Meng Li 0006

dblp:70/1726-6 · DBLP profile ↗
← Back
111ranked-venue papers
28as first author
96since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 56 · 15 first-author · 49 since 2021Computer networks · 34 · 6 first-author · 29 since 2021Software engineering, systems software and programming languages · 6 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Accurate, Secure, and Efficient Semi-Constrained Navigation with Multiple Spatial Restrictions
Meng Li 0006, Yan Qiao 0001, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
DSN1
2026 ARI-LLM: Autoregressive Imputation for Network Traffic Matrix via Large Language Models
Fenglin Yan, Yan Qiao 0001, Meng Li 0006, Cuiying Feng
INFOCOM4
2026 Lmte: Putting the "Reasoning" into WAN Traffic Engineering with Language Models
Xinyu Yuan, Yan Qiao 0001, Zonghui Wang, Meng Li 0006, Wenzhi Chen
INFOCOM4
2026 C2FFormer: Coarse-to-Fine Time Series Imputation via Autoregressive Transformer
Yan Qiao 0001, Jiangqi Song, Jiaxuan Dong, Anchi Zhang, Zilong Hu, Meng Li 0006
PAKDD (3)6
2026 DACL: Double-Anchor Contrastive Learning for IoT Network Intrusion Detection
abstract
In the Internet of Things, openness significantly increases security risks. Therefore, detecting such attacks through anomaly traffic monitoring is crucial for ensuring network security. Although existing Intrusion Detection Systems (IDS) have made some progress in detection performance using deep learning techniques (e.g., graph learning and meta-learning), the class imbalance problem remains a major challenge that needs to be addressed. To this end, we propose a Double-Anchor Contrastive Learning (DACL) framework. Firstly, we introduce a positive-negative sample construction module. Compared to traditional contrastive learning methods, this module directly constructs sample pairs, preserving more flow information and thereby enhancing the effectiveness. Secondly, we design a feature embedding and extraction module. By utilizing convolutional neural networks to extract spatial correlations among raw features, we generate more discriminative feature representations. Subsequently, we propose the double-anchor contrastive learning module, introducing a double-anchor mechanism to impose double constraints on inter-class distances, further enhancing feature representation capabilities and clustering effects. Finally, we map the learned features to a low-dimensional space via a classification network, achieving precise detection of abnormal traffic. Extensive experiments demonstrate that DACL outperforms existing works in terms of accuracy on datasets such as CIC-DDoS2017, CIC-IDS2018, and CIC-DDoS2019.
Lei Chen 0081, Na Xia, Meng Li 0006
IEEE Internet Things J.3
2026 DiffLoc+: Toward Robust Wi-Fi Hidden Camera Localization Based on Electromagnetic Diffraction
abstract
The proliferation of hidden WiFi cameras has raised serious privacy concerns, making their accurate detection and localization essential for the secure development of future intelligent wireless networks. However, existing solutions often require substantial user involvement, large movement spaces, predefined system parameters, or pre-collected training data, limiting their practicality and scalability. In this paper, we present DiffLoc+, a novel and low-cost system that localizes hidden WiFi cameras by harnessing the fundamental physical principle of electromagnetic diffraction. When an obstacle crosses the line-of-sight path between a transmitter and a receiver, it causes a distinctive signal attenuation pattern. We theoretically analyze the feasibility of exploiting this phenomenon for localization and identify two key conditions for building an unbiased diffraction-based model: symmetry and observability. To satisfy these conditions, DiffLoc+ introduces a controllable diffraction generation mechanism that precisely rotates a small metal plate around a WiFi receiver (e.g. a Raspberry Pi), producing a stable and predictable diffraction “shadowing” effect. We then construct an unbiased localization model that maps this effect to the azimuth of the camera. To ensure the robustness of the theoretical model in real-world applications, DiffLoc+ further introduces two robustness-enhancing mechanisms: (1) an attenuation-region difference-driven subcarrier selection method, which filters subcarriers that reliably reflect the diffraction attenuation pattern by quantifying the signal contrast between diffraction- and reflection-dominated regions; and (2) an uncertainty evaluation framework that integrates result consistency and diffraction signal quality to eliminate unreliable estimates. Implemented entirely with commodity off-the-shelf (COTS) hardware, DiffLoc+ achieves an average angular error of 11.92° across six diverse indoor environments and eleven commercial camera models, demonstrating its effectiveness and robustness.
Huan Yan 0004, Jian Liu 0055, Xiang Zhang 0011, Zhi Liu 0002, Bin Liu 0016, Meng Li 0006, Ming Gao 0023, Fusang Zhang
IEEE J. Sel. Areas Commun.6
2026 HealthEngine: An Integrated Healthcare Analytics Model Using Multimodal Transformer, Deep Multitask Neural Networks, and SHAP
abstract
The development of more accurate and explainable health predictions is paramount in view of the increasing prevalence rates of chronic diseases and mental illnesses. Existing methods often under-utilize the rich, heterogeneous data streams coming from wearable devices, environmental sensors, and behavioral data, and hence fall short in making predictions that are both accurate and actionable. Most models lack transparency and cannot avoid privacy concerns due to the samples used from sensitive health data. This study specifically addresses the challenge of building a predictive healthcare framework capable of handling multimodal data, data streams that originate from different modalities (physiological, behavioral, and environmental), and exhibit intrinsic heterogeneity. Unlike general heterogeneous datasets, multimodal health data demands models that can effectively integrate structured, semistructured, and temporal information while ensuring privacy and interpretability. In this work, we propose an integrated comprehensive multimodal health prediction framework with five advanced methods, namely multimodal transformer networks (MTN), deep multitask neural networks (DMNN), Shapley additive explanations (SHAP) based explainability, Federated Learning, and Bayesian neural networks (BNN). MTN uses attention mechanisms to fuse different data modalities and captures cross-modal dependencies effectively, achieving an improvement of 8% to 12% in prediction accuracy. DMNN leverages multitask learning to share knowledge between related health prediction tasks, reducing error rates by 10%–15%. SHAP is used to provide localized, patient-specific explanations that improve clinical trust by up to 85%. This is done by privately training the models on decentralized datasets, which provides results without more than a 3% drop in precision compared with centralized models. Third, BNNs are used to quantify uncertainty in predictions, providing useful confidence intervals that improve clinical decision-making by 20%. The results obtained suggest significant improvements in predictive accuracy, transparency, and privacy preservation. This research not only improves health predictions through multimodal analysis but also tackles significant limitations in privacy, interpretability, and uncertainty quantification, thus promoting informed clinical decisions and customized patient care.
Moshedayan Sirapangi, S. Gopikrishnan 0001, Norbert Herencsar, Meng Li 0006, Gautam Srivastava 0001
IEEE Trans. Comput. Soc. Syst.4
2026 Identifying Who You Are No Matter What You Write Through Abstracting Handwriting Style
abstract
With the increasing use of electronic devices, online handwriting verification has become crucial for biometricsbased identity authentication. Traditional methods, which rely on content-dependent verification of the writer's name, are vulnerable to forgery. This paper introduces a content-independent handwriting authentication system, Ph-Wri, designed for commodity smartphones. The core innovation is a multi-path attention feature fusion network that combines both static features (image of the handwritten text) and dynamic features (time-dependent properties during writing), to abstract the handwriting style instead of specific content for recognition, enabling robust user authentication. To extract handwriting style from dynamic writing features, we propose a polarity-aware attention strategy during training. This strategy incorporates Style Channel Attention (SCA) to capture direction-sensitive stylistic features, and Trajectory Spatial Attention (TSA) to highlight key handwriting trajectory regions. In the fine-tuning stage, the Correlation-Aware Attention (CAA) module models inter-channel structural correlations, mitigating the influence of content and enhancing style-consistent representations. By linking content-independent handwriting style to user identity, the system achieves accurate authentication. Extensive experiments on both the self-built CIEHD dataset and the public BiosecurID dataset demonstrate exceptional performance, achieving a 99% Verification Accuracy on CIEHD. Compared to state-of-theart methods that utilize only static or dynamic data, Ph-Wri significantly reduces the Equal Error Rate, showcasing the effectiveness and practicality of the proposed approach.
Jinyang Huang, Yuanhao Feng, Feng-Qi Cui, Xiang Zhang 0011, Zhi Liu 0002, Xin Liu 0104, Jianchun Liu, Fusang Zhang, Meng Li 0006
IEEE Trans. Dependable Secur. Comput.9
2026 Hydra: Support Dynamic BFT With Weaker Assumptions and Explicit Request Handling
abstract
This paper presents Hydra, a dynamic BFT protocol that allows replicas to join and leave the system dynamically. It addresses the limitations of traditional static BFTs in managing membership changes and can be used to simplify the implementation of many features in modern blockchain applications. Hydra relies on weaker assumptions to achieve standard properties compared to the existing solution Dyno and introduces a configuration auto-transition protocol to ensure liveness. Through temporary configurations and explicitly defined replica responsibilities for request handling, Hydra pipelines membership requests alongside regular requests and realizes clarity, achieving a more efficient and smoother configuration transitions. It also employs a non-blocking configuration discovery mechanism, enabling new replicas to participate in consensus quickly. We formally prove Hydra's correctness under the dynamic BFT model. Experimental results demonstrate Hydra's ability to maintain throughput fluctuations within 5% during various replica join and leave scenarios, outperforming Dyno and existing BFT system supporting reconfiguration in both stability and efficiency. Hydra effectively manages scenarios that Dyno circumvents with stronger assumptions and quickly restores throughput to normal levels.
Zijian Zhang 0001, Haibo Sun, Meng Li 0006, Jing Sun 0002, Jiamou Liu, Lei Xu 0016, Jincheng An, Mauro Conti, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.5
2026 Traceable Cross-Domain Data Sharing With Expressive Keyword Search
abstract
The Internet of Vehicles (IoV) generates massive sensitive perception data, typically managed by manufacturer-specific domains. While encryption with domain-specific parameters protects confidentiality, many IoV applications require secure cross-domain data sharing to access complementary information, and expressive keyword search for efficient access. However, existing Attribute-Based Keyword Search (ABKS) schemes are designed for single-domain settings, and thus cannot address heterogeneous key management or provide traceability without a universally trusted authority. To address these issues, we propose TCroS, a traceable cross-domain data sharing scheme that generalizes CP-ABE via proxy re-encryption mechanism, enabling ciphertexts generated in one domain to be securely transformed for authorized requesters in another. To provide traceability, TCroS embeds requester identities into decryption keys using Boneh-Boyen signatures, allowing any party (rather than the universally trusted authority) to trace the source of a leaked key. We further extend TCroS to TCroSS, which incorporates privacy-preserving expressive keyword search supporting Boolean queries, thereby enabling efficient retrieval of authorized data while resisting keyword guessing attacks. Formal security analysis proves that our schemes achieve IND-SCPA and IND-SCKA security. Experimental results demonstrate their practicality, showing that cross-domain sharing can be realized with computation and storage overheads comparable to single-domain setting.
Qiuyun Tong, Xiyun Yao, Zhe Ren, Yinbin Miao, Xinghua Li 0001, Meng Li 0006, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.6
2026 Enhancing Integrity Verification of Convolutional Neural Network Predictions in a Malicious Model
abstract
The widespread deployment of neural networks has raised significant concerns regarding the integrity and privacy of model predictions, especially in malicious environments. Current approaches have explored zero-knowledge proofs for integrity verification. However, they suffer from inefficiency in proving runtime and a lack of rigorous integrity verification for non linear operations. To address these issues, we present a trustwor thy framework for Enhancing Integrity Verification of Convolutional Neural Network predictions (EIV-CNN) in a malicious model, whose key contributions are an efficient optimized sum check protocol and a robust enhanced verification mechanism. Specifically, we first propose an algorithm that enables efficient proving of both batch and collaborative CNN predictions by com bining sumcheck claims of multiple matrix multiplications into one. Moreover, we introduce a non-interactive sumcheck protocol with malicious security (NM-Sumcheck) to serve as a building block for publicly verifying matrix multiplication operations. Furthermore, we introduce a verifiable method for transforming nonlinear operations into matrix operations, enabling their sub sequent evaluation with the NM-Sumcheck protocol. Our EIV CNN provides malicious security, guarantees public verifiability, and preserves model privacy. Empirical results demonstrate that our sumcheck framework achieves constant prover time, verifier time, and proof size. Compared to the state-of-the-art, it achieves up to a 128.56× reduction in prover time, along with significant reductions in communication overhead and enhanced scalability.
Zhongkai Lu, Meng Li 0006, Jingjing Wang 0003, Huaqun Wang
IEEE Trans. Dependable Secur. Comput.4
2026 Toward Trustworthy Dynamic Facial Expression Recognition via Information Bottleneck Modeling
Feng-Qi Cui, Anyang Tong, Jinyang Huang, Jie Zhang 0073, Meng Li 0006, Linsheng Huang, Dan Guo 0001, Meng Wang 0001
IEEE Trans. Inf. Forensics Secur.5
2026 Frequency-Domain Signatures for Proactive Defense Against Model Poisoning Attacks in Federated Learning
abstract
Federated Learning enables decentralized model training without exposing raw data, but remains fundamentally vulnerable to poisoning attacks from malicious clients. Existing defenses rely heavily on passive anomaly detection, honest majority assumptions, or unrealistic statistical priors, making them ineffective against adaptive and stealthy adversaries. In this paper, we propose SpecShield, a proactive defense mechanism that actively probes client models through calibrated adversarial perturbations. By leveraging the Fast Gradient Sign Method on the server side, SpecShield elicits dynamic response patterns from each client. These responses are then analyzed in the frequency domain using the Discrete Wavelet Transform. These frequency-domain features uncover distinctive response patterns between benign and malicious clients, enabling robust detection of model poisoning attacks in both non-IID environments and Byzantine majority scenarios. We further derive theoretical upper bounds on perturbation magnitudes to guarantee detection accuracy while preserving benign client performance. Through extensive experiments conducted on real-world datasets under six state-of-the-art poisoning attacks, SpecShield consistently outperforms existing defenses in both detection accuracy and model robustness. Our results demonstrate that active perturbation-induced profiling provides a new dimension for securing federated learning against sophisticated adversarial threats.
Fangjie Hu, Aiqing Zhang, Meng Li 0006, Chen Wang 0011
IEEE Trans. Inf. Forensics Secur.3
2026 Secure and Customized Data Sharing With Identical Sub-Policy and Bilateral Access Control
Fuyuan Song, Chuan Zhang 0003, Zhangjie Fu 0001, Meng Li 0006, Zheng Qin 0001, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2026 Scriptless Atomic Swap With Batch Processing
Menghao Wang, Mengxuan Liu, Meng Li 0006, Chuan Zhang 0003, Licheng Wang 0004, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.4
2026 DeSA: Decentralized Secure Aggregation for Federated Learning in Zero-Trust D2D Networks
abstract
Secure Aggregation (SA) is a fundamental privacy-preserving technique in Federated Learning (FL) that ensures the confidentiality of local model updates while enabling global model aggregation. Previous studies have implemented SA within the FL architecture that includes a central server. However, in a Device-to-Device (D2D) based FL, decentralized SA becomes challenging due to the lack of a central server, particularly in a zero-trust network vulnerable to Byzantine attacks. To address this issue, we present a novel Byzantine-robust decentralized SA protocol (DeSA) that guarantees the integrity of model training and aggregation while protecting the privacy of model updates. Specifically, we utilize an enhanced zk-SNARK proof system to verify the local model training process. Additionally, we propose a framework that embeds multiple zero-knowledge proofs to ensure the integrity of model aggregation, while maintaining succinct proofs and fast verification. Moreover, we present a Byzantine-robust D2D aggregation protocol that can withstand malicious nodes trying to disrupt model aggregation. To protect privacy, we develop a one-time masking method that eliminates aggregated masks through a dynamic aggregation strategy. This strategy takes into account the adjacency and trust relationships among nodes in evolving network topologies. Finally, we perform a theoretical analysis and evaluate DeSA on real-world datasets. Experimental results show that the time required to verify an embedded proof is significantly reduced compared to the time of verifying multiple proofs. Additionally, its accuracy remains robust against malicious nodes.
