Xiaohui Liang 0002

dblp:92/3528-2 · DBLP profile ↗
← Back
90ranked-venue papers
16as first author
17since 2021 · last 2025
0000-0003-4064-2393ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 49 · 8 first-author · 6 since 2021Security and privacy · 16 · 4 first-author · 1 since 2021Systems, architecture and hardware · 6 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 6 · 6 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Databases, data management, data science and information retrieval · 4
YearPublicationVenuePosition
2025 Unveil Multi-Picture Descriptions for Multilingual Mild Cognitive Impairment Detection via Contrastive Learning
abstract
Detecting Mild Cognitive Impairment from picture descriptions is critical yet challenging, especially in multilingual and multiple picture settings. Prior work has primarily focused on English speakers describing a single picture (e.g., the 'Cookie Theft'). The TAUKDIAL-2024 challenge expands this scope by introducing multilingual speakers and multiple pictures, which presents new challenges in analyzing picture-dependent content. To address these challenges, we propose a framework with three components: (1) enhancing discriminative representation learning via supervised contrastive learning, (2) involving image modality rather than relying solely on speech and text modalities, and (3) applying a Product of Experts (PoE) strategy to mitigate spurious correlations and overfitting. Our framework improves MCI detection performance, achieving a +7.1% increase in Unweighted Average Recall (UAR) (from 68.1% to 75.2%) and a +2.9% increase in F1 score (from 80.6% to 83.5%) compared to the text unimodal baseline. Notably, the contrastive learning component yields greater gains for the text modality compared to speech. These results highlight our framework's effectiveness in multilingual and multi-picture MCI detection.
Kristin Qi, Jiali Cheng, Youxiang Zhu, Hadi Amiri, Xiaohui Liang 0002
GLOBECOM5
2025 Cog-TiPRO: Iterative Prompt Refinement with LLMs to Detect Cognitive Decline via Longitudinal Voice Assistant Commands
abstract
Early detection of cognitive decline is crucial for enabling interventions that can slow neurodegenerative disease progression. Traditional diagnostic approaches rely on labor-intensive clinical assessments, which are impractical for frequent monitoring. Our pilot study investigates voice assistant systems (VAS) as non-invasive tools for detecting cognitive decline through longitudinal analysis of speech patterns in short and unstructured voice commands. Over an 18-month period, we collected voice commands from 35 older adults, with 15 participants providing daily at-home VAS interactions. To address the challenges of analyzing these short, unstructured and noisy commands, we propose Cog-TiPRO, a framework that combines (1) LLM-driven iterative prompt refinement for linguistic feature extraction, (2) HuBERT-based acoustic feature extraction, and (3) transformer-based temporal modeling. Using iTransformer, our approach achieves 73.80% accuracy and 72.67% F1-score in detecting MCI, outperforming its baseline by 27.13%. Through our LLM approach, we identify linguistic features that uniquely characterize everyday command usage patterns in individuals experiencing cognitive decline.
Kristin Qi, Youxiang Zhu, Caroline Summerour, John A. Batsis, Xiaohui Liang 0002
GLOBECOM5
2024 Adversarial Text Generation using Large Language Models for Dementia Detection
abstract
Although large language models (LLMs) excel in various text classification tasks, regular prompting strategies (e.g., few-shot prompting) do not work well with dementia detection via picture description.The challenge lies in the language marks for dementia are unclear, and LLM may struggle with relating its internal knowledge to dementia detection.In this paper, we present an accurate and interpretable classification approach by Adversarial Text Generation (ATG), a novel decoding strategy that could relate dementia detection with other tasks.We further develop a comprehensive set of instructions corresponding to various tasks and use them to guide ATG, achieving the best accuracy of 85%, >10% improvement compared to the regular prompting strategies.In addition, we introduce feature context, a humanunderstandable text that reveals the underlying features of LLM used for classifying dementia.From feature contexts, we found that dementia detection can be related to tasks such as assessing attention to detail, language, and clarity with specific features of the environment, character, and other picture content or languagerelated features.Future work includes incorporating multi-modal LLMs to interpret speech and picture information.* The stool is falling over, which suggests that it's either old, unstable, or has been poorly maintained.This adds to the sense of chaos in the kitchen.* The cookies being taken out of the cookie jar by the boy and being asked by the little girl to be handed to her quietly implies that snacking is a common activity in this household.* The fact that the stool is falling while the cookies are being handled increases the risk of mess and potential accidents.**Sink Overflowing** * The sink is overflowing, which means the mother is either taking a long time to wash dishes or isn't paying attention to the water level.This could be a source of stress or annoyance for her, but for now, she's choosing to dry dishes (on the assumption that it's less pressing).* This detail also creates a sense of water-themed tension, with water running "into" and possibly outside, but no indication of what happens to it.**Wind Outside** * The curtains are drawn back to allow a gentle breeze into the house, and the scene appears to be on a relatively mild day, as you mentioned.The fact that you explicitly state there's nothing to note about the outside action (beyond the path, window, and building envelope) suggests that the wind is likely a gentle, harmless blow.**Kids' Actions** * The girl's finger to the mouth could be seen as a clever play on innocence, hiding mischief behind a cookie-stealing facade.Her reach for a cookie and the brother's slippage from the stool create a sense of partnership in their naughtiness.* Both kids seem comfortable snacking in the kitchen, almost like it's a normalized behavior.**Mother's Neglect (Daycare... er, laundry of attention?)*** You cleverly contrast the overflowing sink with the mother's drying of dishes, implying a degree of obliviousness or prioritization on her part.Her feet getting soaked or compromised hygiene aren't necessarily consequences of her actions, but it does add to the impression of a household where multiple tasks are happening simultaneously.**Summer Puddled Insight** * Your aside about not knowing whether you meant for it to be action-worthy mentions several extraneous details, but effectively highlights the fact that the outside scene doesn't quite gel with the chaotic interior.You raise an interesting question about the importance of showing consequences or actions related to the stool tipping, overflowing water, or blowing curtains.* The comment about shortsightedly standing in the mother's attention ("um the mother or don't see much.um mother wiping dishes ") serves as a wry commentary on the scene's pandemonium.Overall, this vivid scene showcases a busy, potentially messy household where multiple dynamics are at play.The juxtaposition of controlled chaos (curtains flowing, kids snacking) with underlying mayhem (stool tipping, overflowing sink) creates a engaging contrast.The outside weather serves as a brief interlude, acknowledging that not everything has to be resolved or escalating inside
Youxiang Zhu, Nana Lin, Kiran Balivada, Daniel Haehn, Xiaohui Liang 0002
EMNLP5
2024 Exploiting Privacy Preserving Prompt Techniques for Online Large Language Model Usage
abstract
Online Large Language Models (LLMs) are widely employed across various tasks, including privacy-sensitive ones like financial advice or paragraph rewriting. Presently, users directly submit prompts to online LLM servers, inadvertently revealing sensitive keywords and facilitating server tracking to build user profiles. In this paper, we propose a local privacy-preserving prompt assistant (LPPA) that provides users with a usable method to balance privacy in the prompts and the utility of the LLM output. The LPPA will analyze the users' prompts, suggest modifying the prompts to protect the sensitive keywords, and provide an inference of the potential utility impact of the online LLM output. Specifically, we first propose a privacy module to identify the sensitive keywords in the prompt and adopt four privacy techniques, including remove, mask, replace, and rewrite to hide the keywords. While these techniques affect the utility of online LLM output, we measure such impact using the LLM output of the original prompt and modified prompts and discuss the cases with high, median, and low impact. In addition, we propose a utility inference model to infer the utility impact locally without disclosing the prompts to the online LLM. We evaluated LPPA on the real-world users' prompts and showed that the remove technique achieves the best performance, and it empowers users with meaningful ways to adjust their prompts to safeguard their privacy while still maintaining a satisfactory level of utility in online LLM usage.
Youxiang Zhu, Xiaohui Liang 0002, Honggang Zhang 0003
GLOBECOM3
2024 Exploiting Longitudinal Speech Sessions via Voice Assistant Systems for Early Detection of Cognitive Decline
abstract
Mild Cognitive Impairment (MCI) is an early stage of Alzheimer's disease (AD), a form of neurodegenerative disorder. Early identification of MCI is crucial for delaying its progression through timely interventions. Existing research has demonstrated the feasibility of detecting MCI using speech collected from clinical interviews or digital devices. However, these approaches typically analyze data collected at limited time points, limiting their ability to identify cognitive changes over time. This paper presents a longitudinal study using voice assistant systems (VAS) to remotely collect seven-session speech data at three-month intervals across 18 months. We propose two methods to improve MCI detection and the prediction of cognitive changes. The first method incorporates historical data, while the second predicts cognitive changes at two time points. Our results indicate improvements when incorporating historical data: the average F1-score for MCI detection improves from 58.6% to 71.2% (by 12.6%) in the case of acoustic features and from 62.1% to 75.1% (by 13.0%) in the case of linguistic features. Additionally, the prediction of cognitive changes achieves an F1-score of 73.7% in the case of acoustic features. These results confirm the potential of VAS-based speech sessions for early detection of cognitive decline.
Kristin Qi, Jiatong Shi, Caroline Summerour, John A. Batsis, Xiaohui Liang 0002
HealthCom5
2024 Clinical Geriatric Functional Assessment Using Wearable Sensing and Machine Learning
abstract
Physical function is critically important for older adults as it directly impacts their independence, quality of life, and overall health. To assess the physical functions of older adults, primary health provider are optimally placed, but they do not complete the assessments due to time and space constraints. In this paper, we introduce a geriatric functional assessment (GFA) system using a wearable device and machine learning methods to assess older adults' physical function during their clinical visits and enable clinicians to monitor physical function results. Specifically, the GFA system includes a badge-sized wearable prototype with motion and visual sensors that continuously collect sensor data during ~15-minute clinical visits. Then, the GFA system integrates three different physical function inference methods using a support vector classifier, random forest, and deep neural network to infer actionable clinician-familiar measures, including gait speed, sit-to-stand, and balance metrics. We tested the GFA among 21 older adults who visited the same clinic. The evaluation of the inference methods shows that the random forest classifier performs better than the Support vector classifier and Dense neural network; the accuracy score is increased from 68.80 to 74.10 for gait speed, from 60.70 to 66.90 for sit-to-stand and from 69.80 to 76.2 for balance. Moreover, we showed that the GFA's usability score is promising, 79 out of 100, and we identified critical design issues that should be addressed in future designs.
Rishank Singh, Sankalp Vaish, Xiaohui Liang 0002, Jennifer G. Poole, John A. Batsis, Danae C. Gross
HealthCom3
2024 Analyzing Multimodal Features of Spontaneous Voice Assistant Commands for Mild Cognitive Impairment Detection
abstract
Mild cognitive impairment (MCI) is a major public health concern due to its high risk of progressing to dementia. This study investigates the potential of detecting MCI with spontaneous voice assistant (VA) commands from 35 older adults in a controlled setting. Specifically, a command-generation task is designed with pre-defined intents for participants to freely generate commands that are more associated with cognitive ability than read commands. We develop MCI classification and regression models with audio, textual, intent, and multimodal fusion features. We find the command-generation task outperforms the command-reading task with an average classification accuracy of 82%, achieved by leveraging multimodal fusion features. In addition, generated commands correlate more strongly with memory and attention subdomains than read commands. Our results confirm the effectiveness of the command-generation task and imply the promise of using longitudinal in-home commands for MCI detection.
