VLDB 2026 Research / reviewers in the wild / expert
Yu Chen 0002
dblp:87/1254-2
· DBLP profile ↗
66ranked-venue papers
7as first author
22since 2021 · last 2026
0000-0003-1880-0586ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 25 · 2 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 since 2021Systems, architecture and hardware · 4 · 2 first-authorSecurity and privacy · 4 · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4Software engineering, systems software and programming languages · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MilliSARImageNet: A 2D High-Resolution Millimeter-Wave SAR Image DatasetabstractMillimeter-wave (mmWave) imaging is a key sensing modality for cyber-physical systems (CPS), enabling applications in autonomous robotics, industrial inspection, and security screening. Yet collecting large, labeled mmWave imaging datasets is costly, limiting progress in robust perception. We present MilliSARImageNet, a high-resolution mmWave imaging dataset that couples a physics-based digital-twin simulation with real measurements from a 77–81 GHz imager. The digital twin replicates the real imager’s geometry, waveform, and reconstruction pipeline, enabling scalable, physically consistent data generation, while the real subset provides an evaluation reference for synthetic-to-real transfer. Images are reconstructed using four imaging algorithms, and targeted augmentations are applied to capture realistic variability. Fine-tuning ConvNeXt-B, Swin-B, ViT-B/16, and ResNet-152 solely on synthetic images yields 95%–98% classification accuracy on unseen synthetic images and 81%–88% on unseen real images. These results show that our digital-twin approach is effective while still revealing a remaining synthetic-to-real domain gap. MilliSARImageNet provides a reproducible foundation for studying domain adaptation and robust, trustworthy mmWave perception in CPS. Lhamo Dorje, Nihal Poredi, Jordan Madden, Soamar Homsi, Yu Chen 0002, Xiaohua Li 0003 |
CCNC | 5 |
| 2026 | Is ENF a Good Physical Fingerprint?abstractElectric Network Frequency (ENF) is a promising physical fingerprint for forensic and security applications. Through comprehensive evaluations using Phasor Measurement Units (PMU) datasets and audio recording datasets, we identify critical limitations in terms of Survival Bias and Tale of Twin Algorithm. To address these limitations, we advocate for a combined environmental fingerprinting approach that integrates multiple side-channel data, such as electromagnetic, acoustic, and illumination signals, to complement and enhance ENF-based authentication. Such multi-signal fusion significantly mitigates the limitations of individual signals, providing a robust framework that is less vulnerable to localized perturbations or adversarial manipulation. Our findings underscore the necessity of hybrid fingerprinting strategies, positioning the combined environmental fingerprint as a highly promising and practical approach to secure critical multimedia authentication, digital twins, and virtual environments in the future. Mohsen Hatami, Lhamo Dorje, Xiaohua Li 0003, Yu Chen 0002 |
CCNC | 4 |
| 2026 | Senior Safety Monitoring in Microverse using Fuzzy Neural Network Enhanced Action RecognitionabstractThe global aging population presents an urgent challenge in ensuring the safety and well-being of senior adults. This paper proposes an innovative Fuzzy Neural Network (FNN)-enhanced Image-based Action Recognition (FIAR) system in Microverse, an edge-scale Internet of Medical Things (IoMT) Metaverse designed for the Department of Homeland Security (DHS). Using adaptive FNNs, FIAR enhances the adaptability of the multisensor fusion process to accommodate varying input modes and quantities of input sources, thus reducing decision uncertainty and learning fuzzy relationships among multiple data streams. An experimental study confirms the feasibility of the Microverse framework and the ability of FIAR to deliver accurate and rapid responses, validating its effectiveness in safeguarding the independent living of elderly individuals. Qian Qu, Lhamo Dorje, Yu Chen 0002, Xiaohua Li 0003 |
CCNC | 4 |
| 2025 | Detecting Manipulated Digital Entities Through Real-World Anchors
Xinyun Liu, Deeraj Nagothu, Qian Qu, Yu Chen 0002 |
AINA (8) | 5 |
| 2025 | Secure Avatars via Environmental Fingerprints for Virtual Health Monitoring ServicesabstractThe emergence of the Metaverse as a virtual extension of our social and professional lives has amplified concerns about identity, security, and authenticity. Advanced Deepfake technologies enable malicious actors to create highly realistic but fraudulent avatars, posing significant risks such as identity theft, misinformation, and erosion of trust within virtual communities. In sensitive applications such as virtual healthcare, these risks can have severe consequences. This paper proposes to Secure Avatars via Environmental Fingerprints (SAVE), a novel method for detecting Deepfake avatars leveraging unique environmental information in the physical world, including Electric Network Frequency (ENF) signals and device-specific sensor readings, to establish an authentication framework that is challenging for impostors to replicate. To evaluate the effectiveness of our SAVE scheme, we conducted a case study within a virtual healthcare application: a Microverse-based nursing home designed to monitor the safety of seniors living alone. Our experimental results demonstrate that SAVE achieves a high detection rate with minimal false positives. Our findings highlight the potential of physical environmental fingerprints as a robust layer of security in virtual worlds, especially in critical applications like virtual healthcare. Qian Qu, Jenny Chen, Deeraj Nagothu, Yu Chen 0002 |
ICC | 5 |
| 2025 | Guest Editorial Special Issue on Security and Privacy of Intelligent VehiclesabstractIntelligent vehicles are systems tightly integrating computation, communication, and physical behavior. The recent proliferation of artificial intelligence, machine learning, the Internet of Things (IoT), and edge-fog–cloud computing envisions that intelligent vehicles are capable of innovative solutions to change our lifestyles. However, the potential benefits come along with new challenges and concerns on security and privacy. This special issue consists of 12 papers and covers broad research contributions, including 1) intrusion detection from in-vehicular networks to connected vehicles, drones, and global positioning systems; 2) authentication with matchmaking encryption, certificateless cryptography, and blockchains for Internet of Vehicles; 3) privacy protection with data sharing and cross-vehicle federated learning; and 4) secure data analysis supported by the cloud. The special issue seeks to assist theoretical analysis, system architecture design, emerging applications, and social impacts of intelligent vehicles. Chung-Wei Lin, Bo Chen 0028, Weizhi Meng 0001, Yu Chen 0002, Qi Zhu 0002 |
IEEE Internet Things J. | 4 |
| 2024 | Detecting Reentrancy Vulnerability in Smart Contracts using Graph Convolution NetworksabstractBecause of many advanced features, Decentralized Finance (DeFi) has become a hot topic in the past decade. As an application of blockchain technology, DeFi allows people to trade cryptocurrencies and other financial products more efficiently, securely, and privately. Specifically, using smart contracts further improves transaction rate and the quality of user experience (QoE) by defining the business logic via code. However, if smart contracts are not audited before compiling on an immutable blockchain, it may result in losses of millions. Therefore, there is a compelling need for efficient and effective measures to ensure the robustness and genuineness of smart contracts. In this paper, we propose a Homogeneous Graph Machine Learning Algorithm for Reentrancy attacks DEtection using Graph Convolution Networks (HARDEN). Reentrancy attacks are one of the most infamous vulnerabilities in smart contracts. The experimental results are encouraging and validate the feasibility of applying a Deep Learning (DL) approach to detect vulnerabilities in smart contracts. We hope this preliminary study will inspire more interest and discussions in the raising area. Hozefa Lakadawala, Komla Dzigbede, Yu Chen 0002 |
CCNC | 3 |
| 2024 | Authenticating AI-Generated Social Media Images Using Frequency Domain AnalysisabstractLiving in the age of social media, it is a daily routine for individuals to post videos, audio, pictures, and text online. In addition, the proliferation of Artificial Intelligence (AI) technology allows customizing multimedia content to meet personal demands. However, the popularity of AI-based text-to-image generators like DeepAI also opens the door to generating images for social media platforms that impersonate unsuspecting users without their permission. While people enjoy high creativity, such “fake” images could enable the propagation of deceptive information that negatively impacts an individual's personal life and potentially cause public unrest. Therefore, reliable methods to facilitate image authentication are vital to identify and flag them. In this paper, we present AUSOME-2, an upgraded version of our system that AUthenticates SOcial MEdia images (AUSOME) using frequency analysis technologies and machine learning (ML) algorithms. Images from several text-to-image platforms, such as Dall-E 2 and Google Deep Dream, are distinguished from genuine images. Spectral analysis techniques are used to obtain features and fingerprints in the frequency domain. These features enable the ML model to classify AI -generated social media images from genuine ones. The experimental results, on top of a proof-of-concept prototype, showed that the AUSOME-2 system is a promising approach to authenticate images with decent detection accuracy. Nihal Poredi, Deeraj Nagothu, Yu Chen 0002 |
