VLDB 2026 Research / reviewers in the wild / expert
Feng Li 0001
dblp:92/2954-1
· DBLP profile ↗
71ranked-venue papers
14as first author
16since 2021 · last 2026
0000-0001-7633-7863ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 47 · 10 first-author · 11 since 2021Systems, architecture and hardware · 10 · 2 first-author · 1 since 2021Security and privacy · 5 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DietWatch: Fine-Grained and Robust Dietary Monitoring via Smartwatch in Real-World ScenariosabstractDietary behaviors play a pivotal role in promoting overall health and preventing chronic diseases (e.g., hypertension and diabetes). The widespread adoption of smartwatches offers a promising platform for continuous dietary monitoring. However, existing smartwatch-based dietary monitoring approaches struggle with challenges in real-world scenarios, including dynamic interference, gesture generalization, and user diversity. To address these limitations, we proposeDietWatch, a real-world dietary monitoring system that utilizes a commercial smartwatch to capture and analyze fine-grained dietary behaviors.DietWatchincorporates a dynamic interference mitigation module to suppress acoustic and inertial noise. It further employs a contrastive learning-based framework to distinguish eating gestures from diverse daily activities, without constraining users’ eating styles and activity types. To enhance generalizability across users,DietWatchadopts a cross-user adaptation mechanism to extract user-independent features. Furthermore, a clustering algorithm is designed to estimate dietary time, while an attention-based multimodal fusion method is employed to analyze biting and chewing frequencies and identify food categories. Experimental results demonstrate thatDietWatchachieves 79.95% temporal Intersection over Union for eating time detection, 85.68% accuracy in food classification, and mean absolute errors of 1.26 bites/min for biting frequency and 7.71 chews/min for chewing frequency estimation. Zhen Hou 0002, Yucheng Xie, Feng Li 0001, Honggang Wang 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Data-Free Backdoor Attack on Malware Image Classification ModelsabstractMachine learning-based image malware classifiers are increasingly vital for safeguarding enterprises and infrastructure. However, these models are vulnerable to backdoor attacks, where adversaries inject subtle triggers causing intentional misclassifications. Existing backdoor techniques typically require access to the original training data, a significant limitation in regulated domains where malware datasets are proprietary and confidential. In this work, we propose a novel data-free backdoor attack methodology that circumvents this constraint by utilizing surrogate datasets constructed from publicly available malware repositories. Our approach incorporates a logit-based dictionary filtering mechanism to select surrogate samples closely resembling the original training distribution, subsequently embedding stealthy visual triggers—such as checkerboard patterns and noise patches—into these samples. By fine-tuning a blackbox convolutional neural network (CNN) malware classifier with this poisoned surrogate data and employing a logit similarity-based loss function, we successfully implant robust backdoors. Experimental results demonstrate an attack success rate (ASR) of up to 99%, where we utilize the DIKE dataset to construct the surrogate dataset and target an existing CNN-based malware classifier architecture [2], with minimal degradation in clean sample classification accuracy. Our findings highlight a critical vulnerability in contemporary malware detection systems, emphasizing the necessity for enhanced defense mechanisms against data-free adversarial threats. The code and dataset are available at our GitHub repository1. Garvit Agarwal, Yousef Mohammed Y. Alomayri, Agnideven Palanisamy Sundar, Feng Li 0001 |
ICCCN | 4 |
| 2025 | Vigilante Defender: A Vaccination-based Defense Against Backdoor Attacks on 3D Point Clouds Using Particle Swarm OptimizationabstractBackdoor attacks on 3D Point Clouds (PCs) pose a serious threat by embedding hidden triggers into a subset of the training data. These triggers cause targeted misclassifications at inference time while leaving the model’s behavior unaffected in the absence of triggers, making them stealthy and difficult to detect. In distributed learning settings, where a central trainer aggregates data from multiple sources and offers only black-box access to the model, a single malicious contributor can compromise the model’s integrity if defenses are not in place. We propose a novel client-side defense that empowers individual contributors to act as vigilante defenders. By injecting benign ‘vaccination’ triggers—identified via Particle Swarm Optimization—into their local training data, defenders can proactively neutralize potential backdoors without prior knowledge of their location or structure. Experiments on standard benchmarks with PointNet and DGCNN show our method significantly reduces attack success while preserving classification accuracy, outperforming existing defenses. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Yucheng Xie, Ryan Hosler |
ICCCN | 2 |
| 2025 | RansomNet: Ransomware Classification Using Sub-Graph Mining of Function Call GraphsabstractThe classification of ransomware remains a critical yet challenging task in cybersecurity. Motivated by the increasing sophistication and overlap in behaviors between ransomware and general malware, this work addresses the need for more precise differentiation methods to facilitate targeted mitigation efforts. Our study proposes an innovative approach for ransomware classification using sub-graph mining of Function Call Graphs (FCGs). We employ Cuckoo Sandbox™ to extract dynamic API calls and construct detailed FCGs. Through focused subgraph mining, we isolate critical API call patterns specifically relevant to ransomware behavior. These extracted patterns are then vectorized and classified using a Convolutional Neural Network (RansomNet-CNN), achieving high precision in distinguishing ransomware from general malware. Unlike full-graph or flat-sequence models, our subgraph-level approach precisely captures ransomware-relevant behaviors. The RansomNet-CNN model demonstrates superior performance, achieving a precision of 99% and a recall of 100%, thus underscoring its practical effectiveness in ransomware identification. The dataset and code are publicly available at our Zenodo Repository1. Garvit Agarwal, Yucheng Xie, Yousef Mohammed Y. Alomayri, Feng Li 0001 |
MASS | 4 |
| 2025 | Vaccination Against Backdoor Attacks on Federated Learning Systems
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao, Ryan Hosler |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2024 | Subjective Logic-based Decentralized Federated Learning for Non-IID DataabstractExisting Federated Learning (FL) methods are highly influenced by the training data distribution. In the single global model FL systems, users with highly non-IID data do not improve the global model, and neither does the global model work well on their local data distribution. Even with the clustering-based FL approaches, not all participants get clustered adequately enough for the models to fulfill their local demands. In this work, we design a modified subjective logic-based FL system utilizing the distribution-based similarity among users. Each participant has complete control over their own aggregated model, with handpicked contributions from other participants. The existing clustered model only satisfies a subset of clients, while our individual aggregated models satisfy all the clients. We design a decentralized FL approach, which functions without a trusted central server; the communication and computation overhead is distributed among the clients. We also develop a layer-wise secret-sharing scheme to amplify privacy. We experimentally show that our approach improves the performance of each participant’s aggregated model on their local distribution over the existing single global model and clustering-based approach. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
ARES | 2 |
| 2024 | Graph Representation Learning on Novel Feature Based Graphs for Network Intrusion DetectionabstractNetwork Intrusions are an ever present threat in the modern age of instant transmission of data over the cyberspace. Ideally, an effective cybersecurity mechanism will detect an attack before it affects a given network. Hence, organizations utilize Network Intrusion Detection Systems (NIDS) to monitor incoming network traffic for all potential misuses. For this research, we present a novel method for aggregating network traffic into a graph for representation learning capable of outperforming existing NIDS in literature. We apply and validate our methods on numerous publically available network flow datasets for demonstrable and concrete performance evaluation. Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao |
GLOBECOM | 4 |
| 2024 | Toward Multimodal Vertical Federated Learning: A Traffic Analysis Case StudyabstractFederated Learning (FL) is an emerging subclass of Artificial Intelligence that decentralizes the learning process. Unlike the well-studied Horizontal Federated Learning (HFL), which requires the feature space of all participants to be the same, the newly emerging Vertical Federated Learning (VFL) allows participants to hold different features, provided the sample space is the same. This unique aspect enables VFL to incorporate features from different data modalities, a capability that has not yet been sufficiently explored. Currently, VFL researchers adapt datasets originally used for HFL by splitting the data vertically, whether it is text, tabular, or image data. In this paper, we extend the application of VFL to multimodal datasets, specifically in the field of Intelligent Transportation. We build models by combining local models from participants holding CCTV image datasets and Traffic flow tabular datasets. Due to the absence of suitable existing datasets, we introduce a new dataset, the INDOT traffic dataset, which also supports sequential training across time and distance. Our experiments demonstrate the efficiency of VFL in the multimodal traffic analysis scenario and aim to expand the scope of VFL research. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
ICCCN | 2 |
