VLDB 2026 Research / reviewers in the wild / expert
Tao Peng 0011
dblp:89/6609-11
· DBLP profile ↗
41ranked-venue papers
8as first author
28since 2021 · last 2026
0000-0003-1653-4501ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 12 · 2 first-author · 7 since 2021Computer networks · 9 · 2 first-author · 7 since 2021Security and privacy · 9 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 6 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LO-GDRL: Privacy-preserving online task allocation based on Lyapunov optimization and graph-based deep reinforcement learning in mobile crowdsensingabstractIn Mobile Crowdsensing (MCS), online task allocation ensures timely task completion and improves overall system performance in dynamic environments through real-time scheduling and optimizing resource utilization. Existing Deep Reinforcement Learning methods have several limitations, including poor model performance, low system stability, and the problem of data privacy leakage. To address these issues, this paper proposes a lightweight privacy-preserving online task allocation framework called LO-GDRL (Lyapunov Optimization with Graph-based Deep Reinforcement Learning). LO-GDRL formulates NP-hard online task allocation as a graph-constrained optimization problem and designs a Deep Reinforcement Learning method with a new Dual-branch Graph Attention Dueling Network to enhance dynamic environment adaptation and complex dependency capture capability. To improve system stability, LO-GDRL establishes a dynamic-queue mechanism for dynamic resource coordination based on Lyapunov Optimization. Additionally, while preserving worker location privacy through differential privacy, the system achieves an optimal privacy-performance trade-off. The case studies on the simulation data of MCS systems based on the two real-world datasets verify the effectiveness of the proposed framework and demonstrate that our framework achieves more stable and superior performance across diverse environments compared to state-of-the-art methods. Yuhong Tan, Tao Peng 0011, Guojun Wang 0001, Qin Liu 0001, Tian Wang 0001 |
Comput. Networks | 2 |
| 2026 | VulTrLM: LLM-assisted vulnerability detection via AST decomposition and comment enhancement
Shaobo Zhang 0001, Qianzhi Wang, Qin Liu 0001, Tao Peng 0011 |
Empir. Softw. Eng. | 5 |
| 2026 | CAA: Toward Camouflaged and Transferable Adversarial ExamplesabstractTransferable adversarial examples (AEs) are visually indistinguishable from benign images, but can successfully mislead unknown deep neural networks. However, existing AEs normally vary considerably from benign images in the feature space, making them hard to pass label checking and adversarial detection. Therefore, how to make AEs camouflaged, disguising as benign images during detection is still an open problem. In this paper, we propose a novel camouflaged adversarial attack (CAA), which produces camouflaged adversarial examples (CAEs) for the first time. Our main idea is to make CAEs’ adversarial properties keep “dormant” state until the target model inadvertently triggers the “activated” state. To this end, we craftattackandcamouflageperturbations, so that CAEs are visually and feature/label-wise indistinguishable from benign images at first, but will implicitly turn into AEs once being triggered. Specifically, we exploit two common preprocessing operations, image scaling and JPEG compression, as the trigger, and propose a two-stage optimization strategy. As the preprocessing details of target models are unknown, the first stage trains a well-designed generative adversarial network under varying scaling/compression parameters to enhance the robustness of attack perturbations. The second stage uses feature (dis)similarities and contrastive distances to improve the transferability of camouflage perturbations. Extensive experiments on ImageNet dataset validate the effectiveness of CAA. Especially for robust models, the average fooling rate after preprocessing could reach 96.3% outperforming the state-of-the-art adversarial attack by 13.5%. Yipeng Zou, Qin Liu 0001, Jie Wu 0001, Tian Wang 0001, Guo Chen 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | AD2QT: Online Task Allocation Based on Transformer and Deep Reinforcement Learning in Mobile Crowdsensing
Yuhong Tan, Tao Peng 0011, Zeyu Chi, Xingyi Wu, Yi Guan |
ICIC (9) | 2 |
| 2025 | VADP: Visitor-attribute-based adaptive differential privacy for IoMT data sharing
Shaobo Zhang 0001, Lujie Zhang, Tao Peng 0011, Qin Liu 0001, Xiong Li 0002 |
Comput. Secur. | 3 |
| 2025 | P2-TaskMP: Privacy-Preserving Task Allocation Optimization Based on Mobility Prediction
Zhidong Xie, Tao Peng 0011, Guojun Wang 0001, Qin Liu 0001 |