CCNC | 3 |
| 2024 | High-Resolution Imaging Capability of Large-Scale LEO Satellite ConstellationsabstractThere has been a great interest in deploying large-scale Low-Earth Orbit (LEO) satellite constellations for wireless communications. This paper shows that LEO satellite constellations developed for communication purposes can be exploited for ground target imaging applications, where a unique advantage is to achieve super-high imaging resolutions that are not achievable via other imaging techniques. A new imaging algorithm is developed for this novel integrated sensing and communication (ISAC) application based on delay-sensitive signal processing and irregular sensing data exploitation. Imaging performance is analyzed. Simulations with the practical SpaceX Starlink satellite orbital data are conducted to verify both the new algorithm and the analysis results. This paper demonstrates that while the resolution of conventional satellite imaging is limited to sub-meters, the new method can potentially use only a small set of LEO satellites to achieve sub-centimeter resolution. Lhamo Dorje, Xiaohua Li 0003, Yu Chen 0002, Nihal Poredi |
ICC | 3 |
| 2023 | Enhance Public Safety Surveillance in Smart Cities by Fusing Optical and Thermal CamerasabstractThe recent advancements in the Internet of Video Things (IoVT) and Edge-Fog-Cloud Computing paradigm make smart public safety surveillance (SPSS) a realistic solution for an effective public safety service in smart cities. Typically, a fully functional SPSS system requires multiple sensory inputs for situational awareness (SAW). As an essential component in the context of highly complex, dynamic, and heterogeneous smart city operations, SPSS is expected to be environment-resilient. Personal safety is among the top concerns of the residents in smart cities, and correspondingly pedestrian detectors are critical. Contemporary pedestrian detectors use optical cameras, whose accuracy is diminished in low-light environments, and they are rendered ineffective when obstacles block the direct line of sight to the camera. Complementary imaging sensors such as infrared have shown promise. This paper presents a full-spectrum, environment-resilient surveillance platform as an ultimate solution, which consists of multiple imaging units to cover a wide sensing spectrum. The initial hybrid pedestrian detection (HYPE) scheme is based on the fusion of data obtained from an IoVT network equipped with optical and thermal cameras. We demonstrate that training the YOLOv5 object detection model on a dataset of infrared images improves its accuracy in the detection of humans present in thermal surveillance images. A 41% decrease in objectness loss is achieved after transfer learning is performed. Nihal Poredi, Yu Chen 0002, Xiaohua Li 0003, Erik Blasch |
FUSION | 2 |
| 2023 | Enforcing Privacy Preservation on Edge Cameras Using Lightweight Video Frame ScramblingabstractPrivacy protecting is a very challenging task in a highly surveilled world with zillions of surveillance cameras deployed. The difficulty mainly lies in the facts: (i) there is not a distinctively defined boundary between usability and privacy, (ii) video frames indiscriminately created and collected by the edge cameras could be abused and intercepted, and (iii) it is difficult to enforce the commonly used compute-intensive standard techniques as-is on the edge cameras because of limited computational resources. In this paper, we propose a lightweight and secure scheme to Enforce Privacy-preservation on Edge Cameras (EnPEC) using deep learning and a sinusoidal chaotic-map. The proposed EnPEC architecture comprises a lightweight frame classifier designed to label frames as offensive and harmless depending on their content to ensure the practice of selective surveillance following a frame approximation process and a novel sinusoidal-map-based chaotic image scrambling technique that enciphers frames color-channel wise to ensure end-to-end privacy of frame contents. The extensive analysis of the functionality, performance and security of the EnPEC scheme, and comparison with related works verify that the EnPEC scheme is more feasible, robust and secure when it runs in real-time on edge cameras equipped with computational power equivalent to the Raspberry PI 4. Alem Fitwi, Yu Chen 0002, Sencun Zhu |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | A Secure Dynamic Edge Resource Federation Architecture for Cross-Domain IoT SystemsabstractThe fast integration of 5G communication, Artificial Intelligence (AI), and Internet-of-Things (IoT) technologies is envisioned to enable Next Generation Networks (NGNs) for diverse smart services and user-defined applications for Smart Cities. However, it is still challenging to build a scalable and efficient infrastructure that satisfies the various performance, security, and management demands by heterogeneous IoT applications across multiple administrative domains. This paper presents a dynamic edge resource federation architecture, which integrates the concept of network slicing (NS) and blockchain to improve scalability, dynamicity, and security for multi-domain IoT applications. A NS-enabled dynamic edge resource federation framework adopts intelligent mechanisms to support efficient multi-domain service coordination that satisfies diverse Quality of Service (QoS) and security requirements. We propose a Hierarchical Integrated Federated Ledger (HIFL), which aims to guarantee decentralized security and privacy-preserving properties in multi-domain resource orchestration and service re-adjustment. As a secure-by-design solution, HIFL is promising to support efficient, trust and secured end-to-end IoT services. A preliminary proof-of-concept prototype has been implemented for comparing intra- and inter-domain performance expectations. Yu Chen 0002, Xiaohua Li 0003, Erik Blasch |
ICCCN | 2 |
| 2022 | Robustness of Electrical Network Frequency Signals as a Fingerprint for Digital Media AuthenticationabstractLeveraging modern Artificial Intelligence (AI) technology, Deepfake attacks manipulate audio/video streams (AVS) to mimic any targeted person or scenario. Deepfake attacks are highly disturbing, and the misinformation can mislead the public, raising further challenges in policy, technical, social, and legal aspects. Electrical Network Frequency (ENF) signals embedded in AVS data are promising to be utilized as fingerprints to authenticate digital media and timely detect deepfaked audio or video. Meanwhile, the success of ENF-based deepfake detection approaches will be forfeited if attackers can create false ENF fingerprints to fool the detector. In this paper, a thorough experimental study validates the robustness of ENF signals as a fingerprint for digital media authentication. Taking statistical, supervised learning, and deep learning approaches, this work shows that it is infeasible to forecast the future ENF signals based on historical records. While strict theoretical proof is yet to be done, this work experimentally verifies ENF signals as a reliable fingerprint to authenticate digital media. Nihal Poredi, Deeraj Nagothu, Yu Chen 0002, Xiaohua Li 0003, Alex Aved, Erika Ardiles-Cruz, Erik Blasch |
MMSP | 3 |
| 2022 | ZoomP3: Privacy-Preserving Publishing of Online Video Conference RecordingsabstractThe COVID-19 epidemic has made online video conferencing extremely popular throughout the world, with many schools, companies and government sectors using video conferencing applications (e.g., Zoom, Google Meet) in a daily basis. These applications also provide local or cloud recording services, which allow the replay or sharing of video conference recordings (VCRs) in a later time. Such convenience, however, can easily cause infringement of privacy as meeting participants’ personally identifiable information (e.g., face, name, voice) may be exposed to the public without their awareness or consent. While privacy regulation and training can help relieve the situation, efficient and effective tools are also highly desired to protect the privacysensitive users in the VCRs before their public releases. In this work, we propose the first Privacy-Preserving Publishing system (ZoomP3 ) that automatically processes video and audio information in VCRs for privacy protection. Besides leveraging and integrating multiple state-of-the-art computer vision and audio processing tools seamlessly into our system, a number of optimization algorithms are proposed to improve the scalability of the system, enabling it to protect the privacy of long video conferences. We have conducted various tests with short and long videos, and the results (with online demos) verified that ZoomP3 system is suitable for largescale use. It may be applied as an online service, e.g., by Zoom, or by large organizations such as