VLDB 2026 Research / reviewers in the wild / expert
Yupeng Hu 0004
dblp:62/7825-4
· DBLP profile ↗
33ranked-venue papers
5as first author
23since 2021 · last 2026
0000-0002-7358-7426ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 14 · 3 first-author · 7 since 2021Computer networks · 7 · 5 since 2021Security and privacy · 6 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FirmCCF: Detecting Custom Cryptographic Function Vulnerabilities Through Query-Driven ApproachesabstractCryptographic techniques are widely used to safeguard software against privacy breaches. Efficiently detecting encryption algorithms in software to determine whether they meet security requirements is a critical task. However, traditional static and dynamic detection methods often suffer from high false alarm rates or low efficiency, as they cannot fully capture the structural and semantic features of cryptographic algorithms. In this paper, we proposed FirmCCF, a vulnerability detection tool for custom cryptographic functions in Internet of Things (IoT) devices. FirmCCF leverages an improved deep learning encoder-decoder classification model, CodeT5-cate, to identify and classify cryptographic functions in source code and decompiled firmware. It then outputs highly structured metalevel attributes of cryptographic functions via a large language model (LLM) and detects vulnerabilities through a query-driven approach. FirmCCF achieves 99.97% accuracy, 99.72% recall, and 99.86% F1-score in detecting cryptographic functions from binary files. We further define 7 security rules, encode them as queries, and use them to uncover seven categories of vulnerabilities. An evaluation on 40,902 function codes revealed 46 vulnerabilities, including 8 previously unknown issues. Our work highlights the urgent need for systematic assessment solutions to detect and mitigate vulnerabilities in custom cryptographic functions. Yupeng Hu 0004 |
IEEE Internet Things J. | 3 |
| 2026 | FGAA: Enhancing adversarial robustness in AIoT-enabled smart systems via Fine-Grained Activation Alignment
Wenxin Kuang, Fengxiao Tang, Yupeng Hu 0004, Keqin Li 0001 |
J. Syst. Archit. | 4 |
| 2026 | Sound Eavesdropping on Mobile Device Via Audio-Induced EMRabstractSound eavesdropping poses serious threats to user privacy in daily mobile usage scenarios such as phone calls, voice messaging, and confidential meetings. Headphones are thus favored by mobile users as they provide physical sound isolation to protect audio privacy. However, our paper presents the first proof-of-concept system,Periscope, that demonstrates the vulnerabilities of headphone-plugged mobile devices. The system shows that audio-induced electromagnetic radiations (EMRs) from mobile devices' audio circuits can be exploited as an effective side channel in recovering the victim's audio sounds. Our theoretical analysis and feasibility studies further reveal that audio-induced EMRs are highly correlated with the device's audio inputs but suffer from signal distortions and ambient noises, making recovering audio sounds extremely challenging. To address this challenge, we develop signal processing techniques to clear noises and distortions, enabling EMRs to be converted back to audio sounds. Our attack prototype, comparable in size to hidden voice recorders, successfully recovers victims' private audio sounds with a word error rate (WER) as low as 7.44% across 12 mobile devices and 6 headphones. The recovery results are recognizable to natural human hearing and online speech-to-text tools. We also propose a software-based defense solution that mitigates this audio eavesdropping threat without requiring hardware modification. Yupeng Hu 0004, Hongrui Pan, Wenqiang Jin, Zhenyu Ye, Chenxi Liu 0003 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | MPCCP: A Multi-chain Perception Crime Charge Prediction Method
Congshan Huang, Tianshuo Jiao, Qiao Hu 0005, Yupeng Hu 0004, Bianxia Du |
ICANN (4) | 4 |
| 2025 | Unveiling the Pruning Risks on Privacy Vulnerabilities of Deep Neural NetworksabstractLarge-scale deep neural networks (DNNs), such as large language models, have gained immense popularity due to their outstanding performance across various tasks. However, their application in resource-constrained scenarios faces significant challenges due to the high computational costs and memory usage of these models during inference. Model pruning emerges as a viable technique to mitigate these limitations by reducing the computational complexity of deep models. While existing research primarily focuses on maximizing inference efficiency without compromising accuracy, the privacy implications of pruning techniques remain largely unexplored. In this work, we systematically investigate the impact of popular pruning techniques on the privacy vulnerabilities of DNNs. We begin by applying common pruning schemes to various DNNs and evaluating their privacy risks, both before and after pruning, using model inversion attacks. We then analyze how the pruning rate and granularity affect these privacy vulnerabilities. Moreover, we conduct experiments on both original and pruned models equipped with defenses to confirm that the increase in privacy risks following pruning is not merely coincidental. Finally, we offer guidelines for the careful application of pruning techniques. Our findings serve as a cautionary note, highlighting the inherent privacy risks associated with current pruning schemes and providing valuable insights for developing pruning methods that are both efficient and secure. Wenxin Kuang, Qizhuang Liang, Yupeng Hu 0004 |
