Zhiwei Zhang 0004

dblp:68/1980-4 · DBLP profile ↗
← Back
18ranked-venue papers
1as first author
15since 2021 · last 2026
0000-0001-6455-6866ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 7 · 1 first-author · 5 since 2021Computer networks · 5 · 5 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Security and privacy · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 An Integrated Framework for Cooperative Transmission and Physical Layer Authentication in Relay-Assisted Wireless Networks
abstract
Traditional physical layer authentication (PLA) schemes in wireless networks typically depend on individual nodes for feature observation, lacking cooperative gain and thus suffering from limited accuracy and robustness. This paper investigates a cooperative transmission and PLA framework for wireless networks, wherein multiple legitimate devices serve as both message relays and identity verifiers by extracting hardware fingerprints. We first establish a theoretical model for the system’s bit error rate (BER), false alarm rate (FAR), and detection probability (PD), and derive closed-form upper bounds to characterize the transmission reliability and authentication performance. Based on our theoretical model, we then define an accuracy improvement ratio (AIR) metric that quantifies FAR gain without compromising BER and PD performance, and derive channel conditions to ensure a positive AIR. To validate the proposed integrated framework, a time-division multiple access (TDMA)-based case study is conducted using carrier frequency offset as the authentication feature. Simulation results demonstrate that the proposed scheme can reduce FAR by up to 100.0% under favorable signal-to-noise ratio (SNR) conditions, while maintaining the BER and PD performance of the conventional non-cooperative scheme, thereby confirming its effectiveness for enhancing secure wireless communications.
Shuangrui Zhao, Huifang Zhang, Yuanyu Zhang 0001, Zhiwei Zhang 0004, Yulong Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2026 Opportunistic Gossip Learning-Aided Collaborative Physical Layer Authentication for Internet of Vehicles
abstract
Traditional device authentication techniques relying only on a single device for authentication are susceptible to poor performance due to insufficient channel observations. Although these challenges are mitigated by centralized collaborative authentication schemes, such schemes assume that all users desire to learn the same model. They further assume constant collaborator presence, leading to poorly trained models in Internet of Vehicles (IoV) environments with fleeting encounters. Moreover, they are vulnerable to GPS spoofing attack. To overcome these limitations, we propose a Gossip Learning (GL)-based collaborative Physical Layer Authentication (PLA) scheme, where collaborators assist vehicles in authenticating transmitters by distributively training their Long Short-term Memory (LSTM) models using the location and Channel State Information (CSI) of the transmitters. The collaborators also improve their model instances by incorporating the learned experiences of other vehicles they meet opportunistically. Instead of using the claimed location of transmitters during authentication, which may be affected by the GPS spoofing attack, their Received Signal Strength (RSS) and Angle of Arrival (AoA) features are used to estimate their current location. The estimated location is then used to predict their current CSI for authentication. Moreover, we propose a distance-based GPS signal spoofing detection algorithm, which ensures that only collaborators not under GPS spoofing attack are selected for collaborative training. The simulation results from experiments conducted using realistic channel attributes obtained from the Quasi-Deterministic Radio channel Generator (QuaDRiGa) platform demonstrate the effectiveness of our system in IoV scenarios, underscoring its relevance to Intelligent Transportation Systems and its superiority over existing techniques.