| 2024 | Generating-Based Attacks to Online Social NetworksabstractOnline social network (OSN) privacy leakage problem addresses more and more users’ concerns. Studying the problem from attackers’ view could tell us how to prevent further data leakage. Currently, attackers mainly focus on mapping identities between their background knowledge and the published data to collect useful information. However, it becomes difficult to find the global optimal mapping strategy because of the complexity of the OSN data. This article proposes a novel generating-based attack on OSN data, no longer restricted to mapping-based information collection. Generally, the proposed scheme learns OSN properties from the attackers’ background knowledge and employs the knowledge to fill the unknown area in the published data. The proposed scheme employs a generative adversarial network to ensure the similarity between the generated graph and the published data. The conditional information is also added in the generation process such that the generated graph is restricted to the conditions under attackers’ background knowledge. Experimental results show that the proposed scheme successfully infer private information with real-world OSN datasets. Tianchong Gao, Yucheng Bian, Feng Li 0001, Agnideven Palanisamy Sundar |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2023 | Unsupervised Deep Learning for an Image Based Network Intrusion Detection SystemabstractThe most cost-effective method of cybersecurity is prevention. Therefore, organizations and individuals utilize Network Intrusion Detection Systems (NIDS) to inspect network flow for potential intrusions. However, Deep Learning based NIDS still struggle with high false alarm rates and detecting novel and unseen attacks. Therefore, in this paper, we propose a novel NIDS framework based on generating images from feature vectors and applying Unsupervised Deep Learning. For evaluation, we apply this method on four publicly available datasets and have demonstrated an accuracy improvement of up to 8.25 % when compared to Deep Learning models applied to the original feature vectors. Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao |
GLOBECOM | 4 |
| 2023 | TrustNetFL: Enhancing Federated Learning with Trusted Client Aggregation for Improved SecurityabstractFederated Learning (FL) has emerged as a promising approach for training machine learning models across individual devices while preserving data privacy. However, FL faces many challenges, specifically a vulnerability to adversarial attacks due to its strict adherence to ensuring individual client model and data privacy. To mitigate these issues, dynamic clipping techniques have been proposed which dynamically adjust the gradient clipping threshold during model aggregation. However, current iterations depend on specific and often intensive calculations to determine a clipping threshold which can lead to an over fitting to a specific dataset or attacker model. In this paper, we focus on improving the limitations of existing FL and dynamic clipping approaches by introducing a novel method that incorporates a group of trusted users during the aggregation of client models for a global update. By identifying and utilizing a network of trusted users, our defense method TrustNetFL enhances the robustness of model aggregation against malicious updates. This method not only maintains the model's performance but also improves its resistance to adversarial influences. We demonstrate the effectiveness of our defense through extensive experiments thus showcasing its superiority and simplicity in achieving enhanced model security in FL settings. Agnideven Palanisamy Sundar, Feng Li 0001 |
MobiHoc | 4 |
| 2023 | Sorting Ransomware from Malware Utilizing Machine Learning Methods with Dynamic AnalysisabstractRansomware attacks have grown significantly in the past dozen years and have disrupted businesses that engage with personal data. In this paper, we discuss the identification of ransomware, malware, and benign software from one another using machine learning techniques. We collected data samples from repositories on the internet as well as referencing a dataset from a previous study that provided a basis for our approach. We collected ransomware, malware, and benign software samples manually using Cuckoo Sandbox™. We filtered on certain feature groups to test and determine if certain activity/processes in the infection process could be used to correctly distinguish ransomware from malware and benign software. These feature groups represent correlated processes within a running application: network activity, registry/events processes, and file interactions. The datasets were analyzed using several machine learning (ML) models which included Random Forest, Support Vector Machines (SVM), Gradient Boosting, and Decision Trees using binary classification. The best classifiers for distinctly identifying ransomware from benign software were Random Forest and SVM with an f1- score of 86% and an f1-score of 82% as well as an 85% in overall accuracy for Random Forest. In addition to ransomware versus benign software, we also compared malware software to ransomware data. Yielding a 100% accuracy in performance, Gradient Boosting Classifier and Decision Trees were the best at distinguishing ransomware from malware software. This high result may partially be caused by a smaller malware and ransomware dataset. Overall, we were able to successfully distinguish ransomware from malware and benign software. Joshua Schoenbachler, Vinay Krishnan, Garvit Agarwal, Feng Li 0001 |
MobiHoc | 4 |
| 2022 | Machine Learning-based Online Social Network Privacy PreservationabstractOnline data privacy draws more and more concerns. Online Social Network (OSN) service providers employ anonymization mechanisms to preserve private information and data utility. However, these mechanisms mostly focus on the traditional definitions about privacy and utility. Recently, both benign data scientists and attackers utilize machine learning methods to extract information from OSNs. This paper aims to present a novel angle of balancing privacy and utility under machine learning. The proposed scheme perturbs the data that breaks the attackers' learning results and protect the benign third parties' learning results. To preserve both privacy and utility, we propose two different anonymization approaches to solve the multi-objective optimization problem. The first approach combines the two objectives. It utilizes the deep learning model, Generative Adversarial Network (GAN), to sequentially learns the two objectives and generates graphs. The second approach analyzes the differences between the two objects on structures. It utilizes Integrated Gradient (IG) in learning to break attackers' learning results. It structurally rewires edges to preserve third parties' learning results afterwards. The experiment results show that both approaches work well in privacy preservation. Tianchong Gao, Feng Li 0001 |
AsiaCCS | 2 |
| 2022 | Distributed Swift and Stealthy Backdoor Attack on Federated LearningabstractFederated Learning (FL) provides enhanced privacy over traditional centralized learning; unfortunately, it is also as susceptible to backdoor attacks, just like its centralized counterpart. Conventionally, in data poisoning-based backdoor attacks, all the malicious participants overlay the same single trigger pattern on a subset of their private data during local training. The same trigger is used to induce the backdoor in the otherwise benign global model at inference time. Such single trigger attacks can be detected and removed with relative ease as they undermine the distributed nature of FL. In this work, we focus on building an attack scheme where each batch of malicious clients uses sizably discrete local triggers during local training, with the ability to invoke the attack with a single small inference trigger during the global model testing. The larger size of the trigger pattern ensures prolonged attack longevity even after the termination of the attack. We conduct extensive experiments to show that our approach is far faster, stealthier, and more effective than the centralized trigger approach. The stealthiness of our work is explained using the DeepLIFT visual feature interpretation method. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
NAS | 2 |
| 2021 | Energy-Efficient Device Selection in Federated Edge LearningabstractDue to the increasing demand from mobile devices for the real-time response of cloud computing services, federated edge learning (FEL) emerges as a new computing paradigm, which utilizes edge devices to achieve efficient machine learning while protecting their data privacy. Implementing efficient FEL suffers from the challenges of devices’ limited computing and communication resources, as well as unevenly distributed datasets, which inspires several existing research focusing on device selection to optimize time consumption and data diversity. However, these studies fail to consider the energy consumption of edge devices given their limited power supply, which can seriously affect the cost-efficiency of FEL with unexpected device dropouts. To fill this gap, we propose a device selection model capturing both energy consumption and data diversity optimization, under the constraints of time consumption and training data amount. Then we solve the optimization problem by reformulating the original model and designing a novel algorithm, named E2DS, to reduce the time complexity greatly. By comparing with two classical FEL schemes, we validate the superiority of our proposed device selection mechanism for FEL with extensive experimental results. Qin Hu 0001, Jianan Chen 0009, Kyubyung Kang, Feng Li 0001, Xukai Zou |
ICCCN | 5 |
| 2021 | Learning Discriminative Features for Adversarial RobustnessabstractDeep Learning models have shown incredible image classification capabilities that extend beyond humans. However, they remain susceptible to image perturbations that a human could not perceive. A slightly modified input, known as an Adversarial Example, will result in drastically different model behavior. The use of Adversarial Machine Learning to generate Adversarial Examples remains a security threat in the field of Deep Learning. Hence, defending against such attacks is a studied field of Deep Learning Security. In this paper, we present the Adversarial Robustness of discriminative loss functions. Such loss functions specialize in either inter-class or intra-class compactness. Therefore, generating an Adversarial Example should be more difficult since the decision barrier between different classes will be more significant. We conducted White-Box and Black-Box attacks on Deep Learning models trained with different discriminative loss functions to test this. Moreover, each discriminative loss function will be optimized with and without Adversarial Robustness in mind. From our experimentation, we found White-Box attacks to be effective against all models, even those trained for Adversarial Robustness, with varying degrees of effectiveness. However, state-of-the-art Deep Learning models, such as Arcface, will show significant Adversarial Robustness against Black-Box attacks while paired with adversarial defense methods. Moreover, by exploring Black-Box attacks, we demonstrate the transferability of Adversarial Examples while using surrogate models optimized with different discriminative loss functions. Ryan Hosler, Tyler Phillips 0001, Xiaoyuan Yu, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001 |
MSN | 6 |
