Hua Zhang 0001

dblp:69/2745-1 · DBLP profile ↗
← Back
51ranked-venue papers
6as first author
29since 2021 · last 2026
0000-0002-0532-9783ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 8 · 7 since 2021Software engineering, systems software and programming languages · 7 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 3 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2
YearPublicationVenuePosition
2026 GIANT: Structure-Agnostic Practical Adversarial Attacks for Graph-based Network Intrusion Detection Systems
Jianjin Zhao, Qi Li 0057, Hua Zhang 0001, Mingshu He, Jiong Dong, Yuyin Ma, Meng Shen 0001
WWW7
2026 A fast gray-box adversarial example generation algorithm based on FakeBob
abstract
There are the excessive queries to the targeted model during the generates of gray-box adversarial examples for speaker recognition systems, which result in high costs of attacks. In this paper, a fast generates algorithm of gray-box adversarial example is proposed based on FakeBob, named F-FakeBob. This algorithm introduces a threshold mechanism for optimization to the optimization strategy of gradient. Only when the increasing of the confidence scores of the adversarial example before and after optimizing is less than the threshold, the gradient is recalculated for the next iteration. By reducing the frequency of gradient calculations, the number of queries to the targeted system is decreased. Experiments on three public datasets of speech, TIMIT, Common Voice, and Voxceleb2, are conducted to generate adversarial examples. The targeted speaker recognition models are based on ECAPA-TDNN and TitaNet architectures. The experimental results show that F-FakeBob can achieve a targeted attack success rate of 99.2% and the numbers of queries are effectively reduced in the adversarial example generates, with an average query reduction of 25.71% compared to FakeBob.
Wanjin Hou, Hua Zhang 0001, Ming Lv, Huiyu Zhou 0001
High Confid. Comput.3
2026 A publishing scheme for high-dimensional graph data under personalized local differential privacy
Kaixuan Li 0007, Hua Zhang 0001, Xiangliang Ma, Qi Li 0057, Yanxin Xu
Neurocomputing2
2026 FBFL: Flexible Byzantine-Robust Federated Learning With Privacy-Preserving
abstract
Privacy-preserving federated learning allows many clients to collaboratively train a machine learning model by sharing encrypted models. Among them, mask-based schemes have been widely applied due to their efficiency advantages. Unfortunately, as the invisibility of an individual local model, such schemes are vulnerable to poisoning attacks by Byzantine clients. Current work lacks a practical method to detect Byzantine clients within the mask-based scheme. We propose FBFL, a flexible Byzantine-robust federated learning scheme with privacy-preserving. While protecting the privacy of the client, we implement a defense against Byzantine clients without relying on an individual masked local model. Specifically, we design a secure distance computation method based on the Pedersen commitment. The exponential Manhattan distance we design is utilized to compute the malicious score of the client in order to distinguish the benign model from the abnormal model. Since the malicious score is obtained utilizing only the commitment value and not the masked local model, our Byzantine-robust method can be flexibly combined with other mask-based privacy-preserving methods. Security analysis shows that FBFL is Byzantine-robust and can ensure the data security of clients. Experimental evaluation shows that the robustness and efficiency of FBFL are great.
Yanxin Xu, Hua Zhang 0001, Jianjin Zhao, Keke Gai, Zian Tian, Jianxin Yang
IEEE Trans. Cloud Comput.2
2025 VeriTrac: Verifiable and traceable cross-silo federated learning
Yanxin Xu, Hua Zhang 0001, Zhenyan Liu, Fei Gao 0001
Future Gener. Comput. Syst.2
2025 F2Attack: Two-Factors Scoring Method for Query-Efficient Hard-Label Black-Box Textual Adversarial Attacks
Hua Zhang 0001, Qi Li 0057, Huiyu Zhou 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Comments on "VERSA: Verifiable Secure Aggregation for Cross-Device Federated Learning"
abstract
Recently, in IEEE Transactions on Dependable and Secure Computing (TDSC), the VERSA scheme proposed by Hahnet al. uses a double aggregation method for verifying the correctness of results returned from the server. The authors proposed that the correctness of the model aggregation can be verified with lower verification overhead by utilizing only a lightweight pseudorandom generator. To support verifiability of results returned from the server, a method of sharing a pair of vectors$(a,b)$by all clients is proposed, which is one of the most important work in VERSA. Unfortunately, in this paper, we show that the method is incorrect, which leads clients to consistently conclude that the aggregated results are incorrect. Furthermore, the model training process in federated learning is forced to abort. Finally, we demonstrate our view through theory analysis and instantiation verification.
Yanxin Xu, Hua Zhang 0001, Shaohua Zhao, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001, Kaixuan Li 0007
IEEE Trans. Dependable Secur. Comput.2
2024 NUAT-GAN: Generating Black-Box Natural Universal Adversarial Triggers for Text Classifiers Using Generative Adversarial Networks
abstract
Recent works have demonstrated that text classifiers are vulnerable to universal adversarial triggers (UATs), which are concatenated to any original text from the dataset to mislead text classifiers. Existing methods for generating UATs are limited to a white-box setting, where the adversary needs access to the gradient information about the target model. In the more practical black-box setting, the adversary can only access the logit output of the target model, which increases the difficulty of crafting UATs. In this paper, we propose a framework for generating natural UATs using generative adversarial networks (NUAT-GAN) in the black-box setting. To update parameters of the generator in the black-box setting, we design a training generator algorithm with policy gradient (TGPG), in which the gradient of the target model is replaced with the policy gradient of reinforcement learning. On three text classification datasets, we evaluate the attack and the natural performance of UATs generated on LSTM, CNN and BERT models. Results show that UATs generated by NUAT-GAN can mislead the above models. The average values of the Attack Success Rate (ASR) and GPT-2 Loss of UATs are 0.81 and 9.10, respectively. The UATs can effectively attack online models, such as AllenNLP and ChatGPT. Moreover, we replace the reward given by the discriminator with GPT-2 Loss, the attack and the natural performance of UATs are close to those of NUAT-GAN. This shows that NUAT-GAN is extensible and can combined with the language model.