Zhongkai Lu, Meng Li 0006, Jingjing Wang 0003, Keke Gai, Xiaofeng Chen 0001
IEEE Trans. Inf. Forensics Secur.3
2026 HKT-SmartAudit: Distilling Lightweight Models for Smart Contract Auditing
abstract
The rapid growth of blockchain technology has driven the widespread adoption of smart contracts; however, their inherent vulnerabilities have led to significant financial losses. Traditional auditing methods, while essential, struggle to keep pace with the increasing complexity and scale of smart contracts. Large language models (LLMs) offer promising capabilities for automating vulnerability detection, but their adoption is often limited by high computational costs. Although prior work has explored leveraging large models through agents or workflows, relatively little attention has been given to improving the performance of smaller, fine-tuned models—a critical factor for achieving both efficiency and data privacy. In this paper, we introduce HKT-SmartAudit, a framework for developing lightweight models optimized for smart contract auditing. It features a multi-stage knowledge distillation pipeline that integrates classical distillation, external domain knowledge, and reward-guided learning to transfer high-quality insights from large teacher models. A single-task learning strategy is employed to train compact student models that maintain high accuracy and robustness while significantly reducing computational overhead. Experimental results show that our distilled models outperform both commercial tools and larger models in detecting complex vulnerabilities and logical flaws, offering a practical, secure, and scalable solution for smart contract auditing. The source code is available in the GitHub repository1.
Jing Sun 0002, Zijian Zhang 0001, Xianhao Zhang, Meng Li 0006, Yuqiang Sun 0001, Daoyuan Wu, Yang Liu 0003, Chunmiao Li, Mingchao Wan, Jin Dong 0004
IEEE Trans. Inf. Forensics Secur.6
2026 IFAD: Privacy-Preserving Isolation Forest-Based Anomaly Detection in Public Cloud Environments
abstract
Anomaly detection plays a vital role in processing multi-source data through public cloud servers, yet existing privacy-preserving schemes fail to efficiently detect anomalies while protecting data source privacy. Although isolation forest offer advantages for unsupervised high-dimensional data analysis, implementing its tree-based privacy-preserving mechanisms remains challenging. In this paper, we propose IFAD, a novel isolation forest-based scheme for detecting anomalies in private data. IFAD guarantees end-to-end privacy protection by safeguarding original data, tree structures, and intermediate information throughout detection workflows. Our design achieves efficiency through three key contributions: 1) Cryptographic building blocks combining function secret sharing (FSS) and secret sharing (SS) to enable secure computations; 2) A split index protocol and layer update protocol to facilitate efficient, layer-by-layer isolation forest construction; 3) A detection phase optimization converting the anomaly score calculations into lookup table operations. Experimental evaluations demonstrate that IFAD achieves superior performance, outperforming prior schemes by 2.4×-3.1× in runtime under LAN and WAN environments, and by 1.8×-7.8× in online communication overhead, while maintaining comparable detection accuracy. Our solution establishes an effective balance between privacy preservation and operational efficiency for cloud-based anomaly detection.
Jingcheng Zhao, Kaiping Xue, Meng Li 0006, Yingjie Xue, Yaxuan Huang
IEEE Trans. Inf. Forensics Secur.3
2026 Secure Multi-Character Searchable Encryption Supporting Rich Search Functionalities
abstract
Wildcard Keyword Searchable Encryption (WKSE) has grown into a ubiquitous tool. It enables clients to search desired files with wildcard expressions. Although promising, previous schemes confront three barriers: (1) An adversary can launch a correlation attack to acquire the similarity between keywords. (2) The WKSE schemes exhibit false positives which can lead to wrong search results. (3) Existing feature extraction strategies limit the flexibility of search expressions. In this paper, we propose a Multi-Character Searchable Encryption scheme (MCSE) that overcomes the aforementioned barriers. To resist correlation attacks, we design the randomize pad model to encrypt the vector. To eradicate false positives, we apply the vector space model and complete feature extraction strategies so that a feature set uniquely identifies a keyword or expression. To enhance search flexibility, we introduce three distinct feature extraction strategies for keyword expressions, wildcard expressions, and logical expressions, enabling effective multi-character search. These strategies enable indexes to accom modate the search of diverse expressions. Finally, we prove that MCSE is indistinguishable against chosen-feature attacks and implement MCSE on two real datasets. Compared with state-of the-art schemes, the experiment results show that MCSE achieves good performance.
Qing Wang 0060, Donghui Hu, Meng Li 0006, Yan Qiao 0001, Guomin Yang, Mauro Conti
IEEE Trans. Knowl. Data Eng.3
2026 Learning-Based Sketches for Frequency Estimation in Data Streams Without Ground Truth
abstract
Estimating the frequency of items on the high-volume, fast data stream has been extensively studied in many areas, such as database and network measurement. Traditional sketches provide only coarse estimates under strict memory constraints. Although some learning-augmented methods have emerged recently, they typically rely on offline training with real frequencies or/and labels, which are often unavailable. Moreover, these methods suffer from slow update speeds, limiting their suitability for real-time processing despite offering only marginal accuracy improvements. To overcome these challenges, we propose UCL-sketch, a practical learning-based paradigm for per-key frequency estimation. Our design introduces two key innovations: (i) an online training mechanism based on equivalent learning that requires no ground truth (GT), and (ii) a highly scalable architecture leveraging logically structured estimation buckets to scale to real-world data stream. The UCL-sketch, which utilizes compressive sensing (CS), converges to an estimator that provably yields an error bound far lower than that of prior works, without sacrificing the speed of processing. Extensive experiments on both real-world and synthetic datasets demonstrate that our approach outperforms previously proposed approaches regarding per-key accuracy and distribution. Notably, under extremely tight memory budgets, its quality almost matches that of an (infeasible) omniscient oracle. Moreover, compared to the existing equation-based sketch, UCL-sketch achieves an average decoding speedup of nearly 500 times.
Xinyu Yuan, Yan Qiao 0001, Meng Li 0006, Zhenchun Wei, Cuiying Feng, Zonghui Wang, Wenzhi Chen
IEEE Trans. Knowl. Data Eng.3
2026 Building Trust for Underwater Wireless Sensor Networks via Riemannian Variational Autoencoders
Na Xia, Sizhou Wei, Meng Li 0006, Jiashan Wan
IEEE Trans. Mob. Comput.3
2026 Routing-Oblivious and Data-Efficient Network Tomography With Flow-Based Generative Model
abstract
Given the high cost associated with directly measuring the Traffic Matrix (TM), researchers have devoted efforts to devising methods for estimating the complete TM from low-cost link loads by solving a set of heavily ill-posed linear equations. Today’s increasingly intricate networks present an even greater challenge: as adaptive and dynamically changing routing strategies are gradually replacing traditional fixed routing schemes, the routing matrix within these equations can no longer be deemed reliable. In our previous work, we pioneered a flow-based generative model, FlowTM, which estimated the TM by establishing an invertible correlation between the TM and link loads without relying on the routing matrix. We demonstrated that the missing information in the ill-posed equations can be decoupled from the TM and learned jointly with the invertible mapping. Considering that acquiring a complete training set for FlowTM is often impractical in many real-world networks, we further propose an enhanced model, FlowTM+, in this extended work. It incorporates anInspectormodule to mine deeper latent structures from the partially observed TM data and link load measurements. This new technique effectively compensates for unobservable information in the training data. Extensive experiments demonstrate that FlowTM improves the performance of the best baseline by 38%–58% when the actual routing matrix is absent. Remarkably, with only 2% of the training data, FlowTM+ achieves an estimation accuracy comparable to that of state-of-the-art baselines trained with full routing knowledge and complete training data.
Yan Qiao 0001, Minyue Li, Xinyu Yuan, Kui Wu 0001, Cuiying Feng, Meng Li 0006, Kun Xie 0001
IEEE Trans. Netw.6
2025 PPNA: Enabling Privacy-Preserving and Efficient Social Network Alignment
abstract
Social network alignment has made significant progress in social network analysis, with representative applications such as cross-domain recommendation and community detection. However, existing approaches require institutions to share raw user data, raising significant privacy concerns. To address this issue, we propose a Privacy-Preserving Network Alignment (PPNA) scheme that eliminates the need for raw data sharing. In concrete, PPNA leverages homomorphic encryption to enable computation over the ciphertext domain without decryption. It ensures provable data privacy. PPNA also presents a secure multiparty computation protocol to eliminate reliance on trusted third-party servers, which is often impractical in real-world scenarios. Furthermore, its well-designed iterative update mechanism is well-suited for iterative alignment algorithms. Comprehensive experimental results have demonstrated that PPNA improves performance compared to the scenario where raw data sharing is unfeasible due to privacy concerns. It achieves an average F1-score increase of 1.65 times and up to 2.28 times. The performance gain is more pronounced in decentralized settings, highlighting PPNA’s practicality in real-world scenarios when multi-institution collaboration is imperative.
Rui Tang 0020, Hao Ren 0001, Haizhou Wang 0001, Xingshu Chen, Meng Li 0006, Hongwei Li 0001
GLOBECOM6
2025 Artemis: Decentralized, Secure, and Efficient Safety Monitoring with Dynamic Trajectories
Meng Li 0006, Zhuangwei Li, Yifei Chen 0005, Yan Qiao 0001, Mauro Conti
ICICS (1)1
2025 Network Traffic Matrix Imputation via Large Language Models
abstract
Large Language Models (LLMs) have demonstrated remarkable zero-shot capabilities across various domains. This paper pioneers the application of LLMs’ outstanding knowledge and reasoning abilities to the challenging task of Traffic Matrix (TM) imputation. However, the application poses significant challenges due to the skewed TM distribution and the deficient traffic feature under low sampling rate. To address these issues, we propose TM-LLM, the first LLM-based model specifically designed for TM imputation. Our approach includes two critical designs: Firstly, we develop an adversarial training strategy to pre-impute TM data, allowing the LLM to understand the distributional features even when faced with extensive missing data. Secondly, we devise a TM-specific embedding scheme along with a crafted prompt template, which enables our approach to harness LLMs’ exceptional inferential ability. Experimental results show that TMLLM significantly outperforms state-of-the-art imputation methods, achieves a notable 16.5% -44.8 % improvement in accuracy over the current best baseline, while reduces measurement costs by 80 % - 96 %. It can accurately capture the traffic pattern even when the sampling rate is extremely low. The code for reproducing our experiments is publicly available1. These findings strongly indicate the breakthrough potential of LLMs in network TM analysis tasks.1The experimental codes with our methods and the datasets are available at https://github.com/FILingK/TM-LLM
Fenglin Yan, Yan Qiao 0001, Meng Li 0006, Mauro Conti
ISCC4
2025 CamLopa: A Hidden Wireless Camera Localization Framework via Signal Propagation Path Analysis
abstract
Hidden wireless cameras pose significant privacy threats, necessitating effective detection and localization methods. However, existing localization solutions often require impractical activity spaces, expensive specialized devices, or pre-collected training data, limiting their practical deployment. To address these limitations, we introduce CamLopa, a training-free wireless camera localization framework that operates with minimal activity space constraints using low-cost, commercial-off-the-shelf (COTS) devices. CamLopa can achieve detection and localization in just 45 seconds of user activities with a Raspberry Pi board. During this short period, it analyzes the causal relationship between wireless traffic and user movement to detect the presence of a hidden camera. Upon detection, CamLopa utilizes a novel azimuth localization model based on wireless signal propagation path analysis for localization. This model leverages the time ratio of user paths crossing the First Fresnel Zone (FFZ) to determine the camera's azimuth angle. Subsequently, CamLopa refines the localization by identifying the camera's quadrant. We evaluate CamLopa across various devices and environments, demonstrating its effectiveness with a 95.37% detection accuracy for snooping cameras and an average localization error of 17.23°, under the significantly reduced activity space requirements and without the need for training. Our code and demo are available at https://github.com/CamLoPA/CamLoPA-Code.
Xiang Zhang 0011, Jie Zhang 0073, Zehua Ma, Jinyang Huang, Meng Li 0006, Huan Yan 0004, Peng Zhao 0024, Zijian Zhang 0001, Bin Liu 0016, Qing Guo 0005, Tianwei Zhang 0004, Nenghai Yu
SP5
2025 DiffLoc: WiFi Hidden Camera Localization Based on Electromagnetic Diffraction
Xiang Zhang 0011, Jie Zhang 0073, Huan Yan 0004, Jinyang Huang, Zehua Ma, Bin Liu 0016, Meng Li 0006, Kejiang Chen, Qing Guo 0005, Tianwei Zhang 0004, Zhi Liu 0002
USENIX Security Symposium7
2025 Multivariate Time Series forecasting based on temporal decomposition and graph neural network
Yan Qiao 0001, Rongyao Hu, Minyue Li, Xinyu Yuan, Meng Li 0006, Zhenchun Wei, Cuiying Feng
Eng. Appl. Artif. Intell.7
2025 Sniffer Channel Selection Based on Value Decomposition Networks in CRNs
abstract
In Cognitive Radio Networks (CRNs), network fault analysis, traffic tracing, and resource optimization are challenging tasks. With the increasing number of wireless applications and the conflict with limited wireless spectrum resources, the Sniffers Channel Assignment problem in CRNs has become particularly important. To address this issue, we propose a Value Decomposition Networks-based channel selection (CSVDN) algorithm. During centralized training, the Monitoring Quality Network (MQN) is trained based on observed data, using global information to calculate the Quality of Monitoring (QoM), which is then used as a reward to guide sniffers in selecting the optimal channels. During decentralized execution, sniffers share model parameters and independently run the MQN, sequentially selecting the optimal channels. This process ensures that sniffers collectively maximize network coverage while maintaining distributed control, thereby improving efficiency and scalability in dynamic environments. The results from NS-3 simulations show that CSVDN provides a distributed and implementable channel selection solution with high scalability and practicality, making it particularly suitable for large-scale CRNs.
Lei Chen 0081, Na Xia, Meng Li 0006, Jiashan Wan, Sizhou Wei
IEEE Internet Things J.3
2025 Covert Transmission via Steganography and Smart Contract
abstract
The Internet of Things (IoT) system gathers data through diverse smart devices and sensors to make thorough decisions tailored to specific needs. Yet, in intricate IoT setups, privacy infringement occurs through various means like data collection, initial data handling, and data sharing. Therefore, the concealment of data during transmission should receive sufficient attention. The communication approach that merges blockchain technology with covert communication has shown progress in addressing the aforementioned issues. However, this integration has also led to challenges, such as low-data embedding rates and distinctive features in blockchain transactions containing covert data. To seek a solution with high-embedding rates that do not make generated transactions stand out distinctly, this article analyzes the Ethereum transaction field formats, identifies the input data field with high concealment and large capacity as the embedding target, then proposes a data covert transmission scheme based on hybrid embedding in contract fields. This scheme utilizes LSB steganography to embed high-capacity covert data in images, and embeds the URL of the image into the input data field of the Ethereum smart contract transaction, thereby increasing the embedding rates. Subsequently, to further enhance the concealment of this scheme, a data embedding method based on contract relationships is proposed. Through this technique, for the first time, covert data transmission is achieved solely through the invocation relationships of smart contracts within the blockchain covert communication environment, instead of directly embedding covert data into transactions. This method results in transactions that are theoretically indistinguishable from regular transactions, greatly enhancing the security of the scheme. Finally, an evaluation of undetectability, embedding rate, and scalability was conducted for the proposed schemes, concluding that the schemes presented in this article have significant advantages in all three areas.