Future Gener. Comput. Syst. | 2 |
| 2024 | Toward Answering Federated Spatial Range Queries Under Local Differential PrivacyabstractFederated analytics (FA) over spatial data with local differential privacy (LDP) has attracted considerable research attention recently. Existing solutions for this problem mostly employ a uniform grid (UG) structure, which recursively decomposes the whole spatial domain into fine‐grained regions in the distributed setting. In each round, the sampled clients perturb their locations using a random response mechanism with a fixed probability. This approach, however, cannot encode the client’s location effectively and will lead to ill‐suited query results. To address the deficiency of existing solutions, we propose LDP‐FSRQ, a spatial range query algorithm that relies on a hybrid spatial structure composed of the UG and quad‐tree with nonuniform perturbation (NUP) probability to encode and perturb clients’ locations. In each iteration of LDP‐FSRQ, each client adopts the quad‐tree to encode his/her location into a binary string and uses four local perturbation mechanisms to protect the encoded string. Then, the collector prunes the quad‐tree of the current round according to the clients’ reports and shares the pruned tree with the clients of the next round. We demonstrate the application of LDP‐FSRQ on Beijing, Landmark, Check‐in, and NYC datasets, and the experimental results show that our approach outperforms its competitors in terms of queries’ utility. Guanghui Feng, Guojun Wang 0001, Tao Peng 0011 |
Int. J. Intell. Syst. | 3 |
| 2024 | Spatiotemporal-Aware Privacy-Preserving Task Matching in Mobile CrowdsensingabstractTask matching is widely used for participant selection in mobile crowdsensing (MCS). However, accurate task matching relies on collecting a large amount of user information, which has the risk of privacy leakage. Existing privacy-preserving task matching methods have the disadvantages of low matching efficiency and coarse matching granularity, and are difficult to apply to MCS because of higher real-time requirements. In this article, we propose a spatiotemporal-aware privacy-preserving task matching scheme, achieving efficient and fine-grained matching while protecting privacy between users and task publishers. Specifically, the time matching score (TMS) and location matching score (LMS) between users and tasks are defined for the spatiotemporal requirement of MCS. In addition, a lightweight protocol called SCP (secure computing protocol) is constructed based on Shamir secret sharing and Carmichael theorem for securely calculating TMS and LMS and matching attribute values by size and range. The correctness and security of our scheme are proved by detailed theoretical analysis, and the experimental result shows that the computational overhead of our proposed scheme is only 10% of that in the scheme we compared with, while the difference in communication overhead is less than 200 KB. Tao Peng 0011, Wentao Zhong, Guojun Wang 0001, Shaobo Zhang 0001, Tian Wang 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Privacy-preserving multiobjective task assignment scheme with differential obfuscation in mobile crowdsensing
Tao Peng 0011, Kejian Guan, Shaobo Zhang 0001, Guojun Wang 0001, Tian Wang 0001, Youke Wu |
J. Netw. Comput. Appl. | 1 |
| 2024 | $\mathsf{MARS}$MARS: Enabling Verifiable Range-Aggregate Queries in Multi-Source EnvironmentsabstractThe huge values created by Big Data and the recent advances in cloud computing have been driving data from different sources into cloud repositories for comprehensive query services. However, cloud-based data fusion makes it challenging to verify if an untrusted server faithfully integrates data and executes queries or not. This is even harder for range-aggregate queries that apply aggregate operations on data within given ranges. In this paper, we propose a query authentication scheme, named${\sf MARS}$, enabling a user to efficiently authenticate range-aggregate queries on multi-source data. Specifically,${\sf MARS}$creates a VG-tree by subtly integrating Expressive Set Accumulator into a multi-dimensional G-tree while signing the root digest with a multi-source aggregate signature scheme. Compared with previous solutions,${\sf MARS}$has the following merits: (1)Practicality.Instead of treating range and aggregate queries separately, the user can directly verify the statistical result of selected data. (2)Scalability.Instead of authenticating the individual result from each source, the user can perform an aggregative validation on the integrated result from multiple sources. The experimental results demonstrate the effectiveness of MARS. For large-scale data fusion, the user-side verification time increases by only 103 ms as the amount of data sources increases by five times. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001, Shaobo Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | Privacy-Preserving Truth Discovery Based on Secure Multi-Party Computation in Vehicle-Based Mobile CrowdsensingabstractVehicle-based mobile crowdsensing has gained widespread attention due to its low cost and efficient data collection mode. One common method to improve the accuracy of sensing data in this context is truth discovery. However, the emergence of privacy leakage and data misuse has reduced users’ motivation to participate in sensing tasks. Meanwhile, existing solutions for privacy-preserving truth discovery generally suffer from low computational efficiency and frequent interactions between users and servers. Hence, this paper proposes a novel privacy-preserving truth discovery scheme based on secure multi-party computation. For the purpose of high efficiency and strong privacy protection, we utilize the Secret Sharing method to securely decompose data and construct a Secure Multi-party Computation protocol to compute the ground truth. In addition, the weight value generated by truth discovery is employed as a quantitative data quality indicator that dynamically adjusts the user’s rewards and constructs a data quality-driven incentive mechanism. Finally, we demonstrate the high performance of our method through a detailed analysis, showing its effectiveness even in scenarios with numerous users. Tao Peng 0011, Wentao Zhong, Guojun Wang 0001, Shui Yu 0001, Yi-Ning Liu 0002, Yi Yang 0027, Xuyun Zhang |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2024 | veffChain: Enabling Freshness Authentication of Rich Queries Over Blockchain DatabasesabstractWith the wide adoption of blockchains in data-intensive applications, enabling verifiable queries over a blockchain database is urgently required. Aiming at reducing costs, previous solutions embed a small-sized authenticated data structure (ADS) in each block header, so that a user can verify search results without maintaining a full copy of blockchain databases. However, existing studies focus on exact queries with difficulty to guarantee the freshness of search results. In this article, we propose two frameworks, called$\mathsf{veffChain}$and$\mathsf{veffChain++}$, to realize freshness authentication of rich queries over blockchain databases. Specifically,$\mathsf{veffChain}$concerns about verifiable latest-$K$exact queries and employs RSA accumulator to generate constant-size ADSs;$\mathsf{veffChain++}$integrates RSA accumulator into the Trie tree to further authenticate latest-$K$fuzzy queries. For improved scalability, an adaptive keyword splitting (AKS) solution is proposed to enable ADSs to be incrementally updated. Compared with the state-of-the-art work, our frameworks have the following merits: (1)Freshness Guarantee. The user can efficiently retrieve the freshest data from a blockchain database in a verifiable way. (2)Flexibility. The user can specify different query patterns on demand to retrieve data as accurately as possible. The detailed security analysis and extensive experiments validate the practicality of our frameworks. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2024 | MPV: Enabling Fine-Grained Query Authentication in Hybrid-Storage BlockchainabstractDue to the large-scale data streams produced by distributed terminals, hybrid-storage blockchain (HSB) that combines on-chain and off-chain storages has emerged as a promising solution for secure data storage in decentralized applications. Because all the raw data is outsourced to an untrusted service provider (SP), existing solutions suggest to utilize an on-chain authenticated data structure (ADS) to verify query results retrieved off-chain. However, existing solutions support onlycoarse-grained authenticationmaking a user abandon all the query results once the validation fails. In this paper, we focus on realizingfine-grained authenticationfor range queries, enabling a user to distinguish authentic data from falsified results. Considering the heavy gas consumption of on-chain storage, we propose two multi-dimensional parity-based verification (MPV) schemes with a trade-off between off-chain and on-chain efficiencies. Our main idea is to design an accumulator-based ADS to summarize well-designed verifiable hypercubes, so that fake results can be quickly located by combining multi-dimensional faces failed validation. Compared with previous solutions, our MPV schemes allow a user to make efficient use