VLDB 2026 Research / reviewers in the wild / expert
Hanlin Zhang 0001
dblp:60/7872-1
· DBLP profile ↗
61ranked-venue papers
4as first author
45since 2021 · last 2026
0000-0001-8869-6863ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 3 first-author · 17 since 2021Security and privacy · 11 · 10 since 2021Systems, architecture and hardware · 7 · 5 since 2021Databases, data management, data science and information retrieval · 6 · 3 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-enhanced clustered federated learning with secure clustering
Xinjie Liu, Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Xidan Zhang, Liyan Shang |
J. Syst. Archit. | 2 |
| 2026 | Secure Outsourcing Scheme for FCM-PSO Based Medical Image Segmentation AlgorithmabstractMachine learning algorithm for multi-modal image segmentation is extensively employed in medical analysis and diagnosis. Clustering represents a mainstream approach for image segmentation, with the fuzzy c-means and particle swarm optimization (FCM-PSO) algorithm garnering significant attention. As image segmentation tasks have substantial computational costs, the outsourcing scheme offers an effective solution by leveraging cloud servers to execute complex computations. Given that medical images contain sensitive patient information, the image segmentation outsourcing scheme must ensure data privacy and confidentiality. In this paper, we propose a secure outsourcing scheme for the FCM-PSO based image segmentation algorithm through a novel sparse matrix encryption method. By analyzing each stage of the image segmentation algorithm, we delegate the computationally intensive task of calculating the Euclidean distance to an untrusted cloud server. We utilize sparse matrices to obscure the private image data. These matrices are created by incorporating multiple small-sized random invertible matrices, thereby circumventing the local storage of generation factors. Additionally, we implement a lightweight verification method to verify the correctness of returned results. Experimental results show that our scheme improves the efficiency of the image segmentation task by 29.99% to 49.50% with the increasing of image set, compared to the original algorithm executed locally. Xinrong Sun, Yunting Tao, Chunpeng Ge 0001, Chuan Ma 0001, Fanyu Kong 0002, Hanlin Zhang 0001, Jia Yu 0003 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Enhancing the Policy Generalization on OOD Tasks via Latent Variable Distribution Enhancement SamplerabstractIn standard reinforcement learning, since the uncertainty of task objectives is not adequately considered in the policy training, the policy achieves poor generalization for the out-of-distribution (OOD) tasks. Although considerable efforts have been made to enhance the generalization for OOD tasks, most of these methods overlook the structural information of task representations in latent space during the generation of extrapolative data, resulting in biased and blurred data embeddings, which then affect the policy generalization. To address this issue, we propose a context-based meta-reinforcement learning (meta-RL) method, namely latent variable distribution enhancement sampler (LVDES), which enhances the policy generalization on OOD tasks by providing efficient task representation space and accurate augmentation policy training data for OOD tasks. Specifically, the proposed LVDES consists of four modules: a task inference module, a task separation module, a latent enhancement module (LEM), and a policy module. The task inference module is used to identify the task. The task separation module (TSM) learns a representation space with highly structured separability. The LEM generates relevant additional task trajectories for augmenting policy training data. The policy module learns a policy to solve tasks. By using efficient task representation space and augmented trajectory data, the exploration efficiency and generalization of the policy for OOD tasks can be enhanced by our LVDES method. Extensive experiments are conducted to demonstrate the effectiveness of our method in comparison with existing methods on the MuJoCo and Meta-World benchmarks. The experimental results show that the task completion accuracy of our LVDES on OOD tasks is increased by 60.20%, with the average exploration time being reduced by 62.99% in comparison with the most effective current method, which demonstrates that our LVDES can achieve great policy generalization on OOD tasks. Jie Lin 0002, Xiangyuan Yang, Hanlin Zhang 0001, Peng Zhao 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2026 | KOG: A secret sharing-based scalable privacy-preserving training framework for decision trees
Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Hansong Xu, Kun Hua |
VLDB J. | 2 |
| 2025 | SMART: a practical and robust client-side RAP detection approachabstractRogue Access Points (RAPs) pose a persistent security threat to IEEE 802.11 Wireless Local Area Networks (WLANs). These attacks enable attackers to monitor, manipulate, and tamper with victims’ communications, resulting in significant privacy breaches and financial losses annually. Among the existing methods, client-based RAP detection has demonstrated greater effectiveness compared to admin-based approaches, primarily due to its wider applicability in real-world environments. However, existing series-model RAP detection methods often suffer from limited robustness and scope of application. To address these challenges, we propose SMART, an innovative series-model RAP detection method. SMART leverages special frame length sequences and arrival times as detection metrics, transforming the RAP detection problem into one of identifying malicious forwarding behavior. This is further simplified into the task of searching for specific sequences and analyzing their arrival times. By designing distinct frame length sequences and setting precise time windows, SMART effectively detects RAPs by identifying abnormal forwarding behavior. Extensive experiments demonstrate that SMART achieves a 100% detection rate in low and medium traffic scenarios and a 98.33% detection rate in high-traffic scenarios, performing reliably in both open and encrypted networks. Hanlin Zhang 0001, Qianqian Su, Xinrui Ge |
ICCCN | 3 |
| 2025 | SMCD: Privacy-preserving deep learning based malicious code detection
Gaoli Mu, Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002 |
Comput. Secur. | 2 |
| 2025 | Fedai: Federated recommendation system with anonymized interactions
Lingtao Wei, Fei Chen 0014, Hanlin Zhang 0001, Jia Yu 0003 |
Expert Syst. Appl. | 4 |
| 2025 | Towards efficient privacy-preserving conjunctive keywords search over encrypted cloud data
Xiaodong Xiao, Fanyu Kong 0002, Hanlin Zhang 0001, Jia Yu 0003 |
Future Gener. Comput. Syst. | 4 |
