Xiaoli Zhang 0003

dblp:67/6767-3 · DBLP profile ↗
← Back
27ranked-venue papers
9as first author
24since 2021 · last 2026
0000-0002-5255-2216ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 5 first-author · 7 since 2021Security and privacy · 10 · 2 first-author · 10 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Towards Efficient and Reliable Training Assurance of Untrusted Federated Learning Participants Under Hardware Non-Determinism
abstract
Federated learning (FL) is a popular privacy-preserving machine learning paradigm, enabling collaborative training across participants without exposing local data. Since FL loses direct control over participants' training executions, a fundamental requirement is to verify that participants faithfully perform the assigned training tasks. In this paper, we present TrustFL+, an efficient, scalable, and reliable verification scheme that ensures the training correctness of federated learning participants by leveraging both Trusted Execution Environments (TEEs) and GPUs. Essentially, it pushes all local training on high-performance but untrusted GPUs, while the TEE replicates the random parts for tunable levels of assurance. A key challenge is that hardware non-determinism can cause the same floating-point operations to yield different results between GPUs and TEEs, leading to false positives when participants behave honestly. TrustFL+ builds on deterministic training by recording rounding directions of intermediate operations during GPU-side model training and reusing them in TEE-based verification. It especially introduces adaptive rounding precisions to practically control non-determinism while maintaining global model performance in federated learning systems with lots of heterogeneous GPUs and iterative training. We prototype TrustFL+ using a range of NVIDIA GPUs covering multiple hardware architectures, along with Intel SGX, and evaluate its performance across convolutional neural networks and transformer-based networks. The experimental results demonstrate that TrustFL+ delivers up to an order of magnitude speedup compared to naive SGX-based training. Furthermore, all models trained with TrustFL+ on different GPU architectures successfully pass verification within SGX, resulting in 0 false positives.
Xiaoli Zhang 0003, Jiaqing Cheng, Wenmao Liu, Xiaohu Ye, Ke Xu 0002, Qi Li 0002, Xu-Cheng Yin
IEEE Trans. Dependable Secur. Comput.2
2025 Training Robust Classifiers for Classifying Encrypted Traffic under Dynamic Network Conditions
abstract
Most existing DL-based encrypted traffic classification methods suffer performance degradation in real-world deployments due to dynamic network conditions, e.g., network environment changes and traffic obfuscation. Dynamic network conditions cause encrypted traffic to exhibit distinct feature patterns during training and testing phases. To address this issue, we propose MetaTraffic, a novel and general DL training framework built upon meta-learning that enhances the performance of supervised DL models designed for encrypted traffic classification against dynamic network conditions. Our key observation is that the traffic of the same network behaviors share the same semantic features even under different network conditions, which can be considered as stable feature representations. Therefore, MetaTraffic helps DL models learn stable feature representations by minimizing the discrepancies in how the models represent traffic features under different network conditions, thereby achieving robust classification under dynamic network conditions. We implement MetaTraffic based on meta-learning with three innovative facilitate modules to enhance its performance. We evaluate MetaTraffic using three public datasets and three new large-scale encrypted traffic datasets that cover multiple types of network conditions. Experimental results show that, under dynamic multiple types of network conditions, our framework improves the accuracy of DL models by 8.94% and the F1-Macro score by 12.55%, while existing robust training methods decrease the accuracy by 28.85% and the F1-Macro score by 33.52%.
Yuqi Qing, Qilei Yin, Xinhao Deng 0001, Xiaoli Zhang 0003, Zhuotao Liu, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
CCS4
2025 Detecting and Adapting to Stealthy Label-Inversion Drifts via Conditional Distribution Inference
abstract
Deep learning (DL) based malicious traffic detectors have been widely developed to detect diverse network attacks, yet they are suffering from significant performance degradation due to concept drift. Existing anti-concept drift arts focus on combating the drifting traffic whose features significantly diverge from training traffic. However, they neglect a stealthy yet common situation where the testing traffic has similar features to the training traffic but with opposite ground truth labels. As a result, the DL-based detectors would always make incorrect predictions for the stealthy drifting traffic, insufficient to perform long-term real-world intrusion detection. In this paper, we propose Chameleon, a novel active learning framework that combats stealthy drifting traffic by inferring the conditional distribution of the testing traffic with small manual labeling overhead. Specifically, Chameleon measures the fine-grained correlations between the high-dimensional and heterogeneous testing traffic and selects a small number of highly representative testing traffic samples for manual labeling, to accurately infer other testing samples’ labels. With the inferred labels, Chameleon checks the conditional distribution shift from the training to testing traffic to detect concept drift and incrementally trains the DL-based detectors to make them effectively adapt to the shifted distribution. Extensive experiments with six supervised and unsupervised DL-based detectors on three public and four synthetic datasets show that, under stealthy drifting traffic, Chameleon improves the AUT of the DL-based detectors by a range of $18.53 \%$ to $23.89 \%$, while the improvement of SOTA baselines is only between $0.06 \%$ and $1.86 \%$.