ICASSP | 6 |
| 2025 | SemSyn-LCE: A Charge Prediction Method Based on Semantic Syntactic Fusion and Legal Constituent Elements Matching
Bianxia Du, Wenhui Xia, Qiao Hu 0005, Yupeng Hu 0004 |
ICDAR (1) | 5 |
| 2025 | FirmPass: Identifying Broken Password Management in Linux-Based IoT Firmware Through Query-Driven ApproachesabstractPassword management is a fundamental aspect of security for Internet of Things (IoT) devices. However, despite the availability of established guidelines and best practices, the implementation of password management in IoT firmware often falls short, leading to vulnerabilities and potential breaches. Because of the lack of automated tools, the severity and pervasiveness of broken password management of IoT firmware has been less understood. In this paper, we present FIRMPASS, a new tool to identify broken password management of Linuxbased IoT firmware. Particularly, we establish general password management models for Linux-based IoT devices based on password management processes and related vulnerabilities. To automatically identify the vulnerabilities, FIRMPASS employs a query-driven approach to locate the firmware that violate the properties of correct password management. Specifically, we manually define four rules that should be complied with, encode the rules with queries, and check the queries in the firmware, which leads to the discovery of four types of vulnerabilities. Evaluation of 615 IoT firmware images uncovers 67 vulnerabilities, including 37 previously unknown issues. Our work underscores the urgent need for assessment solutions for IoT firmware. Jiongyi Chen, Zheng Qin 0001, Yupeng Hu 0004 |
IEEE Internet Things J. | 5 |
| 2024 | FIRMRES: Exposing Broken Device-Cloud Access Control in IoT Through Static Firmware AnalysisabstractDevice-cloud interfaces are a critical component of IoT given their centrality of the cloud-side control over the connected devices, which has attracted an increasing number of attacks exploiting their access control. Regrettably, there is a lack of techniques to facilitate the examination of such a critical interface, primarily hindered by the challenges of dynamic firmware analysis to reconstruct device-cloud messages and generate testing cues. This paper presents FIRMRES, a principled static approach that automatically reconstructs device-cloud messages by modeling message construction semantics in IoT firmware. At the center of FIRMRES is a message field tree which is formed of the backward data flows from message delivery callsites to the potential sources of message fields. By walking through, transforming, and contextual learning from this tree, device-cloud messages are automatically reconstructed and a set of semantics during “message construction” such as the message format, the field semantics, and the order of the fields are inferred. Facilitated with the messages reconstructed by FIRMRES, we were able to manually examine the access control of device-cloud interfaces. FIRMRES reconstructed 246 effective messages from the firmware of 20 IoT devices, leading to the discovery of 13 previously-unknown vulnerabilities in their clouds. Jiongyi Chen, Yupeng Hu 0004 |
DSN | 3 |
| 2024 | FortifyPatch: Towards Tamper-Resistant Live Patching in Linux-Based HypervisorabstractLinux-based hypervisors in the cloud server suffer from an increasing number of vulnerabilities in the Linux kernel.To address these vulnerabilities in a timely manner while avoiding the economic loss caused by unplanned shutdowns, live patching schemes have been developed. Unfortunately, existing live patching solutions have failed to protect patches from post-deployment attacks. In addition, patches that involve changes to global variables can lead to practical issues with existing solutions. To address these problems, we present FortifyPatch, a tamper-resistant live patching solution for Linux-based hypervisors in cloud environments. Specifically, FortifyPatch employs multiple Granule Protection Tables from Arm Confidential Computing Architecture to protect the integrity of deployed patches. TrustZone Address Space Controller and Performance Monitor Unit are used to prevent the bypassing of the Patch via kernel code protection and timely page table verification. FortifyPatch is also able to patch global variables via well-designed data access traps.We prototype FortifyPatch and evaluate it using real-world CVE patches. The result shows that FortifyPatch is capable of deploying 81.5% of CVE patches. The performance evaluation indicates that FortifyPatch protects deployed patches with 0.98% and 3.1% overhead on average across indicative benchmarks and real-world applications, respectively. Zhenyu Ye, Lei Zhou 0023, Fengwei Zhang, Wenqiang Jin, Zhenyu Ning, Yupeng Hu 0004, Zheng Qin 0001 |
ISSTA | 6 |
| 2024 | Eavesdropping on Black-box Mobile Devices via Audio Amplifier's EMR
Wenqiang Jin, Yupeng Hu 0004, Zhenyu Ning, Kenli Li 0001, Zheng Qin 0001, Mingxing Duan, Daibo Liu, Ming Li 0006 |
NDSS | 3 |