| 2025 | How to Securely Outsource the Multiple Kernel Fuzzy Clustering Task in Edge ComputingabstractFor the huge amount of data from the Internet of Things (IoT) devices, multiple kernel learning is a widely concerned issue in data analyzing, among which the multiple kernel fuzzy clustering (MKFC) algorithm is an effective approach for extracting linear features in high-dimensional space. For a time-consuming multiple kernel clustering task, it is meaningful to find a secure and efficient outsourcing scheme in the edge-end collaborative architecture, which utilizes edge computing resources while resisting untrusted edge servers. However, existing secure outsourcing schemes cannot align well with the distributed and real-time characteristics of edge computing due to their complex encryption processes. In this article, we propose a secure MKFC outsourcing scheme based on a novel matrix blinding method. The proposed novel matrix blinding method conducts two related encryption operations with disturbance terms, which avoids specific disturbance elimination computations, to reduce the computational burdens in the decryption phase. Additionally, we introduce a sampling verification method to detect the server’s deceptive behaviors. The theoretical analysis demonstrates that our scheme guarantees data privacy and has the capability to verify incorrect results. The experimental results indicate that our scheme is 6.73% superior to other schemes on average when conducting matrix outsourcing computation and enhances the efficiency of conducting the MKFC algorithm by 10.44% to 55.70% on different datasets. Xinrong Sun, Yunting Tao, Fanyu Kong 0002, Chunpeng Ge 0001, Qiuliang Xu, Hanlin Zhang 0001 |
IEEE Internet Things J. | 7 |
| 2025 | Privacy-Preserving Edge-Aided Eigenvalue Decomposition in Internet of ThingsabstractEigenvalue decomposition (EVD) is a fundamental yet time-consuming operation with extensive applications in Internet of Things (IoT). When the matrix dimension reaches millions, resource-limited IoT devices struggle to perform such computationally expensive operations. Edge computing, with its plentiful computing resources, offers an effective solution to this problem. However, privacy concerns arise because outsourced tasks may contain sensitive user data. In this article, we propose the first privacy-preserving, edge-assisted EVD outsourcing scheme that securely enables users to outsource EVD tasks to edge servers. We design a privacy-preserving matrix transformation method to encode the original data, ensuring that edge servers cannot access users’ private information. Additionally, we design a verification scheme that enables the user to verify the correctness of the results returned by the edge servers. Our protocol supports parallel computation by multiple edge servers, thus enhancing the efficiency of EVD. The feasibility of our proposed scheme is demonstrated through both theoretical and experimental perspectives. Hanlin Zhang 0001, Jie Lin 0002, Fan Liang 0003, Fanyu Kong 0002, Hansong Xu, Kun Hua |
IEEE Internet Things J. | 2 |
| 2025 | Enhancing adversarial transferability via transformation inference
Jie Lin 0002, Xiangyuan Yang, Hanlin Zhang 0001, Peng Zhao 0001 |
Neural Networks | 4 |
| 2025 | Rethinking the optimization objective for transferable adversarial examples from a fuzzy perspective
Xiangyuan Yang, Jie Lin 0002, Hanlin Zhang 0001, Peng Zhao 0001 |
Neural Networks | 3 |
| 2025 | SLIoTDI: Scalable and Lightweight IoT Device Identification With Session-Level Grayscale Fingerprinting and Adversarial TrainingabstractThe rapid expansion of the Internet of Things (IoT) has revolutionized various domains but also introduced critical security challenges, such as device spoofing and unauthorized access. These vulnerabilities underscore the urgent need for effective device identification to safeguard IoT networks and services. Despite ongoing research efforts, existing methods often fall short in scalability and lightweight design, which limits their deployment in real-world IoT environments. To address these challenges, we propose SLIoTDI, a novel scalable and lightweight IoT device identification approach. SLIoTDI uses session-level grayscale image-based fingerprinting and incorporates adversarial training with data augmentation to develop a robust and scalable feature extractor. Once trained, the extractor can generate fingerprints for unseen devices without retraining, ensuring adaptability to evolving IoT settings. Comprehensive experiments conducted on four public datasets and a real-world deployment validate the effectiveness of SLIoTDI, achieving the identification accuracies up to 99.98% and 99.16%, respectively. SLIoTDI is open-sourced to promote transparency and enable further research, offering a practical solution to enhance IoT security and device management in real-world applications. Zaiting Xu, Hanlin Zhang 0001, Hequn Xian |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Privacy-Preserving Group Closeness MaximizationabstractThis study explores the metric of group closeness centrality within the framework of social networks, a departure from the traditional analysis focused solely on the significance of individual nodes. Given the intricate dynamics observed in networks governed by various stakeholders, we introduce a framework that preserves privacy through the application of a greedy algorithm. This approach is designed to evaluate the collective influence of groups while ensuring the confidentiality of individual data. Furthermore, we employ Oblivious Random Access Memory (ORAM) [1] within cloud servers to conceal access patterns, thereby enhancing data privacy. Through comprehensive experimentation across three real-world social network datasets within the MP-SPDZ framework [2], dedicated to secure multi-party computation, we demonstrate the efficiency of our proposed methods. Sijia Cao, Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Leyun Yu |
ICCCN | 3 |
| 2024 | Privacy-Preserving Edge Assistance for Solving Matrix Eigenvalue ProblemabstractThe large-scale matrix eigenvalue computation, as a basic mathematical tool, has been widely used in many fields such as face recognition and data analysis. However, local terminal devices lack sufficient resources to undertake heavy computational tasks, which poses a challenge to the applications of eigenvalue computation. In this paper, we propose the first privacy-preserving edge-assisted computation scheme for solving the largest eigenvalue and corresponding eigenvector. We propose a privacy-preserving transformation method to protect data privacy and prevent edge servers from retrieving sensitive information. Mean-while, we design a verification scheme to ensure the correctness of the results returned by the edge servers. In addition, we design a distributed parallel computing scheme to ensure the efficiency of edge computation. Through theoretical analysis and simulation experiments, we verify the feasibility and efficiency of our proposed scheme. Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Leyun Yu |
ICCCN | 2 |
| 2024 | Fast Distributed Polynomial Multiplication Algorithm for Lattice-based Cryptographic Decryption In Blockchain SystemsabstractLattice-based Post-Quantum Cryptography (PQC) can effectively resist the quantum threat to blockchain's underlying cryptographic algorithms. Blockchain node decryption is one of the most commonly used cryptographic computations in blockchain systems, and polynomial multiplication, a time-consuming operation for decryption, is one of the factors limiting blockchain efficiency. This paper proposes a novel distributed computing algorithm for polynomial multiplication, applicable in blockchain decryption. By splitting polynomials into lower-degree terms and delegating tasks to distributed nodes, our approach reduces computation time. A novel verification strategy based on the Karatsuba algorithm ensures result accuracy. The experimental results demonstrate that our proposed scheme improves the execution efficiency of NTT and INTT operations by approximately 47.8% and 52.4%, and reduces Kyber decryption time by up to 23.5%. Hongjian Zhao, Yunting Tao, Fanyu Kong 0002, Guoyan Zhang, Hanlin Zhang 0001, Jia Yu 0003 |