Nana Lin, Youxiang Zhu, Xiaohui Liang 0002, John A. Batsis, Caroline Summerour
INTERSPEECH3
2023 Early Detection of Cognitive Decline Using Voice Assistant Commands
abstract
Early detection of Alzheimer's Disease and Related Dementias (ADRD) is critical in treating the progression of the disease. Previous studies have shown that ADRD can be detected and classified using machine learning models trained on samples of spontaneous speech. We propose using Voice-Assistant Systems (VAS), e.g., Amazon Alexa, to monitor and collect data from at-risk adults, and we show that this data can be used to achieve functional accuracy in classifying their cognitive status. In this paper, we develop multiple unique feature sets from VAS data that can be used in the training of machine learning models. We then perform multi-class classification, binary classification, and regression using these features on our dataset of older adults with three varying stages of cognitive decline interacting with VAS. Our results show that the VAS data can be used to classify Dementia (DM), Mild Cognitive Impairment (MCI), and Healthy Control (HC) participants with an accuracy up to 74.7%, and classify between HC and MCI with accuracy up to 62.8%.
Eli Kurtz, Youxiang Zhu, Tiffany M. Driesse, Bang Tran, John A. Batsis, Robert M. Roth, Xiaohui Liang 0002
ICASSP7
2023 Exploiting Relevance of Speech to Sleepiness Detection via Attention Mechanism
abstract
Excessive sleepiness in critical tasks and jobs can lead to adverse outcomes, such as work accidents and car crashes. Detecting and monitoring sleepiness levels can prevent these adverse events from happening. In this paper, we propose an attention-based sleepiness detection method using HuBERT embeddings and eGeMAPS features of human speech. Specifically, we propose an attention-based convolutional neural network (CNN) model that achieves accurate 82.57 % sleepiness detection using HuBERT embeddings plus age and gender as inputs. We also show that the embedded attention layers significantly improve the detection accuracy in different cases of inputs. We then explore the attention weights from the attention layers and observe that the long and semantically-different responses from “Picture description”, “Microphone test”, and “Free speech” tasks are more relevant to sleepiness detection when the model is trained with HuBERT only; the short and semantically-similar responses from “Sustained phonation” and “Diadochokinetic” tasks are more relevant when trained with HuBERT plus age and gender. The attention mechanism enables our model to take all responses as one input, simplifying the data pre-processing and identifying the relevant speech responses to sleepiness detection.
Bang Tran, Youxiang Zhu, James W. Schwoebel, Xiaohui Liang 0002
ICC4
2023 VPASS: Voice Privacy Assistant System for Monitoring In-home Voice Commands
abstract
Voice assistant systems (VAS), such as Google Assistant or Amazon Alexa, provide convenient means for users to interact verbally with online services. VAS is particularly important for users with severe health conditions or motor skills impairment. At the same time, voice commands may contain highly-sensitive information about individuals. Therefore, sharing such data with service providers must be done in a carefully controlled and transparent manner in order to prevent privacy breaches. One important challenge is identifying which voice commands contain sensitive information. Different individuals are likely to have distinct interpretations of what is sensitive and what must be kept private, depending on gender, age, cultural background, etc. Furthermore, even for the same individual, the context in which a command is issued can result in significantly different sensitivity perceptions. We introduce a framework named VPASS that supports the management of personalized privacy requirements for VAS systems. Specifically, we propose mechanisms to quantify two key aspects: the amount of information disclosure and the level of privacy sensitivity that each voice command has. Our mechanisms employ deep transfer learning techniques for processing voice commands and can accurately detect privacy-sensitive commands based on an individual’s prior history of VAS interaction. Finally, VPASS generates monthly reports or immediate privacy alerts based on the privacy policies pre-defined by users.
Bang Tran, Sai Harshavardhan Reddy Kona, Xiaohui Liang 0002, Gabriel Ghinita, Caroline Summerour, John A. Batsis
PST3
2022 Speech Tasks Relevant to Sleepiness Determined With Deep Transfer Learning
abstract
Excessive sleepiness in attention-critical contexts can lead to adverse events, such as car crashes. Detecting and monitoring sleepiness can help prevent these adverse events from happening. In this paper, we use the Voiceome dataset to extract speech from 1,828 participants to develop a deep transfer learning model using Hidden-Unit BERT (HuBERT) speech representations to detect sleepiness from individuals. Speech is an under-utilized source of data in sleep detection, but as speech collection is easy, cost-effective, and non-invasive, it provides a promising resource for sleepiness detection. Two complementary techniques were conducted in order to seek converging evidence regarding the importance of individual speech tasks. Our first technique, masking, evaluated task importance by combining all speech tasks, masking selected responses in the speech, and observing systematic changes in model accuracy. Our second technique, separate training, compared the accuracy of multiple models, each of which used the same architecture, but was trained on a different subset of speech tasks. Our evaluation shows that the best-performing model utilizes the memory recall task and categorical naming task from the Boston Naming Test, which achieved an accuracy of 80.07% (F1-score of 0.85) and 81.13% (F1-score of 0.89), respectively.
Bang Tran, Youxiang Zhu, Xiaohui Liang 0002, James W. Schwoebel, Lindsay A. Warrenburg
ICASSP3
2022 Towards Interpretability of Speech Pause in Dementia Detection Using Adversarial Learning
abstract
Speech pause is an effective biomarker in dementia detection. Recent deep learning models have exploited speech pauses to achieve highly accurate dementia detection, but have not exploited the interpretability of speech pauses, i.e., what and how positions and lengths of speech pauses affect the result of dementia detection. In this paper, we will study the positions and lengths of dementia-sensitive pauses using adversarial learning approaches. Specifically, we first utilize an adversarial attack approach by adding the perturbation to the speech pauses of the testing samples, aiming to reduce the confidence levels of the detection model. Then, we apply an adversarial training approach to evaluate the impact of the perturbation in training samples on the detection model. We examine the interpretability from the perspectives of model accuracy, pause context, and pause length. We found that some pauses are more sensitive to dementia than other pauses from the model's perspective, e.g., speech pauses near to the verb "is". Increasing lengths of sensitive pauses or adding sensitive pauses leads the model inference to Alzheimer's Disease (AD), while decreasing the lengths of sensitive pauses or deleting sensitive pauses leads to non-AD.
Youxiang Zhu, Bang Tran, Xiaohui Liang 0002, John A. Batsis, Robert M. Roth
ICASSP3
2022 Domain-aware Intermediate Pretraining for Dementia Detection with Limited Data
abstract
Detecting dementia using human speech is promising but faces a limited data challenge. While recent research has shown general pretrained models (e.g., BERT) can be applied to improve dementia detection, the pretrained model can hardly be fine-tuned with the available small dementia dataset as that would raise the overfitting problem. In this paper, we propose a domain-aware intermediate pretraining to enable a pretraining process using a domain-similar dataset that is selected by incorporating the knowledge from the dementia dataset. Specifically, we use pseudo-perplexity to find an effective pretraining dataset, and then propose dataset-level and sample-level domain-aware intermediate pretraining techniques. We further employ information units (IU) from previous dementia research and define an IU-pseudo-perplexity to reduce calculation complexity. We confirm the effectiveness of perplexity by showing a strong correlation between perplexity and accuracy using 9 datasets and models from the GLUE benchmark. We show that our domain-aware intermediate pretraining improves detection accuracy in almost all cases. Our results suggested that the difference in text-based perplexity values between patients with Alzheimer's Disease (AD) and Healthy Control (HC) is still small, and the perplexity incorporating acoustic features (e.g., pause) may make the pretraining more effective.
Youxiang Zhu, Xiaohui Liang 0002, John A. Batsis, Robert M. Roth
INTERSPEECH2
2022 Evaluating voice-assistant commands for dementia detection
Xiaohui Liang 0002, John A. Batsis, Youxiang Zhu, Tiffany M. Driesse, Robert M. Roth, David Kotz, Brian MacWhinney
Comput. Speech Lang.1
2021 Exploiting Physical Presence Sensing to Secure Voice Assistant Systems
abstract
Voice Assistant System (VAS) provides a convenient way for users to interact with smart-home devices via a voice interface. However, it raises unique security issues, including voice replay and injection attacks, where attackers remotely and maliciously control the smart-home devices via a voice interface. In this paper, we consider a typical smart-home scenario in which a VAS device and a compromised speaker device are placed in close physical proximity. The attacker can remotely play malicious voice commands through the speaker device to manipulate the VAS device for malicious purposes. We propose a defense system on the VAS device to secure the VAS device against both voice replay and injection attacks, without any additional devices and without any extra user effort. Specifically, our system aims to collect voice data and wireless data continuously from the VAS device and then extracts the Mel-Cepstral Frequency Coefficients (MFCC) features from voice and wireless data. We consider that both voice and wireless data are affected by the same present users' physical activities, and the correlation can be used to detect the attacks. Finally, our system applies a deep learning model that learns from previous time-series data and analyzes real-time data to infer whether the real-time voice command is generated from a user or the speaker device. We have tested our system in certain real-world smart-home scenarios. Our experiments showed that the proposed system has a probability between 76.4% to 89.1% to successfully detect the voice replay and injection attacks in the considered scenarios.
Bang Tran, Shenhui Pan, Xiaohui Liang 0002, Honggang Zhang 0003
ICC3
2021 WavBERT: Exploiting Semantic and Non-Semantic Speech Using Wav2vec and BERT for Dementia Detection
abstract
In this paper, we exploit semantic and non-semantic information from patient's speech data using Wav2vec and Bidirectional Encoder Representations from Transformers (BERT) for dementia detection. We first propose a basic WavBERT model by extracting semantic information from speech data using Wav2vec, and analyzing the semantic information using BERT for dementia detection. While the basic model discards the non-semantic information, we propose extended WavBERT models that convert the output of Wav2vec to the input to BERT for preserving the non-semantic information in dementia detection. Specifically, we determine the locations and lengths of inter-word pauses using the number of blank tokens from Wav2vec where the threshold for setting the pauses is automatically generated via BERT. We further design a pre-trained embedding conversion network that converts the output embedding of Wav2vec to the input embedding of BERT, enabling the fine-tuning of WavBERT with non-semantic information. Our evaluation results using the ADReSSo dataset showed that the WavBERT models achieved the highest accuracy of 83.1% in the classification task, the lowest Root-Mean-Square Error (RMSE) score of 4.44 in the regression task, and a mean F1 of 70.91% in the progression task. We confirmed the effectiveness of WavBERT models exploiting both semantic and non-semantic speech.
Youxiang Zhu, Abdelrahman Obyat, Xiaohui Liang 0002, John A. Batsis, Robert M. Roth
Interspeech3
2021 Exploiting peer-to-peer communications for query privacy preservation in voice assistant systems
Bang Tran, Xiaohui Liang 0002
Peer-to-Peer Netw. Appl.2
2020 Exploiting Privacy-preserving Voice Query in Healthcare-based Voice Assistant System
abstract
Voice Assistant Systems (VAS) such as Amazon Echo and Google Home are becoming a popular technology for medical health systems among patients and caregivers. The VAS devices allow patients and caregivers to interact with them via voice commands. In most cases, the users' private voice data is fully disclosed to the VAS server, which may raise severe privacy concerns, especially in case of medical information which are clearly sensitive. In this paper, we propose a privacy-preserving voice query scheme in the healthcare-based voice assistant system, which enables the users to use voice commands for uploading medical data and later retrieving them. The VAS server in this case has no access to the original voice command or the data stored but it can accurately respond to user's query. Our scheme consists of two voice matching techniques with weak and strong privacy levels, where the former discloses only the voice feature, and not the original voice to the server. The latter further uses an obfuscation function to hide the voice features, thus the data is fully protected. We evaluate the performance of our proposed scheme by conducting experiments on self-generated voice data set, from three different languages, English, Chinese, and Arabic. We prove that our proposed scheme can achieve the privacy preservation of the voice data, and up to 98% accuracy in responding to voice queries.
