Juan Wang 0006

dblp:74/3634-6 · DBLP profile ↗
← Back
33ranked-venue papers
9as first author
26since 2021 · last 2026
0000-0001-8813-7842ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 4 first-author · 7 since 2021Artificial intelligence and machine learning · 7 · 7 since 2021Systems, architecture and hardware · 6 · 3 first-author · 5 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SLeak: Multi-Target Privacy Stealing Attack Against Split Learning
abstract
Split Learning (SL) is a distributed learning framework that has gained popularity for its privacy-preserving nature and low computational demands. However, recent studies have the potential that a server adversary to carry out inference attacks, compromising the privacy of victim clients. Nevertheless, upon re-evaluating prior studies, we found that existing methods rely on overly strong assumptions to enhance their performance, resulting in a significant decline in effectiveness under more realistic scenarios. In this work, we provide new insights into the inherent vulnerabilities of SL. Specifically, we discover that both the smashed data and the server model contain the client's representation preference, which the server adversary can exploit to build a substitute client that approximates the target client's unique feature extraction behavior. With a well-trained substitute client, the server can perfectly steal the target client's functionality, training data, and labels. Building on this observation, we introduce Split Leakage (SLeak), a new threat that targets multiple privacy stealing objectives against SL. Notably, SLeak does not depend on strong privacy priors and only requires partial same-domain auxiliary public data to conduct the attacks. Experimental results on diverse datasets and target models show that SLeak surpasses the state-of-the-art method across multiple metrics. Moreover, ablation studies further confirm its robustness and applicability under various scenarios and assumptions.
Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Mengda Yang, Yong Zhuang, Mang Ye
IEEE Trans. Pattern Anal. Mach. Intell.3
2026 Palladium: Guarding Neural Network Training With Confidential Computing
abstract
In the era of deep learning, protecting the training data and model parameters of high-performance Deep Neural Networks (DNNs) is critical. Data holders often want to use private data to train dedicated DNNs while leveraging AI accelerators hosted on remote servers, such as GPUs or TPUs. However, cloud systems are vulnerable to adversaries who may compromise both computational integrity and user data privacy. Performing verifiable and private training without losing access to untrusted accelerators remains a significant challenge. While previous works rely on Trusted Execution Environments (TEEs) to safeguard privacy during inference, they primarily address forward propagation and are not suitable for backward propagation in training. To address this limitation, this paper proposesPalladium, the first system to achieve confidentiality, integrity, and low latency for both model parameters and training data.Palladiumleverages TEE-empowered confidential computing to protect privacy and verify integrity, while securely outsourcing most linear layer computations to untrusted GPUs to optimize performance. Specifically,Palladiumpreserves the confidentiality of outsourced parameters by transforming the weights of linear operators and generating input masks through a carefully designedCloakstrategy. It then fully recovers the execution results inside the TEE using the correspondingUnCloakstrategy. To further ensure computational integrity,Palladiumincorporates a stochastic operator verification mechanism that detects breaches outside the TEE with 99% confidence. We implement a prototype ofPalladiumbased on Libtorch and Occlum and conduct a comprehensive evaluation on four network architectures and four datasets. Evaluation results show thatPalladiumprovides strong security guarantees with reasonable performance overhead, preserves high training accuracy, and protects model privacy.
Wenzhe Yi, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001
IEEE Trans. Dependable Secur. Comput.3
2026 Learning to Defend: Auto-Augmentation Search Against Model Inversion Attacks
abstract
Model Inversion Attacks (MIAs) can recover private training data by accessing model weights or outputs, posing significant threats to user privacy. Existing defenses cannot provide comprehensive protection against attackers with varying levels of knowledge and often lack evaluation against the most advanced attacks. Moreover, current defenses primarily focus on regularizing latent representations or labels. While prior work has explored input-level defenses (e.g., Random Erasing), these approaches are typically limited to simple transformations, and more complex or systematically combined input-level defenses remain underexplored. As the most common input-level perturbation technique, data augmentation applies transformations like cropping directly to input images. However, finding augmentations or their combinations that achieve a good privacy-utility trade-off is challenging, as it is impossible to evaluate every augmentation exhaustively through attacks. To address this, we design privacy and utility assessments for efficient evaluation and propose a Defense via Auto-Augmentation Search (DAAS). DAAS can automatically assess and identify candidates with strong privacy-utility trade-offs from a large augmentation pool. The final search results can then be leveraged for privacy-preserving training against MIAs. We evaluate DAAS across various models, datasets, and attacks, demonstrating superior defense performance compared to existing methods. Extensive ablation studies further demonstrate the effectiveness of DAAS.
