VLDB 2026 Research / reviewers in the wild / expert
Khin Mi Mi Aung
dblp:85/2357
· DBLP profile ↗
45ranked-venue papers
9as first author
16since 2021 · last 2026
0000-0002-5652-3455ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 17 · 4 first-author · 3 since 2021Security and privacy · 12 · 2 first-author · 9 since 2021Computer networks · 5Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Theory of computation · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Secure bioinformatics: privacy-preserving federated analytics using homomorphic encryptionabstractMOTIVATION: Large-scale bioinformatics analyses increasingly require collaboration across multiple cohorts and institutions, yet existing workflows often rely on data co-localization, which is slow, difficult to scale, and raises privacy concerns. We present a privacy-preserving federated analytics framework that enables secure statistical analysis across distributed datasets without transferring raw data, by performing all computations on encrypted data via cryptographic methods. RESULTS: We evaluate the framework by validating polygenic risk scores and conducting meta-analyses on two real-world cohorts. The proposed solution achieves over 99.9% accuracy relative to plaintext analyses, while maintaining scalable runtime performance with increasing data size and number of participating sites. These results demonstrate the feasibility of secure federated analytics for practical bioinformatics applications involving sensitive data. Weizhuang Zhou, Chao Jin 0002, Zexi Yao, Meenatchi Sundaram Muthu Selva Annamalai, Yu En Chan, Sreejith Kumar Ashish Jith, Xiaoxia Deng, Chan Fook Mun, Kok Leong Foong, Rayden Chua Ming Hong, Kevin Kok Wai Wong, Roger Foo Sik Yin, Carolyn S. P. Lam, Arthur Mark Richards, Weng Khong Lim, Jonathan Yap, Khung Keong Yeo, Boon Ooi Patrick Tan, Neerja Karnani, Pavitra Krishnaswamy, Sebastian Maurer-Stroh, Khin Mi Mi Aung |
Bioinform. | 22 |
| 2025 | Bootstrapping with RMFE for Fully Homomorphic Encryption
Khin Mi Mi Aung, Enhui Lim, Sim Jun Jie, Benjamin Hong Meng Tan, Huaxiong Wang |
PKC (5) | 1 |
| 2024 | Unsupervised Fingerphoto Presentation Attack Detection With Diffusion ModelsabstractSmartphone-based contactless fingerphoto authentication has become a reliable alternative to traditional contact-based fingerprint biometric systems owing to rapid advances in smartphone camera technology. Despite its convenience, fingerprint authentication through fingerphotos is more vulnerable to presentation attacks, which has motivated recent research efforts towards developing fingerphoto Presentation Attack Detection (PAD) techniques. However, prior PAD approaches utilized supervised learning methods that require labeled training data for both bona fide and attack samples. This can suffer from two key issues, namely (i) generalization—the detection of novel presentation attack instruments (PAIs) unseen in the training data, and (ii) scalability—the collection of a large dataset of attack samples using different PAIs. To address these challenges, we propose a novel unsupervised approach based on a state-of-the-art deep-learning-based diffusion model, the Denoising Diffusion Probabilistic Model (DDPM), which is trained solely on bona fide samples. The proposed approach detects Presentation Attacks (PA) by calculating the reconstruction similarity between the input and output pairs of the DDPM. We present extensive experiments across three PAI datasets to test the accuracy and generalization capability of our approach. The results show that the proposed DDPM-based PAD method achieves significantly better detection error rates on several PAI classes compared to other baseline unsupervised approaches. Hailin Li, Ramachandra Raghavendra, Mohamed Ragab 0002, Soumik Mondal, Yong Kiam Tan, Khin Mi Mi Aung |
IJCB | 6 |
| 2024 | The Initialization Factor: Understanding its Impact on Active Learning for Analog Circuit DesignabstractActive learning, which aims to enhance modeling efficiency, precision, and cost effectiveness through selective labeling, is emerging as a promising strategy for analog circuit modeling. However, analog circuits are constrained by strict functional and technological limitations, resulting in scarcity of data for modeling, and additional data acquisition involves expensive and time-consuming simulations. For efficient and effective active learning for analog circuit modeling, our research analyzes data-driven initial sampling techniques which lays the foundation for the active learning process. Our experiments reveal that these initialization strategies expedite the learning process, decrease the demand for extensive simulations, and produces more accurate models. Furthermore, the results demonstrate that active learning techniques, which uniformly sample the design space, tend to benefit from distance-based initialization technique. Sezin Kircali Ata, Zhi-Hui Kong, Anusha James, Lile Cai, Kiat Seng Yeo, Khin Mi Mi Aung, Chuan-Sheng Foo, Ashish James |
ISCAS | 6 |