| 2020 | Correlated Participation Decision Making for Federated Edge LearningabstractDriven by the sheer amount of data generated at the network edge and improved computation capabilities of mobile devices, federated edge learning (FEL) emerges as a novel paradigm to achieve edge intelligence with a favorable property of protecting privacy for data generators, i.e., edge devices. However, limited computation and communication resources at the edge make it challenging to execute FEL cost-efficiently in practice. Faced with this challenge, lots of existing work focus on the optimization control during the learning process. However, these research take no precaution in terms of composing the FEL system given heterogeneous candidate devices, which can severely impact the implementation performance. To solve this issue, we define a participation game to capture the dependent but competitive relationships among edge devices with respect to making decisions on whether to participate in a round of FEL. Then we propose a correlated equilibrium based participation decision making strategy to achieve individual rationality and global profit maximization at the same time, which can maintain the efficiency and sustainability of FEL in the long term. Furthermore, we devise an improved method with polynomial computational cost to enhance the scalability of the game-theoretic solution. The performance of our proposed scheme is evaluated through extensive experimental results. Qin Hu 0001, Feng Li 0001, Xukai Zou, Yinhao Xiao |
GLOBECOM | 2 |
| 2020 | Deep Dynamic Clustering of Spam Reviewers using Behavior-Anomaly-based Graph EmbeddingabstractOnline reviews have become an increasingly important factor in the purchase decision of a customer. However, many spammers write deceptive reviews to alter the credibility of a product/service. Often than not, these spammers exhibit group behavior, which can be exploited to differentiate them from authentic reviewers. Such behaviors are found in spammers working together as well as with crowdsourced review manipulators. The existing graph-based spammer detection approaches do not capture the dynamic and nonlinear relationship between the users. This paper aims to address this issue by introducing a method to use a deep structure embedding approach that preserves highly nonlinear structural information along with the dynamic aspects of user reviews to identify and cluster the spam users. It is worth mentioning that, in the experiment with real datasets, our method captures about 92% of all spam reviewers using an unsupervised learning approach. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao |
GLOBECOM | 2 |
| 2020 | Multi-Armed-Bandit-based Shilling Attack on Collaborative Filtering Recommender SystemsabstractCollaborative Filtering (CF) is a popular recommendation system that makes recommendations based on similar users’ preferences. Though it is widely used, CF is prone to Shilling/Profile Injection attacks, where fake profiles are injected into the CF system to alter its outcome. Most of the existing shilling attacks do not work on online systems and cannot be efficiently implemented in real-world applications. In this paper, we introduce an efficient Multi-Armed-Bandit-based reinforcement learning method to practically execute online shilling attacks. Our method works by reducing the uncertainty associated with the item selection process and finds the most optimal items to enhance attack reach. Such practical online attacks open new avenues for research in building more robust recommender systems. We treat the recommender system as a black box, making our method effective irrespective of the type of CF used. Finally, we also experimentally test our approach against popular state-of-the-art shilling attacks. Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Qin Hu 0001, Tianchong Gao |
MASS | 2 |
| 2019 | Sharing Social Networks Using a Novel Differentially Private Graph ModelabstractOnline social networks (OSNs) often contain sensitive information about individuals. Therefore, anonymizing social network data before releasing it becomes an important issue. Recent research introduces several graph abstraction models to extract graph features and add sufficient noise to achieve differential privacy.In this paper, we design and analyze a comprehensive differentially private graph model that combines the dK-1, dK-2, and dK-3 series together. The dK-1 series stores the degree frequency, the dK-2 series adds the joint degree frequency, and the dK-3 series contains the linking information between edges. In our scheme, low dimensional data makes the regeneration process more executable and effective, while high dimensional data preserves additional utility of the graph. As the higher dimensional model is more sensitive to the noise, we carefully design the executing sequence. The final released graph increases the graph utility under differential privacy. Tianchong Gao, Feng Li 0001 |
CCNC | 2 |
| 2019 | Efficient Content Delivery via Interest QueueingabstractContent sharing is an approach to relieve the congestion of cellular networks with alternative communication technologies such as the Wi-Fi and bluetooth. Through a Content Delivery Network (CDN), only a small portion of users need to download the data directly. Other users obtain packets from these users through short-range communications. However, the uncertainty of movement of mobile users challenges the effectiveness of CDNs. Unlike previous CDN solutions, in this paper, we present a novel scheme that studies the probabilistic meeting of users. When the accessibility to the cellular network is limited, we apply the queueing theory to guide the downloading or waiting strategies of users. In this system, the users who hold the content become seeds in the CDN and benefit their neighbors. Therefore we also consider the seed growing performance in the strategy. The purpose of our scheme is to let every user efficiently obtain their target content with restricted cellular data. The evaluation results show that our scheme gains significant satisfaction throughput improvements compared to the performance of basic downloading strategies. Tianchong Gao, Feng Li 0001 |
ICC | 2 |
| 2019 | De-Anonymization of Dynamic Online Social Networks via Persistent StructuresabstractService providers of Online Social Networks (OSNs) periodically publish anonymized OSN data, which creates an opportunity for adversaries to de-anonymize the data and identify target users. Most commonly, these adversaries use de-anonymization mechanisms that focus on static graphs. Some mechanisms separate dynamic OSN data into slices of static graphs, in order to apply a traditional de-anonymization attack. However, these mechanisms do not account for the evolution of OSNs, which limits their attack performance. In this paper, we provide a novel angle, persistent homology, to capture the evolution of OSNs. Persistent homology barcodes show the birth time and death time of holes, i.e., polygons, in OSN graphs. After extracting the evolution of holes, we apply a two-phase de-anonymization attack. First, holes are mapped together according to the similarity of birth/death time. Second, already mapped holes are converted into super nodes and we view them as seed nodes. We then grow the mapping based on these seed nodes. Our de-anonymization mechanism is extremely compatible to the adversaries who suffer latency in relationship collection, which is very similar to real-world cases. Tianchong Gao, Feng Li 0001 |
ICC | 2 |
| 2019 | PHDP: Preserving Persistent Homology in Differentially Private Graph PublicationsabstractOnline social networks (OSNs) routinely share and analyze user data. This requires protection of sensitive user information. Researchers have proposed several techniques to anonymize the data of OSNs. Some differential-privacy techniques claim to preserve graph utility under certain graph metrics, as well as guarantee strict privacy. However, each graph utility metric reveals the whole graph in specific aspects.We employ persistent homology to give a comprehensive description of the graph utility in OSNs. This paper proposes a novel anonymization scheme, called PHDP, which preserves persistent homology and satisfies differential privacy. To strengthen privacy protection, we add exponential noise to the adjacency matrix of the network and find the number of adding/deleting edges. To maintain persistent homology, we collect edges along persistent structures and avoid perturbation on these edges. Our regeneration algorithms balance persistent homology with differential privacy, publishing an anonymized graph with a guarantee of both. Evaluation result show that the PHDP-anonymized graph achieves high graph utility, both in graph metrics and application metrics. Tianchong Gao, Feng Li 0001 |
INFOCOM | 2 |
| 2019 | Enhancing Biometric-Capsule-based Authentication and Facial Recognition via Deep LearningabstractIn recent years, developers have used the proliferation of biometric sensors in smart devices, along with recent advances in deep learning, to implement an array of biometrics-based authentication systems. Though these systems demonstrate remarkable performance and have seen wide acceptance, they present unique and pressing security and privacy concerns. One proposed method which addresses these concerns is the elegant, fusion-based BioCapsule method. The BioCapsule method is provably secure, privacy-preserving, cancellable and flexible in its secure feature fusion design. In this work, we extend BioCapsule to face-based recognition. Moreover, we incorporate state-of-art deep learning techniques into a BioCapsule-based facial authentication system to further enhance secure recognition accuracy. We compare the performance of an underlying recognition system to the performance of the BioCapsule-embedded system in order to demonstrate the minimal effects of the BioCapsule scheme on underlying system performance. We also demonstrate that the BioCapsule scheme outperforms or performs as well as many other proposed secure biometric techniques. Tyler Phillips 0001, Xukai Zou, Feng Li 0001, Ninghui Li 0001 |
SACMAT | 3 |
| 2019 | Privacy-Preserving Sketching for Online Social Network Data PublicationabstractReleasing private data can cause panic to both Online Social Network (OSN) users and service providers. Therefore, anonymization mechanisms are proposed to protect data before sharing it. However, some of these mechanisms set unrealistic privacy demands but cannot defend against real-world de-anonymization attacks.In this paper, we introduce an anonymization algorithm based on All-Distance Sketch (ADS). Sketching can significantly limit attackers’ confidence, as well as provide accurate estimation about shortest path length and other utility metrics. Because sketching removes large amounts of edges, it is invulnerable to seed-based and subgraph-based de-anonymization attacks. However, existing sketching algorithms do not add dummy edges and paths. Adversaries have low false positive in extracting linking information, which challenges the privacy performance. We propose the novel bottom-(l, k) sketch to defend against these advanced attacks. We develop a scheme to add and delete enough edges to satisfy our privacy demand. The experiment results show that our published graphs are closely matched with the original graphs under some metrics, preserving utility, while 80% edges are removed, ensuring privacy. Tianchong Gao, Feng Li 0001 |
SECON | 2 |