Wenzhe Yi, Xiaoyang Xu 0001, Yong Zhuang, Juan Wang 0006, Hongxin Hu
IEEE Trans. Inf. Forensics Secur.4
2025 From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed Learning
abstract
Model Inversion Attacks (MIAs) aim to reconstruct private training data from models, leading to privacy leakage, particularly in facial recognition systems. Although many studies have enhanced the effectiveness of white-box MIAs, less attention has been paid to improving efficiency and utility under limited attacker capabilities. Existing black-box MIAs necessitate an impractical number of queries, incurring significant overhead. Therefore, we analyze the limitations of existing MIAs and introduce Surrogate Model-based Inversion with Long-tailed Enhancement (SMILE), a high-resolution oriented and query-efficient MIA for the black-box setting. We begin by analyzing the initialization of MIAs from a data distribution perspective and propose a long-tailed surrogate training method to obtain high-quality initial points. We then enhance the attack’s effectiveness by employing the gradient-free black-box optimization algorithm selected by NGOpt. Our experiments show that SMILE outperforms existing state-of-the-art black-box MIAs while requiring only about 5% of the query overhead. Our code is available at https://github.com/L1ziang/SMILE.
Juan Wang 0006, Meihui Chen, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001, Mengda Yang, Chenjun Ma
CVPR3
2025 ZION: A Practical Confidential Virtual Machine Architecture on Commodity RISC-V Processors
abstract
Trusted Execution Environments (TEEs) provide robust hardware-based isolation to mitigate data breaches and privacy risks. Confidential Virtual Machines (confidential VMs or CVMs) extend these capabilities by using VMs as their execution abstraction, offering superior compatibility over process-based TEEs like Intel SGX. The rising demand for Confidential VMs has spurred innovations from major chip manufacturers, such as AMD SEV, Intel TDX, and Arm CCA, and their integration into leading cloud platforms, including AWS, Azure, and Google Cloud. On the RISC-V platform, however, existing TEE architectures rely on process-level abstractions or custom hardware, leading to limited compatibility and scalability.This paper presents ZION, a confidential VM architecture for commodity RISC-V hardware that operates without custom extensions. ZION ensures security, flexibility, and efficiency through a short-path CVM mode and a secure vCPU mechanism for protecting and efficiently updating vCPU states, enhancing context-switching performance. It combines Physical Memory Protection (PMP) with paging for scalable memory isolation, employs a hierarchical memory structure for efficient management, and introduces a split-page-table-based mechanism for secure memory sharing with virtio devices. Evaluations show ZION achieves under 5% overhead in real-world applications, demonstrating its practicality.
Jie Wang 0006, Juan Wang 0006, Yinqian Zhang
DAC2
2025 HVGuard: Utilizing Multimodal Large Language Models for Hateful Video Detection
abstract
The rapid growth of video platforms has transformed information dissemination and led to an explosion of multimedia content. However, this widespread reach also introduces risks, as some users exploit these platforms to spread hate speech, which is often concealed through complex rhetoric, making hateful video detection a critical challenge. Existing detection methods rely heavily on unimodal analysis or simple feature fusion, struggling to capture cross-modal interactions and reason through implicit hate in sarcasm and metaphor. To address these limitations, we propose HVGuard, the first reasoning-based hateful video detection framework with multimodal large language models (MLLMs). Our approach integrates Chain-of-Thought (CoT) reasoning to enhance multimodal interaction modeling and implicit hate interpretation. Additionally, we design a Mixture-of-Experts (MoE) network for efficient multimodal fusion and final decision-making. The framework is modular and extensible, allowing flexible integration of different MLLMs and encoders. Experimental results demonstrate that HVGuard outperforms all existing advanced detection tools, achieving an improvement of 6.88% to 13.13% in accuracy and 9.21% to 34.37% in M-F1 on two public datasets covering both English and Chinese.