| 2024 | Scores Tell Everything about Bob: Non-adaptive Face Reconstruction on Face Recognition SystemsabstractFace recognition systems (FRSs) typically store databases of discriminative real-valued template vectors, which are extracted from each enrolled user’s facial image(s). Such template databases must be carefully protected for user privacy—indeed, the dangers of template leakages have been widely reported in the literature. In contrast, the similarity scores between queried images and enrolled users is often unprotected and can be readily queried through typical FRS APIs. Such scores provide a potential avenue of adversarial attack on FRSs, but recently proposed score-based attacks remain largely impractical because they essentially rely on trial-and-error strategies that use an enormous number of adaptive queries (>50K) for face reconstruction.We present the first practical score-based face reconstruction and impersonation attack against three commercial FRS APIs: AWS CompareFaces, FACE++, and KAIROS, as well as five commonly used pre-trained open-source FRSs. Our attack is carried out in the black-box FRS model, where the adversary has no knowledge of the FRS (underlying models, parameters, template databases, etc.), except for the ability to make a limited number of similarity score queries. Notably, the attack is straightforward to implement, requires no trial-and-error guessing, and uses a small number of nonadaptive score queries. We motivate the attack by analyzing the topological meaning of similarity scores and then present our novel method using orthogonal face sets: a precomputed approximate basis set of human-like face images that enables us to get meaningful similarity scores from a small number of non-adaptive queries. Our approach successfully reconstructs human-like impersonation images with >20% (resp. >96%) success rates across three test datasets when directly attacking the AWS CompareFaces API (resp. open-source CosFace FRS) using only 100 queries—up to two orders of magnitude fewer queries than previous approaches. We provide evidence that personally identifiable biometric features are captured in our reconstructions by evaluating our approach in transfer-like attack settings and through other image similarity metrics. Sunpill Kim, Yong Kiam Tan, Bora Jeong, Soumik Mondal, Khin Mi Mi Aung, Jae Hong Seo |
SP | 5 |
| 2024 | Enabling Threshold Functionality for Private Set Intersection Protocols in Cloud ComputingabstractMulti-party computation (MPC) allows parties to interact with cloud-based data and services while maintaining privacy and confidentiality of their private data. As a special case of MPC, private set intersection (PSI) protocols focus on securely computing the intersection between a server and a client of their private set. Our research extends the threshold functionality for PSI within the realm of cloud computing, where the server possesses a larger set than the client. This paper fills this gap by proposing new private intersection cardinality (PSI-CA) protocol, and more broadly, threshold private set intersection (tPSI) protocol using fully homomorphic encryption (FHE). In tPSI protocol, two parties holding two private sets collaboratively compute the intersection and reveal the result if and only if the size of the intersection exceeds some predefined threshold. In this process, no other information, in particular, elements not in the intersection remain hidden. The problem of PSI-CA and tPSI has many applications in online collaboration,e.g., fingerprint matching, online dating, and ride sharing. At a high level, we use FHE to encrypt a Bloom filter (BF) that encodes the small set and homomorphically check whether the elements in the larger set belongs to the small set,e.g., homomorphic membership test. Counting the number of positive membership directly already yields a PSI-CA protocol with optimal asymptotic communication complexity Ω(n) = Ω(min(N,n)), whereN(resp.n) is the size of the large (resp. small) set. To construct a tPSI protocol, we develop a novel secret token generation protocol: a shared secret token is generated if and only if the intersection size satisfies the threshold condition, by exploiting the programmable bootstrapping technique in FHE. This new secret token generation protocol, when composed with any standard PSI protocol, yields a tPSI with the same asymptotic communication complexity as the chosen plain PSI. Along the way, we develop specific FHE optimizations that might be of independent interest. These optimizations overcome the weakness of low precision in programmable bootstrapping. As a result, tPSI over relatively large sets can be supported. Jingwei Hu 0001, Yongjun Zhao 0001, Benjamin Hong Meng Tan, Khin Mi Mi Aung, Huaxiong Wang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Threshold Homomorphic Encryption From Provably Secure NTRUabstractAbstract Homomorphic Encryption (HE) supports computation on encrypted data without the need to decrypt, enabling secure outsourcing of computing to an untrusted cloud. Motivated by application scenarios where private information is offered by different data owners, Multi-Key Homomorphic Encryption (MKHE) and Threshold Homomorphic Encryption (ThHE) were proposed. Unlike MKHE, ThHE schemes do not require expensive ciphertext extension procedures and are therefore as efficient as their underlying single-key HE schemes. In this work, we propose a novel NTRU-type ThHE scheme which caters to the computation scenarios with pre-defined participants. In addition to inheriting the simplicity of NTRU scheme, our construction has no expensive relinearization and correspondingly no costly evaluation keys. Controlling noise to make it increase linearly and then using a wide key distribution, our scheme is immune to the subfield lattice attacks and its security follows from the hardness of the standard R-LWE problem. Finally, based on the {0,1}-linear secret sharing and noise flooding techniques, we design a single round distributed threshold decryption protocol, where the decryption is able to be completed even when only given a subset (say $t$-out-of-$k$) of partial decryptions. To the best of our knowledge, our construction is the first NTRU-type ThHE scheme. Benjamin Hong Meng Tan, Khin Mi Mi Aung, Huaxiong Wang |
