Liming Fang 0001

dblp:59/4426-1 · DBLP profile ↗
← Back
79ranked-venue papers
14as first author
57since 2021 · last 2026
0000-0002-1420-2047ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 30 · 4 first-author · 22 since 2021Computer networks · 12 · 3 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 12 · 1 first-author · 10 since 2021Artificial intelligence and machine learning · 9 · 1 first-author · 9 since 2021Systems, architecture and hardware · 7 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 GADT: Enhancing transferable adversarial attacks through gradient-guided adversarial data transformation
Yating Ma, Xiaogang Xu 0002, Liming Fang 0001, Jiafei Wu, Lu Zhou 0002
Neurocomputing3
2026 LETA: A Lattice-Based Efficient and Traceable Privacy-Preserving Batch Authentication Scheme for Vehicle Platoon in VANETs
abstract
Vehicle platoon (VP), as a typical form of traffic cooperation, can significantly enhance traffic efficiency and safety in Vehicular Ad hoc Networks (VANETs). However, malicious vehicles in VP poses a severe threat to the security of entire VP, requiring to be efficiently traced by identity authentication. In this paper, we propose a lattice-based efficient and traceable privacy-preserving batch authentication scheme for vehicle platoon in VANETs, named LETA. First, we design a dynamic VP identity structure VPD-Tree which is constructed based on hash tree and pseudonyms of vehicles to preserve privacy. Then, an aggregate signature is constructed based on VPD-tree and modular lattice for secure and efficient batch authentication of VP. Finally, Zero-Knowledge Proofs (ZKP) is applied on the VPD-Tree structure to anonymously and efficiently trace the malicious vehicles of VP. Security analysis shows that LETA achieves stronger security guarantees, thereby offering a more secure solution than existing approaches. Moreover, performance evaluations show that LETA achieves lower computation and communication overheads through the VPD-tree structure and efficient batch authentication scheme.
Yingjie Xia, Xuejiao Liu 0002, Zhiquan Liu 0001, Zhen Guo 0003, Zhe Liu 0001, Liming Fang 0001
IEEE J. Sel. Areas Commun.8
2026 SOOM: A Schedule-Search-Based Operator Obfuscation Method Against Model Extraction Attacks
abstract
Deep Neural Networks (DNNs) are gradually becoming indispensable in various technological domains. To cater to more deployment backends and increasingly complex model architectures, deep learning compiler-driven efficient compilation modes are becoming essential components of productivity. However, this deployment method exacerbates security risks. Recent studies have shown that attackers can reverse-engineer executable files to regenerate trainable deep learning models, leading to adversarial attacks and other security breaches. Previous research indicates that such attacks pose significant threats, yet progress in implementing cost-effective mitigation strategies remains limited. Existing defense mechanisms primarily focus on Trusted Execution Environments or partial encryption to protect critical model parameters, often at the expense of compiled execution efficiency. To address this gap, we propose a schedule search based operator obfuscation method (SOOM) to defend against model extraction attacks for models compiled and executed on standard CPU and GPU backends, where low latency on device inference is required. SOOM is built on TVM, a deep learning compiler, and constructs a comprehensive obfuscation space for deep learning operators. It leverages a security aware learned cost model based on XGBoost gradient boosted trees to balance security objectives and performance requirements, and ultimately generates obfuscated executable code for various deep learning operators. Extensive experiments covered over 105 operator configurations and more than 30,000 tensor computation test cases. Our method was tested against state-of-the-art model extraction attacks, raising the operator inference failure rate to as high as 89%. We also observe up to approximately 25.4% performance gains in selected cases, while the balanced setting keeps model-level latency overhead within a modest budget.
Yang Li 0103, Changchun Yin, Liming Fang 0001
IEEE Trans. Inf. Forensics Secur.4
2026 Blockchain-Oriented Certificateless Threshold Signature With Identifiable Abort for Federated Learning in Digital Twin-Assisted IoV
abstract
As a promising subdomain of intelligent transportation systems (ITS), Internet of Vehicles (IoV) can be empowered by digital twin (DT) technology for real-time traffic simulation and artificial intelligence (AI)-driven predictive analytics in evolutionary trend projection, demonstrating significant potential in dynamic transportation optimization. Among various machine learning paradigms, federated learning (FL) not only aligns well with IoV, but also provides it with privacy protection. Traditional FL faces single point of failure due to the existence of an aggregation center, so blockchain-based FL with multiple aggregators is utilized to mitigate this issue. Nevertheless, in such distributed environments, both aggregators and model parameters exposed to network are vulnerable to attacks, impeding the normal operation of FL. In this paper, for blockchain-enabled FL with multiple aggregators in IoV, we propose CLTSwNI&IA, the first non-interactive certificateless threshold signature with identifiable abort. This scheme eliminates certificate management and key escrow, adopts a blockchain-oriented approach by utilizing a fully distributed signing paradigm. Additionally, the proposed signing scheme is capable of identifying malicious FL aggregators during the entire process through distributed fine-grained verification and ensuring the integrity of aggregation results. Finally, theoretical and experimental comparisons with related literature demonstrate the advanced functionality and the acceptable efficiency of our approach.
Yunfan Hu, Zengxiang Wang, Hu Xiong, Liming Fang 0001, Changgen Peng, Abubaker Wahaballa, Zhen Qin 0002, Zhiguang Qin
IEEE Trans. Intell. Transp. Syst.5
2026 SOFAN: Side-Channel Oriented Fingerprinting and Neutralization for TVM-Compiled DNNs
abstract
Deep learning compilers such as TVM lower neural networks through intermediate representations (IRs) into optimized, hardware-specific binaries. While enabling high-performance deployment via optimizations like operator fusion and loop tiling, they leave stable execution signatures exploitable by reverse engineering. Prior attacks often rely on a single modality, symbolic lifting, instruction classification, or side channels, each struggles under at least one realistic condition, such as deep fusion, schedule diversity, or OS noise. We present SOFAN, a side-channel oriented fingerprinting and neutralization framework for TVM-compiled DNNs. On the attack side, TCScaptures timing and cache traces to recover operator boundaries via smoothing, non-maximum suppression (NMS), and dynamic time warping (DTW). A multimodal fusion network (MFN) then integrates these side-channel signals with instruction embeddings to classify deeply fused operators. On the defense side, LASR (Leakage-Aware Schedule Rewriting) selectively perturbs critical leakage via schedule diversification, access equalization, and memory remapping, under a fixed runtime budget. Evaluated across CNNs and fusion schedules, SOFANimproves segmentation and recognition over prior baselines. LASR reduces Top-1 attack accuracy by up to 24 points (16 on average) under 10-20% runtime overhead and minimal memory cost. By aligning both attack and defense with compiler boundaries, SOFANenables practical, budget-aware protection for real-world deployments.
Yang Li 0103, Changchun Yin, Liming Fang 0001
IEEE Trans. Reliab.5
2025 SymND: Detecting Backdoor Attacks in Self-Supervised Facial Representation Tasks
abstract
Facial image tasks present distinct challenges in self-supervised learning (SSL) that are not encountered in general image classification, with existing backdoor attacks and defenses often fail to handle these specific issues. This paper introduces SymND, the first defense framework specifically designed to counter backdoor attacks in facial image SSL scenarios. SymND innovatively assesses noise stability across images and dynamically adjusts noise placement, capitalizing on the symmetrical properties of facial triggers—a departure from traditional SSL defenses that presume static trigger locations. Our method’s efficacy is underscored by experiments conducted on RAF-DB and UTKFace datasets, which show a significant reduction in attack success rates, plummeting from 99.58% to 0.15%, across a variety of downstream tasks employing different encoders.
Liyue Zhu, Changchun Yin, Liming Fang 0001, Zhen Qin 0002
ICME3
2025 An Effective Approach to Class-Wise Unlearning in Pre-trained Encoders for Contrastive Learning
abstract
Image encoder pre-training has experienced a substantial evolution due to contrastive learning, facilitating the extraction of intricate feature representations from unlabeled datasets. Nevertheless, the precise mitigation of the influence of specific data points, particularly in scenarios without labels, remains an inadequately explored issue within this field. This paper proposes CU-Encoder, the first approach aimed at selectively eliminating the impact of a designated ‘class’ from pre-trained encoders in contrastive learning. We also introduce a new evaluation framework that evaluates the unlearning effect, revealing how effectively the influence of the ‘class’ is removed and the model’s generalization capability is maintained. Comprehensive experiments conducted across different models and datasets highlight the effectiveness of CU-Encoder, confirming its capacity to achieve efficient unlearning while maintaining the model’s performance.
Changchun Yin, Liming Fang 0001, Lu Zhou 0002
IJCNN2
2025 SSTAP: Generating Sample-Specific Transferable Adversarial Patch in Multimodal Contrastive Learning
abstract
The growing use of multimodal contrastive learning in critical applications demands robustness against adversarial attacks. Although universal adversarial patches can broadly impact downstream tasks, their fixed perturbations are easily detectable and can be mitigated by simple defenses. To address this, we propose the sample-specific transferable adversarial patch (SSTAP), which generates adversarial patches tailored to individual inputs. By exploiting the unique features of each sample, SSTAP creates imperceptible patches that disrupt feature representations across diverse downstream tasks. Experiments on Wikipedia and Pascal-Sentence datasets show significant performance drops, demonstrating SSTAP's effectiveness.