Mubarak Umar, Shuangrui Zhao, Shuguang Wang, Ming-Gang Zheng, Yulong Shen 0001, Zhiwei Zhang 0004, Yufeng Kang, Hafsa Kabir Ahmad
IEEE Trans. Intell. Transp. Syst.7
2026 MHCertChain: A Multi-CA Hierarchical Certificate Blockchain With Low Overhead
abstract
Blockchain-based certificate management schemes provide a distributed approach for Public Key Infrastructure through the integration of blockchain services, thereby enhancing transparency and security in identity authentication. However, existing schemes often suffer from limited scalability when accommodating new CAs, high overhead of blockchain systems, and a high false-positive rate in revocation status checks. To address above issues, we propose MHCertChain, a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure including the main chain and sub-chains is designed to enhance scalability, while the main chain stores trust paths between CAs and each automatically deployed sub-chain records user certificates issued by an end-entity CA. Then, we propose a lightweight dual-signature certificate format that contains certificate location information without requiring any external certificate location method outside the blockchain. Considering time characteristics of certificates, a time-partitioned cuckoo filter is proposed with a low false positive rate and accelerates revocation status query. Moreover, we deduce an optimal global performance parameter of such filter through mathematical modeling. We present a thorough security analysis of our MHCertChain utilizing the universally composable framework, and extensive experiments demonstrate that the CPU overhead and false positive rate are reduced by 70% and 95%, respectively, compared to state-of-the-art schemes. Blockchain-based certificate management schemes provide a distributed approach for Public Key Infrastructure through the integration of blockchain services, thereby enhancing transparency and security in identity authentication. However, existing schemes seldom discuss hierarchical CA architecture, and often suffer from limited scalability and high overhead when considering new CAs, frequent certificate authentication and revocation status verification. To address above issues, we propose MHCertChain, a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure including the main chain and sub-chains is designed, while the main chain stores trust paths between CAs and each automatically deployed sub-chain records user certificates issued by an end-entity CA. Then, we propose a lightweight dual-signature certificate format that contains certificate location information without requiring any external certificate location method outside the blockchain. Considering time characteristics of certificates, a time-partitioned cuckoo filter is proposed with a low false positive rate and accelerates revocation status query. Moreover, we deduce an optimal global performance parameter of such filter through mathematical modeling. We present a thorough security analysis of our MHCertChain utilizing the universally composable framework, and extensive experiments demonstrate that the CPU overhead and false positive rate are reduced by 70% and 95%, respectively, compared to state-of-the-art schemes. Blockchain-based certificate management schemes provide a distributed means to increase the transparency of PKI (Public Key Infrastructure) and prevent single point attacks in web communications. However, certificate management based on hierarchical multi-CA architecture often faces the problems of poor scalability and high CPU overhead in blockchain. In this article, we are the first to propose a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure of the main chain and sub-chain is adopted, with the main chain storing the trust paths and the sub-chain storing the user certificates. By monitoring to the CA transactions of the main chain, the sub-chain is automatically deployed. Then, in the certificate operation, we consider the high CPU overhead of traditional certificate query in blockchain and propose a dual-signature certificate format. combined with the time characteristics of the certificate, a time-partitioned cuckoo filter is proposed with a low false positive rate for the revocation status query speeding, and we find a global performance optimal parameter through mathematical modeling. Finally, we use a general composable framework to prove the security of HiCertChain, and the experiments show that the CPU overhead and false positive rate are reduced by 90% and 95%, respectively, compared with those of state-of-the-arts.
Xuewen Dong, Qingsong Yao, Lingxiao Yang, Zhiwei Zhang 0004, Ning Xi 0002, Yulong Shen 0001
IEEE Trans. Serv. Comput.5
2025 RSFuzz: A Robustness-Guided Swarm Fuzzing Framework Based on Behavioral Constraints
abstract
Multi-robot swarms play an essential role in complex missions including battlefield reconnaissance, agricultural pest monitoring, as well as disaster search and rescue. Unfortunately, given the complexity of swarm algorithms, logical vulnerabilities are inevitable and often lead to severe safety and security consequences. Although various methods have been presented for detecting logical vulnerabilities through software testing, when they are used in swarm environments, these techniques face significant challenges: 1) Due to the swarm’s vast composable parameter space, it is extremely difficult to generate failure-triggering scenarios, which is crucial to effectively expose logical vulnerabilities; 2) Because of the swarm’s high flexibility and dynamism, it is challenging to model and evaluate the global swarm state, particularly in terms of cooperative behaviors, which makes it difficult to detect logical vulnerabilities.In this work, we propose RSFuzz, a robustness-guided swarm fuzzing framework designed to detect logical vulnerabilities in multi-robot systems. It leverages the robustness of behavioral constraints to quantitatively evaluate the swarm state and guide the generation of failure-triggering scenarios. In addition, RSFuzz identifies and targets key swarm nodes for perturbations, effectively reducing the input space. Upon the RSFuzz framework, we construct two swarm fuzzing schemes, Single Attacker Fuzzing (SA-Fuzzing) and Multiple Attacker Fuzzing (MA-Fuzzing), which employ single and multiple attackers, respectively, during fuzzing to disturb swarm mission execution. We evaluated RSFuzz’s performance with three popular swarm algorithms in simulated environments. The results show that RSFuzz outperforms the state-of-the-art with an average improvement of 17.75% in effectiveness and a 38.4% increase in efficiency. We also validated some detected vulnerabilities in real-world environments. Our code and data are publicly available.