Comput. J. | 4 |
| 2023 | Privacy-preserving outsourcing decision tree evaluation from homomorphic encryption
Benjamin Hong Meng Tan, Khin Mi Mi Aung, Huaxiong Wang |
J. Inf. Secur. Appl. | 4 |
| 2023 | Multi-key fully homomorphic encryption from NTRU and (R)LWE with faster bootstrapping
Benjamin Hong Meng Tan, Khin Mi Mi Aung, Huaxiong Wang |
Theor. Comput. Sci. | 4 |
| 2022 | Field Instruction Multiple Data
Khin Mi Mi Aung, Enhui Lim, Sim Jun Jie, Benjamin Hong Meng Tan, Huaxiong Wang, Sze Ling Yeo |
EUROCRYPT (1) | 1 |
| 2022 | Towards high performance homomorphic encryption for inference tasks on CPU: An MPI approach
Souhail Meftah, Benjamin Hong Meng Tan, Khin Mi Mi Aung, Yuxiao Lu, Jie Lin 0001, Bharadwaj Veeravalli |
Future Gener. Comput. Syst. | 3 |
| 2022 | Skellam Mixture Mechanism: a Novel Approach to Federated Learning with Differential PrivacyabstractDeep neural networks have strong capabilities of memorizing the underlying training data, which can be a serious privacy concern. An effective solution to this problem is to train models withdifferential privacy(DP), which provides rigorous privacy guarantees by injecting random noise to the gradients. This paper focuses on the scenario where sensitive data are distributed among multiple participants, who jointly train a model throughfederated learning, using bothsecure multiparty computation(MPC) to ensure the confidentiality of each gradient update, and differential privacy to avoid data leakage in the resulting model. A major challenge in this setting is that common mechanisms for enforcing DP in deep learning, which injectreal-valued noise, are fundamentally incompatible with MPC, which exchangesfinite-field integersamong the participants. Consequently, most existing DP mechanisms require rather high noise levels, leading to poor model utility. Motivated by this, we proposeSkellam mixture mechanism(SMM), a novel approach to enforcing DP on models built via federated learning. Compared to existing methods, SMM eliminates the assumption that the input gradients must be integer-valued, and, thus, reduces the amount of noise injected to preserve DP. The theoretical analysis of SMM is highly non-trivial, especially considering (i) the complicated math of DP deep learning in general and (ii) the fact that the mixture of two Skellam distributions is rather complex. Extensive experiments on various practical settings demonstrate that SMM consistently and significantly outperforms existing solutions in terms of the utility of the resulting model. Ergute Bao, Yizheng Zhu, Xiaokui Xiao, Yin Yang 0001, Beng Chin Ooi, Benjamin Hong Meng Tan, Khin Mi Mi Aung |
Proc. VLDB Endow. | 7 |
| 2022 | CryptoRec: Novel Collaborative Filtering Recommender Made Privacy-Preserving EasyabstractWith the explosive growth of user data, recommenders have become increasingly complicated. State-of-the-art algorithms often have high computational complexity and heavily use non-linear transformations. This fact makes the privacy-preserving problem more challenging, despite the significant advances in cryptography. To alleviate this problem, we propose a privacy-friendly recommender, CryptoRec. It only relies on additions and multiplications, which are efficiently supported by most cryptographic primitives. Different from others, in CryptoRec, the parameter space only contains item features (user features can be directly computed from the item features). This property allows CryptoRec to, (1) naturally achieve transferability if two datasets share the same item entries, which can benefit differential privacy protection; (2) directly estimate the preference of new users whose data is not included in the training set, drastically improving recommendation efficiency. We first evaluate CryptoRec on three real-world datasets. The evaluation results show that the accuracy is competitive with state-of-the-art. Then, we build differential privacy into CryptoRec and leverage its transferability property to reduce the overall privacy loss. Lastly, we demonstrate the simplicity and efficiency of using CryptoRec to construct secure recommendation protocols based on homomorphic encryption schemes. Our results show that CryptoRec outperforms existing solutions in terms of both accuracy and efficiency. Jun Wang 0020, Chao Jin 0002, Qiang Tang 0001, Zhe Liu 0001, Khin Mi Mi Aung |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Efficient Private Comparison Queries Over Encrypted Databases Using Fully Homomorphic Encryption With Finite FieldsabstractTo achieve security and privacy for data stored on the cloud, we need the ability to secure data in compute. Equality comparisons, “$x=y, x\ne y$”, have been widely studied with many proposals but there is much room for improvement for order comparisons, “$x < y,~x \leq y,~x > y \text{ and } x \geq y$”. Most protocols for order comparisons have some limitation, either leaking some information about the data or requiring several