Changchun Yin, Liming Fang 0001
ICMR2
2025 Integrating Pretrained Models with Graph Neural Networks for Smart Contract Interpretability
Xinxin Hao, Liming Fang 0001
WASA (2)3
2025 CFVDT: A Cost-Effective Data Trading Framework With Fine-Grained and Verifiable Access Control
Yu Tao 0004, Lu Zhou 0002, Hao Wang 0189, Liming Fang 0001, Chunpeng Ge 0001, Zhe Liu 0001
IEEE Internet Things J.5
2025 MACO: Model Anti-Extraction via Compiler Obfuscation
abstract
Deep neural networks (DNNs) are widely deployed across applications, but growing model sizes and performance demands on edge devices necessitate aggressive compiler-based acceleration, as enabled by frameworks like TVM. Compiling models into standalone executables, however, introduces new security risks, reverse-engineering these binaries can reveal core architectures and enable unauthorized model cloning or tampering. Existing defenses largely rely on trusted execution or encryption, which target weight confidentiality but fail to protect architectural details or operator attributes, often with high runtime costs. To address these gaps, we propose MACO, a multi-tier obfuscation framework built atop TVM, spanning high-level graph rewriting and low-level IR transformations. MACO integrates three transformation categories: operator attribute obfuscation, memory layout perturbation, and dummy branching, covering the full compilation stack. A tiered design enables flexible trade-offs between security and performance. We evaluate MACO on eight common models and three attack types: side-channel, symbolic execution, and deep learning–based extraction. Results show up to 85.8% reduction in attribute inference success and 99% reduction in topology reconstruction, with the lightest tier incurring only 1.036× overhead over the unobfuscated baseline.
Yang Li 0103, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.4
2025 Hard Adversarial Example Mining for Improving Robust Fairness
abstract
Adversarial training (AT) is widely considered the state-of-the-art technique for improving the robustness of deep neural networks (DNNs) against adversarial examples (AEs). Nevertheless, recent studies have revealed that adversarially trained models are prone to unfairness problems. Recent works in this field usually apply class-wise regularization methods to enhance the fairness of AT. However, this paper discovers that these paradigms can be sub-optimal in improving robust fairness. Specifically, we empirically observe that the AEs that are already robust (referred to as “easy AEs” in this paper) are useless and even harmful in improving robust fairness. To this end, we propose the hard adversarial example mining (HAM) technique which concentrates on mining hard AEs while discarding the easy AEs in AT. Specifically, HAM identifies the easy AEs and hard AEs with a fast adversarial attack method. By discarding the easy AEs and reweighting the hard AEs, the robust fairness of the model can be efficiently and effectively improved. Extensive experimental results on four image classification datasets demonstrate the improvement of HAM in robust fairness and training efficiency compared to several state-of-the-art fair adversarial training methods. Our code is available athttps://github.com/yyl-github-1896/HAM.
Chenhao Lin, Yulong Yang 0002, Qian Li 0024, Zhengyu Zhao 0001, Zhe Peng, Run Wang 0001, Liming Fang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.8
2024 Hawkes-Enhanced Spatial-Temporal Hypergraph Contrastive Learning Based on Criminal Correlations
abstract
Crime prediction is a crucial yet challenging task within urban computing, which benefits public safety and resource optimization. Over the years, various models have been proposed, and spatial-temporal hypergraph learning models have recently shown outstanding performances. However, three correlations underlying crime are ignored, thus hindering the performance of previous models. Specifically, there are two spatial correlations and one temporal correlation, i.e., (1) co-occurrence of different types of crimes (type spatial correlation), (2) the closer to the crime center, the more dangerous it is around the neighborhood area (neighbor spatial correlation), and (3) the closer between two timestamps, the more relevant events are (hawkes temporal correlation). To this end, we propose Hawkes-enhanced Spatial-Temporal Hypergraph Contrastive Learning framework (HCL), which mines the aforementioned correlations via two specific strategies. Concretely, contrastive learning strategies are designed for two spatial correlations, and hawkes process modeling is adopted for temporal correlations. Extensive experiments demonstrate the promising capacities of HCL from four aspects, i.e., superiority, transferability, effectiveness, and sensitivity.
Ke Liang 0006, Sihang Zhou 0001, Meng Liu 0014, Yue Liu 0008, Wenxuan Tu, Yi Zhang 0104, Liming Fang 0001, Zhe Liu 0001, Xinwang Liu 0002
AAAI7
2024 TraceEvader: Making DeepFakes More Untraceable via Evading the Forgery Model Attribution
abstract
In recent few years, DeepFakes are posing serve threats and concerns to both individuals and celebrities, as realistic DeepFakes facilitate the spread of disinformation. Model attribution techniques aim at attributing the adopted forgery models of DeepFakes for provenance purposes and providing explainable results to DeepFake forensics. However, the existing model attribution techniques rely on the trace left in the DeepFake creation, which can become futile if such traces were disrupted. Motivated by our observation that certain traces served for model attribution appeared in both the high-frequency and low-frequency domains and play a divergent role in model attribution. In this work, for the first time, we propose a novel training-free evasion attack, TraceEvader, in the most practical non-box setting. Specifically, TraceEvader injects a universal imitated traces learned from wild DeepFakes into the high-frequency component and introduces adversarial blur into the domain of the low-frequency component, where the added distortion confuses the extraction of certain traces for model attribution. The comprehensive evaluation on 4 state-of-the-art (SOTA) model attribution techniques and fake images generated by 8 generative models including generative adversarial networks (GANs) and diffusion models (DMs) demonstrates the effectiveness of our method. Overall, our TraceEvader achieves the highest average attack success rate of 79% and is robust against image transformations and dedicated denoising techniques as well where the average attack success rate is still around 75%. Our TraceEvader confirms the limitations of current model attribution techniques and calls the attention of DeepFake researchers and practitioners for more robust-purpose model attribution techniques.
Jingui Ma, Run Wang 0001, Sidan Zhang, Ziyou Liang, Boheng Li, Chenhao Lin, Liming Fang 0001, Lina Wang 0001
AAAI8
2024 DVSAI: Diverse View-Shared Anchors Based Incomplete Multi-View Clustering
abstract
In numerous real-world applications, it is quite common that sample information is partially available for some views due to machine breakdown or sensor failure, causing the problem of incomplete multi-view clustering (IMVC). While several IMVC approaches using view-shared anchors have successfully achieved pleasing performance improvement, (1) they generally construct anchors with only one dimension, which could deteriorate the multi-view diversity, bringing about serious information loss; (2) the constructed anchors are typically with a single size, which could not sufficiently characterize the distribution of the whole samples, leading to limited clustering performance. For generating view-shared anchors with multi-dimension and multi-size for IMVC, we design a novel framework called Diverse View-Shared Anchors based Incomplete multi-view clustering (DVSAI). Concretely, we associate each partial view with several potential spaces. In each space, we enable anchors to communicate among views and generate the view-shared anchors with space-specific dimension and size. Consequently, spaces with various scales make the generated view-shared anchors enjoy diverse dimensions and sizes. Subsequently, we devise an integration scheme with linear computational and memory expenditures to integrate the outputted multi-scale unified anchor graphs such that running spectral algorithm generates the spectral embedding. Afterwards, we theoretically demonstrate that DVSAI owns linear time and space costs, thus well-suited for tackling large-size datasets. Finally, comprehensive experiments confirm the effectiveness and advantages of DVSAI.
Shengju Yu, Siwei Wang 0001, Pei Zhang 0008, Zhe Liu 0001, Liming Fang 0001, En Zhu, Xinwang Liu 0002
AAAI7
2024 DMA: Mutual Attestation Framework for Distributed Enclaves
Peixi Li, Xiang Li 0166, Liming Fang 0001
ICICS (1)3
2024 Adversarial Attack and Defense for Transductive Support Vector Machine
abstract
As a classic semi-supervised approach, the Transductive Support Vector Machine (TSVM) has exhibited remarkable accuracy by utilizing unlabeled data. However, the robustness of TSVM against adversarial attacks remains a subject of investigation, prompting concerns about its reliability in security-critical applications. To unveil the vulnerability of TSVM, we introduce a finite-attack model specifically tailored to its characteristics, effectively manipulating its outputs. Additionally, we present Adversarial Defense-based TSVM (AD-TSVM), the first dedicated defense scheme designed for TSVM. AD-TSVM incorporates adversarial information into the optimization process, enhancing robustness by rebuilding a customized loss function and decision margin to counteract attacks. Rigorous experiments conducted on benchmark datasets demonstrate the effectiveness of AD-TSVM in significantly improving both the accuracy and stability of TSVM when confronted with adversarial attacks. This pioneering research assesses the weaknesses of TSVM and, more importantly, offers valuable insights and solutions for developing secure and trustworthy TSVM systems in the face of emerging threats.
