VLDB 2026 Research / reviewers in the wild / expert
Chen Wang 0011
dblp:82/4206-11
· DBLP profile ↗
68ranked-venue papers
12as first author
44since 2021 · last 2026
0000-0003-1963-4954ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 25 · 8 first-author · 6 since 2021Security and privacy · 17 · 17 since 2021Artificial intelligence and machine learning · 8 · 8 since 2021Databases, data management, data science and information retrieval · 6 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Breaking the Boundary Barrier: Robust Model Fingerprinting via Unlearnable Examples in Model-Parameter SpaceabstractDeep learning models represent valuable intellectual property due to their high development costs. To protect model ownership, existing fingerprinting techniques have been proposed to use adversarial examples to fingerprint a model's decision boundaries. However, these fingerprints are inherently fragile, as model decision boundaries are highly sensitive to common model modifications such as fine-tuning, pruning, and adversarial training. In this paper, we propose MFUE (Model Fingerprinting via Unlearnable Examples), a novel fingerprinting methodology that leverages the stable unlearnability of unlearnable examples to fingerprint arbitrary modified models in parameter space, fundamentally circumventing the inherent vulnerability of decision boundaries. To achieve robust model fingerprinting in parameter space, we are the first to identify that unlearnable examples, owing to their persistent training resistance, can serve as stable fingerprints beyond the model's decision boundaries. To endow unlearnable examples with robustness against arbitrary model modifications, we introduce adversarial training that simulates the randomness of model modifications by jointly optimizing the unlearnable examples over models at different training stages. We evaluate the performance of MFUE against six different attack types, including both model and input tampering. Through extensive experiments, we demonstrate that MFUE outperforms four existing methods in terms of robustness and uniqueness. Tianlong Xu, Zixiong Wang, Gaoyang Liu, Jian Chen 0046, Ahmed M. Abdelmoniem, Chen Wang 0011 |
KDD (1) | 6 |
| 2026 | Federated Learning for Edge Computing Enabled Artificial Intelligence of Things: A comprehensive surveyabstractAmong contemporary AI computing paradigms, Federated Learning (FL) stands out as an innovative method and has shown great potential in conjunction with edge computing. The two techniques combined serve as a building block forthe development of the Artificial Intelligence of Things (AIoT). This paper sheds light on the synergistic integration of FL with edge computing to propel AIoT’s capabilities in decentralized environments. By executing computing tasks closer to the data, FL at the edge not only alleviates latency and bandwidth limitations inherent in cloud-centric architectures, but also presents a robust solution to privacy concerns—a crucial obstacle in traditional centralized training setups. This paper delves into how FL tackles these privacy issues, providing an intricate explanation of its operational principles, applications, and the resultant benefits for AIoT systems. Through this scrutiny, we highlight FL’s potential in bolstering the efficiency and privacy of AIoT deployments while also delineating future research directions and the expected impact across various domains. This study aims to comprehensively comprehend FL for Edge Computing-enabled AIoT and foster developments in intelligent technologies and applications in an interconnected world. Qilei Li, Mingliang Gao 0001, Wenzhe Zhai, Wentai Wu, Chen Wang 0011, Ahmed M. Abdelmoniem |
Knowl. Based Syst. | 5 |
| 2026 | Stealthy Targeted Poisoning Attacks in Vertical Split Learning via Embedding Model ManipulationabstractVertical split learning (VSL) has recently emerged as a novel privacy-preserving paradigm by partitioning a model between multiple clients and a server. Despite its practical utility, recent research has revealed its vulnerability to backdoor attacks, where malicious attackers inject poisoned samples embedded with crafted triggers into the training data. In this paper, we present a stealthyTargetedPoisoningAttack within the context of VSL, termed TPA-VSL, which directly manipulates the embedding model without introducing any obvious trigger patterns. The crux of TPA-VSL is to map the embedding vector of the targeted sample to the attacker-desired class, adversely affecting the targeted sample's prediction. To achieve this, TPA-VSL features two novel components. The first component leverages the conditional generation capability of the state-of-the-art generative models — diffusion models, and uniquely guides them with an integrated multimodal encoder-decoder for informative training data generation. This approach allows us to mimic the target model and obtain the mappings of the targeted sample in the embedding space. The second component effectively poisons the embedding model by aligning the mappings of the targeted samples with those of the attacker-desired class. Experimental results demonstrate that TPA-VSL can achieve a 30% higher attack success rate on average compared to baseline attacks. Jian Chen 0046, Yufei Kang, Chen Wang 0011, Wanyu Lin |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Frequency-Domain Signatures for Proactive Defense Against Model Poisoning Attacks in Federated LearningabstractFederated Learning enables decentralized model training without exposing raw data, but remains fundamentally vulnerable to poisoning attacks from malicious clients. Existing defenses rely heavily on passive anomaly detection, honest majority assumptions, or unrealistic statistical priors, making them ineffective against adaptive and stealthy adversaries. In this paper, we propose SpecShield, a proactive defense mechanism that actively probes client models through calibrated adversarial perturbations. By leveraging the Fast Gradient Sign Method on the server side, SpecShield elicits dynamic response patterns from each client. These responses are then analyzed in the frequency domain using the Discrete Wavelet Transform. These frequency-domain features uncover distinctive response patterns between benign and malicious clients, enabling robust detection of model poisoning attacks in both non-IID environments and Byzantine majority scenarios. We further derive theoretical upper bounds on perturbation magnitudes to guarantee detection accuracy while preserving benign client performance. Through extensive experiments conducted on real-world datasets under six state-of-the-art poisoning attacks, SpecShield consistently outperforms existing defenses in both detection accuracy and model robustness. Our results demonstrate that active perturbation-induced profiling provides a new dimension for securing federated learning against sophisticated adversarial threats. Fangjie Hu, Aiqing Zhang, Meng Li 0006, Chen Wang 0011 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Unified Multimodal Vessel Trajectory Prediction With Explainable Navigation IntentionabstractVessel trajectory prediction is fundamental to intelligent maritime systems. Within this domain, short-term prediction of rapid behavioral changes in complex maritime environments has established multimodal trajectory prediction (MTP) as a promising research area. However, existing vessel MTP methods suffer from limited scenario applicability and insufficient explainability. To address these challenges, we propose a unified MTP framework incorporating explainable navigation intentions, which we classify into sustained and transient categories. Our method constructs sustained intention trees from historical trajectories and models dynamic transient intentions using a Conditional Variational Autoencoder (CVAE), while using a non-local attention mechanism to maintain global scenario consistency. Experiments on real Automatic Identification System (AIS) datasets demonstrates our method’s broad applicability across diverse scenarios, achieving significant improvements in both ADE and FDE. Furthermore, our method improves explainability by explicitly revealing the navigational intentions underlying each predicted trajectory. Rui Zhang 0066, Kezhong Liu, Chen Wang 0011, Bolong Zheng, Hongbo Jiang 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2025 | Prototype Surgery: Tailoring Neural Prototypes via Soft Labels for Efficient Machine UnlearningabstractThe rapid advancements and widespread application of deep neural networks (DNNs), coupled with their reliance on sensitive and private data, have sparked growing concerns regarding data privacy and the ''right to be forgotten''. To address these concerns, machine unlearning has been proposed to efficiently eliminate the influence of specific training data from trained DNNs. However, existing machine unlearning methods struggle with the large number of parameters in trained DNNs, which lead to slow execution and high memory consumption, making them impractical for large-scale models. In this paper, we shift our focus to the small set of weights in the final classification layer of DNNs, which are defined as as ''prototypes'' for different classes. Our key observation is that the prototype associated with the unlearned training data undergoes a significant shift, whereas prototypes of unrelated classes exhibit only minor changes when comparing the prototypes of original and retrained models. Based on this observation, we propose a novel machine unlearning approach that efficiently achieves machine unlearning by directly adjusting the prototypes of DNNs. We first introduce Naive Prototype Surgery (Naive PS), a fast and simplified method that uses a closed-form solution to approximate unlearning effect by directly adjusting the prototype associated with the unlearned data. Next, we propose Prototype Surgery (PS), which incorporates soft label information to fine-tune the prototypes of all classes, to achieve a more effective unlearning. Both methods achieve data unlearning by only modifying the prototypes in the DNNs, thus avoiding the challenges posed by the large number of model parameters. Extensive experiments on four datasets demonstrate that our methods significantly accelerate the unlearning process while achieving comparable results to five existing methods in terms of both unlearning performance and privacy guarantee. Gaoyang Liu, Xijie Wang, Zixiong Wang, Chen Wang 0011, Ahmed M. Abdelmoniem, Desheng Wang 0001 |
CCS | 4 |
| 2025 | Generating Is Believing: Membership Inference Attacks against Retrieval-Augmented GenerationabstractRetrieval-Augmented Generation (RAG) is a state-of-the-art technique that mitigates issues such as hallucinations and knowledge staleness in Large Language Models (LLMs) by retrieving relevant knowledge from an external database to assist in content generation. Existing research has demonstrated potential privacy risks associated with the LLMs of RAG. However, the privacy risks posed by the integration of an external database, which often contains sensitive data such as medical records or personal identities, have remained largely unexplored. In this paper, we aim to bridge this gap by focusing on membership privacy of RAG’s external database, with the aim of determining whether a given sample is part of the RAG’s database. Our basic idea is that if a sample is in the external database, it will exhibit a high degree of semantic similarity to the text generated by the RAG system. We present S2MIA, a Membership Inference Attack that utilizes the Semantic Similarity between a given sample and the content generated by the RAG system. With our proposed S2MIA, we demonstrate the potential to breach the membership privacy of the RAG database. Extensive experimental results demonstrate that S2MIA outperforms five existing MIAs, even when the system is protected by three representative defenses. Gaoyang Liu, Chen Wang 0011, Yang Yang 0060 |
ICASSP | 3 |