rounds of communication between client and server. In addition, little work has been done on retrieving with compound conditions, mixing several equality and order comparisons. Fully homomorphic encryption (FHE) promises the ability to compute arbitrary functions on encrypted data without sacrificing privacy and without communication, but its potential has yet to be fulfilled. Particularly, private comparisons for database queries using FHE are expensive to compute. In this article, we design an efficient private database query (PDQ) protocol which supports compound conditions with equality and order comparisons. To this end, we first present a private comparison algorithm on encrypted integers using FHE, which scales efficiently for the length of input integers, by applying techniques from finite field theory. Then, we consider a scenario for PDQ protocols, querying for values based on a conjunction of one order and four equality conditions on key columns. The proposed algorithm and protocol are implemented and tested to determine their performance in practice. The proposed comparison algorithm takes about$25.259$seconds to compare 697 pairs of 64-bit integers using Brakerski-Gentry-Vaikuntanathan's leveled FHE scheme with single instruction multiple data (SIMD) techniques at more than 138 bits of security. This yields an amortized rate of just 36 milliseconds per comparison. On top of that, we show that our techniques achieve an efficient PDQ protocol for one order and four equality comparisons, achieving an amortized time and communication cost of 57 milliseconds and 448 bytes per database element. Benjamin Hong Meng Tan, Hyung Tae Lee, Huaxiong Wang, Shu Qin Ren, Khin Mi Mi Aung |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | DOReN: Toward Efficient Deep Convolutional Neural Networks with Fully Homomorphic EncryptionabstractFully homomorphic encryption (FHE) is a powerful cryptographic primitive to secure outsourced computations against an untrusted third-party provider. With the growing demand for AI and the usefulness of machine learning as a service (MLaaS), the need for secure training and inference of artificial neural networks is rising. However, the computational complexity of existing FHE schemes has been a strong deterrent to this. Prior works suffered from accuracy degradation, lack of scalability, and ciphertext expansion issues. In this paper, we take the first step towards the problem of space-efficiency in evaluating deep neural networks through designing DOReN: a low depth, batched neuron that can simultaneously evaluate multiple quantized ReLU-activated neurons on encrypted data without approximations. Our circuit design reduced the complexity of the accumulator circuit depth from O(logm ·logn) to O(logm + logn) for n bit integers. The experimental results show that the amortized processing time of our homomorphic neuron is approximately 1.26 seconds for 300 inputs and less than 0.13 seconds for 10 inputs at 80 bit security, which is a 20 fold improvement upon Lou and Jiang, NeurIPS 2019. Souhail Meftah, Benjamin Hong Meng Tan, Chan Fook Mun, Khin Mi Mi Aung, Bharadwaj Veeravalli, Vijay Chandrasekhar 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2021 | Multi-GPU Design and Performance Evaluation of Homomorphic Encryption on GPU ClustersabstractWe present a multi-GPU design, implementation and performance evaluation of the Halevi-Polyakov-Shoup (HPS) variant of the Fan-Vercauteren (FV) levelled Fully Homomorphic Encryption (FHE) scheme. Our design follows a data parallelism approach and uses partitioning methods to distribute the workload in FV primitives evenly across available GPUs. The design is put to address space and runtime requirements of FHE computations. It is also suitable for distributed-memory architectures, and includes efficient GPU-to-GPU data exchange protocols. Moreover, it is user-friendly as user intervention is not required for task decomposition, scheduling or load balancing. We implement and evaluate the performance of our design on two homogeneous and heterogeneous NVIDIA GPU clusters: K80, and a customized P100. We also provide a comparison with a recent shared-memory-based multi-core CPU implementation using two homomorphic circuits as workloads: vector addition and multiplication. Moreover, we use our multi-GPU Levelled-FHE to implement the inference circuit of two Convolutional Neural Networks (CNNs) to perform homomorphically image classification on encrypted images from the MNIST and CIFAR - 10 datasets. Our implementation provides 1 to 3 orders of magnitude speedup compared with the CPU implementation on vector operations. In terms of scalability, our design shows reasonable scalability curves when the GPUs are fully connected. Ahmad Al Badawi, Bharadwaj Veeravalli, Jie Lin 0001, Xiao Nan, Kazuaki Matsumura, Khin Mi Mi Aung |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2020 | Secure Transfer Learning for Machine Fault Diagnosis Under Different Operating Conditions
Chao Jin 0002, Mohamed Ragab 0002, Khin Mi Mi Aung |
ProvSec | 3 |
| 2019 | Fully homomorphic encryption over the integers for non-binary plaintexts without the sparse subset sum problem
Khin Mi Mi Aung, Hyung Tae Lee, Benjamin Hong Meng Tan, Huaxiong Wang |
Theor. Comput. Sci. | 1 |
| 2018 | Accelerating subset sum and lattice based public-key cryptosystems with multi-core CPUs and GPUs