Hua Zhang 0001, Xin Zhang 0120, Huawei Wang 0001, Wenmin Li 0001, Tengfei Tu
IEEE Trans. Inf. Forensics Secur.2
2024 Understanding and Detecting Real-World Safety Issues in Rust
abstract
Rust is a relatively new programming language designed for systems software development. Its objective is to combine the safety guarantees typically associated with high-level languages with the performance efficiency often found in executable programs implemented in low-level languages. The core design of Rust is a set of strict safety rules enforced through compile-time checks. However, to support more low-level controls, Rust also allows programmers to bypass its compiler checks by writingunsafecode. As the adoption of Rust grows in the development of safety-critical software, it becomes increasingly important to understand what safety issues may elude Rust’s compiler checks and manifest in real Rust programs.In this paper, we conduct a comprehensive, empirical study of Rust safety issues by close, manual inspection of 70 memory bugs, 100 concurrency bugs, and 110 programming errors leading to unexpected execution panics from five open-source Rust projects, five widely-used Rust libraries, and two online security databases. Our study answers three important questions: what memory-safety issues real Rust programs have, what concurrency bugs Rust programmers make, and how unexpected panics in Rust programs are caused. Our study reveals interesting real-world Rust program behaviors and highlights new issues made by Rust programmers. Building upon the findings of our study, we design and implement five static detectors. After being applied to the studied Rust programs and another 12 selected Rust projects, our checkers pinpoint 96 previously unknown bugs and report a negligible number of false positives, confirming their effectiveness and the value of our empirical study.
Boqin Qin, Hua Zhang 0001, Qiaoyan Wen, Linhai Song, Yiying Zhang 0005
IEEE Trans. Software Eng.4
2023 Privacy Protection Data Retrieval Scheme With Inverted Index for IoT Based on Blockchain
abstract
In the 6G era, Internet of Things (IoT) devices can form a blockchain network, which also faces the problems of data sharing. The data transmitted and stored through the network have the risk of privacy leaking. Encrypting the shared data can satisfy the need of the privacy, and retrieving the encrypted data can make the data used efficiently. However, to enable users to retrieve encrypted data and perform fine-grained authorization on their encrypted files is still a great challenge. Although attribute-based keyword search (ABKS) is a well-received solution to the challenge, there are still privacy and efficiency issues if the traditional ABKS schemes are directly used in blockchain data sharing. In order to solve the problems, this article proposes privacy protection data retrieval scheme with an inverted index, which is an application of attribute-based encryption. First, our scheme is proved secure against the outside keyword guessing attack (KGA) and chosen keyword attack (CKA) under the semitrusted model. Second, the scheme returns a multikeywords ranked result. Third, we analyze the efficiency of our scheme and verify it by simulation. The results show that our scheme has improvement in efficiency and can meet the data sharing needs of the blockchain network composed of IoT devices.
Wenmin Li 0001, Yang Chen 0042, Fei Gao 0001, Shuo Zhang 0008, Hua Zhang 0001, Qiaoyan Wen
IEEE Internet Things J.5
2023 Secure and Efficiently Searchable IoT Communication Data Management Model: Using Blockchain as a New Tool
abstract
With the rapid development of the Internet of Things (IoT), more IoT devices are connected in the same network and communicate frequently for sharing data and switching instructions. So that the traditional centralized security architecture of IoT will be limited in terms of data storage space, data reliability, scalability, and operating costs. In this article, we propose a novel communication data management model based on blockchain technology. Specifically, all encrypted IoT communication data files are uploaded to the public cloud server for obtaining enough storage space, but the key information extracted from these data files (called “communication logs”) will be recorded in an “IoT ledger” maintained by all IoT devices. In fact, the IoT ledger is a kind of blockchain structured distributed database, which can solve the problem of data reliability, scalability and would not involve high operating costs. Besides, in order to efficiently search communication logs and not reveal any sensitive information of communication data, we design a secure search scheme over such blockchain database, the asymmetric scalar-product-preserving encryption (ASPE) approach is exploited to guarantee the data security, and the two layers index improves the search efficiency. Security analysis and experiments on synthetic data set show that our scheme is secure and efficient.
