Yao Zheng 0004

dblp:66/3310-4 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
4since 2021 · last 2025
0000-0003-2820-1034ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 1 first-author · 4 since 2021Security and privacy · 4 · 4 first-authorSystems, architecture and hardware · 1
YearPublicationVenuePosition
2025 Enabling Joint Sensing and Communication via STBC Assisted NOMA in ISAC Systems
abstract
Integrated Sensing and Communication (ISAC) is a key enabler for Sixth-Generation (6G) and future wireless networks, which seamlessly combines ambient sensing with data communication. In this paper, we propose a novel ISAC-enabled Non-Orthogonal Multiple Access (NOMA) scheme named ISAC-Space-Time Block Coding (STBC) NOMA. We present a thorough performance comparison of our proposed scheme against three previously studied ISAC-NOMA variants: Conventional ISAC-NOMA, ISAC-Unmanned Aerial Vehicle (UAV) NOMA, and ISAC-Generalized Space Shift Keying (GSSK) NOMA, in a multi-user scenario. The comparison specifically focuses on three critical performance metrics: spectral efficiency, Bit Error Rate (BER), and Successive Interference Cancellation (SIC) decoding complexity. The evaluation results show that ISAC-STBC NOMA consistently outperforms the other schemes across all metrics. Specifically, ISAC-STBC NOMA achieves approximately 24% higher spectral efficiency at 30 dB Signal-to-Noise Ratio (SNR), reduces the BER by approximately 30%, and lowers SIC decoding complexity by up to 25%. These findings position ISAC-STBC NOMA as a strong candidate for next-generation networks, offering a well-balanced solution that enhances communication robustness, spectrum utilization, and computational efficiency.
Anindya Bal, Haofan Cai, Hanqing Guo, Yao Zheng 0004, Xiaoxue Zhang 0001
MASS4
2024 Interface-Based Side Channel in TEE-Assisted Networked Services
abstract
With the accelerating adaption of Cloud and Edge computing, cloud-based networked deployment emerges to enable providers to deliver services in a cost-effective and elastic manner. However, security concern remains one of the major obstacles to its wider adaption. Trusted Execution Environment (TEE) has been advocated to protect cloud services in an isolated execution environment. In this paper, we present a new genre of side-channel attack called interface-based side-channel attack and demonstrate its effectiveness on the TEE-assisted networked service system. The root cause of this attack is the input-dependent interface invocation (e.g., interface information and invocation patterns) that can be observed by untrusted software to reveal the control flows inside the enclave. Our evaluation demonstrates that the attack can effectively re-identify encrypted web pages processed in the SGX enclave with an accuracy of 87.6% and a recall of 76.6%, and can reduce the search domain of the 1024 bits RSA private keys to$1.69 \times 10^{-6}$of the original search domain. As countermeasures, we propose, implement and evaluate a set of static analysis tools to mitigate the newly discovered threats. The key idea is to use inter-procedural dataflow analysis to identify potential leakage via the interface, and then mitigate them during compilation using techniques including branch obfuscation, loop obfuscation, and constant size wrapper.
Yueqiang Cheng, Qi Li 0002, Kun Sun 0001, Yao Zheng 0004, Ning Zhang 0017, Xinghua Li 0001
IEEE/ACM Trans. Netw.6
2023 Cross-Modality Continuous User Authentication and Device Pairing With Respiratory Patterns
abstract
At-home screening systems for obstructive sleep apnea (OSA) can bring convenience to remote chronic disease management. However, the unsupervised home environment is subject to spoofing and unintentional interference from the household member. To improve robustness, this work presents SIENNA, an insider-resistant breathing-based authentication/pairing protocol. SIENNA leverages the uniqueness of breathing patterns to automatically and continuously authenticate a user and pairs a mobile OSA app and a physiological monitoring radar system (PRMS). SIENNA does not require biometric enrollment and instead transforms the respiratory measurements taken during the users routine physical checkup into breathing biometrics comparable with the PRMS readings. Furthermore, it can operate within a noisy multi-target home environment and is secure against a co-located attacker through the usage of JADE-ICA, fuzzy commitment, and friendly jamming. We fully implemented SIENNA and evaluated its performance with medium-scale trials. Results show that SIENNA can achieve reliable (> 90% success rate) user authentication and secure device pairing in a noisy environment against an attacker with full knowledge of the authorized users breathing biometrics.