Ahmad Al Badawi, Bharadwaj Veeravalli, Khin Mi Mi Aung, Brahim Hamadicharef |
J. Parallel Distributed Comput. | 3 |
| 2018 | Dynamic scheduling strategy with efficient node availability prediction for handling divisible loads in multi-cloud systems
Seungmin Kang, Bharadwaj Veeravalli, Khin Mi Mi Aung |
J. Parallel Distributed Comput. | 3 |
| 2018 | Blockchain-based decentralized content trust for docker images
Quanqing Xu, Chao Jin 0002, Mohamed Faruq Bin Mohamed Rasid, Bharadwaj Veeravalli, Khin Mi Mi Aung |
Multim. Tools Appl. | 5 |
| 2017 | Decentralized Content Trust for Docker Images
Quanqing Xu, Chao Jin 0002, Mohamed Faruq Bin Mohamed Rasid, Bharadwaj Veeravalli, Khin Mi Mi Aung |
IoTBDS | 5 |
| 2016 | Machine Learning Approach to Generate Pareto Front for List-scheduling AlgorithmsabstractList Scheduling is one of the most widely used techniques for scheduling due to its simplicity and efficiency. In traditional list-based schedulers, a cost/priority function is used to compute the priority of tasks/jobs and put them in an ordered list. The cost function has been becoming more and more complex to cover increasing number of constraints in the system design. However, most of the existing list-based schedulers implement a static priority function that usually provides only one schedule for each task graph input. Therefore, they may not be able to satisfy the desire of system designers, who want to examine the trade-off between a number of design requirements (performance, power, energy, reliability ...). To address this problem, we propose a framework to utilize the Genetic Algorithm (GA) for exploring the design space and obtaining Pareto-optimal design points. Furthermore, multiple regression techniques are used to build predictive models for the Pareto fronts to limit the execution time of GA. The models are built using training task graph datasets and applied on incoming task graphs. The Pareto fronts for incoming task graphs are produced in time 2 orders of magnitude faster than the traditional GA, with only 4% degradation in the quality. Pham Nam Khanh, Akash Kumar 0001, Khin Mi Mi Aung |
SCOPES | 3 |
| 2016 | Secure searching on cloud storage enhanced by homomorphic indexingabstractEnterprise cloud tenants would store their outsourced cloud data in encrypted form for data privacy and security. However, flexible data access functions such as data searching is usually sacrificed as a result. Thus, enterprise tenants demand secure data retrieval and computation solution from the cloud provider , which will allow them to utilize cloud services without the risks of leaking private data to outsiders and even service providers. In this paper, we propose an exclusive-or (XOR) homomorphism encryption scheme to support secure keyword searching on encrypted data for cloud storage. First, this scheme specifies a new data protection method by encrypting the keyword and randomizing it by performing XOR operation with a random bit-string for each session to protect access pattern leakage; Secondly, the homomorphic evaluation key enables the searching evaluation to be on-demand calculated, thus it removes the dependency of key storage on cloud and enhance protection against cloud’s violability; Thirdly, this scheme can effectively protect data-in-transit against passive attack such as access pattern analysis due to the randomization . This scheme also can reduce data leakage to service provider because the homomorphism-key solution instead of key storage on cloud. The above three features have been proved by the experiments and further tested out at Email service which can support secure subject searching. The execution time of one searching process is just in the order of milliseconds. We could get 2–3 times speedup compared to default utility grep with the concern of expensive one-time indexing which can be built off-line in advance. Shu Qin Ren, Benjamin Hong Meng Tan, Sivaraman Sundaram, Taining Wang, Yibin Ng, Victor Chang 0001, Khin Mi Mi Aung |
Future Gener. Comput. Syst. | 7 |
| 2016 | Building a large-scale object-based active storage platform for data analytics in the internet of things
Quanqing Xu, Khin Mi Mi Aung, Khai Leong Yong |
J. Supercomput. | 2 |
| 2015 | Exploiting loop-array dependencies to accelerate the design space exploration with high level synthesis
Pham Nam Khanh, Amit Kumar Singh 0002, Akash Kumar 0001, Khin Mi Mi Aung |
DATE | 4 |
| 2015 | HEDup: Secure Deduplication with Homomorphic EncryptionabstractDeduplication on encrypted data is a promising trend for both cloud storage providers and subscribers. Data deduplication allows cloud storage providers (CSP) to save storage space by eliminating the copies of the same data. Data encryption can ensure the confidentiality of customer's data both in transit and at rest. However, deduplication that works on detecting identical data does not work well with encrypted data provided by conventional encryption. Encryption of the same data using different key (by different subscribers) will result in different ciphertexts that will not allow the CSP to carry out deduplication. In this paper, we propose a scheme to allow deduplication on encrypted data with the aid of a key server deployed at cloud service provider premises, called HEDup (Homomorphic Encryption Deduplication). In this solution, the subscriber encrypts data with data-encryption key obtained from key server via various key-management schemes, one of which uses homomorphic encryption. The main contributions of this project are (1) with a key server deployed at cloud provider premises, it will not only deduplicate data from particular domain but also for the CSP's entire client base including public and different enterprise users - this results in higher storage savings and (2) data owners still maintain exclusive control of their data and data-encryption keys, i.e. CSP has no access to any of it - strong confidentiality guarantees. The experiments conducted show that data uploads and downloads using HEDup have minor storage and latency overhead. Our implementation also shows significant performance optimization when compared to commercial key management service for cloud object storage. Miguel Rodel Felipe, Khin Mi Mi Aung, Mediana |