Hua Zhang 0001, Xin Zhang 0120, Ziqing Guo, Huawei Wang 0001, Qiaoyan Wen
IEEE Internet Things J.1
2023 Publishing locally private high-dimensional synthetic data efficiently
Hua Zhang 0001, Kaixuan Li 0007, Xin Zhang 0120, Wenmin Li 0001, Zhengping Jin, Fei Gao 0001, Minghui Gao
Inf. Sci.1
2023 A detector for Android repackaged applications with layout-fingerprint
Tengfei Tu, Hua Zhang 0001, Yangye Hu, Xilin Zhai
J. Inf. Secur. Appl.2
2023 Enhanced covertness class discriminative universal adversarial perturbations
Hua Zhang 0001, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001
Neural Networks2
2023 Scalable Fuzzy Keyword Ranked Search Over Encrypted Data on Hybrid Clouds
abstract
Searchable encryption (SE) is a powerful technology that enables keyword-based search over encrypted data becomes possible. However, most SE schemes focus on exact keyword search which can not tolerate misspellings and typos. Existing fuzzy keyword search schemes only support fuzzy search within a limited similarity threshold$d$, the storage cost will grow exponentially or the precision of search results will greatly decrease as$d$increases. Moreover, the current fuzzy keyword ranked search schemes consider only the keyword weight, and disregard the influence of keyword morphology similarity on the ranking. In this article, we propose a scalable fuzzy keyword ranked search scheme over encrypted data under hybrid clouds architecture. We use the edit distance to measure the similarity of keywords and design an edit distance algorithm over encrypted data, in which our scheme achieves fuzzy keyword search for any similarity threshold$d$with a constant storage size and accurate search results. Furthermore, we design a two-factor ranking function combining keyword weight with keyword morphology similarity, which is utilized to rank the search results and enhance system usability. Extensive experiments are performed to demonstrate the trade-off of efficiency and security of the proposed scheme.
Hua Zhang 0001, Shaohua Zhao, Ziqing Guo, Qiaoyan Wen, Wenmin Li 0001, Fei Gao 0001
IEEE Trans. Cloud Comput.1
2022 Jasmine: A Static Analysis Framework for Spring Core Technologies
abstract
The Spring framework is widely used in developing enterprise web applications. Spring core technologies, such as Dependency Injection and Aspect-Oriented Programming, make development faster and easier. However, the implementation of Spring core technologies uses a lot of dynamic features. Those features impose significant challenges when using static analysis to reason about the behavior of Spring-based applications. In this paper, we propose Jasmine, a static analysis framework for Spring core technologies extends from Soot to enhance the call graph’s completeness while not greatly affecting its performance. We evaluate Jasmine’s completeness, precision, and performance using Spring micro-benchmarks and a suite of 18 real-world Spring programs. Our experiments show that Jasmine effectively enhances the state-of-the-art tools based on Soot and Doop to better support Spring core technologies. We also add Jasmine support to FlowDroid and discovered twelve sensitive information leakage paths in our benchmarks. Jasmine is expected to provide significant benefits for many program analyses scenes of Spring applications where more complete call graphs are required.
Tengfei Tu, Hua Zhang 0001, Qiaoyan Wen, Weihang Wang 0001
ASE3
2022 Secure and Differentiated Fog-Assisted Data Access for Internet of Things
abstract
Abstract The ability of Fog computing to admit and process huge volumes of heterogeneous data is the catalyst for the fast expansion of Internet of things (IoT). The critical challenge is secure and differentiated access to the data, given limited computation capability and trustworthiness in typical IoT devices and Fog servers, respectively. This paper designs and develops a new approach for secure, efficient and differentiated data access. Secret sharing is decoupled to allow the Fog servers to assist the IoT devices with attribute-based encryption of data while preventing the Fog servers from tampering with the data and the access structure. The proposed encryption supports direct revocation and can be decoupled among multiple Fog servers for acceleration. Based on the decisional $q$-parallel bilinear Diffie–Hellman exponent assumption, we propose a new extended $q$-parallel bilinear Diffie–Hellman exponent (E$q$-PBDHE) assumption and prove that the proposed approach provides ‘indistinguishably chosen-plaintext attacks secure’ data access for legitimate data subscribers. As numerically and experimentally verified, the proposed approach is able to reduce the encryption time by 20% at the IoT devices and by 50% at the Fog network using parallel computing as compared to the state of the art .
Wei Ni 0001, Hua Zhang 0001, Ren Ping Liu 0001, Qiaoyan Wen, Wenmin Li 0001, Fei Gao 0001
Comput. J.3
2022 A rORAM scheme with logarithmic bandwidth and logarithmic locality
abstract
Oblivious Random Access Machine (ORAM) is a kind of cryptographic primitive that allows a client to access its private data from the server without disclosing the access pattern. To deal with consecutive requested blocks at a time efficiently, range ORAM (rORAM) is presented. In the previous rORAM scheme, the locality, namely, the number of discontinuous seeks to complete a request, is reduced to O(log2 N), nevertheless, the bandwidth cost is increased to the poly-logarithmic level. Hence, there exists an open question, that is, whether rORAM can be constructed with the same bandwidth efficiency as a regular ORAM, that is, O(log N)-block? In this paper, we propose a new rORAM scheme, called L2-rORAM. In our scheme, a compatible superblock technique is proposed, and it is combined together with an eviction technique for range blocks, so that it avoids duplication of multiple copies and extra dummy access. As a result, it obtains O(log N)-block bandwidth cost, which affirmatively answers the above open question. Meanwhile, the data locality is reduced to O(log N). In addition, the client storage is maintained at the small level of O(log N)-block, and the server storage is maintained at the unexpanded level of O(N)-block. Finally, experimental results show that the average response time of our L2-rORAM is reduced by one order of magnitude over the state-of-the-art rORAM scheme.