| 2024 | SIAT: A systematic inter-component communication real-time analysis technique for detecting data leak threats on AndroidabstractThis paper presents the design and implementation of a systematic Inter-Component Communications (ICCs) dynamic Analysis Technique (SIAT) for detecting privacy-sensitive data leak threats. SIAT’s specific approach involves the identification of malicious ICC patterns by actively tracing both data flows and implicit control flows within ICC processes during runtime. This is achieved by utilizing the taint tagging methodology, a technique utilized by TaintDroid. As a result, it can discover the malicious intent usage pattern and further resolve the coincidental malicious ICCs and bypass cases without incurring performance degradation. SIAT comprises two key modules: Monitor and Analyzer. The Monitor makes the first attempt to revise the taint tag approach named TaintDroid by developing the built-in intent service primitives to help Android capture the intent-related taint propagation at multi-level for malicious ICC detection. Specifically, we enable the Monitor to perform systemwide tracking of intent with five abstraction functionalities embedded in the interactive workflow of components. By analyzing the taint logs offered by the Monitor, the Analyzer can build the accurate and integrated ICC patterns adopted to identify the specific leak threat patterns with the identification algorithms and predefined rules. Meanwhile, we employ the patterns’ deflation technique to improve the efficiency of the Analyzer. We implement the SIAT with Android Open Source Project and evaluate its performance through extensive experiments on a particular dataset consisting of well-known datasets and real-world apps. The experimental results show that, compared to state-of-the-art approaches, the SIAT can achieve about 25% ∼200% accuracy improvements with 1.0 precision and 0.98 recall at negligible runtime overhead. Apart from that, the SIAT can identify two undisclosed cases of bypassing that prior technologies cannot detect and quite a few malicious ICC threats in real-world apps with lots of downloads on the Google Play market. Yupeng Hu 0004, Wenxin Kuang, Wenjia Li, Keqin Li 0001, Jiliang Zhang 0002, Qiao Hu 0005 |
J. Comput. Secur. | 1 |
| 2024 | HPDK: A Hybrid PM-DRAM Key-Value Store for High I/O ThroughputabstractThis paper explores the design of an architecture that replaces Disk with Persistent Memory (PM) to achieve the highest I/O throughput in Log-Structured Merge Tree (LSM-Tree) based key-value stores (KVS). Most existing LSM-Tree based KVSs use PM as an intermediate or smoothing layer, which fails to fully exploit PM’s unique advantages to maximize I/O throughput. However, due to PM’s distinct characteristics, such as byte addressability and short erasure time, simply replacing existing storage with PM does not yield optimal I/O performance. Furthermore, LSM-Tree based KVSs often face slow read performance. To tackle these challenges, this paper presents HPDK, a hybrid PM-DRAM KVS that combines level compression for LSM-Trees in PM with a B+-tree based in-memory search index in DRAM, resulting in high write and read throughput. HPDK also employs a key-value separation design and a live-item rate-based dynamic merge method to reduce the volume of PM writes. We implement and evaluate HPDK using a real PM drive, and our extensive experiments show that HPDK provides 1.25-11.8 and 1.47-36.4 times higher read and write throughput, respectively, compared to other state-of-the-art LSM-Tree based approaches. Bihui Liu, Zhenyu Ye, Qiao Hu 0005, Yupeng Hu 0004, Yuchong Hu, Yang Xu 0013, Keqin Li 0001 |
IEEE Trans. Computers | 4 |
| 2023 | Adaptive multi-source data fusion vessel trajectory prediction model for intelligent maritime traffic
Jiangjin Yin, Wei Liang 0005, Yupeng Hu 0004 |
Knowl. Based Syst. | 5 |
| 2023 | Achieving Fine-Grained Data Sharing for Hierarchical Organizations in CloudsabstractCloud computing has become an increasingly popular option for users to store and share data. Encryption prior to outsourcing data to the cloud is the best way to protect data security and privacy; however, it hinders sharing of the data that was encrypted. In addition, users in many real-world organizations (e.g., enterprises) have multiple level structures and a higher-level user should have the privilege to decide which data can be shared with a lower-level user. Most solutions in the literature suffer from inefficiency or inflexibility in tackling this problem. In this article, we propose a fine-grained hierarchical data sharing (FHDS) scheme in clouds. With FHDS, the data owner can encrypt data with his public key, and then selectively share encrypted data with users in a hierarchy; if necessary, the users can disseminate the owner's data to their subordinates in the lower levels by generating access keys. In particular, the higher-level users could puncture the keys with some tags such that the part of the owner's data which is labeled by the punctured tags will not be accessible to the lower-level users. The proposed scheme is provable secure under our security model and performance analyses show the efficiency of the scheme. Zheng Qin 0001, Qianhong Wu, Robert H. Deng, Zhenyu Guan 0002, Yupeng Hu 0004, Fangmin Li |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2023 | Bidirectional Data-Driven Trajectory Prediction for