NAS | 2 |
| 2014 | An efficient scheme to ensure data availability for a cloud service providerabstractWith the emergence of information technologies, an overwhelming amount of data and information is generated everyday. Storing and processing this huge volume of data is named by a ubiquitous term: big data management. Cloud storage systems enhance reliability and availability of data by introducing redundancy, i.e., data replication, in the system, thereby protecting the data integrity from node failures which occur frequently in any large-scale storage system. However, efficiently determining the level of redundancy, i.e., number of data replicas, is not a trivial task for a cloud service provider (CSP). Traditional methods, which use a fixed number of replicas for all users regardless of the user's budget, do not achieve efficiency in terms of financial benefit of CSPs. This paper presents an efficient replication scheme that allows a CSP to determine the optimal number of replicas for each user depending on the user's budgetary constraint and the CSP's resource capacity while maximizing the financial benefit of the CSP. Numerical simulations were performed to assess the validity of our approach. The results show the scalability of the proposed scheme which can apply to real systems with an arbitrary number of users. Seungmin Kang, Bharadwaj Veeravalli, Khin Mi Mi Aung, Chao Jin 0002 |
IEEE BigData | 3 |
| 2014 | Homomorphic Exclusive-Or Operation Enhance Secure Searching on Cloud StorageabstractEnterprise cloud tenants would store their outsourced cloud data in encrypted form for data privacy and security. However, flexible data access functions such as data searching is usually sacrificed as a result. Thus, enterprise tenants demand secure data retrieval and computation solution from the cloud provider, which will allow them to utilize cloud services without the risks of leaking private data to outsiders and even service providers. In this paper, we propose an exclusive-or (XOR) homomorphism encryption scheme to support secure keyword searching on encrypted data. First, this scheme specifies a new data protection method by encrypting the data and randomizing it by performing XOR operation with a random bit-string. Second, this scheme can effectively protect data-in-transit against passive attack such as cipher text analysis due to the randomization. Third, this scheme is lightweight and only requires a symmetric encryption scheme and bitwise operations, which requires processing time in the order of milliseconds. Shu Qin Ren, Benjamin Hong Meng Tan, Sivaraman Sundaram, Taining Wang, Khin Mi Mi Aung |
CloudCom | 5 |
| 2014 | Design Space Exploration to Accelerate Nelder-Mead Algorithm Using FPGAabstractNelder-Mead algorithm (NMA) is the best-known algorithm for multidimensional optimization without involving derivative computations. Due to the simplicity in implementation and the fast convergent property of NMA, it is widely used in the fields of statistics, engineering, physics and medical sciences. In practice, when objective function is complicated, the optimization procedure requires a lot of computation efforts, leading to a time-consuming process. This work introduces a NMA solver engine fully implemented on FPGA hardware and performs design space exploration to provide various solutions suitable for FPGA device. Pham Nam Khanh, Amit Kumar Singh 0002, Akash Kumar 0001, Khin Mi Mi Aung |
FCCM | 4 |
| 2014 | Virtual machine placement with two-path traffic routing for reduced congestion in data center networks
Renuga Kanagavelu, Bu-Sung Lee, Le Nguyen The Dat, Luke Ng Mingjie, Khin Mi Mi Aung |
Comput. Commun. | 5 |
| 2013 | Incorporating Energy and Throughput Awareness in Design Space Exploration and Run-Time Mapping for Heterogeneous MPSoCsabstractThe advancement in process technology has enabled integration of different types of processing cores into a single chip towards creating heterogeneous Multiprocessor Systems-on-Chip (MPSoCs). While providing high level of computation power to support complex applications, these modern systems also introduce novel challenges for system designers, like managing a huge number of mappings (application tasks to processing cores allocations) that increases exponentially with the number of cores and their types. This paper presents a mapping approach that computes multiple energy-throughput trade-off points (mappings) at design-time and uses one of these points at run-time based on desired throughput and current resource availability while optimizing for the overall energy consumption. While significantly reducing the complexity of the design space exploration (DSE) to compute mappings at design-time, the proposed strategy still evaluates mappings for all the resource combinations of the platform, providing efficient mapping solutions for all the scenarios of system architecture at run-time. Moreover, the proposed approach performs energy-aware mapping at run-time while utilizing the DSE results. Experimental results show that proposed strategy achieves better energy-throughput trade-off points, covers all the resource combinations and reduces energy consumption up to 24.93% at design-time and additionally 17.8% at run-time when compared to state-of-the-art techniques. Pham Nam Khanh, Amit Kumar Singh 0002, Akash Kumar 0001, Khin Mi Mi Aung |