universities, research institutes and government sectors. Yuanyi Sun, Sencun Zhu, Yu Chen 0002 |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | μDFL: A Secure Microchained Decentralized Federated Learning Fabric Atop IoT NetworksabstractFederated Learning (FL) has been recognized as a privacy-preserving machine learning (ML) technology that enables collaborative training and learning of a global ML model based on the aggregation of distributed local model updates. However, security and privacy guarantees could be compromised due to malicious participants and the centralized aggregation manner. Possessing attractive features like decentralization, immutability and auditability, Blockchain is promising to enable a tamper-proof and trust-free framework to enhance performance and security in IoT based FL systems. However, directly integrating blockchains into the large scale IoT-based FL scenarios still faces many limitations, such as high computation and storage demands, low transactions throughput, poor scalability and challenges in privacy preservation. This paper proposes$\mu $DFL, a novel hierarchical IoT network fabric for decentralized federated learning (DFL) atop of a lightweight blockchain called microchain. Following the hierarchical infrastructure of FL, participants in$\mu $DFL are fragmented into multiple small scale microchains. Each microchain network relies on a hybrid Proof of Credit (PoC) block generation and Voting-based Chain Finality (VCF) consensus protocol to ensure efficiency and privacy-preservation at the network of edge. Meanwhile, microchains are federated vie a high-level inter-chain network, which adopts an efficient Byzantine Fault Tolerance (BFT) consensus protocol to achieve scalability and security. A proof-of-concept prototype is implemented, and the experimental results verify the feasibility of the proposed$\mu $DFL solution in cross-devices FL settings with efficiency, security and privacy guarantees. Yu Chen 0002 |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2021 | Secure and Privacy-Preserving Stored Surveillance Video Sharing atop Permissioned BlockchainabstractAt present, more than a billion closed-circuit television (CCTV) cameras are watching the world. These cameras garner a lot of visual information that is often processed and stored in remote and centralized cloud servers. Multiple occasions have revealed that this traditional approach is plagued with security and privacy breaches. The breaches could be the interception of raw videos while in transit to distant surveillance analytics centers (SAC), infiltration to cameras and network video records (NVR), or abuse of cameras and stored videos. Hence, the traditional video surveillance system (VSS) cannot guarantee the protection of the privacy of individuals caught on CCTV cameras. Therefore, this paper proposes a Secure and Privacy-preserving Stored surveillance video sharing (SePriS) mechanism for authorized users/nodes based on blockchain (BC), smart contracts, and the enciphering of video frames using DAB, a mechanism developed based on discrete cosine transform (DCT), advanced encryption standard (AES), and a block shuffling (BS) algorithm. The BC-based solution creates an environment auspicious for creating decentralized, reliable SACs and storage sites with secure and privacy-aware sharing of stored surveillance videos across SAC nodes and by law enforcers, police departments, and courts securely connected to the SAC nodes. The experiments and analyses validate that the proposed BC-based SePriS solution achieves the design purpose. Alem Fitwi, Yu Chen 0002 |
ICCCN | 2 |
| 2021 | Fed-DDM: A Federated Ledgers based Framework for Hierarchical Decentralized Data MarketplacesabstractData marketplaces (DMs) promote the benefits of the Internet of Things (IoT) in smart cities. To facilitate the easy exchanges of real-time IoT data streams between device owners and third-party applications, it is required to provide scalable, interoperable, and secured services for large numbers of distributed IoT devices operated by different application vendors. Thanks to decentralization, immutability, and auditability, Blockchain is promising to enable a tamper-proof and trust-free framework to enhance performance and security issues in centralized DMs. However, directly integrating blockchains into large-scale IoT-based DMs still faces many limitations, such as high resource and energy demands, low transaction throughput, poor scalability, and challenges in privacy preservation. This paper introduces a novel Federated Ledgers-based Framework for Hierarchical Decentralized Data Marketplaces (Fed-DDM). In Fed-DDM, participants are divided into multiple permissioned domains given their registrations. Each domain leverages an efficient Byzantine Fault Tolerance (BFT) consensus protocol to commit transactions of a domain on a private intra-ledger. A public inter-ledger network adopts a scalable Proof-of-Work (PoW) consensus protocol to federate multiple private intra-ledger networks. We design a smart contract-enabled inter-ledger protocol to guarantee the security of the cross-domain operations on a public federated ledger without exposing sensitive privacy information from private ledgers. A proof-of-concept prototype is implemented, and the experimental results verify the feasibility of the proposed Fed-DDM solution with performance and security guarantees. Yu Chen 0002 |
ICCCN | 2 |
| 2021 | DeFake: Decentralized ENF-Consensus Based DeepFake Detection in Video ConferencingabstractModern video conferencing technologies provide state-of-the-art end-to-end encryption models but do not verify the authenticity of the media broadcast, where the verification of the media is left to the end-users. A perpetrator can forge the video or audio streams using replay attacks or deepfake attacks to manipulate the real-time perception of transcribed events. Leveraging Electrical Network Frequency (ENF) signals as an environmental fingerprint, this paper proposes a distributed consensus network-based audio authentication scheme named DeFake - Decentralized ENF-consensus based deepFake detection, which detects multimedia manipulations in real-time. Since the fluctuations in an ENF signal are of a distributed and random nature, a novel Proof-of-ENF (PoENF) algorithm can guarantee byzantine resistant deepfakes detection on audio streams with minimal computational resources. By utilizing audio conferencing or audio editing applications as the frontend software service, the DeFake solution can effectively and efficiently verify the authenticity of the recorded video clip. Deeraj Nagothu, Yu Chen 0002, Erik Blasch, Alex Aved |
MMSP | 3 |
| 2021 | Detecting Compromised Edge Smart Cameras using Lightweight Environmental Fingerprint ConsensusabstractRapid advances in the Internet of Video Things (IoVT) deployment in modern smart cities has enabled secure infrastructures with minimal human intervention. However, attacks on audio-video inputs affect the reliability of large-scale multimedia surveillance systems as attackers are able to manipulate the perception of live events. For example, Deepfake audio/video attacks and frame duplication attacks can cause significant security breaches. This paper proposes a Lightweight Environmental Fingerprint Consensus based detection of compromised smart cameras in edge surveillance systems (LEFC). LEFC is a partial decentralized authentication mechanism that leverages Electrical Network Frequency (ENF) as an environmental fingerprint and distributed ledger technology (DLT). An ENF signal carries randomly fluctuating spatio-temporal signatures, which enable digital media authentication. With the proposed DLT consensus mechanism named Proof-of-ENF (PoENF) as a backbone, LEFC can estimate and authenticate the media recording and detect byzantine nodes controlled by the perpetrator. The experimental evaluation shows feasibility and effectiveness of proposed LEFC scheme under a distributed byzantine network environment. Deeraj Nagothu, Yu Chen 0002, Erik Blasch, Alex Aved |
SenSys | 3 |
| 2021 | I-ViSE: Interactive Video Surveillance as an Edge Service Using Unsupervised Feature QueriesabstractSituation awareness (SAW) is essential for many mission-critical applications. However, SAW is challenging when trying to immediately identify objects of interest or focus on suspicious activities from thousands of video frames. This article develops a queryable system to instantly select interesting content. While face recognition technology is mature, in many scenarios, such as public safety monitoring, the features of objects of interest may be much more complicated than face features. In addition, human operators may not be always able to provide a descriptive, simple, and accurate query. Actually, it is more often that there are only rough, general descriptions of certain suspicious objects or accidents. This article proposes interactive video surveillance as an edge service (I-ViSE) based on unsupervised feature queries. Adopting unsupervised methods that do not reveal any private information, the I-ViSE scheme utilizes general features of a human body and color of clothes. An I-ViSE prototype is built following the edge-fog computing paradigm and the experimental results verified the I-ViSE scheme meets the design goal of scene recognition and target analysis in less than 2 s. Seyed Yahya Nikouei, Yu Chen 0002, Alex Aved, Erik Blasch |