ISPA | 5 |
| 2024 | Optimized verifiable delegated private set intersection on outsourced private datasets
Guangshang Jiang, Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Leyun Yu |
Comput. Secur. | 2 |
| 2024 | Privacy-preserving outsourcing scheme of face recognition based on locally linear embedding
Yunting Tao, Yuqun Li, Fanyu Kong 0002, Yuliang Shi, Ming Yang 0023, Jia Yu 0003, Hanlin Zhang 0001 |
Comput. Secur. | 7 |
| 2024 | PVFL: Verifiable federated learning and prediction with privacy-preserving
Benxin Yin, Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Leyun Yu |
Comput. Secur. | 2 |
| 2024 | Bot-DM: A dual-modal botnet detection method based on the combination of implicit semantic expression and graphical expressionabstractA botnet is a group of hijacked devices that conduct various cyberattacks, which is one of the most dangerous threats on the internet. Individuals or organizations can effectively detect botnets by analyzing abnormal behaviors in network traffic. Existing works focus on extracting the deterministic behavioral features, which highly rely on statistical features and existing botnet interaction structures, resulting in unsatisfactory detection accuracy, especially for unknown botnet traffic. The botnet detection method based on the original traffic bytes has more advantages in this regard, especially the use of mining payload information in the traffic to enhance the identification of abnormal botnet behavior is the focus of this study. In this paper, we propose a dual-mode botnet detection scheme, which takes the original traffic bytes as the object, one is to encode the implicit semantic relationship between the traffic bytes through a multi-layer Transformer encoder, and the other is the network traffic Image representation, the spatial relationship of traffic bytes is captured by a deep neural network, and then botnet detection is achieved by maximizing the mutual information between the two. We conduct comprehensive experiments with both known botnets and unknown botnets to evaluate our scheme. Experimental results show that for known botnets, our approach achieves 99.84% and 91.92% detection accuracy with CTU-13 and ISCX-2014 datasets, respectively, which is 3.04% and 2.54% more accurate compared with the state-of-art (DL). For unknown datasets, our scheme is 10.19% more accurate than the existing traffic representation. Guangli Wu, Hanlin Zhang 0001 |
Expert Syst. Appl. | 4 |
| 2024 | Secure Edge-Aided Singular Value Decomposition in Internet of ThingsabstractSingular Value Decomposition (SVD) is a widely applied foundational decomposition technique; however, its computational demands often exceed the capabilities of Internet of Things (IoT) devices. While leveraging edge servers can alleviate this load, it may introduce potential security vulnerabilities. Current secure outsourcing computation methods designed for cloud environments are challenging to adapt to distributed schemes in edge computing. Our research proposes a novel secure edge-assisted protocol for IoT devices solving SVD, aiming to conceal the Input/Output matrix and balance computational loads across multiple edge servers. The protocol ensures the confidentiality of original matrices and decomposition results, preventing exposure to edge servers. We conduct a comprehensive theoretical analysis of the protocol’s efficiency and security, substantiating its advancements through experiments. Hanlin Zhang 0001, Jie Lin 0002, Fan Liang 0003, Hansong Xu, Xing Liu 0013, Leyun Yu |
IEEE Internet Things J. | 2 |
| 2024 | MRFE: A Deep-Learning-Based Multidimensional Radio Frequency Fingerprinting Enhancement Approach for IoT Device IdentificationabstractNowadays, wireless networks have been widely deployed in our daily lives, providing people with convenient Internet of Things (IoT) services in healthcare, smart cities, transportation, etc. However, the open nature of communication mediums leaves IoT devices susceptible to unauthorized access by rogue devices, leading to significant privacy breaches and property damage. Among various security measures, radio frequency (RF) fingerprinting stands out as a promising device identification technique, owing to RF fingerprints’ uniqueness and forgery-resistant nature. Existing methods, however, overlook the structural relationship of a transmitter’s internal hardware paths, affecting the performance and efficiency of RF fingerprint identification. Inspired by the internal hardware paths, this article introduces a novel deep-learning-based RF fingerprinting approach, multidimensional RF fingerprinting enhancement (MRFE). MRFE enhances RF fingerprinting by dissecting raw IQ signals into multiple dimensions and proposing a novel fingerprint strengthen layer (FSL) to extract multidimensional fingerprints from the separate hardware paths, then leveraging attention mechanisms to fuse them into an enhanced RF fingerprint. The enhanced fingerprint captures more detailed physical hardware characteristics, effectively enhancing device identification accuracy. Our MRFE’s open-source implementation has been validated on the public ORACLE RF fingerprinting data set, achieving an impressive 99.33% accuracy in identifying 16 high-end bit-similar transmitters with identical configurations. Zaikai Yang, Hanlin Zhang 0001, Fei Chen 0014, Hequn Xian |
IEEE Internet Things J. | 3 |
| 2024 | Eliminating Rogue Access Point Attacks in IoT: A Deep Learning Approach With Physical-Layer Feature Purification and Device IdentificationabstractWi-Fi plays an essential role in various emerging Internet of Things (IoT) services and applications in smart cities and communities, such as IoT access, data transmission, and intelligent control. However, the openness of such wireless communication medium makes IoT extremely vulnerable to conventional Wi-Fi attacks, of which one is rouge access point (RAP) attacks. This attack brings about serious privacy leakage and property damage to IoT users, motivating in-depth research on RAP attack detection in both academic and industrial communities. Recently, the phase error extracted from channel state information (CSI) has been extensively explored as a physical-layer hardware fingerprint to realize RAP detection. However, in this article, we discover that the phase error suffers from an fingerprint fracture phenomenon (FFP), leading to the complete failure of environment noise filters applied in state-of-the-art approaches and resulting in unsatisfactory detection accuracy. Inspired by our significant discovery, we propose a deep-learning RAP detection method named DL-PEDR. It innovatively offers an Auto-NRK network to effectively remove the environment interference on phase error drift range and inputs it into a Self-ACC network as a reconstructed device fingerprint to accurately authenticate the access point (AP) identity. Through comprehensive evaluation experiments with 30 commonly used Wi-Fi routers, we demonstrate that DL-PEDR achieves a 100% device distinction rate and a 96.6% RAP detection rate under dynamic environments. Moreover, we collect and share more than 1.5 million pieces of CSI data to alleviate the need for large-scale public CSI data sets. Zaikai Yang, Hanlin Zhang 0001, Fei Chen 0014, Hequn Xian |