DSD | 4 |
| 2013 | sAES: A high throughput and low latency secure cloud storage with pipelined DMA based PCIe interfaceabstractModern cloud storage requires a high throughput and low latency data protection system, which is usually implemented with an Advanced Encryption Standard (AES) hardware accelerator connected with CPU through PCI Express (PCIe). However, most existing systems cannot simultaneously achieve high throughput and low latency, as they impose conflicting requirements to the block size of packets used in PCIe. High throughput requires the block size to be larger, while low latency requires the block size to be smaller. To provide both high throughput and low latency, we have developed an FPGA based data protection system called sAES. It uses a highly pipelined Direct Memory Access (DMA) based PCIe interface. It can achieve 10.4 Gbps throughput when the block size is 512 bytes, which is 51 times higher than the state-of-the-art Speedy PCIe interface [1]. The worst latency of sAES is only 4.368 μs when its block size is 512 bytes. Yongzhen Chen, Miguel Rodel Felipe, Yi Estelle Wang, Yajun Ha, Shu Qin Ren, Khin Mi Mi Aung |
FPT | 6 |
| 2012 | Energy optimizations for data center network: Formulation and its solutionabstractData center consumes increasing amount of power nowadays, together with expanding number of data centers and upgrading data center scale, its power consumption becomes a knotty issue. While main efforts of this research focus on server and storage power reduction, network devices as part of the key components of data centers, also contribute to the overall power consumption as data centers expand. In this paper, we address this problem with two perspectives. First, in a macro level, we attempt to reduce redundant energy usage incurred by network redundancies for load balancing. Second, in the micro level, we design algorithm to limit port rate in order to reduce unnecessary power consumption. Given the guidelines we obtained from problem formulation, we propose a solution based on greedy approach with integration of network traffic and minimization of switch link rate. We also present results from a simulation-based performance evaluation which shows that expected power saving is achieved with tolerable delay. Shuo Fang, Chuan Heng Foh, Yonggang Wen 0001, Khin Mi Mi Aung |
GLOBECOM | 5 |
| 2012 | Prompt congestion reaction scheme for data center network using multiple congestion pointsabstractWith recent advocates on end-to-end congestion control, we still observe lack of consideration of network congestion status in literature. Since end-to-end congestion control mechanisms are capable of gathering path load information through data paths, taking advantage of this information, network systems have potential capacity to react promptly in presence of congestion, especially for paths with multiple congestion points. In this paper, we design a congestion control scheme with consideration of multiple congestion points along data paths. Using an improved ECN mechanism, our scheme tunes source rate with feedbacks collecting from ECNs. We further improve our scheme with saturation detection and congestion prediction mechanisms. Simulation results show that our scheme works effectively. We evaluate our scheme and compare it with DCTCP, a recently proposed congestion control scheme for data center. In scenarios of multiple congestion points, our scheme exhibits better performance in terms of reaction time and stability. Shuo Fang, Chuan Heng Foh, Khin Mi Mi Aung |
ICC | 3 |
| 2011 | Differentiated Congestion Management of Data Traffic for Data Center EthernetabstractThis paper aims at designing a congestion and priority solution for Ethernet congestion management. Following the popular approach that uses a cooperation of an Additive Increase and Multiplicative Decrease (AIMD) based rate limiter and Explicit Congestion Notification (ECN) active queue management to combat congestions in Ethernet, the proposal considers differentiated AIMD settings for rate limiters to achieve congestion control differentiation for traffic of different priorities. We illustrate that while the operations of AIMD and ECN are independent, by using different AIMD settings, we can achieve differentiated control of bandwidth utilization. We develop a control theoretic analytical model to study the effectiveness of our proposed method. Moreover, we implement our proposed method in OMNET++ simulator to conduct simulation experiments. Our analytical and simulation results both indicate the effectiveness of bandwidth ratio differentiation. Shuo Fang, Chuan Heng Foh, Khin Mi Mi Aung |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2010 | Secured Key Distribution