| 2019 | Android Malware Detection via Graphlet SamplingabstractAndroid systems are widely used in mobile & wireless distributed systems. In the near future, Android is believed to dominate the mobile distributed environment. However, with the popularity of Android-based smartphones/tablets comes the rampancy of Android-based malware. In this paper, we propose a novel topological signature of Android apps based on the function call graphs (FCGs) extracted from their Android App PacKages (APKs). Specifically, by leveraging recent advances on graphlet mining, the proposed method fully captures the invocator-invocatee relationship at local neighborhoods in an FCG without exponentially inflating the state space. Using real benign app and malware samples, we demonstrate that our method, App topologiCal signature through graphleT Sampling (ACTS), can detect malware and identify malware families robustly and efficiently. More importantly, we demonstrate that, without augmenting the FCG with any semantic features such as bytecode-based vertex typing, local topological information captured by ACTS alone can achieve a high malware detection accuracy. Since ACTS only uses structural features, which are orthogonal to semantic features, it is expected that combining them would give a greater improvement in malware detection accuracy than combining non-orthogonal semantic features. Tianchong Gao, Wei Peng 0007, Devkishen Sisodia, Tanay Kumar Saha, Feng Li 0001, Mohammad Al Hasan |
IEEE Trans. Mob. Comput. | 5 |
| 2018 | Studying the utility preservation in social network anonymization via persistent homology
Tianchong Gao, Feng Li 0001 |
Comput. Secur. | 2 |
| 2018 | Local Differential Privately Anonymizing Online Social Networks Under HRG-Based ModelabstractFollowing the trend of online social networks (OSNs) data sharing and publishing, users raise serious concerns on OSN privacy. Differential privacy is a mechanism to anonymize sensitive data. It employs graph abstraction models, such as the hierarchical random graph (HRG) model, to extract graph features and then add sufficient noise. However, the noise amount, determined by the sensitivity, is usually proportional to the size of the whole network. Therefore, achieving global differential privacy may harm the utility of releasing graphs. In this paper, we define the notion of group-based local differential privacy. In particular, by resolving the network into 1-neighborhood graphs and applying HRG-based methods, our scheme preserves differential privacy and reduces the noise scale on the local graphs. By deploying the grouping algorithm, our scheme abandons the attempt to anonymize every relationship to be ordinary, but we focus on the similarities in HRG models. In the final released graph, each individual user in one group is not distinguishable, which greatly enhances the OSN privacy. We experimentally evaluate our approach on three real-world OSNs. It produces synthetic graphs that are more closely matched with the originals compared with the existing differential-privacy results. Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2017 | Preserving Graph Utility in Anonymized Social Networks? A Study on the Persistent HomologyabstractFollowing the trend of privacy preserving online social network publishing, various anonymization mechanisms have been designed and employed. Many differential privacybased mechanisms claim that they can preserve the utility as well as guarantee the privacy. Their utility analysis are always based on some specifically chosen metrics.This paper aims to find a novel angle that describing the network in multiple scales. Persistent homology is such a high level metric that it reveals the parameterized topological features with various scales and it is applicable for read-world applications. In this paper, four differential privacy mechanisms employing different models are analyzed under the traditional graph metrics and the persistent homology. The evaluation results demonstrate that all algorithms can partially or conditionally preserve certain traditional graph utilities, but none of them are suitable for all metrics. Furthermore, none of the existing mechanisms can fully preserve the persistent homology, especially in high dimensions, which implies that the true graph utility is lost. Tianchong Gao, Feng Li 0001 |
MASS | 2 |
| 2017 | Using Persistent Homology to Represent Online Social Network GraphsabstractOnline Social Networks (OSNs) are simple, unweighted graphs used to store information in the context of social media and emails. Accurately representing the connectivity and features of these graphs is important in applications of graph utility and differential privacy. Current methods of describing these network graphs use graph metrics such as the shortest-path betweenness centrality, clustering coefficient, and degree distribution. Although these metrics are sufficient in providing information about a particular aspect of network graphs, they fail to give a multi-faceted snapshot of an OSN. Persistent homology provides a novel method for a comprehensive visual representation of the information stored in network graphs. By translating a network graph to a persistent homology barcode format, the correlation in key features between the figures will be observed against various utility metrics. This paper evaluates the persistent homology barcodes of OSNs across social media platforms and provides a means of analyzing network graphs without revealing sensitive information. Tianchong Gao, Feng Li 0001 |
MASS | 2 |
| 2017 | A Cancellable and Privacy-Preserving Facial Biometric Authentication SchemeabstractIn recent years, biometric, or "who you are," authentication has grown rapidly in acceptance and use. Biometric authentication offers users the convenience of not having to carry a password, PIN, smartcard, etc. Instead, users will use their inherent biometric traits for authentication and, as a result, risk their biometric information being stolen. The security of users’ biometric information is of critical importance within a biometric authentication scheme as compromised data can reveal sensitive information: race, gender, illness, etc. A cancellable biometric scheme, the "BioCapsule" scheme, proposed by researchers from Indiana University Purdue University Indianapolis, aims to mask users’ biometric information and preserve users’ privacy. The BioCapsule scheme can be easily embedded into existing biometric authentication systems, and it has been shown to preserve user-privacy, be resistant to several types of attacks, and have minimal effects on biometric authentication system accuracy.In this research we present a facial authentication system which employs several cutting-edge techniques. We tested our proposed system on several face databases, both with and without the BioCapsule scheme being embedded into our system. By comparing our results, we quantify the effects the BioCapsule scheme, and its security benefits, have on the accuracy of our facial authentication system. Tyler Phillips 0001, Xukai Zou, Feng Li 0001 |
MASS | 3 |
| 2017 | No one can track you: Randomized authentication in Vehicular Ad-hoc NetworksabstractVehicular Ad-hoc Networks (VANETs) are formed by a huge number of vehicles which act as the network nodes and communicate with one another. This emerging paradigm has opened up new business opportunities and enables numerous applications ranging from road safety enhancement to mobile entertainment. A fundamental issue that impacts the successful deployment of VANET applications is the security and privacy concerns raised by VANET users. However, it is a challenging task to authenticate vehicles while fully preserving their privacy. In this work, we propose a novel privacy-preserving randomized authentication protocol that leverages Homomorphic encryption to allow each individual vehicle to self-generate any number of authenticated identities to achieve full anonymity in VANETs. The proposed protocol prevents vehicles from being tracked by any single party including peer vehicles, service providers, authentication servers, and other infrastructure. Meanwhile, our protocol also provides traceability in case of any dispute. We have conducted both security analysis and experimental study which demonstrates the superiority of our protocol compared to other existing works. Wei Jiang 0026, Feng Li 0001, Dan Lin 0001, Elisa Bertino |
PerCom | 2 |
| 2017 | Preserving Local Differential Privacy in Online Social Networks
Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou |
WASA | 2 |
| 2017 | Preserving Privacy with Probabilistic Indistinguishability in Weighted Social NetworksabstractThe increasing popularity of social networks has inspired recent research to explore social graphs for marketing and data mining. As social networks often contain sensitive information about individuals, preserving privacy when publishing social graphs becomes an important issue. In this paper, we consider the identity disclosure problem in releasingweightedsocial graphs. We identifyweighted 1*-neighborhood attacks, which assume that an attacker has knowledge about not only a target's one-hop neighbors and connections between them (1-neighborhood graph), but also related node degrees and edge weights. With this information, an attacker may re-identify a target with high confidence, even if any node's 1-neighborhood graph is isomorphic with$k-1$other nodes’ graphs. To counter this attack while preserving high utility of the published graph, we define a key privacy property,probabilistic indistinguishability, and propose a heuristic indistinguishable group anonymization (HIGA) scheme to anonymize a weighted social graph with such a property. Extensive experiments on both real and synthetic data sets illustrate the effectiveness and efficiency of the proposed scheme. Qin Liu 0001, Guojun Wang 0001, Feng Li 0001, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2016 | Trust Evaluation in Online Social Networks Using Generalized Network FlowabstractIn online social networks (OSNs), to evaluate trust from one user to another indirectly connected user, the trust evidence in the trusted paths (i.e., paths built through intermediate trustful users) should be carefully treated. Some paths may overlap with each other, leading to a unique challenge ofpath dependence, i.e., how to aggregate the trust values of multiple dependent trusted paths. OSNs bear the characteristic of high clustering, which makes the path dependence phenomenon common. Another challenge istrust decaythrough propagation, i.e., how to propagate trust along a trusted path, considering the possible decay in each node. We analyze the similarity between trust propagation and network flow, and convert a trust evaluation task with path dependence and trust decay into a generalized network flow problem. We propose a modified flow-based trust evaluation schemeGFTrust, in which we address path dependence using network flow, and model trust decay with the leakage associated with each node. Experimental results, with the real social network data sets of Epinions and Advogato, demonstrate that GFTrust can predict trust in OSNs with a high accuracy, and verify its preferable properties. Jie Wu 0001, Feng Li 0001, Guojun Wang 0001, Huanyang Zheng |
IEEE Trans. Computers | 3 |