Thamer Altuwaiyan, Mohammad Hadian, Samuel Rubel, Xiaohui Liang 0002
ICC4
2020 LIDAUS: Localization of IoT Device via Anchor UAV SLAM
abstract
We introduce LIDAUS (Localization of IoT Device via Anchor UAV SLAM), an infrastructure-free, multi-stage SLAM system that utilizes an Unmanned Aerial Vehicle (UAV) to accurately localize IoT devices in a 3D indoor space where GPS signals are unavailable or weak, e.g., manufacturing factories, disaster sites, or smart buildings. The lack of GPS signals and infrastructure support makes most of the existing indoor localization systems not practical when localizing a large number of wireless IoT devices. In addition, safety concerns, access restriction, and simply the huge amount of IoT devices make it not practical for humans to manually localize and track IoT devices. To address these challenges, the UAV in our LIDAUS system conducts multi-stage 3D SLAM trips to localize devices based only on RSSIs, the most widely available measurement of the signals of almost all commodity IoT devices. The main novelties of the system include a weighted entropy-based clustering algorithm to select high quality RSSI observation locations, a 3D U-SLAM algorithm that is enhanced by deploying anchor beacons along the UAV's path, and the path planning based on Eulerian cycles on multi-layer grid graphs that model the space in exploring stage and Steiner tree paths in searching stages. Our simulations and experiments of Bluetooth IoT devices have demonstrated that the system can achieve high localization accuracy based only on RSSIs of commodity IoT devices.
Deqiang Xu, Zhuoming Huang, Honggang Zhang 0003, Xiaohui Liang 0002
IPCCC5
2020 Securely Connecting Wearables to Ambient Displays with User Intent
abstract
Wearables are often small and have limited user interfaces, hence they often wirelessly interface with a personal smartphone or a personal computer to relay information from the wearable for display. In this paper, we envision a new method LightTouch by which a wearable can establish a secure connection to an ambient display, such as a television or computer monitor, based on the user's intention to connect to the display. Such connections must be secure to prevent impersonation attacks, must work with unmodified display hardware, and must be easy to establish. LightTouch uses standard RF methods for communicating the data to display, securely bootstrapped with a key shared via a brightness channel between the low cost, low power, ambient light sensor of a wearable and the screen of the display. A screen touch gesture is adopted by users to ensure the modulation of screen brightness can be accurately and securely captured by the ambient light sensor. We further propose novel on-screen localization and correlation algorithms to improve security and reliability. Through experiments we demonstrate that LightTouch is compatible with current display and wearable designs, easy-to-use (5-6 seconds), reliable for connecting displays (98 percent success connection ratio), and secure against impersonation attacks.
Xiaohui Liang 0002, Ronald A. Peterson, David Kotz
IEEE Trans. Dependable Secur. Comput.1
2020 Revealing Your Mobile Password via WiFi Signals: Attacks and Countermeasures
abstract
In this study, we present WindTalker, a novel and practical keystroke inference framework that can be used to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from an observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). An attacker can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's password input. Compared with the previous keystroke inference approaches, WindTalker neither deploys external equipment physically close to the target device nor compromises the target device. Instead, it employs a more practical setting by deploying a free public WiFi hotspot and collects the CSI data from the target device as long as the device is connected to the hotspot. In addition, to improve inference accuracy and efficiency, it analyzes the WiFi traffic to selectively collect CSI only for the sensitive period where password entering occurs. WindTalker can be implemented without the requirement of visually seeing the target device, or installing any malware on the device. We tested Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. Furthermore, we proposed a novel CSI obfuscation countermeasure to thwart the inference attack. The evaluation results show that the performance of WindTalker can be dramatically reduced by adopting the proposed countermeasures.
Yan Meng 0001, Jinlei Li, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan
IEEE Trans. Mob. Comput.4
2019 Energy Theft Detection With Energy Privacy Preservation in the Smart Grid
abstract
As a prominent early instance of the Internet of Things in the smart grid, the advanced metering infrastructure (AMI) provides real-time information from smart meters to both grid operators and customers, exploiting the full potential of demand response. However, the newly collected information without security protection can be maliciously altered and result in huge loss. In this paper, we propose an energy theft detection scheme with energy privacy preservation in the smart grid. Especially, we use combined convolutional neural networks (CNNs) to detect abnormal behavior of the metering data from a long-period pattern observation. In addition, we employ Paillier algorithm to protect the energy privacy. In other words, the users' energy data are securely protected in the transmission and the data disclosure is minimized. Our security analysis demonstrates that in our scheme data privacy and authentication are both achieved. Experimental results illustrate that our modified CNN model can effectively detect abnormal behaviors at an accuracy up to 92.67%.
Donghuan Yao, Mi Wen, Xiaohui Liang 0002, Zipeng Fu, Kai Zhang 0016, Baojia Yang
IEEE Internet Things J.3
2018 WiLock: Exploiting Wireless Signals for Device-Free Continuous Authentication
abstract
Mobile devices use time-based de-authentication to secure themselves against un-authorized users, and usually lock themselves after a pre- defined time of inactivity, known as "lock-out time". The technique is effective, however lack of an adaptive de-authentication mechanism may limit the usability and security: if the lock-out time is too short, the usability suffers from requirement of frequent and possibly unnecessary user authentications, and if too long, the security suffers from an increased window of opportunity for lunch-time attacks. In this paper, we propose WiLock; a WiFi-assisted proximity-based device locking technique, to complement the traditional authentication and de-authentication mechanism on the mobile devices in simplistic but highly common scenarios, to avoid unnecessary de- authentication of the user and to secure devices against lunch-time attacks. We introduce the concept of "Personal Space" (PS) as a safe zone around the device in which the solo presence of the user is considered safe. This approach adopts analyzing wireless signals received at the device to sense human presence in device proximity and make security- aware decisions on locking the device. Physical proximity of the device, along with the presence and relative locations of human objects in it as an authentication factor has been studied and is shown to be effective for enhancing security and usability of mobile devices. After benchmarking different classifiers, we adopt a k-NN based learning method to classify collected information into lock and unlock classes. Our evaluation through extensive experiments on real collected data using off-the-shelf WiFi equipments confirms our scheme's performance and shows an average detection accuracy of 92.62% and 78.73% for stationary and moving objects respectively in the experiment's environment and setting.
Mohammad Hadian, Thamer Altuwaiyan, Xiaohui Liang 0002
GLOBECOM4
2018 Efficient and Privacy-Preserving Roadmap Data Update for Autonomous Vehicles
abstract
Autonomous vehicles (AV) need an access to a big amount of data from online roadmap servers and local sensors to make real-time control decision for safety. Considering the roadmap data may change in cases of road maintenance, new/broken road signs, accidents, traffic jams, AV should keep its local roadmap data updated with the online roadmap servers. In this paper, we propose an efficient and privacy-preserving roadmap data update scheme for AV, which achieves the privacy preservation of route information while minimizing the update overhead. We define a new type of privacy sensitivity of a road segment based on its three properties, hotspot sensitivity, proximity sensitivity, and route sensitivity. We then define a new type of k-anonymity protection on road segment, i.e., to protect a target segment with sensitivity l, the anonymity segment set must include at least k-1 segments with sensitivity ≥ l. In addition, we consider for a more sensitive segment, k needs to be larger to protect the segment. Finally, this scheme, by considering different privacy features, achieves the required privacy preservation at a lower bandwidth cost compared to the traditional k-anonymity mechanism due to prioritizing the selection of the most sensitive anonymity segments. Based on the roadmap data from Google Map, we evaluated our scheme for roadmap data update and route conditions and showed a trade-off between the route privacy preservation and the communication overheads.
Mohammad Hadian, Xiaohui Liang 0002
GLOBECOM3
2018 EPIC: Efficient Privacy-Preserving Contact Tracing for Infection Detection
abstract
The world has experienced many epidemic diseases in the past, SARS, H1N1, and Ebola are some examples of these diseases. When those diseases outbreak, they spread very quickly among people and it becomes a challenge to trace the source in order to control the disease. In this paper, we propose an efficient privacy-preserving contact tracing for infection detection (EPIC) which enables users to securely upload their data to the server and later in case of one user got infected other users can check if they have ever got in contact with the infected user in the past. The process is done privately and without disclosing any unnecessary information to the server. Our scheme uses a matching score to represent the result of the contact tracing, and uses a weight-based matching method to increase the accuracy of the score. In addition, we have developed an adaptive scanning method to optimize the power consumption of the wireless scanning process. Further, we evaluate our scheme in real experiment and show that the user's privacy is preserved, and the accuracy achieves 93% in detecting the contact tracing based on the matching score in an energy efficient way.
Thamer Altuwaiyan, Mohammad Hadian, Xiaohui Liang 0002
ICC3
2018 WiVo: Enhancing the Security of Voice Control System via Wireless Signal in IoT Environment
abstract
With the prevalent of smart devices and home automations, voice command has become a popular User Interface (UI) channel in the IoT environment. Although Voice Control System (VCS) has the advantages of great convenience, it is extremely vulnerable to the spoofing attack (e.g., replay attack, hidden/inaudible command attack) due to its broadcast nature. In this study, we present WiVo, a device-free voice liveness detection system based on the prevalent wireless signals generated by IoT devices without any additional devices or sensors carried by the users. The basic motivation of WiVo is to distinguish the authentic voice command from a spoofed one via its corresponding mouth motions, which can be captured and recognized by wireless signals. To achieve this goal, WiVo builds a theoretical model to characterize the correlation between wireless signal dynamics and the user's voice syllables. WiVo extracts the unique features from both voice and wireless signals, and then calculates the consistency between these different types of signals in order to determine whether the voice command is generated by the authentic user of VCS or an adversary. To evaluate the effectiveness of WiVo, we build a testbed based on Samsung SmartThings framework and include WiVo as a new application, which is expected to significantly enhance the security of the existing VCS. We have evaluated WiVo with 6 participants and different voice commands. Experimental evaluation results demonstrate that WiVo achieves the overall 99% detection rate with 1% false accept rate and has a low latency.
Yan Meng 0001, Zichang Wang, Wei Zhang 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007
MobiHoc6
2018 Smoke Screener or Straight Shooter: Detecting Elite Sybil Attacks in User-Review Social Networks
Haizhong Zheng, Minhui Xue 0001, Shuang Hao 0001, Haojin Zhu, Xiaohui Liang 0002, Keith W. Ross
NDSS6
2018 Privacy Leakage of Location Sharing in Mobile Social Networks: Attacks and Defense
abstract
Along with the popularity of mobile social networks (MSNs) is the increasing danger of privacy breaches due to user location exposures. In this work, we take an initial step towards quantifying location privacy leakage from MSNs by matching the users’ shared locations with their real mobility traces. We conduct a three-week real-world experiment with 30 participants and discover that both direct location sharing (e.g., Weibo or Renren) and indirect location sharing (e.g., Wechat or Skout) can reveal a small percentage of users’ real points of interests (POIs). We further propose a novel attack to allow an external adversary to infer the demographics (e.g., age, gender, education) after observing users’ exposed location profiles. We implement such an attack in a large real-world dataset involving 22,843 mobile users. The experimental results show that the attacker can effectively predict demographic attributes about users with some shared locations. To resist such attacks, we propose SmartMask, a context-based system-level privacy protection solution, designed to automatically learn users’ privacy preferences under different contexts and provide a transparent privacy control for MSN users. The effectiveness and efficiency of SmartMask have been well validated by extensive experiments.
