC). To instantiate the proposed framework, we propose a forward secure DSSE scheme, called CLOSE-F, and a forward and backward secure DSSE scheme, called CLOSE-FB. Experiments showed that the computation cost of CLOSE-F and CLOSE-FB are as efficient as the state-of-the-art solutions, while the storage costs on the client side are constant in both CLOSE-F and CLOSE-FB, which are much smaller than existing schemes.
Kun He 0008, Jing Chen 0003, Qinxi Zhou, Ruiying Du, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.1
2020 Liveness is Not Enough: Enhancing Fingerprint Authentication with Behavioral Biometrics to Defeat Puppet Attacks
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ziming Zhao 0001, Ruiying Du
USENIX Security Symposium2
2020 CaIAuth: Context-Aware Implicit Authentication When the Screen Is Awake
abstract
Relieving users from the burden of remembering and inputting authentication information explicitly, such as passwords/PINs and lock patterns, implicit authentication mechanisms have gained an increasing concern. When providing authentication, the existing implicit methods only depend on a specific behavior, such as typing on the screen, performing gestures, or taking a walk. However, in real applications, a user's behavioral characteristics are also decided by the context where behavior is performed. Thus, those existing methods show limited authentication accuracy and usability. To address these issues, we propose CaIAuth, a reliable context-aware implicit authentication framework, which profiles users' behavior and context characteristics in a holistic fashion. It observes the states of context-sensing entities for different smartphone usage patterns and builds a context-aware model to distinguish between legitimate users and illegal ones. We conducted extensive experiments to evaluate system performance with a large data set collected from 142 subjects. The experimental results show that our system achieves a low equal error rate (EER) (e.g., less 7%) and is resilient against common threats, including zero-effect attack and mimicry attack. In addition, CaIAuth achieves a low authentication delay and overhead.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ruiying Du, Yang Xiang 0001
IEEE Internet Things J.2
2020 PowerPrint: Identifying Smartphones through Power Consumption of the Battery
abstract
Device fingerprinting technologies are widely employed in smartphones. However, the features used in existing schemes may bring the privacy disclosure problems because of their fixed and invariable nature (such as IMEI and OS version), or the draconian of their experimental conditions may lead to a large reduction in practicality. Finding a new, secure, and effective smartphone fingerprint is, however, a surprisingly challenging task due to the restrictions on technology and mobile phone manufacturers. To tackle this challenge, we propose a battery-based fingerprinting method, named PowerPrint, which captures the feature of power consumption rather than invariable information of the battery. Furthermore, power consumption information can be easily obtained without strict conditions. We design an unsupervised learning-based algorithm to fingerprint the battery, which is stimulated with different power consumption of tasks to improve the performance. We use 15 smartphones to evaluate the performance of PowerPrint in both laboratory and public conditions. The experimental results indicate that battery fingerprint can be efficiently used to identify smartphones with low overhead. At the same time, it will not bring privacy problems, since the power consumption information is changing in real time.
Kun He 0008, Jing Chen 0003, Yingying Fang, Ruiying Du
Secur. Commun. Networks2
2020 EliMFS: Achieving Efficient, Leakage-Resilient, and Multi-Keyword Fuzzy Search on Encrypted Cloud Data
abstract
Motivated by privacy preservation requirements for outsourced data, keyword searches over encrypted cloud data have become a hot topic. Compared to single-keyword exact searches, multi-keyword fuzzy search schemes attract more attention because of their improvements in search accuracy, typo tolerance, and user experience in general. However, existing multi-keyword fuzzy search solutions are not sufficiently efficient when the file set in the cloud is large. To address this, we propose an Efficient Leakage-resilient Multi-keyword Fuzzy Search (EliMFS) framework over encrypted cloud data. In this framework, a novel two-stage index structure is exploited to ensure that search time is independent of file set size. The multi-keyword fuzzy search function is achieved through a delicate design based on the Gram Counting Order, the Bloom filter, and the Locality-Sensitive Hashing. Furthermore, considering the leakages caused by the two-stage index structure, we propose two specific schemes to resist these potential attacks in different threat models. Extensive analysis and experiments show that our schemes are highly efficient and leakage-resilient.