Yiheng Jing, Mingming Zhang 0009, Yong Zhuang, Jiacheng Guo, Juan Wang 0006, Xiaoyang Xu 0001, Wenzhe Yi, Keyan Guo, Hongxin Hu
EMNLP5
2025 BiFD: A Bidirectional Feature Discrepancy Defense against Hijacking Attack in Split Learning
abstract
Split Learning (SL) is a widely adopted distributed privacy-preserving training paradigm with minimal computational overhead for clients. However, Feature-Space Hijacking Attack (FSHA) poses a significant threat against SL, where the server manipulates the client's optimization process, compromising input privacy. Some studies propose that clients can detect potential hijacking by monitoring the gradients returned by the server. However, these gradient-based methods are vulnerable to adversarial anti-detection and lack robustness to changes in model architecture. In this paper, we propose a novel detection method named Bidirectional Feature Discrepancy Defense (BiFD), which leverages features to capture richer semantic information. We also observe that hijacked features are easier to reconstruct and harder to classify, providing a key distinction between malicious and honest servers—an aspect overlooked in previous works. Extensive results across multiple datasets and model architectures demonstrate the excellent and robust performance of BiFD.
Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Yong Zhuang, Mengda Yang
ICME3
2025 Eclipse Attacks on Monero's Peer-to-Peer Network
Ruisheng Shi, Lina Lan, Yulian Ge, Peng Liu 0005, Qin Wang 0008, Juan Wang 0006
NDSS7
2025 I know what you MEME! Understanding and Detecting Harmful Memes with Multimodal Large Language Models
Yong Zhuang, Keyan Guo, Juan Wang 0006, Yiheng Jing, Xiaoyang Xu 0001, Wenzhe Yi, Mengda Yang, Bo Zhao 0023, Hongxin Hu
NDSS3
2025 Stealing Data from Active Party in Vertical Split Learning
Xiaoyang Xu 0001, Wenzhe Yi, Yong Zhuang, Juan Wang 0006, Mengda Yang
ECML/PKDD (5)5
2024 Is Difficulty Calibration All We Need? Towards More Practical Membership Inference Attacks
abstract
The vulnerability of machine learning models to Membership Inference Attacks (MIAs) has garnered considerable attention in recent years. These attacks determine whether a data sample belongs to the model's training set or not. Recent research has focused on reference-based attacks, which leverage difficulty calibration with independently trained reference models. While empirical studies have demonstrated its effectiveness, there is a notable gap in our understanding of the circumstances under which it succeeds or fails. In this paper, we take a further step towards a deeper understanding of the role of difficulty calibration. Our observations reveal inherent limitations in calibration methods, leading to the misclassification of non-members and suboptimal performance, particularly on high-loss samples. We further identify that these errors stem from an imperfect sampling of the potential distribution and a strong dependence of membership scores on the model parameters. By shedding light on these issues, we propose RAPID: a query-efficient and computation-efficient MIA that directly Re-leverAges the original membershiP scores to mItigate the errors in Difficulty calibration. Our experimental results, spanning 9 datasets and 5 model architectures, demonstrate that RAPID outperforms previous state-of-the-art attacks (e.g., LiRA and Canary offline) across different metrics while remaining computationally efficient. Our observations and analysis challenge the current de facto paradigm of difficulty calibration in high-precision inference, encouraging greater attention to the persistent risks posed by MIAs in more practical scenarios.
Yu He 0009, Boheng Li, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xingyu Zhao 0001
CCS5
2024 CCall: Recovering Indirect Call Targets from Binaries With Cross-Domain Fine-Tuning
abstract
Reconstructing control flow graphs from stripped binaries remains a conundrum. One of the crucial challenges is recovering the targets of indirect calls. Existing solutions rely heavily on expert knowledge or have limited generalization capability. In this paper, we propose CCall, a novel solution that combines neural network models with a cross-domain fine-tuning strategy to automatically identify the targets of indirect calls. To make up for the shortcomings of existing methods and obtain sufficient code semantics from binaries, we introduce the concept of Inter-procedural Control Flow Sub graph (ICFSG) to capture the complete execution flow and path-sensitive semantics. Additionally, we pre-train a representation model for fine-grained embedding of binary code and design a composite neural network to capture the contextual relationship between indirect call sites and their targets. To improve performance when dealing with binaries exhibiting diverse semantics, we integrate domain adaptation into binary analysis and conduct a cross-domain fine-tuning strategy, which allows the model to learn the distinctive distribution and semantics of unlabeled test binaries. Evaluated on groups of binaries with over 6 million indirect call samples, CCall achieves an Fl-score of 92.54%, outperforming existing solutions. We extended our evaluations to different optimization levels, architectures, and compiles to gain deeper insights into the cross-domain capability of our solution. The evaluation demonstrates that our cross-domain fine-tuning strategy enhances the model's generalization ability and can be applied to other AI-based binary analysis tasks.