Shekh M. M. Islam, Yao Zheng 0004, Yanjun Pan 0001, Marionne Millan, Willy Chang, Ming Li 0003, Olga Boric-Lubecke, Victor Lubecke, Wenhai Sun
IEEE Internet Things J.2
2021 Insider-Resistant Context-Based Pairing for Multimodality Sleep Apnea Test
abstract
The increasingly sophisticated at-home screening systems for obstructive sleep apnea (OSA), integrated with both contactless and contact-based sensing modalities, bring convenience and reliability to remote chronic disease management. However, the device pairing processes between system components are vulnerable to wireless exploitation from a non-compliant user wishing to manipulate the test results. This work presents SIENNA, an insider-resistant context-based pairing protocol. SIENNA leverages JADE-ICA to uniquely identify a user's respiration pattern within a multi-person environment and fuzzy commitment for automatic device pairing, while using friendly jamming technique to prevent an insider with knowledge of respiration patterns from acquiring the pairing key. Our analysis and test results show that SIENNA can achieve reliable (> 90% success rate) device pairing under a noisy environment and is robust against the attacker with full knowledge of the context information.
Yao Zheng 0004, Shekh M. M. Islam, Yanjun Pan 0001, Marionne Millan, Samson Aggelopoulos, Brian Lu, Alvin Yang, Thomas Yang 0003, Stephanie Aelmore, Willy Chang, Alana Power, Ming Li 0003, Olga Boric-Lubecke, Victor Lubecke, Wenhai Sun
GLOBECOM1
2020 ROBin: Known-Plaintext Attack Resistant Orthogonal Blinding via Channel Randomization
abstract
Orthogonal blinding based schemes for wireless physical layer security aim to achieve secure communication by injecting noise into channels orthogonal to the main channel and corrupting the eavesdropper’s signal reception. These methods, albeit practical, have been proven vulnerable against multiantenna eavesdroppers who can filter the message from the noise. The vulnerability is rooted in the fact that the main channel state remains static in spite of the noise injection, which allows an eavesdropper to estimate it promptly via known symbols and filter out the noise. Our proposed scheme leverages a reconfigurable antenna for Alice to rapidly change the channel state during transmission and a compressive sensing based algorithm for her to predict and cancel the changing effects for Bob. As a result, the communication between Alice and Bob remains clear, whereas randomized channel state prevents Eve from launching the knownplaintext attack. We formally analyze the security of the scheme against both single and multi-antenna eavesdroppers and identify its unique anti-eavesdropping properties due to the artificially created fast-changing channel. We conduct extensive simulations and real-world experiments to evaluate its performance. Empirical results show that our scheme can suppress Eve’s attack success rate to the level of random guessing, even if she knows all the symbols transmitted through other antenna modes.
Yanjun Pan 0001, Yao Zheng 0004, Ming Li 0003
INFOCOM2
2017 A Feedback Control-Based Crowd Dynamics Management in IoT System
abstract
The development of technologies related to the Internet of Things (IoT) provides a new perspective on applications pertaining to smart cities. Smart city applications focus on resolving issues facing people in everyday life, and have attracted a considerable amount of research interest. The typical issue encountered in such places of daily use, such as stations, shopping malls, and stadiums is crowd dynamics management. Therefore, we focus on crowd dynamics management to resolve the problem of congestion using IoT technologies. Real-time crowd dynamics management can be achieved by gathering information relating to congestion and propose less crowded places. Although many crowd dynamics management applications have been proposed in various scenarios and many models have been devised to this end, a general model for evaluating the control effectiveness of crowd dynamics management has not yet been developed in IoT research. Therefore, in this paper, we propose a model to evaluate the performance of crowd dynamics management applications. In other words, the objective of this paper is to present the proof-of-concept of control effectiveness of crowd dynamics management. Our model uses feedback control theory, and enables an integrated evaluation of the control effectiveness of crowd dynamics management methods under various scenarios. We also provide extensive numerical results to verify the effectiveness of the model.