Intelligent Maritime TrafficabstractIntelligent maritime transportation is one of the most promising enabling technologies for promoting trade efficiency and releasing the physical labor force. The trajectory prediction method is the foundation to guarantee collision avoidance and route optimization for ship transportation. This article proposes a bidirectional data-driven trajectory prediction method based on Automatic Identification System (AIS) spatio-temporal data to improve the accuracy of ship trajectory prediction and reduce the risk of accidents. Our study constructs an encoder-decoder network driven by a forward and reverse comprehensive historical trajectory and then fuses the characteristics of the sub-network to predict the ship trajectory. The AIS historical trajectory data of US West Coast ships are employed to investigate the feasibility of the proposed method. Compared with the current methods, the proposed approach lessens the prediction error by studying the comprehensive historical trajectory, and 60.28% has reduced the average prediction error. The ocean and port trajectory data are analyzed in maritime transportation before and after COVID-19. The prediction error in the port area is reduced by 95.17% than the data before the epidemic. Our work helps the prediction of maritime ship trajectory, provides valuable services for maritime safety, and performs detailed insights for the analysis of trade conditions in different sea areas before and after the epidemic. Wen Yao 0001, Yupeng Hu 0004 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Half-Duplex Mode-Based Secure Key Generation Method for Resource-Constrained IoT DevicesabstractThe physical layer secret key generation scheme is a preferred solution designed for resource-constrained Internet of Things (IoT) devices. But it suffers from a severe attack, the signal manipulating attack, which aims at controlling the generated key. The existing solutions either cannot prevent all kinds of signal manipulation attacks or require working in full-duplex mode, which is not suitable for resource-constrained IoT devices. In this article, we introduce a secret key generation scheme with the help of an untrusted relay to address this dilemma. Also, our method can protect the privacy of legitimate users from the untrusted relay. We conclude a general signal manipulation attack model from existing practical signal manipulation attacks and analyze the security strength and privacy preserving ability of our scheme based on this model. Finally, we compare our method with existing signal manipulation attack solutions. The result shows that our method is the best solution for resource-constrained IoT systems. Qiao Hu 0005, Jingyi Zhang 0006, Gerhard P. Hancke 0002, Yupeng Hu 0004, Wenjia Li, Hongbo Jiang 0001, Zheng Qin 0001 |
IEEE Internet Things J. | 4 |
| 2022 | Deep Neural Network Security Collaborative Filtering Scheme for Service Recommendation in Intelligent Cyber-Physical SystemsabstractCyber–physical systems (CPSs) is a security real-time embedded system. CPS integrates the information sensed by the current physical sensors, through high-speed real-time transmission, and then carries out powerful information processing to effectively interact and integrate the physical and the information worlds. With the aim to improve the quality of service, optimize the existing physical space, and increase security, collaborative filtering algorithms have also been widely used in various recommendation models for Internet of Things (IoT) services. However, general collaborative filtering algorithms cannot capture complex interactive information in the sparse Mashup–Web service call matrix, which leads to lower recommendation performance. Based on the artificial intelligence technology, this study proposes a recommendation algorithm for a security collaborative filtering service that integrates content similarity. A security collaborative filtering module is used to capture the complex interaction information between Mashup and Web services. By applying the content similarity module to extract the semantic similarity information between the Mashup and Web services, the two modules are seamlessly integrated into a deep neural network to accurately and quickly predict the rating information of Mashup for the Web services. Real data set on the intelligent CPS is captured and then compared with mainstream service recommendation algorithms. Experimental results show that the proposed algorithm not only efficiently completes the Web service recommendation task under the premise of sparse data but also shows better accuracy, effectivity, and privacy. Thus, the proposed method is highly suitable for the application of intelligence CPS. Wei Liang 0005, Songyou Xie, Jiahong Cai, Jianbo Xu, Yupeng Hu 0004, Yang Xu 0013, Meikang Qiu |
IEEE Internet Things J. | 5 |