Yingxue Liu, Jing Sun 0002, Zhuo Chen 0001, Feng Gao 0019, Xiangbo Yuan, Zijian Zhang 0001, Lei Zhang 0101, Meng Li 0006, Liehuang Zhu
IEEE Internet Things J.8
2025 Wi-SFDAGR: WiFi-Based Cross-Domain Gesture Recognition via Source-Free Domain Adaptation
abstract
WiFi channel state information (CSI)-based gesture recognition offers unique advantages, including cost-effectiveness and enhanced privacy protection, and has garnered significant attention in recent years. However, existing WiFi-based gesture recognition solutions exhibit poor generalization ability when deployed in new environment, orientation, or location. Although some methods combine labeled source domain and unlabeled target domain to learn domain-independent features, factors, such as data privacy protection, hinder access to source data during practical environment adaptation. Consequently, we consider realistic scenario where source data is unavailable during adaptation of unlabeled test data, and instead, a trained source domain model is used. In this article, we propose Wi-SFDAGR, a WiFi-based source-free domain adaptation gesture recognition framework. Specifically, we treat cross-domain as an unsupervised clustering problem, aiming to ensure that features within local neighborhoods exhibit similar prediction results while those farther apart display different prediction outcomes in the feature space. We theoretically analyze the effect of enhanced prediction consistency between neighbor points extracted from gestures on generalization error. Furthermore, we employ an attraction-dispersion network to strengthen prediction consistency among closely located features in the feature space while reducing it for distantly located features. To mitigate noise introduced during nearest neighbor sample selection in the feature space (where predictions may not align with the input sample’s prediction), we progressively improve nearby sample feature aggregation by estimating uncertainty to reweight local neighborhood predictions. Finally, extensive experiments are conducted on the Widar 3.0 and XRF55 datasets and the results show our proposed framework outperforms most cross-domain methods.
Huan Yan 0004, Xiang Zhang 0011, Jinyang Huang, Yuanhao Feng, Meng Li 0006, Anzhi Wang, Weihua Ou, Zhi Liu 0002
IEEE Internet Things J.5
2025 PQ3FAKE: Postquantum Three-Factor Authentication Against Server Compromise in Mobile Cloud Computing
abstract
The rapid advancement of mobile cloud computing has prompted users and commercial entities to increasingly access and utilize cloud resources for executing resource-intensive operations, which requires strong three-factor authentication and key exchange (3FAKE) protocols to ensure secure interactions in cloud environments. However, the current 3FAKE protocols not only primarily rely on traditional public-key cryptosystems that are vulnerable to quantum attacks, but lack sufficient protection for sensitive information of cloud users as well. To this end, this paper proposes a post-quantum 3FAKE (PQ3FAKE) protocol employing identity-based oblivious pseudorandom function (IBOPRF). Specifically, an IBOPRF from module learning with errors is instantiated to achieve a better balance between efficiency and security. Next, PQ3FAKE is built upon this IBOPRF to protect password from server compromise. We conduct an extensive evaluation and comparison with existing typical protocols in terms of computational overhead and security, demonstrating that the proposed PQ3FAKE achieves higher security while maintaining expected performance.
Xue Yang 0017, Qi Jiang 0001, Meng Li 0006, Meijia Xu, Ding Wang 0002, Jianfeng Ma 0001
IEEE Internet Things J.3
2025 Wi-Pulmo: Commodity WiFi Can Capture Your Pulmonary Function Without Mouth Clinging
abstract
Pulmonary function testing is a crucial examination for respiratory diseases. Current medical spirometers are bulky and inconvenient, while available portable spirometers are extremely expensive and often lack accuracy. Furthermore, both devices require direct contact, inevitably increasing the cross-infection risk. To tackle these challenges, we propose Wi-Pulmo, an end-to-end deep learning-based Wireless System that utilizes WiFi channel state information (CSI) to provide contact-free, convenient, cost-effective, and precise pulmonary function testing outside the clinical setting. Based on the analysis of thoracic and abdominal movement patterns, Wi-Pulmo first validates the feasibility of using WiFi to estimate pulmonary function. Then, Wi-Pulmo designs an efficient fine-grained sensing quality-based algorithm for complete exhalation segmentation. Additionally, a relevant interference-tolerant learning algorithm based on variational inference is proposed to accurately map the CSI of WiFi signals to pulmonary function. Extensive experiments achieved average monitoring error rates of 2.59% for normal subjects in daily scenarios and 5.87% for real patients in tertiary hospitals over a two-month period. These satisfactory results demonstrate the strong effectiveness and robustness of Wi-Pulmo. Furthermore, our findings in clinical reveal a close correlation between chronic diseases and pulmonary function.
Peng Zhao 0024, Jinyang Huang, Xiang Zhang 0011, Zhi Liu 0002, Huan Yan 0004, Meng Wang 0037, Guohang Zhuang, Yutong Guo, Xiao Sun 0003, Meng Li 0006
IEEE Internet Things J.10
2025 Accurate, Secure, and Efficient Semi-Constrained Navigation Over Encrypted City Maps
abstract
Navigation services enable users to find the shortest path from a starting point$S$to a destination$D$, reducing time, gas, and traffic congestion. Still, navigation users risk the exposure of their sensitive location data. Our motivation arises from how users can accurately, securely, and efficiently navigate from$S$to$D$while passing through$k$unordered stops, i.e., midway locations with a non-fixed visiting order. In this work, we formally define Semi-Constrained Navigation (SCN) and present a novel scheme Hermes to achieve accurate, secure, and efficient SCN. Specifically, we propose a divide-and-conquer approach to strike a good balance between accuracy and efficiency. It recursively depth-first-searches the whole area (a navigation tree) and invokes five carefully-crafted strategies stop-by-stop to compute three subpaths in three sequential subareas. We construct a path-distance oracle to encrypt the road graph and securely implement the strategies by using homomorphic encryption and garble circuits. We formally prove the security in the random oracle model and analyze the search complexity to be less than$O(k^{2})$. We experiment over a real-world city map and compare with six baselines. Results show that path search with$k=4$among$N=1000$intersections requires 5.58 seconds with a 3.2% distance deviation rate and an 82.5% path similarity.
Meng Li 0006, Yifei Chen 0005, Jingyu Wu, Zijian Zhang 0001, Jialing He, Liehuang Zhu, Mauro Conti, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Group BFT: Two-Round BFT Protocols Via Replica Grouping
abstract
This paper seeks to enhance the performance of large-scale leader-based Byzantine Fault Tolerant (BFT) systems by proposing a novel Group BFT scheme. The scheme utilizes a two-round message transmission process to distribute the load from a single leader across multiple replicas by dividing the entire consensus network into groups, each with an equal number of replicas. Each group has a leader to process the group's voting messages into a single aggregated voting message during the first round, which is then transmitted to the consensus leader in the second round (similar process for proposing). We establish a formal system framework for Group BFT protocols with a versatile set of base components and explicit definitions, addressing the challenges inherent in designing such a system. We further design and implement two highly efficient Group BFT protocols: one that supports inter-group member exchange and the other one that does not. We theoretically prove the safety, liveness, and responsiveness of the Group BFT protocols. We conduct a formal analysis of Group BFTs' tolerance and complexity. Experimental results show that the two Group BFT protocols significantly alleviate the processing bottlenecks of the leader and highly improve throughput in large-scale systems.
Zijian Zhang 0001, Meng Li 0006, Lei Xu 0016, Meng Ao, Liehuang Zhu
IEEE Trans. Dependable Secur. Comput.5
2025 TMT-FL: Enabling Trustworthy Model Training of Federated Learning With Malicious Participants
abstract
Federated learning is a widely used method for collaborative machine learning without sharing local data. In this approach, participants train models using their local data, and the model updates are aggregated into a global model. However, ensuring trustworthy model training is crucial because malicious participants may not use their actual local data or may not train the model as intended, which makes it challenging to guarantee the authenticity of the data and the integrity of the model training. To address these issues, we propose a trustworthy model training scheme (TMT-FL) with verifiable authenticity and integrity. Specifically, we leverage zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) based proofs to verify the integrity of the training execution. To deal with the performance bottleneck in generating zk-SNARK proofs, we use the Chinese Remainder Theorem to optimize the convolution operation, and present an improved zk-SNARK based proof generating scheme which significantly reduces the online proving time. Besides, we adopt matrix commitment along with bloom filter to ensure the authenticity and integrity of the training datasets. Extensive experimental results demonstrate that our improved zk-SNARK scheme performs nearly$3.1\times$faster than the state-of-the-art in online proving time. Moreover, we experimentally confirm the efficiency of TMT-FL under diverse datasets in terms of computational costs, storage costs, and communication overheads.
Zhongkai Lu, Zhengyin Zhang, Mei Huang, Jingjing Wang 0003, Meng Li 0006
IEEE Trans. Dependable Secur. Comput.6
2025 Privacy-Preserving Truth Discovery of Evolving Truths for Mobile Crowdsensing Systems
abstract
Privacy-preserving truth discovery (PPTD) enables the crowdsensing platform to extract reliable inferred truths from unreliable user sensory data. While mobile crowdsensing systems have driven the emergence of many applications, continuously extracting inferred truths of evolving objects over streaming data (continuous PPTD) remains a challenge. Most existing works focus on static scenarios and cannot handle the new challenges in continuous PPTD, such as accuracy decrease, user dynamics, real-time requirements, and outliers. To address these challenges, we present PTET, a PPTD framework for continuous PPTD. By mining evolving patterns, PTET extracts accurate inferred truths of evolving objects even when some epochs lack sufficient user sensory data. PTET ensures the privacy of both users and data requesters while achieving high accuracy. Furthermore, we present PTET-P for practical applications. It employs a virtual user combined with evolving patterns to effectively eliminate the impact of user dynamics in continuous PPTD. Meanwhile, PTET-P achieves “immediate on-arrival processing” to improve real-time performance significantly. In addition, we address the outliers problem with the help of evolving patterns. We provide security analysis to prove that our frameworks protect the privacy of both users and data requesters. Extensive experiments demonstrate that our frameworks dramatically outperform the existing schemes in extracting inferred truths of evolving objects in continuous PPTD.
Jingcheng Zhao, Kaiping Xue, Ruidong Li 0001, Bin Zhu 0010, Meng Li 0006, Qibin Sun, Jun Lu 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Loki: Physical-World Adversarial Attacks on Wireless Indoor Localization via Differentiable Object Placement
abstract
As a cornerstone for numerous sensing applications, wireless indoor localization has been a pivotal area of research over the last two decades. While techniques such as jamming, spoofing, and adversarial perturbation have been exploited to compromise wireless indoor localization, existing attacks face challenges in accessibility to wireless systems and stealthiness. To address these limitations, we introduceLoki, a novel physical-world attack on wireless indoor localization via differentiable object placement. Specifically, we develop a differentiable wireless ray-tracing technique that allows us to optimize object placement in the scene. By repositioning an existing object in the scene by just a few centimeters,Lokifools existing wireless indoor localization systems into generating erroneous localization results. We also show via experiments that the object placement generated byLokialigns with wireless sensing theory (e.g., the forward scattering region and Fresnel zone), confirming its explainability. Additionally,Lokiproves effective across various localization models and scenarios, highlighting its generalizability.
Xueqiang Han, Jinyang Huang, Meng Li 0006, Chao Cai 0001, Tianyue Zheng
IEEE Trans. Inf. Forensics Secur.3
2025 DamPa: Dynamic Adaptive Model Poisoning Attack in Federated Learning
abstract
Federated learning (FL) enables cross-device collaboration by sharing local model updates without exposing raw data. However, its distributed nature introduces complex, multi-layered security threats that threaten both data privacy and model robustness. One of the most significant threats is the model poisoning attack, which exploits the server’s limited verification of client updates to inject malicious gradients, undermining aggregated model integrity and amplifying vulnerabilities in dynamic FL environments. Traditional defense mechanisms are notably vulnerable to highly adaptive, dynamic model poisoning attacks, struggling to respond effectively to attackers’ real-time adjustments in strategy. To expose these vulnerabilities and advance federated learning defense strategies, we propose a Dynamic Adaptive Model Poisoning Attack (DamPa), the first adaptive poisoning method that combines multiobjective optimization with dynamic strategy adjustments. DamPa exploits dynamic optimization to generate malicious updates that closely imitate benign patterns. It achieves significant early-stage performance degradation while maintaining both stealth and effectiveness throughout training. Our experimental evaluation on multiple real-world datasets demonstrates that DamPa outperforms existing attack methods in terms of effectiveness, particularly against robust aggregation defenses like Bulyan, DnC, FLtrust. It drastically reduces model accuracy to near-random classification levels (e.g., on the CIFAR-10 dataset, accuracy drops to 10.53%). This work reveals the limitations of existing defenses against dynamic attacks and highlights the urgent need to advance FL security. The DamPa framework offers valuable insights for designing more resilient defense mechanisms. Code is available at: https://github.com/HUFangjie/code.
Fangjie Hu, Aiqing Zhang, Xiaoming Liu 0019, Meng Li 0006
IEEE Trans. Inf. Forensics Secur.4
2025 Efficient Intrusion Detection for In-Vehicle Networks Using Knowledge Distillation From BERT to CNN-BiLSTM
abstract
Under the development of intelligent transportation systems, In-Vehicle Networks (IVNs) serve as a critical channel for both internal and external communications. However, the inherent complexity and diversity of data traffic present significant challenges for the detection of IVN anomalous flows. Meanwhile, the introduction of various novel technologies has introduced new security vulnerabilities to IVNs. These vulnerabilities significantly impact the security of IVNs and the accuracy of in-vehicle Intrusion Detection Systems (IDS). To address these issues, this paper proposes a lightweight and efficient anomaly detection method based on knowledge distillation technology, termed Knowledge Distillation from BERT to CNN-BiLSTM (KDBC). Specifically, the KDBC distills the deep semantic knowledge from the BERT model into a more lightweight CNN-BiLSTM architecture, significantly reducing computational overhead and storage requirements without substantially compromising detection performance. Experimental results demonstrate that the KDBC model enhances both security and versatility, achieving superior detection accuracy in identifying abnormal attacks across diverse IVN data, including automotive Ethernet and CAN networks. Moreover, the KDBC model has been validated for its effectiveness and robustness in actual in-vehicle gateway environments, achieving an accuracy of over 0.98 and an F1 score greater than 0.98.
Yue Cao 0002, Guojun Peng, Meng Li 0006
IEEE Trans. Inf. Forensics Secur.4
2025 Trust in a Decentralized World: Data Governance From Faithful, Private, Verifiable, and Traceable Data Feeds
abstract
Blockchain technology autonomously executes smart contracts that require external data to facilitate specific applications, underscoring the necessity for Authenticated Data Feeds (ADF). Existing solutions fall short in providing genuine authentication of data, lack private and verifiable computations across multiple data sources, and overlook data traceability, rendering current systems inadequate for complex applications. We present WuKong (WK), a data governance system that offers authenticated, privately verifiable, and traceable data feeds. WK enables a server to collect faithful data through an oracle committee and to prove computation correctness in zero-knowledge proofs, and empowers legal entities to trace a leakage source conditionally. We formally define and prove the security of WK in the universal composability framework. We implement three applications that seamlessly integrate with WK. Experimental results indicate that WK effectively liberates sensitive data from distributed, untrusted, and anonymous providers, making it accessible to various services and establishing trust in a decentralized world.
Meng Li 0006, Yifei Chen 0005, Yan Qiao 0001, Guixin Ye, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Inf. Forensics Secur.1
2025 Threshold Signatures With Verifiably Timed Combining and Message-Dependent Tracing
Meng Li 0006, Hanni Ding, Yifei Chen 0005, Yan Qiao 0001, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Inf. Forensics Secur.1
2025 The Deferred Byzantine Generals Problem
abstract
This paper introduces the Deferred Byzantine Generals Problem, a variant of the Byzantine Generals Problem which focuses on ensuring replicas maintain consistency over timed-release secret operations (operations that can only be known after a specified time or event). The solution to the problem is called the Deferred Byzantine Fault Tolerant (DBFT) consensus. DBFT can operate exclusive or be interleave with BFTs to handle specific tasks at designated sequence numbers or views, thereby facilitating the implementation of certain system-desirable features or supporting novel applications. It does not rely on existing timed-release primitives, but instead ensures its timed-release property through voting interactions. We presents the system model of DBFT SMR under partial synchronization using Threshold Public Key Encryption (TPKE) as the cryptographic primitives, highlighting the core issues. Then we design and implement the DBFT protocol using PBFT notations, focusing on the unique parts to facilitate expansions to other paradigms. Through experimental results, we show the impact of different executing modes and parameter choices on performance and discuss potential optimizations.