Xiaoli Zhang 0003, Qilei Yin, Jianrong Zhang, Ke Xu 0002, Qi Li 0002, Xu-Cheng Yin
RAID1
2025 DePoL: Assuring training integrity in collaborative learning via decentralized verification
Xiaoli Zhang 0003, Xuanyu Yin, Hongbing Cheng
J. Parallel Distributed Comput.2
2025 DCrowd: Decentralized Mobile Crowdsensing Via Proof of Task Assignment Blockchain
abstract
Recently, blockchain-based decentralized mobile crowdsensing systems have emerged to eliminate traditional centralized trust and to achieve transparent task assignments via smart contracts. It allows workers to select tasks freely, thereby maximizing their benefits. However, prior designs rarely considered the globally optimal task assignment that significantly impacts the efficiency and quality of task performance, like maximizing the task completion ratio and minimizing the total travel distance of workers. So in this paper, we propose DCrowd, a new blockchain-based mobile crowdsensing system, to realize the decentralized, transparent, and globally optimal task assignment. In brief, we first introduce the Proof of Task Assignment consensus mechanism. This allows miners to conduct globally optimal task assignments off-chain, leverages smart contracts to perform lightweight verification for task assignment results on-chain, and stores the globally optimal task assignment in a customized block. Then, we devise the Weight-Prioritized Task Selection strategy and Threshold-based Adaptive Minimum Cost Flow algorithm, to further optimize the system performance and guide miners in competing for minting rights. A thorough theoretical analysis is provided. Extensive experiments on real-world datasets indicate that DCrowd can reduce the broadcast and consensus latency by over 50% and improve the throughput by over 87% compared with existing systems.
Hao Zeng 0006, Helei Cui, Xiaoli Zhang 0003, Bo Zhang 0119, Yuefeng Du 0001, Bin Guo 0001, Zhiwen Yu 0001
IEEE Trans. Dependable Secur. Comput.3
2025 OTA-Key: Over-the-Air Key Management for Flexible and Reliable IoT Device Provision
abstract
As the Internet of Things (IoT) industry advances, the imperative to secure IoT devices has become increasingly critical. Current practices in both industry and academia advocate for the enhancement of device security through key installation. However, it has been observed that, in practice, IoT vendors frequently assign shared keys to batches of devices. This practice can expose devices to risks, such as data theft by attackers or large-scale Distributed Denial of Service (DDoS) attacks. To address this issue, our intuition is to assign a unique key to each device. Unfortunately, this strategy proves to be highly complex within the IoT context, as existing keys are typically hardcoded into the firmware, necessitating the creation of bespoke firmware for each device. Furthermore, correct pairing of device keys with their respective devices is crucial. Errors in this pairing process would incur substantial human and temporal resources to rectify and require extensive communication between IoT vendors, device manufacturers, and cloud platforms, leading to significant communication overhead. To overcome these challenges, we propose the OTA-Key scheme. This approach fundamentally decouples device keys from the firmware features stored in flash memory, utilizing an intermediary server to allocate unique device keys in two distinct stages and update keys. We conducted a formal security verification of our scheme using ProVerif and assessed its performance through a series of evaluations. The results demonstrate that our scheme is secure and effectively manages the large-scale distribution and updating of unique device keys. Additionally, it achieves significantly lower update times and data transfer volumes compared to other schemes.