| 2025 | From Expansion to Retraction: Long-tailed Machine Unlearning via Boundary ManipulationabstractMachine unlearning aims to remove the information of specific data from a trained machine learning model while retaining its utility for the remaining data, so as to meet the requirements of privacy regulations. Existing unlearning methods often assume a balanced data distribution, but neglect the real-world, long-tailed scenarios, where the decision boundaries of tail classes are frequently distorted due to insufficient sample representation, thereby reducing the unlearning efficacy. In this paper, we propose the first Long-Tailed Machine Unlearning (LTMU) framework from a unified decision-boundary perspective. Our framework begins with a directional boundary repair scheme designed to enrich the distorted decision boundary of the tail class, and then develop a novel boundary retraction approach tailored for long-tailed unlearning, dispersing both the augmented and original features throughout the feature space. This bidirectional manipulation not only offers a unified interpretation of the relationship between long-tailed learning and unlearning, but also enables flexible control over both repair and unlearning processes through the generation of augmented features, thereby effectively accomplishing the long-tailed unlearning task. Extensive experiments across multiple datasets and neural network architectures demonstrate the effectiveness of our framework in achieving complete unlearning of tail classes in long-tailed distributions. Weizhuo Gao, Chen Wang 0011, Gaoyang Liu, Ahmed M. Abdelmoniem, Kai Peng 0001 |
KDD (2) | 3 |
| 2025 | FedSC: Game-Theoretic Design of Sustainable Contracts for Unreliable Federated Edge LearningabstractAlthough promising, federated edge learning (FEL) is being plagued by unreliable clients with low-quality parameters due to tight edge association and frequent edge aggregation. Existing efforts mainly focus on setting thresholds or identifying malicious behaviors to resist unreliable clients, which comes at the cost of losing their training samples and leads to unsustainable and collaborative inefficiencies. To tackle this issue, we propose the first sustainable contract, named FedSC, which allows for sustaining truthful contributions in more general conditions including clients’ multidimensional attributes and imperfect system monitoring. Specifically, by modeling the long-term strategic behaviors of self-interested clients as a Markov decision process, we quantify the impact of client behavior on their utilities and derive the critical conditions that make the rating-based contract sustainable, thereby promoting honest participation as the optimal choice for strategic clients. Since directly deriving the optimal design of FedSC under multiple constraints and nonlinear coupling of parameters is intractable, we characterize the impact of design parameters on objective function and analytically prove the existence of closed solution. Then, through a low-time-complexity greedy-based algorithm, the optimality of sustainable contracts under different system errors is guaranteed. Extensive experiments using both synthetic and real datasets demonstrate the effectiveness and superiority of FedSC compared to the state-of-the-art baselines. Excitingly, FedSC can reduce the number of free-riders up to 34.52% and improve the amount of contributed data and model performance up to 22.98% and 8.62%, respectively. Jianfeng Lu 0002, Wenxuan Yuan, Riheng Jia, Shuqin Cao, Chen Wang 0011, Minglu Li 0001 |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2025 | Poisoning as a Post-Protection: Mitigating Membership Privacy Leakage From Gradient and Prediction of Federated ModelsabstractFederated learning (FL) is a distributed learning paradigm that enables multiple clients to train a unified model without sharing their private data. However, recent works demonstrate that FL models are vulnerable to membership inference attacks (MIAs), which can infer whether a data sample was used to train a given FL model. Existing countermeasures either require far-reaching modifications of FL training process or enforce extra processing in prediction phase, yielding them unlikely to be applied well in practice. In this paper, we design a post-protection mechanism, dubbedP$^{2}$-Protection, which degrades the inference performance of MIAs by simultaneously poisoning the prediction and gradient of the target FL model to reduce the privacy leakage of training data while keeping the model prediction accuracy.P$^{2}$-Protectiononly involves one additional training round to embed the poisoned prediction and gradient into the target FL model, without requiring model retraining or training process modification. We evaluateP$^{2}$-Protectionand compare it with two state-of-the-art defenses against three MIAs on five realistic datasets. Experimental results show thatP$^{2}$-Protectionoutperforms the existing defenses by offering limited implement overhead and improved utility-privacy trade-off. Gaoyang Liu, Tianlong Xu, Yang Yang 0060, Ahmed M. Abdelmoniem, Chen Wang 0011, Jiangchuan Liu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | LLMGraph: Label-Free Detection Against APTs in Edge Networks via LLM and GCNabstractIn the growing trend of remote working, millions of edge networks (e.g., homes or branch offices) are increasingly threatened by Advanced Persistent Threats (APTs), because of the weakened segmentation between business and non-business devices in remote working environment. Despite the fact that numerous APT detection mechanisms have been proposed, all of them are struggling to handle thecomplex structure, themassive scaleand thediverse topologyof edge networks.Can recent machine-learning advances tackle these APT detection pain points in edge networks?The GNNs (Graph Neural Networks) seems to be suited to capture thecomplex structure, but its adjacency matrix fails to capture key network flow context. Additionally, GNNs require extensive manual labeling, which is not scalable. LLMs (Large Language Models) have the potential to provide automatic labeling for the GNNs, but they lack the supplementary security context needed for effective labeling. To address these gaps, we presentLLMGraph, which incorporates extended GCNs (Graph Convolutional Networks) and domain-specific RAG (Retrieval-Augmented Generation) pipeline to achieve label-free detection against APTs in edge networks.LLMGraph's extended GCNs model can capture network flow context and direction.LLMGraph's domain-specific RAG pipeline can supplement key security contexts, including device vulnerability and network flow, for effective labeling. Additionally,LLMGraphprovides an LLM aggregator to augment and merge thediverse topologyof the edge networks. Compared to the state-of-the-art mechanisms,LLMGraphproveseffectiveandscalable, improving the F1-score by at least 46.9%, and the training time for 1 million edge networks is within 1000 s. Tianlong Yu, Gaoyang Liu, Chen Wang 0011, Yang Yang 0060 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Unlearning Attacks for Regression LearningabstractRecently, the machine unlearning has emerged as a popular method for efficiently erasing the impact of personal data in machine learning (ML) models upon the data owner's removal request. However, few studies take into consideration the security concerns that may exist in the unlearning process. In this article, we propose the first unlearning attack dubbed unlearning attack for regression learning (UnAR) to deliberately influence the predictive behavior of the target sample against regression learning models. The central concept of UnAR revolves around misleading the regression model into erasing the information associated with the influential samples for the target sample. Observing that the influential samples for target data are generally located far away from the regression plane, we thus propose two novel methods, known as influential sample selection (ISS) and influential sample unlearning (ISU), to identify and subsequently eliminate the lineage of the influential samples. By doing so, we can substantially introduce bias into the prediction pertaining to the target sample, yielding the deliberate manipulation for the user adversely. We extensively evaluate UnAR on five public datasets, and the experimental results indicate our attacks can achieve prediction deviations over 35% by unlearning only 0.5% data as the influential samples. Jian Chen 0046, Wenlong Shi, Wanyu Lin, Chen Wang 0011, Wei Liu 0004, Hailong Sun 0001, Gaoyang Liu |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2025 | Synthetic Privacy-Preserving Trajectories With Semantic-Aware Dummies for Location-Based ServicesabstractTrajectory synthesis with a series of fake locations has been deemed as a promising obfuscation technology to preserve the individual privacy of users in Location-Based Services (LBSs). However, a number of previous approaches fail to take into consideration the geographic distance and motion direction of the real locations to synthesize trajectories. As a result, most of them always cannot represent the statistical characteristics of real trajectories in a privacy-preserving manner, and thus suffer from various attacks through data analysis. To tackle this issue, this paper presents SPSD, a novel privacy-preserving trajectory synthesis approach with a$k$-anonymous guarantee, through extracting the semantic, geographic and directional similarity of locations from the real trajectories to create plausible trajectories. SPSD first classifies all historical trajectory data into a series of sets for location identity, by introducing the visiting time and visiting duration, which can clearly represent the semantic information of locations. Then,$4k$locations and$2k$of$4k$ones have been selected from each set to act as the initial disguises of each corresponding real location, with quantitative semantic and geographic similarities, respectively. In order to find enough fake locations for each real location in less time, the candidate locations have been narrowed down to$k$in direction recovery through step-by-step screening, with the$k$-anonymous property. Experiment results built on the real-world trajectory datasets indicate that SPSD has outperformed the previous approaches in terms of semantic similarity, directional accuracy and security resistance to synthesize privacy-preserving trajectories at the tolerable time cost. Haojun Huang, Weimin Wu 0003, Chen Wang 0011, Wuwu Liu, Wang Miao, Geyong Min |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | A Continuous Verification Mechanism for Clients in Federated Unlearning to Defend the Right to be ForgottenabstractIn Federated Learning (FL), the regulatory need for the "right to be forgotten" requires efficient Federated Unlearning (FU) methods, which enable FL models to unlearn appointed training data. Associating with the emergence FU, verifying the performance of FU plays a critical role in evaluating the consistency FU methods, in case of the unexpected degradation of the FL model. Though well developed, none of the existing verification methods in FU stands for the clients who opt out of the FL process, which is a universal demand in FL. More specifically, after the clients quit the FL cooperation, they can no longer verify whether the FL model unlearns their data after the FL keeps training for several rounds. To this end, we introduce a continuous verification mechanism for FL clients, called Backdoor Attack-based Forgetting Verification (BAFV). Inspired by backdoor attack, BAFV embedded a persistent mark for the client that proposes to leave, with the intention that the client still has the right to verify of FU after leaving the FL cooperation for a relatively long period. Extensive experiments across diverse FU environments and datasets demonstrated that our method maintains the accuracy of model and provides clients with a continuous verification mechanism to defend their rights. Our code of BAFV is publicly available at: https://github.com/paper-liu/BAFV-master.git. Yang Yang 0060, Gaoyang Liu, Chen Wang 0011 |
ISPA | 7 |