Zijian Zhang 0001, Peng Jiang 0007, Meng Li 0006, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.6
2025 Rethinking Prefix-Based Steganography for Enhanced Security and Efficiency
abstract
Generative models have demonstrated remarkable capabilities in synthesizing realistic content, creating new opportunities for secure communication through steganography---the practice of embedding covert messages within seemingly innocuous data. While prefix-based steganography, which encodes secret messages into shared probability intervals during generative sampling, has emerged as a promising paradigm for provably secure communication, its practical adoption remains constrained by inherent tradeoffs between security, capacity, and efficiency. To address these challenges, we propose two enhancements. The first enhancement optimizes quantization distortion in existing frameworks to minimize KL divergence, thereby enhancing theoretical security. The second redesigns the sampling mechanism via distribution coupling to amplify steganographic capacity, achieving this without incurring substantial computational overhead. Experimental validation on text generation task confirms our enhancements substantially outperform previous implementations, demonstrating notable capacity improvements, marked security enhancements, and efficiency gains on consumer-grade hardware. Cross-task comparisons with popular provably secure steganography further establish the proposed enhancements as achieving superior security-capacity-efficiency tradeoffs across diverse generative scenarios, advancing the practical deployment of provably secure steganography systems.
Donghui Hu, Yaofei Wang, Kejiang Chen, Yinyin Peng, Xianjin Rong, Chen Gu, Meng Li 0006
IEEE Trans. Inf. Forensics Secur.8
2025 IDCNet: Image Decomposition and Cross-View Distillation for Generalizable Deepfake Detection
abstract
Existing deepfake detectors predominantly process entire facial images as input, which limits their sensitivity to local forgery cues due to representation bias and information loss through CNN feature aggregation. To address these limitations, we propose IDCNet, a novel deepfake detection framework based on image decomposition and cross-view distillation. Our key insight is that decomposing images into complementary views enables specialized processing of global and local forgery cues, while cross-view distillation facilitates their mutual enhancement. Specifically, the framework employs a lightweight U-Net generator with a dual-objective mechanism to decompose input images into global content and local detail views, optimized through reconstruction and classification losses. A cross-view distillation strategy is then applied to enhance complementary feature learning between views. Furthermore, to integrate local artifact information into existing detection models without architectural modifications, we propose a feature alignment method. Extensive experiments across 14 forgery methods demonstrate the effectiveness of our approach, achieving up to 4.4% AUC improvement on the CDFV2 dataset compared to state-of-the-art methods. The source code is available at: https://github.com/ wangzhiyuan120/idcnet.
Yuanzhi Yao, Wenpeng Xing, Meng Li 0006
IEEE Trans. Inf. Forensics Secur.6
2025 RaSA: Robust and Adaptive Secure Aggregation for Edge-Assisted Hierarchical Federated Learning
abstract
Secure Aggregation (SA), in the Federated Learning (FL) setting, enables distributed clients to collaboratively learn a shared global model while keeping their raw data and local gradients private. However, when SA is implemented in edge-intelligence-driven FL, the open and heterogeneous environments will hinder model aggregation, slow down model convergence speed, and decrease model generalization ability. To address these issues, we present a Robust and adaptive Secure Aggregation (RaSA) protocol to guarantee robustness and privacy in the presence of non-IID data, heterogeneous system, and malicious edge servers. Specifically, we first design an adaptive weights updating strategy to address the non-IID data issue by considering the impact of both gradient similarity and gradient diversity on the model aggregation. Meanwhile, we enhance privacy protection by preventing privacy leakage from both gradients and aggregation weights. Different from previous work, we address system heterogeneity in the case of malicious attacks, and the malicious behavior from edge servers can be detected by the proposed verifiable approach. Moreover, we eliminate the influence of straggling communication links and dropouts on the model convergence by combining efficient product-coded computing with repetition-based secret sharing. Finally, we perform a theoretical analysis that proves the security of RaSA. Extensive experimental results show that RaSA can ensure model convergence without affecting the generalization ability under non-IID scenarios. Moreover, the decoding efficiency of RaSA achieves 1.33× and 6.4× faster than the state-of-the-art product-coded and one-dimensional coded computing schemes.
Mei Huang, Zhengyin Zhang, Meng Li 0006, Jingjing Wang 0003, Keke Gai
IEEE Trans. Inf. Forensics Secur.4
2025 Balancing Differential Privacy and Utility: A Relevance-Based Adaptive Private Fine-Tuning Framework for Language Models
abstract
Differential privacy (DP) has been proven to be an effective universal solution for privacy protection in language models. Nevertheless, the introduction of DP incurs significant computational overhead. One promising approach to this challenge is to integrate Parameter Efficient Fine-Tuning (PEFT) with DP, leveraging the memory-efficient characteristics of PEFT to reduce the substantial memory consumption of DP. Given that fine-tuning aims to quickly adapt pretrained models to downstream tasks, it is crucial to balance privacy protection with model utility to avoid excessive performance compromise. In this paper, we propose a Relevance-based Adaptive Private Fine-Tuning (Rap-FT) framework, the first approach designed to mitigate model utility loss caused by DP perturbations in the PEFT context, and to achieve a balance between differential privacy and model utility. Specifically, we introduce an enhanced layer-wise relevance propagation process to analyze the relevance of trainable parameters, which can be adapted to the three major categories of PEFT methods. Based on the relevance map generated, we partition the parameter space dimensionally, and develop an adaptive gradient perturbation strategy that adjusts the noise addition to mitigate the adverse impacts of perturbations. Extensive experimental evaluations are conducted to demonstrate that our Rap-FT framework can improve the utility of the fine-tuned model compared to the baseline differentially private fine-tuning methods, while maintaining a comparable level of privacy protection.
Naiyu Wang, Shen Wang 0012, Meng Li 0006, Longfei Wu, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2025 Resisting Poisoning Attacks in Federated Learning via Dual-Domain Distance and Trust Assessment
abstract
Subsequently, by executing various attacks on benchmark datasets such as MNIST, we construct Federated Learning Malicious Parameter Identification (FLMPID) dataset to enable malicious client detection. Building on this dataset, we propose FORTRESS (Federated POisoning-Resistance Defense via Dual-Domain Distance and TRust AssESSment), a framework designed to detect and mitigate malicious updates from clients. FORTRESS employs a unique encoder-decoder architecture. The encoder utilizes dual-domain distance metrics on weights and gradients to extract hidden representations, while the decoder leverages Actor-Critic (AC) reinforcement learning for trust assessment. We evaluated FORTRESS under multiple attack scenarios and demonstrated its defense effectiveness, making it a promising solution for enhancing the security of FL systems.
Zijian Zhang 0001, Yan Wu 0014, Ye Liu 0012, Meng Li 0006, Xin Li 0033, Jincheng An, Wei Liang 0005, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.6
2025 VSecNN: Verifiable and Privacy-Preserving Neural Network Inference in Cloud Service
abstract
Neural network inference in cloud service offers tangible benefits to users, from individuals and small institutions to large companies. However, two crucial concerns must be addressed. The first arises in satisfying the privacy of the model, the input data, and the inference results throughout the inference process. The second pertains to verifying that the inferences are derived from the designated neural network model. Although Secure Multi-Party Computation (MPC) and Zero-Knowledge Proof (ZKP) are typically adopted to mitigate such issues, the major challenge lies in achieving privacy preservation and verifiability simultaneously. In this study, we address both issues by proposing VSecNN, a verifiable and privacy-preserving neural network inference scheme. Specifically, we integrate MPC with the Zero-Knowledge Succinct Non-Interactive Argument of Knowledge (zk-SNARK) protocol to achieve zero-knowledge proof generation for multiple parties. Subsequently, we perform adaptive optimizations on the multi-party proof generation approach to align with the neural network, thereby achieving both privacy-preserving capabilities and verifiability. Experimental results demonstrate an improvement in the efficiency. For example, the computation time for completing our multi-party proof generation could be as low as 1.7 times that of the single-party proof generation, while the verification requires only 169ms on the MNIST dataset.
Wenti Yang, Xuan Li 0007, Meng Li 0006, Zijian Zhang 0001, Zhitao Guan, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2025 Three Birds With One Arrow: Symmetric Two-Factor Authentication Protocol Based on Puncturable Pseudorandom Function
abstract
The combination of smart cards and passwords has given birth to one of the most prevalent two-factor authentication (2FA) approaches. Numerous 2FA schemes have been proposed, nevertheless, most of them either do not possess critical security properties or are not efficient for implementation on smart cards. It is generally considered that asymmetric cryptographic primitives are indispensable to achieve security goals, which are burdensome for resource-limited devices. That is, the literature is being stuck with the security-efficiency tension. In this paper, we propose a 2FA protocol only resorting to symmetric primitives. Specifically, with the puncturable pseudorandom function, the proposed protocol hits three birds: it achieves three subtle security goals, i.e., resisting offline password guessing attacks, perfect forward secrecy and anonymity. It alleviates the long-standing security-efficiency conflict that is considered intractable in the literature. The proposed protocol is provably secure within the harshest adversary model to date. Furthermore, the evaluation results demonstrate that our protocol is the optimal choice when considering both security and efficiency.
Qi Jiang 0001, Meng Li 0006, XinDi Ma, Jianfeng Ma 0001
IEEE Trans. Inf. Forensics Secur.4
2025 Privacy-Preserving Statistical Analysis With Low Redundancy Over Task-Relevant Microdata
abstract
Privacy-preserving statistical analysis enables the data center to analyze datasets from multiple data owners, extracting valuable insights while safeguarding privacy. However, the observation of microdata involvement in various analysis tasks within the data center can indirectly lead to privacy breaches. For instance, when the data center observes microdata involved in a disease-related task, it may reveal information about the corresponding user’s disease. Existing schemes process the entire dataset for each analysis task to prevent privacy breaches, resulting in significant redundancy overhead due to the large amount of task-irrelevant data involved in processing. In this paper, we propose FDC, which can protect privacy and effectively reduce the redundancy overhead. It frees the data center from huge redundancy overhead. Specifically, we propose a co-design of local differential privacy and multiparty computation with preprocessing by the data owner. This design enables the data center to process only task-relevant and LDP noise-induced microdata instead of the entire dataset while maintaining analysis results without accuracy loss. In some scenarios where preprocessing by the data owner is unfeasible, we present a data center-assisted method to complete preprocessing within the data center. Additionally, we design and optimize a secure shuffle protocol within this method. Finally, we implement and evaluate FDC using the aggregation task as a baseline. With different proportions of task-relevant microdata, experimental results show that the runtime of FDC is 2~11x faster than existing schemes on LAN and 2~22x on WAN, and the communication overhead is up to 3~153x lower.
Jingcheng Zhao, Kaiping Xue, Yingjie Xue, Meng Li 0006, Bin Zhu 0010, Shaoxian Yuan
IEEE Trans. Inf. Forensics Secur.4
2025 Gupacker: Generalized Unpacking Framework for Android Malware
abstract
Android malware authors often use packers to evade analysis. Although many unpacking tools have been proposed, they face two significant challenges: 1) They are easily impeded by anti-analysis techniques employed by packers, preventing efficient collection of hidden Dex data. 2) They are typically designed to unpack a specific packer and cannot handle malware packed with mixed packers. Consequently, many packed malware samples evade detection. To bridge this gap, we propose Gupacker, a novel generalized unpacking framework. Gupacker offers a generic solution for first-generation holistic packer by customizing the Android system source code. It identifies the type of packer and selects an appropriate unpacking function, constructs a deeper active call chain to achieve generic unpacking of second-generation function extraction packers, and usesJNIfunction and instruction monitoring to handle third-generation virtual obfuscation packer. On this basis, we counteract a diverse array of anti-analysis techniques. We conduct extensive experiments on 5K packed Android malware samples, comparing Gupacker with 2 commercial and 4 state-of-the-art academic unpacking tools. The results demonstrate that Gupacker significantly improves the efficiency of Android malware unpacking with acceptable system overhead. We analyze real packed applications based on Gupacker and found several are second-packed by attackers, including WPS for Android, with tens of millions of users. We receive and responsibly report 13 0day vulnerabilities and also assist in the remediation of all vulnerabilities.
Qiyu Hou, Xingshu Chen, Hao Ren 0001, Meng Li 0006, Hongwei Li 0001, Changxiang Shen
IEEE Trans. Inf. Forensics Secur.5
2025 Lightweight and Dropout Toleration Aggregation for Privacy Crowdsourcing Federated Learning
abstract
Federated learning-based mobile crowdsourcing (F-MCS) leverages crowdsourcing for large-scale data perception, but it faces challenges from privacy concerns and network instability problems. Hence, privacy-protecting F-MCS schemes have been proposed to address these issues by aggregating local models on a trusted central server or a trusted third party (TTP). However, these schemes are still vulnerable to single points of failure and other malicious attacks, making them impractical. Moreover, due to the instability of the communication network, workers in the F-MCS scheme may drop out of the task, which oversees the entire model aggregation. In order to tackle the obstacles above, we design an aggregation method combined with Shamir secret sharing that comes with secure aggregation of global models without relying on a TTP. In addition, to enhance the robustness and adaptability of the scheme, we handle worker disconnection and new user joining to maintain protocol continuity and data integrity, thus tolerating dropouts and dynamic participation. We have conducted a thorough analysis of the scheme’s security, which shows that it can effectively protect user data privacy. Furthermore, our experimental results demonstrate that the proposed scheme performs well in model accuracy and is comparable to the system performance in the nondropout case.
Yunwei Dong, Meng Li 0006, Yi-Ning Liu 0002
IEEE Trans. Ind. Informatics3
2025 VBSF: Vulnerability Behavior Scanning Framework for Intelligent Autonomous Transport Systems
abstract
Vulnerability behavior scanning plays a crucial role in securing Intelligent Autonomous Transportation Systems by ensuring protected communications and maintaining data integrity. Current scanning solutions, however, demonstrate several critical shortcomings: (1) their dependence on static analysis methods with predetermined scanning locations prevents dynamic adjustment of scanning strategies; (2) their limited capacity to capture data across multiple system layers fails to address sophisticated multi-layered attack patterns; and (3) their inability to dynamically activate monitoring probes hinders timely responses to newly emerging threats. To resolve these limitations, we present$\textsf {VBSF}$, an efficient and non-intrusive vulnerability scanning framework built upon extended Berkeley Packet Filter technology. The proposed system incorporates two key innovations: a dynamic probe activation mechanism that intelligently adjusts scanning locations in real-time to optimize resource usage, and a standardized data format that enables integrated analysis of vulnerability behaviors across different system layers. Experimental evaluations confirm that$\textsf {VBSF}$effectively identifies critical vulnerability behaviors in diverse attack scenarios while introducing only 1.47% additional system overhead.
Hao Ren 0001, Lei Zhang 0101, Wenxian Wang, Meng Li 0006, Hongwei Li 0001
IEEE Trans. Intell. Transp. Syst.5
2025 Joint Double Auction-Based Channel Selection in Wireless Monitoring Networks
abstract
In wireless networks, utilizing sniffers for fault analysis, traffic traceback, and resource optimization is a crucial task. However, existing centralized algorithms cannot be applied to high-density wireless networks. Therefore, distributed optimization of channel selection to maximize the monitoring rate of sensors in Wireless Monitoring Networks (WMNs) is a challenge. This paper proposes a joint double auction-based distributed channel selection algorithm (J2A-CS) to maximize overall quality of monitoring (QoM). First, sniffers are redundantly deployed in WMNs, and an initial channel allocation strategy is formulated. Subsequently, sniffers collectively act as buyers and sellers at different stages. Finally, buyers bid asynchronously, and sellers settle synchronously to maximize the seller’s marginal revenue and update the channel selection scheme. As a distributed channel selection algorithm, J2A-CS addresses the highest overall QoM issue in WMNs, demonstrating high scalability and fault tolerance. Simulation results show that J2A-CS significantly improves QoM compared to existing distributed algorithms and outperforms centralized algorithms in high-density scenarios.