| 2022 | STT-MRAM-Based Reliable Weak PUFabstractIn recent years, micro-nano device characteristics like ferroelectrics and resistive switching are being used to build important security primitives such as Physical Unclonable Function (PUF). The micro-nano device-based hardware security primitives, although with higher security, energy efficiency, and integration density, suffer from serious reliability issues caused by process scaling. To mitigate this issue, this paper introduces a reconfigurable weak PUF based on spin-transfer torque magnetoresistive random-access memory (STT-MRAM), which adopts the crossing switches implemented with simple demultiplexes (DEMUXs) to improve the flexibility and reliability. Moreover, two algorithms,neighboring bit linesandtop-$n$n, are proposed to enlarge the gap between two parallel reading currents, thus further enhancing the reliability of PUF responses. Experimental results demonstrate that the proposed PUF scheme achieves good uniqueness (50.64 percent), uniformity (50.02 percent), and bit-aliasing ($\approx$49.80%). Particularly, the proposed method significantly improves the PUF reliability, achieving low bit error rate (BER$\leq$2.13%) within the range of -20$^\circ$C to 90$^\circ$C. Yupeng Hu 0004, Linjun Wu, Zhuojun Chen, Xiaolin Xu 0001, Keqin Li 0001, Jiliang Zhang 0002 |
IEEE Trans. Computers | 1 |
| 2022 | FLAM-PUF: A Response-Feedback-Based Lightweight Anti-Machine-Learning-Attack PUFabstractPhysical unclonable functions (PUFs) have been adopted in many resource-constrained Internet of Things (IoT) applications to provide effective and lightweight solutions for device authentication. However, an attacker can collect challenge–response pairs (CRPs) of a strong PUF, to build a machine learning (ML) model and mimic its behavior, i.e., predicting the responses of unseen challenges with high accuracy. Although several PUFs have been proposed to resist such modeling attacks, they incur high hardware overhead. Developing a PUF primitive with low hardware cost and high resistance to ML attacks is thus a crucial task. In this article, we propose the first response–feedback-based lightweight anti-ML-attack PUF (FLAM-PUF). It is only composed of one arbiter PUF (APUF) and one Galois linear-feedback shift register (LFSR), with some basic logic gates, reducing more than 62% hardware cost compared with the state-of-the-art robust strong PUFs. Specifically, FLAM-PUF leverages a cost-effective feedback loop structure to dynamically control and update the LFSR configuration. FLAM-PUF has two main characteristics: 1) it feeds back a 1-bit response in every cycle to intentionally poison the data of the CRP set for training. To resist ML-based modeling attacks, the 1-bit response can randomly update one coefficient of the feedback polynomial to implant more complex correlations into the model built by attackers and 2) it takes advantage of an$n-$bit response feedback-controlled reconfigurable Galois LFSR to enlarge the original challenge space of the APUF. Extensive experimental results show that the proposed FLAM-PUF achieves near-optimal uniformity, uniqueness, and reliability. Our scheme works well under standard attack models with public crucial initial information. In particular, the prediction accuracy of modeling attacks against FLAM-PUF is nearly 50% under the four widely used ML algorithms, i.e., support vector machines (SVMs), logistic regression (LR), covariance matrix adaptation evolution strategy (CMA-ES), and deep neural networks (DNNs), indicating excellent resistance against these ML attacks. Linjun Wu, Yupeng Hu 0004, Kehuan Zhang, Wenjia Li, Xiaolin Xu 0001, Wanli Chang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2022 | A Blockchain-Based Multi-Cloud Storage Data Auditing Scheme to Locate FaultsabstractNetwork storage services have benefited countless users worldwide due to the notable features of convenience, economy and high availability. Since a single service provider is not always reliable enough, more complex multi-cloud storage systems are developed for mitigating the data corruption risk. While a data auditing scheme is still needed in multi-cloud storage to help users confirm the integrity of their outsourced data. Unfortunately, most of the corresponding schemes rely on trusted institutions such as the centralized third-party auditor (TPA) and the cloud service organizer, and it is difficult to identify malicious service providers after service disputes. Therefore, we present a blockchain-based multi-cloud storage data auditing scheme to protect data integrity and accurately arbitrate service disputes. We not only introduce the blockchain to record the interactions among users, service providers, and organizers in data auditing process as evidence, but also employ the smart contract to detect service dispute, so as to enforce the untrusted organizer to honestly identify malicious service providers. We also use the blockchain network and homomorphic verifiable tags to achieve the low-cost batch verification without TPA. Theoretical analyses and experiments reveal that the scheme is effective in multi-cloud environments and the cost is acceptable. Cheng Zhang 0035, Yang Xu 0013, Yupeng Hu 0004, Jiajing Wu, Ju Ren 0001, Yaoxue Zhang |
IEEE Trans. Cloud Comput. | 3 |