IEEE Internet Things J. | 3 |
| 2024 | Improving query efficiency of black-box attacks via the preference of deep learning models
Xiangyuan Yang, Jie Lin 0002, Hanlin Zhang 0001, Peng Zhao 0001 |
Inf. Sci. | 3 |
| 2024 | Secure Outsourcing Evaluation for Sparse Decision TreesabstractDecision tree classifiers are pervasively applied in a wide range of areas, such as healthcare, credit-risk assessment, spam detection, and many more. To ensure effectiveness and efficiency, clients usually choose to adopt classification services that are offered by model providers. However, the required data interactions in the evaluation process raise privacy concerns for both the provider and the client, indicating an imminent need for private decision tree evaluation (PDTE). Recently, some works, e.g., [1] (ESORICS'19) and [2] (NDSS'21), try to achieve PDTE by secure outsourcing computation. However, to hide the decision tree structure, [1] and [2] require non-complete decision trees to be made complete by padding dummy nodes, which lead to exponential (provider-side and cloud-side) computation and communication complexity in the depth of the decision tree. This is especially impractical for deep but sparse decision trees. In this paper, we propose a secure and efficient outsourced PDTE protocol with a focus on sparse trees. We avoid padding dummy nodes by vector dot products in outsourcing settings. Through experiments, we show the competitive performance of our design. Compared with [2] on Spambase dataset in the cloud-side, we are 486× more communication efficient in offline phase and 15× more communication efficient in online phase. Hanlin Zhang 0001, Xiangfu Song, Jie Lin 0002, Fanyu Kong 0002 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | SecureGAN: Secure Three-Party GAN TrainingabstractGenerating Adversarial Network (GAN) is a prominent unsupervised learning method that utilizes two competing neural networks to generate realistic data, which has been widely employed in image synthesis and data augmentation. Outsourcing GAN training to cloud servers can significantly reduce the computation load on local devices. Furthermore, in outsourcing settings, training data can be gathered from multiple users, leading to larger amounts of data and, as a result, improved training accuracy. However, outsourcing is associated with privacy risks, as training data often contains sensitive information. To address this problem, we propose SecureGAN, a privacy-preserving framework for GAN that aims to protect the privacy of the training input and output. We implement secure protocols based on replicated secret sharing technology to protect the privacy of the linear and nonlinear layers. We conduct experiments using the MP-SPDZ framework, and the results demonstrate the effectiveness of the proposed protocols. Sijia Cao, Hanlin Zhang 0001, Jie Lin 0002, Fanyu Kong 0002, Leyun Yu |
ICCCN | 2 |
| 2023 | Secure parallel Outsourcing Scheme for Large-scale Matrix Multiplication on Distributed Cloud ServersabstractLarge-scale matrix multiplication is a computational bottleneck in various applications including artificial intelligence and machine learning. Given the time complexity of O(n3) for matrix multiplication, large matrix computation is exceedingly time-consuming for the client-side user. By outsourcing this task to cloud servers with substantial computational resources, we can significantly reduce the client-side computational time. This paper presents a parallel matrix multiplication outsourcing scheme based on Cannon’s algorithm. By distributing the matrix across multiple cloud servers for parallel computation, we can get a significant efficiency speedup. Our scheme employs multiple cloud servers to perform parallel matrix computation, reducing the computational load by 89-97% when utilizing 4-16 servers as opposed to using a single server. We provide a comprehensive analysis of the scheme’s correctness, security, and verifiability, substantiating the benefits of our approach through the experimental data. Yinlong Wang, Yunting Tao, Fanyu Kong 0002, Zhaoquan Gu, Jia Yu 0003, Hanlin Zhang 0001 |
ICPADS | 6 |
| 2023 | Efficient Privacy-Preserving Multi-Functional Data Aggregation Scheme for Multi-Tier IoT SystemabstractThe proliferation of Internet of Things (IoT) devices has led to the generation of massive amounts of data that require efficient aggregation for analysis and decision-making. However, multi-tier IoT systems, which involve multiple layers of devices and gateways, face more complex security challenges in data aggregation compared to ordinary IoT systems. In this paper, we propose an efficient privacy-preserving multi-functional data aggregation scheme for multi-tier IoT architecture. The scheme supports privacy-preserving calculation of mean, variance, and anomaly proportion. The scheme uses the Paillier cryptosystem and the BLS algorithm for encryption and signature, and uses blinding techniques to keep the size of the IoT system secret. In order to make the Paillier algorithm more suitable for the IoT scenario, we also improve its efficiency of encryption and decryption. The performance evaluation shows that the scheme improves encryption efficiency by 43.7% and decryption efficiency by 45% compared to the existing scheme. Yunting Tao, Fanyu Kong 0002, Yuliang Shi, Jia Yu 0003, Hanlin Zhang 0001, Huiyi Liu |
ISCC | 5 |
| 2023 | Efficient, secure and verifiable outsourcing scheme for SVD-based collaborative filtering recommender system
Yunting Tao, Fanyu Kong 0002, Yuliang Shi, Jia Yu 0003, Hanlin Zhang 0001 |
Future Gener. Comput. Syst. | 5 |
| 2023 | A Deep-Reinforcement-Learning-Based Computation Offloading With Mobile Vehicles in Vehicular Edge ComputingabstractVehicular edge networks involve edge servers that are close to mobile devices to provide extra computation resource to complete the computation tasks of mobile devices with low latency and high reliability. Considerable efforts on computation offloading in vehicular edge networks have been developed to reduce the energy consumption and computation latency, in which roadside units (RSUs) are usually considered as the fixed edge servers (FESs). Nonetheless, the computation offloading with considering mobile vehicles as mobile edge servers (MESs) in vehicular edge networks still needs to be further investigated. To this end, in this article, we propose a Deep-Reinforcement-Learning-based computation offloading with mobile vehicles in vehicular edge computing, namely, Deep-Reinforcement-Learning-based computation offloading scheme (DRL-COMV), in which some vehicles (such as autonomous vehicle) are deployed and considered as the MESs that move in vehicular edge networks and cooperate with FESs to provide extra computation resource for mobile devices, in order to assist in completing the computation tasks of these mobile devices with great Quality of Experience (QoE) (i.e., low latency) for mobile devices. Particularly, the computation offloading model with considering both mobile and FESs is conducted to achieve the computation tasks offloading through vehicle-to-vehicle (V2V) communications, and a collaborative route planning is considered for these MESs to move in vehicular edge networks with objective of improving efficiency of computation offloading. Then, a Deep-Reinforcement-Learning approach with designing rational reward function is proposed to determine the effective computation offloading strategies for multiple mobile devices and multiple edge servers with objective of maximizing both QoE (i.e., low latency) for mobile devices. Through performance evaluations, our results show that our proposed DRL-COMV scheme can achieve a great convergence and stability. Additionally, our results also demonstrate that our DRL-COMV scheme also can achieve better both QoE and task offloading requests hit ratio for mobile devices in comparison with existing approaches (i.e., DDPG, IMOPSOQ, and GABDOS). Jie Lin 0002, Hanlin Zhang 0001, Xinyu Yang 0001, Peng Zhao 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Improving the transferability of adversarial examples via direction tuning