Ruoyu Zhou, Zhiwei Zhang 0004, Haocheng Han, Xiaodong Zhang 0014, Zehan Chen, Jun Sun 0001, Yulong Shen 0001, Dehai Xu
ASE2
2025 Effectively Detecting Software Vulnerabilities via Leveraging Features on Program Slices
abstract
Detecting software vulnerabilities has become increasingly challenging with the growing size and complexity of modern software. Traditional static and dynamic analysis methods often suffer from poor accuracy and reliance on expert knowledge. In recent years, deep learning has shown great promise in this domain due to its ability to automatically learn subtle features from software data. However, existing deep-learning-based methods face two main limitations: 1) difficulty in effectively processing long source code sequences, leading to suboptimal feature representation and 2) insufficient exploration and utilization of common vulnerability features, which hampers further performance improvements. To address these challenges, we propose DV-LVF, a novel deep-learning-based vulnerability detection method that combines program slicing with gated recurrent unit (GRU) embedding techniques to enhance feature representation. Additionally, we introduce a vulnerability dictionary (vulDict) that explicitly captures and leverages common vulnerability patterns to improve detection accuracy. Our evaluation demonstrates that DV-LVF outperforms state-of-the-art methods, achieving accuracies of 98.59% at the function level and 99.27% at the statement level. Notably, DV-LVF successfully identifies 11 previously unknown vulnerabilities across six open-source software projects, including GPAC, Vim, NanoMQ, PJSIP, Libmobi, and Radare2.
Xiaodong Zhang 0014, Zhiwei Zhang 0004, Guiyuan Tang, Jun Sun 0001, Yulong Shen 0001, Jianfeng Ma 0001
IEEE Internet Things J.3
2025 Joint RIS and Beamforming Design for Secure and Energy-Efficient Two-Way Relay Communications
abstract
This paper examines the enhancement of secrecy energy efficiency (SEE) in a reconfigurable intelligent surface (RIS)-assisted two-way relay (TWR) system. We first establish a theoretical model for the system's secrecy rate, energy consumption, and SEE, and formulate the SEE maximization problem through the joint design of the RIS phase shifts and beamforming matrix. Using techniques such as weighted minimum mean square error (WMMSE), alternating optimization, and the augmented Lagrange method, we then develop a theoretical framework that identifies locally optimal solutions for the RIS and beamforming settings under unit-modulus and power constraints. The proposed framework is also shown to be applicable to solving the system's secrecy rate maximization problem. To address the computational complexity involved in optimizing the RIS phase shifts, we further propose a suboptimal scheme leveraging the Newton's method, which significantly reduces the computational burden while achieving performance close to the optimal SEE. Extensive numerical results validate the effectiveness of the proposed schemes, showing significant SEE improvements compared to traditional channel-capacity-based secure transmission scheme.