of query results by filtering out errors, and thus have higher data utility. The detailed security analysis and extensive experiments demonstrate the security and effectiveness of our MPV schemes, respectively. Qin Liu 0001, Yu Peng 0003, Mingzuo Xu, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2024 | Authorized Keyword Search on Mobile Devices in Secure Data OutsourcingabstractWith the increasing awareness of secure data outsourcing, dynamic searchable symmetric encryption (DSSE) that enables searches and updates over encrypted data has begun to receive growing attention. Despite promising, existing DSSE schemes with forward and backward privacy are still hard to achieve authorized keyword searches on mobile devices while supporting secure and flexible updates. In this article, we propose a DSSE scheme, named$\mathsf{FLY_{++}}$based on a flexible index structure$\mathsf{Hybrid}$that incorporates the merits of inverted indexes and forward indexes while compacting the index size. Specifically,$\mathsf{FLY_{++}}$encrypts the newly added data with a fresh key and disperses previous keys into$\mathsf{Hybrid}$for forward privacy, while applying symmetric puncturable encryption (SPE) and a dual-key mechanism to realize backward privacy further. Compared with the state-of-the-art work,$\mathsf{FLY_{++}}$has the following advantages: (1)Authorized search. It dispenses with caching or re-encrypting search results, enabling a mobile device to search only designated keywords over the data outsourced before authorization. (2)Flexibility.It not only allows for sublinear search time, but also simultaneously supports fine-grained and coarse-grained updates of outsourced data. The detailed security analysis and extensive experiments conducted on a real dataset demonstrate the security and practicality of$\mathsf{FLY_{++}}$, respectively. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2024 | Protecting Inference Privacy With Accuracy Improvement in Mobile-Cloud Deep LearningabstractWith the wide spread of data-driven deep learning applications, a growing number of users outsource compute-intensive inference processes to the cloud. To protect inference privacy, Liu (INFOCOM 2022) proposed two steganography-based solutions, named GHOST and GHOST+, relying on the mobile-cloud collaborative framework, where the mobile device hides sensitive images into public cover images before feature extraction, while launching adversarial attacks on the cloud-side deep neural network (DNN) to obtain desired results. Although both solutions demonstrate significant advantages in private deep learning, they suffer from limited practicality; since the inference accuracy decreases sharply as the hiding ratio increases. To address this, we propose two improved solutions, IGHO and IGHO+, which ensure high inference accuracy even when abundant sensitive images need to be hidden. Specifically, IGHO as the improved version of GHOST proposes two feature fusion methods, feature synthesis and pixel synthesis, to preprocess cover images, making the poisoned DNN learn hidden sensitive features better, while IGHO+as the improved version of GHOST+designs a novel feature mining generative adversarial network (FMGAN) to craft adversarial perturbations highly robust against variable sensitive types. Experimental results show that the proposed solutions highly improve the practicality of GHOST and GHOST+. Shulan Wang, Qin Liu 0001, Yang Xu 0013, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Mob. Comput. | 7 |
| 2023 | Improved Task Allocation in Mobile Crowd Sensing Based on Mobility Prediction and Multi-objective Optimization
Zhidong Xie, Tao Peng 0011, Guojun Wang 0001 |
ICA3PP (5) | 2 |
| 2023 | Real-Time Driver Fatigue Detection Method Based on Comprehensive Facial Features
Yihua Zheng, Shuhong Chen, Kairen Chen, Tian Wang 0001, Tao Peng 0011 |
ICA3PP (2) | 6 |
| 2023 | Differential privacy protection method for trip-oriented shared dataabstractSummary While location information sharing technology provides convenience for unmanned driving and journey navigation, user journey information sharing has also become a disaster for privacy information leakage. The traditional differential privacy method can only perturb the data entirely and cannot consider the design of data availability. In this paper, the difference privacy algorithm is improved by combining it with the Apriori algorithm, and the relevant perturbation is carried out after mining the associated data of the user's trip. In the face of possible data attacks, the privacy protection of the sensitive information of the user's actual data is ensured while the availability of the data is ensured. By testing 3000 trip data generated by experimental simulation, the results show that the correlation information between the original datasets is destroyed. However good availability is maintained after the Laplace data perturbation of the proposed algorithm for both simultaneous and multi‐person trips. Danlei Du, Tao Peng 0011, Xubin Li, Shaobo Zhang 0001, Tian Wang 0001 |