Huaxin Li, Haojin Zhu, Suguo Du, Xiaohui Liang 0002, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.4
2018 Exploiting Social Network to Enhance Human-to-Human Infection Analysis without Privacy Leakage
abstract
Human-to-human infection, as a type of fatal public health threats, can rapidly spread, resulting in a large amount of labor and health cost for treatment, control and prevention. To slow down the spread of infection, social network is envisioned to provide detailed contact statistics to isolate susceptive people who has frequent contacts with infected patients. In this paper, we propose a novel human-to-human infection analysis approach by exploiting social network data and health data that are collected by social network and e-healthcare technologies. We enable the social cloud server and health cloud server to exchange social contact information of infected patients and user's health condition in a privacy-preserving way. Specifically, we propose a privacy-preserving data query method based on conditional oblivious transfer to guarantee that only the authorized entities can query users’ social data and the social cloud server cannot infer anything during the query. In addition, we propose a privacy-preserving classification-based infection analysis method that can be performed by untrusted cloud servers without accessing the users’ health data. The performance evaluation shows that the proposed approach achieves higher infection analysis accuracy with the acceptable computational overhead.
Kuan Zhang 0001, Xiaohui Liang 0002, Jianbing Ni, Kan Yang 0001, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.2
2017 Re-DPoctor: Real-Time Health Data Releasing with W-Day Differential Privacy
abstract
Wearable devices enable users to collect health data and share them with healthcare providers for improved health service. Since health data contain privacy-sensitive information, unprotected data release system may result in privacy leakage problem. Most of the existing work use differential privacy for private data release. However, they have limitations in healthcare scenarios because they do not consider the unique features of health data being collected from wearables, such as continuous real-time collection and pattern preservation. In this paper, we propose Re-DPoctor, a real-time health data releasing scheme with w-day differential privacy where the privacy of health data collected from any consecutive w days is preserved. We improve utility by using a specially-designed partition algorithm to protect the health data patterns. Meanwhile, we improve privacy preservation by applying newly proposed adaptive sampling tech- nique and budget allocation method. We prove that Re-DPoctor satisfies w-day differential privacy. Experiments on real health data demonstrates that our method achieves better utility with strong privacy guarantee than existing state-of-the-art methods.
Jiajun Zhang 0005, Xiaohui Liang 0002, Zhikun Zhang 0001, Shibo He, Zhiguo Shi 0001
GLOBECOM2
2017 LightTouch: Securely connecting wearables to ambient displays with user intent
abstract
Wearables are small and have limited user interfaces, so they often wirelessly interface with a personal smartphone/computer to relay information from the wearable for display or other interactions. In this paper, we envision a new method, LightTouch, by which a wearable can establish a secure connection to an ambient display, such as a television or a computer monitor, while ensuring the user's intention to connect to the display. LightTouch uses standard RF methods (like Bluetooth) for communicating the data to display, securely bootstrapped via the visible-light communication (the brightness channel) from the display to the low-cost, low-power, ambient light sensor of a wearable. A screen `touch' gesture is adopted by users to ensure that the modulation of screen brightness can be securely captured by the ambient light sensor with minimized noise. Wireless coordination with the processor driving the display establishes a shared secret based on the brightness channel information. We further propose novel onscreen localization and correlation algorithms to improve security and reliability. Through experiments and a preliminary user study we demonstrate that LightTouch is compatible with current display and wearable designs, is easy to use (about 6 seconds to connect), is reliable (up to 98% success connection ratio), and is secure against attacks.
Xiaohui Liang 0002, Tianlong Yun, Ronald A. Peterson, David Kotz
INFOCOM1
2017 Privacy-Preserving Time-Sharing Services for Autonomous Vehicles
abstract
Sharing the Autonomous Vehicles (AV) has the potential to be the ultimate solution for overcoming the cost problem of these type of vehicles to fundamentally change the transportation systems. AVs enable the time sharing services where AV owners share their AVs at the times they don't need them. Such sharing could reduce the cost by enabling the owner to share the cost of the vehicle with other users. However, these services raise a severe privacy concern as the shared location and route data of the users are considered highly private and sensitive. In this paper we propose a privacy- preserving time-sharing scheme for AVs. Our approach enables the owner and the requester to perform a privacy-preserving matching on their transportation needs over the server without disclosing their routes to the server. To do so we use a set of Points of Interest (POI) locations as intermediate destinations in travel paths. Only if the matching is conflict-free and efficient, the owner and the requester share the details of the routes. We also show the accuracy of the proposed approach through extensive simulations on real data. It is shown that our enhanced POI selection scheme, with consideration of the traffic information and patterns in the area, outperforms the baseline scheme where the POIs are chosen randomly. Furthermore, it shows that our scheme achieves high accuracy in terms of resulting in false negatives compared to the ground truth.
Mohammad Hadian, Thamer Altuwaiyan, Xiaohui Liang 0002
VTC Fall3
2017 SPFM: Scalable and Privacy-Preserving Friend Matching in Mobile Cloud
abstract
Profile (e.g., contact list, interest, and mobility) matching is more than important for fostering the wide use of mobile social networks. The social networks such as Facebook, Line, or WeChat recommend the friends for the users based on users personal data such as common contact list or mobility traces. However, outsourcing users' personal information to the cloud for friend matching will raise a serious privacy concern due to the potential risk of data abusing. In this paper, we propose a novel scalable and privacy-preserving friend matching (SPFM) protocol, which aims to provide a scalable friend matching and recommendation solutions without revealing the users personal data to the cloud. Different from the previous works which involves multiple rounds of protocols, SPFM presents a scalable solution which can prevent honest-but-curious mobile cloud from obtaining the original data and support the friend matching of multiple users simultaneously. We give detailed feasibility and security analysis on SPFM and its accuracy and security have been well demonstrated via extensive simulations. The result show that our scheme works even better when original data is large.
Mengyuan Li 0004, Na Ruan, Qiyang Qian, Haojin Zhu, Xiaohui Liang 0002, Le Yu 0002
IEEE Internet Things J.5
2017 Privacy-Preserving Ride Sharing Scheme for Autonomous Vehicles in Big Data Era
abstract
Ride sharing can reduce the number of vehicles in the streets by increasing the occupancy of vehicles, which can facilitate traffic and reduce crashes and the number of needed parking slots. Autonomous vehicles can make ride sharing convenient, popular, and also necessary because of the elimination of the driver effort and the expected high cost of the vehicles. However, the organization of ride sharing requires the users to disclose sensitive detailed information not only on the pick-up/drop-off locations but also on the trip time and route. In this paper, we propose a scheme to organize ride sharing and address the unique privacy issues. Our scheme uses a similarity measurement technique over encrypted data to preserve the privacy of trip data. The ride sharing region is divided into cells and each cell is represented by one bit in a binary vector. Each user should represent trip data as binary vectors and submit the encryptions of the vectors to a server. The server can measure the similarity of the users' trip data and find users who can share rides without knowing the data. Our analysis has demonstrated that the proposed scheme can organize ride sharing without disclosing private information. We have implemented our scheme using Visual C on a real map and the measurements have confirmed that our scheme is effective when ride sharing becomes popular and the server needs to organize a large number of rides in short time.
Ahmed B. T. Sherif, Khaled Rabieh, Mohamed Mahmoud 0001, Xiaohui Liang 0002
IEEE Internet Things J.4
2017 Efficient Public Verification of Data Integrity for Cloud Storage Systems from Indistinguishability Obfuscation
abstract
Cloud storage services allow users to outsource their data to cloud servers to save local data storage costs. However, unlike using local storage devices, users do not physically manage the data stored on cloud servers; therefore, the data integrity of the outsourced data has become an issue. Many public verification schemes have been proposed to enable a third-party auditor to verify the data integrity for users. These schemes make an impractical assumption-the auditors have enough computation capability to bear expensive verification costs. In this paper, we propose a novel public verification scheme for the cloud storage using indistinguishability obfuscation, which requires a lightweight computation on the auditor and the delegate most computation to the cloud. We further extend our scheme to support batch verification and data dynamic operations, where multiple verification tasks from different users can be performed efficiently by the auditor and the cloud-stored data can be updated dynamically. Compared with other existing works, our scheme significantly reduces the auditor's computation overhead. Moreover, the batch verification overhead on the auditor side in our scheme is independent of the number of verification tasks. Our scheme could be practical in a scenario, where the data integrity verifications are executed frequently, and the number of verification tasks (i.e., the number of users) is numerous; even if the auditor is equipped with a low-power device, it can verify the data integrity efficiently. We prove the security of our scheme under the strongest security model proposed by Shi et al. (ACM CCS 2013). Finally, we conduct a performance analysis to demonstrate that our scheme is more efficient than other existing works in terms of the auditor's communication and computation efficiency.
Yuan Zhang 0006, Chunxiang Xu, Xiaohui Liang 0002, Hongwei Li 0001, Yi Mu 0001
IEEE Trans. Inf. Forensics Secur.3
2016 When CSI Meets Public WiFi: Inferring Your Mobile Phone Password via WiFi Signals
abstract
In this study, we present WindTalker, a novel and practical keystroke inference framework that allows an attacker to infer the sensitive keystrokes on a mobile device through WiFi-based side-channel information. WindTalker is motivated from the observation that keystrokes on mobile devices will lead to different hand coverage and the finger motions, which will introduce a unique interference to the multi-path signals and can be reflected by the channel state information (CSI). The adversary can exploit the strong correlation between the CSI fluctuation and the keystrokes to infer the user's number input. WindTalker presents a novel approach to collect the target's CSI data by deploying a public WiFi hotspot. Compared with the previous keystroke inference approach, WindTalker neither deploys external devices close to the target device nor compromises the target device. Instead, it utilizes the public WiFi to collect user's CSI data, which is easy-to-deploy and difficult-to-detect. In addition, it jointly analyzes the traffic and the CSI to launch the keystroke inference only for the sensitive period where password entering occurs. WindTalker can be launched without the requirement of visually seeing the smart phone user's input process, backside motion, or installing any malware on the tablet. We implemented Windtalker on several mobile phones and performed a detailed case study to evaluate the practicality of the password inference towards Alipay, the largest mobile payment platform in the world. The evaluation results show that the attacker can recover the key with a high successful rate.
Mengyuan Li 0004, Yan Meng 0001, Haojin Zhu, Xiaohui Liang 0002, Yao Liu 0007, Na Ruan
CCS5
2016 Privacy-Preserving mHealth Data Release with Pattern Consistency
abstract
Mobile healthcare system integrating wearable sensing and wireless communication technologies continuously monitors the users' health status. However, the mHealth system raises a severe privacy concern as the data it collects are private information, such as heart rate and blood pressure. In this paper, we propose an efficient and privacy-preserving mHealth data release approach for the statistic data with the objectives to preserve the unique patterns in the original data bins. The proposed approach adopts the bucket partition algorithm and the differential privacy algorithm for privacy preservation. A customized bucket partition algorithm is proposed to combine the database value bins into buckets according to certain conditions and parameters such that the patterns are preserved. The differential privacy algorithm is then applied to the buckets to prevent an attacker from being able to identify the small changes at the original data. We prove that the proposed approach achieves differential privacy. We also show the accuracy of the proposed approach through extensive simulations on real data. Real experiments show that our partitioning algorithm outperforms the state-of-the-art in preserving the patterns of the original data by a factor of 1.75.
Mohammad Hadian, Xiaohui Liang 0002, Thamer Altuwaiyan, Mohamed Mahmoud 0001
GLOBECOM2
2016 Towards Efficient Privacy-Preserving Truth Discovery in Crowd Sensing Systems
abstract
With the rapid development of portable mobile devices, crowd sensing systems have been recognized as a key technology to utilize the data collected by the portable mobile devices towards scalable and flexible mobile services. However, since the information provided by devices may not be reliable, the aggregated results of the collected data may not be accurate. To tackle this challenge, various truth discovery schemes have been proposed. On the other hand, a practical issue of privacy protection is not considered in most existing truth discovery schemes. In this paper, we propose an Efficient Privacy-preserving Truth Discovery (EPTD) in Crowd Sensing Systems, which can protect the privacy of users' observed values and weights in truth discovery process. Finally, we show the performance of our scheme is better than existing models in terms of computation overhead.