Haiyan Chen 0001, Changchun Yin, Liming Fang 0001
IJCNN4
2024 REDLC: Learning-driven Reverse Engineering for Deep Learning Compilers
abstract
Deep Learning (DL) compilers such as TVM enable the efficient deployment of diverse DL models on heterogeneous and resource-constrained devices to meet the needs for low latency, privacy protection, and enhanced reliability. However, the booming of on-device DL technology will inevitably attract new types of cybercriminals and industrial spies aiming to steal commercial models. Emerging research focused on model-stealing attacks from the perspective of DL compilers mainly uses heuristic approaches, which do not work well with compiler-optimized models. This work proposes an advanced model-stealing attack pipeline that combines code representation learning and binary analysis to efficiently reverse retrainable DL framework models from TVM-compiled executables. To further improve the accuracy of reversed models, we exploit the computational relationships to correct the prediction of operators in the models using Graph Convolutional Networks. Extensive experiments demonstrate that our approach can recover 18 common DL models with different scales downloaded from Keras repositories with 99% accuracy.
Yang Li 0103, Xiaopeng Ke, Fengyuan Xu, Liming Fang 0001
ISSRE7
2024 FedScale: A Federated Unlearning Method Mimicking Human Forgetting Processes
Wenshu Huang, Huiwen Wu, Liming Fang 0001, Lu Zhou 0002
WASA (1)3
2024 Defense Strategy in Federated Learning: Unveiling Stealthy Threats and the Similarity Filter Solution
Liming Fang 0001, Ming Ding 0001, Lu Zhou 0002
WASA (1)2
2024 GhostEncoder: Stealthy backdoor attacks with dynamic triggers to pre-trained encoders in self-supervised learning
Qiannan Wang, Changchun Yin, Liming Fang 0001, Zhe Liu 0001, Run Wang 0001, Chenhao Lin
Comput. Secur.3
2024 ORR-CP-ABE: A secure and efficient outsourced attribute-based encryption scheme with decryption results reuse
Yu Tao 0004, Chunpeng Ge 0001, Lu Zhou 0002, Shouchen Zhou, Yongjing Zhang, Jiarong Liu, Liming Fang 0001
Future Gener. Comput. Syst.8
2024 Privacy-Preserving Collaborative Learning for Genome Analysis via Secure XGBoost
abstract
Genomic data is usually stored in a decentralized manner among data providers, who cannot share them publicly due to privacy concerns. A significant technical challenge is to combine machine learning and cryptography techniques to build secure machine learning models over distributed datasets without violating privacy. Therefore, data providers in collaborative machine learning want to maintain the privacy of their genomic data, and the researcher who owns the training model wants to keep the model and training methods confidential. This paper proposes a framework that supports secure collaborative learning tasks without disclosing the participants' genomic data and training model information simultaneously. With the help of a cluster of Intel SGX enclaves, our work performs fast distributed training over these enclaves, and a dedicated enclave is solely used for updating the global model. Also, Secure XGBoost was implemented over these hardware enclaves for fast learning and to enhance the enclaves' security with unique data-oblivious algorithms that eliminate side-channel attacks. From the experimental results, our scheme achieves fast and efficient results in collaborative learning systems without an increase in communication overhead, making it practical for large genomic data.
Mohammed Shujaa Aldeen, Liming Fang 0001, Zhe Liu 0001
IEEE Trans. Dependable Secur. Comput.4
2024 Attribute-Based Encryption With Reliable Outsourced Decryption in Cloud Computing Using Smart Contract
abstract
Outsourcing the heavy decryption computation to a cloud service provider has been a promising solution for a resource-constrained mobile device to deploy an attribute-based encryption scheme. However, the current attribute based encryption with outsourced decryption schemes only enable the mobile device to verify whether the cloud service provider has returned a correct decryption result, they lack a mechanism to enable the cloud service provider to escape from a mobile device's wrong claim if it has returned a correct decryption result. This article, for the first time, proposes an attribute based encryption with reliable outsourced decryption scheme using the blockchain smart contract. In the proposed scheme, not only can the mobile device verify whether the cloud service provider has returned a correct decryption result, but also the cloud service provider can escape from a wrong claim if the returned decryption result is correct. Moreover, our system achieves the fairness property, which means the cloud service provider can get the reward from the mobile device if and only if it has returned a correct decryption result. Finally, we conduct an implementation to demonstrate that the proposed scheme is practical and efficient.
Chunpeng Ge 0001, Zhe Liu 0001, Willy Susilo, Liming Fang 0001, Hao Wang 0189
IEEE Trans. Dependable Secur. Comput.4
2024 Attribute-Based Proxy Re-Encryption With Direct Revocation Mechanism for Data Sharing in Clouds
abstract
Cloud computing, which provides adequate storage and computation capability, has been a prevalent information infrastructure. Secure data sharing is a basic demand when data was outsourced to a cloud server. Attribute-based proxy re-encryption has been a promising approach that allows secure encrypted data sharing on clouds. With attribute-based proxy re-encryption, a delegator can designate a set of shared users through issuing a re-encryption key which will be used by the cloud server to transform the delegator's encrypted data to the shared users’. However, the existing attribute-based proxy re-encryption schemes lack a mechanism of revoking users from the sharing set which is critical for data sharing systems. Therefore, in this article, we propose a concrete attribute-based proxy re-encryption with direct revocation mechanism (ABPRE-DR) for encrypted data sharing that enables the cloud server to directly revoke users from the original sharing set involved in the re-encryption key. We implemented the new schemes and evaluated its performance. The experimental results show that the proposed ABPRE-DR scheme is efficient and practical.
Chunpeng Ge 0001, Willy Susilo, Zhe Liu 0001, Joonsang Baek, Xiapu Luo, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.6
2024 Anonymous Multi-Hop Payment for Payment Channel Networks
abstract
Payment Channel Networks (PCNs) have flourished as one of the most promising solutions to the blockchain scalability problem. Unfortunately, the existing PCN solutions either fail to provide path privacy guarantees or require the not-always-true All-Anonymous-Connected assumption (i.e., an anonymous communication channel always exists for any two participants). To alleviate these problems, we first present a new cryptographic primitive named anonymous multi-hop payment (AMHP), which is an improvement of anonymous multi-hop lock (AMHL). Using AMHP and payment channels, we can have a new PCN solution with path privacy but removing the All-Anonymous-Connected assumption. After that, we present the first AMHP scheme, called AMHL+, by adapting the generic construction of AMHL, but at the cost of high communication overhead. To reduce the communication cost, we further present a new AMHP scheme (named EAMHL+) using bilinear pairing. The communication cost of the EAMHL+ is reduced by 92.3% compared to the AMHL+. The rigorous security analysis demonstrates that the EAMHL+ holds consistency, balance security, and path privacy. Finally, we implement the proposed AMHP schemes using Java. The extensive experimental results show that, though the EAMHL+ requires more computational cost than the AMHL+, it is more efficient than the latter in terms of communication overhead.
Yi Zhang 0104, Bianjing Pan, Jun Shao 0001, Liming Fang 0001, Rongxing Lu, Guiyi Wei
IEEE Trans. Dependable Secur. Comput.5
2023 Cluster-Guided Contrastive Graph Clustering Network
abstract
Benefiting from the intrinsic supervision information exploitation capability, contrastive learning has achieved promising performance in the field of deep graph clustering recently. However, we observe that two drawbacks of the positive and negative sample construction mechanisms limit the performance of existing algorithms from further improvement. 1) The quality of positive samples heavily depends on the carefully designed data augmentations, while inappropriate data augmentations would easily lead to the semantic drift and indiscriminative positive samples. 2) The constructed negative samples are not reliable for ignoring important clustering information. To solve these problems, we propose a Cluster-guided Contrastive deep Graph Clustering network (CCGC) by mining the intrinsic supervision information in the high-confidence clustering results. Specifically, instead of conducting complex node or edge perturbation, we construct two views of the graph by designing special Siamese encoders whose weights are not shared between the sibling sub-networks. Then, guided by the high-confidence clustering information, we carefully select and construct the positive samples from the same high-confidence cluster in two views. Moreover, to construct semantic meaningful negative sample pairs, we regard the centers of different high-confidence clusters as negative samples, thus improving the discriminative capability and reliability of the constructed sample pairs. Lastly, we design an objective function to pull close the samples from the same cluster while pushing away those from other clusters by maximizing and minimizing the cross-view cosine similarity between positive and negative samples. Extensive experimental results on six datasets demonstrate the effectiveness of CCGC compared with the existing state-of-the-art algorithms. The code of CCGC is available at https://github.com/xihongyang1999/CCGC on Github.