Jing Chen 0003, Kun He 0008, Lan Deng, Quan Yuan 0003, Ruiying Du, Yang Xiang 0001, Jie Wu 0001
IEEE Trans. Serv. Comput.2
2019 ICAuth: Implicit and Continuous Authentication When the Screen Is Awake
abstract
Implicit authentication has become increasingly popular over recent years due to the fact that it relieves users from explicit actions such as remembering and entering passwords. This paper puts forward ICAuth, a general and simple implicit authentication method for mobile devices, to authenticate the current user implicitly and continuously when the screen is awake. Distinct from existing implicit user authentication methods which only focus on behavioral characteristics and ignore contextual information, ICAuth is devised to understand different behaviors in various contexts. We investigate the correlations between the behavioral characteristics and contextual information via sensors on mobile devices and observe that user's behavioral characteristics are strongly related to the context. These sensors are divided into two kinds, including fine-grained sensors and coarse-grained sensors, where fine-grained sensor data represent behavioral features and the coarse-grained depict contextual information. ICAuth provides continuous authentication without the involvement of users. It promotes security via authenticating the current user continuously and improves the usability via eliminating the limitation of specific behaviors. We evaluate ICAuth comprehensively with a large dataset including 340842 samples collected from 142 subjects. Our approach achieves an accuracy of 96.85%, FNR of 2.95%, and FPR of 4.01%. Security analysis is also conducted to demonstrate that ICAuth is resilient against common smartphone authentication threats. Finally, we show the low power consumption and authentication latency with 2.2 seconds of ICAuth.
Cong Wu 0003, Kun He 0008, Jing Chen 0003, Ruiying Du
ICC2
2018 CertChain: Public and Efficient Certificate Audit Based on Blockchain for TLS Connections
abstract
In recent years, real-world attacks against PKI take place frequently. For example, malicious domains' certificates issued by compromised CAs are widespread, and revoked certificates are still trusted by clients. In spite of a lot of research to improve the security of SSL/TLS connections, there are still some problems unsolved. On one hand, although log-based schemes provided certificate audit service to quickly detect CAs' misbehavior, the security and data consistency of log servers are ignored. On the other hand, revoked certificates checking is neglected due to the incomplete, insecure and inefficient certificate revocation mechanisms. Further, existing revoked certificates checking schemes are centralized which would bring safety bottlenecks. In this paper, we propose a blockchain-based public and efficient audit scheme for TLS connections, which is called Certchain. Specially, we propose a dependability-rank based consensus protocol in our blockchain system and a new data structure to support certificate forward traceability. Furthermore, we present a method that utilizes dual counting bloom filter (DCBF) with eliminating false positives to achieve economic space and efficient query for certificate revocation checking. The security analysis and experimental results demonstrate that CertChain is suitable in practice with moderate overhead.
Jing Chen 0003, Shixiong Yao, Quan Yuan 0003, Kun He 0008, Shouling Ji, Ruiying Du
INFOCOM4
2018 Blind Filtering at Third Parties: An Efficient Privacy-Preserving Framework for Location-Based Services
abstract
Location-based service (LBS) has gained increasing popularity recently, but protecting users' privacy in LBS remains challenging. Depending on whether a trusted third party (TTP) is used, existing solutions can be classified into: TTP-based and TTP-free. The former relies on a TTP for user privacy protection, which creates a single-point-failure and is thus impractical in reality. The latter does not require any TTP, but usually introduces redundant point-of-interest (POI) records in query result and thus incurs significant computation and communication costs on the user side, making them unsuitable for resource-constrained mobile devices. In this paper, we propose a novel framework to protect user privacy while ensuring efficiency. Our framework also uses redundant POI records to protect privacy against LBS provider but employs a semi-trusted third party, called proxy, to filter out redundant POI records. To protect privacy against proxy, we design a novel filtering protocol, Blind filter, to allow the proxy to filter out redundant encrypted POI records in a blind way. In comparison with existing solutions, our framework is not only resilient to dual identity attack, but also incurs lower communication and computation overhead. Comprehensive analysis and experiments show that our framework is secure and highly efficient in mobile environments.