Na Xia, Lei Chen 0081, Meng Li 0006, Yutao Yin, Ke Zhang 0034
IEEE Trans. Netw. Serv. Manag.3
2025 RF-Eye: Commodity RFID Can Know What You Write and Who You Are Wherever You Are
abstract
Handwriting recognition systems have greatly enhanced AIoT applications, especially in human-computer interaction. Wireless-based methods, favored for their non-invasive nature and ease of deployment, are becoming more common. However, existing works, which typically depend on the user’s position, often perform poorly in varied writing positions. Additionally, they do not incorporate user identity information, which could lead to security vulnerabilities by failing to reject unauthorized users. To address these issues, this article introduces RF-Eye , a system that enables contactless, position-independent handwriting recognition and user identification without prior training. Its innovative approach uses each Radio-frequency identification (RFID) tag as a unique viewpoint for observing hand movements and employs pairs of tags to track directional changes. Specifically, building upon the signal transmission model and the Fresnel Zone, we propose a novel feature, DCG , to capture changes in gesture direction and confirm its consistency across different positions. Based on DCG , we develop unique patterns for common handwriting symbols that enhance our recognition algorithm. Moreover, to strengthen the system security, we link these patterns with distinct handwriting styles through the extraction of finer-grained features, thus, preventing the misuse of the system by unauthorized users. Extensive experiments demonstrate RF-Eye ’s efficacy, which achieves recognition accuracies of 93.5%, 95.2%, and 95.8% for 26 lowercase letters, 10 digits, and 10 graphic symbols, respectively, and identifying unauthorized users with 98.6% accuracy.
Yuanhao Feng, Jinyang Huang, Xiang Zhang 0011, Meng Li 0006, Fusang Zhang, Tianyue Zheng, Anran Li 0001, Mianxiong Dong, Zhi Liu 0002
ACM Trans. Sens. Networks5
2025 ABSE: Adaptive Baseline Score-Based Election for Leader-Based BFT Systems
abstract
Leader-based BFT systems face potential disruption and performance degradation from malicious leaders, with current solutions often lacking scalability or greatly increasing complexity. In this paper, we introduce ABSE, an Adaptive Baseline Score-based Election approach to mitigate the negative impact of malicious leaders on leader-based BFT systems. ABSE is fully localized and proposes to accumulate scores for processes based on their contribution to consensus advancement, aiming to bypass less reliable participants when electing leaders. We present a formal treatment of ABSE, addressing the primary design and implementation challenges, defining its generic components and rules for adherence to ensure global consistency. We also apply ABSE to two different BFT protocols, demonstrating its scalability and negligible impact on protocol complexity. Finally, by building a system prototype and conducting experiments on it, we demonstrate that ABSE-enhanced protocols can effectively minimize the disruptions caused by malicious leaders, whilst incurring minimal additional resource overhead and maintaining base performance.
Zijian Zhang 0001, Meng Li 0006, Jiamou Liu, Mauro Conti, Liehuang Zhu
IEEE Trans. Parallel Distributed Syst.5
2025 Advanced Smart Contract Vulnerability Detection via LLM-Powered Multi-Agent Systems
abstract
Blockchain’s inherent immutability, while transformative, creates critical security risks in smart contracts, where undetected vulnerabilities can result in irreversible financial losses. Current auditing tools and approaches often address specific vulnerability types, yet there is a need for a comprehensive solution that can detect a wide range of vulnerabilities with high accuracy. We propose LLM-SmartAudit, a novel framework that leverages Large Language Models (LLMs) to automate smart contract vulnerability detection and analysis. Using a multi-agent conversational architecture with a buffer-of-thought mechanism, LLM-SmartAudit maintains a dynamic record of insights generated throughout the audit process. This enables a collaborative system of specialized agents to iteratively refine their assessments, enhancing the accuracy and depth of vulnerability detection. To evaluate its effectiveness, LLM-SmartAudit was tested on three datasets: a benchmark for common vulnerabilities, a real-world project corpus, and a CVE dataset. It outperformed existing tools with 98% accuracy on common vulnerabilities and demonstrates higher accuracy in real-world scenarios. Additionally, it successfully identifies 12 out of 13 CVEs, surpassing other LLM-based methods. These results demonstrate the effectiveness of multi-agent collaboration in automated smart contract auditing, offering a scalable, adaptive, and highly efficient solution for blockchain security analysis.
Jing Sun 0002, Yuqiang Sun 0001, Ye Liu 0012, Daoyuan Wu, Zijian Zhang 0001, Xianhao Zhang, Meng Li 0006, Yang Liu 0003, Chunmiao Li, Mingchao Wan, Jin Dong 0004, Liehuang Zhu
IEEE Trans. Software Eng.8
2024 Threshold Signatures with Private Accountability via Secretly Designated Witnesses
Meng Li 0006, Hanni Ding, Qing Wang 0060, Zijian Zhang 0001, Mauro Conti
ACISP (1)1
2024 Secure, Available, Verifiable, and Efficient Range Query Processing on Outsourced Datasets
abstract
Range queries allow data users to outsource their data to a Cloud Server (CS) that responds to data users who submit a request with range conditions. However, security concerns hinder the wide-scale adoption. Existing works neglect item availability, fail to protect secure verification or sacrifice search accuracy for efficiency. In this paper, we propose Secure, Available, Verifiable, and Efficient (SAVE) range query processing, which has three distinctive features. (1) Secure availability checking against a malicious CS: we design a keyed index-based secure verification mechanism to check the availability of matched nodes, including validity and freshness. (2) Secure result verification: we design a targeted verification mechanism for result correctness and completeness while not compromising security. (3) Improved efficiency and accuracy: we design a lay-ered encoding method to improve search efficiency and accuracy. We formally stated and proved the security of SAVE in the random oracle model. We conducted extensive experiments over the Yelp and FourSquare dataset to validate the efficiency, e.g., a query over 10 thousand data items only needs 19.4 ms to get queried results and 3.5 ms for local verification.
Meng Li 0006, Zijian Zhang 0001, Mauro Conti, Mamoun Alazab
ICC1
2024 UPBEAT: Test Input Checks of Q# Quantum Libraries
abstract
High-level programming models like Q# significantly simplify the complexity of programming for quantum computing. These models are supported by a set of foundation libraries for code development. However, errors can occur in the library implementation, and one common root cause is the lack of or incomplete checks on properties like values, length, and quantum states of inputs passed to user-facing subroutines. This paper presents Upbeat, a fuzzing tool to generate random test cases for bugs related to input checking in Q# libraries. Upbeat develops an automated process to extract constraints from the API documentation and the developer implemented input-checking statements. It leverages open-source Q# code samples to synthesize test programs. It frames the test case generation as a constraint satisfaction problem for classical computing and a quantum state model for quantum computing to produce carefully generated subroutine inputs to test if the input-checking mechanism is appropriately implemented. Under 100 hours of automated test runs, Upbeat has successfully identified 16 bugs in API implementations and 4 documentation errors. Of these, 14 have been confirmed, and 12 have been fixed by the library developers.
Tianmin Hu, Guixin Ye, Zhanyong Tang, Shin Hwei Tan, Huanting Wang, Meng Li 0006, Zheng Wang 0001
ISSTA6
2024 Hidden WiFi Camera Localization via Signal Propagation Path Analysis
abstract
Hidden WiFi cameras pose significant privacy threats, necessitating effective localization methods. In this work, we introduce CamLoPA, a system designed for the detection and localization of WiFi cameras. CamLoPA achieves this in just 45 seconds of user walking. It begins by analyzing the causal relationship between WiFi traffic and user movement to identify the presence of a snooping camera. Upon detection, CamLoPA utilizes a novel azimuth location model based on WiFi signal propagation path analysis to localize the hidden camera. Comprehensive evaluations demonstrate that CamLoPA can accurately and swiftly detect and localize snooping WiFi cameras with minimal constraints.
Xiang Zhang 0011, Zehua Ma, Jinyang Huang, Huan Yan 0004, Meng Li 0006, Zhi Liu 0002, Bin Liu 0016
MobiCom5
2024 Efficient and Verifiable General Quantum Secret Sharing Based on Special Entangled State
abstract
Quantum secret sharing plays a crucial role in quantum cryptography. The two main trends in quantum secret sharing are to address the problem of scheme failure due to participant spoofing and to improve the efficiency of quantum secret sharing. This paper focuses on the quantum secret sharing scheme with general access structure due to its flexibility. We design a special entangled state by resorting to Monotone Span Program (MSP). Based on the special 2-dimensional entangled state, an efficient and verifiable general quantum secret sharing (GQSS) scheme is proposed. In the GQSS scheme, the authorized participants only provide the X-basis measurement results of particles to recover and verify the shared secret, which makes that our scheme have lower communication consumption and quantum computational complexity. The analysis shows that the proposed scheme is simpler and more practical compared with related quantum secret sharing schemes.
Tingyan Chen, Meng Li 0006, Changlu Lin
IEEE Internet Things J.3
2024 Trusted Execution Environment With Rollback Protection for Smart Contract-Based IoT Data Trading
abstract
Blockchain uses smart contract technology to automate the execution of Internet of Things (IoT) data trading and facilitate the flow and application of IoT data. The verifiability of the blockchain system requires data to be open and transparent. Directly using smart contracts for IoT data trading may expose sensitive data generated by IoT devices, thereby increasing the risk of data leakage and abuse. The trusted execution environment represented by software guard extension (SGX) provides new ideas for trusted execution of IoT data trading based on smart contracts. SGXs is a set of hardware security enhancement technologies launched by Intel, which aims to protect the execution of sensitive data and code through the hardware isolation and security encryption capabilities provided by the processor. However, we found that due to SGX’s lack of a checksum mechanism for the execution state of smart contracts, a rollback attack can lead to errors when the account state of IoT data trading is replayed. To address the above issues, we propose a trusted execution environment for IoT data trading with rollback protection. First, we design a freshness checking mechanism for the execution state of IoT data trading contracts for rollback protection. In addition, we propose a “chain-of-trust”-based authentication model to realize trust metrics and remote proofs for the proposed trusted execution environment for IoT data trading. Finally, we then provide a formal security analysis and comprehensive performance evaluation.
Zijian Zhang 0001, Meng Li 0006, Tyler Zhou, Liehuang Zhu
IEEE Internet Things J.4
2024 Decentralized Fair IoT Data Trading via Searchable Proxy Re-Encryption
abstract
The Internet of Things (IoT) is a network composed of information-gathering devices, sensors, and computing devices assembled in an intelligent manner, and the most important element in this system is data. IoT data trading plays a vital role in the area of personalized business nowadays. Individual IoT devices generate large amounts of private data, which data owners can sell to enterprises as important digital assets to make money, while enterprises collect IoT data to improve the accuracy of their services. Cloud storage services have been widely used in IoT data trading. In IoT data trading, cloud storage services have been widely used for individuals to store IoT data and for enterprises to automatically facilitate data trading. However, there are still two crucial drawbacks to be solved. From the point of security, it is difficult for data buyers to check the validity of the search result without getting the decryption key of the data owner. From the point of fairness, there is a lack of a punishment mechanism to transfer money from the cheating party to the honest party. To tackle the two challenges, we propose a searchable re-encryption scheme to maintain traditional security without sacrificing service quality. Next, we design a fair trading protocol based on smart contracts to automatically detect any cheating behaviors. Formal security analysis proves that the scheme provides expected security. Experimental results show that the scheme achieve good performance.
Zijian Zhang 0001, Tyler Zhou, Tao Niu, Meng Li 0006, Zhitao Guan, Liehuang Zhu
IEEE Internet Things J.5
2024 SVCA: Secure and Verifiable Chained Aggregation for Privacy-Preserving Federated Learning
abstract
Federated learning (FL), as a distributed machine learning paradigm, enables multiple users to train machine learning models locally using individual data and then update global model in a privacy-preserving aggregated manner. However, in FL, the users model parameters are at risk of a privacy breach. Furthermore, the aggregation server may forge aggregated results. To address these problems, in this paper, we propose SVCA, a secure and verifiable chained aggregation for privacy-preserving federated learning (PPFL) scheme. Specifically, we first group users and construct a chained aggregation structure, then employ secret sharing to prevent the entire group of users dropout, and finally propose a scheme for secure verification of the aggregation result to ensure the result correctness and the security of the verification process. The security analysis shows that SVCA not only protects the privacy of users but also ensures the training integrity. Extensive experimental results demonstrate the practical performance of SVCA without compromising classification accuracy.
Yuanjun Xia, Yi-Ning Liu 0002, Shi Dong 0001, Meng Li 0006, Cheng Guo 0001
IEEE Internet Things J.4
2024 Robust Asynchronous Federated Learning With Time-Weighted and Stale Model Aggregation
abstract
Federated Learning (FL) ensures collaborative learning among multiple clients while maintaining data locally. However, the traditional synchronous FL solutions have lower accuracy and require more communication time in scenarios where most devices drop out during learning. Therefore, we propose anAsynchronousFederatedLearning (AsyFL) scheme using time-weighted and stale model aggregation, which effectively solves the problem of poor model performance due to the heterogeneity of devices. Then, we integrate Symmetric Homomorphic Encryption (SHE) into AsyFL to proposeAsynchronousPrivacy-PreservingFederatedLearning (Asy-PPFL), which protects the privacy of clients and achieves lightweight computing. Privacy analysis shows that Asy-PPFL is indistinguishable under Known Plaintext Attack (KPA) and convergence analysis proves the effectiveness of our schemes. A large number of experiments show that AsyFL and Asy-PPFL can achieve the highest accuracy of 58.40% and 58.26% on Cifar-10 dataset when most clients (i.e., 80%) are offline or delayed, respectively.
Yinbin Miao, Xinghua Li 0001, Meng Li 0006, Hongwei Li 0001, Kim-Kwang Raymond Choo, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.4
2024 A Blockchain-Based Privacy-Preserving Scheme for Sealed-Bid Auction
abstract
The sealed-bid auction enables bidders to secretly send their bids to the auctioneer, which compares all bids and publishes the winning one on the bid-opening day. This type of auction is friendly for protecting the bid privacy, and sufficiently fair for all bidders if the auctioneer acts faithfully. Unfortunately, the auctioneer may not always be trustworthy. The auctioneer has the ability to deliberately leak any bid information to a part of bidders for raising the final winning price based on the investigation. Meanwhile, the auctioneer can appoint any bidder as the winner, as long as the bidder accepts a higher winning price than the current highest bid. Since bidders cannot obtain any bid information from others, to the best of our knowledge, it is difficult to prevent bid leakage from the auctioneer, and support bidders to verify the bid comparison results without disclosing the winning bid, simultaneously. To alleviate these problems, we first construct a homomorphic encryption(HE)-based bid comparison circuit. All bidders can directly compute a cipher of the winning bid by using this circuit; hence, the winning bid does not need to be exposed to all bidders. Then, we propose a blockchain-based sealed-bid scheme (BSS) by integrating the circuit with commitment and zero-knowledge proof. The auctioneer only obtains the commitments of bids before the bid-opening day, and he has to prove that the winner's bid is the same as the plaintext of the bidders' computed cipher. Thus, the auctioneer can neither leak the bid information nor publish a higher winning price during in the auction. Detailed performance analysis shows that the computational complexity of BSS is linear with the binary length of bids.