| 2024 | United We Stand, Divided We Fall: Fingerprinting Deep Neural Networks via Adversarial TrajectoriesabstractIn recent years, deep neural networks (DNNs) have witnessed extensive applications, and protecting their intellectual property (IP) is thus crucial. As a non-invasive way for model IP protection, model fingerprinting has become popular. However, existing single-point based fingerprinting methods are highly sensitive to the changes in the decision boundary, and may suffer from the misjudgment of the resemblance of sparse fingerprinting, yielding high false positives of innocent models. In this paper, we propose ADV-TRA, a more robust fingerprinting scheme that utilizes adversarial trajectories to verify the ownership of DNN models. Benefited from the intrinsic progressively adversarial level, the trajectory is capable of tolerating greater degree of alteration in decision boundaries. We further design novel schemes to generate a surface trajectory that involves a series of fixed-length trajectories with dynamically adjusted step sizes. Such a design enables a more unique and reliable fingerprinting with relatively low querying costs. Experiments on three datasets against four types of removal attacks show that ADV-TRA exhibits superior performance in distinguishing between infringing and innocent models, outperforming the state-of-the-art comparisons. Tianlong Xu, Chen Wang 0011, Gaoyang Liu, Yang Yang 0060, Kai Peng 0001, Wei Liu 0004 |
NeurIPS | 2 |
| 2024 | An Improved Bounding Volume Hierarchies Method for V2V Ray Tracing Channel ModelingabstractRay tracing (RT) is an effective deterministic channel modeling method, but the computational burden for dynamic scenarios is high. To address this issue, this study categorizes objects involved in various types of motion within dynamic scenarios based on their motion characteristics, distinguishing between static and dynamic objects. Subsequently, the subinterval of the optimal split plane suitable for bounding volume hierarchies (BVH) construction is calculated, and the simplified interval BVH algorithm (SIBVH) is applied to the vehicle-to-vehicle (V2V) communication scenario. The simulation results indicate that, SIBVH based RT algorithm can trace rays much faster than traditional RT method, and improve computational efficiency significantly. The proposed algorithm can be effectively used in complex high-mobility communication scenarios. Chen Wang 0011, Songjiang Yang, Yinghua Wang, Cheng-Xiang Wang 0001, Jie Huang 0004 |
VTC Spring | 1 |
| 2024 | Manipulating Pre-Trained Encoder for Targeted Poisoning Attacks in Contrastive LearningabstractIn recent years, contrastive learning has become very powerful for representation learning using large-scale unlabeled data, by involving pre-trained encoders to fine-tune downstream classifiers. However, the latest research indicates that contrastive learning can potentially suffer from the risks of data poisoning attacks, where the attacker injects maliciously crafted poisoned samples into the unlabeled pre-training data. To step forward, in this paper, we present a more stealthy poisoning attack dubbed PA-CL to directly poison the pre-trained encoder, such that the downstream classifier’s behavior on a single target instance to the attacker-desired class can be manipulated without affecting the overall downstream classification performance. We observe that a high similarity exists between the feature representation generated by the poisoned pre-trained encoder for the target sample and samples from the attacker-desired class. This leads to the downstream classifier misclassifying the target sample with the attacker-desired class. Therefore, we formulate our attack as an optimization problem, and design two novel loss functions, namely, the target effectiveness loss to effectively poison the pre-trained encoder, and the model utility loss to maintain the downstream classification performance. Experimental results on four real-world datasets demonstrate that the attack success rate of the proposed attack is 40% higher on average than that of the three baseline attacks, and the fluctuation of the downstream classifier’s prediction accuracy is within 5%. Jian Chen 0046, Gaoyang Liu, Ahmed M. Abdelmoniem, Chen Wang 0011 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Gradient-Leaks: Enabling Black-Box Membership Inference Attacks Against Machine Learning ModelsabstractMachine Learning (ML) techniques have been applied to many real-world applications to perform a wide range of tasks. In practice, ML models are typically deployed as the black-box APIs to protect the model owner’s benefits and/or defend against various privacy attacks. In this paper, we present Gradient-Leaks as the first evidence showcasing the possibility of performing membership inference attacks (MIAs), with mere black-box access, which aim to determine whether a data record was utilized to train a given target ML model or not. The key idea of Gradient-Leaks is to construct a local ML model around the given record which locally approximates the target model’s prediction behavior. By extracting the membership information of the given record from the gradient of the substituted local model using an intentionally modified autoencoder, Gradient-Leaks can thus breach the membership privacy of the target model’s training data in an unsupervised manner, without any priori knowledge about the target model’s internals or its training data. Extensive experiments on different types of ML models with real-world datasets have shown that Gradient-Leaks can achieve a better performance compared with state-of-the-art attacks. Gaoyang Liu, Tianlong Xu, Rui Zhang 0066, Zixiong Wang, Chen Wang 0011, Ling Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | EgoMUIL: Enhancing Spatio-Temporal User Identity Linkage in Location-Based Social Networks With Ego-Mo HypergraphabstractUsers tend to own multiple accounts on different location-based social network (LBSN) platforms, and they typically engage with diverse social circles on each platform within the same locations. Consequently, linking these accounts across separate networks becomes essential, playing a critical role in information fusion. Previous works accomplishing user identity linkage (UIL) utilize individual mobility records, which are significantly affected by the issue of data scarcity. In this paper, we propose EgoMUIL, a heterogeneous graph embedding approach specifically devised for information propagation, aiming to alleviate the scarcity problem to some extent. Considering that follow relations of respective networks also hold great significance for the UIL task, we are inspired to enrich individual limited mobility records through follow relations. Our preliminary research reveals that direct common follow relations are quite insufficient. Since the followers with the same spatio-temporal mode tend to have social connections, we first mine closely-related users for each user through topology and locality similarity, generating respective cross-domain ego-networks. Subsequently, we construct a heterogeneous ego-mo hypergraph consisting of mobility and ego-networks. We propose a novel graph convolutional network (GCN)-based approach to learn user representations, which enables the aggregation of information from surrounding nodes, incorporating topological similarities, stay locality similarities, and co-occurrence frequencies. The resulting embeddings provide comprehensive representations of users and locations, capturing their characteristics and relationships across platforms, which further facilitates the UIL task. Our experimental results on real-world check-in datasets from Foursquare and Twitter demonstrate that EgoMUIL outperforms the state-of-the-art methods on the UIL task. Notably, EgoMUIL exhibits superior performance in scenarios involving limited check-in records and follow relations. Haojun Huang, Fengxiang Ding, Gaoyang Liu, Chen Wang 0011, Dapeng Oliver Wu |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Revisiting Long- and Short-Term Preference Learning for Next POI Recommendation With Hierarchical LSTMabstractPoint-of-interest (POI) recommendation has drawn much attention with the widespread popularity of location-based social networks (LBSNs). Previous works define long- and short-term trajectories via long short-term memory (LSTM) to capture user's stable and current preference, and incorporate context factors to improve recommendation effectiveness. However, these factors have different impacts on POI recommendation, and meanwhile, they are mutually influenced. Existing studies either model all the factors separately, or feed them into the same LSTM model, which are less meticulous for modeling the LBSNs trajectories. To address such issues, we revisit the long- and short-term preference learning for next POI recommendation by presenting a novel framework that can model both POI level and semantic level check-in trajectories. We develop a hierarchical LSTM to learn the two-level representations and consider the interplay of the two-level features by adding factors to the gates of LSTMs for each trajectory. We further construct a semantic filter to improve the recommendation efficacy. Experimental results using two real-world check-in datasets indicate that the proposed framework outperforms four state-of-the-art baselines regarding two commonly used metrics. Chen Wang 0011, Yang Yang 0060, Kai Peng 0001, Hongbo Jiang 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | FedUP: Bridging Fairness and Efficiency in Cross-Silo Federated LearningabstractAlthough federated learning (FL) enables collaborative training across multiple data silos in a privacy-protected manner, naively minimizing the aggregated loss to facilitate an efficient federation may compromise its fairness. Many efforts have been devoted to maintaining similar average accuracy across clients by reweighing the loss function while clients’ potential contributions are largely ignored. This, however, is often detrimental since treating all clients equally will harm the interests of those clients with more contribution. To tackle this issue, we introduce utopian fairness to expound the relationship between individual earning and collaborative productivity, and proposeFederated-UtoPia (FedUP), a novel FL framework that balances both efficient collaboration and fair aggregation. For the distributed collaboration, we model the training process among strategic clients as a supermodular game, which facilitates a rational incentive design through the optimal reward. As for the model aggregation, we design a weight attention mechanism to compute the fair aggregation weights by minimizing the performance bias among heterogeneous clients. Particularly, we utilize the alternating optimization theory to bridge the gap between collaboration efficiency and utopian fairness, and theoretically prove that FedUP has fair model performance with fast-rate training convergence. Extensive experiments using both synthetic and real datasets demonstrate the superiority of FedUP. Jianfeng Lu 0002, Xiong Wang 0006, Chen Wang 0011, Riheng Jia, Minglu Li 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | Multi-User Semantic Communication on Hybrid NOMAabstractIn traditional non-orthogonal multiple access (NOMA) systems, the secondary user often encounters decoding challenges caused by a lower signal-to-noise ratio (SNR) as it is assigned less power to prevent the primary user from decoding errors. One way to address this issue is by employing semantic communication, which is known for its robustness in low SNR conditions. In this paper, multi-user semantic communication is investigated in a traditional-semantic hybrid NOMA (TSH-NOMA) system, enabling simultaneous transmissions from both the bit user and the semantic user at the same frequency. However, the compatibility between continuous semantic signals and discrete bit signals remains an open problem. Quantization of semantic features has been attempted to address this problem, but it often results in noticeable performance degradation. To tackle this issue, a novel digital semantic constellation design that allows the encoder to generate a semantic constellation similar to typical digital modulation is proposed. This enables the semantic user’s signal to be readily transmitted over the digital channel without affecting the traditional bit user. Simulation results demonstrate that the proposed method allows for the transmission of the semantic user’s signal on the digital channel with negligible performance degradation. Furthermore, the secondary user in the proposed TSH-NOMA system exhibits considerable performance improvement over its counterpart in traditional NOMA, particularly at low-to-medium SNR, without compromising the performance of the primary user. Zian Meng, Likun Huang, Qiang Li 0009, Wensheng Zhang 0004, Bing Tang, Chen Wang 0011, Xiaohu Ge |