Yunru Wang, Juan Wang 0006, Mengda Yang, Fei Li 0021
COMPSAC3
2024 A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split Learning
abstract
Split Learning (SL) is a distributed learning framework renowned for its privacy-preserving features and minimal computational requirements. Previous research consistently highlights the potential privacy breaches in SL systems by server adversaries reconstructing training data. However, these studies often rely on strong assumptions or compromise system utility to enhance attack performance. This paper introduces a new semi-honest Data Reconstruction Attack on SL, named Feature-Oriented Reconstruction Attack (FORA). In contrast to prior works, FORA relies on limited prior knowledge, specifically that the server utilizes auxiliary samples from the public without knowing any client's private information. This allows FORA to conduct the attack stealthily and achieve robust performance. The key vulnerability exploited by FORA is the revelation of the model representation preference in the smashed data output by victim client. FORA constructs a substitute client through feature-level transfer learning, aiming to closely mimic the victim client's representation preference. Leveraging this substitute client, the server trains the attack model to effectively reconstruct private data. Extensive experiments showcase FORA's superior performance compared to state-of-the-art methods. Furthermore, the paper systematically evaluates the proposed method's applicability across diverse settings and advanced defense strategies.
Xiaoyang Xu 0001, Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Yong Zhuang
CVPR5
2024 rTPM: A Native Firmware-Based Trusted Platform Module for RISC-V
abstract
The Trusted Platform Module (TPM) enhances system security by offering features such as a root of trust, secure storage, and authentication mechanisms. While TPM has been widely adopted, there has been no detailed exploration of a firmware-based TPM implementation specifically designed for the RISC-V architecture. In this paper, we present the design and implementation of a firmware TPM system for RISC-V, named rTPM. rTPM leverages DRAM latency-based Physical Unclonable Functions (PUFs) and PMP (Physical Memory Protection) to achieve secure NVRAM storage. Addressing challenges such as the need for additional security hardware extensions and the requirement for a Trusted Execution Environment (TEE) in firmware-based TPMs, we develop a secure communication mechanism across different privilege levels, tailored to the RISC-V security architecture. In addition, we proposed new solutions to address rollback attacks and the absence of secure clocks. Our prototype demonstrates that, although rTPM incurs approximately 200 ms of additional overhead during startup and data read/write operations, it significantly improves message transmission efficiency. As a result, rTPM achieves a performance enhancement of nearly 2-3 times compared to TPM emulators when executing related instructions, while also providing enhanced security.
Xibin Wang, Juan Wang 0006, Yunhao Jia, Delong Jiang, Yuqi Qiu, Mohan Liu, Zhidong Shen
HPCC2
2024 Penetralium: Privacy-preserving and memory-efficient neural network inference at the edge
Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001
Future Gener. Comput. Syst.3
2024 Real-Time Collaborative Intrusion Detection System in UAV Networks Using Deep Learning
abstract
Unmanned aerial vehicles (UAVs) are being used extensively in various fields. UAVs provide various services to users, including monitoring, logistics, and sensing, because of their flexible deployment and dynamic reconfigurability. However, UAV networks have become more susceptible to malicious threats because of their multiconnectivity and openness. A great effort has been made to develop an effective intrusion detection system (IDS) based on machine-learning approaches for UAVs. Unfortunately, existing methods were unable to identify real time and zero-day attacks for UAV networks. This is due to that existing methods have still used obsolete data sets and past knowledge-based detection. Also, the shortcomings of standalone IDS render them unsuitable for defending UAV networks from potential security risks. Further, the lack of precise identification for compromised UAV nodes in UAV networks poses a critical security gap, risking the entire network’s integrity with the compromise of a single node. Therefore, in this work, we propose an autonomous collaborative IDS (UAV-CIDS) with a feedforward convolutional neural network (FFCNN), which accurately identifies zero-day with high accuracy. The proposed solution takes into account encoded Wi-Fi traffic logs of three popular UAVs types: 1) DBPower UDI; 2) parrot Bebop; and 3) DJI spark. Evaluation results indicate that our FFCNN model has produced outstanding results based on the UAVIDS data set with 98.23% accuracy compared to existing models. After the detection of attacks, their mitigation is equally significant. In addition, we also design and implement real-time incident response handling against cyber-attacks on UAV Networks. The incident response handling will assist in minimizing the effects of a security breach, remediate vulnerabilities and systematically secure the entire UAV networks.