IEEE Internet Things J. | 2 |
| 2021 | Lightweight 2D Imaging for Integrated Imaging and Communication ApplicationsabstractWhile integrated sensing and communication has attracted great attention, integrated imaging and communication is still largely open. Microwave, millimeter-wave, and tera-Hz imaging needs to sample a huge number of antenna positions and is thus too complex and costly to mobile communication devices. To address this challenge, we propose a Lightweight Imaging Algorithm (LIA) to reduce the complexity of both imaging hardware and computation. Based on the synthetic aperture radar principle, LIA uses the iterative matrix inversion lemma to estimate image pixels efficiently. Simulations with both simulated and real-world data verified that LIA had superior performance. The algorithm is promising to compact handheld and mobile devices in integrated imaging and communication applications. Xiaohua Li 0003, Yu Chen 0002 |
IEEE Signal Process. Lett. | 2 |
| 2021 | Toward Intelligent Surveillance as an Edge Network Service (iSENSE) Using Lightweight Detection and Tracking AlgorithmsabstractEdge computing extends the realm of information technology beyond the boundaries defined by cloud computing. Performing computation near the sensors, edge computing is promising to address the challenges in many bandwidth-and delay-sensitive applications. Although recently many smart video surveillance approaches based on Machine Learning (ML) algorithms become available, it is still challenging to efficiently migrate those smart algorithms to edge. In this paper, we propose an intelligent Surveillance as an Edge Network Service (iSENSE), which explores the feasibility of moving ML to the edge by testing two popular human-object detection schemes. Besides, a lightweight Convolutional Neural Network (L-CNN) is introduced to improve computational execution by leveraging the depth-wise separable convolution. To enhance performance on edge, we propose a hybrid lightweight tracking algorithm, Kerman (Kernelized Kalman filter), which is a decision tree based hybrid Kernelized Correlation Filter algorithm designed for human-object tracking. We have implemented both Kerman and L-CNN algorithms on edge by using different types of single board computers. The proposed iSENSE system was validated using both real-world campus surveillance video and open image sets. The experimental results present that the proposed algorithms can track the human objects in real-time with a good accuracy with limited resource in edge devices. Seyed Yahya Nikouei, Yu Chen 0002, Sejun Song, Baek-Young Choi, Timothy R. Faughnan |
IEEE Trans. Serv. Comput. | 2 |
| 2020 | Privacy-Preserving Selective Video SurveillanceabstractThe pervasive and intrusive surveillance practices have raised a widespread concern amongst zillions of people about the invasion of their privacy. The privacy breaches in the existing mass-surveillance system are mainly attributed to the exploits of vulnerabilities by adversaries and abuse of cameras by people in charge of them. As a result, there has been a tremendously pressing demand from the public to make the surveillance system privacy-conscious. In this paper, we propose PriSev, a privacy-preserving selective video surveillance method, which enables selective-surveillance where only video frames containing aggressive and suspicious behavioral patterns, like gun brandishing or/and fist-raising, are made available for view by security personnel in the surveillance operation center and for storage. By introducing a lightweight dynamic chaotic image enciphering (DyCIE) scheme, the proposed PriSev method enables onsite object detection and frame encryption at the network edge where the video is created. At the fog/cloud layer, frame decryption is efficiently performed followed by deep-neural-network (DNN) based frame-filtering and selective storage that runs on a surveillance server. In addition, a multiagent system is introduced for the exchange of deciphering keys between the sending and receiving agents. Extensive experimental study and performance analyses corroborate that the proposed PriSev method is able to efficiently perform a privacy-preserving selective surveillance in real-time. Alem Fitwi, Yu Chen 0002 |
ICCCN | 2 |
| 2020 | Minor Privacy Protection Through Real-time Video Processing at the EdgeabstractThe collection of a lot of personal information about individuals, including the minor members of a family, by closed-circuit television (CCTV) cameras creates a lot of privacy concerns. Particularly, revealing children's identifications or activities may compromise their well-being. In this paper, we investigate lightweight solutions that are affordable to edge surveillance systems, which is made feasible and accurate to identify minors such that appropriate privacy-preserving measures can be applied accordingly. State of the art deep learning architectures are modified and re-purposed in a cascaded fashion to maximize the accuracy of our model. A pipeline extracts faces from the input frames and classifies each one to be of an adult or a child. Over 20,000 labeled sample points are used for classification. We explore the timing and resources needed for such a model to be used in the Edge-Fog architecture at the edge of the network, where we can achieve near real-time performance on the CPU. Quantitative experimental results show the superiority of our proposed model with an accuracy of 92.1% in classification compared to some other face recognition based child detection approaches. Seyed Yahya Nikouei, Alem Fitwi, Yu Chen 0002, Yunxi Dong |
ICCCN | 4 |
| 2020 | iRyP: a purely edge-based visual privacy-respecting system for mobile camerasabstractWith the growing popularity of mobile devices that have built-in cameras, capturing images has become a trivial job for ordinary people, who share the images with their friends or the public online. However, such digital images are often taken without the consent of some photographed persons, hence leading to privacy concerns. In this paper, we propose iRyP, a purely edge-based privacy-respecting system for mobile cameras. In order to meet the requirements of efficiency and usability, we propose to piggyback privacy policies in the advertising messages of Bluetooth Low Energy (BLE), which has been widely deployed in most mobile devices. As such, privacy policies of people in a photo view can be delivered timely and automatically. Moreover, we propose to use a perceptual hashing algorithm for fast face matching. To improve detection accuracy, we also design several new techniques for face-related image processing. We implement and evaluate a prototype system purely based on the Android platform. Our experiments show that iRyP can meet our design requirements and is practical and ready to use. Yuanyi Sun, Shiqing Chen, Sencun Zhu, Yu Chen 0002 |
WISEC | 4 |
| 2020 | Wireless multimedia surveillance networks
Seungmin Rho, Yu Chen 0002 |
Multim. Tools Appl. | 2 |
| 2019 | Kerman: A Hybrid Lightweight Tracking Algorithm to Enable Smart Surveillance as an Edge ServiceabstractEdge computing pushes the cloud computing boundaries beyond uncertain network resource by leveraging computational processes close to the source and target of data. Time-sensitive and data-intensive video surveillance applications benefit from on-site or near-site data mining. In recent years, many smart video surveillance approaches are proposed for object detection and tracking by using Artificial Intelligence (AI) and Machine Learning (ML) algorithms. However, it is still hard to migrate those computing and data-intensive tasks from Cloud to Edge due to the high computational requirement. In this paper, we envision to achieve intelligent surveillance as an edge service by proposing a hybrid lightweight tracking algorithm named Kerman (Kernelized Kalman filter). Kerman is a decision tree based hybrid Kernelized Correlation Filter (KCF) algorithm proposed for human object tracking, which is coupled with a lightweight Convolutional Neural Network (L-CNN) for high performance. The proposed Kerman algorithm has been implemented on a couple of single board computers (SBC) as edge devices and validated using real-world surveillance video streams. The experimental results are promising that the Kerman algorithm is able to track the object of interest with a decent accuracy at a resource consumption affordable by edge devices. Seyed Yahya Nikouei, Yu Chen 0002, Sejun Song, Timothy R. Faughnan |
CCNC | 2 |
| 2019 | Social Internet of Things: Applications, architectures and protocols
Seungmin Rho, Yu Chen 0002 |
Future Gener. Comput. Syst. | 2 |