Zijian Zhang 0001, Meng Li 0006, Jincheng An, Yang Yu 0001, Liehuang Zhu, Jiamou Liu, Bakhadyr Khoussainov
IEEE Trans. Dependable Secur. Comput.3
2024 HCA: Hashchain-Based Consensus Acceleration Via Re-Voting
abstract
In the context of consortium blockchain, consensus protocols set permission mechanisms to maintain a relatively fixed group of participants. They can easily use distributed consistent algorithms for achieving deterministic and efficient consensus and generate incessant blocks as the ledger. However, most of the existing consensus protocols do not sufficiently leverage the chain structure of blocks, and therefore leaving room for performance improvement. In this paper, we first propose a Hashchain-based Consensus Acceleration (HCA) protocol. The HCA protocol enables a leader to generate blocks that contain a quorum of votes on the previous block, and allow voters to re-vote for accelerating the block generation to Byzantine Fault Tolerance (BFT) consensus protocols. Then, we present a rolling-based leader selection (RLS) scheme to further optimize the HCA protocol. In the RLS scheme, the leader is changed in a round-robin fashion. Finally, theoretical analysis proves the safety, liveness and responsiveness of the optimized HCA protocol, while experimental evaluation shows that the optimized HCA protocol outperforms the existing BFT consensus protocols, from the viewpoint of efficiency.
Zijian Zhang 0001, Meng Li 0006, Liehuang Zhu, Bakhadyr Khoussainov, Keke Gai
IEEE Trans. Dependable Secur. Comput.3
2024 Graph-Based Covert Transaction Detection and Protection in Blockchain
abstract
Covert communication is an method that plays an important role in secure data transmission. The technology embeds covert information into data and propagates it through covert channels. The communication quality depends on the choice of channel and data embedding techniques. Recently, blockchain has emerged to become the preferred channel to carry out covert communication for its decentralization and anonymity features. Existing covert transaction methods are constructed transaction-by-transaction, which makes them immune to text analysis-based detection methods. However, it is easy to expose their features on the transaction graph level. Unfortunately, there is yet no method to detect covert transactions by the features of transaction graph. In this paper, we propose a covert transaction detection method based on graph structure. By analyzing the statistical features of graph structure for addresses, we can infer whether they are the participants of covert transactions. Furthermore, we design a protection method of covert transactions based on graph generation networks. By adjusting the structural features between different addresses, our method enhances the security of multiple interrelated covert transactions. Experimental analysis on the Bitcoin Testnet verifies the security and the efficiency of the proposed methods.
Xin Li 0033, Jiamou Liu, Zijian Zhang 0001, Meng Li 0006, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.5
2024 KeystrokeSniffer: An Off-the-Shelf Smartphone Can Eavesdrop on Your Privacy From Anywhere
abstract
With mobile phones becoming increasingly prevalent and embedding high-quality microphones, attackers have the ability to employ these microphones to eavesdrop user’s keyboard input. However, existing work usually assumes that keystroke eavesdropping is performed against known environments and victims, which inevitably makes attack systems lack generalization. To reveal the real threat of the acoustic signal-based attack strategy, this paper proposes a keystroke eavesdropping algorithm called KeystrokeSniffer, which is robust to unknown input environments and unknown victims. In particular, to mimic the real input environment of victims, an environment estimation algorithm is first designed by extracting the timbre-related characteristics to predict the keyboard type and identifying large-size key data from collected unlabeled samples to estimate the 3D microphone coordinates. Then, by imitating unknown environments and victim data, this algorithm achieves effective keystroke eavesdropping with a small training set. By further considering the commonalities of different keystroke habits, a robust feature extraction method that reflects the keystroke location is adopted to reduce the impact of individual input habits. Extensive experimental results using various commodity smartphones indicate that the scheme is capable of predicting keyboard input accurately under different unknown scenarios. Specifically, even when both the victims and keyboards are unknown, KeystrokeSniffer can still achieve high Top-5 accuracy, reaching 79.5% in predicting keystrokes and 96.7% in predicting meaningful words, which demonstrates KeystrokeSniffer has excellent generalization capabilities. By setting different parameter values of various impact factors, e.g., noise and hand length factors, the strong robustness of the system is demonstrated, which proves that KeystrokeSniffer can violate privacy in real situations.
Jinyang Huang, Jia-Xuan Bai, Xiang Zhang 0011, Zhi Liu 0002, Yuanhao Feng, Jianchun Liu, Xiao Sun 0003, Mianxiong Dong, Meng Li 0006
IEEE Trans. Inf. Forensics Secur.9
2024 Cross-Modal Learning Based Flexible Bimodal Biometric Authentication With Template Protection
abstract
Face and voice are two of the most popular traits used for authentication tasks in daily life, as they can be easily captured using low-cost visual and audio sensors on smartphones, laptops, tablets,etc. Many bimodal biometric authentication schemes based on these two traits have been presented to provide higher accuracy than unimodal systems. However, these schemes are inflexibility due to the requirement of submitting two traits simultaneously, and they lack template protection, which may lead to biometric data leakage. We present a cross-modal learning based bimodal biometric authentication scheme, which improves the flexibility of existing schemes while ensuring the biometric template security. We integrate cross-modal learning into the feature extraction to obtain a bimodal biometric shared representation given input face images and voice clips. In order to enhance biometric template security without sacrificing authentication accuracy, a residual network and polar codes based template protection method is proposed, which can eliminate the noise in shared representations due to intra-user variations and generate protected templates. We have evaluated the efficacy of the bimodal biometric scheme using a real video dataset containing face images and voice clips. Experimental results demonstrate that our scheme can achieve flexible authentication with high accuracy no matter the probe input is a face image, a voice clip or a combination of them. Furthermore, the security analysis demonstrates that our scheme provides irreversibility, unlinkability and revocability of protected templates.
Qi Jiang 0001, Guichuan Zhao, XinDi Ma, Meng Li 0006, Youliang Tian, Xinghua Li 0001
IEEE Trans. Inf. Forensics Secur.4
2024 Decentralized Threshold Signatures With Dynamically Private Accountability
abstract
Threshold signature is a fundamental cryptographic primitive used in many practical applications. As proposed by Boneh and Komlo (CRYPTO’22), TAPS is a threshold signature that is a hybrid of privacy and accountability. It enables a combiner to combine$t$signature shares while revealing nothing about the threshold$t$or signing quorum to the public and asks a tracer to track a signature to the quorum that generates it. However, TAPS has three disadvantages: it 1) structures upon a centralized model, 2) assumes that both combiner and tracer are honest, and 3) leaves the tracing unnotarized and static. In this work, we introduce Decentralized, Threshold, dynamically Accountable and Private Signature (DeTAPS) that provides decentralized combining and tracing, enhanced privacy against untrusted combiners (tracers), and notarized and dynamic tracing. Specifically, we adopt Dynamic Threshold Public-Key Encryption (DTPKE) to dynamically notarize the tracing process, design non-interactive zero knowledge proofs to achieve public verifiability of notaries, and utilize the Key-Aggregate Searchable Encryption to bridge TAPS and DTPKE so as to awaken the notaries securely and efficiently. In addition, we formalize the definitions and security requirements for DeTAPS. Then we present a concrete construction and formally prove its security and privacy. To evaluate the performance, we build a prototype based on SGX2 and Ethereum.
Meng Li 0006, Hanni Ding, Qing Wang 0060, Weizhi Meng 0001, Liehuang Zhu, Zijian Zhang 0001, Xiaodong Lin 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Secure and Flexible Wildcard Queries
abstract
Wildcard Keyword Searchable Encryption (WKSE) enables users to search desired encrypted files with wildcard queries. Previous schemes only enabled single-character wildcard queries or restricted multi-character wildcard queries. Even if the two types of queries are supported by several schemes, they are vulnerable to correlation attacks and composition attacks. In this paper, we propose a WKSE scheme Secure Flexible Wildcard Queries (SFWQ) that supports highly flexible wildcard queries and resists correlation and composition attacks. Specifically, we adopt the interval matching method instead of traditional position matching, so that SFWQ supports a variety of queries, including single-character wildcard queries, multi-character wildcard queries, and mixed wildcard queries that the combination of both single-character and multi-character wildcards within the same query. Moreover, the number and position of wildcards within wildcard keywords are adjustable according to user preference. To resist the correlation attack and composition attack, we leverage key aggregate searchable encryption (KASE) and key exchange protocol to process characters so that even the same characters of the same keyword behave as different ciphertexts. We define a security model for WKSE which catches the correlation attack and composition attack. Our proof validates SFWQ is secure under the security model. Finally, we implement SFWQ and compare it with state-of-the-art schemes. The experimental results demonstrate that our scheme is feasible and efficient.
Qing Wang 0060, Donghui Hu, Meng Li 0006, Guomin Yang
IEEE Trans. Inf. Forensics Secur.3
2024 Anonymous, Secure, Traceable, and Efficient Decentralized Digital Forensics
abstract
Digital forensics is crucial to fight crimes around the world. Decentralized Digital Forensics (DDF) promotes it to another level by channeling the power of blockchain into digital investigations. In this work, we focus on the privacy and security of DDF. Our motivations arise from (1) how to track an anonymous-and-malicious data user who leaks only a part of the previously requested data, (2) how to achieve access control while protecting data from untrusted data centers, and (3) how to enable efficient and secure search on the blockchain. To address these issues, we propose Themis: an anonymous and secure DDF scheme with traceable anonymity, private access control, and efficient search. Our framework is boosted by establishing a Trusted Execution Environment in each authority (blockchain node) for securing the uploading, requesting, and searching. To instantiate the framework, we design a secure and robust watermarking scheme in conjunction with decentralized anonymous authentication, a private and fine-grained access control scheme, and an efficient and secure search scheme based on a dynamically updated data structure. We formally define and prove the privacy and security of Themis. We build a prototype with Ethereum and Intel SGX2 to evaluate its performance, which supports processing data from a considerable number of data providers and investigators.
Meng Li 0006, Yanzhe Shen, Guixin Ye, Jialing He, Zijian Zhang 0001, Liehuang Zhu, Mauro Conti
IEEE Trans. Knowl. Data Eng.1
2024 Decentralized and Privacy-Preserving Smart Parking With Secure Repetition and Full Verifiability
abstract
Smart Parking Services (SPSs) enable cruising drivers to find the nearest parking lot with available spots, reducing the traveling time, gas, and traffic congestion. However, drivers risk the exposure of sensitive location data during parking query to an untrusted Smart Parking Service Provider (SPSP). Our motivation arises from a repetitive query to an updated database, i.e., how a driver can be repetitively paired with a previously-matched-but-forgotten lot. Meanwhile, we aim to achieve repetitive query in an oblivious and unlinkable manner. In this work, we present Mnemosyne2 : decentralized and privacy-preserving smart parking with secure repetition and full verifiability. Specifically, we design repetitive, oblivious, and unlinkable Secure k Nearest Neighbor (SkNN) with basic verifiability (correctness and completeness) for encrypted-andupdated databases. We build a local Ethereum blockchain to perform driver-lot matching via smart contracts. To adapt to the lot count update, we resort to the immutable blockchain for advanced verifiability (truthfulness). Last, we utilize decentralized blacklistable anonymous credentials to guarantee identity privacy. Finally, we formally define and prove privacy and security. We conduct extensive experiments over a real-world dataset and compare Mnemosyne2 with existing work. The results show that a query only needs 8 seconds (175 ms) on average for service waiting (verification) among 500 drivers.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Mauro Conti, Mamoun Alazab
IEEE Trans. Mob. Comput.1
2024 Dolphin: Efficient Non-Blocking Consensus via Concurrent Block Generation
abstract
Blockchain technology has become a research hotspot in distributed systems, aiming to sustain a decentralized ledger via consensus. Traditional consensus solutions exhibit slow processing speed and response time, resulting in poor performance. To address this issue, several consensus protocols have been proposed. One such popular protocol is HotStuff, a Byzantine fault-tolerant consensus (BFT) that achieves high throughput at the cost of latency. However, its throughput suffers from a proportional decrease with the increase in latency, posing a significant challenge. In this paper, we propose a new protocol called Dolphin that builds upon HotStuff. It operates in a partially synchronous network with$n$replicas, up to$f$byzantine faults, where$n \ge 3f+1$, and achieves higher throughput in high-latency environments by leveraging non-blocking concurrent block generation. Specifically, we formalize our strategy as a generic Asynchronization Procedure Patch and prove that it does not affect the execution process of the original protocol. Theoretical analysis validates that Dolphin preserves the safety, liveness, and responsiveness properties while enhancing the throughput. The evaluation demonstrates that Dolphin typically achieves more than 10x higher throughput in Wide Area Network (WAN) environments with lower latency compared to HotStuff and its variants, and exhibits similar bandwidth utilization to DAG-based protocols such as Narwhal.
Kaiyu Feng, Zijian Zhang 0001, Meng Li 0006, Wenqian Lai, Liehuang Zhu
IEEE Trans. Mob. Comput.4
2024 ABDP: Accurate Billing on Differentially Private Data Reporting for Smart Grids
abstract
While smart grid significantly facilitates energy efficiency by using users’ power consumption data, it poses privacy leakage risk for user personal behaviors. Differential privacy (DP) has emerged as a promising solution to address this issue. However, existing approaches suffer from severe data utility degradation due to the intensive noise introduced by DP. Additionally, some of these methods are vulnerable to security attacks. To bridge this gap, in this paper, we propose ABDP (accuratebilling-enableddifferentiallyprivate), a mechanism that achieves high-strength DP while ensuring accurate aggregation and billing operations without compromising security. In particular, we propose aggregated and individual noise cancellation algorithms to counteract the negative effects of noise on data utility. Specifically, our ABDP ensures precise aggregation and accurate billing calculations for the power grid and individual users, respectively Furthermore, we present a Blockchain smart contract exploiting the pseudo random function to enforce a fair and secure data reporting process. Theoretical analysis is provided to evaluate the privacy and security guarantees of ABDP. Experimental results on real-world datasets, namely NERL-DATA and REDD, demonstrate that ABDP achieves error-free aggregation and billing calculation, offers arbitrary intensity privacy protection against non-intrusive load monitoring and filtering attacks, and outperforms existing state-of-the-art approaches.
Jialing He, Ning Wang 0003, Tao Xiang 0001, Yiqiao Wei, Zijian Zhang 0001, Meng Li 0006, Liehuang Zhu
IEEE Trans. Serv. Comput.6
2024 Time-Restricted, Verifiable, and Efficient Query Processing Over Encrypted Data on Cloud
abstract
Outsourcing data users’ location data to a cloud server (CS) enables them to obtain$k$nearest points of interest. However, data users’ privacy concerns hinder the wide-scale use. Several studies have achieved Secure k Nearest Neighbor (SkNN) query, but do not addresstime-restricted accessorresult privacy, and randomly partition data items which degrades efficiency. In this article, we proposeTime-restricted,verifiable, andefficientQueryProcessing (TiveQP). TiveQP has three distinguishing features. 1) Expand SkNN: data users can query$k$nearest locations open at a specific time. 2) Adopt a stronger threat model: we assume the CS is malicious and proposecomplementary set(i.e., transform proving “in” a set to proving “in” its complementary set) to allow data users to verify results without leaking unqueried data items’ information. 3) Improve efficiency: we design a space encoding technique and a pruning strategy to improve efficiency in query processing and result verification. We formally proved the security of TiveQP in the random oracle model. We conducted extensive evaluations over a Yelp dataset to show that TiveQP significantly improves over existing work, e.g., top-10NN query over 100 thousand data items only needs 10 ms to get queried results and 1.4 ms for verification.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti
IEEE Trans. Serv. Comput.1
2024 Phantasm: Adaptive Scalable Mining Toward Stable BlockDAG
abstract
Blockchain technology builds an immutable and append-only ledger in peer-to-peer networks, which attracts attention from various fields. However, traditional chain-based blockchain systems typically have the problem of low throughput, leading to unsatisfactory performance. Among the proposed solutions, introducing a structure of the Directed Acyclic Graph (DAG) into the blockchain reaches a high transaction throughput. Such an approach enables blocks to refer to more than one previous block, thus processing blocks in parallel with better performance. However, existing DAG-based blockchain schemes do not establish a deterministic rule for block reference priority. Adversaries can initiate a splitting attack to select block references to affect DAG topology, making the consensus unstable. In this paper, we propose a more stable consensus protocol named Phantasm, aiming to stabilize the ordering result in the consensus protocol. The referred blocks can be decided after computing a solution to the block puzzle and the difficulty of this solution affects the number of block references. We design two strategies to guide the honest nodes to select references so that they can resist the splitting attacks to stabilize the ordering. Theoretical analysis and simulation experiments show that Phantasm is more stable than the classic DAG-based blockchain consensus protocol Phantom regarding the ordering results.