Yuichi Kawamoto, Naoto Yamada, Hiroki Nishiyama 0001, Nei Kato, Yoshitaka Shimizu, Yao Zheng 0004
IEEE Internet Things J.6
2017 Location Based Handshake and Private Proximity Test with Location Tags
abstract
A location proximity test service allows mobile users to determine whether they are in close proximity to each other, and has found numerous applications in mobile social networks. Unfortunately, existing solutions usually reveal much of users' private location information during a proximity test. They are also vulnerable to location cheating where an attacker reports false locations to gain an advantage. Moreover, the initial trust establishment among unfamiliar users in large scale mobile social networks has been a challenging task. In this paper, we propose a novel scheme that enables a user to perform (1) a location based handshake that establishes secure communications among strangers, who do not have a pre-shared secret, and (2) a privacy-preserving proximity test without revealing the user's actual location to the server or other users not within the proximity. The proposed scheme is based on a novel concept, i.e., spatial-temporal location tags, and we put forward a location tag construction method using environmental signals that provides an unforgeable location proof. We use Bloom filters to efficiently represent users' location tags and vicinity regions. We exploit fuzzy extractor, a lightweight cryptographic primitive, to extract shared secrets between matching location tags. We conduct extensive analysis, simulation, and real experiments to demonstrate the feasibility, security, and efficiency of our scheme.
Yao Zheng 0004, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001
IEEE Trans. Dependable Secur. Comput.1
2016 Profiling the Strength of Physical-Layer Security: A Study in Orthogonal Blinding
abstract
Physical layer security for wireless communication is broadly considered as a promising approach to protect data confidentiality against eavesdroppers. However, despite its ample theoretical foundation, the transition to practical implementations of physical-layer security still lacks success. A close inspection of proven vulnerable physical-layer security designs reveals that the flaws are usually overlooked when the scheme is only evaluated against an inferior, single-antenna eavesdropper. Meanwhile, the attacks exposing vulnerabilities often lack theoretical justification. To reduce the gap between theory and practice, we posit that a physical-layer security scheme must be studied under multiple adversarial models to fully grasp its security strength. In this regard, we evaluate a specific physical-layer security scheme, i.e. orthogonal blinding, under multiple eavesdropper settings. We further propose a practical "ciphertext-only attack" that allows eavesdroppers to recover the original message by exploiting the low entropy fields in wireless packets. By means of simulation, we are able to reduce the symbol error rate at an eavesdropper below 1% using only the eavesdropper's receiving data and a general knowledge about the format of the wireless packets.
Yao Zheng 0004, Matthias Schulz 0001, Wenjing Lou, Y. Thomas Hou 0001, Matthias Hollick
WISEC1
2015 Privacy-Preserving Link Prediction in Decentralized Online Social Networks
Yao Zheng 0004, Bing Wang 0005, Wenjing Lou, Y. Thomas Hou 0001
ESORICS (2)1
2015 PeerClean: Unveiling peer-to-peer botnets through dynamic group behavior analysis
abstract
Advanced botnets adopt a peer-to-peer (P2P) infrastructure for more resilient command and control (C&C). Traditional detection techniques become less effective in identifying bots that communicate via a P2P structure. In this paper, we present PeerClean, a novel system that detects P2P botnets in real time using only high-level features extracted from C&C network flow traffic. PeerClean reliably distinguishes P2P bot-infected hosts from legitimate P2P hosts by jointly considering flow-level traffic statistics and network connection patterns. Instead of working on individual connections or hosts, PeerClean clusters hosts with similar flow traffic statistics into groups. It then extracts the collective and dynamic connection patterns of each group by leveraging a novel dynamic group behavior analysis. Comparing with the individual host-level connection patterns, the collective group patterns are more robust and differentiable. Multi-class classification models are then used to identify different types of bots based on the established patterns. To increase the detection probability, we further propose to train the model with average group behavior, but to explore the extreme group behavior for the detection. We evaluate PeerClean on real-world flow records from a campus network. Our evaluation shows that PeerClean is able to achieve high detection rates with few false positives.