| 2018 | Real-Time Human Objects Tracking for Smart Surveillance at the EdgeabstractAllowing computation to be performed at the edge of a network, edge computing has been recognized as a promising approach to address some challenges in the cloud computing paradigm, particularly to the delay-sensitive and mission-critical applications like real-time surveillance. Prevalence of networked cameras and smart mobile devices enable video analytics at the network edge. However, human objects detection and tracking are still conducted at cloud centers, as real-time, online tracking is computationally expensive. In this paper, we investigated the feasibility of processing surveillance video streaming at the network edge for real-time, uninterrupted moving human objects tracking. Moving human detection based on Histogram of Oriented Gradients (HOG) and linear Support Vector Machine (SVM) is illustrated for features extraction, and an efficient multi-object tracking algorithm based on Kernelized Correlation Filters (KCF) is proposed. Implemented and tested on Raspberry Pi 3, our experimental results are very encouraging, which validated the feasibility of the proposed approach toward a real-time surveillance solution at the edge of networks. Seyed Yahya Nikouei, Yu Chen 0002, Aleksey Polunchenko, Sejun Song, Chengbin Deng, Timothy R. Faughnan |
ICC | 3 |
| 2018 | A Novel PMU Fog Based Early Anomaly Detection for an Efficient Wide Area PMU NetworkabstractBased on phasor measurement units (PMUs), a synchronphasor system is widely recognized as a promising smart grid measurement system. It is able to provide high-frequency, high-accuracy phasor measurements sampling for Wide Area Monitoring and Control (WAMC) applications.However,the high sampling frequency of measurement data under strict latency constraints introduces new challenges for real time communication. It would be very helpful if the collected data can be prioritized according to its importance such that the existing quality of service (QoS) mechanisms in the communication networks can be leveraged. To achieve this goal, certain anomaly detection functions should be conducted by the PMUs. Inspired by the recent emerging edge-fog-cloud computing hierarchical architecture, which allows computing tasks to be conducted at the network edge, a novel PMU fog is proposed in this paper. Two anomaly detection approaches, Singular Spectrum Analysis (SSA) and K-Nearest Neighbors (KNN), are evaluated in the PMU fog using the IEEE 16-machine 68-bus system. The simulation experiments based on Riverbed Modeler demonstrate that the proposed PMU fog can effectively reduce the data flow end-to-end (ETE) delay without sacrificing data completeness. Yu Chen 0002 |
ICFEC | 3 |
| 2018 | Constructing Trustworthy and Safe Communities on a Blockchain-Enabled Social Credits SystemabstractThe emergence of big data and Artificial Intelligence (AI) technology is reshaping the world. While the technological revolution improves the quality of our life, new concerns are triggered. The superhuman capability enables AI to outperform human workers in many data-and/or computing-intensive tasks. Also, digital superpowers are showing arrogance towards individuals, which erodes the trust foundation of the society. In this position paper, we suggest to construct trustworthy and safe communities based on a BLockchain-Enabled Social credits System (BLESS) that rewards the residents who commit in socially beneficial activities. Human being's true value lies in serving other people. The BLESS system is considered as an efficient approach to promote the value and dignity in efforts focused on enhancing our communities and regulating business and private behaviors. The BLESS system leverages the decentralized architecture of the blockchain network, which not only allows grassroots individuals to participate rating process of a social credit system (SCS), but also provides tamper proof of transaction data in the trustless network environment. The anonymity in blockchain records also protects individuals from being targeted in the fight against powerful enterprises. Smart contract enabled authentication and authorization strategy prevents any unauthorized entity from accessing the credit system. The BLESS scheme is promising to offer a secure, transparent and decentralized SCS. Xuheng Lin, Yu Chen 0002 |
MobiQuitous | 4 |
| 2018 | An Adaptive Primary User Emulation Attack Detection Mechanism for Cognitive Radio Networks
Yu Chen 0002, Xiaohua Li 0003, Kai Zeng 0001, Roger Zimmermann |
SecureComm (1) | 2 |
| 2018 | Social Internet of Things: Applications, architectures and protocols
Seungmin Rho, Yu Chen 0002 |
Future Gener. Comput. Syst. | 2 |
| 2018 | Local Differential Privately Anonymizing Online Social Networks Under HRG-Based ModelabstractFollowing the trend of online social networks (OSNs) data sharing and publishing, users raise serious concerns on OSN privacy. Differential privacy is a mechanism to anonymize sensitive data. It employs graph abstraction models, such as the hierarchical random graph (HRG) model, to extract graph features and then add sufficient noise. However, the noise amount, determined by the sensitivity, is usually proportional to the size of the whole network. Therefore, achieving global differential privacy may harm the utility of releasing graphs. In this paper, we define the notion of group-based local differential privacy. In particular, by resolving the network into 1-neighborhood graphs and applying HRG-based methods, our scheme preserves differential privacy and reduces the noise scale on the local graphs. By deploying the grouping algorithm, our scheme abandons the attempt to anonymize every relationship to be ordinary, but we focus on the similarities in HRG models. In the final released graph, each individual user in one group is not distinguishable, which greatly enhances the OSN privacy. We experimentally evaluate our approach on three real-world OSNs. It produces synthetic graphs that are more closely matched with the originals compared with the existing differential-privacy results. Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2017 | Preserving Local Differential Privacy in Online Social Networks
Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou |
WASA | 3 |
| 2016 | Intelligence Measure of Cognitive Radios with Learning CapabilitiesabstractCognitive radio (CR) is considered as a key enabling technology for dynamic spectrum access to improve spectrum efficiency. Although the CR concept was invented with the core idea of realizing "cognition", the research on measuring CR cognition capabilities and intelligence is largely open. Deriving the intelligence capabilities of CR not only can lead to the development of new CR technologies, but also makes it possible to better configure the networks by integrating CRs with different intelligence capabilities in a more cost- efficient way. In this paper, for the first time, we propose a data-driven methodology to quantitatively analyze the intelligence factors of the CR with learning capabilities. The basic idea of our methodology is to run various tests on the CR in different spectrum environments under different settings and obtain various performance results on different metrics. Then we apply factor analysis on the performance results to identify and quantize the intelligence capabilities of the CR. More specifically, we present a case study consisting of sixty three different types of CRs. CRs are different in terms of learning-based dynamic spectrum access strategies, number of sensors, sensing accuracy, and processing speed. Based on our methodology, we analyze the intelligence capabilities of the CRs through extensive simulations. Four intelligence capabilities are identified for the CRs through our analysis, which comply with the nature of the tested algorithms. Monireh Dabaghchian, Amir Alipour-Fanid, Kai Zeng 0001, Xiaohua Li 0003, Yu Chen 0002 |
GLOBECOM | 6 |
| 2016 | A Robust and Reusable ECG-Based Authentication and Data Encryption Scheme for eHealth SystemsabstracteHealth systems generate from the integration of information and communication technologies with traditional healthcare systems. They have widely replaced paper-based systems due to their prominent features of convenience and accuracy. However, eHealth systems also face many challenges, such as the privacy and security concerns over patients' identities and their personal health records (PHRs). Traditional cryptographic approaches are only capable of verifying ``what you possess" or ``what you remember" with the help of trust authorities. As a result, they are not suitable for medical applications and cannot handle above concerns effectively. Using biometrics can verify ``who you are" due to permanence, distinctiveness, and undeniability properties of biometrics. It outstands conventional authentication and encryption approaches in eHealth systems. A promising one among all is the ECG (ElectroCardioGram) signal, which is easier to implement than other biometrics. Unfortunately, most of existing works do not take the nonuniformity of ECG signals into consideration. Besides, they do not protect ECG signals well despite their sensitivity. Hence, we propose a robust and reusable authentication and encryption scheme based on ECG signals for eHealth systems. Our scheme can authenticate patients' identities and protect their PHRs, enable the reuse of the same ECG signal, and preserve the privacy of ECG signals. Theoretical and empirical evaluations demonstrate the security, effectiveness, and efficiency of the proposed scheme. Pei Huang 0005, Borui Li 0002, Linke Guo, Zhanpeng Jin, Yu Chen 0002 |
GLOBECOM | 5 |