Yi He 0020, Xiaoli Zhang 0003, Chunhua Song
IEEE Trans. Netw. Serv. Manag.4
2025 SmartUpdater: Enabling Transparent, Automated, and Secure Maintenance of Stateful Smart Contracts
abstract
Smart contracts in the Ethereum system are stored tamper-resistant, complicating necessary maintenance for offering new functionalities or fixing security vulnerabilities. Previous contract maintenance approaches mainly focus on logic modification using delegatecall-based patterns. While popular, they fail to handle data state updates (like storage layout changes), leading to impracticality and security risks in real-world applications. To address these challenges, this paper introduces SmartUpdater, a novel toolchain designed for transparent, automated, and secure maintenance of stateful smart contracts. SmartUpdater employs a hyperproxy-based contract maintenance pattern, where the hyperproxy serves as a constant entry and ensures that any state/logic modifications remain transparent to end users. SmartUpdater automates the maintenance process in terms of development streamlining, gas cost efficiency, and state migration verifiability. In extensive evaluations, we show that SmartUpdater can reduce gas consumption in contract maintenance compared with actual maintenance approaches. The evaluations point out the potential of SmartUpdater to significantly simplify the maintenance process for developers.
Xiaoli Zhang 0003, Yiqiao Song, Yuefeng Du 0001, Chengjun Cai, Hongbing Cheng, Ke Xu 0002, Qi Li 0002
IEEE Trans. Software Eng.1
2024 AACD '24: 11th ACM Workshop on Adaptive and Autonomous Cyber Defense
abstract
The eleventh ACM Workshop on Adaptive and Autonomous Cyber Defense (AACD) will be held on October 14, 2024, in conjunction with the ACM Conference on Computer and Communications Security (CCS). AACD represents a cutting-edge approach to cybersecurity, where systems leverage AI and machine learning to dynamically detect, respond to, and mitigate evolving cyber threats in real time, minimizing the need for human intervention. A key aspect of this approach is adaptability-autonomous systems can assess attacker behavior, anticipate future threats, and adjust their defenses proactively. As cyberattacks grow more sophisticated, this transition from static defense strategies to dynamic, automated responses offers organizations a more resilient way to protect against emerging threats. The workshop will focus on discussing the challenges and opportunities inherent in this advanced cybersecurity paradigm.
Neil Zhenqiang Gong, Qi Li 0002, Xiaoli Zhang 0003
CCS3
2024 RobustETH: Ensuring Economic Fairness in ETH2.0's Distributed Validator Technology
abstract
Distributed Validator Technology (DVT) mitigates single points of failure in Ethereum validators by distributing validator duties across a node cluster and making decisions within the cluster through consensus algorithms. However, these systems often fail to ensure economic fairness for participants, where misconduct by a few nodes can lead to financial losses for honest nodes within the cluster. To address this issue, we introduce RobustETH, an innovative DVT implementation that prioritizes operational efficiency and economic fairness for participants. Specifically, RobustETH incorporates an efficient consensus protocol, X-IBFT, to enhance DVT’s operational efficiency. Additionally, we propose a BFT forensic protocol and a reputation-based recluster strategy to accurately penalize malicious nodes and mitigate their impact, thereby safeguarding the financial interests of honest participants. Our theoretical analysis proves RobustETH’s safety, liveness, and accountability. Moreover, through comprehensive evaluations, we demonstrate that RobustETH achieves a 58% reduction in end-to-end latency compared to current state-of-the-art DVT implementations while ensuring economic fairness.
Shenghang Chen, Xiaoli Zhang 0003, Hongbing Cheng
ICCCN4
2024 Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak Prompts
abstract
Large Vision Language Models (VLMs) extend and enhance the perceptual abilities of Large Language Models (LLMs).Despite offering new possibilities for LLM applications, these advancements raise significant security and ethical concerns, particularly regarding the generation of harmful content.While LLMs have undergone extensive security evaluations with the aid of red teaming frameworks, VLMs currently lack a well-developed one.To fill this gap, we introduce Arondight, a standardized red team framework tailored specifically for VLMs.Arondight is dedicated to resolving issues related to the absence of visual modality and inadequate diversity encountered when transitioning existing red teaming methodologies from LLMs to VLMs.Our framework features an automated multi-modal jailbreak attack, wherein visual jailbreak prompts are produced by a red team VLM, and textual prompts are generated by a red team LLM guided by a reinforcement learning agent.To enhance the comprehensiveness of VLM security evaluation, we integrate entropy bonuses and novelty reward metrics.These elements incentivize the RL agent to guide the red team LLM in creating a wider array of diverse and previously unseen test cases.Our evaluation of ten cutting-edge VLMs exposes significant security vulnerabilities, particularly in generating toxic images and aligning multi-modal prompts.In particular, our Arondight achieves an average attack success rate of 84.5% on GPT-4 in all fourteen prohibited scenarios defined by OpenAI in terms of generating toxic text.For a clearer comparison, we also categorize existing VLMs based on their safety levels and provide corresponding reinforcement recommendations.Our multimodal prompt dataset and red team code will be released after ethics committee approval.