Yunping Gong, Fei Gao 0001, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin, Qiaoyan Wen
Int. J. Intell. Syst.4
2022 A comprehensive study of Mozi botnet
abstract
With the trend of digital transformation of enterprises, the use of Internet of Things (IoT) devices is increasing. IoT devices that are not protected by security measures have gradually become targets of attackers. Attackers use weak passwords and software vulnerabilities in the device to invade the device and control it to become a node of the botnet. The Mozi botnet was discovered in December 2019, and its attention has increased day by day, and its influence once exceeded Mirai. After a preliminary reverse analysis of the Mozi samples, we have continued to track the development and changes of the Mozi botnet since February 2021. First, through the in-depth analysis of the communication principles of the Mozi botnet and the distributed sloppy hash table protocol, we have proposed an in-depth analysis of the Mozi botnet. The active detection method of Mozi, through daily and continuous tracking of the number of Mozi nodes, is infinitely close to the boundary of the Mozi network. On the basis of the collected detection data, we give our conclusions on Mozi's node size, global geographic distribution, 24-hour global activity, equipment composition, and Mozi botnet countermeasures. Through this study, we found that the security of IoT devices around the world is not optimistic, and there is an urgent need to increase the security protection of IoT devices. At the same time, we also hope that this study can further promote more research on future botnets.
Tengfei Tu, Jiawei Qin, Hua Zhang 0001
Int. J. Intell. Syst.3
2022 Label specificity attack: Change your label as I want
abstract
Graph neural networks (GNN) have been widely used in many machine learning tasks, such as text classification, sequence labeling, protein interface prediction, and knowledge graph. With increasing security concerns, GNN have been proved to be vulnerable and unreliable. Recent years, inspired by adversarial model in computer vision, various attacks on graph data begin to emerge. However, the exist attacks mostly focus on security violation and attack specificity, and very few attacks concern error specificity. In this paper, we focus on dealing with this kind of attack on one node of the graph by slightly manipulating the graph structure. Our goal is to change the label of the node to what we want after attack. We formulate this case as label specificity attack problem. The biggest challenge in solving this problem is the lack of theoretical guidance to perform this attack. For this, we reinterpret structural entropy and define differential structural entropy (DS-entropy) to guide the manipulation. Based on DS-entropy, we propose the target-label principle and max-degree principle to execute our attack, and then design the corresponding algorithm DSEM. We compare our algorithm DSEM with two benchmarks on three classical graph data sets. Results show that our algorithm is effective in performing label specificity attacks.
Huawei Wang 0001, Peng Yin 0005, Hua Zhang 0001, Qiaoyan Wen
Int. J. Intell. Syst.4
2022 Forward privacy multikeyword ranked search over encrypted database
abstract
Dynamic searchable encryption (SE) aims at achieving varied search function over encrypted database in dynamic setting, which is a trade-off in efficiency, security, and functionality. Recent work proposes a file-injection attack which can successfully attack by utilizing some information leaked in the update process. To mitigate this attack, some SE schemes with forward privacy are proposed. However, these schemes are designed to achieve single keyword or conjunctive keyword search, which cannot support multikeyword search. Moreover, these schemes do not consider the function of results ranking. In this paper, we propose a forward privacy multikeyword ranked search scheme over encrypted database. We design a forward privacy multikeyword search scheme based on the classic MRSE scheme. Our scheme makes the cloud cannot obtain the actual match results of the past query with the newly updated files by adding the well-chosen dummy elements to the original index and query vectors. We rank the search results based on the matched keyword number and the T F × I D F $TF\times IDF$ rule in the dynamic setting. Our scheme uses only the symmetric encryption primitive. We implement our scheme for COVID-19 data set and the experimental evaluation results show that the proposed scheme is secure and efficient.
Shaohua Zhao, Hua Zhang 0001, Xin Zhang 0120, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen
Int. J. Intell. Syst.2
2022 Generating natural adversarial examples with universal perturbations for text classification
Hua Zhang 0001, Xingguo Yang, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen
Neurocomputing2
2022 KRProtector: Detection and Files Protection for IoT Devices on Android Without ROOT Against Ransomware Based on Decoys
abstract
Nowadays, cryptographic ransomware on Android has become one of the most serious threat. They extort users by means of encrypting private data on their devices. Even worse, there exists little files protection solution on IoT devices without ROOT. In light of this, there is an urgent need for countermeasure solutions on IoT devices without ROOT. In this article, we analyze characteristics of cryptographic ransomware. We propose the strategy of files protection against ransomware based on decoys. In order to satisfy the need of files protection on devices without root, we design and implement KRProtector to detect ransomware and protect files based on decoys.
Senmiao Wang, Hua Zhang 0001, Su-Juan Qin, Wenmin Li 0001, Tengfei Tu, Ana Shen
IEEE Internet Things J.2
2022 Efficient Encrypted Range Query on Cloud Platforms
abstract
In the Internet of Things (IoT) era, various IoT devices are equipped with sensing capabilities and employed to support clinical applications. The massive electronic health records (EHRs) are expected to be stored in the cloud, where the data are usually encrypted, and the encrypted data can be used for disease diagnosis. There exist some numeric health indicators, such as blood pressure and heart rate. These numeric indicators can be classified into multiple ranges, and each range may represent an indication of normality or abnormity. Once receiving encrypted IoT data, the CS maps it to one of the ranges, achieving timely monitoring and diagnosis of health indicators. This article presents a new approach to identify the range that an encrypted numeric value corresponds to without exposing the explicit value. We establish the sufficient and necessary condition to convert a range query to matchings of encrypted binary sequences with the minimum number of matching operations. We further apply the minimization of range queries to design and implement a secure range query system, where numeric health indicators encrypted independently by multiple IoT devices can be cohesively stored and efficiently queried by using Lagrange polynomial interpolation. Comprehensive performance studies show that the proposed approach can protect both the health records and range query against untrusted cloud platforms and requires less computational and communication cost than existing techniques.