| 2016 | Integration of machine learning and human learning for training optimization in robust linear regressionabstractIn this paper machine learning and human learning are applied jointly to optimize the training of linear regression. Human learning is exploited to label extra training data so as to resolve problems such as insufficient training and over-fitting. Considering the inevitable human errors in labeling, two machine learning algorithms are developed which optimize the selection of the extra training data and detect human errors during linear regression. The first algorithm assumes sparse human errors and implements a sparse optimization within a sequential active learning procedure. The second algorithm deals with non-sparse human errors. By exploiting the IRT (item response theory) to model the distribution of human errors, it reconstructs the training data set so that the human labeling errors become sparse. Simulations are conducted to show that the two algorithms are effective in resolving the insufficient training and human labeling error problems. Xiaohua Li 0003, Yu Chen 0002, Kai Zeng 0001 |
ICASSP | 2 |
| 2015 | Pseudo-real-time Wide Area Motion Imagery (WAMI) processing for dynamic feature detection
Ryan Wu, Bingwei Liu, Yu Chen 0002, Erik Blasch, Haibin Ling, Genshe Chen |
FUSION | 3 |
| 2015 | Singular Spectrum Analysis Based Quick Online Detection of Disturbance Start Time in Power GridabstractTimely detection of the start time and location of disturbance is critical to power grid. The information helps operators quickly catch the disturbance events over wide areas and allows time for taking remedial reactions. In this paper, we proposed to detect the start time point of disturbance using Singular Spectrum Analysis (SSA), which has been proved to be an effective technique in the area of time series analysis for change-point detection. Using the simulation data generated by Power System Tool box, we compared the SSA algorithm with the Event Start Time (EST) algorithm. The experimental results have shown that our SSA algorithm is not only faster and more robust in the noisy environments, but also is able to capture more subtle disturbance that the EST cannot detect. Aleksey Polunchenko, Yu Chen 0002 |
GLOBECOM | 4 |
| 2015 | Ultra-lightweight deep packet anomaly detection for Internet of Things devicesabstractAs we race toward the Internet of Things (IoT), small embedded devices are increasingly becoming network-enabled. Often, these devices can't meet the computational requirements of current intrusion prevention mechanisms or designers prioritize additional features and services over security; as a result, many IoT devices are vulnerable to attack. We have developed an ultra-lightweight deep packet anomaly detection approach that is feasible to run on resource constrained IoT devices yet provides good discrimination between normal and abnormal payloads. Feature selection uses efficient bit-pattern matching, requiring only a bitwise AND operation followed by a conditional counter increment. The discrimination function is implemented as a lookup-table, allowing both fast evaluation and flexible feature space representation. Due to its simplicity, the approach can be efficiently implemented in either hardware or software and can be deployed in network appliances, interfaces, or in the protocol stack of a device. We demonstrate near perfect payload discrimination for data captured from off the shelf IoT devices. Douglas H. Summerville, Kenneth M. Zach, Yu Chen 0002 |
IPCCC | 3 |
| 2015 | Cloud, grid, P2P and internet computing: Recent trends and future directions
Sang-Soo Yeo, Yu Chen 0002, Cho-Li Wang |
Peer-to-Peer Netw. Appl. | 2 |
| 2014 | A study of SSL Proxy attacks on Android and iOS mobile applicationsabstractAccording to recent articles in popular technology websites, some mobile applications function in an insecure manner when presented with untrusted SSL certificates. These non-browser based applications seem to, in the absence of a standard way of alerting a user of an SSL error, accept any certificate presented to it. This paper intends to research these claims and show whether or not an invisible proxy based SSL attack can indeed steal user's credentials from mobile applications, and which types applications are most likely to be vulnerable to this attack vector. To ensure coverage of the most popular platforms, applications on both Android 4.2 and iOS 6 are tested. The results of our study showed that stealing credentials is indeed possible using invisible proxy man in the middle attacks. John Hubbard, Ken Weimer, Yu Chen 0002 |
CCNC | 3 |
| 2014 | Enabling Smart Personalized Healthcare: A Hybrid Mobile-Cloud Approach for ECG TelemonitoringabstractThe severe challenges of the skyrocketing healthcare expenditure and the fast aging population highlight the needs for innovative solutions supporting more accurate, affordable, flexible, and personalized medical diagnosis and treatment. Recent advances of mobile technologies have made mobile devices a promising tool to manage patients' own health status through services like telemedicine. However, the inherent limitations of mobile devices make them less effective in computation- or data-intensive tasks such as medical monitoring. In this study, we propose a new hybrid mobile-cloud computational solution to enable more effective personalized medical monitoring. To demonstrate the efficacy and efficiency of the proposed approach, we present a case study of mobile-cloud based electrocardiograph monitoring and analysis and develop a mobile-cloud prototype. The experimental results show that the proposed approach can significantly enhance the conventional mobile-based medical monitoring in terms of diagnostic accuracy, execution efficiency, and energy efficiency, and holds the potential in addressing future large-scale data analysis in personalized healthcare. Xiaoliang Wang 0003, Qiong Gui, Bingwei Liu, Zhanpeng Jin, Yu Chen 0002 |
IEEE J. Biomed. Health Informatics | 5 |
| 2013 | Scalable sentiment classification for Big Data analysis using Naïve Bayes ClassifierabstractA typical method to obtain valuable information is to extract the sentiment or opinion from a message. Machine learning technologies are widely used in sentiment classification because of their ability to “learn” from the training dataset to predict or support decision making with relatively high accuracy. However, when the dataset is large, some algorithms might not scale up well. In this paper, we aim to evaluate the scalability of Naïve Bayes classifier (NBC) in large datasets. Instead of using a standard library (e.g., Mahout), we implemented NBC to achieve fine-grain control of the analysis procedure. A Big Data analyzing system is also design for this study. The result is encouraging in that the accuracy of NBC is improved and approaches 82% when the dataset size increases. We have demonstrated that NBC is able to scale up to analyze the sentiment of millions movie reviews with increasing throughput. Bingwei Liu, Erik Blasch, Yu Chen 0002, Dan Shen 0004, Genshe Chen |
IEEE BigData | 3 |
| 2013 | An optimized design of reconfigurable PSD accelerator for online shrew DDoS attacks detectionabstractShrew Distributed Denial-of-Service (DDoS) attacks are stealthy, concealing their malicious activities in normal traffic. Although it is difficult to detect shrew DDoS attacks in the time domain, the existent energy exposes them in frequency domain. For this purpose, online Power Spectral Density (PSD) analysis necessitates real-time PSD data conversion. In this paper, an optimized FPGA based accelerator for real-time PSD conversion is proposed, which is based on our innovative component-reusable Auto-Correlation (AC) algorithm and the adapted 2N-point real-valued Discrete Fourier Transform (DFT) algorithm. Further optimization is achieved through the exploration of algorithm characteristics and hardware parallelism for this case. Evaluation results from both simulation and synthesis are provided. The overall design can be easily placed in a Xilinx Virtex2 Pro FGPA. Hao Chen 0006, Yu Chen 0002, Douglas H. Summerville, Zhou Su 0001 |
INFOCOM | 2 |
| 2013 | Behavioral Modeling for Suspicious Process Detection in Cloud Computing EnvironmentsabstractOne of the defining features of cloud computing, multi-tenancy provides significant benefits to both clients and service providers by supporting elastic on-demand resource provisioning and efficient resource allocation. However, this architecture also introduces additional security implications. Client virtual machine (VM) instances running on the same physical machine are susceptible to side-channel and escape-to-hypervisor attacks. Timely detection/mitigation of intrusive behaviors of malicious processes using signature based intrusion detection technologies or system call level anomaly analysis due to high false alarm rate presents a challenging task. In this work, a behavioral modeling scheme is proposed to detect suspicious processes on the highest semantic level. Our preliminary results have validated the effectiveness and efficiency of this novel approach. Andrey M. Dolgikh, Zachary Birnbaum, Yu Chen 0002, Victor A. Skormin |
MDM (2) | 3 |