Yi Liu 0057, Chengjun Cai, Xiaoli Zhang 0003, Xingliang Yuan, Cong Wang 0001
ACM Multimedia3
2024 From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT Devices
Yi He 0020, Xiaoli Zhang 0003, Qian Wang 0002, Renjie Xie, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
NDSS3
2024 Deep Reinforcement Learning from Drifting Network Environments in Anomaly Detection
Junli Zheng, Shaobing Wang, Xiaoli Zhang 0003, Hongbing Cheng
SecureComm (1)4
2024 EVM-Shield: In-Contract State Access Control for Fast Vulnerability Detection and Prevention
abstract
Recently, smart contracts have been widely applied in security-sensitive fields yet are fragile to various vulnerabilities and attacks. Regarding this, existing research efforts either statically scrutinize smart contracts’ code or detect suspicious transaction execution flows. However, they either fail to timely protect contracts or only handle a small subset of well-known vulnerabilities. In the paper, we propose$\mathtt {EVM}$-$\mathtt {Shield}$that secures vulnerable smart contracts in real-time via fine-grained access control over sensitive states. The behind rationale is most of attacks aim to manipulate money-related states (e.g., tokens) for profits. Specifically, transaction-level state access control policies are first defined by developers and then translated into EVM-level policies with contract-aware function-level state access permissions. In policy enforcement,$\mathtt {EVM}$-$\mathtt {Shield}$introduces a hybrid storage analyzer to accurately identify (dynamic-allocated) storage locations for policy-involved states and a multi-stage cache based filter to fast revert bad transactions with unexpected state access behaviors. Finally, we conduct thorough experiments using 12 types of real-world contract vulnerabilities and all open-source smart contracts on the first$8M$blocks of Ethereum. The results demonstrate that$\mathtt {EVM}$-$\mathtt {Shield}$outperforms two state-of-the-art runtime analysis tools in terms of attack detection. Extensive performance evaluations with$185M$real-world transactions show that$\mathtt {EVM}$-$\mathtt {Shield}$can block 100% unexpected state accesses at the cost of 8% throughput degradation (compared with the native EVM).
Xiaoli Zhang 0003, Wenxiang Sun, Hongbing Cheng, Chengjun Cai, Helei Cui, Qi Li 0002
IEEE Trans. Inf. Forensics Secur.1
2024 TEBChain: A Trusted and Efficient Blockchain-Based Data Sharing Scheme in UAV-Assisted IoV for Disaster Rescue
abstract
The destruction of communication infrastructure after a disaster makes it impossible for vehicles to timely transmit important data, such as casualty locations, road conditions and rescue demands, which brings great difficulties to ensure safe driving and efficient rescue. Some existing schemes have proposed the use of Unmanned Aerial Vehicles (UAVs) to assist data sharing in the Internet of Vehicles (IoV) to perform instant rescue missions. However, the untrusted network environment after the disaster and the mutual unbelief among rescue vehicles lead to potential security problems in data sharing between vehicles and UAVs. In addition, some selfish or malicious participants may disseminate meaningless or false data, which will not only waste valuable rescue resources in disaster areas but also may threaten the safety of rescue workers. To overcome these challenges, we propose TEBChain, a trusted and efficient data sharing scheme based on blockchain. In TEBChain, a blockchain-based lightweight framework is first designed to guarantee effective data sharing and record all abnormal behavior. Then, we present an improved key update mechanism based on the Boneh-Lynn-Shacham (BLS) threshold signature, which can ensure the trust of shared data among frequently moving vehicles. Furthermore, to facilitate consensus and reduce communication overhead, a lightweight and secure PBFT (LS-PBFT) consensus protocol is proposed to enable efficient rescue of vehicles and UAVs. Finally, the effectiveness and feasibility of our proposed TEBChain are validated through performance comparisons and simulation experiments.