APCC | 6 |
| 2023 | Boundary Unlearning: Rapid Forgetting of Deep Networks via Shifting the Decision BoundaryabstractThe practical needs of the “right to be forgotten” and poisoned data removal call for efficient machine unlearning techniques, which enable machine learning models to unlearn, or to forget a fraction of training data and its lineage. Recent studies on machine unlearning for deep neural networks (DNNs) attempt to destroy the influence of the forgetting data by scrubbing the model parameters. However, it is prohibitively expensive due to the large dimension of the parameter space. In this paper, we refocus our attention from the parameter space to the decision space of the DNN model, and propose Boundary Unlearning, a rapid yet effective way to unlearn an entire class from a trained DNN model. The key idea is to shift the decision boundary of the original DNN model to imitate the decision behavior of the model retrained from scratch. We develop two novel boundary shift methods, namely Boundary Shrink and Boundary Expanding, both of which can rapidly achieve the utility and privacy guarantees. We extensively evaluate Boundary Unlearning on CIFAR-10 and Vggface2 datasets, and the results show that Boundary Unlearning can effectively forget the forgetting class on image classification and face recognition tasks, with an expected speed-up of 17x and 19x, respectively, compared with retraining from the scratch. Weizhuo Gao, Gaoyang Liu, Kai Peng 0001, Chen Wang 0011 |
CVPR | 5 |
| 2023 | Secure Energy-Efficient RIS-Assisted MISO Networks with Artificial Noise JammingabstractSecurity and energy efficiency are two critical design metrics in the future wireless communication networks. In this paper, a Reconfigurable Intelligent Surface (RIS) assisted multiple-input single-output (MISO) downlink network is investigated. In order to counteract the multiple randomly distributed eavesdroppers, an artificial noise (AN) jamming scheme is proposed. For achieving a desirable performance tradeoff between security and energy efficiency, a new metric of secrecy energy efficiency (SEE) is proposed. In order to maximize the SEE, an optimization problem is then formulated, subject to the maximum transmit power limit and minimum required data rate. For tackling the challenging non-convex fractional order problem with multiple mutually coupled variables, an efficient alternating optimization algorithm based on Dinkelbach and semi-definite programming (SDP) relaxation is proposed. This corresponds to a joint design of the transmit pre-coding matrix, the covariance matrix of AN, and the phase shifts of RIS. Simulation results demonstrate that an inherent trade-off exists between the secrecy rate and SEE, and significant performance gains in terms of SEE are achieved by the proposed scheme as compared to existing schemes. Furthermore, the introduction of AN into the transmit beamforming plays a crucial role in enhancing the SEE, especially as the number of eavesdroppers increases. Junyu Ma, Qiang Li 0009, Ashish Pandharipande, Wensheng Zhang 0004, Chen Wang 0011, Xiaohu Ge |
GLOBECOM | 5 |
| 2023 | Class-Targeted Poisoning Attacks against DNNsabstractIn recent years, the emergence of targeted cleanlabel poisoning attacks, which maliciously influence the training data without controlling over the labeling process to manipulate the behavior of the predictive model, is shown to be crucial threats to compromise deep learning systems. Prior targeted clean-label poisoning attacks have been demonstrated to target only one sample at a time, which is not always applicable in restricted real-world situations. In this paper, we explore targeted clean-label poisoning attacks on a per-class basis, which refers to misclassify samples from a victim class to the desired class while maintaining the classification accuracy of samples on other classes in multi-class classification tasks. To achieve this, we present the first class-targeted clean-label poisoning attack, called CTCL, which firsts craft clean label poisons along with multiple directions in the target feature space and enhance the attacking capability of poisons by reducing their the feature information of the target class. We illustrate the effectiveness of the proposed CTCL on various deep neural network models. The experiment results demonstrate that our attack is effective, with the attacking success rate over 80% compared to the other two baseline attacks on average, while the detection accuracy of state-of-the-art defenses is lower than 65% illustrating that CTCL can escape the detection of existing defenses readily. Jian Chen 0046, Qiang Li 0009, Wensheng Zhang 0004, Chen Wang 0011 |
TrustCom | 6 |
| 2023 | Membership Inference Attacks Against Machine Learning Models via Prediction SensitivityabstractMachine learning (ML) has achieved huge success in recent years, but is also vulnerable to various attacks. In this article, we concentrate on membership inference attacks and propose Aster, which merely requires the target model's black-box API and a data sample to determine whether this sample was used to train the given ML model or not. The key idea of Aster is that the training data of a fully trained ML model usually has lower prediction sensitivities compared with that of the non-training data (i.e., testing data). Less sensitivity means that when perturbing a training sample's feature value in the corresponding feature space, the prediction of the perturbed sample obtained from the target model tends to be consistent with the original prediction. In this article, we quantify the prediction sensitivity with the Jacobian matrix which could reflect the relationship between each feature's perturbation and the corresponding prediction's change. Then we regard the samples with a lower as training data. Aster can breach the membership privacy of the target model's training data with no prior knowledge about the target model or its training data. The experiment results on four datasets show that our method outperforms three state-of-the-art inference attacks. Yi Wang 0150, Gaoyang Liu, Kai Peng 0001, Chen Wang 0011 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | TEAR: Exploring Temporal Evolution of Adversarial Robustness for Membership Inference Attacks Against Federated LearningabstractFederated learning (FL) is a privacy-preserving machine learning paradigm that enables multiple clients to train a unified model without disclosing their private data. However, susceptibility to membership inference attacks (MIAs) arises due to the natural inclination of FL models to overfit on the training data during the training process, thereby enabling MIAs to exploit the subtle differences in the FL model’s parameters, activations, or predictions between the training and testing data to infer membership information. It is worth noting that most if not all existing MIAs against FL require access to the model’s internal information or modification of the training process, yielding them unlikely to be performed in practice. In this paper, we present with TEAR the first evidence that it is possible for an honest-but-curious federated client to perform MIA against an FL system, by exploring the Temporal Evolution of the Adversarial Robustness between the training and non-training data. We design a novel adversarial example generation method to quantify the target sample’s adversarial robustness, which can be utilized to obtain the membership features to train the inference model in a supervised manner. Extensive experiment results on five realistic datasets demonstrate that TEAR can achieve a strong inference performance compared with two existing MIAs, and is able to escape from the protection of two representative defenses. Gaoyang Liu, Zehao Tian, Jian Chen 0046, Chen Wang 0011, Jiangchuan Liu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Knowledge Representation of Training Data With Adversarial Examples Supporting Decision BoundaryabstractDeep learning (DL) has achieved tremendous success in recent years in many fields. The success of DL typically relies on a considerable amount of training data and the expensive model optimization process. Therefore, a trained DL model and its corresponding training data have become valuable assets whose intellectual property (IP) needs to be protected. Once a DL model or its training dataset is released, there is currently no mechanism for the entity that owns one part to establish a clear relationship with the other. In this paper, we aim to reveal the integrated relationship between a given DL model and the corresponding training dataset, by framing the problem of knowledge representation of a dataset with respect to DL models trained on it:how to effectively represent the knowledge transferred from a training dataset to a DL model?Our basic idea is that the knowledge transferred from a training dataset to a DL model can be uniquely represented by the model’s decision boundary. Therefore, we design a novel generation method that utilizes geometric consistency to find the samples supporting the decision boundary, which can serve as the proxy for the knowledge representation. We evaluate our method in three different cases: IP audit of training data, IP audit of DL models, and adversarial knowledge distillation. The experimental results show that our method can improve the performance of existing works in all cases, which confirm that our method can effectively represent the knowledge transferred from a training dataset to a DL model. Zehao Tian, Zixiong Wang, Ahmed M. Abdelmoniem, Gaoyang Liu, Chen Wang 0011 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | Manipulating Supply Chain Demand Forecasting With Targeted Poisoning AttacksabstractDemand forecasting (DF) plays an essential role in supply chain management, as it provides an estimate of the goods that customers are expected to purchase in the foreseeable future. While machine learning techniques are widely used for building DF models, they also become more susceptible to data poisoning attacks. In this article, we study the vulnerability of targeted poisoning attacks for linear regression DF models, where the attacker controls the behavior of forecasting models on a specific target sample without compromising the overall forecasting performance. We devise a gradient-optimization framework for targeted regression poisoning in white-box settings, and further design a regression value manipulation strategy for targeted poisoning in black-box settings. We also discuss some possible countermeasures to defend against our attacks. Extensive experiments are conducted on two real-world datasets with four linear regression models. The results demonstrate that our attacks are very effective, and can achieve a high prediction deviation with control of less than 1% of the training samples. Jian Chen 0046, Jinyong Shan, Kai Peng 0001, Chen Wang 0011, Hongbo Jiang 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2023 | CP-Link: Exploiting Continuous Spatio-Temporal Check-In Patterns for User Identity LinkageabstractDriven by the large amount of spatio-temporal data obtained from location-based social networks, the implementation of cross-domain user linkage, also known as the User Identity Linkage (UIL), has attracted increasing research attentions. While most of the existing UIL works discretize the spatio-temporal sparse data when identifying encountering or co-located events for UIL, user’s distinctive behavior patterns implicit in the “check-in” spatio-temporal data with continuous nature pave the way for enhancing UIL performance. In this paper, we propose an approach dubbedCP-Linkthat exploits user behavior patterns in a continuous way. In CP-Link, the continuous space is divided into irregularly shaped stay regions, and a continuous time-based improved dynamic time warping (IDTW) method is proposed to calculate the similarity. To bridge the gap between the ideal scenario with ample records and the reality with sparse data, we adopt the user-associated location frequent pattern (LFP) model to compensate