Xihong Yang, Yue Liu 0008, Sihang Zhou 0001, Siwei Wang 0001, Wenxuan Tu, Qun Zheng, Xinwang Liu 0002, Liming Fang 0001, En Zhu
AAAI8
2023 Multi-Layer Feature Division Transferable Adversarial Attack
abstract
Improving the transferability of adversarial examples for the purpose of attacking unknown black-box models has been intensively studied. In particular, feature-level transfer-based attacks, which destroy the intermediate feature outputs of source models, are proven to generate more transferable adversarial examples. However, existing state-of-the-art feature-level attacks only destroy a single intermediate layer, this severely limits the transferability of adversarial examples. And all of these attacks have a vague distinction between positive and negative features. By contrast, we propose the Multi-layer Feature Division Attack (MFDA), which aggregates multi-layer feature information on the basis of feature division to attack. Extensive experimental evaluation demonstrates that MFDA can significantly boost the adversarial transferability and quantitatively distinguish the effects of positive and negative features on transferability. Compared to the state-of-the-art feature-level attacks, our improvement methods with MFDA increase the average success rate by 2.8% against normally trained models and 3.0% against adversarially trained models.
Zikang Jin, Changchun Yin, Piji Li, Lu Zhou 0002, Liming Fang 0001, Xiangmao Chang, Zhe Liu 0001
ICASSP5
2023 FedCom: Byzantine-Robust Federated Learning Using Data Commitment
abstract
Federated learning is a promising distributed edge learning methodology that allows multiple clients to collaboratively train statistical models without disclosing private training data. However, there may exist Byzantine clients launching data/model poisoning attacks to compromise global model's performance or convergence. Most of the existing Byzantine-robust FL schemes are either ineffective against several advanced poisoning attacks, and their robustness suffers from further degradation when local datasets are highly non-independently and identically distributed (non-IID). To address these issues, we propose FedCom, which could achieve data/model poisoning tolerant FL under practical non-IID data partitions, even the attackers do not honestly follow FedCom's protocol. The cardinal design of FedCom is privacy-respectfully asking clients to generate the commitments, which commit and verify the honesty of their local data distributions or local model updates. An extensive performance evaluation demonstrates FedCom's superior performance compared to the state-of-the-art Byzantine-robust schemes under various rigorous settings, even the attackers do not honestly follow the protocol of FedCom and fabricate the commitments.
Liming Fang 0001
ICC3
2023 What can Discriminator do? Towards Box-free Ownership Verification of Generative Adversarial Networks
abstract
In recent decades, Generative Adversarial Network (GAN) and its variants have achieved unprecedented success in image synthesis. However, well-trained GANs are under the threat of illegal steal or leakage. The prior studies on remote ownership verification assume a black-box setting where the defender can query the suspicious model with specific inputs, which we identify is not enough for generation tasks. To this end, in this paper, we propose a novel IP protection scheme for GANs where ownership verification can be done by checking outputs only, without choosing the inputs (i.e., box-free setting). Specifically, we make use of the unexploited potential of the discriminator to learn a hypersphere that captures the unique distribution learned by the paired generator. Extensive evaluations on two popular GAN tasks and more than 10 GAN architectures demonstrate our proposed scheme to effectively verify the ownership. Our proposed scheme shown to be immune to popular input-based removal attacks and robust against other existing attacks. The source code and models are available at https://github.com/AbstractTeen/gan_ownership_verification.
Ziheng Huang 0008, Boheng Li, Yan Cai 0015, Run Wang 0001, Shangwei Guo, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ICCV6
2023 An Enhanced Privacy-Preserving Hierarchical Federated Learning Framework for IoV
Jiacheng Luo, Xuhao Li, Hao Wang 0189, Dongwan Lan, Lu Zhou 0002, Liming Fang 0001
ICICS7
2023 Mining for Better: An Energy-Recycling Consensus Algorithm to Enhance Stability with Deep Learning
Zhen Xia, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
ISPEC6
2023 Free Fine-tuning: A Plug-and-Play Watermarking Scheme for Deep Neural Networks
abstract
Watermarking has been widely adopted for protecting the intellectual property (IP) of Deep Neural Networks (DNN) to defend the unauthorized distribution. Unfortunately, studies have shown that the popular data-poisoning DNN watermarking scheme via tedious model fine-tuning on a poisoned dataset (carefully-crafted sample-label pairs) is not efficient in tackling the tasks on challenging datasets and production-level DNN model protection. To address the aforementioned limitation, in this paper, we propose a plug-and-play watermarking scheme for DNN models by injecting an independent proprietary model into the target model to serve the watermark embedding and ownership verification. In contrast to the prior studies, our proposed method by incorporating a proprietary model is free of target model fine-tuning without involving any parameters update of the target model, thus the fidelity is well preserved and scalable to challenging real tasks. Experimental results on real-world challenging datasets (e.g., ImageNet) and production-level DNN models demonstrated its effectiveness, fidelity w.r.t. the functionality preservation of the target model, robustness against popular watermark removal attacks, and the plug-and-play deployment. The source code and models are available at https://github.com/AntigoneRandy/PTYNet.
Run Wang 0001, Jixing Ren, Boheng Li, Tianyi She, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ACM Multimedia6
2023 MMDSSE: Multi-client and Multi-keyword Dynamic Searchable Symmetric Encryption for Cloud Storage
abstract
Since data outsourcing poses privacy concerns with data leakage, searchable symmetric encryption (SSE) has emerged as a powerful solution that enables clients to perform query operations on encrypted data while preserving their privacy. Dynamic SSE schemes have been proposed to handle update operations. However, it is shown that updates might increase the risk of information leakage. Meanwhile, to meet the requirement of real-world applications, it is desirable to have the searchable encryption scheme which supports both multiple clients and multi-keyword queries. To address these issues, this paper proposes MMDSSE, a multi-client forward secure dynamic SSE scheme that supports multi-keyword queries. MMDSSE allows the clients narrow down the results by providing an arbitrary subset of the entire archive, and thus suitable for cloud storage environment. Security analysis and experimental evaluations show that MMDSSE is secure and efficient.
Panyu Wu, Zhenfu Cao, Xiaolei Dong, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su
PST7
2023 MDPPC: Efficient Scalable Multiparty Delegated PSI and PSI Cardinality
abstract
Private Set Intersection (PSI) is one of the most important functions in secure multiparty computation (MPC). PSI protocols have been a practical cryptographic primitive and there are many privacy-preserving applications based on PSI protocols such as computing conversion of advertising and distributed computation. Private Set Intersection Cardinality (PSI-CA) is a useful variant of PSI protocol. PSI and PSI-CA allow several parties, each holding a private set, to jointly compute the intersection and cardinality, respectively without leaking any additional information. Nowadays, most PSI protocols mainly focus on two-party settings, while in multiparty settings, parties are able to share more valuable information and thus more desirable. On the other hand, with the advent of cloud computing, delegating computation to an untrusted server becomes an interesting problem. However, most existing delegated PSI protocols are unable to efficiently scale to multiple clients. In order to solve these problems, this paper proposes MDPPC, an efficient PSI protocol which supports scalable multiparty delegated PSI and PSI-CA operations. Security analysis shows that MDPPC is secure against semi-honest adversaries and it allows any number of colluding clients. For 15 parties with set size of 220on server side and 216on clients side, MDPPC costs only 81 seconds in PSI and 80 seconds in PSI-CA, respectively. The experimental results show that MDPPC has high scalability.
Xiaolei Dong, Zhenfu Cao, Yunbo Yang, Jun Zhou 0018, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001, Chunhua Su, Zongyang Hou
PST7
2023 Practical Single-Round Secure Wildcard Pattern Matching
Zhe Liu 0001, Liming Fang 0001
SEC6
2023 Efficient and Low Overhead Website Fingerprinting Attacks and Defenses based on TCP/IP Traffic
abstract
Website fingerprinting attack is an extensively studied technique used in a web browser to analyze traffic patterns and thus infer confidential information about users. Several website fingerprinting attacks based on machine learning and deep learning tend to use the most typical features to achieve a satisfactory performance of attacking rate. However, these attacks suffer from several practical implementation factors, such as a skillfully pre-processing step or a clean dataset. To defend against such attacks, random packet defense (RPD) with a high cost of excessive network overhead is usually applied. In this work, we first propose a practical filter-assisted attack against RPD, which can filter out the injected noises using the statistical characteristics of TCP/IP traffic. Then, we propose a list-assisted defensive mechanism to defend the proposed attack method. To achieve a configurable trade-off between the defense and the network overhead, we further improve the list-based defense by a traffic splitting mechanism, which can combat the mentioned attacks as well as save a considerable amount of network overhead. In the experiments, we collect real-life traffic patterns using three mainstream browsers, i.e., Microsoft Edge, Google Chrome, and Mozilla Firefox, and extensive results conducted on the closed and open-world datasets show the effectiveness of the proposed algorithms in terms of defense accuracy and network efficiency.