Concurr. Comput. Pract. Exp. | 4 |
| 2023 | A blockchain-based mobile crowdsensing scheme with enhanced privacyabstractAbstract With the popularity and development of sensors‐containing intelligent terminals, mobile crowdsensing system (MCS) based on the Internet of Things (IoT) has become a new paradigm of application. By the MCS, the pervasive smart device users are enabled to collect large‐scale data cost‐effectively, for crowd intelligent extraction and human‐centric service delivery. However, most of the existing MCSs are based on a centralized structure vulnerable to attacks and intrusions. Moreover, the data collected through crowdsensing are diverse and difficult to guarantee user privacy, especially during the payment and data upload stages. In this article, we propose a blockchain‐based privacy‐preserving crowdsensing (BPPC) scheme based on the distributed structure, to protect user privacy. First, we combine the multiblockchain technology and K‐anonymity to construct anonymity groups for the confusion. Second, we present the random algorithm HashProof to select candidates from the anonymity groups to avoid deployment of Trusted Third Party (TTP) or agent server. Ultimately, we design encryption‐based algorithms building trust and authentication mechanisms in the system to guarantee the confidentiality of user data and achieve the accurate distribution of rewards. To verify the effectiveness and efficiency of the BPPC scheme, extensive experiments were conducted. Tao Peng 0011, Kejian Guan, Jierong Liu, Jianer Chen, Guojun Wang 0001 |
Concurr. Comput. Pract. Exp. | 1 |
| 2023 | Blockchain-assisted multi-keyword fuzzy search encryption for secure data sharing
Yipeng Zou, Tao Peng 0011, Guojun Wang 0001, Jinbo Xiong |
J. Syst. Archit. | 2 |
| 2023 | SlimBox: Lightweight Packet Inspection over Encrypted TrafficabstractDue to the explosive increase of enterprise network traffic, middleboxes that inspect packets through customized rules have been widely outsourced for cost-saving. Despite promising, redirecting enterprise traffic to remote middleboxes raises privacy concerns about the exposure of corporate secrets. To address this, existing solutions mainly apply searchable encryption (SE) to encrypt traffic and rules, enabling middlebox to perform pattern matching over ciphertexts without learning any sensitive information. However, SE is designed for searching pre-chosen keywords, and may cause extensive costs when applied directly to inspecting traffic in which the keywords cannot be determined in advance. The inefficiency of existing SE-based approaches motivates us to investigate a privacy-preserving and lightweight middlebox. To this end, this paper designs$\mathsf{SlimBox}$, which rapidly screens out potentially malicious packets in constant time while incurring only moderate communication overhead. Our main idea is to fragment a traffic/rule string into sub-patterns to achieve conjunctive sub-pattern matching over ciphertexts, while incorporating the position information into the secure matching process to avoid false positives. Experiment results on real datasets show that$\mathsf{SlimBox}$can achieve a good tradeoff between matching latency and communication cost compared to prior work. Qin Liu 0001, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | When Deep Learning Meets Steganography: Protecting Inference Privacy in the DarkabstractWhile cloud-based deep learning benefits for high-accuracy inference, it leads to potential privacy risks when exposing sensitive data to untrusted servers. In this paper, we work on exploring the feasibility of steganography in preserving inference privacy. Specifically, we devise GHOST and GHOST+, two private inference solutions employing steganography to make sensitive images invisible in the inference phase. Motivated by the fact that deep neural networks (DNNs) are inherently vulnerable to adversarial attacks, our main idea is turning this vulnerability into the weapon for data privacy, enabling the DNN to misclassify a stego image into the class of the sensitive image hidden in it. The main difference is that GHOST retrains the DNN into a poisoned network to learn the hidden features of sensitive images, but GHOST+ leverages a generative adversarial network (GAN) to produce adversarial perturbations without altering the DNN. For enhanced privacy and a better computation-communication trade-off, both solutions adopt the edge-cloud collaborative framework. Compared with the previous solutions, this is the first work that successfully integrates steganography and the nature of DNNs to achieve private inference while ensuring high accuracy. Extensive experiments validate that steganography has excellent ability in accuracy-aware privacy protection of deep learning. Qin Liu 0001, Jiamin Yang, Hongbo Jiang 0001, Jie Wu 0001, Tao Peng 0011, Tian Wang 0001, Guojun Wang 0001 |