Zijian Zhang 0001, Kaiyu Feng, Mingchao Wan, Meng Li 0006, Jin Dong 0004, Liehuang Zhu
IEEE Trans. Serv. Comput.5
2024 Enabling Low Sidelobe Secret Multicast Transmission for mmWave Communication: An Integrated Oblique Projection Approach
abstract
The protection of multicast transmission with optimized secrecy in millimeter-wave (mmWave) communication is still an open problem. In this paper, we propose a low sidelobe secret multicast transmission scheme in mmWave communication based on physical layer security techniques. By utilizing oblique projection, we jointly adopt the directional modulation (DM) and the artificial noise (AN) to achieve secret multicast transmission at low computational costs, without jeopardizing the low sidelobe transmitting pattern. Specifically, considering the constraint of multibeam with the channel knowledge of all target users, a primary transmitting weight vector of the base station (BS) is designed to achieve a low sidelobe transmitting pattern. Then, in each symbol period, the transmitting weight vector of the BS is updated by performing a linear transformation on the primary weight vector with a transformation matrix, which is obtained from the oblique projection matrices of all the target users’ channel vectors. In this way, without deteriorating the primary weight vector’s low sidelobe transmitting pattern, the obtained transmitting weight vector synthesizes the expected symbols at the target users and adds randomness to the eavesdroppers at undesired directions. Finally, the simulations demonstrate that our proposed scheme achieves outstanding communication performance for the target users at low computational costs, while keeping the high symbol error rates at the undesired directions.
Jianbing Ni, Meng Li 0006, Alessandro Brighente, Mauro Conti
IEEE Trans. Wirel. Commun.3
2023 Eunomia: Anonymous and Secure Vehicular Digital Forensics Based on Blockchain
abstract
Vehicular Digital Forensics (VDF) is essential to enable liability cognizance of accidents and fight against crimes. Ensuring the authority to timely gather, analyze, and trace data promotes vehicular investigations. However, adversaries crave the identity of the data provider/user, damage the evidence, violate evidence jurisdiction, and leak evidence. Therefore, protecting privacy and evidence accountability while guaranteeing access control and traceability in VDF is no easy task. To address the above-mentioned issues, we propose Eunomia: an anonymous and secure VDF scheme based on blockchain. It preserves privacy with decentralized anonymous credentials without trusted third parties. Vehicular data and evidence are uploaded by data providers to the blockchain and stored in distributed data storage. Each investigation is modeled as a finite state machine with state transitions being executed by smart contracts. Eunomia achieves fine-grained evidence access control via ciphertext-policy attribute-based encryption and Bulletproofs. A user must hold specific attributes and a temporary-and-unexpired token/warrant to retrieve data from the blockchain. Finally, a secret key is embedded into data to trace the traitor if any evidence breach happens. We use a formal analysis to demonstrate the strong privacy and security properties of Eunomia. Moreover, we build a prototype in a WiFi-based Ethereum test network to evaluate its performance.
Meng Li 0006, Yifei Chen 0005, Chhagan Lal, Mauro Conti, Mamoun Alazab, Donghui Hu
IEEE Trans. Dependable Secur. Comput.1
2023 Nereus: Anonymous and Secure Ride-Hailing Service Based on Private Smart Contracts
abstract
Security and privacy issues have become a major hindrance to the broad adoption of Ride-Hailing Services (RHSs). In this article, we introduce a new collusion attack initiated by the Ride-Hailing Service Provider (RHSP) and a driver that could easily link the real riders and their anonymous requests (credentials). Besides this attack, existing work requires heavy computations to execute user matching, and it is challenging for riders to verify matching results. Meanwhile, a malicious driver may cancel an assigned ride order due to its short distance. To address these issues, we present a RHS system named Nereus to support collusion resistance, efficiency, verifiability, and accountability. First, we integrate a smart contract into a Software Guard Extensions (SGX) enclave to establish aprivate smart contractfor collusion resistance. We use a Bloom filter to achieve efficient matching. Second, we leverage privacy-preserving range query and Merkle proofs to make matching results verifiable. Meanwhile, we adopt short group signatures to provide anonymous authentication and deposit commitments to hold the runaway driver accountable. We formally state and prove the security and privacy of Nereus. We build a prototype based on Ethereum and SGX to conduct extensive performance analysis in regard to gas costs, computational costs, and communication overhead. Experimental results show that Nereus significantly improves over existing schemes in terms of computational costs.
Meng Li 0006, Yifei Chen 0005, Chhagan Lal, Mauro Conti, Fabio Martinelli, Mamoun Alazab
IEEE Trans. Dependable Secur. Comput.1
2023 Astraea: Anonymous and Secure Auditing Based on Private Smart Contracts for Donation Systems
abstract
Many regions are in urgent need of facial masks for slowing down the spread of COVID-19. To fight the pandemic, people are contributing masks through donation systems. Most existing systems are built on a centralized architecture which is prone to the single point of failure and lack of transparency. Blockchain-based solutions neglect fundamental privacy concerns (donation privacy) and security attacks (collusion attack, stealing attack). Moreover, current auditing solutions are not designed to achieve donation privacy, thus not appropriate in our context. In this work, we design a decentralized, anonymous, and secure auditing frameworkAstraeabased on private smart contracts for donation systems. Specifically, we integrate a Distribute Smart Contract (DiSC) with an SGX Enclave to distribute donations, prove the integrity of donation number (intention) and donation sum while preserving donation privacy. With DiSC, we design a Donation Smart Contract to refund deposits and defend against the stealing attack the collusion attack from malicious collector and transponder. We formally define and prove the privacy and security of Astraea by using security reduction. We build a prototype of Astraea to conduct extensive performance analysis. Experimental results demonstrate that Astraea is practically efficient in terms of both computation and communication.
Meng Li 0006, Yifei Chen 0005, Liehuang Zhu, Zijian Zhang 0001, Jianbing Ni, Chhagan Lal, Mauro Conti
IEEE Trans. Dependable Secur. Comput.1
2023 Reversible Database Watermarking Based on Order-preserving Encryption for Data Sharing
abstract
In the era of big data, data sharing not only boosts the economy of the world but also brings about problems of privacy disclosure and copyright infringement. The collected data may contain users’ sensitive information; thus, privacy protection should be applied to the data prior to them being shared. Moreover, the shared data may be re-shared to third parties without the consent or awareness of the original data providers. Therefore, there is an urgent need for copyright tracking. There are few works satisfying the requirements of both privacy protection and copyright tracking. The main challenge is how to protect the shared data and realize copyright tracking while not undermining the utility of the data. In this article, we propose a novel solution of a reversible database watermarking scheme based on order-preserving encryption. First, we encrypt the data using order-preserving encryption and adjust an encryption parameter within an appropriate interval to generate a ciphertext with redundant space. Then, we leverage the redundant space to embed robust reversible watermarking. We adopt grouping and K-means to improve the embedding capacity and the robustness of the watermark. Formal theoretical analysis proves that the proposed scheme guarantees correctness and security. Results of extensive experiments show that OPEW has 100% data utility, and the robustness and efficiency of OPEW are better than existing works.
Donghui Hu, Qing Wang 0060, Meng Li 0006, Shuli Zheng
ACM Trans. Database Syst.5
2022 Repetitive, Oblivious, and Unlinkable SkNN Over Encrypted-and-Updated Data on Cloud
Meng Li 0006, Chhagan Lal, Mauro Conti, Mamoun Alazab
ICICS1
2022 Graph Encryption for Shortest Path Queries with k Unsorted Nodes
abstract
Shortest distance queries over large-scale graphs bring great benefits to various applications, i.e., save planning time and travelling expenses. To protect the sensitive nodes and edges in the graph, a user outsources an encrypted graph to an untrusted server without losing the query ability. However, no prior work has considered the user requirement of the shortest path with k unsorted nodes. In particular, we are concerned with how to securely find the shortest path by passing k nodes that do not have a fixed traverse order. To solve the problems, we propose Gespun (stands for Graph encryption for shortest path queries with k unordered nodes). It includes an oracle encryption scheme that is provably secure against the semi-honest server. Specifically, we compute the shortest paths and distances for all nodes locally to obtain path-distance oracles. We transform the shortest paths to a sequence of secure codes by using a pseudo-random permutation to protect the structure privacy. We encrypt the shortest distance by using additively homomorphic encryption. Second, we pack the oracles in link-list nodes and store them in an array-based dictionary after another permutation. Next, we construct a search graph to compute the shortest path while guaranteeing that the path passes the required k nodes. We formally prove that Gespun is adaptively semantically-secure in the random oracle. We implement a prototype of Gespun and evaluate its performance. Experiments results demonstrate that Gespun is efficient, e.g., a query over 6301 nodes, 20777 edges, and 5 unsorted nodes only needs 483 ms to get queried results. We believe that our research problem span new research that soon promotes a new line of graph encryption schemes.
Meng Li 0006, Zijian Zhang 0001, Chaoping Fu, Chhagan Lal, Mauro Conti
TrustCom1
2022 Practical Blockchain-Based Steganographic Communication Via Adversarial AI: A Case Study In Bitcoin
abstract
Abstract With the development of 5G, the wireless Internet of Things (IoT) has become possible; how to provide privacy protections for the communication of IoT devices in a more vulnerable wireless transmission environment is a huge challenge. Thus, steganography is introduced as a safe and effective technology. Blockchain systems have been widely used in the area of steganography. Several works attempted to embed covert data into transactions in public blockchain systems such as Bitcoin, Ethereum and Monero. However, most of them merely focus on putting covert data into certain fields in transactions based on cryptographic algorithms. In this paper, a Covert Transaction Recognition (CTR) model is proposed by the Text Convolutional Neural Networks and Back Propagation Neural Networks. When utilizing the covert data-embedded field for recognizing, our CTR model can attain 0.79 precision and 0.83 recall on average for seven covert transaction construction schemes. The precision and recall can increase by at most 43 and 47%, respectively, if other unembedded fields were additionally exploited for recognition. We further propose a Practical Covert Transaction Construction (PCTC) model. This model fixes the contents in the embedded fields of the constructed transactions, and generates the contents in other fields using Generative Adversarial Networks. Experimental results demonstrated that the precision and recall are greatly decreased when identifying the covert transactions generated by our PCTC model. The data underlying this article are available in ‘covert-transaction-model’, at https://github.com/1997mint/covert-transaction-model.
Minxian Wang, Zijian Zhang 0001, Jialing He, Feng Gao 0019, Meng Li 0006, Shubin Xu, Liehuang Zhu
Comput. J.5
2022 Proof of Continuous Work for Reliable Data Storage Over Permissionless Blockchain
abstract
Bitcoin first proposed the Nakamoto consensus that applies proof of work into the blockchain structure to build a trustless append-only ledger. The Nakamoto consensus solves the distributed consistency problem in the public network but wastes too much computing power. Instead of consuming computing resources, many improved consensus schemes address this problem by leveraging miners’ storage resources. However, these schemes fail to let miners store data constantly and usually rely on a dealer to assign data, which is hard to build a reliable decentralized storage system. In this article, we first design a variant consensus algorithm named Proof of Continuous Work (PoCW) with a storage-related incentive mechanism. Miners can accumulate mining advantage by continuously submitting proofs of storage. Then, we present a hash ring-based data allocation algorithm using the blockchain’s state. Combined with both of them, we build a reliable blockchain-based storage system without relying on any third parties. The theoretical analysis and simulation results demonstrate that the proposed system has higher reliability than those existing systems, and we also give practical suggestions about system parameters. Finally, we discuss additional benefits that our system brings.
Zijian Zhang 0001, Jialing He, Liran Ma, Liehuang Zhu, Meng Li 0006, Bakhadyr Khoussainov
IEEE Internet Things J.6
2022 Privacy-Preserving Navigation Supporting Similar Queries in Vehicular Networks
abstract
Traffic-sensitive navigation systems in vehicular networks help drivers avoid traffic jams by providing several realtime navigation routes. However, drivers still encounter privacy concerns because their sensitive locations, i.e., their start point and endpoint, are submitted to an honest-but-curious navigation service provider (NSP). Previous privacy-preserving studies exhibit serious deficiencies under similar queries: if a driver makes several similar queries, i.e., periodically makes requests for the same start point and endpoint to the NSP, these requests will eventually reveal the areas of the two points as well as the route. In this paper, we present a novel privacy-preserving navigation scheme PiSim, which supports similar queries in navigation services. Intuitively, we transform the typical navigation approach into a traffic congestion querying approach. Instead of sending two locations to the NSP and awaiting a navigation route, drivers query the traffic congestion along the navigation route. Specifically, PiSim is characterized by extending anonymous authentication, facilitating privacy-preserving multi-keyword fuzzy search, and constructing weighted proximity graphs. Our scheme protects location privacy and route privacy, and defends against multiple requesting, spurious reporting, and collusion attacks from malicious drivers. Finally, a detailed analysis confirms the privacy and security properties of PiSim. Extensive experiments are conducted to demonstrate the feasibility, performance, and privacy protection level.
Meng Li 0006, Yifei Chen 0005, Shuli Zheng, Donghui Hu, Chhagan Lal, Mauro Conti
IEEE Trans. Dependable Secur. Comput.1
2022 User-Defined Privacy-Preserving Traffic Monitoring Against n-by-1 Jamming Attack
abstract
Traffic monitoring services collect traffic reports and respond to users’ traffic queries. However, the reports and queries may reveal the user’s identity and location. Although different anonymization techniques have been applied to protect user privacy, a new security threat arises, namely, n-by-1 jamming attack, in which an anonymous contributing driver impersonates$n$drivers and uploads$n$normal reports by using$n$reporting devices. Such an attack will mislead the traffic monitoring service provider and further degrade the service quality. Existing traffic monitoring services do not support customized queries, and private information retrieval techniques cannot be applied directly in traffic monitoring. We formally define the new attack and propose a traffic monitoring scheme TraJ to defend the attack and achieve user-defined location privacy. Specifically, we bridge anonymous contributing drivers without disclosing their speed set by using private set intersection. Each RSU collects time traffic reports and structures a weighted proximity graph to filter out malicious colluding drivers. We design a user-defined privacy-preserving query method by encoding complex road network. We leverage the uploading phase from private aggregation to collect traffic conditions and allow requesting drivers to dynamically and privately query traffic conditions. We provide a formal analysis of TraJ to prove its privacy and security properties. We also construct a prototype based on a real-world dataset and Android smartphones to demonstrate its feasibility and efficiency. A formal analysis demonstrates the privacy and security properties. Extensive experiments illustrate the performance and defense efficacy.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti, Mamoun Alazab
IEEE/ACM Trans. Netw.1
2021 A blockchain-based trading system for big data
Donghui Hu, Lixuan Pan, Meng Li 0006, Shuli Zheng
Comput. Networks4
2021 LEChain: A blockchain-based lawful evidence management scheme for digital forensics
Meng Li 0006, Chhagan Lal, Mauro Conti, Donghui Hu
Future Gener. Comput. Syst.1
2021 An improved steganography without embedding based on attention GAN
Cong Yu 0014, Donghui Hu, Shuli Zheng, Wenjie Jiang 0001, Meng Li 0006, Zhong-Qiu Zhao
Peer-to-Peer Netw. Appl.5
2021 Anonymous and Verifiable Reputation System for E-Commerce Platforms Based on Blockchain
abstract
E-commerce platforms incorporate reputation systems that allow customers to rate suppliers following financial transactions. Existing reputation systems cannot defend the centralized server against arbitrarily tampering with the supplier’s reputation. Furthermore, they do not offer reputation access across platforms. Rates are faced with privacy leakages because rating activities are correlated with privacy (e.g., identity and rating). Meanwhile, raters could be malicious and initiate multiple rating attacks and abnormal rating attacks. Determining how to address these issues have both research and practical value. In this paper, we propose a blockchain-based privacy-preserving reputation system for e-commerce platforms named RepChain; our system allows cross-platform reputation access and anonymous and private ratings. Using RepChain, all e-commerce platforms collaborate and share users’ reputations by co-constructing a consortium blockchain and modeling the rating process as a finite state machine. In particular, we facilitate one-show anonymous credentials constructed from two-move blind signatures to protect customers’ identities and resist multiple rating attacks, leverage zero-knowledge range proof to verify the correctness of ratings and defend against abnormal rating attacks, design a secure sum computation protocol among nodes to update reputations, and verify ratings via batch processing and consensus hashes. Finally, we demonstrate the security and privacy of RepChain via a formal analysis and evaluate its performance based on Ethereum test network.