Guowen Xu, Hongwei Li 0001, Hao Ren 0001, Yuan-Shun Dai, Xiaohui Liang 0002
GLOBECOM6
2016 Wanda: Securely introducing mobile devices
abstract
Nearly every setting is increasingly populated with wireless and mobile devices - whether appliances in a home, medical devices in a health clinic, sensors in an industrial setting, or devices in an office or school. There are three fundamental operations when bringing a new device into any of these settings: to configure the device to join the wireless local-area network, to partner the device with other nearby devices so they can work together, and (3) to configure the device so it connects to the relevant individual or organizational account in the cloud. The challenge is to accomplish all three goals simply, securely, and consistent with user intent. We present a novel approach we call Wanda - a `magic wand' that accomplishes all three of the above goals - and evaluate a prototype implementation.
Timothy J. Pierson, Xiaohui Liang 0002, Ronald A. Peterson, David Kotz
INFOCOM2
2016 CIT: A credit-based incentive tariff scheme with fraud-traceability for smart grid
abstract
Abstract The growing peak‐hour power demand has invoked an urgency to increase the peak‐hour supply. Although smart grid has been envisioned as the next generation power system due to its two‐way communication of information and power, the peak‐hour power shortage problem still exists. In this paper, we propose a credit‐based incentive tariff (CIT) scheme with fraud‐traceability for smart grid. Specifically, the CIT encourages retail customers to sell the power generated by their renewable resources back to the grid during peak hours via giving additional incentive rate to them based on their credits. If a fraud is detected during the power transaction, the malicious customer's identity can be traced out and his or her credit can be correspondingly reduced. The security analysis shows that the CIT resists various security threats and makes the incentive tariff fair and more secure. The performance evaluation demonstrates that the CIT can dramatically increase the peak‐hour supply and reduce the peak‐to‐average power demand ratio by up to 7%. Copyright © 2013 John Wiley & Sons, Ltd.
Mi Wen, Kuan Zhang 0001, Jingsheng Lei, Xiaohui Liang 0002, Ruilong Deng, Xuemin Shen
Secur. Commun. Networks4
2016 Enabling Fine-Grained Multi-Keyword Search Supporting Classified Sub-Dictionaries over Encrypted Cloud Data
abstract
Using cloud computing, individuals can store their data on remote servers and allow data access to public users through the cloud servers. As the outsourced data are likely to contain sensitive privacy information, they are typically encrypted before uploaded to the cloud. This, however, significantly limits the usability of outsourced data due to the difficulty of searching over the encrypted data. In this paper, we address this issue by developing the fine-grained multi-keyword search schemes over encrypted cloud data. Our original contributions are three-fold. First, we introduce the relevance scores and preference factors upon keywords which enable the precise keyword search and personalized user experience. Second, we develop a practical and very efficient multi-keyword search scheme. The proposed scheme can support complicated logic search the mixed “AND”, “OR” and “NO” operations of keywords. Third, we further employ the classified sub-dictionaries technique to achieve better efficiency on index building, trapdoor generating and query. Lastly, we analyze the security of the proposed schemes in terms of confidentiality of documents, privacy protection of index and trapdoor, and unlinkability of trapdoor. Through extensive experiments using the real-world dataset, we validate the performance of the proposed schemes. Both the security analysis and experimental results demonstrate that the proposed schemes can achieve the same security level comparing to the existing ones and better performance in terms of functionality, query complexity and efficiency.
Hongwei Li 0001, Yi Yang 0027, Tom H. Luan, Xiaohui Liang 0002, Liang Zhou 0003, Xuemin Shen
IEEE Trans. Dependable Secur. Comput.4
2015 Exploiting mobile social behaviors for Sybil detection
abstract
In this paper, we propose a Social-based Mobile Sybil Detection (SMSD) scheme to detect Sybil attackers from their abnormal contacts and pseudonym changing behaviors. Specifically, we first define four levels of Sybil attackers in mobile environments according to their attacking capabilities. We then exploit mobile users' contacts and their pseudonym changing behaviors to distinguish Sybil attackers from normal users. To alleviate the storage and computation burden of mobile users, the cloud server is introduced to store mobile user's contact information and to perform the Sybil detection. Furthermore, we utilize a ring structure associated with mobile user's contact signatures to resist the contact forgery by mobile users and cloud servers. In addition, investigating mobile user's contact distribution and social proximity, we propose a semi-supervised learning with Hidden Markov Model to detect the colluded mobile users. Security analysis demonstrates that the SMSD can resist the Sybil attackers from the defined four levels, and the extensive trace-driven simulation shows that the SMSD can detect these Sybil attackers with high accuracy.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Kan Yang 0001, Xuemin Shen
INFOCOM2
2015 PIF: A Personalized Fine-Grained Spam Filtering Scheme With Privacy Preservation in Mobile Social Networks
abstract
Mobile social network (MSN) emerges as a promising social network paradigm that enables mobile users' information sharing in the proximity and facilitates their cyber-physical-social interactions. As the advertisements, rumors, and spams spread in MSNs, it is necessary to filter spams before they arrive at the recipients to make the MSN energy efficient. To this end, we propose a personalized fine-grained filtering scheme (PIF) with privacy preservation in MSNs. Specifically, we first develop a social-assisted filter distribution scheme, where the filter creators send filters to their social friends (i.e., filter holders). These filter holders store filters and decide to block spams or relay the desired packets through coarse-grained and fine-grained keyword filtering schemes. Meanwhile, the developed cryptographic filtering schemes protect creator's private information (i.e., keyword) embedded in the filters from directly disclosing to other users. In addition, we establish a Merkle Hash tree to store filters as leaf nodes where filter creators can check if the distributed filters need to be updated by retrieving the value of root node. It is demonstrated that the PIF can protect users' private keywords included in the filter from disclosure to others and detect forged filters. We also conduct the trace-driven simulations to show that the PIF can not only filter spams efficiently but also achieve high delivery ratio and low latency with acceptable resource consumption.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
IEEE Trans. Comput. Soc. Syst.2
2014 Poster: Balancing disclosure and utility of personal information
abstract
The ubiquity of smartphones and mobile and wearable devices allow people to collect information about their health, wellness and lifestyle and share with others. If it is not clear what they need to share to receive benefits, subjects (people whose information is collected) might share too much, thus disclosing unnecessary private information. On the other hand, concerned about disclosing personal information, subjects might share less than what the recipient needs and lose the opportunity to enjoy the benefits. This balance of disclosure and utility is important when the subject wants to receive some benefits, but is concerned about disclosing private information.
Aarathi Prasad, Xiaohui Liang 0002, David Kotz
MobiSys2
2014 RSEL: revocable secure efficient lightweight RFID authentication scheme
abstract
SUMMARY Radio frequency identification (RFID) has been regarded as one of the 10 important technologies in the 21st century. Because of its capability to rapidly and accurately collect and process data in real‐time, RFID has been widely applied in many areas, such as Internet of Things and Smart Grid. However, the existing security threats become more severe toward RFID authentication scheme. The traditional security mechanisms cannot be used in RFID directly because of the limitations of processing capability, storage space, and power supply of RFID tags. In this paper, we propose a revocable secure efficient lightweight RFID authentication scheme (RSEL). To achieve authentication efficiency, the key of the tag is chosen to reduce the number of hash computing in the database. Furthermore, the key is stored in the database and updated constantly with the tag to prevent the tracking and synchronization attacks. The valid period of each tag is stored in the database so that RSEL can revoke the expired tag. The correctness of RSEL has been proved using GNY logic. The performance of RSEL in terms of security and efficiency is evaluated. Compared with other existing approaches, RSEL achieves stronger security and higher efficiency. Copyright © 2013 John Wiley & Sons, Ltd.
Kai Fan 0001, Hui Li 0006, Xiaohui Liang 0002, Xuemin Shen, Yintang Yang
Concurr. Comput. Pract. Exp.4
2014 CPAL: A Conditional Privacy-Preserving Authentication With Access Linkability for Roaming Service
abstract
The roaming service enables mobile subscribers to access the internet service anytime and anywhere, which can fulfill the requirement of ubiquitous access for the emerging paradigm of networking, e.g., the Internet of Things (IoT). In this paper, we propose a conditional privacy-preserving authentication with access linkability (CPAL) for roaming service, to provide universal secure roaming service and multilevel privacy preservation. CPAL provides an anonymous user linking function by utilizing a novel group signature technique, which can not only efficiently hide users’ identities but also enables the authorized entities to link all the access information of the same user without knowing the user’s real identity. Specifically, by using the master linking key possessed by the trust linking server, the authorized foreign network operators or service providers can link the access information from the user to improve its service, while preserving user anonymity, e.g., using individual access information to analyze user preferences without revealing user’s identity. Furthermore, the subscribers can also use this functionality to anonymously query their usage of service. In addition, CPAL has an efficient revocation function, which revokes a group of users at the same time. Through extensive analysis, we demonstrate that CPAL resists various security threats and provides more flexible privacy preservation compared to the existing schemes. Meanwhile, performance evaluations demonstrate its efficiency in terms of communication and computation overhead.
Chengzhe Lai, Hui Li 0006, Xiaohui Liang 0002, Rongxing Lu, Kuan Zhang 0001, Xuemin Shen
IEEE Internet Things J.3
2014 Sybil Attacks and Their Defenses in the Internet of Things
abstract
The emerging Internet-of-Things (IoT) are vulnerable to Sybil attacks where attackers can manipulate fake identities or abuse pseudoidentities to compromise the effectiveness of the IoT and even disseminate spam. In this paper, we survey Sybil attacks and defense schemes in IoT. Specifically, we first define three types Sybil attacks: SA-1, SA-2, and SA-3 according to the Sybil attacker's capabilities. We then present some Sybil defense schemes, including social graph-based Sybil detection (SGSD), behavior classification-based Sybil detection (BCSD), and mobile Sybil detection with the comprehensive comparisons. Finally, we discuss the challenging research issues and future directions for Sybil defense in IoT.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
IEEE Internet Things J.2
2014 PHDA: A priority based health data aggregation with privacy preservation for cloud assisted WBANs
Kuan Zhang 0001, Xiaohui Liang 0002, Mrinmoy Barua, Rongxing Lu, Xuemin Shen
Inf. Sci.2
2014 RCare: Extending Secure Health Care to Rural Area Using VANETs
Mrinmoy Barua, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
Mob. Networks Appl.2
2014 SESA: an efficient searchable encryption scheme for auction in emerging smart grid marketing
abstract
Distributed energy resources DERs, which are characterized by small-scale power generation technologies to provide an enhancement of the traditional power system, have been strongly encouraged to be integrated into the smart grid, and numerous trading strategies have recently been proposed to support the energy auction in the emerging smart grid marketing. However, few of them consider the security aspects of energy trading, such as privacy preservation, bid integrity, and pre-filtering ability. In this paper, we propose an efficient searchable encryption scheme for auction SESA in emerging smart grid marketing. Specifically, SESA uses a public key encryption with keyword search technique to enable the energy sellers e.g., DERs to inquire suitable bids while preserving the privacy of the energy buyers. Additionally, to facilitate the seller to search for detailed information of the bids, we also propose an extension of SESA to support conjunctive keywords search. Security analysis demonstrates that the proposed SESA and its extension can achieve data and keyword privacy, bid integrity and trapdoor unforgeability. Simulation results also show that both SESA and its extension have less computation and communication overhead than the existing searchable encryption approaches. Copyright © 2013 John Wiley & Sons, Ltd.