Xiangyuan Yang, Jie Lin 0002, Hanlin Zhang 0001, Xinyu Yang 0001, Peng Zhao 0001 |
Inf. Sci. | 3 |
| 2023 | Action density based frame sampling for human action recognition in videos
Jie Lin 0002, Zekun Mu, Tianqing Zhao, Hanlin Zhang 0001, Xinyu Yang 0001, Peng Zhao 0001 |
J. Vis. Commun. Image Represent. | 4 |
| 2022 | Privacy-Preserving and Verifiable Outsourcing Message Transmission and Authentication Protocol in IoTabstractWith the popularity of Internet of Things (IoT) and 5G, privacy-preserving message transmission and authentication have become an indispensable part in the field of data collection and analysis. There exist many protocols based on the public key cryptosystem, which allow the users to utilize their own identity as the public key to carry out data encryption and digital signature, which is very suitable for applying in the IoT environment with a large number of terminal devices. However, these protocols usually involve some complex cryptographic operations, which hinder their application on the resource-constrained IoT devices. In this paper, we design a privacy-preserving and verifiable outsourcing message transmission and authentication protocol, which allows the resource-constrained users to delegate some complex operations to the two untrusted edge servers and reduce the computational burden on the users side. The designed protocol contains several secure and novel outsourcing algorithms for modular exponentiation, bilinear pairing and scalar multiplication. For the different operations in the different situations, we design several different blinding techniques and verification methods, which not only protect the users’ private information, but also ensure the users can verify the correctness of results. Finally, we carry out some experiments to show that our proposed protocol is efficient. Fanyu Kong 0002, Jia Yu 0003, Hanlin Zhang 0001, Lu Hong Diao, Yunting Tao |
TrustCom | 4 |
| 2022 | A Novel Lyapunov based Dynamic Resource Allocation for UAVs-assisted Edge Computing
Jie Lin 0002, Hanlin Zhang 0001, Xinyu Yang 0001, Peng Zhao 0001 |
Comput. Networks | 3 |
| 2022 | Privacy-Preserving cloud-Aided broad learning system
Hanlin Zhang 0001, Jia Yu 0003, Jie Lin 0002 |
Comput. Secur. | 2 |
| 2022 | Privacy-Preserving and verifiable SRC-based face recognition with cloud/edge server assistance
Chengliang Tian, Changhui Hu 0002, Weizhong Tian, Hanlin Zhang 0001, Jia Yu 0003 |
Comput. Secur. | 5 |
| 2022 | An Improved Outsourcing Algorithm to Solve Quadratic Congruence Equations in Internet of ThingsabstractSolving quadratic congruence equations is an expensive operation widely employed in cryptographic constructions for secure Internet of Things applications. Recently, two outsourcing algorithms were proposed by Zhanget al.to solve quadratic congruence equations by employing Cippolla’s algorithm. It was claimed that all the inputs and outputs can be obscured in these two algorithms. However, we present two passive attacks in this article to show that all the inputs and outputs can be recovered efficiently by just a curious server, which implies the two outsourcing algorithms are insecure. To fix them, we further propose an improved outsourcing algorithm to solve quadratic congruence equations, which is more efficient and the privacy of actual inputs and outputs can be protected very well. Xiulan Li, Jingguo Bi, Chengliang Tian, Hanlin Zhang 0001, Jia Yu 0003, Yanbin Pan 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Secure Edge-Aided Computations for Social Internet-of-Things SystemsabstractDevices in the Internet-of-Things (IoT) are networked and perform massive computations to support various social IoT systems. Applications in social IoT systems often involve complicated computations that are out of the computation capacity of some resource-constrained IoT devices. Thus, how to enable resource-constrained IoT devices to accomplish complex computations efficiently and securely is of significant importance. To address this problem, we develop a secure edge-aided computation scheme for the social IoT systems. We scope the framework of edge-aided computations and identify the security threats in such a system. We define the security requirements that the outsourcing algorithms should meet. Then, we provide two examples of secure outsourcing algorithms (matrix multiplication and modular exponentiation) that meet the given security requirements. The efficiency and security of the proposed algorithms are supported through the theoretical analysis and experimental results. Hanlin Zhang 0001, Jia Yu 0003, Mohammad S. Obaidat, Pandi Vijayakumar, Linqiang Ge, Jie Lin 0002, Jianxi Fan, Rong Hao |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2022 | Novel Secure Outsourcing of Modular Inversion for Arbitrary and Variable ModulusabstractIn cryptography and algorithmic number theory, modular inversion is viewed as one of the most common and time-consuming operations. It is hard to be directly accomplished on resource-constrained clients (e.g., mobile devices and IC cards) since modular inversion involves a great amount of operations on large numbers in practice. To address the above problem, this paper proposes a novel unimodular matrix transformation technique to realize secure outsourcing of modular inversion. This technique makes our algorithm achieve several amazing properties. First, to the best of our knowledge, it is the first secure outsourcing computation algorithm that supports arbitrary and variable modulus, which eliminates the restriction in previous work that the protected modulus has to be a fixed composite number. Second, our algorithm is based on the single untrusted program model, which avoids the non-collusion assumption between multiple servers. Third, for each given instance of modular inversion, it only needs one round interaction between the client and the cloud server, and enables the client to verify the correctness of the results returned from the cloud server with the (optimal) probability 1. Furthermore, we propose an extended secure outsourcing algorithm that can solve modular inversion in multi-variable case. Theoretical analysis and experimental results show that our proposed algorithms achieve remarkable local-client’s computational savings. At last, as two important and helpful applications of our algorithms, the outsourced implementations of the key generation of RSA algorithm and the Chinese Reminder Theorem are given. Chengliang Tian, Jia Yu 0003, Hanlin Zhang 0001, Haiyang Xue, Cong Wang 0001, Kui Ren 