| 2013 | Cloud Security Auditing Based on Behavioral ModelingabstractMulti-tenancy is one of the most attractive features of cloud computing, which provides significant benefits to both clients and service providers by supporting elastic, efficient, and on-demand resource provisioning and allocation. However, this architecture also introduces additional security implications. Client Virtual Machine (VM) instances running on the same physical machine are susceptible to side-channel and escape-to-hypervisor attacks. The timely prevention of intrusive behavior and malicious processes using signature based intrusion detection technologies, or system call level anomaly analysis is a very challenging task due to a high rate of false alarms. In this work, a behavioral modeling scheme is proposed to audit the behaviors of client VMs and to detect suspicious processes on the highest semantic level. Our preliminary results have validated the effectiveness and efficiency of this novel approach. Zachary Birnbaum, Bingwei Liu, Andrey M. Dolgikh, Yu Chen 0002, Victor A. Skormin |
SERVICES | 4 |
| 2012 | An extension of RDP code with parallel decoding procedureabstractXOR based RAID 6 systems outperform other RAID systems. Among the XOR (exclusive OR) based RAID-6 schemes, RDP has better performance than others by a narrow margin. However, the RDP code scheme cannot take full advantage of parallel hardware implementation of XOR codes. In this paper, we propose an extension of the double-erasure-correcting RDP code called EDP, which consists of a parallel decoding scheme. Thus, EDP can improve the decoding velocity of RDP by about 40% without any change to the current RDP configuration for storage. Yu Chen 0002, Douglas H. Summerville, Zhou Su 0001 |
CCNC | 2 |
| 2011 | A location aware virtual infrastructure for VANETsabstractThe dynamical network topology is the source of most challenges in VANETs (Vehicle Ad hoc Networks). In urban area, however, it is feasible to meet the challenge by taking advantage of the heavy traffic. This paper proposes a location aware virtual infrastructure (LAVI) based on recognition memory. Combining the memory of past cooperation with the location information, the mobile nodes can construct cooperative groups with recognized peers and in turn to provide a virtual infrastructure. Yu Chen 0002, Chih-Jye Wang, Wei-Shinn Ku, Zhou Su 0001 |
CCNC | 1 |
| 2011 | Enhancing cloud storage security against roll-back attacks with a new fair multi-party non-repudiation protocolabstractAlong with variant advantages, cloud storage also poses new security challenges. Potential users are reluctant to move important and sensitive data to cloud unless security challenges have been well addressed. This paper reports our on-going efforts to address three data security issues in cloud storage: repudiation, fairness, and roll-back attacks. We proposed a novel fair multi-party non-repudiation (MPNR) protocol, which provide a fair non-repudiation storage cloud and is capable of preventing roll-back attacks. Yu Chen 0002, Douglas H. Summerville, Wei-Shinn Ku, Zhou Su 0001 |
CCNC | 2 |
| 2011 | Consistency Control to Manage Dynamic Contents over Vehicular Communication NetworksabstractTo improve driving comfort and provide entertainment services, vehicular communication networks (VCNs) have appeared as an emerging solution, which consists of road-side units (RSUs) and on-board units (OBUs) to distribute multimedia contents. However, as most of OBUs always request the stored contents in the RSUs, how to update the contents in these RSUs when the original changes at its original servers has become an important issue to be dealt with. This paper proposes a novel method to resolve the above problem. Firstly, based on the characteristics of peers and geographical information, we decide which replica of which content in RSUs should be updated when its original changes. Secondly, by comparing the delivery cost of wired and wireless transmission, we decide whether the updated content should be delivered from a fixed peer or other mobile peers. Lastly, the detailed algorithm is presented and summarized. Zhou Su 0001, Pinyi Ren, Yu Chen 0002 |
GLOBECOM | 3 |
| 2011 | Mitigating DDoS Attacks Using Protection Nodes in Mobile Ad Hoc NetworksabstractMobile Ad Hoc Networks (MANETs) allow mobile hosts to form a communication network without a prefixed infrastructure. Although it provides high flexibility, it also brings more challenges for MANETs to fight against malicious attacks. However, the property of mobility and redundancy also inspires new ideas to design defence strategy. In this paper, we propose a strategy to mitigate DDoS attacks in MANETs. Assume that a malicious attacker normally targets specific victims. The attacker will give up if the attack failed to achieve the desired goals after a certain length of attacking time. In our protection strategy, we take advantage of high redundancy and select a protection node. Once a DDoS attack has been detected, the suspicious traffic will be redirected to the protection node. The victim will function normally, and it is reasonable to expect that the attacker will stop the meaningless efforts. Through intensive simulation experiment using NS-2, we have verified the effectiveness of our approach and evaluated the cost and overhead of the system. Minda Xiang, Yu Chen 0002, Wei-Shinn Ku, Zhou Su 0001 |
GLOBECOM | 2 |
| 2010 | A Novel DDoS Attack Defending Framework with Minimized Bilateral DamagesabstractDistributed Denial of Service (DDoS) attacks are one of the most damaging threats against Internet based applications. Many of the DDoS defense mechanisms may unintentionally deny a certain portion of legitimate user accesses by mistaking them as attackers or may simply not block enough traffic to adequately protect the victim. Other better performing systems have not yet to reach adoption because of designs that require a substantial investment into the Internet infrastructure before offering much effectiveness. This paper proposes Heimdall, a novel traffic verification based framework to protect legitimate traffic from bilateral damages. Based on a proof-of-work technique and application of distributed hash ID, aside from protecting established connections, our system can validate new initial request for communication and open valid channels between users and the protected server. Through intensive simulation experiments on the ns-2 network simulator, we verified that Heimdall scheme can effectively protect legitimate communications and filter out malicious flows with very high accuracy. Yu Chen 0002, Wei-Shinn Ku, Kazuya Sakai, Christopher DeCruze |
CCNC | 1 |
| 2010 | Bridging the Missing Link of Cloud Data Storage Security in AWSabstractThe data that is stored and/or transmitted on the Internet has been called "the blood of the IT". Along with the infrastructure and network based applications, data storage has been recognized as one of the major dimensions of information technology. The prosperity of Cloud Computing requires the moving from server-attached storage to distributed storage. Along with variant advantages, the distributed storage also poses new challenges in creating a secure and reliable data storage and access facility over insecure or unreliable service providers. The security of data stored in the cloud is one of the challenges to be addressed before the novel pay-as-you-go business model is applied widely. In this research, we revealed the vulnerability in the Amazon's AWS cloud and discussed technical approaches towards potential effective solutions. Yu Chen 0002, Pu Liu |
CCNC | 2 |
| 2010 | A comparison study of collaborative strategies for distributed defense against Internet worms based on small-world modelingabstractThe prosperity of the Internet has made it attractive to hackers and malicious attackers. Internet worms have become one type of major threats to the network infrastructure. Distributed defense collaborating with single-point-deployed security applications over multiple network domains are promising Hao Chen 0006, Yu Chen 0002 |
CollaborateCom | 2 |
| 2010 | D-DOG: Securing Sensitive Data in Distributed Storage Space by Data Division and Out-Of-Order Keystream GenerationabstractMigrating from server-attached storage to distributed storage brings new vulnerabilities in creating a secure data storage and access facility. Particularly it is a challenge on top of insecure networks or unreliable storage service providers. For example, in applications such as cloud computing where data storage is transparent to the owner. It is even harder to protect the data stored in unreliable hosts. More robust security scheme is desired to prevent adversaries from obtaining sensitive information when the data is in their hands. Meanwhile, the performance gap between the execution speed of security software and the amount of data to be processed is ever widening. A common solution to close the performance gap is through hardware implementation. This paper proposes D-DOG (Data Division and Out-of-order keystream Generation), a novel encryption method to protect data in the distributed storage environments. Aside from verifying the correctness and effectiveness of the D-DOG scheme through theoretical analysis and experimental study, we also preliminarily evaluated its hardware implementation. Yu Chen 0002, Wei-Shinn Ku, Zhou Su 0001 |
ICC | 2 |