INFOCOM | 5 |
| 2022 | A collaborative deep learning microservice for backdoor defenses in Industrial IoT networks
Qin Liu 0001, Liqiong Chen, Hongbo Jiang 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
Ad Hoc Networks | 6 |
| 2022 | Prime Inner Product Encoding for Effective Wildcard-Based Multi-Keyword Fuzzy SearchabstractWith the prevalence of cloud computing, a growing number of users are delegating clouds to host their sensitive data. To preserve user privacy, it is suggested that data is encrypted before outsourcing. However, data encryption makes keyword-based searches over ciphertexts extremely difficult. This is even challenging forfuzzy searchthat allows uncertainties or misspellings of keywords in a query. In this article, we propose a prime inner product encoding (PIPE) scheme, which makes use of theindecomposableproperty of prime numbers to provide efficient, highly accurate, and flexible multi-keyword fuzzy search. Our main idea is to encode either a query keyword or an index keyword into a vector filled with primes or reciprocals of primes, such that the result of vectors’ inner product is an integer only when two keywords are similar. Specifically, we first construct$\text{PIPE}_{0}$that is secure in the known ciphertext model. Unlike existing works that have difficulty supporting AND and OR semantics simultaneously,$\text{PIPE}_{0}$gives users the flexibility to specify different search semantics in their queries. Then, we construct$\text{PIPE}_{\text{S}}$that subtly adds random noises to a query vector to resist linear analyses. Both theoretical analyses and experiment results demonstrate the effectiveness of our scheme. Qin Liu 0001, Yu Peng 0003, Shuyu Pei, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Enabling Verifiable and Dynamic Ranked Search over Outsourced DataabstractCloud computing as a promising computing paradigm is increasingly utilized as potential hosts for users’ massive dataset. Since the cloud service provider (CSP) is outside the users’ trusted domain, existing research suggests encrypting sensitive data before outsourcing and adopting Searchable Symmetric Encryption (SSE) to facilitate keyword-based searches over the ciphertexts. However, it remains a challenging task to design an effective SSE scheme that simultaneously supportssublinear search time,efficient update and verification, andon-demand information retrieval. To address this, we propose a Verifiable Dynamic Encryption with Ranked Search (VDERS) scheme that allows a user to perform top-$K$Ksearches on adynamicdocument collection and verify the correctness of the search results in a secure and efficient way. Specifically, we first provide a basic construction,$\mathsf {VDERS}^0$VDERS0, where aranked inverted indexand averifiable matrixare constructed to enable verifiable document insertion in top-$K$Ksearches. Then, an advanced construction,$\mathsf {VDERS}^{\star }$VDERS★, is devised to further support document deletion with a reduced communication cost. Extensive experiments on real datasets demonstrate the efficiency and effectiveness of our VDERS scheme. Qin Liu 0001, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2021 | A Fine-grained Privacy-Preserving Profile Matching Scheme in Mobile Social NetworksabstractMobile Social Networks (MSN) have made it easy for us to communicate with our friends. Friend discovery is a common feature in the MSN application, which can recommend friends to requesters by comparing the similarity of attributes between users. However, in the process of attribute matching, users' personal information may be stolen by the server or other malicious users, leading to privacy leakage. Many solutions have been proposed for this problem, but the existing solutions have not considered the different ranges of user attribute values when calculating their similarity, leading to the final matching results not accurate. The existing solutions also do not consider users' location attributes and cannot find users according to the requester's query range. To address these issues, we propose a fine-grained