Hassan Jalil Hadi, Yue Cao 0002, Yulin Hu, Juan Wang 0006, Shoufeng Wang
IEEE Internet Things J.5
2024 Privacy-Preserving and Secure Industrial Big Data Analytics: A Survey and the Research Framework
abstract
The development of the Industrial Internet will generate a large amount of valuable data, known as industrial big data (IBD). By mining and utilizing IBD, enterprises can improve production efficiency, reduce costs and risks, optimize management processes, and innovate services and business models. However, industrial big data comes from various institutions in all walks of life and has features such as multi-source, heterogeneity, and multi-modality. And data sharing and trading (DS&T) occur in the Industrial Internet environment without mutual trust. These characteristics pose new challenges to analytics methods and privacy and security protection technologies. Therefore, this paper aims to provide references for privacy-preserving and secure industrial big data analytics (IBDA) from three perspectives: research framework, platform architecture, and key technologies. Firstly, we review the current state of research on theories and technologies related to IBDA. Then, we reveal three challenges to secure and efficient IBDA. We take the analytics and utilization of IBD as systematic engineering, propose the research framework for privacy-preserving and secure IBDA, and point out the specific content to be studied. Further, we design the architecture of the IBDA platform with the idea of layering, including a function model, security architecture, and system architecture. Finally, detailed research proposals and potential technologies for IBD analytics and utilization are presented from three aspects: data fusion and analytics, data privacy and security protection, and blockchain.
Linbin Liu, Jun'e Li, Jianming Lv, Juan Wang 0006, Qiuyu Lu
IEEE Internet Things J.4
2024 CAT: A Consensus-Adaptive Trust Management Based on the Group Decision Making in IoVs
abstract
Securing Internet of Vehicles (IoVs) systems against common threats such as false message injection remains challenging, and one typical approach is to deploy trust management solutions. In this work, we propose a Consensus-Adaptive Trust management (CAT) based on the Group Decision Making (GDM) in IoVs. Specifically, in our approach the consensus levels are calculated to measure the difference of opinions (trust values) among vehicles. To estimate the reliability of consensus levels, the divergence between consensus levels is calculated, namely: consensus level similarity. GDM allows us to dynamically adjust the opinion of vehicles (namely: Consensus Reaching Process, CRP). Then, a credit guarantee mechanism is designed to improve the efficiency of CRP and seek out malicious vehicles quickly. To empower the adaptability of trust management for changing environments in IoVs, CAT dynamically manages opinions of vehicles, self-confidence, and their consensus thresholds according to the feedback of delivered messages. Extensive simulation results show the potential of CAT operating in high-risk scenarios, and outperforming other competing baseline methods in terms of accuracy, precision, recall, and F-score.
Yue Cao 0002, Chaklam Cheong, Debiao He, Kim-Kwang Raymond Choo, Juan Wang 0006
IEEE Trans. Inf. Forensics Secur.6
2023 GAN You See Me? Enhanced Data Reconstruction Attacks against Split Inference
abstract
Split Inference (SI) is an emerging deep learning paradigm that addresses computational constraints on edge devices and preserves data privacy through collaborative edge-cloud approaches. However, SI is vulnerable to Data Reconstruction Attacks (DRA), which aim to reconstruct users' private prediction instances. Existing attack methods suffer from various limitations. Optimization-based DRAs do not leverage public data effectively, while Learning-based DRAs depend heavily on auxiliary data quantity and distribution similarity. Consequently, these approaches yield unsatisfactory attack results and are sensitive to defense mechanisms. To overcome these challenges, we propose a GAN-based LAtent Space Search attack (GLASS) that harnesses abundant prior knowledge from public data using advanced StyleGAN technologies. Additionally, we introduce GLASS++ to enhance reconstruction stability. Our approach represents the first GAN-based DRA against SI, and extensive evaluation across different split points and adversary setups demonstrates its state-of-the-art performance. Moreover, we thoroughly examine seven defense mechanisms, highlighting our method's capability to reveal private information even in the presence of these defenses.