| 2010 | Breaking and Fixing the Self Encryption Scheme for Data Security in Mobile DevicesabstractData security is one of the major challenges that prevents the wider acceptance of mobile devices, especially within business and government environments. It is non-trivial to protect private and sensitive data stored in these devices due to the limited resources and computing power, particularly when they fall in the hand of an adversary. Previously Chen and Ku proposed a lightweight data encryption and storage scheme named Self-Encryption (SE) to meet the challenge. However, our recent research revealed that there are critical weaknesses in SE. This paper presents the detailed analysis of the weaknesses of SE scheme and proposes a solution to remove the flaws in SE. Through real-world measurements on top of the iPhone platform, we verified the effectiveness of our proposal. Paolo Gasti, Yu Chen 0002 |
PDP | 2 |
| 2009 | Self-Encryption Scheme for Data Security in Mobile DevicesabstractThe pervasive use of wireless networks and mobile devices has been changing our living style significantly. Along with great convenience and efficiency, there are new challenges in protecting sensitive and/or private data carried in these devices. The most challenging part lies in a dilemma: while it should be computationally infeasible for adversaries to decrypt the data, the cryptographic operation should be efficient for legitimate users and minimize battery drain. This paper proposes a novel data encryption and storage scheme to address this challenge. Treating the data as a binary bit stream, our self-encryption (SE) scheme generates a keystream by randomly extracting bits from the stream. The length of the keystream depends on the user's security requirements. The bit stream is encrypted and the ciphertext is stored on the mobile device, whereas the keystream is stored separately. This makes it computationally not feasible to recover the original data stream from the ciphertext alone. Yu Chen 0002, Wei-Shinn Ku |
CCNC | 1 |
| 2009 | BLINK: Securing Information to the Last ConnectionabstractRobust cryptography provides confidentiality and integrity for information transferred between peers. However, the decrypted plaintext in the memory of a receivers' computer is vulnerable - both to surveillance at the endpoints, and users who choose to forward confidential information. In this paper, we proposed a novel scheme called BLINK, which uses a reconfigurable hardware based decoder which operates on the link between a computer and its display. It moves the decryption outside the computer, preventing plaintext stealing, forwarding, screen capture and printing. Currently we are implementing the BLINK scheme on top of Altera FPGA board with Digital Visual Interface (DVI) ports, the correctness, effectiveness, and the performance will be evaluated through experiment. Scott Craver, Yu Chen 0002, Hao Chen 0006, Idris M. Atakli |
CCNC | 2 |
| 2009 | Weighted trust evaluation-based malicious node detection for wireless sensor networksabstractAbstract: Deployed in a hostile environment, the individual Sensor Node (SN) of a Wireless Sensor Network (WSN) could be easily compromised by an adversary due to constraints such as limited memory space and computing capability. Therefore, it is critical to detect and isolate compromised nodes in order to avoid being misled by the falsified information injected by adversaries through compromised nodes. However, it is challenging to secure the flat topology networks effectively because of the poor scalability and high communication overhead. On top of a hierarchical WSN architecture, a novel algorithm based on Weighted Trust Evaluation (WTE) to detect malicious nodes for hierarchical sensor networks is proposed in this paper. The hierarchical network can reduce the communication overhead among SNs by utilising clustered topology. The proposed algorithm models a cluster of SNs and detects malicious nodes by examining their weights that represent the reliability of SNs. Through intensive simulations, the accuracy and effectiveness of the proposed detection algorithm are verified. Hongbing Hu, Yu Chen 0002, Wei-Shinn Ku, Zhou Su 0001, Chung-Han Chen |
Int. J. Inf. Comput. Secur. | 2 |
| 2007 | Spectral Analysis of TCP Flows for Defense Against Reduction-of-Quality AttacksabstractThe RoQ (reduction-of-quality) attacks are low- rate DDoS attacks that degrade the QoS to end systems stealthily but not to deny the services completely. These attacks are more difficult to detect than the flooding DDoS attacks. This paper explores the energy distributions of Internet traffic flows in frequency domain. Normal TCP traffic flows present periodicity because of protocol behavior. Our results reveal that normal TCP flows can be segregated from malicious flows according to energy distribution properties. We discover the spectral shifting of attack flows from that of normal flows. Combining flow-level spectral analysis with sequential hypothesis testing, we propose a novel defense scheme against RoQ attacks. Our detection and filtering scheme can effectively rescue 99% legitimate TCP flows under the RoQ attacks. Yu Chen 0002, Kai Hwang 0001 |
ICC | 1 |
| 2007 | Collaborative Detection of DDoS Attacks over Multiple Network DomainsabstractThis paper presents a new distributed approach to detecting DDoS (distributed denial of services) flooding attacks at the traffic-flow level The new defense system is suitable for efficient implementation over the core networks operated byInternet service providers(ISPs). At the early stage of a DDoS attack, some traffic fluctuations are detectable at Internet routers or at the gateways of edge networks. We develop adistributed change-point detection(DCD) architecture using change aggregation trees (CAT). The idea is to detect abrupt traffic changes across multiple network domains at the earliest time. Early detection of DDoS attacks minimizes the floe cling damages to the victim systems serviced by the provider. The system is built over attack-transit routers, which work together cooperatively. Each ISP domain has a CAT server to aggregate the flooding alerts reported by the routers. CAT domain servers collaborate among themselves to make the final decision. To resolve policy conflicts at different ISP domains, anew secureinfrastructure protocol(SIP) is developed to establish mutual trust or consensus. We simulated the DCD system up to 16 network domains on the Cyber Defense Technology Experimental Research (DETER) testbed, a 220-node PC cluster for Internet emulation experiments at the University of Southern California (USC) Information Science Institute. Experimental results show that four network domains are sufficient to yield a 98 percent detection accuracy with only 1 percent false-positive alarms. Based on a 2006 Internet report onautonomous system(AS) domain distribution, we prove that this DDoS defense system can scale well to cover 84 AS domains. This security coverage is wide enough to safeguard most ISP core networks from real-life DDoS flooding attacks. Yu Chen 0002, Kai Hwang 0001, Wei-Shinn Ku |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2006 | Collaborative detection and filtering of shrew DDoS attacks using spectral analysis
Yu Chen 0002, Kai Hwang 0001 |
J. Parallel Distributed Comput. | 1 |
| 2005 | Achieving maximum throughput with a minimum number of label switched paths in MPLS networksabstractMPLS (multi-protocol label switching) networks allow multiple LSPs (label-switched paths) be established from a source to a destination to satisfy throughput required by an application. Given a MPLS network, where each link is associated with a maximum available bandwidth, a fundamental traffic engineering problem is how we can find minimum number of paths to achieve the maximum throughput. Optimally solving this problem can save huge amount of valuable network resources including available label space and reduce management complexity. This paper proves that finding a minimal number of LSPs is an NP-hard problem. To deal with this problem, we have studied four approximation algorithms. We found from simulations that the average number of paths produced by all these algorithms grows quite slowly when the network grows large. Moreover, the two algorithms, topological-sort-based maximum-path algorithm and greedy-based maximum-edge algorithm perform better than other algorithms. Between these two algorithms, the greedy-based maximum-edge algorithm is more time-efficient while keeps comparable performance. Jianyu Lou, Yu Chen 0002, Ya-Min Sun |
ICCCN | 3 |
| 2005 | Filtering of Shrew DDoS Attacks in Frequency DomainabstractThe shrew distributed denial of service (DDoS) attacks are periodic, bursty, and stealthy in nature. They are also known as reduction of quality (RoQ) attacks. Such attacks could be even more detrimental than the widely known flooding DDoS attacks because they damage the victim servers for a long time without being noticed, thereby denying new visitors to the victim servers, which are mostly e-commerce sites. Thus, in order to minimize the huge monetary losses, there is a pressing need to effectively detect such attacks in real-time. Unfortunately, effective detection of shrew attacks remains an open problem. In this paper, we meet this challenge by proposing a new signal processing approach to identifying and detecting the attacks by examining the frequency-domain characteristics of incoming traffic flows to a server. A major strength of our proposed technique is that its detection time is less than a few seconds. Furthermore, the technique entails simple software or hardware implementations, making it easily deployable in a real-life network environment. Yu Chen 0002, Kai Hwang 0001, Yu-Kwong Kwok |
LCN | 1 |