Duanyang Liu, Xiaoli Zhang 0003, Hongbing Cheng
IEEE Trans. Netw. Serv. Manag.5
2024 Privacy-Preserving and Lightweight Verification of Deep Packet Inspection in Clouds
abstract
In the trend of network middleboxes as a service, enterprise customers adopt in-the-cloud deep packet inspection (DPI) services to protect networks. As network misconfigurations and hardware failures notoriously exist, recent efforts envision to ensure the execution integrity of DPI services in untrusted clouds. However, they either require enterprise customers to know proprietary DPI rulesets of cloud providers or introduce forbidden overhead in the network context. In the paper, we propose a privacy-preserving and lightweight verification scheme that efficiently checks whether in-the-cloud DPI services run correctly without leaking private DPI rulesets. Particularly, our design introduces one trusted third party to perform privacy-preserving and trustworthy ruleset evaluation and DPI execution verification. Meanwhile, it devises a novel DPI ruleset authentication method that enables tamper-proof DPI operations and facilitates fast proof generation. The proofs can be verified without requiring the verifier to always maintain all rulesets. To further reduce the verification costs while resisting cloud cheating behaviors like bias treatments of packets, it employs a commitment-based delayed sampling mechanism which requires the DPI services to first demonstrate that all packets have been processed before receiving sampling decisions. Moreover, extensive experiments are conducted based on Click modules. The results show that the proposed scheme is practical and only incurs the real-time overhead of 10–20 microseconds.
Xiaoli Zhang 0003, Yiqiao Song, Hongbing Cheng, Ke Xu 0002, Qi Li 0002
IEEE/ACM Trans. Netw.1
2024 Accelerating Cross-Shard Blockchain Consensus via Decentralized Coordinators Service With Verifiable Global States
abstract
Sharding is a promising technique to improve the scalability of blockchain systems via processing transactions in parallel. However, there is an overwhelmingly high proportion of cross-shard transactions requiring complicated cross-shard consensus among the involved shards. To solve the problem, most state-of-the-art works adopt a centralized or decentralized coordinator to harmonize the cross-shard consensus. Nevertheless, they usually incur a confirmation latency of at least three consensus rounds and fail to avoid unnecessary communication costs for invalid and conflicting cross-shard transactions. Therefore, we propose DCchain that fully eliminates computation and communication latency for invalid or conflicting transactions. Specifically, DCchain introduces a decentralized coordinator (DC) that maintains verifiable global states. DC directly identifies and aborts invalid and conflicting cross-shard transactions, avoiding additional cross-shard computation and communication overhead. Besides, we present a robust two-tier consensus protocol. It commits valid cross-shard transactions through efficient interaction between DC and involved shards while defeating Byzantine behaviors. Finally, our performance evaluations demonstrate that DCchain's efficiency is superior to a popular existing work by nearly three times at best.
Xiaoli Zhang 0003, Hongbing Cheng
IEEE Trans. Serv. Comput.2
2023 Secure Collaborative Learning in Mining Pool via Robust and Efficient Verification
abstract
Recently, collaborative learning is proposed to amortize massive computation costs of highly sophisticated artificial intelligence (AI) tasks. To attract lots of participants, researchers investigate blockchains ‘ economic incentives with proof of useful work (PoUW) consensus protocols to motivate substantial numbers of miners in a mining pool to complete AI tasks. However, participants might be untrusted and defraud rewards with as less as possible efforts. In the paper, we propose a robust and efficient proof of learning scheme called RPoL that enables pool managers to verify the training integrity of pool workers for secure pooled mining. Specifically, we devise an address-encoded model and employ a commitment-based secure sampling method to prevent malicious participants from abusing well-trained models or evading the sampling-based verification. Besides, we optimize RPoL via locality-sensitive hashing (LSH) to achieve communication-efficient verification while tolerating inherent reproduction errors of AI tasks. Furthermore, we conduct theoretical analysis and extensive evaluations. The results demonstrate that RPoL preserves high model performance against adversaries with acceptable costs and thus helps the pool win the mining competition among consensus nodes.