Shuangrui Zhao, Yuanyu Zhang 0001, Zhiwei Zhang 0004, Yulong Shen 0001
IEEE Trans. Mob. Comput.4
2025 Enhancing Secrecy Energy Efficiency in THz MIMO Two-Way Relay Systems With SWIPT and Precoding
abstract
This paper investigates the enhancement of secrecy energy efficiency (SEE) in a THz MIMO two-way relay system utilizing simultaneous wireless information and power transfer (SWIPT) and precoding techniques. We first model the SEE metric of the system under random SWIPT and precoding settings, and subsequently formulate the SEE maximization problem as a non-convex programming problem. By employing techniques such as Dinkelbach transformation, alternating optimization, and difference of convex programming, we then develop a multi-level theoretical framework to jointly optimize the energy splitting factor and precoding matrices. As a special case, we further demonstrate that the proposed theoretical framework can also be applied to solving the secrecy rate maximization problem. Finally, with the help of orthogonal-triangular decomposition and the Newton-Raphson method, we provide the optimal structure of the relay precoding matrix and a low-complexity suboptimal solution scheme for SEE maximization. Extensive numerical results validate our theoretical findings and demonstrate that the proposed schemes can significantly improve the system’s SEE compared to the conventional microwave-based schemes and the random baseline.
Shuangrui Zhao, Zhiwei Zhang 0004, Ning Xi 0002, Yulong Shen 0001
IEEE Trans. Wirel. Commun.2
2024 Multidimensional Intrinsic Identity Construction and Dynamic Seamless Authentication Schemes in IoT Environments
Zhiwei Zhang 0004, Guiyuan Tang, Ziwei Shi, Yulong Shen 0001, Ning Xi 0002
ICA3PP (4)2
2024 Detecting Vulnerabilities via Explicitly Leveraging Vulnerability Features on Program Slices
Xiaodong Zhang 0014, Zhiwei Zhang 0004, Yulong Shen 0001
TASE3
2024 Physical layer authentication in the internet of vehicles through multiple vehicle-based physical attributes prediction
Mubarak Umar, Shuguang Wang, Minggang Zheng, Zhiwei Zhang 0004, Yulong Shen 0001
Ad Hoc Networks6
2023 FedProc: Prototypical contrastive federated learning on non-IID data
Xutong Mu, Yulong Shen 0001, Ke Cheng 0001, Xueli Geng, Jiaxuan Fu, Tao Zhang 0029, Zhiwei Zhang 0004
Future Gener. Comput. Syst.7
2023 Manto: A Practical and Secure Inference Service of Convolutional Neural Networks for IoT
abstract
As convolutional neural networks (CNNs) exhibit remarkable performance in various inference tasks, it is increasingly important to enable Internet of Things (IoT) devices to perform CNN-based applications. Many companies provide their carefully trained neural networks as inference services for resource-constrained clients (e.g., IoT devices). However, the use of CNN inference in many IoT applications raises privacy concerns. Cryptographic inference services provide a way to perform neural inference efficiently and, at the same time, preserve both the privacy of the client’s input data and the server’s proprietary model. Unfortunately, the existing solutions incur severe latency costs, stemming mostly from nonlinear activations such as ReLUs, which make them still unsuitable for deployment in real IoT devices. In this article, we propose Manto, a secure inference system of CNNs for IoT. Manto makes the following two specific efforts by combining the insights of machine learning and cryptography. First, we customize different quadratic activation functions to replace specific ReLU layers and further propose a sliding-window-based fine-tuning method to produce CNN models involving no or few ReLUs. These techniques allow us to speedup cryptographic inference and guarantee inference accuracy. Second, we develop a series of cryptographic protocols that support ReLU activations and its approximation variants (i.e., polynomial activations), which purely rely on the lightweight secret sharing techniques in the online execution and can well cope with the above-mentioned optimized CNN models in the ciphertext domain. Our experimental results show Manto obtains state-of-the-art performance, reducing online inference latency by$66.2\%\sim 87.7\%$over prior works on CIFAR-100 and TinyImageNet data sets.