| 2015 | Temporal coverage based content distribution in heterogeneous smart device networksabstractThe present work studies content distribution in heterogeneous smart device networks, in which all smartphones/ tablets can communicate through proximity channels such as Bluetooth/NFC/Wi-Fi Direct when they are in proximity, but only some devices have the cellular data communication capability. In the context of recent applications of content distribution in smart device networks such as mobile offloading and enterprise network defense prioritization, we propose a temporal coverage based scheme that exploits nodes' encounter regularity and content's delivery delay tolerance to reduce content delivery costs. Using kernel-density estimation (KDE) on the readily available proximity encounter records, we propose a network structural property, T-covering set, and a corresponding localized algorithm that distributedly elects a T-covering set from the underlying network. Using real Bluetooth encounter traces, we demonstrate that temporal coverage based content distribution using T-covering set can significantly reduce content delivery cost with minimal delay and no sacrifice in coverage. Wei Peng 0007, Feng Li 0001, Xukai Zou |
ICC | 2 |
| 2015 | Enhancing and Implementing Fully Transparent Internet VotingabstractVoting over the internet has been the focus of significant research with the potential to solve many problems. Current implementations typically suffer from a lack of transparency, where the connection between vote casting and result tallying is seen as a black box by voters. A new protocol was recently proposed that allows full transparency, never obfuscating any step of the process, and splits authority between mutually-constraining conflicting parties. Achieving such transparency brings with it challenging issues. In this paper we propose an efficient algorithm for generating unique, anonymous identifiers (voting locations) that is based on the Chinese Remainder Theorem, we extend the functionality of an election to allow for races with multiple winners, and we introduce a prototype of this voting system implemented as a multiplatform web application. Kevin Butterfield, Huian Li, Xukai Zou, Feng Li 0001 |
ICCCN | 4 |
| 2014 | Outsourceable two-party privacy-preserving biometric authenticationabstractBiometric authentication, a key component for many secure protocols and applications, is a process of authenticating a user by matching her biometric data against a biometric database stored at a server managed by an entity. If there is a match, the user can log into her account or obtain the services provided by the entity. Privacy-preserving biometric authentication (PPBA) considers a situation where the biometric data are kept private during the authentication process. That is the user's biometric data record is never disclosed to the entity, and the data stored in the entity's biometric database are never disclosed to the user. Due to the reduction in operational costs and high computing power, it is beneficial for an entity to outsource not only its data but also computations such as biometric authentication process to a cloud. However, due to well-documented security risks faced by a cloud, sensitive data like biometrics should be encrypted first and then outsourced to the cloud. When the biometric data are encrypted and cannot be decrypted by the cloud, the existing PPBA protocols are not applicable. Therefore, in this paper, we propose a two-party PPBA protocol when the biometric data in consideration are fully encrypted and outsourced to a cloud. In the proposed protocol, the security of the biometric data is completely protected since the encrypted biometric data are never decrypted during the authentication process. In addition, we formally analyze the security of the proposed protocol and provide extensive empirical results to show its runtime complexity. Hu Chun, Yousef Elmehdwi, Feng Li 0001, Prabir Bhattacharya, Wei Jiang 0026 |
AsiaCCS | 3 |
| 2014 | A moving-target defense strategy for Cloud-based services with heterogeneous and dynamic attack surfacesabstractDue to deep automation, the configuration of many Cloud infrastructures is static and homogeneous, which, while easing administration, significantly decreases a potential attacker's uncertainty on a deployed Cloud-based service and hence increases the chance of the service being compromised. Moving-target defense (MTD) is a promising solution to the configuration staticity and homogeneity problem. This paper presents our findings on whether and to what extent MTD is effective in protecting a Cloud-based service with heterogeneous and dynamic attack surfaces — these attributes, which match the reality of current Cloud infrastructures, have not been investigated together in previous works on MTD in general network settings. We 1) formulate a Cloud-based service security model that incorporates Cloud-specific features such as VM migration/snapshotting and the diversity/compatibility of migration, 2) consider the accumulative effect of the attacker's intelligence on the target service's attack surface, 3) model the heterogeneity and dynamics of the service's attack surfaces, as defined by the (dynamic) probability of the service being compromised, as an S-shaped generalized logistic function, and 4) propose a probabilistic MTD service deployment strategy that exploits the dynamics and heterogeneity of attack surfaces for protecting the service against attackers. Through simulation, we identify the conditions and extent of the proposed MTD strategy's effectiveness in protecting Cloud-based services. Namely, 1) MTD is more effective when the service deployment is dense in the replacement pool and/or when the attack is strong, and 2) attack-surface heterogeneity-and-dynamics awareness helps in improving MTD's effectiveness. Wei Peng 0007, Feng Li 0001, Chin-Tser Huang, Xukai Zou |
ICC | 2 |
| 2014 | Feedback-based smartphone strategic sampling for BYOD securityabstractBring Your Own Device (BYOD) is an information technology (IT) policy that allows employees to use their own wireless devices to access internal network at work. Mobile malware is a major security concern that impedes BYOD's further adoption in enterprises. Existing works identify the need for better BYOD security mechanisms that balance between the strength of such mechanisms and the costs of implementing such mechanisms. In this paper, based on the idea of self-reinforced feedback loop, we propose a periodic smartphone sampling mechanism that significantly improve BYOD security mechanism's effectiveness without incurring further costs. We quantify the likelihood that “a BYOD smartphone is infected by malware” by two metrics, vulnerability and uncertainty, and base the iterative sampling process on these two metrics; the updated values of these metrics are fed back into future rounds of the mechanism to complete the feedback loop. We validate the efficiency and effectiveness of the proposed strategic sampling via simulations driven by publicly available, real-world collected traces. Feng Li 0001, Chin-Tser Huang, Wei Peng 0007 |
ICCCN | 1 |
| 2014 | Assurable, transparent, and mutual restraining e-voting involving multiple conflicting partiesabstractE-voting techniques and systems have not been widely accepted and deployed by society due to various concerns and problems. One particular issue associated with many existing e-voting techniques is the lack of transparency, leading to the failure to deliver voter assurance. In this work, we propose an assurable, transparent, and mutual restraining e-voting protocol that exploits the existing two-party political dynamics in the US. The proposed e-voting protocol consists of three original technical contributions — universal verifiable voting vector, forward and backward mutual lock voting, and in-process check and enforcement — that, in combination, resolves the apparent conflicts in voting such as anonymity vs. accountability and privacy vs. verifiability. Especially, the trust is split equally among tallying authorities who have conflicting interests and will technically restrain each other. The voting and tallying processes are transparent to voters and any third party, which allow any voter to verify that his vote is indeed counted and also allow any third party to audit the tally. Xukai Zou, Huian Li, Yan Sui, Wei Peng 0007, Feng Li 0001 |
INFOCOM | 5 |
| 2014 | A Two-Stage Deanonymization Attack against Anonymized Social NetworksabstractDigital traces left by users of online social networking services, even after anonymization, are susceptible to privacy breaches. This is exacerbated by the increasing overlap in user-bases among various services. To alert fellow researchers in both the academia and the industry to the feasibility of such an attack, we propose an algorithm, Seed-and-Grow, to identify users from an anonymized social graph, based solely on graph structure. The algorithm first identifies a seed subgraph, either planted by an attacker or divulged by a collusion of a small group of users, and then grows the seed larger based on the attacker's existing knowledge of the users' social relations. Our work identifies and relaxes implicit assumptions taken by previous works, eliminates arbitrary parameters, and improves identification effectiveness and accuracy. Simulations on real-world collected data sets verify our claim. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
IEEE Trans. Computers | 2 |
| 2014 | Design and Analysis of a Highly User-Friendly, Secure, Privacy-Preserving, and Revocable Authentication MethodabstractA large portion of system breaches are caused by authentication failure, either during the login process or in the post-authentication session; these failures are themselves related to the limitations associated with existing authentication methods. Current authentication methods, whether proxy based or biometrics based, are not user-centric and/or endanger users’ (biometric) security and privacy. In this paper, we propose a biometrics based user-centric authentication approach. This method involves introducing a reference subject (RS), securely fusing the user’s biometrics with the RS, generating a BioCapsule (BC) from the fused biometrics, and employing BCs for authentication. Such an approach is user friendly, identity bearing yet privacy-preserving, resilient, and revocable once a BC is compromised. It also supports “one-click sign-on” across systems by fusing the user’s biometrics with a distinct RS on each system. Moreover, active and non-intrusive authentication can be automatically performed during post-authentication sessions. We formally prove that the secure fusion based approach is secure against various attacks. Extensive experiments and detailed comparison with existing approaches show that its performance (i.e., authentication accuracy) is comparable to existing typical biometric approaches and the new BC based approach also possesses many desirable features such as diversity and revocability. Yan Sui, Xukai Zou, Yingzi Du, Feng Li 0001 |
IEEE Trans. Computers | 4 |