privacy-preserving profile matching scheme (FPPM) that supports precise queries. In our scheme, the requester can flexibly set the query range. We use order-preserving encryption to compare the cipher-text submitted by the user to precisely achieve similarity matching. To further protect users' privacy security, we design a secure dot product protocol (SDPP) that uses two servers to jointly compute the dot product of cipher-text vectors to avoid privacy leakage during the computation. Our proposed scheme supports the requester to define the querying range to obtain fine-grained query results. Based on it, we also consider multi-dimensional privacy protection such as user feature attributes and location attributes. Tao Peng 0011, Wentao Zhong, Kejian Guan, Yipeng Zou, Guojun Wang 0001 |
TrustCom | 1 |
| 2021 | Dynamic Searchable Symmetric Encryption with Forward and Backward PrivacyabstractDynamic searchable symmetric encryption (DSSE) that enables a client to perform searches and updates on encrypted data has been intensively studied in cloud computing. Recently, forward privacy and backward privacy has engaged significant attention to protect DSSE from the leakage of updates. However, the research in this field almost focused on keyword-level updates. That is, the client needs to know the keywords of the documents in advance. In this paper, we proposed a document-level update scheme, DBP, which supports immediate deletion while guaranteeing forward privacy and backward privacy. Compared with existing forward and backward private DSSE schemes, our DBP scheme has the following merits: 1) Practicality. It achieves deletion based on document identifiers rather than document/keyword pairs; 2) Efficiency. It utilizes only lightweight primitives to realize backward privacy while supporting immediate deletion. Experimental evaluation on two real datasets demonstrates the practical efficiency of our scheme. Yu Peng 0003, Qin Liu 0001, Jie Wu 0001, Tian Wang 0001, Tao Peng 0011, Guojun Wang 0001 |
TrustCom | 6 |
| 2021 | SecVKQ: Secure and verifiable kNN queries in sensor-cloud systems
Qin Liu 0001, Zhengzheng Hao, Yu Peng 0003, Hongbo Jiang 0001, Jie Wu 0001, Tao Peng 0011, Guojun Wang 0001, Shaobo Zhang 0001 |
J. Syst. Archit. | 6 |
| 2020 | Feature importance in Android malware detectionabstractThe topic of mobile malware detection on the Android platform has attracted significant attention over the last several years. However, while much research has been conducted toward mobile malware detection techniques, little attention has been devoted to feature selection and feature importance. That is, which app feature matters more when it comes to machine learning classification. After succinctly surveying all major, dated from 2012 to 2020, datasets used by state-of-the-art malware detection works in the literature, we analyse a critical mass of apps from the most contemporary and prevailing datasets, namely Drebin, VirusShare, and AndroZoo. Next, we rank the importance of app classification features pertaining to permissions and intents using the Information Gain algorithm for all the three above-mentioned datasets. Vasileios Kouliaridis, Georgios Kambourakis, Tao Peng 0011 |
TrustCom | 3 |
| 2020 | A Function-Centric Risk Assessment Approach for Android ApplicationsabstractDifferent risk evaluation approaches exist to protect users from potentially malicious apps. However, while assessing risks, the existing approaches ignore users' functional needs, and that app funGuojun Wangctions help their developers compete in the marketplace. In this paper, we propose a function-centric risk assessment approach for Android apps. The proposed approach combines operation research and machine learning methods to calculate the risks of an app and offers five competitive apps in the same app-category. We evaluate the proposed approach using 1,377 apps in sixteen app-categories, obtained from the most popular app store of 2019 in China, “Ying Yong Bao.” The experimental evaluation demonstrates the feasibility of the proposed approach. This approach can help users select safe apps in the marketplace that offer competitive functions. Haroon Elahi, Tao Peng 0011, Fang Qi, Guojun Wang 0001 |
TrustCom | 3 |
| 2020 | A Privacy-Preserving Crowdsensing System with Muti-BlockchainabstractMobile crowdsensing system has become a new paradigm application with popularity and development of smart mobile devices. It provides a costless and efficient model to collect sensory data. However, most of mobile crowdsensing systems are based on the centralized structure, which will lead to serious privacy disclosure. In this paper, we combine k-anonymity and blockchain to build a mobile corwdsensing system, in which the users can upload their sensory data and receive corresponding rewards without privacy disclosure concern. With the distributed structure system and encryption algorithm, the system achieves enhanced privacy preservation through breaking the link between data and rewards and their owners. Tao Peng 0011, Jierong Liu, Jianer Chen, Guojun Wang 0001 |
