VLDB 2026 Research / reviewers in the wild / expert
Jiexin Zhang 0001
dblp:86/3523-1
· DBLP profile ↗
11ranked-venue papers
5as first author
3since 2021 · last 2021
0000-0002-1584-7197ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-authorSecurity and privacy · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Quantitative cyber-physical security analysis methodology for industrial control systems based on incomplete information Bayesian game
Jiexin Zhang 0001, Peidong Zhu, QingPing Tan, Wei Yin 0002 |
Comput. Secur. | 2 |
| 2021 | ZKSENSE: A Friction-less Privacy-Preserving Human Attestation Mechanism for Mobile Devices
Iñigo Querejeta-Azurmendi, Panagiotis Papadopoulos, Matteo Varvello, Antonio Nappa, Jiexin Zhang 0001, Benjamin Livshits |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Factory Calibration Fingerprinting of SensorsabstractDevice fingerprinting aims to generate a distinctive signature, or fingerprint, that uniquely identifies individual computing devices. Fingerprints may be a privacy concern since apps and websites can use them to track user activity online. To protect user privacy, both Android and iOS have included a variety of measures to prevent such tracking. In this paper we present a new type of fingerprinting, factory calibration fingerprinting, that bypasses existing tracking protection. Our attack recovers embedded per-device factory calibration data from the accelerometer, gyroscope, and magnetometer sensors that are pervasive in modern smartphones by careful analysis of the sensor output alone. We discuss the factory calibration behaviour of each sensor and show that the calibration fingerprint is fast to generate, does not change over time or after a factory reset, and can be used to track users across apps and websites without any special permission from the user. We find the calibration fingerprint is very likely to be globally unique for iOS devices, with an estimated 67 bits of entropy for the iPhone 6S. In addition, we have analysed 146 Android device models from 11 vendors and found the attack also works on recent Google Pixel devices. For Pixel 4/4 XL, we estimate the calibration fingerprint provides about 57 bits of entropy. Following our disclosures, Apple deployed a mitigation in iOS 12.2 and Google in Android 11. We analyse Apple's fix and show that the mitigation is imperfect although it is likely to be sufficient in most threat models. Jiexin Zhang 0001, Alastair R. Beresford, Ian Sheret |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | LibID: reliable identification of obfuscated third-party Android librariesabstractThird-party libraries are vital components of Android apps, yet they can also introduce serious security threats and impede the accuracy and reliability of app analysis tasks, such as app clone detection. Several library detection approaches have been proposed to address these problems. However, we show these techniques are not robust against popular code obfuscators, such as ProGuard, which is now used in nearly half of all apps. We then present LibID, a library detection tool that is more resilient to code shrinking and package modification than state-of-the-art tools. We show that the library identification problem can be formulated using binary integer programming models. LibID is able to identify specific versions of third-party libraries in candidate apps through static analysis of app binaries coupled with a database of third-party libraries. We propose a novel approach to generate synthetic apps to tune the detection thresholds. Then, we use F-Droid apps as the ground truth to evaluate LibID under different obfuscation settings, which shows that LibID is more robust to code obfuscators than state-of-the-art tools. Finally, we demonstrate the utility of LibID by detecting the use of a vulnerable version of the OkHttp library in nearly 10% of 3,958 most popular apps on the Google Play Store. Jiexin Zhang 0001, Alastair R. Beresford, Stephan A. Kollmann |
ISSTA | 1 |
| 2019 | SensorID: Sensor Calibration Fingerprinting for SmartphonesabstractSensors are an essential component of many computer systems today. Mobile devices are a good example, containing a vast array of sensors from accelerometers and GPS units, to cameras and microphones. Data from these sensors are accessible to application programmers who can use this data to build context-aware applications. Good sensor accuracy is often crucial, and therefore manufacturers often use per-device factory calibration to compensate for systematic errors introduced during manufacture. In this paper we explore a new type of fingerprinting attack on sensor data: calibration fingerprinting. A calibration fingerprinting attack infers the per-device factory calibration data from a device by careful analysis of the sensor output alone. Such an attack does not require direct access to any calibration parameters since these are often embedded inside the firmware of the device and are not directly accessible by application developers. We demonstrate the potential of this new class of attack by performing calibration fingerprinting attacks on the inertial measurement unit sensors found in iOS and Android devices. These sensors are good candidates because access to these sensors does not require any special permissions, and the data can be accessed via both a native app installed on a device and also by JavaScript when visiting a website on an iOS and Android device. We find we are able to perform a very effective calibration fingerprinting attack: our approach requires fewer than 100 samples of sensor data and takes less than one second to collect and process into a device fingerprint that does not change over time or after factory reset. We demonstrate that our approach is very likely to produce globally unique fingerprints for iOS devices, with an estimated 67 bits of entropy in the fingerprint for iPhone 6S devices. In addition, we find that the accelerometer of Google Pixel 2 and Pixel 3 devices can also be fingerprinted by our approach. Jiexin Zhang 0001, Alastair R. Beresford, Ian Sheret |
IEEE Symposium on Security and Privacy | 1 |
| 2017 | Multidimensional Trust-Based Anomaly Detection System in Internet of Things