| 2014 | Behavioral Malware Detection in Delay Tolerant NetworksabstractThe delay-tolerant-network (DTN) model is becoming a viable communication alternative to the traditional infrastructural model for modern mobile consumer electronics equipped with short-range communication technologies such as Bluetooth, NFC, and Wi-Fi Direct. Proximity malware is a class of malware that exploits the opportunistic contacts and distributed nature of DTNs for propagation. Behavioral characterization of malware is an effective alternative to pattern matching in detecting malware, especially when dealing with polymorphic or obfuscated malware. In this paper, we first propose a general behavioral characterization of proximity malware which based on naive Bayesian model, which has been successfully applied in non-DTN settings such as filtering email spams and detecting botnets. We identify two unique challenges for extending Bayesian malware detection to DTNs ("insufficient evidence versus evidence collection risk" and "filtering false evidence sequentially and distributedly"), and propose a simple yet effective method, look ahead, to address the challenges. Furthermore, we propose two extensions to look ahead, dogmatic filtering, and adaptive look ahead, to address the challenge of "malicious nodes sharing false evidence." Real mobile network traces are used to verify the effectiveness of the proposed methods. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Sybil defenses in mobile social networksabstractMobile social networks are vulnerable to Sybil attacks. By creating a large number of fake identities, malicious users can gain a disproportionately high benefit through a Byzantine fashion. Most social network-based Sybil defenses adopt the assumptions that the honest region is a fast-mixing network. However, more and more evidence shows that some real social networks are not fast-mixing, especially when only strong-trust relations are considered. Moreover, the accuracy of all existing solutions is related to the number of attack edges that the adversary can build. In this paper, for addressing these problems, we propose a local ranking system for estimating trust-level between users. Our scheme has three unique features. First, our system is based on both trust and distrust relations. Second, instead of storing the entire social graph, users carry limited information related to themselves. Last but not least, our system weakens the impacts of attack edges by removing several suspicious edges with high centrality. We validate the effectiveness of our solutions through comprehensive experiments. Wei Chang 0001, Jie Wu 0001, Chiu C. Tan 0001, Feng Li 0001 |
GLOBECOM | 4 |
| 2013 | Smartphone strategic sampling in defending enterprise network securityabstractSmartphones have made their inroads in enterprise environment, manifested in the Bring Your Own Device (BYOD) policy: More employees are bringing their own smartphones to work and are using them to access enterprise information assets. The dilemma between responsiveness to security incidents and convenience/cost-effectiveness demands BYOD security solutions beyond the straightforward all-inclusive full-scanning or uniformly random sampling approaches. In this paper, we propose a carefully planned but otherwise random, or strategic, sampling approach out of this dilemma. Strategic sampling provides a balance between security responsiveness and cost effectiveness by identifying and periodically sampling those representative smartphones (security-wise). We validate the efficiency and effectiveness of the proposed strategic sampling via simulations driven by publicly available, real-world collected traces. Feng Li 0001, Wei Peng 0007, Chin-Tser Huang, Xukai Zou |
ICC | 1 |
| 2013 | Outsourcing privacy-preserving social networks to a cloudabstractIn the real world, companies would publish social networks to a third party, e.g., a cloud service provider, for marketing reasons. Preserving privacy when publishing social network data becomes an important issue. In this paper, we identify a novel type of privacy attack, termed 1∗-neighborhood attack. We assume that an attacker has knowledge about the degrees of a target's one-hop neighbors, in addition to the target's 1-neighborhood graph, which consists of the one-hop neighbors of the target and the relationships among these neighbors. With this information, an attacker may re-identify the target from a k-anonymity social network with a probability higher than 1/k, where any node's 1-neighborhood graph is isomorphic with k-1 other nodes' graphs. To resist the 1∗-neighborhood attack, we define a key privacy property, probability indistinguishability, for an outsourced social network, and propose a heuristic indistinguishable group anonymization (HIGA) scheme to generate an anonymized social network with this privacy property. The empirical study indicates that the anonymized social networks can still be used to answer aggregate queries with high accuracy. Guojun Wang 0001, Qin Liu 0001, Feng Li 0001, Jie Wu 0001 |
INFOCOM | 3 |
| 2013 | The Virtue of Patience: Offloading Topical Cellular Content through Opportunistic LinksabstractMobile data offloading is an approach to alleviating overloaded cellular traffic through alternative communication technologies on smartphones. Inspired by the prospect of spontaneous, peer-assisted, bulk data transfer through NFC or Wi-Fi Direct between proximate users' smartphones, we propose a model for mobile data offloading through the opportunistic proximity (e.g., Wi-Fi Direct) links with bounded content delivery delay and differential interests in content. Unlike the previous formulation of mobile data offloading as a target-set selection problem, which, essentially, asks the question "who (will download the content through the cellular link)," we ask "who" and "when." We present methods for individual users to locally estimate (their and their acquaintances') topological importance on the opportunistic proximity-link-based networks and aggregated interests in content. These factors are consolidated into a time-dependent function that embodies the concept of users' patience for the content. Each individual user, then, periodically make a probabilistic cellular download decision based on its patience at that time. Our motivation and insights are: 1) Involving topologically important, but otherwise disinterested, users in downloading and forwarding content helps improve offloading efficiency, 2) situation awareness embodied in the time-dependent patience function is desirable, since it allows users to react to hard-to-predict contact opportunities on the fly. Through trace-driven simulations, we corroborate our insights, and demonstrate the effectiveness of our proposed method in reducing cellular costs. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
MASS | 2 |
| 2012 | A joint replication-migration-based routing in delay tolerant networksabstractDelay tolerant networks (DTNs) use mobility-assisted routing, where nodes carry, store, and forward data to each other in order to overcome the intermittent connectivity and limited network capacity of this type of network. In this paper, we propose a routing protocol that includes two mechanisms: message replication and message migration. Each mechanism has two steps: message selection and node selection. In message replication, we choose the smallest hop-count message to replicate. The hop-count threshold is used to control the replication speed. We propose a metric called 2-hop activity level to measure the relay node's transmission capacity, which is used in node selection. Our protocol includes a novel message migration policy that is used to overcome the limited buffer space and bandwidth of DTN nodes. We validate our protocol via extensive simulation experiments; we use a combination of synthetic and real mobility traces. Yunsheng Wang 0001, Jie Wu 0001, Feng Li 0001 |
ICC | 4 |
| 2012 | Seed and Grow: An attack against anonymized social networksabstractDigital traces left by a user of an online social networking service can be abused by a malicious party to compromise the person's privacy. This is exacerbated by the increasing overlap in user-bases among various services. In this paper, we propose an algorithm, Seed and Grow, to identify users from an anonymized social graph based solely on graph structure. The algorithm first identifies a seed sub-graph, either planted by an attacker or divulged by collusion of a small group of users, and then grows the seed larger based on the attacker's existing knowledge of the users' social relations. Our work identifies and relaxes implicit assumptions taken by previous works, eliminates arbitrary parameters, and improves identification effectiveness and accuracy. Experiments on real-world collected datasets further corroborate our expectation and claim. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
SECON | 2 |
| 2012 | A privacy-preserving social-aware incentive system for word-of-mouth advertisement dissemination on smart mobile devicesabstractThe recent penetration of smart mobile devices into the consumer market sets a stage for novel network applications. In particular, we envision a paradigm shift in the commercial advertising model facilitated by the widespread uses of these devices: advertisements circulate in a word-of-mouth fashion among device users and reach potential customers based on the users' knowledge about their contacts. In this paper, we identify two major challenges baffling the deployment of such an application: users' selfishness and their privacy concerns. We address the selfishness issue by proposing an incentive scheme which aligns users' interest with that of advertisers in a way that the users are willing to fully explore their social knowledge for effective advertisement deliveries - the emphasis is not only on users' participation but also on the extent and effectiveness of their contributions. We address the privacy concerns by designing a privacy-preserving evidence-collection mechanism, on which the incentive scheme is based. In addition, our design is 1) appealing to advertisers by guaranteeing effectiveness and controllability of the incentive dispensing and 2) robust against users' misbehaviors. We perceive incentive and enforcement as the keys to unlock the power of users' collective intelligence for effective information dissemination. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
SECON | 2 |
| 2012 | Secure and privacy-preserving biometrics based active authenticationabstractUser authentication is critical in preventing system breaches. Existing authentication approaches usually do a onetime log-in authentication, but rarely incorporate mechanisms to differentiate the initial log-in user and the user who is currently taking control of the system, which may cause post-authentication breaches. In this paper, we study user authentication for both login session and post-authentication session and propose a biometrics based active authentication approach. Moreover, concerning the usage of biometrics, the system is biometrics-secure and privacy-preserving. Security analysis and experimental results prove that the proposed approach is secure, resilient to various attacks and effective. Yan Sui, Xukai Zou, Yingzi Du, Feng Li 0001 |
SMC | 4 |
| 2012 | Active User Authentication for Mobile Devices
Yan Sui, Xukai Zou, Feng Li 0001, Yingzi Du |
WASA | 3 |