| 2021 | AIT: An AI-Enabled Trust Management System for Vehicular Networks Using Blockchain TechnologyabstractCurrently, connected vehicles have gradually stepped into our daily lives, and they generally rely on vehicular networks to generate and exchange traffic-related messages to improve the overall travel safety and efficiency. However, due to the open nature of vehicular networks, these traffic-related messages could be erroneous, which may be caused by various reasons, ranging from an onboard device (OBD) sensor malfunctioning and reporting incorrect reading to the message being tampered by a malicious vehicle. To address these rapidly increasing security challenges, we have proposed an AI-enabled trust management system (AIT) in this article, which is an AI-enabled trust management system for vehicular networks using the blockchain technique. In the AIT system, each vehicle first senses, generates, and exchanges messages with other vehicles. These messages then get validated by the neighboring vehicles. As vehicles receive and validate messages from other nearby vehicles, they will establish and manage the trust of those nearby vehicles, which is enabled by utilizing the deep learning algorithm. Once a vehicle identifies untrustworthy vehicles, it reports them to the nearby roadside unit (RSU), and the RSU will validate the authenticity of the report as well as the identity of the vehicle by using the emerging blockchain technique. The security credentials of untrustworthy vehicles will then be revoked by the RSU. We have conducted an extensive experimental study to evaluate the AIT system. Simulation results clearly indicate that AIT performs better than existing approaches and can manage the trust of vehicles and detect malicious ones in an accurate and efficient manner. Chenyue Zhang, Wenjia Li, Yuansheng Luo, Yupeng Hu 0004 |
IEEE Internet Things J. | 4 |
| 2021 | Secure fusion approach for the Internet of Things in smart autonomous multi-robot systems
Wei Liang 0005, Zuoting Ning, Songyou Xie, Yupeng Hu 0004, Shaofei Lu, Da-Fang Zhang 0001 |
Inf. Sci. | 4 |
| 2021 | Unequal Failure Protection Coding Technique for Distributed Cloud Storage SystemsabstractIn recent years, erasure codes have become the de facto standard for data protection in large scale distributed cloud storage systems at the cost of an affordable storage overhead. However, traditional erasure coding schemes, such as Reed-Solomon codes, suffer from high reconstruction cost and I/Os. The recent past has seen a plethora of efforts to optimize the tradeoff between the reconstruction cost, I/Os and storage overhead. Quiet different from all prior studies, in this paper, our erasure coding technique makes the first attempt to take advantage of the unequal failure rates across the disks/nodes to optimize the system reliability and reconstruction performance. Specifically, our proposed technique, the Unequal Failure Protection based Local Reconstruction Code (UFP-LRC) divides the data blocks into several unequal-sized groups with local parities, assigning the data blocks stored on more failure-prone disks/nodes into the smaller-sized group, so as to provide unequal failure protection for each group. In this way, by exploiting the nonuniform local parity degrees, the proposed UFP-LRC enables the data blocks that are stored on more failure-prone disks/nodes to tolerate a greater number of failures while suffering from less repair cost than others, leading to a substantial improvement of the overall reliability and repair performance for cloud storage systems. We perform numerical analysis and build a prototype storage system to verify our approach. The analytical results show that the UFP-LRC technique gradually outperforms LRC along the increase of failure rate ratio. Also, extensive experiments show that, when compared to LRC, UFP-LRC is able to achieve a 10 to 15 percent improvement in throughput, and an 8 to 12 percent reduction in decoding latency, while retaining a comparable overall reliability. Yupeng Hu 0004, Yonghe Liu, Wenjia Li, Keqin Li 0001, Kenli Li 0001, Nong Xiao 0001, Zheng Qin 0001 |
IEEE Trans. Cloud Comput. | 1 |
| 2020 | HRAE: Hardware-assisted Randomization against Adversarial Example AttacksabstractWith the rapid advancements of the artificial intelligence, machine learning, especially neural networks, have shown huge superiority over humans in image recognition, autonomous vehicles and medical diagnosis. However, its opacity and inexplicability provide many chances for malicious attackers. Recent researches have shown that neural networks are vulnerable to adversarial example (AE) attacks. In the testing stage, it fools the model by adding subtle perturbations to the original sample to misclassify the input, which poses a serious threat to safety-critical areas such as autonomous driving. In order to mitigate this threat, this paper proposes a hardware-assisted randomization method against AEs, where an approximate computing technique in hardware, voltage over-scaling (VOS), is used to randomize the training set of the model, then the processed data are used to generate multiple neural network models, finally multiple redundant models are used for the integrated classification and detection of the AEs. Various AE attacks on the proposed defense are evaluated to prove its effectiveness. Jiliang Zhang 0002, Shuang Peng 0010, Yupeng Hu 0004, Wei Hu 0008, Jinmei Lai 0001, Jing Ye 0001, Xiangqi Wang |
ATS | 3 |