Wei Ni 0001, Ren Ping Liu 0001, Hua Zhang 0001, Qiaoyan Wen
ACM Trans. Cyber Phys. Syst.5
2022 Practical Attribute-Based Multi-Keyword Ranked Search Scheme in Cloud Computing
abstract
Attribute-based keyword search (ABKS) has a broad developing prospect in providing search service for users and realizing fine-grained access control over ciphertext in the background of cloud computing. However, two open problems prevent further development and application of ABKS. First, most of ABKS schemes suffer from inside keyword guessing attack (KGA) inherently, which is a great threat to the security of the scheme. Second, the existing ABKS schemes focus on single or conjunctive keyword search, these inflexible retrieval modes may lead to efficiency loss caused by inaccurate positioning of user’s interest and greatly reduce user search experience. In this article, we introduce a semi-trusted server and build a dual server model. Based on the dual server model and our proposed techniques, we are the first to put forward an attribute-based multi-keyword ranked search scheme against inside keyword guessing attack (ABKRS-KGA) to solve the mentioned two problems simultaneously. In our scheme, the queries of users contain weighted keywords and the returned files can be ranked according to user’s query interest. We provide strict security definitions for two types of adversaries and we are the first to prove that the construction is adaptively secure against both chosen-keyword attack (CKA) and KGA. Finally, all-side simulation with real-world data set is implemented for the proposed scheme, and the simulation results show that the efficiency of the proposed scheme is acceptable.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Qiaoyan Wen, Hua Zhang 0001, Huawei Wang 0001
IEEE Trans. Serv. Comput.5
2022 Dynamic Proof of Data Possession and Replication With Tree Sharing and Batch Verification in the Cloud
abstract
Cloud storage attracts a lot of clients to join the paradise. For a high data availability, some clients require their files to be replicated and stored on multiple servers. Because clients are generally charged based on the redundancy level required by them, it is critical for clients to obtain convincing evidence that all replicas are stored correctly and are updated to the up-to-date version. In this article, we propose a dynamic proof of data possession and replication (DPDPR) scheme, which is proved to be secure in the defined security model. Our scheme shares a single authenticated tree across multiple replicas, which reduces the tree's storage cost significantly. Our scheme allows for batch verification for multiple challenged leaves and can verify multiple replicas in a single batch way, which considerably save bandwidth and computation resources during audit process. We also evaluate the DPDPR's performance and compare it with the most related scheme. The evaluation results show that our scheme saves almost 66 percent tree's storage cost for three replicas, and obtains almost 60 and 80 percent efficiency improvements in terms of the overall bandwidth and computation costs, respectively, when three replicas are checked and each challenged with 460 blocks.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin, Qiaoyan Wen
IEEE Trans. Serv. Comput.4
2021 Cost-Sensitive Approach to Improve the HTTP Traffic Detection Performance on Imbalanced Data
abstract
Aim. The purpose of this study is how to better detect attack traffic in imbalance datasets. The deep learning technology has played an important role in detecting malicious network traffic in recent years. However, it suffers serious imbalance distribution of data if the traffic model skews towards the modeling in the benign direction, because only a small portion of traffic is malicious, while most network traffic is benign. That is the reason why the authors wrote this manuscript. Methods. We propose a cost-sensitive approach to improve the HTTP traffic detection performance with imbalanced data and also present a character-level abstract feature extraction approach that can provide features with clear decision boundaries in addition. Finally, we design a spark-based HTTP traffic detection system based on these two approaches. Results. The methods proposed in this paper work well in imbalanced datasets. Compared to other methods, the experiment results indicate that our system has F1-score in a high precision. Conclusion. For imbalanced HTTP traffic detection, we confirmed that the method of feature extraction and the cost function is very effective. In the future, we may focus on how to use the cost function to further improve detection performance.
Wenmin Li 0001, Sanqi Sun, Shuo Zhang 0008, Hua Zhang 0001, Yijie Shi
Secur. Commun. Networks4
2021 Efficient Anonymous Data Authentication for Vehicular Ad Hoc Networks
abstract
Vehicular ad hoc network (VANET) encounters a critical challenge of efficiently and securely authenticating massive on-road data while preserving the anonymity and traceability of vehicles. This paper designs a new anonymous authentication approach by using an attribute-based signature. Each vehicle is defined by using a set of attributes, and each message is signed with multiple attributes, enabling the anonymity of vehicles. First, a batch verification algorithm is developed to accelerate the verification processes of a massive volume of messages in large-scale VANETs. Second, replicate messages captured by different vehicles and signed under different sets of attributes can be dereplicated with the traceability of all the signers preserved. Third, the malicious vehicles forging data can be traced from their signatures and revoked from attribute groups. The security aspects of the proposed approach are also analyzed by proving the anonymity of vehicles and the unforgeability of signatures. The efficiency of the proposed approach is numerically verified, as compared to the state of the art.