TrustCom | 1 |
| 2020 | A trajectory privacy-preserving scheme based on a dual-K mechanism for continuous location-based services
Shaobo Zhang 0001, Xinjun Mao, Kim-Kwang Raymond Choo, Tao Peng 0011, Guojun Wang 0001 |
Inf. Sci. | 4 |
| 2019 | Multidimensional privacy preservation in location-based services
Tao Peng 0011, Qin Liu 0001, Guojun Wang 0001, Yang Xiang 0001, Shuhong Chen |
Future Gener. Comput. Syst. | 1 |
| 2019 | A caching and spatial K-anonymity driven privacy enhancement scheme in continuous location-based services
Shaobo Zhang 0001, Xiong Li 0002, Zhiyuan Tan 0001, Tao Peng 0011, Guojun Wang 0001 |
Future Gener. Comput. Syst. | 4 |
| 2019 | Intelligent route planning on large road networks with efficiency and privacy
Qin Liu 0001, Panlin Hou, Guojun Wang 0001, Tao Peng 0011, Shaobo Zhang 0001 |
J. Parallel Distributed Comput. | 4 |
| 2017 | DABKS: Dynamic attribute-based keyword search in cloud computingabstractDue to its fast deployment and scalability, cloud computing has become a significant technology trend. Organizations with limited budgets can achieve great flexibility at a low price by outsourcing their data and query services to the cloud. Since the cloud is outside the organization's trusted domain, existing research suggests encrypting data before outsourcing to preserve user privacy. Two main problems that the cloud user faces while searching over encrypted data are how to achieve a fine-grained search authorization and how to efficiently update the search permission. The existing attribute-based keyword search (ABKS) scheme addresses the first problem, which allows a data owner to control the search of the outsourced encrypted data according to an access policy. This paper proposes a dynamic attribute-based keyword search (DABKS) scheme that incorporates proxy re-encryption (PRE) and a secret sharing scheme (SSS) into ABKS. The DABKS scheme, which allows the data owner to delegate policy updating operations to the cloud, takes full advantage of cloud resources. We conduct experiments on real data sets to validate the effectiveness and efficiency of our proposed scheme. Baishuang Hu, Qin Liu 0001, Xuhui Liu, Tao Peng 0011, Guojun Wang 0001, Jie Wu 0001 |
ICC | 4 |
| 2017 | Verifiable Ranked Search over dynamic encrypted data in cloud computingabstractBig data has become a hot topic in many areas where the volume and growth rate of data require cloud-based platforms for processing and analysis. Due to open cloud environments with very limited user-side control, existing research suggests encrypting data before outsourcing and adopting Searchable Symmetric Encryption (SSE) to facilitate keyword-based searches on the ciphertexts. However, no prior SSE constructions can simultaneously achieve sublinear search time, efficient update and verification, and on-demand file retrieval, which are all essential to the development of big data. To address this, we propose a Verifiable Ranked Searchable Symmetric Encryption (VRSSE) scheme that allows a user to perform top-K searches on a dynamic file collection while efficiently verifying the correctness of the search results. VRSSE is constructed based on the ranked inverted index, which contains multiple inverted lists that link sets of file nodes relating a specific keyword. For verifiable ranked searches, file nodes are ordered according to their ranks for such a keyword, and information about a node's prior/following neighbor will be encoded with the RSA accumulator. Extensive experiments on real data sets demonstrate the efficiency and effectiveness of our proposed scheme. Qin Liu 0001, Xiaohong Nie, Xuhui Liu, Tao Peng 0011, Jie Wu 0001 |
IWQoS | 4 |
| 2017 | Dynamic access policy in cloud-based personal health record (PHR) systems
Xuhui Liu, Qin Liu 0001, Tao Peng 0011, Jie Wu 0001 |
Inf. Sci. | 3 |
| 2017 | Collaborative trajectory privacy preserving scheme in location-based services
Tao Peng 0011, Qin Liu 0001, Dacheng Meng, Guojun Wang 0001 |
Inf. Sci. | 1 |
| 2016 | Dynamic Verifiable Search Over Encrypted Data in Untrusted Clouds
Xiaohong Nie, Qin Liu 0001, Xuhui Liu, Tao Peng 0011, Yapin Lin |
ICA3PP | 4 |
| 2015 | HCBE: Achieving Fine-Grained Access Control in Cloud-Based PHR Systems
Xuhui Liu, Qin Liu 0001, Tao Peng 0011, Jie Wu 0001 |
ICA3PP (3) | 3 |