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Min Chen 0003, Ruiying Du, Yang Xiang 0001
IEEE Trans. Mob. Comput.2
2017 Charge-Depleting of the Batteries Makes Smartphones Recognizable
abstract
Many components of smartphones are used to generate device fingerprinting, such as screens, CPUs and various sensors. These device fingerprinting can be used to identify the smartphones. However, there are many restrictions with these device fingerprinting. Invariable information in screens and CPUs may lead to privacy risks. Moreover, strict experimental steps are required when fingerprinting the sensors. The effectiveness and effeciency of these device fingerprinting is reduced in practice. In this paper, we present a novel hardware fingerprinting based on the battery. Instead of relying on invariable information of the battery, we focus on the charge-depleting of the smartphone. The discrepencies on manufacturing of smartphones make that the charge-depleting is different when performs the same task. Moreover, charge-depleting information can easily be obtained without strict operating steps. We design a highly accurate algorithm to fingerprint the batteries which is based on the unsupervised learning. Besides, we stimulate the algorithm with different charge-depleting of tasks to improve the performance. We use 15 smartphones to evaluate the performance of the battery fingerprinting in both laboratory and public conditions. The experimental results show that battery fingerprinting is quite effective, the recognition accuracy rate can reach 86%.
Jing Chen 0003, Yingying Fang, Kun He 0008, Ruiying Du
ICPADS3
2017 Secure independent-update concise-expression access control for video on demand in cloud
Kun He 0008, Jing Chen 0003, Yu Zhang 0036, Ruiying Du, Yang Xiang 0001, Mohammad Mehedi Hassan, Abdulhameed Alelaiwi
Inf. Sci.1
2017 Batch Identification Game Model for Invalid Signatures in Wireless Mobile Networks
abstract
Secure access is one of the fundamental problems in wireless mobile networks. Digital signature is a widely used technique to protect messages' authenticity and nodes' identities. From the practical perspective, to ensure the quality of services in wireless mobile networks, ideally the process of signature verification should introduce minimum delay. Batch cryptography technique is a powerful tool to reduce verification time. However, most of the existing works focus on designing batch verification algorithms for wireless mobile networks without sufficiently considering the impact of invalid signatures, which can lead to verification failures and performance degradation. In this paper, we propose a Batch Identification Game Model (BIGM) in wireless mobile networks, enabling nodes to find invalid signatures with reasonable delay no matter whether the game scenario is complete information or incomplete information. Specifically, we analyze and prove the existence of Nash Equilibriums (NEs) in both scenarios, to select the dominant algorithm for identifying invalid signatures. To optimize the identification algorithm selection, we propose a self-adaptive auto-match protocol which estimates the strategies and states of attackers based on historical information. Comprehensive simulation results in terms of NE reasonability, algorithm selection accuracy, and identification delay are provided to demonstrate that BIGM can identify invalid signatures more efficiently than existing algorithms.
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Guoliang Xue, Ruiying Du, Lina Wang 0001
IEEE Trans. Mob. Comput.2
2016 Distributed Greedy Coding-aware Deterministic Routing for multi-flow in wireless networks
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Ruiying Du, Lina Wang 0001, Jie Wu 0001
Comput. Networks2
2016 Message-locked proof of ownership and retrievability with remote repairing in cloud
abstract
Cloud storage services are widely deployed and employed in recent years. A number of data checking techniques have been proposed for secure cloud storage services. These state-of-the-art schemes only focus on some aspects, such as data integrity, users' ownership, and data resiliency, but the overall safety of cloud storage services is not discussed sufficiently. Considering cloud storage requirements as a whole, in this paper, we propose a model of message-locked proof of ownership and retrievability with remote repairing, which provides data confidentiality, secure cross-user deduplication at the client-side, file retrievability, ownership privacy-preserving, random block accessing, and remote repairing simultaneously. In addition, we also propose a concrete construction and prove its security in the random oracle model. The experimental results show that our construction is efficient in practice. Copyright © 2016 John Wiley & Sons, Ltd.