Fangyu Gai, Jiexin Zhang 0001, Peidong Zhu, Xinwen Jiang |
WASA | 2 |
| 2017 | Ratee-Based Trust Management System for Internet of Vehicles
Fangyu Gai, Jiexin Zhang 0001, Peidong Zhu, Xinwen Jiang |
WASA | 2 |
| 2017 | Trust on the Ratee: A Trust Management System for Social Internet of VehiclesabstractThe integration of social networking concepts with Internet of Vehicles (IoV) has led to the novel paradigm “Social Internet of Vehicles (SIoV),” which enables vehicles to establish social relationships autonomously to improve traffic conditions and service discovery. There is a growing requirement for effective trust management in the SIoV, considering the critical consequences of acting on misleading information spread by malicious nodes. However, most existing trust models are rater-based, where the reputation information of each node is stored in other nodes it has interacted with. This is not suitable for vehicular environment due to the ephemeral nature of the network. To fill this gap, we propose a Ratee-based Trust Management (RTM) system, where each node stores its own reputation information rated by others during past transactions, and a credible CA server is introduced to ensure the integrality and the undeniability of the trust information. RTM is built based on the concept of SIoV, so that the relationships established between nodes can be used to increase the accuracy of the trustworthiness. Experimental results demonstrate that our scheme achieves faster information propagation and higher transaction success rate than the rater-based method, and the time cost when calculating trustworthiness can meet the demand of vehicular networks. Fangyu Gai, Jiexin Zhang 0001, Peidong Zhu, Xinwen Jiang |
Wirel. Commun. Mob. Comput. | 2 |
| 2016 | A novel optimization scheme for caching in locality-aware P2P networksabstractDeploying cache has been generally adopted by Internet service providers (ISPs) to mitigate P2P traffic in recent years. Most traditional caching algorithms are designed for locality-unaware P2P networks, which mainly consider the requested frequency of contents as the principle of caching policies. However, in more prevalent locality-aware conditions with biased neighbor-selection policies, the existing caching schemes can hardly optimize the situation. In this paper we show that, what need to be cached in locality-aware conditions are the contents that can not be well provided by local neighbors, rather than the contents which are requested most frequently. Therefore, states of local neighbors should be taken into consideration in caching policies. We first present a new model in which P2P cache and locality-aware neighbor selection work together. We focus on inter-ISP traffic and available bandwidth of users in order to benefit both ISPs and users. Based on the mathematical model, a novel caching algorithm is proposed which considers replacement and allocation policies together. According to trace-driven simulations, the proposed algorithm outperforms other two representative caching algorithms in various scenarios. Shaoduo Gan, Jiexin Zhang 0001, Jie Yu 0008, Xiaoling Li 0002, Jun Ma 0015, Lei Luo 0002, Qingbo Wu 0003 |
ISCC | 2 |
| 2016 | Intrusion detection in SCADA systems by traffic periodicity and telemetry analysisabstractSupervisory control and data acquisition (SCADA) system is a vital component of critical infrastructures (CIs). However, most protocols in SCADA systems lack either authentication or integrity checking mechanisms, which makes them extremely vulnerable to cyber attacks when increasingly more SCADA systems are connected with external networks. Intrusion detection systems (IDSs) have been proposed to enhance the system security, but few of them can effectively resist response injection and denial of service attacks at the same time. In this paper we present an IDS named PT-IDS to fill this gap by investigating the periodicity and telemetry patterns of network traffic within typical SCADA systems. Firstly, we analyze the periodicity characteristics in SCADA networks and classify them into four categories through designing an analyzer algorithm. Furthermore, in order to effectively detect response injection attacks, we design an auxiliary module to analyze the network telemetry pattern. Results from both modules are considered simultaneously to promote the accuracy of intrusion detection, especially for denial of service attacks. Beyond that, our proposed system can give alarm reports including both warnings and matching severity information. The time complexity of both analyzer algorithms is polynomial and simulations demonstrate the effectiveness and efficiency of our IDS mechanism. Jiexin Zhang 0001, Shaoduo Gan, Peidong Zhu |
ISCC | 1 |
| 2016 | Cooperation Stimulation and Security in Wireless Ad Hoc Networks - A Power-Efficient Bayesian Game ApproachabstractIn wireless ad hoc networks (WANETs), collaboration among nodes is usually inefficient and the network is vulnerable to various attacks. Although some intrusion detection systems (IDSs) and reputation strategies have been proposed to enhance the network's robustness, the significant power consumption they cause will reduce the networks' lifetime. In this paper, we propose a power-efficient mechanism based on game theoretic analysis to improve the security of WANETs and stimulate the cooperation among nodes. Specifically, we introduce two detection modes for the IDS and formulate the interactions between malicious/regular nodes and IDSs as a Bayesian game. The Nash equilibrium strategies in static Bayesian game model is firstly analyzed, which can not only reduce the probability of misbehaviors (e.g., attacks and non-cooperations) but also prolong the IDS's service time. Then, We extend the static game to a multi-stage imperfect dynamic Bayesian game, in which the IDS updates its belief based on observations and nodes' equilibrium strategy will also change accordingly. Finally, the perfect Bayesian equilibrium (PBE) knowledge is applied to analyze this game, based on which the optimal monitoring scheme for IDS is made out. Simulations on two typical networks demonstrate the effectiveness and practicability of the proposed approach. Jiexin Zhang 0001, Peidong Zhu |
MASCOTS | 1 |