Xiaoli Zhang 0003, Hongbing Cheng, Tong Che, Ke Xu 0002, Weiqiang Wang 0002, Wenbiao Zhao, Qi Li 0002
ICDCS1
2023 EPT: Enhancing User Transparency for Confidential Smart Contract
abstract
In the burgeoning era of digital finance, ensuring user privacy protection within blockchain systems has become a crucial concern. Despite this, existing privacy enhancement methods often lack user-friendliness, as they necessitate users to navigate complex protocols, thereby raising the barrier to entry. This paper introduces EPT, an efficient framework that not only addresses the user privacy concern but also enhances usability. Our method allows users to interact with confidential smart contracts deployed in a Trusted Execution Environment (TEE) by sending private transactions directly to the blockchain. We devise a secure TEE attestation and data privacy scheme for secure private transactions, even when users interact indirectly with the TEE. Further, we utilize a robust data acquisition approach for inputting valid and fresh private transaction-related data into the TEE. Our extensive evaluations demonstrate that EPT can deliver confidential transactions at a gas cost comparable to that of non-confidential block transactions, with a high throughput of 2, 715 tx/s, and an end-to-end latency of around 12 seconds.
Duanyang Liu, Xiaoli Zhang 0003, Hongbing Cheng
MSN4
2023 An Efficient and Secure Trading Framework for Shared Charging Service Based on Multiple Consortium Blockchains
abstract
While electric vehicles are proliferating rapidly, the number of charging piles is only 1/16 of the number of electric vehicles, showing big tension between small supply of public charging piles and intense charging demand of electric vehicles. To alleviate the tension, it is highly desired to incorporate existing idle private charging piles into a shared charging service. However, existing solutions do not well implement the system due to some non-negligible issues, like poor consensus performance or lack of verification for outputs from blockchain networks. In the article, we propose an efficient and secure trading framework built atop multiple consortium blockchains. It devises a novel node voting mechanism so as to improve consensus efficiency. Meanwhile, it employs a publicly verifiable design based on the$(t,n)$Boneh-Lynn-Shacham (BLS) threshold signature technique, so as to enable entities outside the blockchain to verify the consistency between the output results with the valid consensus. Besides these novel system-level designs, it also introduces a fair and robust trading strategy running by smart contracts on the platform. Furthermore, we implemented a proof-of-concept system and conducted extensive experiments. The results show that the overall latency across chains is reduced by about 26% with the node voting mechanism and the transactions fees are comparable to recent popular cross-chain applications.
Peng Zhao 0022, Xiaoli Zhang 0003, Hongbing Cheng
IEEE Trans. Serv. Comput.4
2022 An Efficient Fully Homomorphic Encryption Sorting Algorithm Using Addition Over TFHE
abstract
Fully homomorphic encryption (FHE) can effectively protect data privacy. It allows users to entrust data operations to a third party on a cloud server without revealing their own privacy. Sorting algorithms are the fundamental technique of managing and processing data. Currently, the sorting algorithms based on the traditional FHE schemes of BGV (Brakerski-Gentry-Vaikuntanathan), BFV (BrakerskiFan-Vercauteren) and CKKS (Cheon-Kim-Kim-Song) are difficult to implement and are inefficient because of their slow bootstrapping techniques. TFHE (Fast Fully Homomorphic Encryption over the Torus), a fast FHE scheme over the torus based on GSW (Gentry-Sahai-Waters), significantly decrease the time cost of bootstrapping. In this paper, we first design the bitwise FHE comparison and swap operations using the bootstrapped binary gates of the TFHE library. With the two operations, a bubble sort algorithm is proposed. By reducing the depth of sorting circuits in the proposed bubble sort, we further present AdditionSort, an efficient sorting algorithm using homomorphic addition, which can support the operations of arbitrary array length and unlimited element size. The experiments show that AdditionSort is nearly 50% faster than the bubble sort when the size of an element exceeds 32 bits.