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | SPPS: A Search Pattern Privacy System for Approximate Shortest Distance Query of Encrypted Graphs in IIoTabstractIn recent years, Industrial Internet of Things (IIoT) has gradually attracted the attention of the industry owing to its accurate time synchronization, communication accuracy, and high adaptability. As an important data structure, graphs are widely used in IIoT applications, where entities and their relationships can be expressed in the form of graphs. With the widespread adoption of IIoT and cloud computing, an increasing number of individuals or organizations are outsourcing their IIoT graph data to cloud servers to enjoy the unlimited storage space and fast computing service. To protect the privacy of graph data, graphs are usually encrypted before being outsourced. In this article, we propose a search pattern privacy system for approximate shortest distance query of encrypted graphs in IIoT. To realize search pattern privacy, we adopt two noncolluded cloud servers to accomplish different tasks. We leverage the first server to store the encrypted data and perform query operations, and use the second one to rerandomize the contents and shuffle the locations of the queried records. Before queries, we generate the trapdoors by using different random numbers. After queries, we ask the second server to rerandomize the contents of the records that the first server touched. In addition, we shuffle the physical locations of original records by inserting some fake records. In this way, all contents and physical locations of the touched records change, so that the first server cannot distinguish whether two queries are the same or not. To enhance the efficiency on the user side, we further improve this system by moving some heavy workloads from the user to the cloud. The security analysis and the performance evaluation show that our work is secure and efficient. Xinrui Ge, Jia Yu 0003, Hanlin Zhang 0001, Jianli Bai, Jianxi Fan, Naixue Xiong |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2021 | A novel Latency-Guaranteed based Resource Double Auction for market-oriented edge computing
Jie Lin 0002, Hanlin Zhang 0001, Xinyu Yang 0001, Peng Zhao 0001 |
Comput. Networks | 3 |
| 2021 | Secure Cloud-Aided Object Recognition on Hyperspectral Remote Sensing ImagesabstractObject recognition of hyperspectral remote sensing images based on machine learning is widely applied in many industries. However, the efficiency of the training and recognizing process of object recognition on hyperspectral remote sensing images is a critical issue since it involves complex matrix operations and large scale training data sets, especially for resource-constrained devices. One solution is to outsource the heavy workload of object recognition on hyperspectral remote sensing images to a cloud server. Nonetheless, it may bring some security problems when the cloud server is untrustworthy. Therefore, how to enable resource-constrained devices to securely and efficiently accomplish the training and recognizing process of object recognition on hyperspectral remote sensing images is of significant importance. In this article, we propose a secure and efficient scheme to outsource the object recognition on hyperspectral remote sensing images to the untrustworthy cloud server. The proposed scheme can protect the privacy of the computation input and output. Also, we develop an effective verification approach in our scheme that can detect the misbehavior of cloud server with the optimal probability 1. The theoretical analysis and experimental results indicate that our proposed scheme is secure and efficient. Hanlin Zhang 0001, Jia Yu 0003, Jie Lin 0002, Ming Yang 0023, Fanyu Kong 0002 |
IEEE Internet Things J. | 2 |
| 2021 | Blockchain-Aided Privacy-Preserving Outsourcing Algorithms of Bilinear Pairings for Internet of Things DevicesabstractBilinear pairing is a fundamental operation that is widely used in cryptographic algorithms (e.g., identity-based cryptographic algorithms) to secure IoT applications. Nonetheless, the time complexity of bilinear pairing is$O(n^{3})$, making it a very time-consuming operation, especially for resource-constrained IoT devices. Secure outsourcing of bilinear pairing has been studied in recent years to enable computationally weak devices to securely outsource the bilinear pairing to untrustworthy cloud servers. However, the state-of-art algorithms often require to precompute and store some values, which results in storage burden for devices. In the Internet of Things, devices are generally with very limited storage capacity. Thus, the existing algorithms do not fit the IoT well. In this article, we propose a secure outsourcing algorithm of bilinear pairings, which does not require precomputations. In the proposed algorithm, the outsourcer side’s efficiency is significantly improved compared with executing the original bilinear pairing operation. At the same time, the privacy of the input and output is ensured. Also, we apply the Ethereum blockchain in our outsourcing algorithm to enable fair payments, which ensures that the cloud server gets paid only when he correctly accomplished the outsourced work. The theoretical analysis and experimental results show that the proposed algorithm is efficient and secure. Hanlin Zhang 0001, Le Tong, Jia Yu 0003, Jie Lin 0002 |
IEEE Internet Things J. | 1 |
| 2021 | Lattice-based weak-key analysis on single-server outsourcing protocols of modular exponentiations and basic countermeasures
Yunhai Zheng, Chengliang Tian, Hanlin Zhang 0001, Jia Yu 0003, Fengjun Li |
J. Comput. Syst. Sci. | 3 |
| 2021 | Towards Achieving Keyword Search over Dynamic Encrypted Cloud Data with Symmetric-Key Based VerificationabstractVerifiable Searchable Symmetric Encryption, as an important cloud security technique, allows users to retrieve the encrypted data from the cloud through keywords and verify the validity of the returned results. Dynamic update for cloud data is one of the most common and fundamental requirements for data owners in such schemes. To the best of our knowledge, the existing verifiable SSE schemes supporting data dynamic update are all based on asymmetric-key cryptography verification, which involves time-consuming operations. The overhead of verification may become a significant burden due to the sheer amount of cloud data. Therefore, how to achieve keyword search over dynamic encrypted cloud data with efficient verification is a critical unsolved problem. To address this problem, we explore achieving keyword search over dynamic encrypted cloud data with symmetric-key based verification and propose a practical scheme in this paper. In order to support the efficient verification of dynamic data, we design a novel Accumulative Authentication Tag (AAT) based on the symmetric-key cryptography to generate an authentication tag for each keyword. Benefiting from the accumulation property of our designed AAT, the authentication tag can be conveniently updated when dynamic operations on cloud data occur. In order to achieve efficient data update, we design a new secure index composed by a search table ST based on the orthogonal list and a verification list VL containing AATs. Owing to the connectivity and the flexibility of ST, the update efficiency can be significantly improved. The security analysis and the performance evaluation results show that the proposed scheme is secure and efficient. Xinrui Ge, Jia Yu 0003, Hanlin Zhang 0001, Chengyu Hu 0001, Zengpeng Li 0001, Zhan Qin, Rong Hao |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | A novel multitype-users welfare equilibrium based real-time pricing in smart grid