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Chhagan Lal, Mauro Conti, Mamoun Alazab
IEEE Trans. Netw. Serv. Manag.1
2021 Privacy-Preserving Traffic Monitoring with False Report Filtering via Fog-Assisted Vehicular Crowdsensing
abstract
Traffic monitoring system empowers cloud server and drivers to collect real-time driving information and acquire traffic conditions. However, drivers are more interested in local traffic, and sending driving reports to a faraway cloud server wastes a lot of bandwidth and incurs a long response delay. Recently, fog computing is introduced to provide location-sensitive and latency-aware local data management in vehicular crowdsensing, but it incurs new privacy concerns since drivers’ information could be disclosed. Although these messages are encrypted before transmission, malicious drivers can upload false reports to sabotage the systems, and filtering out false encrypted reports remains a challenging issue. To address the problems, we define a new security model and propose a privacy preserving traffic monitoring scheme. Specifically, we utilize short group signature to authenticate drivers in a conditionally anonymous way, adopt a range query technique to acquire driving information in a privacy-preserving way, and integrate it to the construction of a weighted proximity graph at each fog node through a WiFi challenge handshake to filter out false reports. Moreover, we use variant Bloom filters to achieve fast traffic conditions storage and retrieval. Finally, we prove security and privacy, evaluate performance with real-world cloud servers.
Meng Li 0006, Liehuang Zhu, Xiaodong Lin 0001
IEEE Trans. Serv. Comput.1
2020 One-Time, Oblivious, and Unlinkable Query Processing Over Encrypted Data on Cloud
Yifei Chen 0005, Meng Li 0006, Shuli Zheng, Donghui Hu, Chhagan Lal, Mauro Conti
ICICS2
2020 Privacy-Preserving Ride-Hailing with Verifiable Order-Linking in Vehicular Networks
abstract
Ride-hailing is a favored vehicular service model where drivers can deliver convenient rides to waiting riders via responding to a road-side unit or a ride-hailing service provider. However, previous works did not consider the order-linking function where a rider Cathy waving for a ride will be matched to a driver Bob in service with rider Alice whose destination is close to the start point of Cathy. Furthermore, a malicious matching executor could collude with an appointed driver to interfere with the matching process, which causes service unfairness and has not been addressed before. To mitigate these limitations, we first propose a privacy-preserving ride-hailing scheme OLink with the verifiable order-linking property. Specifically, we adopt road network partitioning and range query to achieve basic user matching. The user matching process supports range conditions and protects users' privacy. Next, a Proof-of-Linking protocol is designed based on the zero-knowledge succinct non-interactive argument of knowledge, zero-knowledge proof, and Bloom filters to enable the driver in service to generate three consecutive proofs for linking a current order to the next rider's order in advance; the proofs will be released such that anyone can verify the proofs and matching fairness is guaranteed. Finally, we formally prove the privacy and security of OLink, and then evaluate its performance with PySNARK to demonstrate feasibility and efficiency.
Meng Li 0006, Yifei Chen 0005, Jingcheng Zhao, Mamoun Alazab
TrustCom1
2020 Blockchain-based anomaly detection of electricity consumption in smart grids
Meng Li 0006, Keli Zhang, Jiamou Liu, Hanxiao Gong, Zijian Zhang 0001
Pattern Recognit. Lett.1
2020 ASAP: An Anonymous Smart-Parking and Payment Scheme in Vehicular Networks
abstract
Cruising for a vacant and economical parking spot causes not only time-consuming and frustrating driving experiences, but fuel waste and air pollution. Public parking spots in crowded cities are scarce and expensive. On the contrary, private parking spots usually have low utilization rates, and the spot suppliers are willing to provide their extra parking resources due to a maintenance cost by charging parking fees. Given this situation, it is imperative to call for a smart parking system that collects and provides private parking spots (e.g., around home or workplace) to ease public parking concerns. However, when the suppliers (drivers) are providing (querying for) parking spots, their privacy (e.g., location, identity) is inevitable to be disclosed and existing parking schemes cannot achieve anonymous authentication and anonymous payment simultaneously. To tackle these problems, we propose an anonymous smart-parking and payment (ASAP) scheme in vehicular networks. Specifically, we use short randomizable signature to provide anonymity and conditional privacy. We achieve quick result matching with hashmap and anonymous payment with E-cash. Security analysis and experimental results show that ASAP can protect privacy in a conditional way and has low computational costs and communication overhead.
Liehuang Zhu, Meng Li 0006, Zijian Zhang 0001, Zhan Qin
IEEE Trans. Dependable Secur. Comput.2
2020 Blockchain-Enabled Secure Energy Trading With Verifiable Fairness in Industrial Internet of Things
abstract
Energy trading in Industrial Internet of Things (IIoT), a fundamental approach to realize Industry 4.0, plays a vital role in satisfying energy demands and optimizing system efficiency. Existing research works utilize a utility company to distribute energy to energy nodes with the help of energy brokers. Afterwards, they apply blockchain to provide transparency, immutability, and auditability of peer-to-peer (P2P) energy trading. However, their schemes are constructed on a weak security model and do not consider the cheating attack initiated by energy sellers. Such an attack refers to an energy seller refusing to transfer the negotiated energy to an energy purchaser who already paid money. In this article, we propose FeneChain, a blockchain-based energy trading scheme to supervise and manage the energy trading process toward building a secure energy trading system and improving energy quality for Industry 4.0. Specifically, we leverage anonymous authentication to protect user privacy, and we design a timed-commitments-based mechanism to guarantee the verifiable fairness during energy trading. Moreover, we utilize fine-grained access control for energy trading services. We also build a consortium blockchain among energy brokers to verify and record energy trading transactions. Finally, we formally analyze the security and privacy of FeneChain and evaluate its performance (i.e., computational costs and communication overhead) by implementing a prototype via a local Ethereum test network and Raspberry Pi.
Meng Li 0006, Donghui Hu, Chhagan Lal, Mauro Conti, Zijian Zhang 0001
IEEE Trans. Ind. Informatics1
2019 New Steganalytic Features for Spatial Image Steganography Based on Non-negative Matrix Factorization
Donghui Hu, Meng Li 0006, Shuli Zheng
IWDW4
2019 CoRide: A Privacy-Preserving Collaborative-Ride Hailing Service Using Blockchain-Assisted Vehicular Fog Computing
Meng Li 0006, Liehuang Zhu, Xiaodong Lin 0001
SecureComm (2)1
2019 Find me a safe zone: A countermeasure for channel state information based attacks
Jie Zhang 0028, Zhanyong Tang, Meng Li 0006, Dingyi Fang, Xiaojiang Chen, Zheng Wang 0001
Comput. Secur.3
2019 Efficient and Privacy-Preserving Carpooling Using Blockchain-Assisted Vehicular Fog Computing
abstract
Carpooling enables passengers to share a vehicle to reduce traveling time, vehicle carbon emissions, and traffic congestion. However, the majority of passengers lean to find local drivers, but querying a remote cloud server leads to an unnecessary communication overhead and an increased response delay. Recently, fog computing is introduced to provide local data processing with low latency, but it also raises new security and privacy concerns because users' private information (e.g., identity and location) could be disclosed when these information are shared during carpooling. While they can be encrypted before transmission, it makes user matching a challenging task and malicious users can upload false locations. Moreover, carpooling records should be kept in a distributed manner to guarantee reliable data auditability. To address these problems, we propose an efficient and privacy-preserving carpooling scheme using blockchain-assisted vehicular fog computing to support conditional privacy, one-to-many matching, destination matching, and data auditability. Specifically, we authenticate users in a conditionally anonymous way. Also, we adopt private proximity test to achieve one-to-many proximity matching and extend it to efficiently establish a secret communication key between a passenger and a driver. We store all location grids into a tree and achieve get-off location matching using a range query technique. A private blockchain is built to store carpooling records. Finally, we analyze the security and privacy properties of the proposed scheme, and evaluate its performance in terms of computational costs and communication overhead.
Meng Li 0006, Liehuang Zhu, Xiaodong Lin 0001
IEEE Internet Things J.1
2019 Secure Fog-Assisted Crowdsensing With Collusion Resistance: From Data Reporting to Data Requesting
abstract
The development and ubiquity of smart mobile devices have produced the idea of crowdsensing, where people report and request data in a community via a cloud server. Recently, fog is introduced to assist the cloud server by providing location-sensitive and latency-aware local data management. However, interaction between users and server without appropriate sanitation puts serious security threats to user' privacy (e.g., data content and preference). While existing work already has a wide range of privacy-preserving schemes, they hardly consider collusion attacks (CAs) between the server and users, let alone CAs between fog nodes and users. To solve this problem, we first define four specific CAs in fog-assisted crowdsensing and propose a novel privacy-preserving data reporting and requesting (PARE) scheme with collusion resistance. PARE is constructed by leveraging one-way hash chains, marked mix-nets, and grouping-based secure searchable encryption to securely collect users' reports and respond to users' requests under CAs. Then, we consider one extreme scenario and provide a solution by introducing a role of sentry reporter while reducing computational costs and communication overhead. Thorough security and privacy analysis shows that PARE is secure and collusion resistant and we also quantitatively measure privacy with mutual information. Extensive performance evaluation results indicate that PARE is lightweight with respect to computational cost and communication overhead. To the best of our knowledge, this paper is the first one that gives four formal definitions of CAs in fog-assisted crowdsensing and aim to defend them at the same time.
Liehuang Zhu, Meng Li 0006, Zijian Zhang 0001
IEEE Internet Things J.2
2018 CrossSense: Towards Cross-Site and Large-Scale WiFi Sensing
abstract
We present CrossSense, a novel system for scaling up WiFi sensing to new environments and larger problems. To reduce the cost of sensing model training data collection, CrossSense employs machine learning to train, off-line, a roaming model that generates from one set of measurements synthetic training samples for each target environment. To scale up to a larger problem size, CrossSense adopts a mixture-of-experts approach where multiple specialized sensing models, or experts, are used to capture the mapping from diverse WiFi inputs to the desired outputs. The experts are trained offline and at runtime the appropriate expert for a given input is automatically chosen. We evaluate CrossSense by applying it to two representative WiFi sensing applications, gait identification and gesture recognition, in controlled single-link environments. We show that CrossSense boosts the accuracy of state-of-the-art WiFi sensing techniques from 20% to over 80% and 90% for gait identification and gesture recognition respectively, delivering consistently good performance - particularly when the problem size is significantly greater than that current approaches can effectively handle.
Jie Zhang 0028, Zhanyong Tang, Meng Li 0006, Dingyi Fang, Petteri Nurmi, Zheng Wang 0001
MobiCom3
2018 Accountable and Transparent TLS Certificate Management: An Alternate Public-Key Infrastructure with Verifiable Trusted Parties
abstract
Current Transport Layer Security (TLS) Public-Key Infrastructure (PKI) is a vast and complex system; it consists of processes, policies, and entities that are responsible for a secure certificate management process. Among them, Certificate Authority (CA) is the central and most trusted entity. However, recent compromises of CA result in the desire for some other secure and transparent alternative approaches. To distribute the trust and mitigate the threats and security issues of current PKI, publicly verifiable log-based approaches have been proposed. However, still, these schemes have vulnerabilities and inefficiency problems due to lack of specifying proper monitoring, data structure, and extra latency. We propose Accountable and Transparent TLS Certificate Management: an alternate Public-Key Infrastructure (PKI) with verifiable trusted parties (ATCM) that makes certificate management phases; certificate issuance, registration, revocation, and validation publicly verifiable. It also guarantees strong security by preventing man-in-middle-attack (MitM) when at least one entity is trusted out of all entities taking part in the protocol signing and verification. Accountable and Transparent TLS Certificate Management: an alternate Public-Key Infrastructure (PKI) with verifiable trusted parties (ATCM) can handle CA hierarchy and introduces an improved revocation system and revocation policy. We have compared our performance results with state-of-the-art log-based protocols. The performance results and evaluations show that it is feasible for practical use. Moreover, we have performed formal verification of our proposed protocol to verify its core security properties using Tamarin Prover.
Salabat Khan, Zijian Zhang 0001, Liehuang Zhu, Meng Li 0006, Qamas Gul Khan Safi, Xiaobing Chen
Secur. Commun. Networks4
2017 Achieving differential privacy of trajectory data publishing in participatory sensing
Meng Li 0006, Liehuang Zhu, Zijian Zhang 0001, Rixin Xu
Inf. Sci.1
2015 How to protect query and report privacy without sacrificing service quality in participatory sensing
abstract
The ubiquity of mobile devices has brought forth the concept of participatory sensing, whereby people can collect and share data from ambient environment for the benefit of themselves or community. To encourage participation of all stakeholders and guarantee system functionality, a privacy-preserving participatory sensing system should be established to hide querier's and participant's sensitive information(e.g., interest, location and content). Meanwhile, it is also imperative for server to provide an accurate and quick service(match the “need” with “supply” and retrieve the desired result from collected data set) for queriers when queries and reports are encrypted to protect privacy. In this paper, we propose Query and Report privacy-preserving protocol(QueRe) in participatory sensing system aiming to protect the query privacy and report privacy without sacrificing the service quality. Security analysis and performance simulation show our method achieves superior performance in privacy protection and service quality. To the best of our knowledge, our work is first attempt for protecting query privacy and report privacy while considering server's service quality.
Meng Li 0006, Fan Wu 0006, Guihai Chen, Liehuang Zhu, Zijian Zhang 0001
IPCCC1
2011 An energy efficient and integrity-preserving aggregation protocol in wireless sensor networks
abstract
Wireless sensor networks(WSNs) is a data-centric network where the querier is mostly concerned about the statistical aggregates (MAX/MIN, SUM, AVERAGE). A few protocols have been proposed for provably secure tree-based in-network data aggregation in WSN. However, these protocols all suffer from high communication overhead or long network delay when sending off-path values to each sensor node to independently verify that its own data was added into the final aggregation result. Since the off-path dissemination phase is the dominating factor, it is crucial to optimize this phase and save energy to increase the lifetime of network. In this paper, we propose a novel integrity preserving protocol Energy Efficient and Integrity-Preserving Aggregation Protocol (E2IPAP) for tree-based sensor network-s, aiming to provide a new approach for result-checking and reduce communication overhead. Analysis shows that, E2IPAP significantly reduces the overhead in disseminating off-path values and overall communication. E2IPAP has O(Δ log n) node congestion and is suitable for similar secure data aggregation protocols.
Liehuang Zhu, Meng Li 0006
IPCCC2