Ke Cheng 0001, Jiaxuan Fu, Yulong Shen 0001, Haichang Gao, Ning Xi 0002, Zhiwei Zhang 0004
IEEE Internet Things J.6
2023 Private Inference for Deep Neural Networks: A Secure, Adaptive, and Efficient Realization
abstract
The advances in deep neural networks (DNNs) have driven many companies to offer their carefully-trained DNNs as inference services for clients’ private data. The privacy concerns have increasingly motivated the need for private inference (PI), where DNN inferences are performed directly on encrypted data without revealing the client's private inputs to the server or revealing the server's proprietary DNN weights to the client. However, existing cryptographic protocols for PI suffer from impractically high latency, stemming mostly from non-linear operators like ReLU activations. In this paper, we propose PAPI, a Practical and Adaptive Private Inference framework. First, we develop an accuracy-adaptive neural architecture search (NAS) approach to generate DNN models tailored for high-efficiency ciphertext computation. Specifically, our NAS automatically generates the DNNs with fewer ReLUs while keeping the accuracy above a user-defined target. Second, we propose secure online/offline protocols for ReLU activation and its approximation variants (i.e., polynomial activations), which purely rely on the lightweight secret sharing techniques in the online execution and can well cope with our optimized DNNs in the ciphertext domain. Experimental results show that PAPI reduces online inference latency on the CIFAR-10/100 and ImageNet datasets by 2.7${\times}$$\sim$7.8${\times}$over the state-of-the-art.
Ke Cheng 0001, Ning Xi 0002, Ximeng Liu, Haichang Gao, Zhiwei Zhang 0004, Yulong Shen 0001
IEEE Trans. Computers6
2023 Joint Controller Placement and Control-Service Connection in Hybrid-Band Control
abstract
By separating the forwarding and control planes, Software-Defined Networking (SDN) facilitates flexible traffic routing and network management for a service network. Because of the impact of controller deployment on message transmission distances and network latency, controller placement problems have drawn many researchers’ attention. However, assumptions in most existing research that all control packets are either transmitted in the service network (i.e., in-band control) or through predetermined control-service connection (i.e., out-of-band control) are not reasonable due to bandwidth resources occupation on the service network or high construction costs. In this paper, we are the first to jointly discuss the controller placement and control-service connection problem for latency minimization in the hybrid-band control mode, which is essentially a bi-level programming optimization problem. Specifically, we introduce auxiliary variables to simplify the above NP-hard problem. Next, Generalized Benders decomposition is used to obtain an optimal solution in theory. In addition, we propose a time-efficient fireworks algorithm with a little latency increment for large-scale networks. Extensive evaluations show that the two proposed algorithms accomplish the desired objectives and respectively achieve up to 35% and 25% latency decrement than greedy algorithms.
Xuewen Dong, Lingtao Xue, Zhiwei Zhang 0004, Yushu Zhang 0001, Teng Li 0003, Zhichao You, Yulong Shen 0001
IEEE Trans. Cloud Comput.3
2022 A blockchain-driven data exchange model in multi-domain IoT with controllability and parallelity
Wei Tong 0003, Xuewen Dong, Yulong Shen 0001, Xiaohong Jiang 0001, Zhiwei Zhang 0004
Future Gener. Comput. Syst.5
2020 SLDS: Secure and location-sensitive data sharing scheme for cloud-assisted Cyber-Physical Systems
Zhiwei Zhang 0004, Xiaofeng Chen 0001, Jianfeng Ma 0001, Jian Shen 0001
Future Gener. Comput. Syst.1
2018 An Associated Deletion Scheme for Multi-copy in Cloud Storage
Dulin, Zhiwei Zhang 0004, Shichong Tan, Jianfeng Wang 0001, Xiaoling Tao
ICA3PP (4)2
2018 An Almost Non-interactive Order Preserving Encryption Scheme
Jianfeng Wang 0001, Zhiwei Zhang 0004, Xiaofeng Chen 0001
ISPEC3