Mengda Yang, Juan Wang 0006, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001
NeurIPS4
2023 Enhance the trust between IoT devices, mobile apps, and the cloud based on blockchain
Juan Wang 0006, Wenzhe Yi, Mengda Yang, Jiaci Ma, Shengzhi Zhang, Shirong Hao
J. Netw. Comput. Appl.1
2023 SvTPM: SGX-Based Virtual Trusted Platform Modules for Cloud Computing
abstract
Virtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is$1700\times$faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX.
Juan Wang 0006, Jie Wang 0006, Chengyang Fan, Fei Yan 0008, Yueqiang Cheng, Yinqian Zhang, Mengda Yang, Hongxin Hu
IEEE Trans. Cloud Comput.1
2022 Measuring Data Reconstruction Defenses in Collaborative Inference Systems
abstract
The collaborative inference systems are designed to speed up the prediction processes in edge-cloud scenarios, where the local devices and the cloud system work together to run a complex deep-learning model. However, those edge-cloud collaborative inference systems are vulnerable to emerging reconstruction attacks, where malicious cloud service providers are able to recover the edge-side users’ private data. To defend against such attacks, several defense countermeasures have been recently introduced. Unfortunately, little is known about the robustness of those defense countermeasures. In this paper, we take the first step towards measuring the robustness of those state-of-the-art defenses with respect to reconstruction attacks. Specifically, we show that the latent privacy features are still retained in the obfuscated representations. Motivated by such an observation, we design a technology called Sensitive Feature Distillation (SFD) to restore sensitive information from the protected feature representations. Our experiments show that SFD can break through defense mechanisms in model partitioning scenarios, demonstrating the inadequacy of existing defense mechanisms as a privacy-preserving technique against reconstruction attacks. We hope our findings inspire further work in improving the robustness of defense mechanisms against reconstruction attacks for collaborative inference systems.
Mengda Yang, Juan Wang 0006, Hongxin Hu, Ao Ren, Xiaoyang Xu 0001, Wenzhe Yi
NeurIPS3
2022 ProcGuard: Process Injection Behaviours Detection Using Fine-grained Analysis of API Call Chain with Deep Learning
abstract
New malware increasingly adopts novel fileless techniques to evade detection from antivirus programs. Process injection is one of the most popular fileless attack techniques. This technique makes malware more stealthy by writing malicious code into memory space and reusing the name and port of the host process. It is difficult for traditional security software to detect and intercept process injections due to the stealthiness of its behavior. We propose a novel framework called ProcGuard for detecting process injection behaviors. This framework collects sensitive function call information of typical process injection. Then we perform a fine-grained analysis of process injection behavior based on the function call chain characteristics of the program, and we also use the improved RCNN network to enhance API analysis on the tampered memory segments. We combine API analysis with deep learning to determine whether a process injection attack has been executed. We collect a large number of malicious samples with process injection behavior and construct a dataset for evaluating the effectiveness of ProcGuard. The experimental results demonstrate that it achieves an accuracy of 81.58% with a lower false-positive rate compared to other systems. In addition, we also evaluate the detection time and runtime performance loss metrics of ProcGuard, both of which are improved compared to previous detection tools.
Juan Wang 0006, Chenjun Ma, Huanyu Yuan, Jie Wang 0006
TrustCom1
2022 S-Blocks: Lightweight and Trusted Virtual Security Function With SGX
abstract
Despite the advantages of scalability and flexibility, Security Function Virtualization (SFV) raises concerns about its own security. To enhance the security of SFV, a promising approach is to run critical components of off-the-shelf security software inside Software Guard Extensions (SGX) enclaves. This idea, however, is hardly practical due to the difficulty of detaching components from the monolithic security function and the unacceptable cost of executing them inside enclaves. In this article, we propose S-Blocks, an architecture to modularize virtual security functions (VSFs) and protect crucial modules with SGX in an efficient manner. S-Blocks decomposes VSFs into trusted and untrusted modules and provides dedicated APIs systematically. Only crucial VSF modules are hardened with enclaves. Furthermore, aiming at addressing state consistency and secure migration issues of security function scaling, we design a fine-grained state synchronization and migration mechanism to ensure loss-free, order-preserving, and state security for VSFs. To demonstrate the effectiveness of our approach, we prototype S-Blocks using Fast-Click on a real Skylake platform and implement three critical types of virtual security functions based on the S-Blocks architecture. Our evaluation results show that S-Blocks only imposes a manageable performance overhead, and low latency and resource consumption when protecting VSFs.