Guodong Huang, Chuan Ma 0001, Ming Ding 0001, Yuwen Qian, Chunpeng Ge 0001, Liming Fang 0001, Zhe Liu 0001
WWW6
2023 Efficient transformer with code token learner for code clone detection
Aiping Zhang, Liming Fang 0001, Chunpeng Ge 0001, Piji Li, Zhe Liu 0001
J. Syst. Softw.2
2022 FLForest: Byzantine-robust Federated Learning through Isolated Forest
abstract
Federated learning (FL) is a privacy-preserving distributed machine learning technique that allows clients to jointly train a global model under the coordination of cloud server. However, malicious clients can corrupt the global model to predict incorrect labels for testing examples. Currently, existing mainstream Byzantine-robust FL methods are vulnerable to various adaptive attacks, and violates the privacy principle of FL. Moreover, these schemes will be less robust in the face of targeted poisoning attacks with few samples and data distributions that are highly non-independent and identically distributed(non-IID). In this work, to address these issues, we propose a novel Byzantine-robust FL framework based on Isolated Forest. Specifically, before the start of each round, FLForest will calculate the divergences between the model update and the model update of the previous round to decide whether to activate the defense. After that, FLForest trains an isolated forest based on model updates after after dimensionality reduction. Model updates isolated with fewer splits will be considered as malicious model updates and excluded from the global model’s aggregation. Extensive experiments demonstrate that FLForest achieves better performance compared to baseline methods under highly non-IID distribution.
Liming Fang 0001
ICPADS3
2022 Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?
abstract
Training Deep Neural Networks (DNN) is a time-consuming process and requires a large amount of training data, which motivates studies working on protecting the intellectual property (IP) of DNN models by employing various watermarking techniques. Unfortunately, in recent years, adversaries have been exploiting the vulnerabilities of the employed watermarking techniques to remove the embedded watermarks. In this paper, we investigate and introduce a novel watermark removal attack, called AdvNP, against all the existing four different types of DNN watermarking schemes via input preprocessing by injecting Adversarial Naturalness-aware Perturbations. In contrast to the prior studies, our proposed method is the first work that generalizes all the existing four watermarking schemes well without involving any model modification, which preserves the fidelity of the target model. We conduct the experiments against four state-of-the-art (SOTA) watermarking schemes on two real tasks (e.g., image classification on ImageNet, face recognition on CelebA) across multiple DNN models. Overall, our proposed AdvNP significantly invalidates the watermarks against the four watermarking schemes on two real-world datasets, i.e., 60.9% on the average attack success rate and up to 97% in the worse case. Moreover, our AdvNP could well survive the image denoising techniques and outperforms the baseline in both the fidelity preserving and watermark removal. Furthermore, we introduce two defense methods to enhance the robustness of DNN watermarking against our AdvNP. Our experimental results pose real threats to the existing watermarking schemes and call for more practical and robust watermarking techniques to protect the copyright of pre-trained DNN models. The source code and models are available at ttps://github.com/GitKJ123/AdvNP.
Run Wang 0001, Lingzhou Mu, Jixing Ren, Shangwei Guo, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ACM Multimedia7
2022 FolketID: A Decentralized Blockchain-Based NemID Alternative Against DDoS Attacks
Wei-Yang Chiu, Weizhi Meng 0001, Wenjuan Li 0001, Liming Fang 0001
ProvSec4
2022 Recovering the Weights of Convolutional Neural Network via Chosen Pixel Horizontal Power Analysis
Weibin Wu 0003, Yanbin Li 0001, Lu Zhou 0002, Liming Fang 0001, Zhe Liu 0001
WASA (2)5
2022 Privacy Preserving Federated Learning Using CKKS Homomorphic Encryption
Fengyuan Qiu, Hao Yang 0062, Lu Zhou 0002, Chuan Ma 0001, Liming Fang 0001
WASA (1)5
2022 A Secure Revocable Fine-Grained Access Control and Data Sharing Scheme for SCADA in IIoT Systems
abstract
The supervisory control and data acquisition (SCADA) system is widely used in industrial control and the contemporary Industrial Internet of Things (IIoT). Unfortunately, due to its relatively weak design in terms of data security and access control, SCADA systems are becoming a favorite target for attackers. End-to-end encryption, such as SSL/TLS protocol, is used to protect the data transmission, but it cannot guarantee security in third-party cloud platforms. In this article, we propose a secure revocable fine-grained access control and data sharing scheme. This scheme not only ensures the confidentiality of the data but also enhances the access control of the SCADA system. Our scheme is based on three key observations. The common communication architecture of SCADA systems cannot protect data security itself. The security supports provided by industrial control protocols are limited. Moreover, the third-party cloud platforms are semitrusted. In addition, we have introduced digital signature technology to assure the integrity of the data in the SCADA system. We prove that our scheme is secure. This scheme has been experimentally evaluated to introduce negligible performance losses while improving data security in the SCADA system.
Weiting Zhang, Hanyi Zhang, Liming Fang 0001, Zhe Liu 0001, Chunpeng Ge 0001
IEEE Internet Things J.3
2022 Code Synthesis for Dataflow-Based Embedded Software Design
abstract
Model-driven methodology has been widely adopted in embedded software design, and Dataflow is a widely used computation model, with strong modeling and simulation ability supported in tools such as Ptolemy. However, its code synthesis support is quite limited, which restricts its applications in real industrial practice. In this article, we focus on the automatic code synthesis of Dataflow, and implementDFSynth, a code generator that could support most of the widely used modeling features, such as the expression type and Boolean switch, more efficiently. First, we disassemble the Dataflow model into actors embedded in if-else or switch-case statements based on the schedule analysis, which bridges the semantic gap between the code and the original Dataflow model. Then, we design well-designed templates for each actor, and synthesize well-structured executable C and Java codes with sequential code assembly. Compared to the existing C and Java code generators of Dataflow model in Ptolemy-II, and the C code generator in Simulink, the lines of code synthesized byDFSynthare decreased by an average of 99.7%, 81.4%, and 61.9%, and the execution time of the synthesized code byDFSynthis also decreased by an average of 76.2%, 56.8%, and 22.7%, respectively.
Zhuo Su 0005, Dongyan Wang, Yixiao Yang, Yu Jiang 0001, Wanli Chang 0001, Liming Fang 0001, Jia-Guang Sun 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.6
2022 A Secure and Authenticated Mobile Payment Protocol Against Off-Site Attack Strategy
abstract
Mobile payment system has been expected to provide more efficient and convenient payment methods. However, compared to traditional payments, mobile payment issues related to the security of electronic accounts and payment apps present serious challenges. In this paper, we find the potential security risks by analyzing the commonly used tokenized mobile payment method and put forward the corresponding off-site attack strategy. In this scenario, the attackers are not only limited to malicious third parties but also can be illegal merchants. To address the off-site attack, especially the potential attackers who may be malicious merchants, we also propose SALP, a secure and authenticated payment protocol, using time and position as necessary conditions for the payment confirmation. Furthermore, we leverage identity-based signature (IBS) to prevent altering the information and reduce the overhead of the third-party authentication. We conduct case studies to demonstrate that the SALP can effectively prevent the off-site payment attack without a trusted hardware environment. In particular, we finally argue that SALP does not bring additional system overhead without degrading the convenience of mobile payment.
Liming Fang 0001, Zhe Liu 0001, Changting Lin, Shouling Ji, Anni Zhou, Willy Susilo, Chunpeng Ge 0001
IEEE Trans. Dependable Secur. Comput.1
2022 Revocable Attribute-Based Encryption With Data Integrity in Clouds
abstract
Cloud computing enables enterprises and individuals to outsource and share their data. This way, cloud computing eliminates the heavy workload of local information infrastructure. Attribute-based encryption has become a promising solution for encrypted data access control in clouds due to the ability to achieve one-to-many encrypted data sharing. Revocation is a critical requirement for encrypted data access control systems. After outsourcing the encrypted attribute-based ciphertext to the cloud, the data owner may want to revoke some recipients that were authorized previously, which means that the outsourced attribute-based ciphertext needs to be updated to a new one that is under the revoked policy. The integrity issue arises when the revocation is executed. When a new ciphertext with the revoked access policy is generated by the cloud server, the data recipient cannot be sure that the newly generated ciphertext guarantees to be decrypted to the same plaintext as the originally encrypted data, since the cloud server is provided by a third party, which is not fully trusted. In this article, we consider a new security requirement for the revocable attribute-based encryption schemes: integrity. We introduce a formal definition and security model for the revocable attribute-based encryption with data integrity protection (RABE-DI). Then, we propose a concrete RABE-DI scheme and prove its confidentiality and integrity under the defined security model. Finally, we present an implementation result and provide performance evaluation which shows that our scheme is efficient and practical.
Chunpeng Ge 0001, Willy Susilo, Joonsang Baek, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.6
2022 A Verifiable and Fair Attribute-Based Proxy Re-Encryption Scheme for Data Sharing in Clouds
abstract
To manage outsourced encrypted data sharing in clouds, attribute-based proxy re-encryption (ABPRE) has become an elegant primitive. In ABPRE, a cloud server can transform an original recipient’s ciphertext to a new one of a shared user’s. As the transformation is computation consuming, a malicious cloud server may return an incorrect re-encrypted ciphertext to save its computation resources. Moreover, a shared user may accuse the cloud server of returning an incorrect re-encrypted ciphertext to refuse to pay the cost of using the cloud service. However, existing ABPRE schemes do not support a mechanism to achieve verifiability and fairness. In this article, a novel verifiable and fair attribute-based proxy re-encryption (VF-ABPRE) scheme is introduced to support verifiability and fairness. The verifiability enables a shared user to verify whether the re-encrypted ciphertext returned by the server is correct and the fairness ensures a cloud server escape from malicious accusation if it has indeed conducted the re-encryption operation honestly. Additionally, we conduct a performance experiment to show the efficiency and practicality of the new VF-ABPRE scheme.