Mi Wen, Rongxing Lu, Jingsheng Lei, Hongwei Li 0001, Xiaohui Liang 0002, Xuemin Shen
Secur. Commun. Networks5
2014 Exploiting Geo-Distributed Clouds for a E-Health Monitoring System With Minimum Service Delay and Privacy Preservation
abstract
In this paper, we propose an e-health monitoring system with minimum service delay and privacy preservation by exploiting geo-distributed clouds. In the system, the resource allocation scheme enables the distributed cloud servers to cooperatively assign the servers to the requested users under the load balance condition. Thus, the service delay for users is minimized. In addition, a traffic-shaping algorithm is proposed. The traffic-shaping algorithm converts the user health data traffic to the nonhealth data traffic such that the capability of traffic analysis attacks is largely reduced. Through the numerical analysis, we show the efficiency of the proposed traffic-shaping algorithm in terms of service delay and privacy preservation. Furthermore, through the simulations, we demonstrate that the proposed resource allocation scheme significantly reduces the service delay compared to two other alternatives using jointly the short queue and distributed control law.
Qinghua Shen, Xiaohui Liang 0002, Xuemin Shen, Xiaodong Lin 0001, Henry Y. Luo
IEEE J. Biomed. Health Informatics2
2014 EPPDR: An Efficient Privacy-Preserving Demand Response Scheme with Adaptive Key Evolution in Smart Grid
abstract
Smart grid has recently emerged as the next generation of power grid due to its distinguished features, such as distributed energy control, robust to load fluctuations, and close user-grid interactions. As a vital component of smart grid, demand response can maintain supply-demand balance and reduce users' electricity bills. Furthermore, it is also critical to preserve user privacy and cyber security in smart grid. In this paper, we propose an efficient privacy-preserving demand response (EPPDR) scheme which employs a homomorphic encryption to achieve privacy-preserving demand aggregation and efficient response. In addition, an adaptive key evolution technique is further investigated to ensure the users' session keys to be forward secure. Security analysis indicates that EPPDR can achieve privacy-preservation of electricity demand, forward secrecy of users' session keys, and evolution of users' private keys. In comparison with an existing scheme which also achieves forward secrecy, EPPDR has better efficiency in terms of computation and communication overheads and can adaptively control the key evolution to balance the trade-off between the communication efficiency and security level.
Hongwei Li 0001, Xiaodong Lin 0001, Haomiao Yang, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.4
2014 Enabling Trustworthy Service Evaluation in Service-Oriented Mobile Social Networks
abstract
In this paper, we propose a Trustworthy Service Evaluation (TSE) system to enable users to share service reviews in service-oriented mobile social networks (S-MSNs). Each service provider independently maintains a TSE for itself, which collects and stores users' reviews about its services without requiring any third trusted authority. The service reviews can then be made available to interested users in making wise service selection decisions. We identify three unique service review attacks, i.e., linkability, rejection, and modification attacks, and develop sophisticated security mechanisms for the TSE to deal with these attacks. Specifically, the basic TSE (bTSE) enables users to distributedly and cooperatively submit their reviews in an integrated chain form by using hierarchical and aggregate signature techniques. It restricts the service providers to reject, modify, or delete the reviews. Thus, the integrity and authenticity of reviews are improved. Further, we extend the bTSE to a Sybil-resisted TSE (SrTSE) to enable the detection of two typical sybil attacks. In the SrTSE, if a user generates multiple reviews toward a vendor in a predefined time slot with different pseudonyms, the real identity of that user will be revealed. Through security analysis and numerical results, we show that the bTSE and the SrTSE effectively resist the service review attacks and the SrTSE additionally detects the sybil attacks in an efficient manner. Through performance evaluation, we show that the bTSE achieves better performance in terms of submission rate and delay than a service review system that does not adopt user cooperation.
Xiaohui Liang 0002, Xiaodong Lin 0001, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.1
2013 RECCE: A reliable and efficient cloud cooperation scheme in E-healthcare
abstract
E-healthcare is an emerging and promising healthcare system to meet the increasing medical demand from aging population. It requires extensive data storage, pervasive data access, and reliable computing resources to support the real-time communication of critical health information and the real-time diagnosis. Recently, cloud computing, including public cloud and private cloud, with both scalability and accessibility is proposed to be integrated in the e-healthcare system. However, in meeting stringent medical requirements, private clouds lack necessary reliability, whereas public clouds suffer from communication delay. In this paper, we first introduce a cooperation framework to address the distinct challenger facing different clouds. It is inspired by the fact that private clouds are geographically deployed and public clouds can be regarded to possess infinite computing resources. In our framework, private clouds are designed to serve parts of local requests to public clouds, and rewarded by receiving help with excess requests. We adopt stochastic control theory to address the failure minimization issues for private clouds under random demand process. We prove the optimality of a policy constructed through recursion. Numerical and simulation results are presented to demonstrate that our proposed scheme can improve the reliability of private clouds, as well as reduce average delay of public clouds.
Qinghua Shen, Xiaohui Liang 0002, Xuemin Shen, Xiaodong Lin 0001, Henry Y. Luo
GLOBECOM2
2013 ECQ: An Efficient Conjunctive Query scheme over encrypted multidimensional data in smart grid
abstract
With the deployment of smart meters at individual households, smart grid can collect metering data of users' power consumption. However, users' power usage patterns would also be revealed. To preserve the users' privacy, metering data is mostly encrypted by cryptographic algorithms. When data mining is needed to support decision making or ensure reliability, to find useful information from the encrypted data is very important for smart grid. Most of the traditional keyword searching schemes rarely consider both users' data privacy and requesters' query privacy. In particular, the power system data in smart grid has multidimensional attributes; thus, how to query over the encrypted multidimensional data on all dimensions is a challenging issue in smart grid. To achieve finer grained conjunctive query, this paper proposes an Efficient Conjunctive Query (ECQ) scheme. Specificly, the ECQ incorporates the idea of public key encryption and conjunctive keywords search to achieve conjunctive query without data and query privacy leakage. Security analysis demonstrates that the ECQ can achieve the security requirements, namely, data confidentiality, integrity and privacy, as well as query privacy. In addition, simulation results show that the ECQ can reduce users' computation cost and total communication cost.
Mi Wen, Rongxing Lu, Jingsheng Lei, Xiaohui Liang 0002, Hongwei Li 0001, Xuemin Shen
GLOBECOM4
2013 SAFE: A social based updatable filtering protocol with privacy-preserving in mobile social networks
abstract
Mobile Social Networks (MSN), as an emerging social networking platform, facilitates social interaction and information sharing among users in the proximity. Spam filtering protocols are extremely important to reduce communication and storage overhead when many spam packets without specific destinations are diffused in MSNs. In this paper, we propose an effective social based updatable filtering protocol (SAFE) with privacy preservation in MSNs. Specifically, we firstly construct a filter Hash tree based on the properties of Merkle tree. Then, we exploit social relationships, and select those users with more than a specific number of common attributes with the filter creator. The selected users are able to store filters in order to block spams or relay regular packets. Furthermore, we develop a cryptographic filtering scheme without disclosing the creator's private information or interests. In addition, we propose a filter update mechanism to allow users to update their distributed filters in time. The security analysis demonstrates that the SAFE can protect user's private information from filter's disclosure to other users and resist filter forgery attack. Through extensive trace-driven simulations, we show that the SAFE is effective and efficient to filter spam packets in terms of delivery ratio, average delay, and communication overhead.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
ICC2
2013 Fully Anonymous Profile Matching in Mobile Social Networks
abstract
In this paper, we study user profile matching with privacy-preservation in mobile social networks (MSNs) and introduce a family of novel profile matching protocols. We first propose an explicit Comparison-based Profile Matching protocol (eCPM) which runs between two parties, an initiator and a responder. The eCPM enables the initiator to obtain the comparison-based matching result about a specified attribute in their profiles, while preventing their attribute values from disclosure. We then propose an implicit Comparison-based Profile Matching protocol (iCPM) which allows the initiator to directly obtain some messages instead of the comparison result from the responder. The messages unrelated to user profile can be divided into multiple categories by the responder. The initiator implicitly chooses the interested category which is unknown to the responder. Two messages in each category are prepared by the responder, and only one message can be obtained by the initiator according to the comparison result on a single attribute. We further generalize the iCPM to an implicit Predicate-based Profile Matching protocol (iPPM) which allows complex comparison criteria spanning multiple attributes. The anonymity analysis shows all these protocols achieve the confidentiality of user profiles. In addition, the eCPM reveals the comparison result to the initiator and provides only conditional anonymity; the iCPM and the iPPM do not reveal the result at all and provide full anonymity. We analyze the communication overhead and the anonymity strength of the protocols. We then present an enhanced version of the eCPM, called eCPM+, by combining the eCPM with a novel prediction-based adaptive pseudonym change strategy. The performance of the eCPM and the eCPM+ are comparatively studied through extensive trace-based simulations. Simulation results demonstrate that the eCPM+ achieves significantly higher anonymity strength with slightly larger number of pseudonyms than the eCPM.
Xiaohui Liang 0002, Xu Li 0001, Kuan Zhang 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
IEEE J. Sel. Areas Commun.1
2012 EDR: An efficient demand response scheme for achieving forward secrecy in smart grid
abstract
Compared with traditional power grid, smart grid has several distinguished features, i.e., distributed energy, large-capacity, robust to load fluctuations, and close consumer-grid interactions. Demand response is vital for smart grid, which is expected to save energy, maintain supply-demand balance, and reduce consumers' electricity bills. Meanwhile, it is paramount important to preserve consumers privacy and cyber security in smart grid. To tackle these challenging issues, in this paper, we propose an efficient demand response (EDR) scheme which utilizes the homomorphic encryption to achieve privacy-preserving demand aggregation and efficient response. Unlike existing schemes, the proposed EDR scheme can also achieve forward secrecy in addition to security features including confidentiality, authenticity and integrity. Extensive analysis demonstrates its security, and efficiency in terms of the computation and communication overhead.
Hongwei Li 0001, Xiaohui Liang 0002, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
GLOBECOM2
2012 VSLP: Voronoi-socialspot-aided packet forwarding protocol with receiver Location Privacy in MSNs
abstract
With the pervasive use of smart phones in the daily life, location privacy has become one of cruxes for the success of mobile social networks (MSNs). In this paper, we propose a Voronoi-social-spot-aided Location Privacy-preserving (VSLP) packet forwarding protocol to improve the packet forwarding efficiency and at the same time protect receiver's location privacy. In VSLP, we first identify the social spot locations according to the user mobility information, and then build a Voronoi diagram based on the defined social spots. On the edge of Delaunay triangulation over the Voronoi diagram, we deploy multiple storage devices to help receivers to temporarily store the packets. With the security analysis, we show that the location privacy can be achieved. Using extensive simulations, we show that VSLP can enhance the packet forwarding efficiency with improved packet delivery ratio and reduced average packet delay.
Kuan Zhang 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen, Hai Zhao 0002
GLOBECOM2
2012 Enabling pervasive healthcare with privacy preservation in smart community
abstract
Smart community is an emerging Internet of Things application. It supports a variety of high-value automated services such as pervasive healthcare through a multi-hop community network of smart homes in a local residential region. In this paper, we study privacy preserving data communication between patients and an online healthcare provider (referred to as vendor) for efficient remote healthcare monitoring (RHM) in a smart community environment. We adopt patients' attribute structures instead of their identities for authentication and preserve identity privacy during patient-to-vendor communication, and we build a receiver chain among smart homes to enable vendor-to-patient communication and achieve location privacy. The privacy preserving properties of the proposed data communication scheme are analyzed, and its effectiveness and efficiency are demonstrated through extensive simulations.
Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
ICC1
2012 SEER: A Secure and Efficient Service Review System for Service-Oriented Mobile Social Networks
abstract
In this paper, we consider service-oriented mobile social networks (S-MSNs) and propose a Secure and Efficient service Review (SEER) system to enable user feedback. Each service provider independently maintains a SEER system for itself, which collects and stores user reviews about its services without requiring any central trusted authority. The service reviews can then be made available to interested users in making wise service selection decisions. We identify three unique service review attacks and then develop sophisticated security mechanisms for SEER to deal with these attacks. Specifically, SEER enables users to distributedly and cooperatively submit their reviews in an integrated chain form by using hierarchical and aggregate signature techniques. It discourages service providers to reject, modify or delete their reviews. The integrity of reviews is therefore improved. Through security analysis and performance evaluation, we show that SEER effectively resists the service review attacks and achieves significantly better performance in terms of submission rate and delay than a service review system that does not adopt user cooperation or the chain review structure.
Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
ICDCS1
2012 Exploiting prediction to enable Secure and Reliable routing in Wireless Body Area Networks
abstract
In this paper, we propose a distributed Prediction-based Secure and Reliable routing framework (PSR) for emerging Wireless Body Area Networks (WBANs). It can be integrated with a specific routing protocol to improve the latter's reliability and prevent data injection attacks during data communication. In PSR, using past link quality measurements, each node predicts the quality of every incidental link, and thus any change in the neighbor set as well, for the immediate future. When there are multiple possible next hops for packet forwarding (according to the routing protocol used), PSR selects the one with the highest predicted link quality among them. Specially-tailored lightweight source and data authentication methods are employed by nodes to secure data communication. Further, each node adaptively enables or disables source authentication according to predicted neighbor set change and prediction accuracy so as to quickly filter false source authentication requests. We demonstrate that PSR significantly increases routing reliability and effectively resists data injection attacks through in-depth security analysis and extensive simulation study.
Xiaohui Liang 0002, Xu Li 0001, Qinghua Shen, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen, Weihua Zhuang
INFOCOM1
2012 PReFilter: An efficient privacy-preserving Relay Filtering scheme for delay tolerant networks
abstract
Without direct path, information delivery in sparse delay tolerant networks (DTNs) typically relies on intermittent relays, making the transmission not only unreliable but also time consuming. To make the matter even worse, the source nodes may transmit some encrypted “junk” information, similar as the spam emails in current mail systems, to the destinations; without effective control, the delivery of encrypted junk information would significantly consume the precious resource of DTN and accordingly throttle the network efficiency. To address this challenging issue, we propose PReFilter, an efficient privacy-preserving relay filter scheme to prevent the relay of encrypted junk information early in DTNs. In PReFilter, each node maintains a specific filtering policy based on its interests, and distributes this policy to a group of “friends” in the network in advance. By applying the filtering policy, the friends can filter the junk packets which are heading to the node during the relay. Note that the keywords in the filtering policy may disclose the node's interest/preference to some extent, harming the privacy of nodes, a privacy-preserving filtering policy distribution technique is introduced, which will keep the sensitive keywords secret in the filtering policy. Through detailed security analysis, we demonstrate that PReFilter can prevent strong privacy-curious adversaries from learning the filtering keywords, and discourage a weak privacy-curious friend to guess the filtering keywords from the filtering policy. In addition, with extensive simulations, we show that PReFilter is not only effective in the filtering of junk packets but also significantly improve the network performance with the dramatically reduced delivery cost due to the junk packets.
Rongxing Lu, Xiaodong Lin 0001, Tom H. Luan, Xiaohui Liang 0002, Xu Li 0001, Xuemin Shen
INFOCOM4
2012 HealthShare: Achieving secure and privacy-preserving health information sharing through health social networks
Xiaohui Liang 0002, Mrinmoy Barua, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
Comput. Commun.1
2012 A Dynamic Privacy-Preserving Key Management Scheme for Location-Based Services in VANETs
abstract
In this paper, to achieve a vehicle user's privacy preservation while improving the key update efficiency of location-based services (LBSs) in vehicular ad hoc networks (VANETs), we propose a dynamic privacy-preserving key management scheme called DIKE. Specifically, in the proposed DIKE scheme, we first introduce a privacy-preserving authentication technique that not only provides the vehicle user's anonymous authentication but enables double-registration detection as well. We then present efficient LBS session key update procedures: 1) We divide the session of an LBS into several time slots so that each time slot holds a different session key; when no vehicle user departs from the service session, each joined user can use a one-way hash function to autonomously update the new session key for achieving forward secrecy. 2) We also integrate a novel dynamic threshold technique in traditional vehicle-to-vehicle (V-2-V) and vehicle-to-infrastructure (V-2-I) communications to achieve the session key's backward secrecy, i.e., when a vehicle user departs from the service session, more than a threshold number of joined users can cooperatively update the new session key. Performance evaluations via extensive simulations demonstrate the efficiency and effectiveness of the proposed DIKE scheme in terms of low key update delay and fast key update ratio.
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen
IEEE Trans. Intell. Transp. Syst.3
2012 EPPA: An Efficient and Privacy-Preserving Aggregation Scheme for Secure Smart Grid Communications
abstract
The concept of smart grid has emerged as a convergence of traditional power system engineering and information and communication technology. It is vital to the success of next generation of power grid, which is expected to be featuring reliable, efficient, flexible, clean, friendly, and secure characteristics. In this paper, we propose an efficient and privacy-preserving aggregation scheme, named EPPA, for smart grid communications. EPPA uses a superincreasing sequence to structure multidimensional data and encrypt the structured data by the homomorphic Paillier cryptosystem technique. For data communications from user to smart grid operation center, data aggregation is performed directly on ciphertext at local gateways without decryption, and the aggregation result of the original data can be obtained at the operation center. EPPA also adopts the batch verification technique to reduce authentication cost. Through extensive analysis, we demonstrate that EPPA resists various security threats and preserve user privacy, and has significantly less computation and communication overhead than existing competing approaches.
Rongxing Lu, Xiaohui Liang 0002, Xu Li 0001, Xiaodong Lin 0001, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.2
2012 BECAN: A Bandwidth-Efficient Cooperative Authentication Scheme for Filtering Injected False Data in Wireless Sensor Networks
abstract
Injecting false data attack is a well known serious threat to wireless sensor network, for which an adversary reports bogus information to sink causing error decision at upper level and energy waste in en-route nodes. In this paper, we propose a novel bandwidth-efficient cooperative authentication (BECAN) scheme for filtering injected false data. Based on the random graph characteristics of sensor node deployment and the cooperative bit-compressed authentication technique, the proposed BECAN scheme can save energy by early detecting and filtering the majority of injected false data with minor extra overheads at the en-route nodes. In addition, only a very small fraction of injected false data needs to be checked by the sink, which thus largely reduces the burden of the sink. Both theoretical and simulation results are given to demonstrate the effectiveness of the proposed scheme in terms of high filtering probability and energy saving.
Rongxing Lu, Xiaodong Lin 0001, Haojin Zhu, Xiaohui Liang 0002, Xuemin Shen
IEEE Trans. Parallel Distributed Syst.4
2011 EPF: An Event-Aided Packet Forwarding Protocol for Privacy-Preserving Mobile Healthcare Social Networks
abstract
In this paper, we propose an event-aided packet forwarding (EPF) protocol, which enables patients to efficiently communicate with each other in privacy-preserving Mobile Healthcare Social Networks (MHSNs). Since patients with common illnesses often attend the same related activities, EPF makes use of these activities in forwarding illness-related messages to the target patients so that it can achieve high target patients coverage ratio. In addition, EPF also adopts predicate encryption to guarantee patient privacy and message confidentiality. Through security analysis, we demonstrate that EPF can effectively resist various attacks launched by adversaries, and ensure patient identity and illness privacy. Extensive simulations are also conducted to evaluate the performance of EPF in terms of average target patients coverage ratio, average number of packet copies, and average packet delay.
Zhenfu Cao, Rongxing Lu, Xiaohui Liang 0002, Xuemin Shen
GLOBECOM4
2011 Coordinate-Free Distributed Algorithm for Boundary Detection in Wireless Sensor Networks
abstract
In this paper, we propose a coordinate-free distributed boundary detection algorithm (CDBD). It adopts general sensing and communication models and exploits two centrality measures, i.e., betweenness and closeness. For CDBD, each node only needs to communicate with its $k$-hop neighbors twice and makes decision whether it itself is a boundary node independently. CDBD has advantages of fast convergence and low communication overhead. Extensive simulation demonstrates the desirable performance of CDBD.
Xu Li 0001, Shibo He, Jiming Chen 0001, Xiaohui Liang 0002, Rongxing Lu, Xuemin Shen
GLOBECOM4
2011 An Efficient and Secure User Revocation Scheme in Mobile Social Networks
abstract
Mobile social network (MSN) is a promising networking and communication platform for users having similar interests (or attributes) to connect and interact with one another. For many recently introduced secure MSN data communication schemes, attribute-based encryption is often adopted to preserve user privacy and prevent outside attackers from eavesdropping. In this paper, we propose an efficient and secure user revocation scheme to address inside attacks based on an attribute-based encryption technique. The proposed scheme enables a trusted authority (TA) to flexibly control the data decryption capability of mobile social users. It disables malicious users from decrypting any data packet. As a result, proper user behavior is encouraged, inside attacks are reduced, and network security is enhanced. Through the analysis, we demonstrate that the proposed user revocation scheme is able to resist attribute collusion attacks and revoke collusion attacks. Extensive simulation results further confirm that the proposed scheme has much smaller communication overhead and much shorter delay than the existing solution [1].
Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
GLOBECOM1
2011 Side Channel Monitoring: Packet Drop Attack Detection in Wireless Ad Hoc Networks
abstract
Wireless ad hoc networks have great potentials in a broad range of applications. Their inherent vulnerability to various network attacks however limits their wide adaptation and deployment in practice. In this paper we address one of the most dangerous attacks, packet drop attack, in wireless ad hoc networks by post-routing detection. We introduce a simple, effective detection technique Side Channel Monitoring (SCM). The idea is to use nodes adjacent to a data communication route to monitor the message forwarding behavior of the nodes en route. These monitoring nodes constitute a directional side channel toward the source, in parallel to the backward route (primary channel). On observing misbehavior, they issue alarm packets to the source node through both channels. Considering channel disconnectivity (topologically or due to malicious packet drop), we analytically study the security strength of SCM including detection rate and expected number of detected attacks. Numeric results show that it is effective in various network scenarios.
Xu Li 0001, Rongxing Lu, Xiaohui Liang 0002, Xuemin Shen
ICC3
2011 Fine-Grained Identification with Real-Time Fairness in Mobile Social Networks
abstract
Mutual user identification is a necessary step for trust establishment among users in an unattended mobile social network (MSN). Directly exposing identity information to others unknown may cause total unfairness in identity loss when the other party of the identification process misbehaves. Using an on-line trusted third party (TTP) for user identification will cause communication and security problems, while a traditional off-line TTP solution will generate delay in fairness enforcement. In this paper, we propose a novel fine-grained identification protocol, which provides confidentiality, unlinkability, and real-time fairness without the involvement of TTP. In the protocol, identification is carried out by an iterative identification information exchange process, where two participating users have to disclose part of their identification information to each other in each iteration. The process terminates whenever one of them fails to do so. In this way, if a user loses part of its identification information to another user, then it must have obtained an approximately equal amount of identification information of that user. Therefore, misbehavior is discouraged, and fairness is improved. Through analysis we demonstrate that fairness can be well guaranteed as long as users strictly follow the protocol rules. Extensive simulation results further confirm that the proposed protocol can significantly reduce fairness loss in MSN environment.