Juan Wang 0006, Shirong Hao, Hongxin Hu, Bo Zhao 0023, Hongda Li 0002, Jun Xu 0024, Peng Liu 0005
IEEE Trans. Cloud Comput.1
2022 Online Rule-Based Classifier Learning on Dynamic Unlabeled Multivariate Time Series Data
abstract
Traditional classification learning algorithms have several limitations: 1) they are time consuming for the large-scale training multivariate time-series (MTS) data, and unsuitable for the dynamically added training data; 2) as the number of the training MTS data becomes larger, they could not achieve the desired classification accuracy; 3) most of them do not consider how to make use of the unlabeled samples to enhance the classifier performance; and 4) due to the high dimension of MTS and complex relationship among variables, existing online learning algorithms are not effective to update shapelet-based association rules. Up to now, few work touched online classification learning for dynamically added unlabeled examples. To efficiently address these issues, we propose an online rule-based classifier learning framework on dynamically added unlabeled MTS data (ORCL-U). This framework integrates a confidence-based labeling strategy (CLS) and an online rule-based classifier learning approach (ORBCL). Extensive experiments on ten datasets show the effectiveness and efficiency of our proposed approach.
Xin Xin 0010, Rong Peng, Min Han 0001, Juan Wang 0006, Xiaoqun Wu
IEEE Trans. Syst. Man Cybern. Syst.5
2021 IoT-Praetor: Undesired Behaviors Detection for IoT Devices
abstract
Due to insecure design and configuration, the Internet-of-Things (IoT) devices are vulnerable to various security issues. In most attacks against IoT, e.g., Mirai, attackers control devices to perform malicious behaviors that are not expected by owners and administrators. Therefore, how to effectively detect malicious behaviors is crucial to protect the security of IoT devices. Different from powerful PCs and servers, resource-constrained IoT devices are generally used to execute the specific function and their behaviors are limited. Based on this observation, we propose IoT-Praetor, an undesired behavior security detection system for IoT devices. In IoT-Praetor, a new device usage description (DUD) model is proposed to construct an IoT device behavior specification, including communication and interaction behaviors. Furthermore, automatic behavior extraction approaches are presented. We also design a behavior rule engine to detect device behaviors in real time. To evaluate the effectiveness of IoT-Praetor, we implemented our methods on Samsung SmartThings and performed a security test. The evaluation results show that the successful detection rate of malicious interaction behavior is 94.5% on average, and the detection rate of malicious communication behavior is above 98%, and system running time delay is only in millisecond level.
Juan Wang 0006, Shirong Hao, Ru Wen, Boxian Zhang, Hongxin Hu, Rongxing Lu
IEEE Internet Things J.1
2019 Towards a reliable firewall for software-defined networks
Hongxin Hu, Wonkyu Han, Sukwha Kyung, Juan Wang 0006, Gail-Joon Ahn, Ziming Zhao 0001, Hongda Li 0002
Comput. Secur.4
2019 Detecting and Mitigating Target Link-Flooding Attacks Using SDN
abstract
DDoS attacks have caused very serious damage to enterprise networks. Recently, a new kind of DDoS attack called link-flooding attack (LFA), has surfaced and is already being used by attackers to flood and congest network critical links. LFA is very difficult to detect since adversaries often utilize large-scale legitimate low-speed flows and rolls target links to isolate target areas for launching attacks. To address such a critical security problem, we design and implement a novel LFA defense system called LFADefender that leverages some key features, such as programmability, network-wide view, and flow traceability, of an emerging network technology, Software-Defined Networking (SDN), to effectively detect and migrate LFA. In LFADefender, we propose a LFA target link selection approach and design a LFA congestion monitoring mechanism to effectively detect LFA. In addition, we present a multiple optional paths rerouting method to temporarily mitigate links congestion caused by LFA. We further propose a malicious traffic blocking approach to radically mitigate LFA. Our evaluation results show that LFADefender can accurately detect and rapidly mitigate LFA, but only imposes minimal overhead in the communication channels between network controllers and data planes.