Jie Lin 0002, Biao Xiao, Hanlin Zhang 0001, Xinyu Yang 0001, Peng Zhao 0001 |
Future Gener. Comput. Syst. | 3 |
| 2020 | Privacy-Preserving and Distributed Algorithms for Modular Exponentiation in IoT With Edge Computing AssistanceabstractWith the development of Internet of Things (IoT) and 5G, edge computing, as a new computing paradigm, has been widely popularized in academia and industry. Due to the distributed architecture and being close to the user, edge computing can faster respond to the IoT device's request and provide a better quality of service for IoT applications. An important application of edge computing is to outsource the complicated computation task to the nearby edge nodes. Modular exponentiation is widely considered as one of the most common and expensive operations in cryptographic protocols. As far as we know, all secure outsourcing algorithms of modular exponentiation are based on the centralized cloud server, but not based on multiple edge nodes. In this article, we propose the first secure and distributed outsourcing algorithm for modular exponentiation (fixed base and variable exponent) under the multiple noncolluding edge node model. In our algorithm, the exponent is divided into a certain number of parts. In addition, we propose another secure and distributed outsourcing algorithm of modular exponentiation (variable base and variable exponent). The user can protect the privacy in the process of outsourcing and detect the invalid results from edge nodes with high probability. Finally, we provide the experimental evaluation to support that our proposed algorithms are efficient on both the user side and the edge node side. Jia Yu 0003, Hanlin Zhang 0001, Ming Yang 0023, Huaqun Wang |
IEEE Internet Things J. | 3 |
| 2020 | Efficient and Secure Outsourcing Scheme for RSA Decryption in Internet of ThingsabstractRivest-Shamir-Adleman (RSA) is one of the widely deployed public-key algorithms. Yet, its decryption facet is very time consuming for resource-constrained Internet-of-Thing (IoT) devices, as it is based on the modular exponentiation of a large number. Although several variants of RSA have been designed to accelerate decryption, the outcomes have been far from satisfactory. Therefore, it is of imminent importance to investigate how to securely outsource RSA decryption to computational powerful parties as an alternative solution. In this article, we introduce the first efficient and secure outsourcing scheme for RSA decryption in IoT. Though RSA decryption is achieved via modular exponentiation, existing secure outsourcing schemes for modular exponentiation either assume the modulus to be prime and are not applicable to RSA or incur massive computation costs and are heavy laden in practice. To address these issues, we have designed our scheme based on the Chinese remainder theorem (CRT). In our scheme, the private keys (including the exponent and the modulus) and the plaintext are concealed concurrently, and the proposed scheme is highly efficient for both client and cloud. In addition, our scheme enables the client to detect any misbehavior of the cloud server with a probability of 99.17%. To validate the effectiveness of our proposed scheme, we provide rigorous proofs of security and verifiability, as well as efficiency analysis. The effectiveness and efficiency of our scheme are further confirmed based on experimental results. Hanlin Zhang 0001, Jia Yu 0003, Chengliang Tian, Le Tong, Jie Lin 0002, Linqiang Ge, Huaqun Wang |
IEEE Internet Things J. | 1 |
| 2020 | Practical and Secure Outsourcing Algorithms for Solving Quadratic Congruences in Internet of ThingsabstractSolving quadratic congruences is a widely applied operation in cryptographic protocols to ensure the data secrecy in the Internet of Things (IoT). Yet it requires unaffordable computation resource for resource-constrained IoT devices when bulk of this type of operations need to be performed. How to efficiently and effectively solve quadratic congruences on IoT devices becomes a challenging issue. To address this problem, in this article, we propose two practical and secure outsourcing algorithms for solving quadratic congruences. Our proposed algorithms enable the IoT devices to outsource the heavy computation of solving quadratic congruences to a single cloud server, and therefore, achieve high efficiency for IoT devices. Meanwhile, we obscure the input and the output so that the outsourcing process does not leak the privacy of the computation, and the IoT devices in our algorithms can detect any misbehavior of the cloud server with a probability of 1. In addition, we take the Rabin encryption algorithm as an example to show how our proposed algorithms can be applied to IoT applications. The theoretical analysis and experimental results support the fact that our proposed algorithms are secure and efficient. Hanlin Zhang 0001, Jia Yu 0003, Chengliang Tian, Guobin Xu, Jie Lin 0002 |
IEEE Internet Things J. | 1 |
| 2020 | Blockchain-based two-party fair contract signing scheme
Hanlin Zhang 0001, Jia Yu 0003, Hequn Xian |
Inf. Sci. | 2 |
| 2020 | How to securely outsource the extended euclidean algorithm for large-scale polynomials over finite fields
Chengliang Tian, Hanlin Zhang 0001, Jia Yu 0003, Fengjun Li |
Inf. Sci. | 3 |
| 2020 | How to Securely Outsource Finding the Min-Cut of Undirected Edge-Weighted GraphsabstractFinding min-cut is a fundamental operation in graph theory. It has been widely used in many applications such as image segmentation and network partition. However, solving the min-cut problem is time-consuming for resource-constrained devices, especially when the graph is large and dense. In this paper, we explore how to securely solve the min-cut problem in the cloud environment, and propose two secure outsourcing schemes for the min-cut of undirected edge-weighted graphs. The first scheme is based on two non-colluded untrusted cloud servers, and the second one is under the single untrusted cloud server model. In the designed schemes, we develop a new technique that contains merging vertices and edges, inserting fake vertices and edges, shuffling vertices and randomizing weights of edges to protect the privacy of graphs. In order to realize the checkability of result from a single untrusted cloud server, we design a novel verification mechanism by outsourcing the min-cut of two related graphs. Besides, we also provide security analysis and the experimental evaluation. To the best of our knowledge, it is the first research on secure outsourcing of graph algorithm. Pu Zhao 0002, Jia Yu 0003, Hanlin Zhang 0001, Zhan Qin, Cong Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2018 | Intrusion-resilient identity-based signatures: Concrete scheme in the standard model and generic construction
Jia Yu 0003, Rong Hao, Hui Xia 0001, Hanlin Zhang 0001, Xiangguo Cheng, Fanyu Kong 0002 |
Inf. Sci. | 4 |
| 2017 | Remote data possession checking with privacy-preserving authenticators for cloud storage
Wenting Shen, Guangyang Yang, Jia Yu 0003, Hanlin Zhang 0001, Fanyu Kong 0002, Rong Hao |
Future Gener. Comput. Syst. | 4 |