for the sparse deficiency. Extensive experiments conducted on real-world datasets demonstrate the effectiveness and superiority of CP-Link, which outperforms the state of the arts by more than 20% in terms of the AUC. Xiaoqiang Ma, Fengxiang Ding, Kai Peng 0001, Yang Yang 0060, Chen Wang 0011 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | Efficient Point-of-Interest Recommendation Services With Heterogenous Hypergraph EmbeddingabstractPoint-of-interest (POI) recommendation service has drawn growing attention with the widespread popularity of location- based social networks (LBSNs). Recent research methods on POI recommendation based on graph embedding have mainly focused on explicit interactions of LBSN objects such as user's check-ins on POIs and social relationships, while neglecting implicit relationship that cannot be directly observed but may notably contribute to the POI recommendation. This paper presents VirHpoi, a heterogeneous hypergraph embedding method for POI recommendation in LBSNs with three original contributions. First, we model the LBSNs as a hypergraph to capture the complex interactions in LBSNs and learn the hypergraph by preserving homophily and interaction attribute affinity of the LBSNs. Second, we introduce the notion of “virtual hyperedges” to capture the intrinsic correlations of POIs. Virtual hyperedges incorporate implicit yet informative connections of the check-in patterns in LBSNs in terms of geographical and semantic characteristics. Third, we propose techniques to learn heterogenous hypergraph embedding on the complex LBSN graph with both homogenous edges and heterogenous hyperedges with dual objectives: we aim to preserve the homophily of objects intra domain by maximizing the co-occurrence probability of all homogenous edges, and we want to learn the interaction attribute affinity across domains by maximizing the probability of predicting the target object in the hyperedges. As a result, our approach can preserve both the intra domain homophily of objects and the interaction attribute affinity across domains by learning low-dimensional embeddings of LBSN objects and then make more effective recommendations based on the embeddings. Extensive experiments on four real-world datasets show the effectiveness and superiority of VirHpoi compared with the state-of-the-art methods. Chen Wang 0011, Rui Zhang 0066, Kai Peng 0001, Ling Liu 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Revisiting Cold-Start Problem in CTR Prediction: Augmenting Embedding via GANabstractClick-through rate (CTR) prediction is one of the core tasks in industrial applications such as online advertising and recommender systems. However, the performance of existing CTR models is hampered by the cold-start users who have very few historical behavior data, given that these models often rely on enough sequential behavior data to learn the embedding vectors. In this paper, we propose a novel framework dubbed GF2 to alleviate the cold-start problem in deep learning based CTR prediction. GF2 augments the embeddings of cold-start users after the embedding layer in the deep CTR model based on the Generative Adversarial Network (GAN), and the obtained generator by GAN can be further fine-tuned locally to enhance the CTR prediction in cold-start settings. GF2 is general for deep CTR models that use embeddings to model the features of users, and it has already been deployed in real-world online display advertising system. Experimental results on two large-scale real-world datasets show that GF2 can significantly improve the prediction performance over three polular deep CTR models. Xuxin Zhang, Dehong Gao, Wei Ning, Chen Wang 0011 |
CIKM | 7 |
| 2022 | Leveraging Model Poisoning Attacks on License Plate Recognition SystemsabstractComputer vision-based license plate recognition (LPR) has been widely deployed for automatic vehicle identity inspection due to the offered convenience and efficiency. However, the practical LPR systems are potentially vulnerable to malicious attacks, which may lead to incorrect recognition and impact the safety of transportation. Previous studies of attacking strategies targeting LPR systems mainly focused on evasion attacks, which are less efficient than model poisoning attacks that can cause mis-classification through directly manipulating the parameters of the victim model other than perturbing each testing sample. To fill this gap, we conduct the first systematic study on the vulnerability of LPR systems against model poisoning attacks. In specific, we aim to compromise the integrity of the model training such that the attacked LPR system would mis-classify all the samples from the victim class to the attacker-chosen class. To achieve this, we fine-tune the feature extractor layers of the LPR model such that it can obtain similar feature representations given samples belong to victim and attacker-chosen classes. This is implemented in a generator-discriminator fashion, where a discriminator learns to classify the victim and attacker-chosen classes given the input samples. Subsequently, the feature extractor is fine-tuned to generate manipulated features that can confuse the discriminator. Our empirical results on the CCPD dataset demonstrate that the proposed attacking strategy can substantially compromise LPR systems with high success rates. Jian Chen 0046, Yang Liu 0064, Chen Wang 0011, Kai Peng 0001 |
TrustCom | 4 |
| 2022 | An Improved Ray Tracing Acceleration Algorithm Based on Bounding Volume HierarchiesabstractRay tracing is an efficient channel modeling method. However, the traditional ray tracing method has high computation complexity. To solve this problem, an improved bounding volume hierarchies (BVH) algorithm is proposed in this paper. Based on surface area heuristic (SAH) and spatial distance, the proposed algorithm can effectively reduce the number of unnecessary intersection tests between ray and triangular facets. In addition, the algorithm fully considers the influence of ray action range, which can not only make up for the defects of spatial division based on uniform grid method and k-dimensional (KD) tree, but also solve the problem of unsatisfactory spatial division based on traditional BVH algorithm. The simulation results show that compared with the traditional BVH algorithm, the proposed algorithm can improve the computation efficiency by 20% to 35% while ensuring the computation accuracy. Chen Wang 0011, Yinghua Wang, Jialing Huang, Jie Huang 0004, Cheng-Xiang Wang 0001 |
VTC Fall | 1 |
| 2022 | OPTDP: Towards optimal personalized trajectory differential privacy for trajectory data publishing
Wenqing Cheng, Ruxue Wen, Haojun Huang, Wang Miao, Chen Wang 0011 |
Neurocomputing | 5 |
| 2022 | Your Model Trains on My Data? Protecting Intellectual Property of Training Data via Membership Fingerprint AuthenticationabstractIn recent years, data has become the new oil that fuels various machine learning (ML) applications. Just as the oil refining, providing data to an ML model is a product of massive costs and expertise efforts. However, how to protect the intellectual property (IP) of the training data in ML remains largely open. In this paper, we present MeFA, a novel framework for detecting training data IP embezzlement via Membership Fingerprint Authentication, which is able to determine whether a suspect ML model is trained on the to be protected target data or not. The key observation is that a part of data has a similar influence on the prediction behavior of different ML models. On this basis, MeFA leverages membership inference techniques to extract these data as the fingerprints of the target data and constructs an authentication model to verify the data’s ownership by identifying the obtained membership fingerprints. MeFA has several salient features. It does not assume any knowledge of the suspect model except for its black-box prediction API, through which we can merely get the prediction output of a given input, and also does not require any modification to the dataset or the training process, since it takes advantage of the inherent membership property of the data. As a by-product, MeFA can also serve as a post-protection to verify the ownership of ML models, without modifying the training process of the model. Extensive experiments on three realistic datasets and seven types of ML models validate the effectiveness of MeFA, and demonstrate that it is also robust to scenarios when the training data is partially used or preprocessed with representative membership inference defenses. Gaoyang Liu, Tianlong Xu, Xiaoqiang Ma, Chen Wang 0011 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Enabling Energy Trading in Cooperative Microgrids: A Scalable Blockchain-Based Approach With Redundant Data ExchangeabstractBlockchain has recently been regarded as an important enabler for building secure energy trading in microgrid systems because of its inherent features of distributively providing immutable data record, storage, and sharing across networks in a peer-to-peer (P2P) manner. However, designing highly efficient and scalable blockchain-enabled energy trading mechanisms is extremely challenging because of the unique features of microgrid systems, e.g., bandwidth-constrained and high-latency communications and large-scale renewable energy source (RES) integration. To address this challenge, in this article, we propose a novel scalable blockchain-based energy trading framework for cooperative microgrid systems, which include four planes, i.e., data plane, consensus plane, smart plane, and application plane. Different from the existing solutions without consideration of network transmission, these four planes are designed with the capability of perceiving the status of block generation and transmission over interrupted P2P networks, and thus proactively improving the consensus process to guarantee the reliability of energy trading in cooperative microgrids. Meanwhile, built on this framework, a novel redundant data exchange strategy is proposed to improve the scalability of block creation with the presence of large-scale RES penetration and interrupted and dynamic communication links. Simulation results show that the proposed system framework outperforms the benchmark blockchain solutions. Furthermore, we investigate the potential applications of the proposed solutions in the practical microgrid systems to facilitate a clear understanding of the mechanisms of the proposed solutions. Haojun Huang, Wang Miao, Chen Wang 0011, Geyong Min |
IEEE Trans. Ind. Informatics | 5 |
| 2021 | FedEraser: Enabling Efficient Client-Level Data Removal from Federated Learning ModelsabstractFederated learning (FL) has recently emerged as a promising distributed machine learning (ML) paradigm. Practical needs of the "right to be forgotten" and countering data poisoning attacks call for efficient techniques that can remove, or unlearn, specific training data from the trained FL model. Existing unlearning techniques in the context of ML, however, are no longer in effect for FL, mainly due to the inherent distinction in the way how FL and ML learn from data. Therefore, how to enable efficient data removal from FL models remains largely under-explored. In this paper, we take the first step to fill this gap by presenting FedEraser, the first federated unlearning method-ology that can eliminate the influence of a federated client’s data on the global FL model while significantly reducing the time used for constructing the unlearned FL model. The basic idea of FedEraser is to trade the central server’s storage for unlearned model’s construction time, where FedEraser reconstructs the unlearned model by leveraging the historical parameter updates of federated clients that have been retained at the central server during the training process of FL. A novel calibration method is further developed to calibrate the retained updates, which are further used to promptly construct the unlearned model, yielding a significant speed-up to the reconstruction of the unlearned model while maintaining the model efficacy. Experiments on four realistic datasets demonstrate the effectiveness of FedEraser, with an expected speed-up of 4× compared with retraining from the scratch. We envision our work as an early step in FL towards compliance with legal and ethical criteria in a fair and transparent manner. Gaoyang Liu, Xiaoqiang Ma, Yang Yang 0060, Chen Wang 0011, Jiangchuan Liu |