Chunpeng Ge 0001, Willy Susilo, Joonsang Baek, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.6
2022 WebEnclave: Protect Web Secrets From Browser Extensions With Software Enclave
abstract
Browser extensions are widely used nowadays to customize users’ browsers with more functionalities, meanwhile introduce potential risks due to escalated privileges. Existing security mechanisms, such as Same Origin Policy and Content Security Policy, do not apply to browser extensions that can read and write on web applications at any time. In spite of the state-of-the-art industrial efforts that rely on centralized management to inspect and detect malicious behaviors massively, the detection-based method cannot analyze fast-evolving behaviors of malicious browser extensions. To this end, we adopt a novel approach to protect users from malicious browser extensions, where we consider the problem of malicious extensions on the side of web applications. From a high level point of view, web developers are allowed to specify sensitive parts in a web application by using our provided software enclave. With our proposed WebEnclave extension installed, when users visit a web application, sensitive information required for the web application to work normally is sealed into an isolated world locally that malicious extensions cannot access. Extensive evaluation of our built prototype shows it can effectively protect user secrets from malicious extensions with negligible performance overhead and usability inconvenience. We also publish source codes for public use.
Xinyu Wang 0007, Yuefeng Du 0001, Cong Wang 0001, Qian Wang 0002, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.5
2022 A Large-Scale Empirical Study on the Vulnerability of Deployed IoT Devices
abstract
The Internet of Things (IoT) has become ubiquitous and greatly affected peoples’ daily lives. With the increasing development of IoT devices, the corresponding security issues are becoming more and more challenging. Such a severe security situation raises the following questions that need urgent attention: What are the primary security threats that IoT devices face currently? How do vendors and users deal with these threats? In this article, we aim to answer these critical questions through a large-scale systematic study. Specifically, we perform a ten-month-long empirical study on the vulnerability of 1,362,906 IoT devices varying from six types. The results show sufficient evidence that N-days vulnerability is seriously endangering the IoT devices: 385,060 (28.25 percent) devices suffer from at least one N-days vulnerability. Moreover, 2669 of these vulnerable devices may have been compromised by botnets. We further reveal the massive differences among five popular IoT search engines:Shodan[1],Censys[2], [3],Zoomeye[4],Fofa[5], andNTI[6]. To study whether vendors and users adopt defenses against the threats, we measure the security of MQTT [7] servers, and identify that 12740 (88 percent) MQTT servers have no password protection. Our analysis can serve as an important guideline for investigating the security of IoT devices, as well as advancing the development of a more secure environment for IoT systems.
Shouling Ji, Wei-Han Lee, Changting Lin, Haiqin Weng, JingZheng Wu, Pan Zhou 0001, Liming Fang 0001, Raheem A. Beyah
IEEE Trans. Dependable Secur. Comput.8
2021 Learn To Align: A Code Alignment Network For Code Clone Detection
abstract
Deep learning techniques have achieved promising results in code clone detection in the past decade. However, existing techniques merely focus on how to extract more dis-criminative features from source codes, while some issues, such as structural differences of functional similar codes, are not explicitly addressed. This phenomenon is common when programmers copy a code segment along with adding or removing several statements, or use a more flexible syntax structure to implement the same function. In this paper, we unify the aforementioned problems as the problem of code misalignment, and propose a novel code alignment network to tackle it. We design a bi-directional causal convolutional neural network to extract feature representations of code fragments with rich structural and semantical information. After feature extraction, our method learns to align the two code fragments in a data-driven fashion. We present two independent strategies for code alignment, namely attention-based alignment and sparse reconstruction-based alignment. Both two strategies strive to learn an alignment matrix that represents the correspondences between two code fragments. Our method outperforms state-of-the-art methods in terms of F1 score by 0.5% and 3.1 % on BigCloneBench and OJClone, respectively11Our code is available at https://github.com/ArcticHare105/Code-Alignment.
Aiping Zhang, Kui Liu 0001, Liming Fang 0001, Qianjun Liu, Xinyu Yun, Shouling Ji
APSEC3
2021 Turbo: Fraud Detection in Deposit-free Leasing Service via Real-Time Behavior Network Mining
abstract
Online deposit-free leasing service has witnessed rapid growth in China and shows a promising market in the future. While eliminating the requirement of a deposit does attract more users to the service, it also lowers the cost for fraudsters. Since the emergence of this service is relatively new, there are few works in literature focusing on detecting fraud transactions in it. Existing efforts mainly fall into hard-coded solutions such as block-listing or scorecard methods, which can be impotent in the face of the diverse fraud tactics, e.g., identity theft, or even suffering concept drift problem as the tactics evolve. In this paper, we contribute Turbo, an efficient graph-based anti-fraud system, to fully exploit the abundant user behavior logs in a real-time manner. Turbo is able to additionally make use of the implicit user relationships beyond the user features in the logs. To capture the user relationships, we first propose a novel algorithm to construct a time-evolving user behavior network called BN. Empirical analysis demonstrates that fraudsters in BN exhibit unique temporal aggregation and homophilic patterns, which inspires us to develop a novel heterogeneous adaptive graph neural network algorithm called HAG. Specifically, in HAG two graph operators are presented to mitigate the over-smoothing problem and make better use of the heterogeneous behavior relations in BN. Extensive experiments on a real-world dataset show that our method outperforms state-of-the-art methods significantly and can give a response in seconds for each detection request.
Sihao Hu, Xuhong Zhang 0002, Junfeng Zhou, Shouling Ji, Zhao Li 0007, Qinming He, Liming Fang 0001
ICDE10
2021 Revocable Identity-Based Broadcast Proxy Re-Encryption for Data Sharing in Clouds
abstract
Cloud computing has become prevalent due to its nature of massive storage and vast computing capabilities. Ensuring a secure data sharing is critical to cloud applications. Recently, a number of identity-based broadcast proxy re-encryption (IB-BPRE) schemes have been proposed to resolve the problem. However, the IB-BPRE requires a cloud user (Alice) who wants to share data with a bunch of other users (e.g., colleagues) to participate the group shared key renewal process because Alice's private key is a prerequisite for shared key generation. This, however, does not leverage the benefit of cloud computing and causes the inconvenience for cloud users. Therefore, a novel security notion named revocable identity-based broadcast proxy re-encryption (RIB-BPRE) is presented to address the issue of key revocation in this work. In a RIB-BPRE scheme, a proxy can revoke a set of delegates, designated by the delegator, from the re-encryption key. The performance evaluation reveals that the proposed scheme is efficient and practical.
Chunpeng Ge 0001, Zhe Liu 0001, Jinyue Xia, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.4
2021 Secure Keyword Search and Data Sharing Mechanism for Cloud Computing
abstract
The emergence of cloud infrastructure has significantly reduced the costs of hardware and software resources in computing infrastructure. To ensure security, the data is usually encrypted before it's outsourced to the cloud. Unlike searching and sharing the plain data, it is challenging to search and share the data after encryption. Nevertheless, it is a critical task for the cloud service provider as the users expect the cloud to conduct a quick search and return the result without losing data confidentiality. To overcome these problems, we propose a ciphertext-policy attribute-based mechanism with keyword search and data sharing (CPAB-KSDS) for encrypted cloud data. The proposed solution not only supports attribute-based keyword search but also enables attribute-based data sharing at the same time, which is in contrast to the existing solutions that only support either one of two features. Additionally, the keyword in our scheme can be updated during the sharing phase without interacting with the PKG. In this article, we describe the notion of CPAB-KSDS as well as its security model. Besides, we propose a concrete scheme and prove that it is against chosen ciphertext attack and chosen keyword attack secure in the random oracle model. Finally, the proposed construction is demonstrated practical and efficient in the performance and property comparison.
Chunpeng Ge 0001, Willy Susilo, Zhe Liu 0001, Jinyue Xia, Pawel Szalachowski, Liming Fang 0001
IEEE Trans. Dependable Secur. Comput.6
2021 ANCS: Automatic NXDomain Classification System Based on Incremental Fuzzy Rough Sets Machine Learning
abstract
Botmasters generate a large number of malicious algorithmically generated domains (mAGDs) through domain generation algorithms (DGAs) to infect a large number of hosts on a network, which creates inconvenience in people's network lives. The workload of detecting mAGDs by collecting the responses of the domain name system (DNS) is considerable. In this article, we propose a system named the automatic NXDomain classification system (ANCS) that can automatically identify and classify the nonexistent domain (NXD) as benign or malicious by studying the features extracted from benign NXDs (bNXDs) and mAGDs. The ANCS uses online, incremental, and fuzzy rough sets machine learning to improve the time, memory, false positive rate, false negative rate, and accuracy of the detection process. First, an online and incremental algorithm can reduce the training time. Second, the addition of fuzzy rough sets can dynamically adjust the degree of the membership function, optimizing the weight distribution of each feature, and further, improving the classification accuracy. The experimental evaluation shows that the ANCS can reach a very high classification accuracy at a low false positive rate and a low false negative rate, which has good practicability. Moreover, both time and memory are well guaranteed, and the ANCS also has good generalization performance, making up for sensitive points of noisy samples and the lack of nonincremental machine learning.