Juan Wang 0006, Ru Wen, Jiangqi Li, Fei Yan 0008, Bo Zhao 0023, Fajiang Yu
IEEE Trans. Dependable Secur. Comput.1
2018 Enabling Security-Enhanced Attestation With Intel SGX for Remote Terminal and IoT
abstract
Along with the advent and popularity of cloud computing, Internet of Things, and bring your own device, the trust requirement for terminal devices has increased significantly. An untrusted terminal, a terminal that runs in an untrustworthy execution environment, may cause serious security issues for enterprise networks. With the release of Software Guard Extension, Intel has provided a promising way to construct trusted terminals and services. Utilizing this technology, we propose a security-enhanced attestation for remote terminals, which can achieve shielded execution for measurements and attestation programs. Furthermore, we present a policy-based measurement mechanism where sensitive data, including secret keys and policy details are concealed using the enclave-specific keys. We implement our attestation prototype on real platform with Intel Skylake processor. Evaluation results show that our attestation system can provide much stronger security guarantees, yet incurs small performance overhead.
Juan Wang 0006, Zhi Hong, Yier Jin
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2017 A Security-Enhanced vTPM 2.0 for Cloud Computing
Juan Wang 0006, Daochen Zha, Chengyang Fan, Huanguo Zhang
ICICS1
2017 CHAOS: An SDN-Based Moving Target Defense System
abstract
Moving target defense (MTD) has provided a dynamic and proactive network defense to reduce or move the attack surface that is available for exploitation. However, traditional network is difficult to realize dynamic and active security defense effectively and comprehensively. Software-defined networking (SDN) points out a brand-new path for building dynamic and proactive defense system. In this paper, we propose CHAOS, an SDN-based MTD system. Utilizing the programmability and flexibility of SDN, CHAOS obfuscates the attack surface including host mutation obfuscation, ports obfuscation, and obfuscation based on decoy servers, thereby enhancing the unpredictability of the networking environment. We propose the Chaos Tower Obfuscation (CTO) method, which uses the Chaos Tower Structure (CTS) to depict the hierarchy of all the hosts in an intranet and define expected connection and unexpected connection. Moreover, we develop fast CTO algorithms to achieve a different degree of obfuscation for the hosts in each layer. We design and implement CHAOS as an application of SDN controller. Our approach makes it very easy to realize moving target defense in networks. Our experimental results show that a network protected by CHAOS is capable of decreasing the percentage of information disclosure effectively to guarantee the normal flow of traffic.
Huanguo Zhang, Juan Wang 0006, Daochen Zha, Hongxin Hu, Fei Yan 0008, Bo Zhao 0023
Secur. Commun. Networks3
2016 A formal analysis of Trusted Platform Module 2.0 hash-based message authentication code authorization under digital rights management scenario
abstract
Abstract Trusted Platform Module (TPM) is the “root of trust” of the whole trusted computing platform. The TPM's own security assurance is very important. This paper describes the TPM 2.0 hash‐based message authentication code (HMAC) authorization scheme as a security protocol and makes a detail comparison of the TPM 2.0 authorization to the TPM 1.2 “Object‐Independent Authorization Protocol” and the “Object‐Specific Authorization Protocol.” Then the authors use the typed pi calculus to describe the TPM 2.0 HMAC authorization and its security properties under the Digital Rights Management (DRM) scenario and use ProVerify to reason that the key handle manipulation attack for TPM 1.2 does not exist any more in TPM 2.0, because the access entity unique name has been linked to the HMAC value, but the vulnerability of key blob substitution still exists in TPM 2.0. Copyright © 2015 John Wiley & Sons, Ltd.
Fajiang Yu, Huanguo Zhang, Bo Zhao 0023, Juan Wang 0006, Fei Yan 0008, Zhenlin Chen
Secur. Commun. Networks4
2014 POSTER: An E2E Trusted Cloud Infrastructure
abstract
In this paper, a framework of end to end (E2E) trusted cloud infrastructure is proposed. On one end of the cloud provider, the trusted chain is extended to VMM and VM by trusted measurement and remote attestation, which can assure the trust of VMM and VM. On another end of the cloud terminal, the trusted mechanism is used to protect the terminal security. For the trust of cloud network, trusted network connect (TNC) is leveraged to protect the security of communication between the loud provider and the cloud terminal. The E2E trusted cloud infrastructure provides an E2E trusted protection for cloud computing. In addition, it can support the Chinese cryptographic algorithm (SMx) based on TPM 2.0.
Juan Wang 0006, Bo Zhao 0023, Huanguo Zhang, Fei Yan 0008, Fajiang Yu, Hongxin Hu
CCS1