IWQoS | 4 |
| 2021 | ML-Stealer: Stealing Prediction Functionality of Machine Learning Models with Mere Black-Box AccessabstractMachine Learning (ML) models are progressively deployed in many real-world applications to perform a wide range of tasks, but are exposed to the security and privacy threats which aim to infer the details and even steal the functionality of the ML models. Despite extensive attacking efforts which rely on white-box or gray-box access, how to perform attacks with black-box access continues to be elusive. Aspiring to fill this gap, we move one step further and present ML-Stealer that can steal the functionality of any type of ML models with mere black-box access. With two algorithm designs, namely, synthetic data generation and replica model construction, ML-Stealer can construct a deep neural network (DNN)-based replica model which has the similar prediction functionality to the victim ML model. ML-Stealer does not require any knowledge about the victim model, nor does it enforce the access to statistical information or samples of the victim's training data. Experiment results demonstrate that ML-Stealer can achieve the consistent prediction results with the victim model of an averaged testing accuracy of 85.6%, and up to 93.6% at best. Gaoyang Liu, Shijie Wang 0007, Borui Wan, Chen Wang 0011 |
TrustCom | 5 |
| 2021 | Protecting Locations with Differential Privacy against Location-Dependent Attacks in Continuous LBS QueriesabstractWith the development of location-based services (LBS), concerns on location privacy frequently arise. Location data often contains users' sensitive information, and direct release it may pose a threat to users' privacy. Differential privacy (DP), as a privacy preserving method with solid mathematical foundation, has been widely used in location data release. However, most if not all of the existing location DP mechanisms only consider static scenarios or perturb the location at single timestamp, which are vulnerable to the so-called location-dependent attacks (LDA) in continuous LBS queries. In this paper, an optimal location DP mechanism against LDA is proposed. Firstly, the necessary conditions for LDA defense are derived by combining the perturbation mechanism of location DP. Then the algorithm of safe perturbance region generation is established to dynamically calculate the perturbation range at each timestamp. Finally, we set up the optimization problem with the real-time quality loss as the optimization objective and the location DP and safe perturbance region as the optimization conditions, and realize the optimal DP mechanism for LDA by solving the optimization problem. Experiment results on real-world datasets show that our mechanism can effectively resist LDA, which also balance privacy protection and data utility well. Ruxue Wen, Rui Zhang 0066, Kai Peng 0001, Chen Wang 0011 |
TrustCom | 4 |
| 2021 | GPS spoofed or not? Exploiting RSSI and TSS in crowdsourced air traffic control data
Gaoyang Liu, Rui Zhang 0066, Yang Yang 0060, Chen Wang 0011, Ling Liu 0001 |
Distributed Parallel Databases | 4 |
| 2021 | Security Challenges and Opportunities for Smart Contracts in Internet of Things: A SurveyabstractSmart contracts, one of the success stories in blockchain 2.0, have been widely utilized in a broad range of applications, including those involving Internet of Things (IoT). Given the fast-pace nature of the topic, it can be challenging for the research community to keep track of the latest advances. Hence, in this article, we perform a comprehensive, in-depth review of known security challenges (e.g., inherently vulnerable particularities, programming vulnerabilities, and attacks) and potential research opportunities associated with the deploying of smart contracts in an IoT setting. We hope this survey will serve as a starting point for the readers seeking to understand and explore the potential applications of smart contracts. Kai Peng 0001, Meijun Li, Haojun Huang, Chen Wang 0011, Shaohua Wan 0001, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 4 |
| 2021 | De-Pois: An Attack-Agnostic Defense against Data Poisoning AttacksabstractMachine learning techniques have been widely applied to various applications. However, they are potentially vulnerable to data poisoning attacks, where sophisticated attackers can disrupt the learning procedure by injecting a fraction of malicious samples into the training dataset. Existing defense techniques against poisoning attacks are largely attack-specific: they are designed for one specific type of attacks but do not work for other types, mainly due to the distinct principles they follow. Yet few general defense strategies have been developed. In this paper, we propose De-Pois, an attack-agnostic defense against poisoning attacks. The key idea of De-Pois is to train a mimic model the purpose of which is to imitate the behavior of the target model trained by clean samples. We take advantage of Generative Adversarial Networks (GANs) to facilitate informative training data augmentation as well as the mimic model construction. By comparing the prediction differences between the mimic model and the target model, De-Pois is thus able to distinguish the poisoned samples from clean ones, without explicit knowledge of any ML algorithms or types of poisoning attacks. We implement four types of poisoning attacks and evaluate De-Pois with five typical defense methods on different realistic datasets. The results demonstrate that De-Pois is effective and efficient for detecting poisoned data against all the four types of poisoning attacks, with both the accuracy and F1-score over 0.9 on average. Jian Chen 0046, Xuxin Zhang, Rui Zhang 0066, Chen Wang 0011, Ling Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Attacking Recommender Systems With Plausible ProfileabstractRecommender systems (RS) have become an essential component of web services due to their excellent performance. Despite their great success, RS have proved to be vulnerable to data poisoning attacks, which inject well-crafted fake profiles into RS, so that the target items can be maliciously recommended. In this paper, we first reveal that existing poisoning attacks in RS can be detected effortlessly, as the features of the generated fake profiles cannot be inconsistent with those of normal profiles all the time. We further propose RecUP, a poisoning attack in RS that can generate plausible profiles whose features stay almost the same as the normal ones, based on Generative Adversarial Networks (GAN). To tailor GAN for poisoning in RS, we develop HRGAN and devise a loss function to guide the training of the generator, along with a masking operation with selected potentially powerful profiles, so that the final generated profiles can perform malicious recommendations as expected. Evaluations against various defense methods using three real-world datasets show that, RecUP can generate the most plausible profiles while maintaining comparable attacking performance compared with state-of-the-art attacks. Xuxin Zhang, Jian Chen 0046, Rui Zhang 0066, Chen Wang 0011, Ling Liu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | Anomaly detection in bitcoin information networks with multi-constrained meta path
Rui Zhang 0066, Guifa Zhang, Chen Wang 0011, Shaohua Wan 0001 |
J. Syst. Archit. | 4 |
| 2020 | Resilient Range-Based d-Dimensional Localization for Mobile Sensor NetworksabstractKnowledge of node locations is essential to Wireless Sensor Networks (WSNs) in a wide range of potential applications and their function-dependent network protocols. A number of localization approaches have already been proposed to fulfill this requirement, but few of them can be applicable to mobile sensor networks, due to their low-dimensional embeddings, Euclidean distance representation limitations, frequent node mobility and additional measurement overhead in the network. In this paper, a resilient range-based d-dimensional localization (RRDL) approach is proposed for mobile WSNs to resolve the issues. RRDL distinguishes itself from previous work with three remarkable characteristics: (1) it works for mobile networks embedded in d-dimensional Non-Euclidean space; (2) it allows static ordinary nodes with pre-known locations to act as the alternative anchor nodes, thus tolerating the motion of the original anchor nodes to ensure that other ordinary nodes can obtain their locations in an efficient manner; and (3) it introduces an efficient path-learning approach, with the knowledge of the existing paths, to represent the real network distances as far as possible, thereby eliminating additional measurement overhead and tolerating node mobility in localization. With these characteristics, RRDL exploits the iterative factorization of the random distance matrix, formed by the distances to and from a set of k-hop static neighbors, to assign each current node d-dimensional Non-Euclidean coordinate in a distributed manner. Simulation results demonstrate that RRDL achieves higher localization accuracy with a moderate communication cost in mobile sensor networks. Haojun Huang, Wang Miao, Geyong Min, Chengqiang Huang, Xu Zhang 0006, Chen Wang 0011 |
IEEE/ACM Trans. Netw. | 6 |
| 2020 | MIASec: Enabling Data Indistinguishability Against Membership Inference Attacks in MLaaSabstractThe emerging of machine learning has massively promoted the abilities of computational sustainability in natural resource management and allocation. Many Internet giants such as Google, Amazon, and Microsoft now provide Machine Learning as a Service (MLaaS) to meet the increasing demand for machine learning services. However, the prediction results of training data and testing data with the same machine learning model in MLaaS have remarkable differences, and thus the attackers can leverage machine learning techniques to launch the so-called membership inference attacks, i.e., to infer whether a record is in the training data or not. In this paper, we propose MIASec that can guarantee the data indistinguishability of the training data and thereby has the ability to defend against membership inference attacks in MLaaS. The key idea of MIASec is to narrow the dynamic ranges of vital features in the training data, such that the training data, the testing data, and even the synthetic data have almost semblable prediction results by the same machine learning model. With elaborated design on modifying the values of vital features in the training data, MIASec can thus reduce the differences between the model's outcomes of training data and testing data, thereby protecting the training data in effect while keeping the model's accuracy stable. We empirically evaluate MIASec on machine learning models trained by off-line neural networks and on-line MLaaS. Using realistic data and classification tasks, our experiment results show that MIASec can defend the membership inference attacks effectively. In particular, MIASec can reduce the precision and recall of attacks respectively by 11.7 and 15.4 percent in average, and by 18.6 and 21.8 percent at best. Chen Wang 0011, Gaoyang Liu, Haojun Huang, Weijie Feng, Kai Peng 0001, Lizhe Wang 0001 |
IEEE Trans. Sustain. Comput. | 1 |
| 2020 | Recent advances in consensus protocols for blockchain: a survey
Shaohua Wan 0001, Meijun Li, Gaoyang Liu, Chen Wang 0011 |
Wirel. Networks | 4 |
| 2019 | Synchronization-Free GPS Spoofing Detection with Crowdsourced Air Traffic Control DataabstractGPS-dependent localization, navigation and air traffic control (ATC) applications have had a significant impact on the modern aviation industry. However, the lack of encryption and authentication makes GPS vulnerable to spoofing attacks with the purpose of hijacking aerial vehicles or threatening air safety. In this paper, we propose GPS-Probe, a GPS spoofing detection algorithm that leverages the ATC messages that are periodically broadcasted by aerial vehicles. By continuously analyzing the received signal strength indicator (RSSI) and the timestamps at server (TSS) of the ATC messages, which are monitored by multiple ground sensors, GPS-Probe constructs a machine learning enabled framework to estimate the real position of the target aerial vehicle and to detect whether or not the position data is compromised by GPS spoofing attacks. Unlike existing techniques, GPS-Probe neither requires any updates of the GPS infrastructure nor updates of the GPS receivers. More importantly, it releases the requirement on time synchronization of the ground sensors distributed around the world. Using the real-world ATC data crowdsourced by the OpenSky Network, our experiment results show that GPS-Probe can achieve the detection accuracy and precision, of 81.7% and 85.3% respectively on average, and up to 89.7% and 91.5% respectively at the best. Gaoyang Liu, Rui Zhang 0066, Chen Wang 0011, Ling Liu 0001 |