Xiaohui Liang 0002, Xu Li 0001, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
ICC1
2011 Anonymity Analysis on Social Spot Based Pseudonym Changing for Location Privacy in VANETs
abstract
Location privacy is one of the Quality of Privacies (QoP) in vehicular ad hoc network (VANET) and imperative for the VANET's full flourish. Frequent pseudonym changing can provide a promising solution to achieve location privacy, however if the pseudonyms are changed in an improper occasion, the solution is ineffective. In this paper, to improve the effectiveness of this kind of solution, we first introduce the social spot where many vehicles could aggregate, e.g., a road intersection when the traffic light is red or a free parking lot near a shopping mall. We then propose a social spot based pseudonyms changing technique to achieve the location privacy. By taking the anonymity set size as the privacy metric, we develop two anonymity analytic models to quantitatively investigate the location privacy achieved in the technique. The analytical results show that better location privacy can be achieved when a vehicle changes its pseudonyms at some highly social spots, and as a result, the proposed models can be used to assist vehicles to change their pseudonyms for better location privacy at the right moment and place.
Rongxing Lu, Xiaodong Lin 0001, Tom H. Luan, Xiaohui Liang 0002, Xuemin Shen
ICC4
2011 STAP: A social-tier-assisted packet forwarding protocol for achieving receiver-location privacy preservation in VANETs
abstract
Receiver-location privacy is an important security requirement in privacy-preserving Vehicular Ad hoc Networks (VANETs), yet the unavailable receiver's location information makes many existing packet forwarding protocols inefficient in VANETs. To tackle this challenging issue, in this paper, we propose an efficient social-tier-assisted packet forwarding protocol, called STAP, for achieving receiver-location privacy preservation in VANETs. Specifically, by observing the phenomena that vehicles often visit some social spots, such as well-traversed shopping malls and busy intersections in a city environment, we deploy storage-rich Roadside Units (RSUs) at social spots and form a virtual social tier with them. Then, without knowing the receiver's exact location information, a packet can be first forwarded and disseminated in the social tier. Later, once the receiver visits one of social spots, it can successfully receive the packet. Detailed security analysis shows that the proposed STAP protocol can protect the receiver's location privacy against an active global adversary, and achieve vehicle's conditional privacy preservation as well. In addition, performance evaluation via extensive simulations demonstrates its efficiency in terms of high delivery ratio and low average delay.
Xiaodong Lin 0001, Rongxing Lu, Xiaohui Liang 0002, Xuemin Shen
INFOCOM3
2011 Toward Reliable Actor Services in Wireless Sensor and Actor Networks
abstract
Wireless sensor and actor networks (WSANs) are service-oriented environments, where sensors request actors to service their detected events and actors move to deliver the desired services. Because of their openness and unattended nature, these networks are vulnerable to various security attacks. In this paper we address service fraud attacks for the first time, whose objective is to stop the normal use of actor services by fake service requests and/or delivery. To mitigate this type of security attacks, we propose a novel cooperative authentication scheme. With the scheme, a sensor's service request is cooperatively authenticated by the sensors that witness the same event, and an actor's service delivery effort is cooperatively authenticated by the sensors that witness the actor's behavior. Considering the presence of compromised sensor/actor nodes, the trustworthiness of each authenticated service delivery process is subject to location consistency check and witness diversity check. It may then be taken into account to adjust the corresponding actor's trust rating so as to influence future actor service selection. We analyze the communication overhead and the security strength of the scheme. We show that our scheme ensures fraud-resistant actor services in our considered WSAN environment.
Xu Li 0001, Xiaohui Liang 0002, Rongxing Lu, Shibo He, Jiming Chen 0001, Xuemin Shen
MASS2
2011 Secure and quality of service assurance scheduling scheme for WBAN with application to eHealth
abstract
Wireless Body Area Network (WBAN) is gaining popularity due to its large scale of applications in eHealth. Due to its critical and real-time nature, eHealth care system must provide security, privacy, and quality of service (QoS) support, in order to provide an efficient, valuable and fully reliable assistance to patients. This paper studies packet scheduling schemes for realtime transmission in WBAN with proper security and privacy. Real-time and non real-time traffic are classified to minimize the waiting time of the eHealth application's data traffic. An efficient secure data transmission scheme in WBAN is proposed with data integrity. The scheme is user-centric and the secure key is shared among all sensors in a WBAN to minimize any additional memory and processing power requirements. Security analysis and numerical results demonstrate that our scheme can minimize the mean waiting time of a real-time traffic in WBAN and provide proper security and privacy.
Mrinmoy Barua, Md. Shamsul Alam, Xiaohui Liang 0002, Xuemin Shen
WCNC3
2011 A Secure Handshake Scheme with Symptoms-Matching for mHealthcare Social Network
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen
Mob. Networks Appl.3
2011 An efficient and provably secure public key encryption scheme based on coding theory
abstract
Abstract Although coding‐based public key encryption schemes such as McEliece and Niederreiter cryptosystems have been well studied, it is not a trivial task to design an efficient coding‐based cryptosystem with semantic security against adaptive chosen ciphertext attacks (IND‐CCA2). To tackle this challenging issue, in this paper, we first propose an efficient IND‐CCA2‐secure public key encryption scheme based on coding theory. We then use the provable security technique to formally prove the security of the proposed scheme is tightly related to the syndrome decoding (SD) problem in the random oracle model. Compared with the previously reported schemes, the proposed scheme is merited with simple construction and fast encryption speed. Copyright © 2010 John Wiley & Sons, Ltd.
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen
Secur. Commun. Networks3
2010 How to Construct Interval Encryption from Binary Tree Encryption
Huang Lin, Zhenfu Cao, Xiaohui Liang 0002, Muxin Zhou, Haojin Zhu, Dongsheng Xing
ACNS3
2010 Secure provenance: the essential of bread and butter of data forensics in cloud computing
abstract
Secure provenance that records ownership and process history of data objects is vital to the success of data forensics in cloud computing, yet it is still a challenging issue today. In this paper, to tackle this unexplored area in cloud computing, we proposed a new secure provenance scheme based on the bilinear pairing techniques. As the essential bread and butter of data forensics and post investigation in cloud computing, the proposed scheme is characterized by providing the information confidentiality on sensitive documents stored in cloud, anonymous authentication on user access, and provenance tracking on disputed documents. With the provable security techniques, we formally demonstrate the proposed scheme is secure in the standard model.
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen
AsiaCCS3
2010 Message Authentication with Non-Transferability for Location Privacy in Mobile Ad hoc Networks
abstract
Message authentication is an effective solution to prevent notorious bogus messages and worm-hole attacks in mobile ad hoc networks (MANET). However, it could also be a double-edge sword threatening mobile users privacy, e.g., location privacy, if the authenticity proofs used in message authentication were abused. In this paper, to prevent such kind of abuse, we first propose a novel efficient message authentication scheme, which can achieve not only users identity privacy but also non-transferability. We then introduce an information theoretical model to gauge the privacy level that the proposed scheme can attain. Extensive simulation results demonstrate the proposed scheme can significantly reduce the violation of mobile users' privacy in MANET.
Xiaohui Liang 0002, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
GLOBECOM1
2010 Sacrificing the Plum Tree for the Peach Tree: A Socialspot Tactic for Protecting Receiver-Location Privacy in VANET
abstract
In this paper, to simultaneously protect the receiver-location privacy and improve the performance of packet delivery in VANET, we utilize ``Sacrificing the Plum Tree for the Peach Tree" - one of the Thirty-Six Strategies of Ancient China, to propose a socialspot-based packet forwarding (SPF) protocol, where each vehicle receiver only reveals a non-sensitive socialspot, e.g., a shopping mall, that he often visits as a relay node to help packet forwarding and protect his other sensitive locations privacy. Detailed security analysis demonstrates the security of the proposed SPF protocol. In addition, extensive simulations have also been conducted to examine its good efficiency in terms of packet delivery ratio and average delay.
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen
GLOBECOM3
2010 FLIP: An Efficient Privacy-Preserving Protocol for Finding Like-Minded Vehicles on the Road
abstract
Vehicle chatting is one of the most promising applications in VANETs, which allows like-minded vehicles to chat on the topics of common interest on the road. However, there exist some newly emerging privacy challenging issues in vehicle chatting application, such as how to find a like-minded vehicle on the road and how to prevent one's interest privacy (IP) from others who are not like-minded? In this paper, to tackle these challenging issues, we propose an efficient privacy-preserving \underline{f}inding \underline{l}ike-minded veh\underline{i}cle \underline{p}rotocol (FLIP), and apply the provable security technique to demonstrate its security. In addition, extensive simulations are also conducted to examine its practical considerations, i.e., the relation between the expected IP-preserving level and the delay of finding like-minded vehicles on the road.
Rongxing Lu, Xiaodong Lin 0001, Xiaohui Liang 0002, Xuemin Shen
GLOBECOM3
2010 PPC: Privacy-Preserving Chatting in Vehicular Peer-to-Peer Networks
abstract
In this paper, a privacy-preserving chatting scheme is proposed to secure vehicular communication and achieve user privacy preservation in vehicular peer- to-peer networks. In specific, we first introduce identity-based-encryption technique which can protect the confidentiality of chatting content. Furthermore, to preserve user privacy, our scheme employs ring signature technique, which not only provides message authentication but also guarantees unconditional source anonymity. With the proposed scheme, vehicles change their pseudo identities periodically and make attackers unable to link users' transactions in different periods. As a result, the proposed scheme can achieve data confidentiality, efficient authentication, and privacy violation elimination. In addition, through detailed security and efficiency analyses, it is demonstrated the proposed scheme resists most of existing attacks in vehicular peer-to-peer networks and provides efficient sending and receiving operations.
Xiaohui Liang 0002, Rongxing Lu, Xiaodong Lin 0001, Xuemin Shen
VTC Fall1
2010 Secure threshold multi authority attribute based encryption without a central authority
Huang Lin, Zhenfu Cao, Xiaohui Liang 0002, Jun Shao 0001
Inf. Sci.3
2010 Proxy re-encryption with keyword search
Jun Shao 0001, Zhenfu Cao, Xiaohui Liang 0002, Huang Lin
Inf. Sci.3
2009 Attribute based proxy re-encryption with delegating capabilities
abstract
Attribute based proxy re-encryption scheme (ABPRE) is a new cryptographic primitive which extends the traditional proxy re-encryption (public key or identity based cryptosystem) to the attribute based counterpart, and thus empower users with delegating capability in the access control environment. Users, identified by attributes, could freely designate a proxy who can re-encrypt a ciphertext related with a certain access policy to another one with a different access policy. The proposed scheme is proved selective-structure chosen plaintext secure and master key secure without random oracles. Besides, we develop another kind of key delegating capability in our scheme and also discuss some related issues including a stronger security model and applications.
Xiaohui Liang 0002, Zhenfu Cao, Huang Lin, Jun Shao 0001
AsiaCCS1
2009 Provably secure and efficient bounded ciphertext policy attribute based encryption
abstract
Ciphertext policy attribute based encryption (CPABE) allows a sender to distribute messages based on an access policy which can be expressed as a boolean function consisting of (OR, AND) gates between attributes. A receiver whose secret key is associated with those attributes could only decrypt a ciphertext successfully if and only if his attributes satisfy the ciphertext's access policy. Fine-grained access control, a new concept mentioned by GPSW in CCS'06 can realize a more delicate access policy which could be represented as an access tree with threshold gates connecting attributes.
Xiaohui Liang 0002, Zhenfu Cao, Huang Lin, Dongsheng Xing
AsiaCCS1
2008 New (t, n) threshold directed signature scheme with provable security
Rongxing Lu, Xiaodong Lin 0001, Zhenfu Cao, Jun Shao 0001, Xiaohui Liang 0002
Inf. Sci.5
2007 Short Group Signature Without Random Oracles
Xiaohui Liang 0002, Zhenfu Cao, Jun Shao 0001, Huang Lin
ICICS1