| 2017 | A Survey on Internet of Things: Architecture, Enabling Technologies, Security and Privacy, and ApplicationsabstractFog/edge computing has been proposed to be integrated with Internet of Things (IoT) to enable computing services devices deployed at network edge, aiming to improve the user's experience and resilience of the services in case of failures. With the advantage of distributed architecture and close to end-users, fog/edge computing can provide faster response and greater quality of service for IoT applications. Thus, fog/edge computing-based IoT becomes future infrastructure on IoT development. To develop fog/edge computing-based IoT infrastructure, the architecture, enabling techniques, and issues related to IoT should be investigated first, and then the integration of fog/edge computing and IoT should be explored. To this end, this paper conducts a comprehensive overview of IoT with respect to system architecture, enabling technologies, security and privacy issues, and present the integration of fog/edge computing and IoT, and applications. Particularly, this paper first explores the relationship between cyber-physical systems and IoT, both of which play important roles in realizing an intelligent cyber-physical world. Then, existing architectures, enabling technologies, and security and privacy issues in IoT are presented to enhance the understanding of the state of the art IoT development. To investigate the fog/edge computing-based IoT, this paper also investigate the relationship between IoT and fog/edge computing, and discuss issues in fog/edge computing-based IoT. Finally, several applications, including the smart grid, smart transportation, and smart cities, are presented to demonstrate how fog/edge computing-based IoT to be implemented in real-world applications. Jie Lin 0002, Wei Yu 0002, Nan Zhang 0004, Xinyu Yang 0001, Hanlin Zhang 0001, Wei Zhao 0001 |
IEEE Internet Things J. | 5 |
| 2017 | Light-weight and privacy-preserving secure cloud auditing scheme for group users via the third party medium
Wenting Shen, Jia Yu 0003, Hui Xia 0001, Hanlin Zhang 0001, Xiuqing Lu, Rong Hao |
J. Netw. Comput. Appl. | 4 |
| 2017 | How to securely outsource the inversion modulo a large composite number
Qianqian Su, Jia Yu 0003, Chengliang Tian, Hanlin Zhang 0001, Rong Hao |
J. Syst. Softw. | 4 |
| 2016 | Ultra-Dense Networks: Survey of State of the Art and Future DirectionsabstractWithin the foreseeable future, the growing number of mobile devices, and their diversity, will challenge the current network architecture. Furthermore, users will expect greater data rates, lower latency, lower packet drop rates, etc. in future wireless networks. Ultra Dense Networks (UDN), considered to be one of the best ways to meet user expectations and support future wireless network deployment, will face multiple significant hurdles, including interference, mobility, and cost. In this paper, we review existing research efforts toward addressing those challenges and present future avenues for research. We first develop a taxonomy to review and describe existing research efforts. Next, we focus on inter-cell interference, handover performance, and energy efficiency as the key techniques to addressing the most pressing challenges. Finally, we present several future research directions, including emergent Internet-of-Things (IoT) applications, security and privacy, modeling and realistic simulations, and relevant techniques. Wei Yu 0002, Hansong Xu, Hanlin Zhang 0001, David W. Griffith, Nada Golmie |
ICCCN | 3 |
| 2016 | A streaming-based network monitoring and threat detection systemabstractThe unyielding trend of increasing cyber threats has made cyber security paramount in protecting personal and private intellectual property. In order to provide the most highly secured network environment, network traffic monitoring and threat detection systems must handle real-time data from varied and branching places in enterprise networks. Though numerous investigations have yielded real-time threat detection systems, in this paper we addressed the issue of handling the large volumes of network traffic data of enterprise systems, while simultaneously providing real-time monitoring and detection remain unsolved. Particularly, we introduced and evaluated a streaming-based threat detection system that can rapidly analyze highly intensive network traffic data in real-time, utilizing the streaming-based clustering algorithms to detect abnormal network activities. The developed system integrates the streaming and high-performance data analysis capabilities of Flume, Sharp, and Hadoop into a cloud-computing environment to provide network monitoring and intrusion detection. Our performance evaluation and experimental results demonstrate that the developed system can cope with a significant volume streaming data with high detection accuracy and good system performance. Zhijiang Chen, Hanlin Zhang 0001, William Grant Hatcher, James H. Nguyen, Wei Yu 0002 |
SERA | 2 |
| 2013 | On effective data aggregation techniques in Host-based Intrusion Detection in MANETabstractMobile Ad Hoc Networks (MANETs) have been widely used in commercial and tactical domains. MANETs commonly demand a robust, diverse, energy-efficient, and resilient communication and computing infrastructure, enabling network-centric operation with minimal downtime. MANETs face security risks and energy consumption. However, conducting cyber attack monitoring and detection in a MANET becomes a challenging issue because of limited resources and its infrastructureless network environment. To address this issue, we develop both lossless and lossy aggregation techniques to reduce the energy cost in information transition and bandwidth consumption while preserving the desired detection accuracy. In particular, we develop two lossless aggregation techniques: compression-based and event-based aggregation and develop a lossy aggregation technique: feature-based aggregation. We conduct real-world experiments and simulation study to evaluate the effectiveness of our proposed data aggregation techniques in terms of the energy consumption and detection accuracy. Difan Zhang, Linqiang Ge, Rommie L. Hardy, Wei Yu 0002, Hanlin Zhang 0001, Robert J. Reschly |
CCNC | 5 |
| 2013 | On behavior-based detection of malware on Android platformabstractBecause of exponential growth in smart mobile devices, malware attacks on smart mobile devices have been growing and pose serious threats to mobile device users. To address this issue, we develop a malware detection system, which uses a behavior-based detection approach to deal with the detection of a large number of unknown malware. To accurately detect malware, we examine system calls to capture the runtime behavior of software, which interacts with an operating system and adopt machine learning approaches such as Support Vector Machine (SVM) and Naive Bayes learning schemes to learn the dynamic behavior of software execution. Using real-world malware and benign samples, we conduct experiments on Android devices and evaluate the effectiveness of our developed system in terms of learning algorithms, the size of training set, the length of n-grams, and the overhead in training and detection processes. Our experimental data demonstrates the effectiveness of our proposed detection system to detect malware. Wei Yu 0002, Hanlin Zhang 0001, Linqiang Ge, Rommie L. Hardy |
GLOBECOM | 2 |