Scheme for Cryptographic Key Management SystemabstractKey distribution is the task of distributing secret keys between transmitter and receiver by providing security properties. Our key distribution scheme is beneficial for key transactions where the data encrypting key is encrypted with an upper-level key encrypting key and transmitted to the receiving side. We assume there is a trusted authority (TA) in the network which choose a secret key for communicating, and transits it to parties that wants to communicate with. There could be two or more parties that establish a secret key. At the end of a key tree two parties share a key K. The value of K is not known to any other party except TA. This scheme limits amount of cipher text available to an attacker and also limit exposure in event of key compromise. While the other schemes focus to reduce computation, or the amount of data the needs to be exchanged, our scheme is cable of Self-Adaptive key establishment for Large-Scale users as well as reduces the computational complexity. Kyawt Kyawt Khaing, Khin Mi Mi Aung |
ARES | 2 |
| 2010 | Differentiated Ethernet Congestion Management for Prioritized TrafficabstractThis paper proposes and studies a differentiated congestion control for Ethernet congestion management. Following the popular approach that uses a cooperation of an Additive Increase and Multiplicative Decrease (AIMD) based rate limiter and Explicit Congestion Notification (ECN) active queue management to combat the congestion in Ethernet, the proposal considers differentiated AIMD settings for rate limiters to achieve congestion control differentiation for traffic of different priorities. We illustrate that while the operation of AIMD and ECN are independent, by using different AIMD settings, we can achieve differentiated control of bandwidth utilization. We provide an analysis and its numerical results showing the effectiveness of this method. Our proposed method is also implemented in OMNET++ simulator with results showing the effectiveness of bandwidth ratio differentiation. Shuo Fang, Chuan Heng Foh, Khin Mi Mi Aung |
ICC | 3 |
| 2010 | Dynamic Load Balancing Multipathing in Data Center EthernetabstractCurrently implemented Spanning Tree Protocol (STP) cannot meet the requirement of a data center due to its poor bandwidth utilization and lack of multipathing capability. In this paper, we propose a layer-2 multipathing solution, namely dynamic load balancing multipathing (DLBMP), for data center Ethernets. With DLBMP, traffic between two communication nodes can be spread among multiple paths. The traffic load of all paths is continuously monitored so that traffic split to each path can be dynamically adjusted. In addition, per-flow forwarding is preserved to guarantee in-order frame delivery. Computer simulations show that DLBMP gives much better performance as compared to STP due to its multipathing and dynamic load balancing capability. Khin Mi Mi Aung, Edmund Kheng Kiat Tong, Chuan Heng Foh |
MASCOTS | 2 |
| 2006 | Survival of the Internet Applications: A Cluster Recovery Model
Khin Mi Mi Aung, Kiejin Park, Jong Sou Park |
CCGRID | 1 |
| 2005 | A rejuvenation methodology of cluster recoveryabstractWhile traditional security mechanisms rely on preventive controls and those are very limited in surviving malicious attacks, we propose a novel approach of the security issue to cluster recovery. In this paper, we present the cluster recovery model with a software rejuvenation methodology, which is applicable in security field. We propose two formal approaches, stochastic and Markov decision process. And we estimate the possibility of surviving under unknown attacks. The basic idea of rejuvenation is to investigate the consequences for the exact respond time in face of attacks and rejuvenating the running software/service, refresh its internal state, and resume or restart it. These actions deter the intruder's progress, prevent from more serious damages and provide time to perform more detailed analysis. Khin Mi Mi Aung, Kiejin Park, Jong Sou Park |
CCGRID | 1 |
| 2005 | A Survivability Model for Cluster System Under DoS Attacks
Khin Mi Mi Aung, Kiejin Park, Jong Sou Park, Howon Kim 0001, Byungil Lee |
HPCC | 1 |
| 2005 | A Survivability Model for Cluster System
Khin Mi Mi Aung, Kiejin Park, Jong Sou Park |
ICA3PP | 1 |
| 2004 | A Framework of Software Rejuvenation for SurvivabilityabstractWe propose a novel approach of the security issue to survivability. The main objectives are to detect the attacks in real time, to characterize the attacks, and to survive in face of the attacks. To counteract the attacks' attempts, we perform the software rejuvenation methods (SWRMS) such as killing the intruders' processes in their tracks, halting abuse before it happens, shutting down unauthorized connection, and responding and restarting in real time. These slogans will really frustrate and deter the attacks, as the attackers can't make their progress. This is a way of survivability to maximize the deterrence against the attacks in the target environment. We address a framework to model and analyze the critical intrusion tolerance problems ahead of intrusion detection and we present a set of innovative models to solve the security aging problems. Khin Mi Mi Aung, Jong Sou Park |
AINA (2) | 1 |
| 2004 | Software Rejuvenation Approach to Security Engineering
Khin Mi Mi Aung, Jong Sou Park |
ICCSA (4) | 1 |