Liming Fang 0001, Xinyu Yun, Changchun Yin, Weiping Ding 0001, Lu Zhou 0002, Zhe Liu 0001, Chunhua Su
IEEE Trans. Fuzzy Syst.1
2021 A Practical Model Based on Anomaly Detection for Protecting Medical IoT Control Services Against External Attacks
abstract
The application of the Internet of Things (IoT) in medical field has brought unprecedented convenience to human beings. However, attackers can use device configuration vulnerabilities to hijack devices, control services, steal medical data, or make devices operate illegally. These restrictions have led to huge security risks for IoT, and have challenged the management of critical infrastructure services. Based on these problems, this article proposes an anomaly detection system for detecting illegal behavior (DIB) in medical IoT environment.The DIB system can analyze data packets transmitted by medical IoT devices, learn operation rules by itself, and remind management personnel that the device is in an abnormal operation state to ensure the safety of control service. We further propose a model that is based on rough set theory and fuzzy core vector machine (FCVM) to improve the accuracy of DIB classification anomalies. Experimental results show that the R-FCVM is effective.
Liming Fang 0001, Yang Li 0103, Zhe Liu 0001, Changchun Yin, Zehong Cao
IEEE Trans. Ind. Informatics1
2021 A Hybrid Fuzzy Convolutional Neural Network Based Mechanism for Photovoltaic Cell Defect Detection With Electroluminescence Images
abstract
In the intelligent manufacturing process of solar photovoltaic (PV) cells, the automatic defect detection system using the Industrial Internet of Things (IIoT) smart cameras and sensors cooperated in IIoT has become a promising solution. Many works have been devoted to defect detection of PV cells in a data-driven way. However, because of the subjectivity and fuzziness of human annotation, the data contains a high quantity of noise and unpredictable uncertainties, which creates great difficulties in automatic defect detection. To address this problem, we propose a novel architecture named fuzzy convolution, which integrates fuzzy logic and convolution operations at microscopic level. Combining the proposed fuzzy convolution with the regular convolution, we build a network called Hybrid Fuzzy Convolutional Neural Network (HFCNN). Compared with convolutional neural networks (CNNs), HFCNN can address the uncertainties of PV cell data to improve the accuracy with fewer parameters, making it possible to apply our method in smart cameras. Experimental results on a public dataset show the superiority of our proposed method compared with CNNs.
Chunpeng Ge 0001, Zhe Liu 0001, Liming Fang 0001, Huading Ling, Aiping Zhang, Changchun Yin
IEEE Trans. Parallel Distributed Syst.3
2020 Secure Door on Cloud: A Secure Data Transmission Scheme to Protect Kafka's Data
abstract
Apache Kafka, which is a high-throughput distributed message processing system, has been leveraged by the majority of enterprise for its outstanding performance. Unlike common cloud-based access control architectures, Kafka service providers often need to build their systems on other enterprises' high-performance cloud platforms. However, since the cloud platform belongs to a third party, it is not necessarily reliable. Paradoxically, it has been demonstrated that Kafka's data is stored in the cloud in the plaintext form, and thus poses a serious risk of user privacy leakage. In this paper, we propose a secure fine-grained data transmission scheme called Secure Door on Cloud (SDoC) to protect the data from being leaked in Kafka. SDoC is not only more secure than Kafka's built-in security mechanism, but also can effectively prevent third-party cloud from stealing plaintext data. To evaluate the performance of the SDoC, we simulate normal inter-entity communication and show that Kafka with SDoC integration has a lower data transfer time overhead than that of Kafka with built-in security mechanism opened.
Hanyi Zhang, Liming Fang 0001, Keyu Jiang, Weiting Zhang, Lu Zhou 0002
ICPADS2
2020 ELPPS: An Enhanced Location Privacy Preserving Scheme in Mobile Crowd-Sensing Network Based on Edge Computing
abstract
Mobile Crowd-Sensing (MCS) is gradually extended to the edge network to reduce the delay of data transmission and improve the ability of data processing. However, a challenge is that there are still loopholes in the protection of privacy data, especially in location-based services. The attacker can reconstruct the location relationship network among the correlation about the environment information, identity information, and other sensing data provided by mobile users. Moreover, in the edge environment, this kind of attack is more accurate and more threatening to the location privacy information. To solve this problem, we propose a location privacy protection scheme (ELPPS) for a mobile crowd-sensing network in the edge environment, to protect the position correlation weight between sensing users through differential privacy. We use the grid anonymous algorithm to confuse the location information in order to reduce the computing cost of edge nodes. The experiment results show that the proposed framework can effectively protect the location information of the sensing users without reducing the availability of the sensing task results, and has a low delay.
Yang Li 0103, Liming Fang 0001
TrustCom3
2020 Ciphertext-Policy Attribute-Based Encryption with Multi-Keyword Search over Medical Cloud Data
abstract
Over the years, public health has faced a large number of challenges like COVID-19. Medical cloud computing is a promising method since it can make healthcare costs lower. The computation of health data is outsourced to the cloud server. If the encrypted medical data is not decrypted, it is difficult to search for those data. Many researchers have worked on searchable encryption schemes that allow executing searches on encrypted data. However, many existing works support single-keyword search. In this article, we propose a patient-centered fine-grained attribute-based encryption scheme with multi-keyword search (CP-ABEMKS) for medical cloud computing. First, we leverage the ciphertext-policy attribute-based technique to construct trapdoors. Then, we give a security analysis. Besides, we provide a performance evaluation, and the experiments demonstrate the efficiency and practicality of the proposed CP-ABEMKS.
Changchun Yin, Hao Wang 0189, Lu Zhou 0002, Liming Fang 0001
TrustCom4
2020 A privacy preserve big data analysis system for wearable wireless sensor network
Chunpeng Ge 0001, Changchun Yin, Zhe Liu 0001, Liming Fang 0001, Juncen Zhu, Huading Ling
Comput. Secur.4
2020 THP: A Novel Authentication Scheme to Prevent Multiple Attacks in SDN-Based IoT Network
abstract
SDN has provided significant convenience for network providers and operators in cloud computing. Such a great advantage is extending to the Internet of Things network. However, it also increases the risk if the security of an SDN network is compromised. For example, if the network operator's permission is illegally obtained by a hacker, he/she can control the entry of the SDN network. Therefore, an effective authentication scheme is needed to fit various application scenarios with high-security requirements. In this article, we design, implement, and evaluate a new authentication scheme called the hidden pattern (THP), which combines graphics password and digital challenge value to prevent multiple types of authentication attacks at the same time. We examined THP in the perspectives of both security and usability, with a total number of 694 participants in 63 days. Our evaluation shows that THP can provide better performance than the existing schemes in terms of security and usability.
Liming Fang 0001, Yang Li 0103, Xinyu Yun, Zhenyu Wen, Shouling Ji, Weizhi Meng 0001, Zehong Cao, Muhammad Tanveer 0001
IEEE Internet Things J.1
2020 A Secure and Fine-Grained Scheme for Data Security in Industrial IoT Platforms for Smart City
abstract
With the high popularity of IoT devices, industrial IoT platforms, such as smart factories and oilfield industrial control systems, have become a new trend in the development of smart city. Although various manufacturers pay wide attention to the different functional requirements of IoT platforms, they seldom consider security issues, especially in terms of data security, which has led to a large number of cases of privacy leakage. Some works have been made to provide secure and reliable communication solutions for industrial IoT platforms, unfortunately, as different communication protocols and interaction models are adopted in different scenarios, these solutions are mainly isolated and fragmented. Therefore, it is an urgent challenge to construct a universal cross-platform secure communication scheme for industrial IoT platforms. In this article, we analyze the logic and requirements of different industrial IoT scenarios to abstracts them into a universal model. We summarize the possible attacks on different industrial IoT platforms and design a security scheme to capture these attacks based on the conditional proxy re-encryption primitive. The proposed scheme ensures that data cannot be accessed by an unauthorized user. We also evaluate the security and performance of our scheme, and the experimental results show that our scheme can achieve the functionality and security requirements with low overhead.