Wei Ni 0001, Guangsheng Yu, Hua Zhang 0001, Ren Ping Liu 0001, Qiaoyan Wen
Secur. Commun. Networks4
2021 Privacy-Preserving Linear Region Search Service
abstract
Due to a variety of advantages of data outsourcing, some Location Based Services (LBS) providers are motivated to outsource the geographic data and query service to commercial cloud. However, for protecting data confidentiality, the valuable data should be encrypted before outsourcing, which obstructs the utilization like geographic information query. To address this problem, some previous works regarding to secure search on encrypted database could be applied in outsourced LBS scenario directly, but none of them is tailor-made for linear region search (LRS). The LRS is a kind of LBS that widely used in navigation system, it finds the nearby points of interest (POI) for a query segment. In this paper, for the first time, we explore and solve the challenging problem of privacy-preserving linear region search. Specifically, we choose the quadtree structure to build index for POI database, then the results of LRS can be efficiently obtained by finding out the rectangular regions that query segment passes through. In order to preserve the privacy of both LBS providers and users, according to computational geometry and Asymmetric Scalar-product Preserving Encryption (ASPE) approach, we design a novel algorithm for accurately determining whether a segment intersects with a rectangle on ciphertext. Moreover, this algorithm also provides a new idea to solve other computational problems in encrypted 2-dimensional geometry space. Based on different privacy requirements of two threat models, we propose two privacy-preserving LRS schemes and corresponding dynamic update operations. Security analysis and experiments on real-world dataset show that our schemes are secure and efficient.
Hua Zhang 0001, Ziqing Guo, Shaohua Zhao, Qiaoyan Wen
IEEE Trans. Serv. Comput.1
2020 Practical Attribute-Based Conjunctive Keyword Search Scheme
abstract
Abstract To date cloud computing may provide considerable storage and computational power for cloud-based applications to support cryptographic operations. Due to this benefit, attribute-based keyword search (ABKS) is able to be implemented in cloud context in order to protect the search privacy of data owner/user. ABKS is a cryptographic primitive that can provide secure search services for users but also realize fine-grained access control over data. However, there have been two potential problems that prevent the scalability of ABKS applications. First of all, most of the existing ABKS schemes suffer from the outside keyword guessing attack (KGA). Second, match privacy should be considered while supporting multi-keyword search. In this paper, we design an efficient method to combine the keyword search process in ABKS with inner product encryption and deploy several proposed techniques to ensure the flexibility of retrieval mode, the security and efficiency of our scheme. We later put forward an attribute-based conjunctive keyword search scheme against outside KGA to solve the aforementioned problems. We provide security notions for two types of adversaries and our construction is proved secure against chosen keyword attack and outside KGA. Finally, all-side simulation with real-world data set is implemented for the proposed scheme, and the results of the simulation show that our scheme achieves stronger security without yielding significant cost of storage and computation.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Kaitai Liang, Hua Zhang 0001, Qiaoyan Wen
Comput. J.5
2020 New Blind Filter Protocol: An Improved Privacy-Preserving Scheme for Location-Based Services
abstract
Abstract Location-based services have attracted much attention in both academia and industry. However, protecting user’s privacy while providing accurate service for users remains challenging. In most of the existing research works, a semi-trusted proxy is employed to act on behalf of a user to minimize the computation and communication costs of the user. However, user privacy, e.g. location privacy, cannot be protected against the proxy. In this paper, we design a new blind filter protocol where a user can employ a semi-trusted proxy to determine whether a point of interest is within a circular area centered at the user’s location. During the protocol, neither the proxy nor the location-based service provider can obtain the location of the user and the query results. Moreover, each type of query is controlled by an access tree and only the users whose attributes satisfy this access tree can complete the specific type of query. Security analysis and efficiency experiments validate that the proposed protocol is secure and efficient in terms of the computation and communication overhead.
Wenmin Li 0001, Fei Gao 0001, Hua Zhang 0001, Zhengping Jin, Qiaoyan Wen
Comput. J.5
2020 Adaptively secure broadcast encryption with authenticated content distributors
Dianli Guo, Qiaoyan Wen, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin
Multim. Tools Appl.4
2020 KNN search-based trajectory cloaking against the Cell-ID tracking in cellular network
Yuanbo Cui, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin
Soft Comput.3
2020 Comments on "Provable Multicopy Dynamic Data Possession in Cloud Computing Systems"
abstract
Replication is a fundamental solution for the cloud service provider (CSP) to guarantee data availability. To provide users with convincing evidence that the copies required by them are all stored correctly, a number of multi-copy integrity auditing schemes were presented. Recently, Barsoum and Hasan proposed a map-based provable multi-copy dynamic data possession scheme (IEEE Transactions on Information Forensics and Security, vol. 10, no. 3, pp. 485-497, 2015), which was claimed to be secure and can ensure that the CSP possesses all copies required by the contract. However, in this letter, we show that the scheme is easily subject to a copy-summation attack and a single-copy attack, by which a cheating CSP only needs to invest a storage cost of a single copy-while can still pass the verifier's challenge at all times. Therefore, the scheme is no longer secure in this case. Furthermore, we propose some simple but effective countermeasures and give a repaired scheme which is free from the above two attacks.
Wei Guo 0042, Su-Juan Qin, Fei Gao 0001, Hua Zhang 0001, Wenmin Li 0001, Zhengping Jin, Qiaoyan Wen
IEEE Trans. Inf. Forensics Secur.4
2020 An Adaptive Encryption-as-a-Service Architecture Based on Fog Computing for Real-Time Substation Communications
abstract
The recent outbreak of industrial cyberattacks indicates that the current industrial network security architecture is under serious challenges. As one of the critical industrial networks, the heterogeneous and real-time substation network lacks compatibility with the conventional cryptography architecture represented by secure sockets layer/transport layer security (SSL/TLS) and public key infrastructure (PKI). To enhance the security of smart substations under the premise of low latency, in this article, we present a novel encryption-as-a-service architecture based on fog computing in this article. The architecture offloads encryption to dedicated devices and makes certificate and key management available through unified web services on the fog and cloud layers. Based on this architecture, we propose MX-SORTS, maximizing security on real-time communication of different services, an algorithm for adaptive configuration of encrypting and signing substation network traffic. By the contrast experiments with the conventional cryptography architecture, we prove that the encryption-as-a-service architecture can significantly improve the real-time and security performance of substation networks.