MDM | 3 |
| 2019 | Clustering Noisy Trajectories via Robust Deep Attention Auto-EncodersabstractTrajectory clustering aims at grouping similar trajectories into one cluster. It is an efficient way of finding the representative path or common trend shared by different moving objects, and also provides a foundation for movement pattern mining, anomaly detection and other applications. Existing trajectory clustering studies mainly rely on feature selection and similarity measurement based on their geographical and spatial properties. However, one obstacle hindering their wide usage is the problem of clustering accuracy in the presence of noisy or incomplete sensing data, due to limited sensory device quantity, communication errors, sensor failures, and sensor vacancy. This paper proposes an error-tolerant trajectory clustering approach by incorporating denoising methods.We propose the Robust Deep Attention Auto-encoders model (called Robust DAA) to learn the representations of low-dimensional denoising trajectories with three novel features. First, we present the deep attention auto-encoders by integrating the attention mechanism into the classical deep auto-encoder, which is capable of enhancing feature propagation and feature selection. Second, we train the deep attention auto-encoder by applying proximal method, back propagation and the Alternating Direction of Method of Multipliers (ADMM). As a result, our Robust DAA can reduce the negative influence of the noise on trajectory data. Finally, we perform clustering over the low-dimensional denoising representations using traditional clustering algorithms and demonstrates the quality of the clustering results by comparing our approach with existing representative methods. Extensive experiments are conducted on both synthetic datasets and real datasets. The results show that our approach outperforms the existing models in terms of accuracy, precision, recall and f1-score. Rui Zhang 0066, Hongbo Jiang 0001, Zhu Xiao, Chen Wang 0011, Ling Liu 0001 |
MDM | 5 |
| 2019 | Classifying transportation mode and speed from trajectory data via deep multi-scale learning
Rui Zhang 0066, Chen Wang 0011, Gaoyang Liu, Shaohua Wan 0001 |
Comput. Networks | 3 |
| 2019 | On the Performance of $k$ -Anonymity Against Inference Attacks With Background InformationabstractInternet of Things (IoT) applications bring in a great convenience for human’s life, but users’ data privacy concern is the major barrier toward the development of IoT.${k}$-anonymity is a method to protect users’ data privacy, but it is presently known to suffer from inference attacks. Thus far, existing work only relies on a number of experimental examples to validate${k}$-anonymity’s performance against inference attacks, and thereby lacks of a theoretical guarantee. To tackle this issue, in this paper we propose the first theoretical foundation that gives a nonasymptotic bound on the performance of${k}$-anonymity against inference attacks, taking into consideration of adversaries’ background information. The main idea is to first quantify adversaries’ background information, and from the point of the view of adversaries, classify users’ data into four kinds: 1) independent with unknown data values; 2) local dependent with unknown data values; 3) independent with certain known data values; and 4) local dependent with certain known data values. We then move one step further, theoretically proving the bound on the performance of${k}$-anonymity corresponding to each of the four kinds of users’ data through cooperating with the noiseless privacy. We argue that such a theoretical foundation links${k}$-anonymity with noiseless privacy, theoretically proving${k}$-anonymity provides noiseless privacy. Additionally, this paper theoretically explains why${k}$-anonymity is vulnerable to inference attacks using the modified Stein method. Simulations on real check-in dataset from the location-based social network have validated our results. We believe that this paper can bridge the gap between design and evaluation, enabling a designer to construct a more practical${k}$-anonymity technique in real-life scenarios to resist inference attacks. Ping Zhao 0001, Hongbo Jiang 0001, Chen Wang 0011, Haojun Huang, Gaoyang Liu, Yang Yang 0060 |
IEEE Internet Things J. | 3 |
| 2019 | SocInf: Membership Inference Attacks on Social Media Health Data With Machine LearningabstractSocial media networks have shown rapid growth in the past, and massive social data are generated which can reveal behavior or emotion propensities of users. Numerous social researchers leverage machine learning technology to build social media analytic models which can detect the abnormal behaviors or mental illnesses from the social media data effectively. Although the researchers only public the prediction interfaces of the machine learning models, in general, these interfaces may leak information about the individual data records on which the models were trained. Knowing a certain user's social media record was used to train a model can breach user privacy. In this paper, we present SocInf and focus on the fundamental problem known as membership inference. The key idea of SocInf is to construct a mimic model which has a similar prediction behavior with the public model, and then we can disclose the prediction differences between the training and testing data set by abusing the mimic model. With elaborated analytics on the predictions of the mimic model, SocInf can thus infer whether a given record is in the victim model's training set or not. We empirically evaluate the attack performance of SocInf on machine learning models trained by Xgboost, logistics, and online cloud platform. Using the realistic data, the experiment results show that SocInf can achieve an inference accuracy and precision of 73% and 84%, respectively, in average, and of 83% and 91% at best. Gaoyang Liu, Chen Wang 0011, Kai Peng 0001, Haojun Huang, Wenqing Cheng |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2018 | ILLIA: Enabling k-Anonymity-Based Privacy Preserving Against Location Injection Attacks in Continuous LBS QueriesabstractWith the increasing popularity of location-based services (LBSs), it is of paramount importance to preserve one's location privacy. The commonly used location privacy preserving approach, location k-anonymity, strives to aggregate the queries of k nearby users within a so-called cloaked region via a trusted third-party anonymizer. As such, the probability to identify the location of every user involved is no more than 1/k, thus offering privacy preservation for users. One inherent limitation of k-anonymity, however, is that all users involved are assumed to be trusted and report their real locations. When location injection attacks (LIAs) are conducted, where the untrusted users inject fake locations (along with fake queries) to the anonymizer, the probability of disclosing one's location privacy could be greatly more than 1/k, yielding a much higher risk of privacy leakage. To tackle this problem, in this paper we present ILLIA, the first work that enables k-anonymity-based privacy preservation against LIA in continuous LBS queries. Central to the ILLIA idea is to explore the pattern of the users' mobility in continuous LBS queries. With a thorough understanding of the users' mobility similarity, a credibility-based k-anonymity scheme is developed, such that ILLIA is able to defense against LIA without requiring in advance knowledge of how fake locations are manipulated while still maintaining high quality of services. Both the effectiveness and the efficiency of ILLIA are validated by extensive simulations on real world dataset loc-Gowalla. Ping Zhao 0001, Jie Li 0058, Fanzi Zeng, Fu Xiao 0001, Chen Wang 0011, Hongbo Jiang 0001 |
IEEE Internet Things J. | 5 |
| 2018 | Low Human-Effort, Device-Free Localization with Fine-Grained Subcarrier InformationabstractDevice-free localization of objects not equipped with RF radios is playing a critical role in many applications. This paper presents LIFS, a Low human-effort, device-free localization system with fine-grained subcarrier information, which can localize a target accurately without offline training. The basic idea is simple: channel state information (CSI) is sensitive to a target's location and thus the target can be localized by modelling the CSI measurements of multiple wireless links. However, due to rich multipath indoors, CSI can not be easily modelled. To deal with this challenge, our key observation is that even in a rich multipath environment, not all subcarriers are affected equally by multipath reflections. Our CSI pre-processing scheme tries to identify the subcarriers not affected by multipath. Thus, CSI on the “clean” subcarriers can still be utilized for accurate localization. Without the need of knowing the majority transceivers' locations, LiFS achieves a median accuracy of 0.5 m and 1.1 m in line-of-sight (LoS) and non-line-of-sight (NLoS) scenarios, respectively, outperforming the state-of-the-art systems. Ju Wang 0003, Jie Xiong 0001, Hongbo Jiang 0001, Kyle Jamieson, Xiaojiang Chen, Dingyi Fang, Chen Wang 0011 |
IEEE Trans. Mob. Comput. | 7 |
| 2018 | SNP: A 1-Manifold Skeleton-Based Navigation Protocol in 3D Sensor NetworksabstractWe consider the navigation application of 3D sensor networks that can proactively guide the movement of internal users from potential dangers to a safe exit, where a 3D sensor network serves as a reactive system, instead of a monitoring tool or a medium of data acquisition. Most if not all existing efforts in this line concentrate on 2D cases only, and none of them can be readily applied to 3D sensor networks, posing it a non-trivial challenge to design an effective and light-weight navigation protocol in 3D sensor networks. In this paper, we propose the first location-free, distributed, and scalable navigation protocol that can provide a navigation route for users inside the 3D sensor network with guaranteed safety. More specifically, we formulate the navigation problem as the minimum cumulative exposure problem, and design SNP, a navigation protocol based on the so-called 1-manifold skeleton, which offers a safe path with a near-optimal cumulative exposure to dangers. Extensive simulations validate the effectiveness and efficiency of the proposed algorithm. Yang Yang 0060, Wenping Liu 0001, Hongbo Jiang 0001, Chen Wang 0011, Desheng Wang 0001, Hongzhi Lin |
IEEE Trans. Mob. Comput. | 4 |
| 2018 | RobLoP: Towards Robust Privacy Preserving Against Location Dependent Attacks in Continuous LBS Queries
Hongbo Jiang 0001, Ping Zhao 0001, Chen Wang 0011 |
IEEE/ACM Trans. Netw. | 3 |
| 2018 | P3-LOC: A Privacy-Preserving Paradigm-Driven Framework for Indoor LocalizationabstractIndoor localization plays an important role as the basis for a variety of mobile applications, such as navigating, tracking, and monitoring in indoor environments. However, many such systems cause potential privacy leakage in data transmission between mobile users and the localization server (LS). Unfortunately, there has been little research done on privacy issue, and the existing privacy-preserving solutions are algorithm-driven, each designed for specific localization algorithms, which hinders their wide-scale adoption. Furthermore, they mainly focus on users' location privacy, while the LS's data privacy cannot be guaranteed. In this paper, we propose a Privacy-Preserving Paradigm-driven framework for indoor LOCalization (P3-LOC). P3-LOC takes the advantage that most indoor localization systems share a common two-stage localization paradigm: information measurement and location estimation. Based on this, P3-LOC carefully perturbs and cloaks the transmitted data in these two stages and employs specially designed “k -anonymity” and “differential privacy” techniques to achieve the provable privacy preservation. The key advantage is that P3-LOC does not rely on any prior knowledge of the underlying localization algorithms, and it guarantees both users' location privacy and the LS's data privacy. Our extensive experiments from the measured data have validated that P3-LOC provides privacy preservation for general indoor localization techniques. In addition, P3-LOC is comparable with the state-of-the-art algorithm-driven techniques in terms of localization error, computation, and communication overhead. Ping Zhao 0001, Hongbo Jiang 0001, John C. S. Lui, Chen Wang 0011, Fanzi Zeng, Fu Xiao 0001, Zhetao Li |