| 2012 | On Maximizing the Lifetime of Wireless Sensor Networks Using Virtual Backbone SchedulingabstractWireless Sensor Networks (WSNs) are key for various applications that involve long-term and low-cost monitoring and actuating. In these applications, sensor nodes use batteries as the sole energy source. Therefore, energy efficiency becomes critical. We observe that many WSN applications require redundant sensor nodes to achieve fault tolerance and Quality of Service (QoS) of the sensing. However, the same redundancy may not be necessary for multihop communication because of the light traffic load and the stable wireless links. In this paper, we present a novel sleep-scheduling technique called Virtual Backbone Scheduling (VBS). VBS is designed for WSNs has redundant sensor nodes. VBS forms multiple overlapped backbones which work alternatively to prolong the network lifetime. In VBS, traffic is only forwarded by backbone sensor nodes, and the rest of the sensor nodes turn off their radios to save energy. The rotation of multiple backbones makes sure that the energy consumption of all sensor nodes is balanced, which fully utilizes the energy and achieves a longer network lifetime compared to the existing techniques. The scheduling problem of VBS is formulated as the Maximum Lifetime Backbone Scheduling (MLBS) problem. Since the MLBS problem is NP-hard, we propose approximation algorithms based on the Schedule Transition Graph (STG) and Virtual Scheduling Graph (VSG). We also present an Iterative Local Replacement (ILR) scheme as a distributed implementation. Theoretical analyses and simulation studies verify that VBS is superior to the existing techniques. Yaxiong Zhao, Jie Wu 0001, Feng Li 0001, Sanglu Lu |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2011 | A New Approach to Weighted Multi-Secret SharingabstractSecret sharing is important in information and network security and has broad applications in the real world. Since an elegant secret sharing mechanism was first proposed by Shamir in 1979, many schemes have appeared in literature. These schemes deal with either single or multiple secrets and their shares have either the same weight or different weights. Weighted shares mean that different shares have different capabilities in recovering the secret(s) -- a more (less) weighted share needs fewer (more) other shares to recover the secret(s). In this paper, we identify a direct relation between the length (i.e., the number of bits) and the weight of shares and, based on this relation, present a new Chinese Remainder Theorem (CRT) based weighted multiple secret sharing scheme. This scheme can also be naturally applied to other cases such as sharing a single secret with same-weight shares and is remarkably simple and easy to implement. Compared to both Shamir's scheme and Mignotte's scheme -- the representative of existing CRT based secret sharing schemes, the new scheme is more efficient than both schemes in share computation and more efficient than Shamir's scheme (and as efficient as Mignotte's scheme) in secret recovery. One prominent advantage of the new scheme is that the sizes of shares can vary distantly to fit different requirements and constraints of various devices such as sensors, PDAs, cell phones, iPads, hence, the new scheme is able to apply to broader applications involving wireless/sensor networks and pervasive computing. Xukai Zou, Fabio Maino, Elisa Bertino, Yan Sui, Kai Wang 0026, Feng Li 0001 |
ICCCN | 6 |
| 2011 | Behavioral Detection and Containment of Proximity Malware in Delay Tolerant NetworksabstractWith the universal presence of short-range connectivity technologies (e.g., Bluetooth and, more recently, Wi-Fi Direct) in the consumer electronics market, the delay-tolerant-network (DTN) model is becoming a viable alternative to the traditional infrastructural model. Proximity malware, which exploits the temporal dimension and distributed nature of DTNs in self-propagation, poses threats to users of new technologies. In this paper, we address the proximity malware detection and containment problem with explicit consideration for the unique characteristics of DTNs. We formulate the malware detection process as a decision problem under a general behavioral malware characterization framework. We analyze the risk associated with the decision problem and design a simple yet effective malware containment strategy, look-ahead, which is distributed by nature and reflects an individual node's intrinsic trade-off between staying connected (with other nodes) and staying safe (from malware). Furthermore, we consider the benefits of sharing assessments among directly connected nodes and address the challenges derived from the DTN model to such sharing in the presence of liars (i.e., malicious nodes sharing false assessments) and defectors (i.e., good nodes that have turned malicious due to malware infection). Real mobile network traces are used to verify our analysis. Wei Peng 0007, Feng Li 0001, Xukai Zou, Jie Wu 0001 |
MASS | 2 |
| 2010 | CPMC: An Efficient Proximity Malware Coping Scheme in Smartphone-based Mobile NetworksabstractSmartphones are envisioned to provide promising applications and services. At the same time, smartphones are also increasingly becoming the target of malware. Many emerging malware can utilize the proximity of devices to propagate in a distributed manner, thus remaining unobserved and making detections substantially more challenging. Different from existing malware coping schemes, which are either totally centralized or purely distributed, we propose a Community-based Proximity Malware Coping scheme, CPMC. CPMC utilizes the social community structure, which reflects a stable and controllable granularity of security, in smartphone-based mobile networks. The CPMC scheme integrates short-term coping components, which deal with individual malware, and long-term evaluation components, which offer vulnerability evaluation towards individual nodes. A closeness-oriented delegation forwarding scheme combined with a community level quarantine method is proposed as the short-term coping components. These components contain a proximity malware by quickly propagating the signature of a detected malware into all communities while avoiding unnecessary redundancy. The long-term components offer vulnerability evaluation towards neighbors, based on the observed infection history, to help users make comprehensive communication decisions. Extensive real- and synthetic-trace driven simulation results are presented to to evaluate the effectiveness of CPMC. Feng Li 0001, Yinying Yang, Jie Wu 0001 |
INFOCOM | 1 |
| 2010 | VBS: Maximum Lifetime Sleep Scheduling for Wireless Sensor Networks Using Virtual BackbonesabstractWireless sensor network (WSN) applications require redundant sensors to guarantee fault tolerance. However, the same degree of redundancy is not necessary for multi-hop communication. In this paper, we present a new scheduling method called virtual backbone scheduling (VBS). VBS employs heterogeneous scheduling, where backbone nodes work with duty-cycling to preserve network connectivity, and non-backbone nodes turn off radios to save energy. We formulate a maximum lifetime backbone scheduling (MLBS) problem to maximize the network lifetime using this scheduling model. Because the MLBS problem is NP-hard, two approximation solutions based on the schedule transition graph (STG) and virtual scheduling graph (VSG) are proposed.We also present an iterative local replacement (ILR) scheme as an distributed implementation of VBS. The path stretch problem is analyzed in order to explore the impact of VBS on the network structure. We show, through simulations, that VBS significantly prolongs the network lifetime under extensive conditions. Yaxiong Zhao, Jie Wu 0001, Feng Li 0001, Sanglu Lu |
INFOCOM | 3 |
| 2010 | Fuzzy Closeness-Based Delegation Forwarding in Delay Tolerant NetworksabstractDelay tolerant networks (DTNs) are envisioned to provide promising applications and services. One critical issue in DTNs is efficiently forwarding the messages within the delay requirements while avoiding the cost associated with blind flooding. To guide the forwarding process, nodes can evaluate their relationships with each other, in terms of ``closeness'', which summarizes both temporal and spacial information, based on contact history. However, due to the uncertainty in nodal mobility, the contact history usually contains fuzziness and incomplete information. In this paper, we first define and utilize a fuzzy trust evaluation system for nodes to summarize their relationships to other nodes, in terms of closeness. We then propose the fuzzy clustering to organize nodes into overlapped fuzzy communities based on nodes' evaluations of closeness. On top of the fuzzy communities, a novel fuzzy-weight-based delegation forwarding scheme is proposed to propagate the messages into all communities while avoiding repeated forwarding in the same community. Extensive simulation results based on real traces are presented to support the effectiveness of our scheme. Feng Li 0001, Yinying Yang, Jie Wu 0001, Xukai Zou |
NAS | 1 |
| 2010 | Uncertainty Modeling and Reduction in MANETsabstractEvaluating and quantifying trust stimulates collaboration in mobile ad hoc networks (MANETs). Many existing reputation systems sharply divide the trust value into right or wrong, thus ignoring another core dimension of trust: uncertainty. As uncertainty deeply impacts a node's anticipation of others' behavior and decisions during interaction, we include uncertainty in the reputation system. Specifically, we define a new uncertainty model to directly reflect a node's confidence in the sufficiency of its past experience, and study how the collection of trust information affects uncertainty in nodes' opinions. After defining a way to reveal and compute the uncertainty in trust opinions, we exploit mobility, one of the important characteristics of MANETs, to efficiently reduce uncertainty and to speed up trust convergence. Two different categories of mobility-assisted uncertainty reduction schemes are provided: the proactive schemes exploit mobile nodes to collect and broadcast trust information to achieve trust convergence; the reactive schemes provide the mobile nodes methods to get authenticated and bring their reputation in the original region to the destination region. Both of the schemes offer a controllable trade-off between delay, cost, and uncertainty. Extensive analytical and simulation results are presented to support our uncertainty model and mobility-assisted reduction schemes. Feng Li 0001, Jie Wu 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2010 | Attack and Flee: Game-Theory-Based Analysis on Interactions Among Nodes in MANETsabstractIn mobile ad hoc networks, nodes have the inherent ability to move. Aside from conducting attacks to maximize their utility and cooperating with regular nodes to deceive them, malicious nodes get better payoffs with the ability to move. In this paper, we propose a game theoretic framework to analyze the strategy profiles for regular and malicious nodes. We model the situation as a dynamic Bayesian signaling game and analyze and present the underlining connection between nodes' best combination of actions and the cost and gain of the individual strategy. Regular nodes consistently update their beliefs based on the opponents' behavior, while malicious nodes evaluate their risk of being caught to decide when to flee. Some possible countermeasures for regular nodes that can impact malicious nodes' decisions are presented as well. An extensive analysis and simulation study shows that the proposed equilibrium strategy profile outperforms other pure or mixed strategies and proves the importance of restricting malicious nodes' advantages brought by the flee option. Feng Li 0001, Yinying Yang, Jie Wu 0001 |
IEEE Trans. Syst. Man Cybern. Part B | 1 |