Xiaoli Zhang 0003, Hongbing Cheng
ICPADS3
2022 Good Learning, Bad Performance: A Novel Attack Against RL-Based Congestion Control Systems
abstract
Reinforcement Learning (RL) has been applied to solve decision-making problems in computer network designs, especially in TCP congestion control. As RL-based congestion control methods enable powerful learning abilities, it achieves competitive performance and adaptiveness advantages over the traditional methods. However, RL-based systems suffer from adversarial attacks that generate perturbations to significantly degrade the performance. In this paper, we conduct a comprehensive study of adversarial attacks against RL-based congestion control systems. Unlike the state-of-the-art adversarial attacks on images where an attacker can easily obtain the input states to introduce perturbations, the attacker cannot directly obtain the input states in congestion control settings that are only available to the agents. It is challenging to add effective perturbations without knowing the input states for RL-based congestion control models. To solve the challenge, we develop an adversarial attack to estimate states of the target agent, craft adversarial perturbations, and apply the generated perturbations in an automated fashion. We evaluate how our adversarial attack affects the target agent’s decision-making process. Our experiments illustrate that our attack can effectively reduce about 50% average throughput while increasing more than 36x latency and 45% packet loss rate.
Zijie Yang, Jiahao Cao 0001, Zhuotao Liu, Xiaoli Zhang 0003, Kun Sun 0001, Qi Li 0002
IEEE Trans. Inf. Forensics Secur.4
2021 See through Walls: Detecting Malware in SGX Enclaves with SGX-Bouncer
abstract
Intel Software Guard Extensions (SGX) offers strong confidentiality and integrity protection to software programs running in untrusted operating systems. Unfortunately, SGX may be abused by attackers to shield suspicious payloads and conceal misbehaviors in SGX enclaves, which cannot be easily detected by existing defense solutions. There is no comprehensive study conducted to characterize malicious enclaves. In this paper, we present the first systematic study that scrutinizes all possible interaction interfaces between enclaves and the outside (i.e., cache-memory hierarchy, host virtual memory, and enclave-mode transitions), and identifies seven attack vectors. Moreover, we propose SGX-Bouncer, a detection framework that can detect these attacks by leveraging multifarious side-channel observations and SGX-specific features. We conduct empirical evaluations with existing malicious SGX applications, which suggests SGX-Bouncer can effectively detect various abnormal behaviors from malicious enclaves.
Xiaoli Zhang 0003, Qi Li 0002, Kun Sun 0001, Yinqian Zhang
AsiaCCS2
2021 Detecting Localized Adversarial Examples: A Generic Approach using Critical Region Analysis
abstract
Deep neural networks (DNNs) have been applied in a wide range of applications, e.g., face recognition and image classification; however, they are vulnerable to adversarial examples. By adding a small amount of imperceptible perturbations, an attacker can easily manipulate the outputs of a DNN. Particularly, the localized adversarial examples only perturb a small and contiguous region of the target object, so that they are robust and effective in both digital and physical worlds. Although the localized adversarial examples have more severe real-world impacts than traditional pixel attacks, they have not been well addressed in the literature. In this paper, we propose a generic defense system called TaintRadar to accurately detect localized adversarial examples via analyzing critical regions that have been manipulated by attackers. The main idea is that when removing critical regions from input images, the ranking changes of adversarial labels will be larger than those of benign labels. Compared with existing defense solutions, TaintRadar can effectively capture sophisticated localized partial attacks, e.g., the eye-glasses attack, while not requiring additional training or fine-tuning of the original model's structure. Comprehensive experiments have been conducted in both digital and physical worlds to verify the effectiveness and robustness of our defense.
Fengting Li, Xuankai Liu, Xiaoli Zhang 0003, Qi Li 0002, Kun Sun 0001
INFOCOM3
2021 vSFC: Generic and Agile Verification of Service Function Chains in the Cloud
abstract
With the advent of network function virtualization (NFV), outsourcing network functions (NFs) to the cloud is becoming increasingly popular for enterprises since it brings significant benefits for NF deployment and maintenance, such as improved scalability and reduced overhead. However, NF outsourcing limits the control of customer enterprises over NF deployment and management, consequently raising serious security concerns. Enterprises cannot ensure whether their outsourced NFs and associated service function chains (SFCs) are correctly enforced according to their specifications. In this paper, we propose vSFC, an SFC verification scheme that allows an enterprise to accurately verify the correctness of SFC enforcement in real time. Specifically, it can detect a wide range of SFC violations including forwarding path incompliance, packet dropping, and flow dropping attacks. Meanwhile, it is generic and agile, which can be applied to arbitrary cloud architectures without requiring any modification to NFs. To demonstrate the feasibility and performance of vSFC, we implement a vSFC prototype on top of Linux kernel-based virtual machines (KVM) and conduct extensive experiments with real traffic. The experimental results show that vSFC can accurately detect SFC violations with negligible overhead.