IEEE/ACM Trans. Netw. | 4 |
| 2017 | SEND: A Situation-Aware Emergency Navigation Algorithm with Sensor NetworksabstractWhen emergencies happen, navigation services that guide people to exits while keeping them away from emergencies are critical in saving lives. To achieve timely emergency navigation, early and automatic detection of potential dangers, and quick response with safe paths to exits are the core requirements, both of which rely on continuous environment monitoring and reliable data transmission. Wireless sensor networks (WSNs) are a natural choice of the infrastructure to support emergency navigation services, given their relatively easy deployment and affordable costs, and the ability of ubiquitous sensing and communication. Although many efforts have been made to WSN-assisted emergency navigation, almost all existing works neglect to consider the hazard levels of emergencies and the evacuation capabilities of exits. Without considering such aspects, existing navigation approaches may fail to keep people farther away from emergencies of high hazard levels and would probably encounter congestions at exits with lower evacuation capabilities. In this paper, we propose SEND, a situation-aware emergency navigation algorithm, which takes the hazard levels of emergencies and the evacuation capabilities of exits into account and provides the mobile users the safest navigation paths accordingly. We formally model the situation-aware emergency navigation problem and establish a hazard potential field in the network, which is theoretically free of local minima. By guiding users following the descend gradient of the hazard potential field, SEND can thereby achieve guaranteed success of navigation and provide optimal safety. The effectiveness of SEND is validated by both experiments and extensive simulations in 2D and 3D scenarios. Chen Wang 0011, Hongzhi Lin, Rui Zhang 0066, Hongbo Jiang 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2016 | CANS: Towards Congestion-Adaptive and Small Stretch Emergency Navigation with Wireless Sensor NetworksabstractOne of the major applications of wireless sensor networks (WSNs) is the navigation service for emergency evacuation, the goal of which is to assist people in escaping from a hazardous region safely and quickly when an emergency occurs. Most existing solutions focus on finding the safest path for each person, while ignoring possible large detours and congestions caused by plenty of people rushing to the exit. In this paper, we present CANS, a C ongestion-Adaptive and small stretch emergency Navigation algorithm with WSNs. Specifically, CANS leverages the idea of level set method to track the evolution of the exit and the boundary of the hazardous area, so that people nearby the hazardous area achieve a mild congestion at the cost of a slight detour, while people distant from the danger avoid unnecessary detours. CANS also considers the situation in the event of emergency dynamics by incorporating a local yet simple status updating scheme. To the best of our knowledge, CANS is the first WSN-assisted emergency navigation algorithm achieving both mild congestion and small stretch, where all operations are in-situ carried out by cyber-physical interactions among people and sensor nodes. CANS does not require location information, nor the reliance on any particular communication model. It is also distributed and scalable to the size of the network with limited storage on each node. Both experiments and simulations validate the effectiveness and efficiency of CANS. Chen Wang 0011, Hongzhi Lin, Hongbo Jiang 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2016 | SLICE: Enabling Greedy Routing in High Genus 3-D WSNs With General TopologiesabstractIn this paper, we propose a highly efficient scheme, SLICE (a scalable and low stretch routing scheme), enabling greedy routing for wireless sensor networks (WSNs) deployed in complex-connected 3-D settings, whose topologies are often theoretically modeled as high genus 3-D WSNs. Compared to previous 3-D greedy embedding techniques, SLICE improves both the robustness and applicability. 1) It achieves a smaller distance distortion and a lower routing stretch with guaranteed delivery. While it follows the basic idea to embed the surface network to a planar topology to enable greedy routing, the embedding method proposed in SLICE is novel. We first slice the surface network to a genus-0 open surface with exactly one boundary. Then, to achieve a lower distance distortion, we purposely propose a variation of the Ricci flow algorithm, by which this open surface is flattened not to a planar annulus, but to a planar convex polygon, resulting in a lower routing stretch. 2) This is the first work, to the best of our knowledge, that enables greedy routing in high genus 3-D WSNs with general topologies. SLICE not only works for high genus 3-D surface WSNs, but also can be easily adapted to more general cases: high genus 3-D surface networks with holes, and high genus 3-D volume networks. For a high genus 3-D surface network with holes, SLICE embeds it to a planar convex polygon with circular holes, where our proposed greedy routing variation can be applied. For a high genus 3-D volume network, SLICE embeds the inner nodes to a height structure attached to the convex polygon, and a variation of greedy routing scheme with guaranteed delivery is proposed in this structure. The effectiveness of SLICE is validated by extensive simulations. Chen Wang 0011, Hongbo Jiang 0001, Tianlong Yu, John C. S. Lui |
IEEE/ACM Trans. Netw. | 1 |
| 2016 | Connectivity-Based Space Filling Curve Construction Algorithms in High Genus 3D Surface WSNsabstractMany applications in wireless sensor networks (WSNs) require that sensor observations in a given monitoring area are aggregated in a serial fashion. This demands a routing path to be constructed traversing all sensors in that area, which is also needed to linearize the network. In this article, we present SURF, a Space filling cURve construction scheme for high genus three-dimensional (3D) surFace WSNs, yielding a traversal path provably aperiodic (that is, any node is covered at most a constant number of times). SURF first utilizes the hop-count distance function to construct the iso-contour in discrete settings, and then it uses the concept of the Reeb graph and the maximum cut set to divide the network into different regions. Finally, it conducts a novel serial traversal scheme, enabling the traversal within and between regions. To the best of our knowledge, SURF is the first high genus 3D surface WSN targeted and pure connectivity-based solution for linearizing the networks. It is fully distributed and highly scalable, requiring a nearly constant storage and communication cost per node in the network. To incorporate adaptive density of the constructed space filling curve, we also design a second algorithm, called SURF + , which makes use of parameterized spiral-like curves to cover the 3D surface and thus can yield a multiresolution SFC adapting to different requirements on travel budget or fusion delay. The application combining both algorithms for in-network data storage and retrieval in high genus 3D surface WSNs is also presented. Extensive simulations on several representative networks demonstrate that both algorithms work well on high genus 3D surface WSNs. Chen Wang 0011, Hongbo Jiang 0001, Yan Dong 0001 |
ACM Trans. Sens. Networks | 1 |
| 2016 | BLOW-UP: Toward Distributed and Scalable Space Filling Curve Construction in 3D Volumetric WSNsabstractIn wireless sensor networks (WSNs), a space filling curve (SFC) refers to a path passing through all nodes in the network, with each node visited at least once. By enforcing a linear order of the sensor nodes through an SFC, many applications in WSNs concerning serial operations on both sensor nodes and sensor data can be performed, with examples including serial data fusion and path planning of mobile nodes. Although a few studies have made efforts to find such SFCs in WSNs, they primarily target 2D planar or 3D surface settings and cannot be directly applied to 3D volumetric WSNs due to considerably more complex geometric features and topology shapes that the 3D volumetric settings introduce. This article presents BLOW-UP, a distributed, scalable, and connectivity-based algorithm to construct an SFC for a 3D volumetric WSN (or alternatively to linearize the 3D volumetric network). The main idea of BLOW-UP is to decompose the given 3D volumetric network into a series of connected and closed layers, and the nodes are traversed layer by layer, incrementally from the innermost to the outermost, yielding an SFC covering the entire network, provably at least once and at most a constant number of times. To the best of our knowledge, BLOW-UP is the first algorithm that realizes linearization in 3D volumetric WSNs. It does not require advance knowledge of location or distance information. It is also scalable with a nearly constant per-node storage cost and message cost. Extensive simulations under various networks demonstrate its effectiveness on nodes’ covered times, coverage rate, and covering speed. Chen Wang 0011, Hongzhi Lin, Hongbo Jiang 0001, John C. S. Lui |
ACM Trans. Sens. Networks | 1 |
| 2016 | Chain-based barrier coverage in WSNs: toward identifying and repairing weak zones
Tingwei Liu, Hongzhi Lin, Chen Wang 0011, Kai Peng 0001, Desheng Wang 0001, Tianping Deng, Hongbo Jiang 0001 |
Wirel. Networks | 3 |
| 2016 | A novel networking architecture for mobile content delivery in urban transport systems
Chen Wang 0011, Hongzhi Lin, Rui Zhang 0066, Hongbo Jiang 0001 |
Wirel. Networks | 2 |
| 2015 | SURF: A connectivity-based space filling curve construction algorithm in high genus 3D surface WSNsabstractMany applications in wireless sensor networks (WSNs) require that sensor observations in a given monitoring area be aggregated in a serial fashion. This demands a routing path to be constructed traversing all sensors in that area, which is also called to linearize the network. In this paper, we present SURF, a Space filling cURve construction scheme for high genus 3D surFace WSNs, yielding a traversal path provably aperiodic (that is, any node is covered at most a constant number of times). SURF first utilizes the hop-count distance function to construct the iso-contour in discrete settings, then it uses the concept of the Reeb graph and the maximum cut set to divide the network into different regions. Finally it conducts a novel serial traversal scheme, enabling the traversal within and between regions. To the best of our knowledge, SURF is the first high genus 3D surface WSNs targeted and pure connectivity-based solution for linearizing the networks. It is fully distributed and highly scalable, requiring a nearly constant storage and communication cost per node in the network. Extensive simulations on several representative networks demonstrate that SURF works well on high genus 3D surface WSNs. Chen Wang 0011, Hongbo Jiang 0001 |
INFOCOM | 1 |
| 2015 | Boundary-free skeleton extraction and its evaluation in sensor networks
Donghui Zhu, Qiangong Tao, Yubao Wang, Wenping Liu 0001, Tianping Deng, Hongzhi Lin, Chen Wang 0011, Hongbo Jiang 0001 |
Wirel. Networks | 8 |
| 2014 | Trajectory-based multi-dimensional outlier detection in wireless sensor networks using Hidden Markov Models
Chen Wang 0011, Hongzhi Lin, Hongbo Jiang 0001 |
Wirel. Networks | 1 |