Hua Zhang 0001, Boqin Qin, Tengfei Tu, Ziqing Guo, Fei Gao 0001, Qiaoyan Wen
IEEE Trans. Ind. Informatics1
2020 Dynamic Outsourced Auditing Services for Cloud Storage Based on Batch-Leaves-Authenticated Merkle Hash Tree
abstract
Cloud computing encourages users to outsource their data to cloud storage. Data outsourcing means that users lose physical autonomy on their own data, which makes remote data integrity verification become a critical challenge for potential cloud users. To free user from the burden incurred by frequent integrity verifications, Third Party Auditor (TPA) is introduced to perform verifications on behalf of user for data integrity assurance. However, existing public auditing schemes rely on the assumption that TPA is trusted, thus these schemes cannot be directly extended to support the outsourced auditing model, where TPA might be dishonest and any two of the three involved entities (i.e. user, TPA, and cloud service provider) might be in collusion. In this paper, we propose a dynamic outsourced auditing scheme which cannot only protect against any dishonest entity and collision, but also support verifiable dynamic updates to outsourced data. We present a new approach, based on batch-leaves-authenticated Merkle Hash Tree (MHT), to batch-verify multiple leaf nodes and their own indexes all together, which is more appropriate for the dynamic outsourced auditing system than traditional MHT-based dynamism approaches that can only verify many leaf nodes one by one. Experimental results show that our solution minimizes the costs of initialization for both user and TPA (compared to existing static outsourced auditing scheme), and incurs a lower price of dynamism at user side.
Lu Rao, Hua Zhang 0001, Tengfei Tu
IEEE Trans. Serv. Comput.2
2020 A Multiclass Detection System for Android Malicious Apps Based on Color Image Features
abstract
The visual recognition of Android malicious applications (Apps) is mainly focused on the binary classification using grayscale images, while the multiclassification of malicious App families is rarely studied. If we can visualize the Android malicious Apps as color images, we will get more features than using grayscale images. In this paper, a method of color visualization for Android Apps is proposed and implemented. Based on this, combined with deep learning models, a multiclassifier for the Android malicious App families is implemented, which can classify 10 common malicious App families. In order to better understand the behavioral characteristics of malicious Apps, we conduct a comprehensive manual analysis for a large number of malicious Apps and summarize 1695 malicious behavior characteristics as customized features. Compared with the App classifier based on the grayscale visualization method, it is verified that the classifier using the color visualization method can achieve better classification results. We use four types of Android App features: classes.dex file, sets of class names, APIs, and customized features as input for App visualization. According to the experimental results, we find out that using the customized features as the color visualization input features can achieve the highest detection accuracy rate, which is 96% in the ten malicious families.
Hua Zhang 0001, Jiawei Qin, Boan Zhang, Fei Gao 0001, Senmiao Wang, Yangye Hu
Wirel. Commun. Mob. Comput.1
2019 Efficient Attribute-Based Data Sharing Scheme with Hidden Access Structures
abstract
Abstract Online data sharing has become a research hotspot while cloud computing is getting more and more popular. As a promising encryption technique to guarantee the security shared data and to realize flexible fine-grained access control, ciphertext-policy attribute-based encryption (CP-ABE) has drawn wide attentions. However, there is a drawback preventing CP-ABE from being applied to cloud applications. In CP-ABE, the access structure is included in the ciphertext, and it may disclose user’s privacy. In this paper, we find a more efficient method to connect ABE with inner product encryption and adopt several techniques to ensure the expressiveness of access structure, the efficiency and security of our scheme. We are the first to present a secure, efficient fine-grained access control scheme with hidden access structure, the access structure can be expressed as AND-gates on multi-valued attributes with wildcard. We conceal the entire attribute instead of only its values in the access structure. Besides, our scheme has obvious advantages in efficiency compared with related schemes. Our scheme can make data sharing secure and efficient, which can be verified from the analysis of security and performance.