| 2020 | TrajData: On Vehicle Trajectory Collection With Commodity Plug-and-Play OBU DevicesabstractFor years, vehicle trajectory data have increasingly been important for a wide range of applications, from driver behavior investigation/classification, travel time/distance estimation, and routing in vehicular networks, to vehicle energy/emission evaluation. This article presents TrajData, the first systematic solution to reliable vehicle trajectory data collection, with only reliance on commercial-off-the-shelf (COTS) onboard unit (OBU) devices that utilize lightweight GPS modules and low-cost onboard diagnostics (OBD) readers. In the practical use of trajectory collection, GPS outages inevitably occur in urban environments thereby leading to large trajectory errors as well as missing vehicle location data. To resolve this, we propose a novel data-fusion-enabled deep learning approach with the purpose of achieving reliable vehicle trajectory collection in various urban road conditions. Specifically, we leverage motion information retrieved from OBD readers in TrajData to help reconstruct the trajectory data during GPS outages. By investigating the changes of direction angle from the OBD readings, we can identify different types of road sections. Furthermore, we integrate the neural arithmetic logic units (NALUs) into our trajectory reconstruction model to tame the challenges when GPS outages take place in various road sections. Experimental results from realistic data have demonstrated the effectiveness and reliability of the proposed method. In the road test, TrajData achieves an average position error below 15-m around a 60-s GPS outage, even in complex road sections, i.e., continuous turns and driving with accelerations/decelerations resulting in frequent changes of direction and speed. Zhu Xiao, Fancheng Li, Ronghui Wu, Hongbo Jiang 0001, Yupeng Hu 0004, Ju Ren 0001, Chenglin Cai, Arun Iyengar |
IEEE Internet Things J. | 5 |
| 2018 | An Efficient and Privacy-Preserving Multiuser Cloud-Based LBS Query SchemeabstractLocation-based services (LBSs) are increasingly popular in today’s society. People reveal their location information to LBS providers to obtain personalized services such as map directions, restaurant recommendations, and taxi reservations. Usually, LBS providers offer user privacy protection statement to assure users that their private location information would not be given away. However, many LBSs run on third-party cloud infrastructures. It is challenging to guarantee user location privacy against curious cloud operators while still permitting users to query their own location information data. In this paper, we propose an efficient privacy-preserving cloud-based LBS query scheme for the multiuser setting. We encrypt LBS data and LBS queries with a hybrid encryption mechanism, which can efficiently implement privacy-preserving search over encrypted LBS data and is very suitable for the multiuser setting with secure and effective user enrollment and user revocation. This paper contains security analysis and performance experiments to demonstrate the privacy-preserving properties and efficiency of our proposed scheme. Lu Ou, Hui Yin 0001, Zheng Qin 0001, Sheng Xiao, Yupeng Hu 0004 |
Secur. Commun. Networks | 6 |
| 2016 | Unequal Failure Protection Coding Technology for Cloud Storage SystemsabstractIn recent years, erasure codes have become the de facto standard for data protection of large scale distributed cloud storage systems at the cost of an affordable storage overhead. While traditional erasure coding schemes, such as Reed-Solomon codes, suffer from high reconstruction cost and I/Os. The recent past has seen a plethora of efforts to optimize the tradeoff between the reconstruction cost, I/Os and storage overhead. Quietly different from all prior studies, in this paper, our erasure coding technology makes the first attempt to take advantage of the unequal failure rates across the disks/nodes to optimize the reconstruction performance and system reliability. Specifically, our proposed technology, the Unequal Failure Protection based Local Reconstruction Code (UFP-LRC) divides the data blocks into several unequal-sized groups with local parities, assigning the data blocks stored on more failure-prone disks/nodes into the smaller-sized group, so as to provide unequal failure protection for each group. In this way, by exploiting the nonuniform local parity degrees, the proposed UFP-LRC enables the data blocks that are stored on more failure-prone disks/nodes to tolerate a greater number of failures while suffer from less repair cost than others, leading to a substantial improvement of overall repair performance and reliability for cloud storage system. We perform numerical analysis and build a prototype storage system to verify our approach. The analytical results show that the UFPLRC technique gradually outperforms LRC along the increase of failure rate ratio. Also, extensive experiments show that, when compared to LRC, UFP-LRC is able to achieve a 10% to 13% improvement in throughput, and a 8% to 12% reduction in decoding latency, while retaining a comparable overall reliability. Yupeng Hu 0004, Yonghe Liu, Wenjia Li, Nong Xiao 0001, Zheng Qin 0001, Shu Yin 0001 |
CLUSTER | 1 |