| 2009 | FRAME: An Innovative Incentive Scheme in Vehicular NetworksabstractVehicular ad hoc networks (VANETs) are envisioned to provide promising applications and services. One critical deployment issue in VANETs is to motivate vehicles and their drivers to cooperate and contribute to packet forwarding in vehicle-to-vehicle or vehicle-to-roadside communication. In this paper, we examine this problem, analyze the drawbacks of two straightforward schemes, and present a secure incentive scheme to stimulate cooperation in VANETs. We define the measurement of contribution according to the unique characteristics of VANET communication. Our scheme uses the weighted rewarding component to ensure fairness. Extensive simulation results are presented to support the effectiveness of our scheme. Feng Li 0001, Jie Wu 0001 |
ICC | 1 |
| 2009 | MOPS: Providing Content-Based Service in Disruption-Tolerant NetworksabstractContent-based service, which dynamically routes and delivers events from sources to interested users, is extremely important to network services. However, existing content-based protocols for static networks will incur unaffordable maintenance costs if they are applied directly to the highly mobile environment that is featured in disruption-tolerant networks (DTNs). In this paper, we propose a unique publish/subscribe scheme that utilizes the long-term social network properties, which are observed in many DTNs, to facilitate content-based services in DTNs. We distributively construct communities based on the neighboring relationships from nodes' encounter histories. Brokers are deployed to bridge the communities, and they adopt a locally prioritized pub/sub scheme which combines the structural importance with subscription interests, to decide what events they should collect, store, and propagate. Different trade-offs for content-based service can be achieved by tuning the closeness threshold in community formation or by adjusting the broker-to-broker communication scheme. Extensive real-trace and synthetic-trace driven simulation results are presented to support the effectiveness of our scheme. Feng Li 0001, Jie Wu 0001 |
ICDCS | 1 |
| 2009 | Thwarting Blackhole Attacks in Disruption-Tolerant Networks using Encounter TicketsabstractNodes in disruption-tolerant networks (DTNs) usually exhibit repetitive motions. Several recently proposed DTN routing algorithms have utilized the DTNs' cyclic properties for predicting future forwarding. The prediction is based on metrics abstracted from nodes' contact history. However, the robustness of the encounter prediction becomes vital for DTN routing since malicious nodes can provide forged metrics or follow sophisticated mobility patterns to attract packets and gain a significant advantage in encounter prediction. In this paper, we examine the impact of the blackhole attack and its variations in DTN routing. We introduce the concept of encounter tickets to secure the evidence of each contact. In our scheme, nodes adopt a unique way of interpreting the contact history by making observations based on the collected encounter tickets. Then, following the Dempster-Shafer theory, nodes form trust and confidence opinions towards the competency of each encountered forwarding node. Extensive real-trace-driven simulation results are presented to support the effectiveness of our system. Feng Li 0001, Jie Wu 0001, Anand Srinivasan |
INFOCOM | 1 |
| 2009 | LocalCom: A Community-based Epidemic Forwarding Scheme in Disruption-tolerant NetworksabstractIn disruption-tolerant networks (DTNs), network topology constantly changes and end-to-end paths can hardly be sustained. However, social network properties are observed in many DTNs and tend to be stable over time. To utilize the social network properties to facilitate packet forwarding, we present LocalCom, a community-based epidemic forwarding scheme that efficiently detects the community structure using limited local information and improves the forwarding efficiency based on the community structure. We define similarity metrics according to nodes' encounter history to depict the neighboring relationship between each pair of nodes. A distributed algorithm, which only utilizes local information, is then applied to detect communities and the formed communities have strong intra-community connections. We also present two schemes to first select and then prune gateways that connect communities to control redundancy and facilitate efficient inter-community packet forwarding. Extensive real-trace-driven simulation results are presented to support the effectiveness of our scheme. Feng Li 0001, Jie Wu 0001 |
SECON | 1 |
| 2009 | Efficient Opportunistic Routing in Utility-Based Ad Hoc NetworksabstractDue to resource scarcity, a paramount concern in ad hoc networks is utilizing limited resources efficiently. The self-organized nature of ad hoc networks makes the network utility-based approach an efficient way to allocate limited resources. However, the effect of link instability has not yet been adequately addressed in literature. To efficiently address the routing problem in ad hoc networks, we integrate the cost and stability into a network utility metric, and adopt the metric to evaluate the routing optimality in a unified, opportunistic routing model. Based on this model, an efficient algorithm is designed, both centralized and distributed implementations are presented, and extensive simulations on NS-2 are conducted to verify our results. Mingming Lu, Feng Li 0001, Jie Wu 0001 |
IEEE Trans. Reliab. | 2 |
| 2008 | Utility-Based Opportunistic Routing in Multi-Hop Wireless NetworksabstractRecently, opportunistic routing (OR) has been widely used to compensate for the low packet delivery ratio of multi-hop wireless networks. Previous works either provide heuristic solutions without optimality analysis, or assume that unlimited retransmission is available for delivering a data packet. In this paper, we apply OR to a utility-based routing where the successful delivery of a data packet generates benefit. The objective is to maximize utility, defined as a function of benefit and cost of transmission. As the link reliability of each relay determines eventual packet delivery and hence utility, OR offers the ability to increase reliability through opportunistic relays. We explore the optimality of utility-based routing through OR without allowing retransmission, and observe that the optimal scheme requires exhaustive searching of all paths from source to destination. We then propose a heuristic solution to select relays and determine priorities among them. Finally, we provide distributed implementations for both schemes. Simulations on NS-2 and our customized simulator are conducted to verify the effectiveness of the heuristic compared with the optimal. Jie Wu 0001, Mingming Lu, Feng Li 0001 |
ICDCS | 3 |
| 2008 | Hit and Run: A Bayesian Game Between Malicious and Regular Nodes in MANETsabstractIn mobile ad hoc networks (MANETs), nodes can move freely. Besides conducting attacks to maximize their utility and cooperating with regular nodes to deceive them, malicious nodes get better payoffs with the ability to move. In this paper, we propose a game theoretic framework to analyze the strategy profiles for regular and malicious nodes. We model the situation as a dynamic Bayesian signaling game, and analyze and present the underlining connection between nodes' best combination of actions and the cost and gain of the individual strategy. Regular nodes consistently update their beliefs based on the opponents' behavior, while malicious nodes evaluate their risk of being caught to decide when to flee. Some possible countermeasures for regular nodes that can impact malicious nodes' decisions are presented as well. An extensive analysis and simulation study shows that the proposed equilibrium strategy profile outperforms other pure or mixed strategies, and proves the importance of restricting malicious node's advantages brought by the flee option. Feng Li 0001, Jie Wu 0001 |
SECON | 1 |
| 2007 | Uncertainty Mitigation for Utility-Oriented Routing in Wireless Ad Hoc NetworksabstractLink and node reliability are important metrics in wireless ad hoc networks. Therefore, evaluating and quantifying reliability has become the cornerstone of research in this field. Many existing wireless ad hoc network routing algorithms assume the availability of precise reliability information. This, however, is an unrealistic assumption given the dynamics of wireless ad hoc networks. Also, due to frequent changes in topology, reliability information is hard to collect, and oftentimes, inaccuracies can creep in. Therefore, a realistic method is needed to evaluate reliability by mitigating uncertainty in the estimation process. In this paper, we propose a novel reliability estimation model, account for uncertainty in the estimation, and design an uncertainty mitigation scheme. We then illustrate the effectiveness of our scheme in estimating reliability under various levels of uncertainty using a utility-oriented routing algorithm as a sample application. An extensive simulation study shows that the mitigation scheme significantly increases path stability and the long-term total benefit of the system. Feng Li 0001, Avinash Srinivasan, Mingming Lu, Jie Wu 0001 |
GLOBECOM | 1 |
| 2007 | Mobility Reduces Uncertainty in MANETsabstractEvaluating and quantifying trust stimulates collaboration in mobile ad hoc networks (MANETs). Many existing reputation systems sharply divide the trust value into right or wrong, thus ignoring another core dimension of trust: uncertainty. As uncertainty deeply impacts a node's anticipation of others' behavior and decisions during interaction, we include uncertainty in the reputation system. Specifically, we use an uncertainty metric to directly reflect a node's confidence in the sufficiency of its past experience, and study how the collection of trust information may affect uncertainty in nodes' opinions. Higher uncertainty leads to higher transaction cost and reduced acceptance of communication and cooperation. After defining a way to reveal and compute the uncertainty in trust opinions, we exploit mobility, one of the important characteristics of MANETs, to efficiently reduce uncertainty and to speed up trust convergence. A two-level mobility assisted uncertainty reduction scheme (MAURS) that offers controllable trade-off between time and cost to achieve a convergence objective of trust is also provided. Extensive analytical and simulation results are presented to support our proposal. Feng Li 0001, Jie Wu 0001 |
INFOCOM | 1 |
| 2006 | A probabilistic voting-based filtering scheme in wireless sensor networksabstractIn this paper, we study the fabricated report with false votes attack and the false votes on real reports attack in wireless sensor networks. Since most of the existing works addresses the first attack while leaving an easy way for the attackers to launch the second attack, we propose a probabilistic voting-based filtering scheme (PVFS) to deal with both of them simultaneously. On the basis of the en-route filtering scheme, PVFS combines cluster-based organization, probabilistic key assignment, and voting methods. Through both analysis and simulation, we demonstrate that PVFS could achieve strong protection against both attacks while maintaining a sufficiently high filtering power. Feng Li 0001, Jie Wu 0001 |
IWCMC | 1 |