Jing Chen 0003, Kun He 0008, Min Chen 0003, Ruiying Du, Lina Wang 0001
Secur. Commun. Networks3
2016 DeyPoS: Deduplicatable Dynamic Proof of Storage for Multi-User Environments
abstract
Dynamic Proof of Storage (PoS) is a useful cryptographic primitive that enables a user to check the integrity of outsourced files and to efficiently update the files in a cloud server. Although researchers have proposed many dynamic PoS schemes in singleuser environments, the problem in multi-user environments has not been investigated sufficiently. A practical multi-user cloud storage system needs the secure client-side cross-user deduplication technique, which allows a user to skip the uploading process and obtain the ownership of the files immediately, when other owners of the same files have uploaded them to the cloud server. To the best of our knowledge, none of the existing dynamic PoSs can support this technique. In this paper, we introduce the concept of deduplicatable dynamic proof of storage and propose an efficient construction called DeyPoS, to achieve dynamic PoS and secure cross-user deduplication, simultaneously. Considering the challenges of structure diversity and private tag generation, we exploit a novel tool called Homomorphic Authenticated Tree (HAT). We prove the security of our construction, and the theoretical analysis and experimental results show that our construction is efficient in practice.
Kun He 0008, Jing Chen 0003, Ruiying Du, Qianhong Wu, Guoliang Xue, Xiang Zhang 0005
IEEE Trans. Computers1
2015 Dominating Set and Network Coding-Based Routing in Wireless Mesh Networks
abstract
Wireless mesh networks are widely applied in many fields such as industrial controlling, environmental monitoring, and military operations. Network coding is promising technology that can improve the performance of wireless mesh networks. In particular, network coding is suitable for wireless mesh networks as the fixed backbone of wireless mesh is usually unlimited energy. However, coding collision is a severe problem affecting network performance. To avoid this, routing should be effectively designed with an optimum combination of coding opportunity and coding validity. In this paper, we propose a Connected Dominating Set (CDS)-based and Flow-oriented Coding-aware Routing (CFCR) mechanism to actively increase potential coding opportunities. Our work provides two major contributions. First, it effectively deals with the coding collision problem of flows by introducing the information conformation process, which effectively decreases the failure rate of decoding. Secondly, our routing process considers the benefit of CDS and flow coding simultaneously. Through formalized analysis of the routing parameters, CFCR can choose optimized routing with reliable transmission and small cost. Our evaluation shows CFCR has a lower packet loss ratio and higher throughput than existing methods, such as Adaptive Control of Packet Overhead in XOR Network Coding (ACPO), or Distributed Coding-Aware Routing (DCAR).
Jing Chen 0003, Kun He 0008, Ruiying Du, Minghui Zheng, Yang Xiang 0001, Quan Yuan 0003
IEEE Trans. Parallel Distributed Syst.2
2014 Proofs of Ownership and Retrievability in Cloud Storage
abstract
With the development and maturity of cloud computing technology, the demand for cloud storage is growing. Deduplication is a basic requirement for cloud storage to save storage space of cloud servers. And as clients are untrusted from the perspective of the server, the notion of Proofs of Ownership (PoWs) has been proposed in client-side deduplication. On the other hand, the clients cannot completely trust the server either, thus clients have to know whether their files are stored integrally in the cloud. However, most existing works only focus on one-way validation. In this paper, we introduce a framework called Proofs of Ownership and Retrievability (PoOR) considering the requirement of mutual validation. In our PoOR scheme, clients can prove to the server their ownership of files and verify the retrievability of the files without uploading or downloading them. For ensuring the recoverability and security of files in server, we encode files by erasure code. In order to keep the communication cost in constant, we employ Merkle Tree and homomorphic verifiable tags which also induce acceptable storage overheads. At last, we implemente our scheme and compare it with other schemes. The result shows that the PoOR scheme is efficient in computation performance, especially when the size of the file is large.
Ruiying Du, Lan Deng, Jing Chen 0003, Kun He 0008, Minghui Zheng
TrustCom4
2012 A key distribution scheme using network coding for mobile ad hoc network
abstract
ABSTRACT Network coding offers an excellent solution for maximizing throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. This paper presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and uses message authentication codes to guarantee the integrity of the distributed keys. We also show that our scheme can resist a series of attacks in wireless ad hoc network and has better performance compared with previous schemes proposed in the literature. Copyright © 2011 John Wiley & Sons, Ltd.
Jianwei Liu 0001, Ruiying Du, Jing Chen 0003, Kun He 0008
Secur. Commun. Networks4