| 2016 | Malware Variant Detection Using Opcode Image Recognition with Small Training SetsabstractMalware detection becomes mission critical as its threats spread from personal computers to industrial control systems. Modern malware generally equips with sophisticated anti-detection mechanisms such as code-morphism, which allows the malware to evolve into many variants and bypass traditional code feature based detection systems. In this paper, we propose to disassemble binary executables into opcodes sequences, and then convert the opcodes into images. By comparing the opcode images generated from binary targets with the opcode images generated from known malware sample codes, we can detect if the target binary executables contain variants of these known malwares. Theoretical analysis and real-life experiments results show that malware detection using visualized analysis is comparable in terms of accuracy, our approach can significantly improve 15\% of detection accuracy when the detection set contains a large quantity of binaries and the training set is small. Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Sheng Xiao, Yupeng Hu 0004 |
ICCCN | 6 |
| 2016 | Multi-User Location Correlation Protection with Differential PrivacyabstractIn the big data era, with the rapid development of location-based applications, GPS enabled devices and big data institutions, location correlation privacy raises more and more people's concern. Because adversaries may combine location correlations with their background knowledge to guess users' privacy, such correlation should be protected to preserve users' privacy. In order to deal with the location disclosure problem, location perturbation and generalization have been proposed. However, most proposed approaches depend on syntactic privacy models without rigorous privacy guarantee. Furthermore, many approaches only consider perturbing the locations of one user without considering multi-user location correlations, so these techniques cannot prevent various inference attacks well. Currently, differential privacy has been regarded as a standard for privacy protection, but there are new challenges for applying differential privacy in the location correlations protection. The privacy protection not only should meet the needs of users who request location-based services, but also should protect location correlation among multiple users. In this paper, we propose a systematic solution to protect location correlations privacy among multiple users with rigorous privacy guarantee. First of all, we propose a novel definition, private candidate sets which are obtained by hidden Markov models. Then, we quantify the location correlation between two users by using the similarity of hidden Markov models. Finally, we present a private trajectory releasing mechanism which can preserve the location correlations among users who move under hidden Markov models in a period of time. Experiments on real-world datasets also show that multi-user location correlation protection is efficient. Lu Ou, Zheng Qin 0001, Yonghe Liu, Hui Yin 0001, Yupeng Hu 0004, Hao Chen 0051 |
ICPADS | 5 |
| 2016 | Secure Conjunctive Multi-Keyword Search for Multiple Data Owners in Cloud ComputingabstractRecently, secure search over encrypted cloud data has become a hot research spot and challenging task. Some secure search schemes have been proposed to try to meet this challenge. In this paper, we propose a conjunctive multi-keyword secure search scheme for multiple data owners. To guarantee data security and system flexibility in the multiple data owners environment, we design an ingenious secure query scheme that allows each data owner to adopt randomly chosen temporary keys to build secure indexes for different data files. An authorized data user does not need to know these temporary keys of constructing indexes and can instead randomly choose another temporary query keys to encrypt query keywords while the cloud can correctly perform keywords matching over encrypted data files. Extensive experiments demonstrate the correctness and practicality of the proposed scheme. Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Wenjie Li 0005, Lu Ou, Yupeng Hu 0004, Keqin Li 0001 |
ICPADS | 6 |
| 2016 | IRMD: Malware Variant Detection Using Opcode Image RecognitionabstractMalware detection becomes mission critical as its threats spread from personal computers to industrial control systems. Modern malware generally equips with sophisticated anti-detection mechanisms such as code-morphism, which allows the malware to evolve into many variants and bypass traditional code feature based detection systems. In this paper, we propose to disassemble binary executables into opcodes sequences, and then convert the opcodes into images. By using convolutional neural network to compare the opcode images generated from binary targets with the opcode images generated from known malware sample codes, we can detect if the target binary executables is malicious. Theoretical analysis and real-life experiments results show that malware detection using visualized analysis is comparable in terms of accuracy, our approach can significantly improve 15% of detection accuracy when the detection set contains a large quantity of binaries and the training set is much smaller. Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Yupeng Hu 0004 |
ICPADS | 5 |
| 2015 | A Personalized Recommendation Approach Based on Content Similarity Calculation in Large-Scale Data
Huigui Rong, Zheng Qin 0001, Yupeng Hu 0004, Chunhua Hu 0001 |
ICA3PP (1) | 4 |
| 2015 | A Secure and Fine-Grained Query Results Verification Scheme for Private Search Over Encrypted Cloud Data
Hui Yin 0001, Zheng Qin 0001, Jixin Zhang, Lu Ou, Yupeng Hu 0004, Huigui Rong |
ICA3PP (3) | 6 |