Qiben Yan 0001, Yao Zheng 0004, Tingting Jiang 0005, Wenjing Lou, Y. Thomas Hou 0001
INFOCOM2
2015 DDoS attack protection in the era of cloud computing and Software-Defined Networking
Bing Wang 0005, Yao Zheng 0004, Wenjing Lou, Y. Thomas Hou 0001
Comput. Networks2
2014 DDoS Attack Protection in the Era of Cloud Computing and Software-Defined Networking
abstract
Cloud computing has become the real trend of enterprise IT service model that offers cost-effective and scalable processing. Meanwhile, Software-Defined Networking (SDN) is gaining popularity in enterprise networks for flexibility in network management service and reduced operational cost. There seems a trend for the two technologies to go hand-in-hand in providing an enterprise's IT services. However, the new challenges brought by the marriage of cloud computing and SDN, particularly the implications on enterprise network security, have not been well understood. This paper sets to address this important problem. We start by examining the security impact, in particular, the impact on DDoS attack defense mechanisms, in an enterprise network where both technologies are adopted. We find that SDN technology can actually help enterprises to defend against DDoS attacks if the defense architecture is designed properly. To that end, we propose a DDoS attack mitigation architecture that integrates a highly programmable network monitoring to enable attack detection and a flexible control structure to allow fast and specific attack reaction. The simulation results show that our architecture can effectively and efficiently address the security challenges brought by the new network paradigm.
Bing Wang 0005, Yao Zheng 0004, Wenjing Lou, Y. Thomas Hou 0001
ICNP2
2013 Scalable and Secure Sharing of Personal Health Records in Cloud Computing Using Attribute-Based Encryption
abstract
Personal health record (PHR) is an emerging patient-centric model of health information exchange, which is often outsourced to be stored at a third party, such as cloud providers. However, there have been wide privacy concerns as personal health information could be exposed to those third party servers and to unauthorized parties. To assure the patients' control over access to their own PHRs, it is a promising method to encrypt the PHRs before outsourcing. Yet, issues such as risks of privacy exposure, scalability in key management, flexible access, and efficient user revocation, have remained the most important challenges toward achieving fine-grained, cryptographically enforced data access control. In this paper, we propose a novel patient-centric framework and a suite of mechanisms for data access control to PHRs stored in semitrusted servers. To achieve fine-grained and scalable data access control for PHRs, we leverage attribute-based encryption (ABE) techniques to encrypt each patient's PHR file. Different from previous works in secure data outsourcing, we focus on the multiple data owner scenario, and divide the users in the PHR system into multiple security domains that greatly reduces the key management complexity for owners and users. A high degree of patient privacy is guaranteed simultaneously by exploiting multiauthority ABE. Our scheme also enables dynamic modification of access policies or file attributes, supports efficient on-demand user/attribute revocation and break-glass access under emergency scenarios. Extensive analytical and experimental results are presented which show the security, scalability, and efficiency of our proposed scheme.
Ming Li 0003, Shucheng Yu, Yao Zheng 0004, Kui Ren 0001, Wenjing Lou
IEEE Trans. Parallel Distributed Syst.3
2012 SHARP: Private Proximity Test and Secure Handshake with Cheat-Proof Location Tags
Yao Zheng 0004, Ming Li 0003, Wenjing Lou, Y. Thomas Hou 0001
ESORICS1