Liming Fang 0001, Hanyi Zhang, Chunpeng Ge 0001, Liang Liu 0006, Zhe Liu 0001
IEEE Internet Things J.1
2020 A physiological and behavioral feature authentication scheme for medical cloud based on fuzzy-rough core vector machine
Liming Fang 0001, Changchun Yin, Lu Zhou 0002, Yang Li 0103, Chunhua Su, Jinyue Xia
Inf. Sci.1
2020 A blockchain based decentralized data security mechanism for the Internet of Things
Chunpeng Ge 0001, Zhe Liu 0001, Liming Fang 0001
J. Parallel Distributed Comput.3
2020 Secure Transmission of Compressed Sampling Data Using Edge Clouds
abstract
Cloud capability is considered to be extended to the edge of the Internet for improving the security of data transmission. Compressive sensing (CS) has been widely studied as a built-in privacy-preserving layer to provide some cryptographic features while sampling and compressing, including data confidentiality guarantees and data integrity guarantees. Unfortunately, most existing CS-based ciphers are too lightweight or highly complex to meet the requirements of both high security of transmitting the captured data over the Internet and low energy consumption of sensing devices in the Internet of Things (IoT). In this article, a secure transmission framework for CS data by combining CS-based cipher and edge computing is proposed. From the perspective of security, the double-layer encryption mechanism and double-layer authentication mechanism are rooted in it by performing some privacy-preserving operations, including CS-based encryption, CS-based hash, information splitting, strong encryption, and feature extraction. Most significantly, the proposed framework is very useful for resource-limited IoT applications.
Yushu Zhang 0001, Ping Wang 0029, Liming Fang 0001, Xing He 0001, Bing Chen 0002
IEEE Trans. Ind. Informatics3
2020 Privacy Protection for Medical Data Sharing in Smart Healthcare
abstract
In virtue of advances in smart networks and the cloud computing paradigm, smart healthcare is transforming. However, there are still challenges, such as storing sensitive data in untrusted and controlled infrastructure and ensuring the secure transmission of medical data, among others. The rapid development of watermarking provides opportunities for smart healthcare. In this article, we propose a new data-sharing framework and a data access control mechanism. The applications are submitted by the doctors, and the data is processed in the medical data center of the hospital, stored in semi-trusted servers to support the selective sharing of electronic medical records from different medical institutions between different doctors. Our approach ensures that privacy concerns are taken into account when processing requests for access to patients’ medical information. For accountability, after data is modified or leaked, both patients and doctors must add digital watermarks associated with their identification when uploading data. Extensive analytical and experimental results are presented that show the security and efficiency of our proposed scheme.
Liming Fang 0001, Changchun Yin, Juncen Zhu, Chunpeng Ge 0001, Muhammad Tanveer 0001, Alireza Jolfaei, Zehong Cao
ACM Trans. Multim. Comput. Commun. Appl.1
2018 A CCA-secure key-policy attribute-based proxy re-encryption in the adaptive corruption model for dropbox data sharing system
Chunpeng Ge 0001, Willy Susilo, Liming Fang 0001, Yun Q. Shi 0001
Des. Codes Cryptogr.3
2018 A proxy broadcast re-encryption for cloud data sharing
Maosheng Sun, Chunpeng Ge 0001, Liming Fang 0001
Multim. Tools Appl.3
2018 A Secure Multimedia Data Sharing Scheme for Wireless Network
abstract
A large number of wireless devices like WiFi cameras and 4G robots have been deployed in the rapidly growing wireless network such as Internet of Things. All of the devices (sensors) are collecting and analyzing multimedia data all the time while they are actively working, and it is also required to share data among these the sensors. Typically, the wireless data is transmitted through the network gateway or the cloud platforms. In such a wireless environment, if there is no appropriate protection to the data, it is easy to cause potential data leakage. In reality, the owner of the sensor might only want to share the multimedia data stored in the sensor with a trusted third party (e.g., a family member or a coworker) through an internet gateway or the cloud platform. Ideally, the gateway or the cloud platform in the wireless network should transform one user’s encrypted data (wireless multimedia data) directly into another ciphertext under a set of new users (e.g., a trusted third party) without accessing the user’s plaintext data. In this work, a new secure notion called fuzzy-conditional proxy broadcast re-encryption (FC-PBRE) is presented to address the concern. In a FC-PBRE scheme, the proxy (the gateway or cloud server) uses a broadcast re-encryption key to re-encrypt the encrypted wireless multimedia data which can be decrypted by a set of delegatees if and only if the broadcast key’s conditional set W is close to the conditional set W′ of the ciphertext. With the FC-PBRE scheme, the wireless multimedia data is not disclosed and cannot be learnt by the proxy (the gateway or cloud server). In this paper, we first present the definition of security against chosen-ciphertext attacks for FC-PBRE. Second, we propose an efficient fuzzy-conditional proxy broadcast re-encryption scheme. Third, we prove that our FC-PBRE scheme is CCA-secure in the random oracle model based on the Decisional nBDHE assumption.
Liming Fang 0001, Liang Liu 0006, Jinyue Xia, Maosheng Sun
Secur. Commun. Networks1
2017 Provably Secure Dynamic ID-Based Anonymous Two-Factor Authenticated Key Exchange Protocol With Extended Security Model
abstract
Authenticated key exchange (AKE) protocol allows a user and a server to authenticate each other and generate a session key for the subsequent communications. With the rapid development of low-power and highly-efficient networks, such as pervasive and mobile computing network in recent years, many efficient AKE protocols have been proposed to achieve user privacy and authentication in the communications. Besides secure session key establishment, those AKE protocols offer some other useful functionalities, such as two-factor user authentication and mutual authentication. However, most of them have one or more weaknesses, such as vulnerability against lost-smart-card attack, offline dictionary attack, de-synchronization attack, or the lack of forward secrecy, and user anonymity or untraceability. Furthermore, an AKE scheme under the public key infrastructure may not be suitable for light-weight computational devices, and the security model of AKE does not capture user anonymity and resist lost-smart-card attack. In this paper, we propose a novel dynamic ID-based anonymous two-factor AKE protocol, which addresses all the above issues. Our protocol also supports smart card revocation and password update without centralized storage. Further, we extend the security model of AKE to support user anonymity and resist lost-smart-card attack, and the proposed scheme is provably secure in extended security model. The low-computational and bandwidth cost indicates that our protocol can be deployed for pervasive computing applications and mobile communications in practice.
Qi Xie 0001, Duncan S. Wong, Guilin Wang, Xiao Tan 0003, Kefei Chen, Liming Fang 0001
IEEE Trans. Inf. Forensics Secur.6
2016 A Key-Policy Attribute-Based Proxy Re-Encryption Without Random Oracles
abstract
A conditional proxy re-encryption (CPRE) scheme enables the proxy to convert a ciphertext from Alice to Bob, if the ciphertext satisfies one condition set by Alice. To improve the issue of more fine-grained on the condition set, Fang, Wang, Ge and Ren proposed a new primitive named Interactive conditional PRE with fine grain policy (ICPRE-FG) in 2011, and left an open problem on how to construct CCA-secure ICPRE-FG without random oracles. In this paper, we answer this open problem affirmatively by presenting a new construction of CCA-secure key-policy attribute-based PRE (KP-ABPRE) without random oracles. In this paper, we enhance the security model of Fang's ICPRE-FG scheme by allowing the adversary to make some extra queries, which do not help them win the game trivially. Finally, we present a CCA-secure KP-ABPRE without random oracles under the 3-weak decisional bilinear Diffie–Hellman inversion(3-wDBDHI) assumption.
Chunpeng Ge 0001, Willy Susilo, Liming Fang 0001, Yongjun Ren
Comput. J.5
2015 A ciphertext-policy attribute-based proxy re-encryption scheme for data sharing in public clouds
abstract
SUMMARY Ciphertext‐policy attribute‐based proxy re‐encryption (CP‐ABPRE) extends the traditional Proxy Re‐Encryption (PRE) by allowing a semi‐trusted proxy to transform a ciphertext under an access policy to another ciphertext with the same plaintext under a new access policy (i.e., attribute‐based re‐encryption). The proxy, however, learns nothing about the underlying plaintext. CP‐ABPRE has many real world applications, such as fine‐grained access control in cloud storage systems and medical records sharing among different hospitals. All the existing CP‐ABPRE schemes are leaving chosen‐ciphertext attack (CCA) security as an interesting open problem. This paper, for the first time, proposes a new CP‐ABPRE scheme to tackle the problem. The new scheme supports attribute‐based re‐encryption with any monotonic access structures. Despite being constructed in the random oracle model, our scheme can be proven CCA secure under the decisional q‐parallel bilinear Diffie–Hellman exponent assumption. Copyright © 2014 John Wiley & Sons, Ltd.
Kaitai Liang, Liming Fang 0001, Duncan S. Wong, Willy Susilo
Concurr. Comput. Pract. Exp.2
2013 Fuzzy conditional proxy re-encryption
Liming Fang 0001, Chunpeng Ge 0001, Yongjun Ren
Sci. China Inf. Sci.1
2013 Public key encryption with keyword search secure against keyword guessing attacks without random oracle
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
Inf. Sci.1
2012 Chosen-ciphertext secure anonymous conditional proxy re-encryption with keyword search
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
Theor. Comput. Sci.1
2011 Interactive conditional proxy re-encryption with fine grain policy
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
J. Syst. Softw.1
2009 A Secure Channel Free Public Key Encryption with Keyword Search Scheme without Random Oracle
Liming Fang 0001, Willy Susilo, Chunpeng Ge 0001
CANS1
2009 Anonymous Conditional Proxy Re-encryption without Random Oracle
Liming Fang 0001, Willy Susilo
ProvSec1