Yang Chen 0042, Wenmin Li 0001, Fei Gao 0001, Wei Yin 0004, Kaitai Liang, Hua Zhang 0001, Qiaoyan Wen
Comput. J.6
2019 Outsourced dynamic provable data possession with batch update for secure cloud storage
Wei Guo 0042, Hua Zhang 0001, Su-Juan Qin, Fei Gao 0001, Zhengping Jin, Wenmin Li 0001, Qiaoyan Wen
Future Gener. Comput. Syst.2
2019 Authenticated public key broadcast encryption with short ciphertexts
Dianli Guo, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001, Wenmin Li 0001
Multim. Tools Appl.4
2018 A New Insight - Proxy Re-encryption Under LWE with Strong Anti-collusion
Wei Yin 0004, Qiaoyan Wen, Wenmin Li 0001, Hua Zhang 0001, Zhengping Jin
ISPEC4
2018 Secure multi-keyword ranked search over encrypted cloud data for multiple data owners
Ziqing Guo, Hua Zhang 0001, Caijun Sun, Qiaoyan Wen, Wenmin Li 0001
J. Syst. Softw.2
2018 Dynamic Outsourced Proofs of Retrievability Enabling Auditing Migration for Remote Storage Security
abstract
Remote data auditing service is important for mobile clients to guarantee the intactness of their outsourced data stored at cloud side. To relieve mobile client from the nonnegligible burden incurred by performing the frequent data auditing, more and more literatures propose that the execution of such data auditing should be migrated from mobile client to third‐party auditor (TPA). However, existing public auditing schemes always assume that TPA is reliable, which is the potential risk for outsourced data security. Although Outsourced Proofs of Retrievability (OPOR) have been proposed to further protect against the malicious TPA and collusion among any two entities, the original OPOR scheme applies only to the static data, which is the limitation that should be solved for enabling data dynamics. In this paper, we design a novel authenticated data structure called bv23Tree, which enables client to batch‐verify the indices and values of any number of appointed leaves all at once for efficiency. By utilizing bv23Tree and a hierarchical storage structure, we present the first solution for Dynamic OPOR (DOPOR), which extends the OPOR model to support dynamic updates of the outsourced data. Extensive security and performance analyses show the reliability and effectiveness of our proposed scheme.
Lu Rao, Tengfei Tu, Hua Zhang 0001, Qiaoyan Wen
Wirel. Commun. Mob. Comput.3
2017 Flexible CP-ABE Based Access Control on Encrypted Data for Mobile Users in Hybrid Cloud System
Wenmin Li 0001, Xuelei Li, Qiaoyan Wen, Shuo Zhang 0008, Hua Zhang 0001
J. Comput. Sci. Technol.5
2017 Privacy-Preserving Outsourced Auditing Scheme for Dynamic Data Storage in Cloud
abstract
As information technology develops, cloud storage has been widely accepted for keeping volumes of data. Remote data auditing scheme enables cloud user to confirm the integrity of her outsourced file via the auditing against cloud storage, without downloading the file from cloud. In view of the significant computational cost caused by the auditing process, outsourced auditing model is proposed to make user outsource the heavy auditing task to third party auditor (TPA). Although the first outsourced auditing scheme can protect against the malicious TPA, this scheme enables TPA to have read access right over user’s outsourced data, which is a potential risk for user data privacy. In this paper, we introduce the notion of User Focus for outsourced auditing, which emphasizes the idea that lets user dominate her own data. Based on User Focus, our proposed scheme not only can prevent user’s data from leaking to TPA without depending on data encryption but also can avoid the use of additional independent random source that is very difficult to meet in practice. We also describe how to make our scheme support dynamic updates. According to the security analysis and experimental evaluations, our proposed scheme is provably secure and significantly efficient.
Tengfei Tu, Lu Rao, Hua Zhang 0001, Qiaoyan Wen
Secur. Commun. Networks3
2015 An anonymous and efficient remote biometrics user authentication scheme in a multi server environment
Peng Jiang 0007, Qiaoyan Wen, Wenmin Li 0001, Zhengping Jin, Hua Zhang 0001
Frontiers Comput. Sci.5
2015 Cryptanalysis and improvement of a certificateless aggregate signature scheme
Lin Cheng 0002, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001
Inf. Sci.4
2015 A strongly secure identity-based authenticated key agreement protocol without pairings under the GDH assumption
abstract
Among the existing identity-based authenticated key agreement ID-AKA protocols, there are only a few of them that can resist to leakage of ephemeral secret keys, which is about the protection of the session secret key after the ephemeral secret keys of users are compromised. However, all these ID-AKA protocols with leakage of ephemeral secret keys resistance require expensive bilinear pairing operations. In this paper, we present a pairing-free ID-AKA protocol with ephemeral secrets leakage resistance. We also provide a full proof of its security in the extended Canetti-Krawczyk model, which not only can capture resistance to leakage of ephemeral secret keys but also can capture other basic security properties such as master key forward security and key compromise impersonation resistance. Compared with the existing ID-AKA protocols, our scheme is a good trade-off between security and efficiency. Copyright © 2015 John Wiley & Sons, Ltd.
Haiyan Sun, Qiaoyan Wen, Hua Zhang 0001, Zhengping Jin
Secur. Commun. Networks3
2014 Cryptanalysis and improvement of a certificateless encryption scheme in the standard model
Lin Cheng 0002, Qiaoyan Wen, Zhengping Jin, Hua Zhang 0001
Frontiers Comput. Sci.4
2013 A novel privacy preserving keyword searching for cloud storage
abstract
In cloud storage environment, clients no longer have physical possession of their data, it indicates that their data may be leaked maliciously by cloud provider. To avoid the security risks, we propose a privacy preserving keyword searching scheme whose encryption procedure needs no pairing operation. Our scheme allows users to encrypt their data before uploading to the cloud, and retrieve them by searching the encrypted keywords, besides it enables the cloud service provider to participate in decipherment which reduces the computational overhead of the client's decryption. Performance analysis shows our new scheme is more efficient and more adaptable to the cloud environment than the existing schemes. In addition, the new scheme is proved to be semantically secure in the random oracle model.
Lin Cheng 0002, Zhengping Jin, Qiaoyan Wen, Hua Zhang 0001
PST4
2013 A novel pairing-free certificateless authenticated key agreement protocol with provable security
Haiyan Sun, Qiaoyan Wen, Hua Zhang 0001, Zhengping Jin
Frontiers Comput. Sci.3