Xiaoli Zhang 0003, Qi Li 0002, Jiahai Yang 0001
IEEE/ACM Trans. Netw.1
2020 Enabling Execution Assurance of Federated Learning at Untrusted Participants
abstract
Federated learning (FL), as a privacy-preserving machine learning framework, draws growing attention in both industry and academia. It obtains a jointly accurate model by distributing training tasks into data owners and aggregating their model updates. However, FL faces new security problems, as it losses direct control to training processes. One fundamental demand is to ensure whether participants execute training tasks as intended.In this paper, we propose TrustFL, a practical scheme that leverages Trusted Execution Environments (TEEs) to build assurance of participants' training executions with high confidence. Specifically, we use TEE to randomly check a small fraction of all training processes for tunable levels of assurance, while all computations are executed on the co-located faster yet insecure processor (e.g., GPU) for efficiency. To prevent various cheating behaviors like only processing TEE-requested computations or uploading old results, we devise a commitment-based method with specific data selection. We prototype TrustFL using GPU and SGX and evaluate its performance. The results show that TrustFL achieves one/two orders of magnitude speedups compared with naive training with SGX, when assuring correct training with a confidence level of 99%.
Xiaoli Zhang 0003, Fengting Li, Qi Li 0002, Cong Wang 0001
INFOCOM1
2019 Towards Verifiable Performance Measurement over In-the-Cloud Middleboxes
abstract
In-the-cloud middleboxes have drawn widespread attentions recently, along with the rapid advancement of network function virtualization (NFV). Despite the well known benefits like reduced hardware and maintenance cost, deploying middleboxes in the remote environment poses new performance and security concerns, due to invisibility of the untrusted cloud and susceptible software implementations. One essential requirement for enterprise customers is to monitor performance compliance, while ensuring that packets are faithfully processed by remote middleboxes. In this paper, we propose a practical scheme towards verifiable performance measurement over in-the-cloud middleboxes. It employs “sample and replay” to achieve performance measurement and packet processing attestation. It estimates performance by collecting receipts in a tunable way, while coping with dynamic traffic changes made by middleboxes. In particular, our sampling is stateful which can capture a sequence of packets sharing same states of middleboxes for correct local replay. More importantly, it ensures high-confidence packet processing attestation by enforcing middleboxes to bind execution assurances with packets using commitment messages, and by using delayed verification procedure to defeat any potential biased results against selected sampling. To demonstrate the feasibility and efficiency of our scheme, we implement a prototype consisting of various types of middleboxes on Click, and conduct extensive experiments on Amazon EC2 with real traces. The experimental results show that our scheme imposes marginal processing delay for packets with various middleboxes and presents negligible throughput degradation.
Xiaoli Zhang 0003, Huayi Duan, Cong Wang 0001, Qi Li 0002
INFOCOM1
2017 Generic and agile service function chain verification on cloud
abstract
Network Function Virtualization (NFV) is an emerging technology to enable network functions (NFs) outsourcing on cloud so as to reduce the costs of deploying and maintaining NFs. However, NF outsourcing poses a serious gap between the expected service function chains (SFCs) and the real enforcement because SFC deployment and management on cloud is invisible to NF customers (i.e., enterprises). In this paper, we propose verifiable SFC, i.e., vSFC, the first scheme that allows an enterprise to accurately verify the correct enforcement of SFC in realtime. In particular, different from the-state-ofthe-art network function verification schemes, vSFC is generic and agile, which can be deployed on various clouds, while not requiring modifications to any NFs on cloud. vSFC detects a wide range of SFC violations including forwarding path incompliance, flow dropping, and packet injection attacks. To demonstrate the feasibility and performance of vSFC, we implement a vSFC prototype built on top of KVM and conduct experiments with real traces. Our experiment results show that vSFC detects various SFC violations with a negligible overhead.
Xiaoli Zhang 0003, Qi Li 0002, Jiahai Yang 0001
IWQoS1